Anti-Money Laundering, Bank Secrecy and OFAC Regulations

Share this page:

The Anti-Money Laundering (AML) regulations, Bank Secrecy (BSA) Act regulations  and the regulations issued by the U.S. Department of the Treasury Office of Foreign Asset Control (OFAC) are the cornerstone of a successful U.S. federal regulatory compliance program.  Consumer, Privacy, and Data Security regulations will also apply to most Fintechs, and will be discussed in a later article. Foreign, state and local laws may also be applicable.

BSA Regulations

The BSA regulations establish requirements for record keeping and reporting by private individuals, banks, and other financial institutions and are intended to help identify the source, volume, and movement of currency and other monetary instruments transported or transmitted into or out of the United States, or deposited in financial institutions, facilitating the enforcement by federal agencies of money laundering and other financial crimes.

AML Regulations

The AML regulations set forth a framework of required due diligence and compliance programs which further facilitate the enforcement by federal agencies of money laundering and other financial crimes, whether pursuant to the AML or BSA regulations.  The regulations also serve as a roadmap for regulated parties, The regulations also serve as a roadmap for regulated parties, assisting them to comply with applicable laws and regulations.

OFAC Regulations

The OFAC regulations are primarily focused on (i) enforcement of economic sanctions based on foreign policy and national security goals against countries, territories, sectors, and individual criminal enterprises, (ii) identification of the beneficial ownership and control of any entity that opens an account relationship with a financial institution, and (iii) the licensing and compliance requirements imposed on entities that are deemed “money service businesses”.

Application of the AML, BSA and OFAC regulations to Fintechs.

Substantially all Fintechs will be subject to some degree of regulation pursuant to the referenced regulations.  As a practical matter, a Fintech will be subject to direct regulation if its activities include the acceptance, custody, or transmission of funds by any means.  Indirect application of such regulations will occur when a Fintech partners with a bank or other regulated financial institution, such as insurance companies, securities and commodities broker dealers, entities involved in real estate settlements, and money service businesses. Partial exemption from the regulations may exist but requires analysis on a case-by-case basis.

Compliance Program Requirements

Pursuant to AML regulations, Fintechs are required to put into effect a Compliance Program which provides for what is known as the “Five Pillars”, which include:

  • Designation of a Compliance Officer. The compliance officer should be a senior officer appointed by the Board of Directors, who will report directly to the Board of Directors. The compliance officer is responsible for the creation and updating of written internal compliance guidelines and the ongoing evaluation and improvement of such guidelines and the related procedures. 
  • Creation of Internal Written Policies. A written compliance policy should be adopted by the Board of Directors.   The policy should specify, in detail, the customer due diligence procedures applicable to current and new customers, and the timing and depth of periodic evaluation of the procedures.  The policy should also specify the reports required to be delivered to the Board of Directors on a periodic basis.
  • Creation Of Internal Training Programs. Training should focus on the proper implementation of the internal policies and the identification of “red flags” which require the application of enhanced procedures.  The training should occur no less frequently than annually and should be updated to cover changes in regulation and market practice.
  • Independent Auditing of the Compliance Program. The compliance program should be tested and audited by independent accredited third parties on a periodic basis.  A written summary of the findings of the auditor should be delivered to the Board of Directors.
  • Customer Identification and Due Diligence. 
    • The Customer Identification Process establishes the identity of the customer, the beneficial ownership and/or control of the customer, and the nature of the customer’s activities. A component of the Customer Identification Process includes checking the customer and its beneficial owners against all OFAC sanctions lists as well as checking relevant databases published by the U.S. Department of Commerce or other federal agencies.
    • The Customer Due Diligence Process is a risk-based analysis of the information obtained pursuant to the Customer Identification Process.  Pursuant to the Customer Due Diligence Process, each customer is assigned a risk profile and rating based on (i) the type of products and services it offers, (ii) the type of entities with which it interacts in the ordinary course of business, and (iii) its geographic location, as well as the geographic locations in which it carries out its principal business activities.  The risk profile will determine whether “enhanced due diligence” should be applied to the customer on an ongoing basis.

The Compliance Program Requirements discussed above are focused solely on compliance with AML, BSA, and OFAC regulations.