Currency Transaction Reports: 2027 CTR Filing Guide
The $10,000 threshold hasn't moved since 1970, but the rules around it have never been more complex. Here's what compliance teams need to know in 2027.

The Bank Secrecy Act turns 57 this year, and its most operationally demanding artifact — the Currency Transaction Report — remains as consequential as ever. Miss a filing deadline and you're looking at civil penalties that start at $1,366 per violation under FinCEN's 2025 inflation adjustments. File one with material errors and you've handed examiners a thread to pull. Yet for many mid-market fintechs and community banks, CTR workflows still run on spreadsheets, tribal knowledge, and fingers crossed.
This guide cuts through the boilerplate. Whether you're a compliance officer auditing an existing program or an ops lead inheriting a process that's never been stress-tested, what follows is a precise, current picture of FinCEN CTR obligations — the thresholds, the aggregation math, the structuring exposure, and the automation stack that keeps it all from eating your team alive.
The $10,000 Rule: What It Actually Covers
Under 31 U.S.C. § 5313 and its implementing regulation at 31 C.F.R. § 1010.311, any financial institution must file a CTR whenever a customer conducts a cash transaction — or multiple related cash transactions in a single business day — that in the aggregate exceed $10,000. That threshold has not changed since the BSA's enactment in 1970, when $10,000 was roughly equivalent to $80,000 in 2027 purchasing power.
Three things catch institutions off guard:
- Direction is bidirectional. Deposits, withdrawals, currency exchanges, cash-in payments for loans — both inflows and outflows count. A customer who withdraws $6,000 in the morning and deposits $5,500 in the afternoon has crossed the threshold if a teller or system links those transactions.
- "Cash" means physical currency. Checks, ACH, wire transfers, and most digital-asset transactions do not trigger CTR obligations under current FinCEN guidance (though they may trigger Suspicious Activity Reports). The operative word in every regulation is currency.
- The filer is the institution, not the branch. If your organization operates multiple branches and a customer splits transactions across locations on the same business day, aggregation rules still apply — provided your systems can see across locations, which is itself an audit finding if they can't.
FinCEN's BSA E-Filing System is the mandatory submission portal. Paper CTRs have not been accepted since 2013.
Aggregation Rules: The Math That Trips Everyone Up
Aggregation is where most CTR errors originate. The regulation requires institutions to aggregate transactions conducted by or on behalf of the same person on the same business day. That phrase — "on behalf of" — is the operational landmine.
Conductor vs. Beneficiary
FinCEN distinguishes between the conductor (the person physically handling cash at the window) and the beneficiary (the account owner or recipient). If a business owner sends three employees to three different branches to deposit cash totaling $12,000, each employee is a conductor acting on behalf of the same beneficiary. The institution is obligated to aggregate, identify the beneficiary, and file.
Multiple Accounts, Same Owner
A customer with a checking account and a money market account at your institution who deposits $6,000 into each on the same day has triggered a $12,000 CTR event. Core banking systems that don't link accounts by taxpayer ID will miss this — and examiners specifically test for it.
Business Day Definition
Most institutions define their business day cutoff for CTR purposes as the close of business (typically 5:00 PM local time or the system's end-of-day batch). Transactions after cutoff roll into the next business day. Document this definition in your BSA policy. Examiners will ask.
Structuring: The Offense That's Worse Than the Threshold
Structuring — deliberately breaking up transactions to avoid the $10,000 reporting threshold — is a federal felony under 31 U.S.C. § 5324, regardless of whether the underlying funds are from legal sources. The Simplot and Dehko cases, both decided by the Sixth Circuit in the 2010s, reinforced that even small business owners depositing legitimate revenue can face civil asset forfeiture if transaction patterns suggest structuring intent.
Compliance insight: A customer who makes $9,800 deposits on twelve consecutive Tuesdays is almost certainly structuring. The red flag isn't any single transaction — it's the pattern. Your transaction monitoring system should flag sub-threshold cash transactions occurring with suspicious regularity, not just aggregate-and-file mechanically.
Structuring detection requires your SAR and CTR workflows to talk to each other. A transaction that doesn't meet the CTR threshold individually may still require a Suspicious Activity Report if the pattern is suspicious. The two obligations are parallel, not mutually exclusive.
Common structuring patterns your monitoring rules should cover:
- Repeated cash deposits of $9,000–$9,900 within short windows
- Multiple same-day transactions at different branches just under $10,000
- Third-party conductors making frequent sub-threshold deposits to the same account
- Sudden drops in deposit size following a CTR filing (customers learning the threshold)
Exemptions: CTRs You Don't Have to File
Not every institution fully uses the exemption framework, which is a missed opportunity. Phase I exemptions cover:
- Banks (for transactions with other banks)
- Federal, state, and local government entities
- Entities listed on a national securities exchange (and their majority-owned subsidiaries)
Phase II exemptions cover non-listed businesses and payroll customers that meet frequency and cash-intensity criteria. Institutions must file a FinCEN 110 Designation of Exempt Person form and conduct annual reviews to maintain exemptions.
The operational leverage here is real: a single Phase II exemption for a high-volume retail client can eliminate dozens of CTR filings per year. But exemptions require due diligence documentation, annual renewals, and revocation procedures if customer risk changes. Don't set and forget.
Filing Mechanics: Deadlines, Data Fields, and Common Errors
CTRs must be filed within 15 calendar days of the transaction date. There is no grace period. Late filings are tracked in FinCEN's system and flagged in examination.
The current FinCEN CTR form (FinCEN Form 112, revised April 2019) requires:
- Transaction information: date, amount, transaction type, institution location
- Person information: full legal name, date of birth, address, SSN or EIN, ID type and number
- Account information: account number(s) affected
- Institution information: legal name, EIN, primary federal regulator, contact officer
The most frequent errors cited in FinCEN enforcement actions and examination findings:
- Missing or incomplete ID information for the conductor (not just the beneficiary)
- Incorrect aggregation — filing only on transactions above $10,000 rather than on the aggregate
- Using a customer's informal name or trade name instead of legal name
- Failing to check "multiple transactions" when aggregation is involved
- Erroneous transaction type codes (e.g., coding a cash loan repayment as a deposit)
FinCEN's SAR/CTR Activity Review bulletins, published semi-annually, are the most practical source of current error taxonomy. They're free and most compliance teams don't read them.
The Automation Imperative: Why Manual CTR Workflows Break
At transaction volumes above roughly 200 cash transactions per month, manual CTR tracking is not a compliance program — it's a liability waiting to be discovered. The failure mode is predictable: a teller misses an aggregation, a supervisor doesn't catch it in review, a missed CTR sits unfiled until an examiner pulls the transaction register.
The modern CTR automation stack has four components:
- Core banking integration: Real-time or end-of-day cash transaction feeds, cross-branch and cross-account aggregation by TIN
- Rules engine: Threshold logic, aggregation rules, exemption status checks, and structuring pattern flags running simultaneously
- Case management: Workflow for compliance review, ID verification, and filing approval before submission
- Direct E-Filing integration: Automated submission to FinCEN's BSA E-Filing System with confirmation tracking and error handling
The Federal Reserve's 2026 Community Banking Survey found that institutions using automated BSA/AML platforms reported 34% fewer examination findings related to CTR completeness compared to those relying primarily on manual processes. That gap widens as transaction volume grows.
For fintechs and neobanks operating on modern infrastructure, the path is API-first: plug transaction data into a compliance engine that handles aggregation, exemption logic, and filing without human touchpoints for routine cases.
What Examiners Look for in 2027
Examination methodology for CTR compliance has evolved. The OCC, FDIC, and FinCEN's own examination teams now use data analytics to pre-screen institution transaction records before the exam even begins. They're looking for:
- Transaction register gaps: days with no CTR filings at high-volume cash institutions
- Statistical anomalies: average transaction sizes that cluster just below $10,000
- Exemption file mismatches: transactions for exempted entities that should have been filed
- Late filing patterns: CTRs submitted on days 14–15 suggesting a backlog problem
The CFPB's 2026 enforcement coordination with FinCEN — particularly the [joint guidance on BSA compliance at non-bank financial institutions](https://www.cfpb.gov/compliance/supervisory-guidance/) — signals that fintechs and money service businesses face the same scrutiny as chartered banks, without always having the same compliance infrastructure.
The practical implication: your CTR program needs to be audit-ready on day one, not assembled in response to an examination notice.
Building a Defensible CTR Program
A defensible program has six elements:
- Written policy that defines business day, aggregation methodology, exemption procedures, and escalation paths — reviewed annually
- System controls that enforce aggregation rules automatically, with alerts for manual override
- Training records showing that all cash-handling staff understand CTR triggers and the prohibition on structuring
- Independent testing — not self-assessment, but a third party or internal audit function testing actual transaction data against CTR filings at least annually
- Exemption file governance with documented annual reviews and revocation triggers
- Metrics dashboard tracking filing volumes, late filings, error rates, and structuring referrals month-over-month
None of this is optional if you're subject to BSA examination. And if you're a fintech that processes cash — through ATM networks, cash-in retail locations, or agent banking arrangements — you are subject to BSA examination, whether or not you have a federal bank charter.
Automate What's Automatable
The compliance overhead of CTR filing is real, but it's also largely solvable. The $10,000 rule is deterministic. Aggregation logic is deterministic. Exemption status is a lookup. What requires human judgment is the structuring detection and SAR decision layer — and that's exactly where your team's attention should be focused, not on manually keying transaction data into FinCEN Form 112.
The AtlasForge Financial API is built for exactly this workflow. It ingests cash transaction events, applies configurable aggregation and exemption logic, surfaces structuring pattern alerts, and manages the FinCEN E-Filing submission lifecycle — with full audit trail at every step. Compliance teams using our platform reduce CTR processing time by an average of 78% while improving filing accuracy scores in examination. If you're running a manual or semi-manual CTR process and your transaction volume is growing, that's not a workflow to optimize — it's one to replace. Talk to our team or explore how the API fits your stack at AtlasForge Financial's developer hub.
Further reading
Ready to build on AtlasForge?
Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.
