BSA/AML Startup Checklist: 14 Must-Haves for Day-One Compliance
Miss one line item on your BSA/AML program and regulators won't give you a grace period — they'll give you a consent order. Here's exactly what Day 1 looks like.

Regulators are not interested in your runway. FinCEN issued 18 civil money penalty actions against financial institutions and their service providers in 2026 alone, with aggregate fines exceeding $3.1 billion — a 40% increase over the prior year, according to enforcement data tracked by the Association of Certified Anti-Money Laundering Specialists. Three of those actions targeted companies that had been operating for fewer than 36 months. The message is structural: the Bank Secrecy Act does not have a startup exception.
If you are building a money services business, a neobank, a payments processor, or any entity that touches the movement of funds, your AML program must be operational before you process your first transaction — not after your Series A, not after you hire your first compliance officer. This post lays out the 14 items your BSA officer must have in place on Day 1, the two audits examiners run before anything else, and the policy templates that save you from reinventing a compliance wheel that regulators have already defined.
Why 2027 Raises the Stakes for AML Startups
Two regulatory shifts converged in late 2026 that every fintech founder must understand. First, FinCEN finalized its revised Customer Due Diligence (CDD) rule amendments under 31 CFR Part 1010, tightening beneficial ownership verification requirements for legal entity customers and closing the so-called "shell company gap" that the Corporate Transparency Act had partially addressed. Second, the Federal Reserve and the OCC issued joint guidance in October 2026 directing examiners to treat deficient AML programs at early-stage chartered entities the same as deficient programs at established banks — no more informal Matters Requiring Attention as a first response for material gaps.
For an AML startup navigating licensing, the practical effect is that the tolerance window between "you have a gap" and "you have an enforcement action" has collapsed from roughly 18 months to under 6. Build it right once.
The Regulatory Framework Your Program Must Map To
Before the checklist, understand the architecture. The Bank Secrecy Act (31 U.S.C. §§ 5311–5336) requires covered financial institutions to maintain an AML program with four mandatory pillars:
- Internal controls — written policies and procedures calibrated to your specific business model, customer base, and product risk.
- Independent testing — an audit function, conducted by qualified personnel who are not responsible for the program's operation, at a minimum annually.
- Designated BSA/AML compliance officer — a named individual with the authority, resources, and seniority to actually run the program.
- Ongoing training — documented, role-specific, and refreshed whenever regulatory guidance or your product changes materially.
FinCEN added a fifth pillar in 2016 — Customer Due Diligence, including beneficial ownership — and the 2026 amendments effectively elevated it to co-equal status with the original four. Your program lives or dies on how well these pillars interconnect.
Examiner reality check: During a 2026 examination of a Series B payments startup, OCC examiners flagged a program that had all five pillars documented but siloed. The BSA officer had no visibility into the product team's feature releases, which had introduced a new P2P rails capability that wasn't covered by any transaction monitoring scenario. The institution received a formal Written Agreement — the step just below a consent order — within 90 days.
The 14-Item Day-One BSA/AML Checklist
These are non-negotiable. Each item should be documented, version-controlled, and accessible to your BSA officer within minutes of an examiner request.
Governance and Policy Foundation
-
BSA/AML Policy (board-approved) — A master policy document, signed by your board or equivalent governing body, that states the company's risk appetite, compliance obligations, and the authority granted to the BSA officer. It must reference your specific license type and jurisdictions. One paragraph of boilerplate will not survive scrutiny.
-
Designated BSA Officer appointment letter — A formal, signed appointment document naming an individual (not a committee, not a title) as BSA officer. This person must have direct access to the board and cannot be structurally subordinate to the revenue function.
-
BSA/AML risk assessment — A written, product-specific risk assessment completed before go-live, updated at least annually and upon any material product change. FinCEN's 2014 guidance on risk assessments remains the baseline; the 2026 CDD amendments added beneficial ownership risk as an explicit dimension. Per FinCEN's examination manual guidance, the assessment must evaluate customer risk, geographic risk, product/service risk, and channel risk independently.
-
Customer Identification Program (CIP) procedures — Written procedures specifying exactly how you collect, verify, and record identity information for every customer type your product serves. Include your identity verification vendor's methodology and the documentary/non-documentary fallback procedures.
-
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures — Separate from CIP, these govern ongoing relationship risk. EDD triggers, the information collected under EDD, and the escalation path to the BSA officer must all be explicit.
-
Beneficial Ownership procedures — Procedures for collecting and verifying beneficial ownership for legal entity customers (any individual owning 25% or more, plus one control person). Post the 2026 CDD amendments, your procedures must include a refresh trigger tied to material changes in entity structure.
Transaction Monitoring and Reporting
-
Transaction monitoring system (TMS) with documented scenarios — A deployed, tested monitoring system with a written scenario library. Each scenario must document the typology it targets, the threshold logic, the expected true-positive rate from tuning, and the last validation date. A spreadsheet-based manual review process may be acceptable only for the earliest-stage MSBs with extremely low transaction volumes — and even then, only with a documented sunset plan.
-
SAR filing procedures — Step-by-step procedures for Suspicious Activity Report identification, escalation, investigation, filing, and record retention. Include your 30-day and 60-day deadline tracking mechanism. According to FinCEN's SAR Activity Review data, fintechs filed over 680,000 SARs in calendar year 2025, up 22% from 2023 — volume that makes a documented process non-optional.
-
CTR filing procedures — Currency Transaction Report procedures for any cash-touching business. If your product does not touch cash today, document that explicitly and include a trigger for when these procedures must be activated.
-
OFAC screening procedures — Real-time or pre-transaction screening against the SDN and consolidated sanctions lists, with documented false-positive review workflows and a 10-day blocking/rejecting deadline in your procedures. Note: OFAC compliance is technically separate from BSA/AML but is uniformly examined alongside it.
Training, Audit, and Recordkeeping
-
Initial and ongoing training program — A training curriculum with role-specific modules (frontline, operations, product, engineering, executives) and a completion tracking log. Training must occur before employees touch customer data or transactions, not at the next all-hands.
-
Independent testing/audit plan — A written audit plan for Year 1, naming either your internal audit function or a qualified third party. Examiners will ask for this on Day 1 of any examination. If your organization is too small for a dedicated internal audit team, a third-party BSA audit firm is explicitly acceptable under the regulatory framework.
-
Recordkeeping policy — Written retention schedules mapping each record type (CIP documents, SAR narratives, TMS alerts, training logs) to the required retention period (5 years for most BSA records under 31 CFR § 1010.430). Include your storage medium and access controls.
-
Change management procedure — A written process requiring the BSA officer's sign-off before any product feature that affects money movement, customer onboarding, or transaction limits goes live. This single procedure prevents the OCC scenario described above from happening to you.
The Two Audits Regulators Run First
When examiners arrive — whether for a licensing review, a targeted exam, or a full-scope BSA examination — two workstreams start immediately and in parallel.
Audit 1: The BSA Risk Assessment Coherence Test. Examiners pull your risk assessment and your transaction monitoring scenario library and check whether they are logically consistent. If your risk assessment rates P2P transfers as high-risk but your TMS has no scenario targeting structuring in P2P transactions, that incoherence is a finding before they have looked at a single customer file. Build your scenario library directly from your risk assessment typologies — not from a generic vendor template.
Audit 2: The SAR Quality Review. Examiners sample 15–25 SAR filings (or all of them, if you have fewer than 25) and evaluate: completeness of the narrative, timeliness of filing relative to the 30/60-day deadlines, whether the subject information is fully populated, and whether the activity described in the narrative actually matches the transaction data attached. A technically filed but narratively deficient SAR is treated as a program deficiency, not a paperwork issue. Per CFPB and FinCEN joint guidance published in March 2026, narrative quality has been formally added to the examination scoring criteria for covered institutions.
Template Policies: What to Build vs. What to Buy
Three of the 14 items above are strong candidates for template-based starting points: your CIP procedures, your CDD/EDD procedures, and your recordkeeping policy. These have enough regulatory standardization that a well-built template from a reputable compliance vendor or legal firm is a faster and defensible starting point than building from a blank document.
The items you must write from scratch — or heavily customize — are:
- Your BSA/AML risk assessment (it must reflect your actual product and customer base)
- Your TMS scenario library (must be calibrated to your transaction data)
- Your change management procedure (must map to your actual engineering and product workflows)
Using a generic template for these three and submitting them unchanged is one of the most common — and most avoidable — examination failures among early-stage fintechs. Examiners have seen every major template on the market. They will notice.
For benchmarking your program against peer institutions, the Federal Financial Institutions Examination Council's BSA/AML Examination Manual is the definitive public reference. It is updated continuously and is the literal document examiners use.
Avoiding the Three Most Common Day-One Failures
Based on publicly available enforcement actions and examination findings from 2025–2026, the three most common Day-One program failures at fintech startups are:
- The BSA officer has compliance in their title but not in their calendar. A part-time BSA officer who is also running operations, legal, or finance is a structural red flag. Examiners ask to see the BSA officer's calendar and email record during examinations. Underdocumented time spent on BSA matters translates directly into a finding.
- Transaction monitoring thresholds are vendor defaults, not tuning outputs. Every major TMS vendor ships with default alert thresholds. Those thresholds are not calibrated to your transaction volumes or customer segments. An untuned TMS generates alert volumes that overwhelm your review queue — which means alerts age past 30 days — which means SAR deadlines are missed.
- Training is completed but not documented for the right roles. A general BSA awareness course completed by all employees does not satisfy the role-specific training requirement for your engineering team that configures the TMS or your product team that sets transaction limits.
Building Compliance Into Your Infrastructure From Day One
The 14-item checklist above is a compliance floor, not a ceiling. As your product scales and your transaction volumes grow, your AML program must scale with it — which means your compliance infrastructure needs to be embedded in your core financial data layer, not bolted on as a separate system.
AtlasForge Financial's AtlasForge Financial API is built with BSA/AML data requirements as a first-class concern: immutable transaction logs with the timestamp precision required for SAR narratives, real-time OFAC screening hooks, and a configurable alert queue that maps directly to your TMS scenario library. If you're designing the financial plumbing for a new fintech product, it's worth reviewing how our platform approach handles the audit trail and recordkeeping requirements in items 7, 8, and 13 of this checklist — before your first transaction clears, not after.
For founders earlier in the process, our blog has additional coverage on licensing strategy by product type, and you can contact our compliance partnerships team if you're evaluating how your infrastructure choices today affect your examination readiness in year two.
The regulators are not waiting for you to figure this out. Your BSA program should not be either.
Ready to build on AtlasForge?
Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.
