
That mismatch creates real risk. Limited staff, tight budgets, and constantly shifting regulatory expectations leave many credit union AML programs with gaps that examiners find before compliance teams do. Turnover alone can wipe out years of institutional knowledge overnight.
This guide walks through the regulations credit unions must follow, the core components of a defensible program, the red flags staff need to recognize, and the practical steps that keep a program scalable as membership grows.
Key Takeaways
- Credit unions count as "banks" under the BSA and carry the same core AML/CFT obligations as commercial banks.
- NCUA, FinCEN, and FFIEC set credit union AML expectations; NCUA Rule 748 codifies program requirements.
- A defensible program pairs a risk assessment with four required elements: internal controls, independent testing, a BSA officer, and training.
- Examiners most often flag legacy systems, thin compliance staffing, and turnover-driven knowledge gaps.
- A financial crime advisory partner can keep AML programs scalable and audit-ready without adding headcount.
What Does AML Mean for Credit Unions?
Anti-money laundering (AML) compliance means preventing member accounts from being used to launder illicit proceeds or finance terrorism. For credit unions, this is a legal obligation, not an optional best practice.
Credit unions sit inside the same federal AML framework as banks:
- FinCEN's BSA rules define "bank" to include each U.S. office of a credit union
- The FFIEC exam manual uses "bank" generically for commercial banks, thrifts, and credit unions
- NCUA Rule 748 (12 CFR 748.2) codifies the program elements credit unions must maintain
In practice, bank-focused BSA guidance applies directly to credit unions.
"Gap" Credit Unions Aren't Exempt
Non-federally-insured, state-chartered credit unions sometimes assume they fall outside federal AML requirements because they lack a federal functional regulator. That assumption is wrong.
FinCEN proposed closing this gap in 2016 and finalized the rule in 2020. It extended AML program and Customer Identification Program (CIP) obligations to banks, including credit unions, that previously had no federal AML mandate. Affected institutions had 180 days from publication to comply. If your credit union is state-chartered without federal insurance, this rule likely applies to you.
AML Regulations and Regulatory Bodies Credit Unions Must Comply With
Credit unions sit under the same federal AML umbrella as banks, with three agencies shaping day-to-day obligations: NCUA as primary supervisor, FinCEN as the rule-maker and enforcer, and FFIEC as the interagency body coordinating examination standards.
Understanding the Key Regulators
NCUA examines BSA/AML compliance during every federally insured credit union exam. Under 12 U.S.C. § 1786(q), the agency must review a credit union's BSA procedures at each examination and report any deficiencies. If a credit union fails to establish or correct required procedures, NCUA can issue a cease-and-desist order.
NCUA also publishes guidance letters and maintains an Examiner's Guide covering BSA risk management and exam procedures.
FinCEN, a bureau of the Treasury Department, administers the BSA itself. It issues implementing regulations, interpretive guidance, and advisories, and brings civil enforcement actions against institutions with inadequate programs.
FinCEN also sets national AML/CFT priorities (corruption, cybercrime, terrorist financing, fraud, and others) that inform how examiners evaluate program design.
FFIEC doesn't examine credit unions directly, but its BSA/AML manual is the shared playbook used across federal banking regulators. The manual defines "bank" to include credit unions explicitly, meaning joint statements and guidance written with banks in mind apply equally to credit unions.
The Core Laws Credit Unions Must Follow
| Law/Rule | What It Requires |
|---|---|
| Bank Secrecy Act (BSA) | Foundational recordkeeping and reporting framework designed to detect money laundering and financial crime |
| PATRIOT Act (CIP) | Written, risk-based procedures to verify member identity at account opening (31 CFR 1020.220) |
| Anti-Money Laundering Act (AMLA) | Directs FinCEN's national AML/CFT priorities; formal incorporation into exam expectations depends on finalized implementing rules |
| NCUA Rule 748 | Credit-union-specific codification of BSA program requirements, including internal controls, testing, a designated officer, and training |
Core Components of an Effective AML Compliance Program
NCUA Rule 748 requires four program elements: internal controls, independent testing, a designated BSA compliance officer, and training. A written risk assessment isn't one of the four, but it is the foundation each of them depends on. Regulators expect it, and examiners will ask for it.

Risk Assessment
A written, regularly updated risk assessment covering products, services, members, and geographies is how a credit union identifies its own vulnerabilities before an examiner does. FFIEC guidance sets no fixed update schedule. Still, a stale assessment that ignores new products, member segments, or expanded geographic reach is a common exam finding.
Member Due Diligence (MDD) and KYC
This covers identity verification at onboarding plus ongoing risk classification. Core pieces include:
- Identity verification and beneficial ownership checks for legal-entity members
- PEP and sanctions screening against OFAC and other watchlists
- Enhanced due diligence (EDD) for higher-risk members and business accounts
- Periodic risk re-scoring as member behavior evolves
Credit unions catch a break on one BOI front: federal rules exempt them from filing their own beneficial ownership information under FinCEN's BOI rule. That exemption does not extend to member due diligence. Credit unions must still collect beneficial ownership data on legal-entity members under the CDD rule's 25% ownership threshold.
Ongoing and Transaction Monitoring
Due diligence does not end at onboarding. Transaction monitoring and screening must run continuously so risk that appears later still gets caught (for example, a member whose activity shifts from personal use to business-like cash flows).
Reporting Obligations: SARs and CTRs
Two reporting mechanisms sit at the center of BSA compliance:
- Suspicious Activity Reports (SARs): Generally required at a $5,000 aggregate threshold when a suspect is identifiable; no dollar minimum for suspected insider abuse
- Currency Transaction Reports (CTRs): Required for currency transactions exceeding $10,000, with limited regulatory exemptions
NCUA Rule 748 governs the specific SAR mechanics for credit unions.
Common AML Risks and Red Flags Facing Credit Unions
Credit unions carry a distinct risk profile compared to larger banks. Three structural issues show up again and again:
- Legacy or manual systems that can't keep pace with transaction volume growth
- Thin compliance teams where one person often wears the BSA officer, fraud, and operations hats simultaneously
- Knowledge gaps from turnover that erase institutional memory on past SARs and risk decisions when a BSA officer leaves
Newer exposure areas add complexity. Banking-as-a-Service partnerships and expanding business membership both carry elevated risk, and regulatory guidance hasn't fully caught up. NCUA's long-standing guidance on third-party relationships still applies here: outsourcing a function never outsources the responsibility for it.
Red Flags Staff Should Know
Frontline and compliance staff should be trained to spot these patterns, drawn directly from FFIEC's red flag guidance:
- Currency deposited or withdrawn in amounts just below reporting thresholds
- Rapid increases in cash deposit size or frequency with no corresponding rise in non-cash activity
- Reluctance to provide identification when purchasing negotiable instruments
- Repeated near-threshold transfers consolidated and routed to a single account outside the country
What Inadequate Controls Actually Cost
Enforcement actions rarely target only the largest institutions. In September 2023, FinCEN assessed a $15 million civil money penalty against Shinhan Bank America, a community bank with as few as 15 branches.
The bank admitted willful BSA violations spanning 2016 to 2021, including failing to maintain an effective AML program and failing to report hundreds of suspicious transactions on time. Institution size didn't shield it from a penalty that would cripple most credit unions.
Best Practices to Build a Scalable, Audit-Ready AML Program
A program that works at $200 million in assets often breaks at $800 million. Building for scale from the start avoids painful rebuilds later.
Structure Around Three Lines of Defense
- Frontline staff: tellers, loan officers, and member services reps who spot red flags in real time
- Compliance/BSA team: owns policy, monitoring, investigations, and reporting
- Independent audit: tests the program's effectiveness separately from the people who run it

Protect Against Turnover
Continuous, role-specific training matters more at credit unions than at larger banks, simply because there's less redundancy if one person leaves. A documented BSA contingency plan (who steps in, where records live, and how open cases get handed off) protects the program when key staff exit unexpectedly.
Use Automation Without Losing Control
Automation and AI-assisted monitoring tools can cut manual alert review, letting a small team cover a growing membership base without proportional headcount growth. The key is matching any tool to your actual risk profile, transaction volume, and budget. A mismatch here often creates more noise than it eliminates.
Bring in Outside Expertise Where It Counts
Many credit unions don't need a full compliance department overhaul. They need targeted expertise at the right moments. Pillars FinCrime Advisory, founded by CAMS-certified compliance professional Joshua Douglas, supports financial institutions across the full program lifecycle: policy development, risk assessments, transaction monitoring optimization, and audit-ready documentation.
For a credit union weighing whether to hire full-time or bring in fractional support, fractional advisory support can fill BSA officer gaps, provide independent vendor evaluation for monitoring tools, and keep a growing program audit-ready without overextending internal teams.
Frequently Asked Questions
What does AML mean for credit unions?
AML refers to the laws and processes that prevent members' accounts from being used to launder illicit proceeds. Credit unions are legally treated as "banks" under BSA regulations, so the same core obligations apply.
Are credit unions required to have an AML program?
Yes. NCUA Rule 748 and the Bank Secrecy Act require a written, board-approved AML program. This applies to both federally insured credit unions and most non-federally-insured, state-chartered credit unions.
What is the $3,000 rule for credit unions?
Credit unions must retain records for fund transmittals of $3,000 or more under the BSA funds transfer rule (31 CFR 1020.410(a)).
How do credit unions perform AML checks?
AML checks typically include identity verification at onboarding, ongoing transaction monitoring, sanctions and PEP screening, and periodic member risk reviews. Higher-risk members typically receive enhanced due diligence and more frequent re-screening.
What happens if a credit union fails an AML/BSA exam?
Outcomes can include written agreements, consent orders, mandated corrective action, and civil money penalties, consistent with past FinCEN actions against institutions with ineffective programs. NCUA can also issue a cease-and-desist order if deficiencies aren't corrected.
How often should a credit union update its AML risk assessment?
There's no fixed regulatory schedule, but FFIEC guidance points to updating whenever products, services, membership, or geographic footprint change materially. Many credit unions treat an annual review as a baseline internal practice.


