Building an AML Program From Scratch: A New MSB's Guide An AML program is the written set of policies, procedures, and controls a money services business must maintain to detect, prevent, and report money laundering and terrorist financing. That's the whole concept in one sentence — but building one that survives a bank's due diligence review or a FinCEN exam is where most new MSBs get stuck.

This guide is for founders and compliance leads at early-stage MSBs: money transmitters, check cashers, prepaid access providers, and currency exchangers who need a functioning program before they can register with FinCEN or open a bank account.

Most first-time operators know they need "an AML program." Few know what regulators actually expect inside it. That gap is exactly why bank applications stall and exams drag on for months.

Here's what this article covers: the required program components, the order to build them in, and the mistakes that most commonly derail new MSBs before they process their first transaction.

Key Takeaways

  • Every FinCEN-registered MSB needs a written, risk-based AML program covering CDD, beneficial ownership, and core BSA elements.
  • Tailor the program to your products, customers, and geography—not a downloaded template.
  • Build in order: risk assessment, policies, monitoring and reporting, then training and independent testing.
  • Banks and examiners reject generic programs, so get this right before launch—not after a failed exam.

What Is an AML Program & Why It's Required for Every MSB

Under the Bank Secrecy Act, every MSB must develop, implement, and maintain a written AML program reasonably designed to prevent the business from being used for money laundering or terrorist financing. That's a binding requirement under 31 CFR 1022.210, enforced by FinCEN. It is not a best practice you can skip at launch.

A working program should:

  • Catch suspicious activity early, before regulators find the pattern first
  • Get Currency Transaction Reports (CTRs) and Suspicious Activity Reports (SARs) filed on time, every time
  • Prove to banking partners and examiners that you actively manage financial crime risk

Registering with FinCEN and having an AML program are two different things, though founders often treat them as one. Registration is a filing: you submit Form 107 and land on FinCEN's list of MSBs. Having a program is the operational system: the risk assessment, written policies, compliance officer, training, testing, and customer due diligence that run day to day.

Filing without that underlying program is how MSBs end up registered and still shut down.

The cost of getting it wrong is not abstract. In 2023, FinCEN hit Binance with a $3.4 billion civil money penalty. Examiners found no functioning compliance officer, inadequate training, and independent testing that never actually tested transactions. More than 100,000 suspicious transactions went unreported.

Most new MSBs will never operate at Binance's scale. The same gaps still sink small operators in a routine bank review: missing controls, absent testing, and undertrained staff.

The Six Pillars: What Every MSB AML Program Must Include

The Bank Secrecy Act formally requires four minimum program elements under 31 CFR 1022.210. In practice, banks, state regulators, and examiners expect new MSBs to build two more: a risk assessment and a customer due diligence process. The risk assessment drives everything else; CDD verifies beneficial ownership. Together, these six form the practical foundation of a defensible program.

Pillar 1: Risk Assessment

Start here. Your program must be commensurate with the risks tied to your location, size, products, and transaction volume. Inventory every product, customer type, delivery channel, and geography you serve, then score each against known money laundering typologies. The output is a risk rating that shapes every other pillar.

Pillar 2: Internal Policies, Procedures & Controls

These must be in writing, not in someone's head. At minimum, document:

  • Customer identification requirements
  • Recordkeeping obligations
  • CTR/SAR reporting thresholds
  • How your team responds to law enforcement requests

Generic language here is one of the fastest ways to draw examiner criticism.

Pillar 3: Designated Compliance Officer

FinCEN requires a named individual accountable for day-to-day compliance. This person needs the authority, budget, and independence to actually run the program, not just hold the title. They're responsible for keeping the program current and reporting its status to leadership.

Pillar 4: Ongoing Employee Training

One onboarding session doesn't satisfy this requirement. Training has to be role-specific and recurring, covering red flags, SAR/CTR triggers, and structuring detection relevant to what each employee does.

Pillar 5: Independent Testing/Review

Someone who doesn't report to your compliance officer has to periodically test the program. That review should cover policies, transaction samples, and filing accuracy. FinCEN's guidance is explicit that testing scope and frequency should match risk, and that annual testing may be unnecessary for some MSBs and insufficient for others.

Pillar 6: Customer Due Diligence & Beneficial Ownership

The CDD Rule's beneficial ownership requirement technically applies to banks and other covered institutions rather than MSBs directly. Even so, sponsor banks and state regulators now expect equivalent practices:

  • Verifying customer identity
  • Identifying beneficial owners of entity customers
  • Understanding the relationship's purpose
  • Monitoring the relationship on an ongoing basis

Six pillars of MSB AML compliance program framework diagram

Building Your AML Program Step by Step

The six pillars define what has to exist. Building them out of order is what creates rework: a training calendar built before the risk assessment ends up teaching the wrong red flags. Start with risk, and build every other control around that risk profile.

A new MSB's program should be scaled to its actual size at launch. A single-state check casher doesn't need the same monitoring infrastructure as a multi-state money transmitter, but both need a clear plan to mature the program as volume grows.

Step 1: Conduct Your Institutional Risk Assessment

Inventory everything you offer and where it runs:

  • Products and services
  • Customer segments
  • Delivery channels (in-person, online, mobile)
  • Geographies, including cross-border corridors

Score each category against known typologies such as cash-intensive activity, rapid movement of funds, high-risk jurisdictions, and anonymous funding sources.

The result should be a single overall risk rating with documented reasoning. That rating drives your policy thresholds, monitoring rules, training priorities, and testing frequency. Rush this step, and every downstream control ends up built on guesswork.

Step 2: Draft Written Policies, Procedures, and Controls

Your policies translate the risk assessment into specific, operational rules:

  • Identification requirements at onboarding, tiered to risk
  • Recordkeeping timelines and formats
  • CTR/SAR thresholds and internal escalation paths
  • How you respond to law enforcement requests and information-sharing programs

Reference the BSA directly, along with any state money transmitter requirements tied to your license. A policy that doesn't cite the actual rule it satisfies is one an examiner will ask you to rewrite.

Step 3: Build Customer Identification, KYC, and Beneficial Ownership Processes

Verify identity at onboarding through a documented Customer Identification Program. Layer in risk-tiered due diligence: a low-risk retail customer needs less scrutiny than a high-volume entity customer moving funds internationally.

For entity customers, build a documented process to collect and verify beneficial ownership: who owns 25% or more, and who exercises significant control. This is what your sponsor bank will ask to see first during underwriting.

Step 4: Stand Up Transaction Monitoring and Reporting Workflows

Define monitoring rules around known thresholds and patterns. Any transaction over $10,000 in currency triggers a CTR, and multiple transactions by the same person totaling more than $10,000 in a single business day must be aggregated as one.

Structuring (breaking up transactions to dodge that threshold) is a federal crime, and your monitoring rules need to flag it specifically.

Assign clear alert-review responsibility so alerts don't sit unactioned. Build internal filing deadlines with buffer: SARs are due within 30 days of initial detection, extendable to 60 days if you're still identifying a suspect.

Step 5: Name a Compliance Officer and Build a Training Calendar

Choose someone with real BSA knowledge, real authority, and independence from transaction processing. A part-time hire is fine at launch; a compliance officer with no actual authority over the business is not.

Build training around each role. Frontline staff need transaction red flags; leadership needs program-level oversight. Schedule initial training before launch and recurring sessions at least annually, more often if your risk assessment flags elevated risk.

Step 6: Schedule Independent Testing Before You Need It

Plan your first independent review within the first year of operation—before a bank partner or examiner forces the issue. Use a reviewer who doesn't report to your compliance officer.

Testing this early catches design gaps (a monitoring rule that never fires, a policy that doesn't match actual practice) while you can still fix them quietly.

6-step process for building an MSB AML program from scratch

Common Mistakes New MSBs Make (and When to Get Expert Help)

New MSBs tend to repeat the same handful of errors:

  • Uncustomized policy templates. Generic money transmitter templates ignore your customer base, product mix, and geography. Examiners spot a copied policy within minutes.
  • Compliance officer as unpaid add-on. Handing BSA responsibility to someone already juggling operations, with no added authority or time, leads to missed filings and paper-only controls.
  • Delayed independent testing. When a bank or regulator forces the review, gaps are already visible outside your organization. Testing on your schedule lets you fix problems quietly.

Building a defensible, audit-ready program correctly the first time is difficult without prior examiner-facing experience. Most founders have never seen the inside of a FinCEN exam or a sponsor bank's underwriting file. That's why many new MSBs work with a CAMS-certified advisor like Pillars FinCrime Advisory to build the program right from day one, rather than paying for remediation after a failed review.

Conclusion

A compliant AML program is one system built from six connected pieces: risk assessment, written policies, a compliance officer, training, independent testing, and customer due diligence with beneficial ownership verification. Build them in that order, and each piece reinforces the next.

For a new MSB, getting this right at launch protects your ability to open and keep a bank account, pass your first exam, and scale without rebuilding your compliance foundation later.

The programs that survive their first real audit are the ones built to function on day one, day one hundred, and every exam after that.

Frequently Asked Questions

What should an AML program include?

A compliant program combines a risk assessment, written policies, a designated compliance officer, ongoing training, independent testing, and customer due diligence with beneficial ownership verification. It must be documented and scaled to your actual risk profile.

How long does it take to build an AML program from scratch?

Timelines depend on complexity, but a functional first version typically takes several weeks to a few months when built methodically. Federal rules require implementation within 90 days of establishing the business.

Who can serve as an MSB's BSA/AML Compliance Officer?

The role can be filled internally or, for smaller MSBs, by an outsourced qualified professional. The person needs real authority, independence from transaction processing, and working BSA knowledge rather than a specific title.

How often should an MSB update its AML risk assessment?

Review it at least annually, and immediately whenever there's a material change in products, customers, or geography. Waiting for the annual cycle leaves your other controls out of date.

What happens if an MSB operates without an adequate AML program?

Consequences range from regulatory fines and lost banking relationships to criminal liability for individuals involved. Banks also routinely close accounts once a program deficiency surfaces.

Can a new MSB outsource parts of its AML program?

Yes. Functions like policy drafting, independent testing, and ongoing advisory support can be outsourced to qualified third parties. Overall program ownership and accountability stay with the MSB.