How to Fix BSA Program Deficiencies Before Your Next Exam

Introduction

Regulators haven't eased up on BSA/AML enforcement — they've sharpened it. In October 2024, FinCEN assessed a $1.3 billion penalty against TD Bank, the largest ever levied against a depository institution in U.S. Treasury and FinCEN history.

Banks, fintechs, and payments companies alike are feeling the pressure to prove their programs are "reasonably designed," not just written down.

Deficiencies don't appear overnight. They build up quietly as products launch, customer bases expand, and transaction volume grows past what the original program was built to handle.

This article covers the deficiencies examiners cite most and why they happen. You'll also get a four-step fix process, guidance on in-house versus outside remediation, and the mistakes that turn a fixable finding into a repeat one.

TL;DR

  • Most deficiencies trace back to one of the five pillars: usually CDD, monitoring, or independent testing
  • Findings are fixable pre-exam when root-caused correctly and remediated with evidence, not just closed on paper
  • Fix in order: pin the gap, root-cause it, remediate, then test and document with evidence
  • Repeat violations or a compressed exam timeline mean you should bring in outside expertise

What Is a BSA Program?

A BSA program is the board-approved framework that keeps an institution compliant with the Bank Secrecy Act and its implementing regulations. It covers internal controls, testing, personnel, training, and customer due diligence procedures.

Regulators evaluate it against five required components:

Pillar What It Covers
Internal controls Policies and procedures ensuring ongoing BSA compliance
Independent testing Testing by staff or an outside party free of conflicting BSA duties
Designated BSA officer The individual(s) coordinating day-to-day compliance
Training Role-based training for relevant personnel
CDD/beneficial ownership Risk-based customer identification and ongoing due diligence

The FFIEC's BSA/AML Examination Manual uses these five pillars as the baseline against which examiners test everything else.

Here's the part institutions miss: a program that is compliant at launch doesn't stay that way automatically. It's a living system. Add a new product line, expand into a new customer segment, or scale transaction volume tenfold. A program that once passed with flying colors can decay into deficiency without a single policy change.

Common BSA Program Deficiencies Examiners Cite

Most exam findings follow a predictable pattern tied to one or more of the five pillars. This isn't limited to money-center banks, either. Pillar violations increasingly show up in orders against community-sized institutions and fintech-adjacent banks.

Deficiency 1: Outdated or Generic Risk Assessment

Symptoms:

  • Risk assessment doesn't reflect new products, customer segments, or geographies
  • Boilerplate language that doesn't tie back to actual transaction or customer data

Likely cause: Teams update the risk assessment on a fixed annual calendar instead of when the business actually changes: a new product launch, an acquisition, or entry into a new market.

Deficiency 2: Weak Customer Due Diligence / Enhanced Due Diligence

Symptoms:

  • Missing or stale risk ratings on existing accounts
  • Incomplete beneficial ownership data
  • No ongoing monitoring tied to a customer's risk profile

Likely cause: Institutions treat CDD as a one-time onboarding checkbox rather than a continuous, risk-based process that updates as the customer relationship evolves.

Deficiency 3: Suspicious Activity Monitoring and SAR Filing Gaps

Symptoms:

  • Late or inaccurate SAR and CTR filings
  • Undocumented alert disposition
  • No clear rationale for SAR/no-SAR decisions

The scale this can reach is real. TD Bank's 2024 FinCEN consent order cited more than 6,000 untimely SARs and over 4,000 late CTRs covering more than $150 million, plus over 1,000 CTRs with incomplete or erroneous information.

Likely cause: Outdated monitoring scenarios and thresholds, or a staffing shortfall that lets alert backlogs pile up faster than the team can clear them.

Deficiency 4: Superficial or Ineffective Independent Testing

Symptoms:

  • Audit scope skips high-risk products or business lines
  • Findings never get tracked to closure
  • Testing lacks actual BSA subject-matter expertise

Likely cause: Internal audit lacks either the independence or the bandwidth to test transaction-level compliance in meaningful depth.

Examiners see these same four patterns repeatedly. Flagging them early gives you time to remediate before the next exam cycle starts.

4 common BSA program deficiencies examiners cite most often

How to Fix BSA Program Deficiencies Before Your Next Exam

Attempting to fix a deficiency without first isolating its true root cause is exactly why so many findings reappear at the next exam. This four-step process catches that mistake before it happens.

Step 1: Identify the Exact Deficiency

Start by pulling everything that points to where the control actually broke:

  • Recent exam findings and internal audit reports
  • SAR/CTR quality metrics and filing timelines
  • Alert volumes, false-positive rates, and backlog aging data

Then narrow it down: which pillar failed, and which specific process within it (a single CDD data field, a monitoring scenario, an onboarding step)? Scope the issue too. Is it isolated to one product or branch, or is it running across the whole institution?

Step 2: Confirm the Root Cause Category

Classify what you found into one of four buckets:

  1. Policy/procedure: the written process is outdated or wrong
  2. Staffing/expertise: the team lacks capacity or specific skill
  3. Technology/monitoring system: the tooling itself is misconfigured
  4. Governance/board oversight: leadership isn't seeing or acting on the right information

Before assigning internal blame, rule out external contributors: a core banking system limitation, a third-party model error. Don't remediate a symptom while the underlying process stays broken. That's precisely what examiners flag as a repeat violation.

Step 3: Apply the Right Fix Based on the Deficiency Type

This is where most remediation time and cost get spent, and the fix depends entirely on the category from Step 2.

If it's policy & procedure related:

  • Rewrite the procedure to reflect current risk profile, product mix, and regulatory guidance
  • Route it through board approval with version-controlled documentation showing what changed and why

If it's a staffing or expertise gap:

  • Assess whether the BSA officer and team have qualifications and bandwidth matching the institution's size and complexity
  • Consider outside compliance expertise for lookbacks, backlog clearance, or interim program leadership

This is a common inflection point for growing fintechs and payments companies. Firms like Pillars FinCrime Advisory, founded by CAMS-certified compliance leader Joshua Douglas, work with these institutions as fractional BSA/compliance officers, providing senior-level oversight and program accountability without adding a full-time executive seat.

If it's a technology or monitoring gap:

  • Retune transaction monitoring scenarios and thresholds using actual alert-to-SAR conversion data
  • Validate and document any model or rule changes before go-live to avoid trading one gap for another

If it's a governance or board oversight gap:

  • Strengthen board reporting to include alert trends, SAR filing timeliness, and staffing adequacy
  • Increase the frequency and documentation quality of BSA/compliance committee meetings

Step 4: Test, Validate, and Document the Fix

An untested fix is only a guess. Before the exam:

  • Re-sample the affected accounts or transactions to confirm the issue is actually resolved
  • Run an internal mini-review or mock exam ahead of the scheduled date
  • Build a closed-loop remediation trail examiners can follow: finding, root cause, fix, evidence, sign-off
  • Report completion and outcomes to the board for formal acknowledgment

4-step process to fix BSA program deficiencies before an exam

Fix In-House or Bring In Outside Expertise?

The right call depends on severity, how much time is left before the next exam, and whether internal resources have the bandwidth and independence to remediate credibly.

Scenario 1: Isolated or Technical Finding

A minor procedure update or a one-off training refresher usually falls to the existing BSA team without issue. Outside help isn't typically necessary here, unless internal capacity is already stretched thin.

Scenario 2: Systemic or Repeat Pillar Violations

This is riskier territory. Letting the same team that built the flawed process self-correct without independent validation rarely convinces examiners.

An outside advisor can root-cause systemic gaps and show credible, independent remediation. A fractional practice like Pillars FinCrime Advisory can lead the diagnostic and remediation plan directly, bringing in specialized resources only when a specific issue exceeds that scope.

Scenario 3: Exam Date Is Imminent

If deficiencies are minor and well understood, an in-house fix is feasible on a tight timeline. If not, a focused gap assessment and mock exam (the kind Pillars FinCrime Advisory runs for fintechs and payments companies under time pressure) can compress remediation and sharpen exam readiness before the deadline hits.

Scenario 4: Rapid Growth Has Outpaced the Program

When product launches and customer growth have outrun the original program design, an internal team already managing daily BSA operations rarely has bandwidth left to redesign the whole framework. This usually calls for outside support to rebuild a program that scales with new products, customers, and transaction volume.

Common Mistakes to Avoid & Staying Exam-Ready Year-Round

Common Mistakes to Avoid When Fixing Deficiencies

  • Closing a finding on paper without fixing the process. This is the fastest path to a repeat citation.
  • Skipping post-remediation testing. You leave no evidence the fix actually worked.
  • Underestimating staffing or expertise needs. A rushed fix rarely holds up under the next review.

Avoiding those traps is only half the job. Exam readiness depends on habits that stop new gaps from forming between exam cycles.

Preventive Measures to Stay Exam-Ready

  • Schedule mock exams or independent testing beyond the minimum annual audit
  • Keep the risk assessment current whenever products, customers, or geographies change
  • Maintain board reporting and governance trails that show ongoing oversight
  • Tie training to your institution’s real risk, not generic annual modules

Most BSA deficiencies are fixable when you catch them early and document the remediation well. Knowing when to bring in outside expertise is often what keeps a manageable finding from becoming an enforcement action.

Frequently Asked Questions

What are the 5 pillars of a BSA compliance program?

The five pillars are:

  • Internal controls
  • Independent testing
  • A designated BSA compliance officer
  • Employee and board training
  • Risk-based CDD and beneficial ownership procedures

Examiners test each pillar separately during a review.

How often must you complete BSA training?

Regulatory guidance calls for periodic, risk-based training rather than a fixed annual mandate. In practice, most institutions run annual refreshers plus targeted updates after regulatory changes or for high-risk roles.

What's the difference between AML and BSA?

BSA is the underlying U.S. law that sets recordkeeping and reporting requirements. AML is the broader set of policies and controls institutions build to detect and prevent money laundering under that law.

How long does it take to fix BSA program deficiencies before an exam?

It varies by severity. An isolated finding might take a few weeks to remediate and test. Systemic pillar violations often take months and require prioritizing the highest-risk gaps first.

Can a bank fail a BSA exam and stay open?

Most findings result in corrective action plans or consent orders rather than closure. Repeated failure to remediate, however, can escalate to formal enforcement, civil money penalties, or mandated outside monitoring.

What happens if BSA deficiencies are not fixed before the next exam?

Unresolved deficiencies are more likely to be classified as repeat or systemic violations. That classification can trigger formal enforcement action, financial penalties, or examiner-mandated outside oversight.