États-Unis KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en États-Unis.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Réponse directe
Que couvre la checklist de conformité pour États-Unis ?
La checklist pour États-Unis traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 44 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary federal AML framework
- Bank Secrecy Act and 31 CFR Chapter X, with sector-specific rules
- Financial intelligence unit
- Financial Crimes Enforcement Network (FinCEN)
- Bank SAR trigger and timing
- $5,000 aggregate threshold; generally 30 days, or 60 days if no suspect is identified
- Currency transaction report
- More than $10,000 in currency aggregated by person and business day; file within 15 days
- Funds-transfer record / travel rule
- $3,000 or more, subject to exclusions and role-specific data requirements
- Covered-institution CDD ownership prong
- Each individual owning 25% or more, plus one control person, subject to exemptions and 2026 relief
- Corporate Transparency Act BOI
- U.S.-created entities and U.S. persons are exempt under the current rule; qualifying foreign registered entities remain in scope
- Core federal AML retention
- Generally 5 years, but the event that starts the clock varies by record
- Money transmission licensing
- FinCEN MSB registration may apply federally; separate state licences or exemptions must be analysed
- OFAC block / reject reporting
- Generally within 10 business days; blocked property also has an annual 30 September report
- Privacy and breach rules
- Sectoral federal rules plus state-by-state privacy, biometric and breach-notification requirements
- FATF public lists
- The United States was not named on the FATF public-list page reviewed 31 July 2026
Détail d’implémentation
Exigences et actions de conformité pour États-Unis
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensing perimeterResolve the legal entity, activity, charter, product, customer location and state nexus first. U.S. AML duties differ materially by sector and federal registration does not replace state authorisation.4 éléments+
BSA obligations in 31 CFR Chapter X are defined by institution type; a bank, broker-dealer, casino and money services business do not share one identical programme or reporting rule set.
- Action d’implémentation
- Build an entity-activity matrix that maps each product and customer flow to the relevant Chapter X part, federal functional regulator and examination manual.
- Preuves à conserver
- Signed perimeter memorandum, charter and entity records, activity map, regulator mapping and counsel conclusions.
- Source primaire
- 31 CFR Chapter X; FinCEN, Financial Institutions
A business that meets a money services business definition must register with FinCEN unless an exception applies; initial registration is generally due within 180 days and renewal is every two calendar years.
- Action d’implémentation
- Classify each money transmission, exchange, cheque, prepaid-access and related service; register on time and calendar biennial renewal.
- Preuves à conserver
- MSB analysis, Form 107 filing, acknowledgement, agent list, renewal calendar and exemption rationale where used.
- Source primaire
- 31 CFR 1022.380; FinCEN, MSB Registration
FinCEN MSB registration is not a substitute for state money-transmitter or virtual-currency licensing, and requirements vary by state and activity.
- Action d’implémentation
- Complete a state-by-state licensing and exemption analysis before serving residents or taking regulated activity into a state; track licence conditions and change triggers.
- Preuves à conserver
- Fifty-state matrix, legal opinions, NMLS records, licences, exemptions, surety bonds and renewal controls.
- Source primaire
- California Financial Code, Money Transmission Act; NYDFS, Virtual Currency Businesses
The federal investment-adviser AML and SAR rule is not effective in 2026; FinCEN postponed its effective date to 1 January 2028.
- Action d’implémentation
- Do not mislabel the postponed rule as a current federal duty. Track the rulemaking and separately implement obligations arising from other status, contracts, sanctions or risk policy.
- Preuves à conserver
- Applicability memo, rule-change register, board decision and implementation roadmap for any future effective rule.
- Source primaire
- FinCEN final rule postponing IA AML Rule, 31 Dec. 2025
02AML programme, governance and risk assessmentDesign the programme for the institution category actually in scope and document why its controls are reasonably designed for the business's products, customers, channels and geographies.4 éléments+
Covered financial institutions must maintain a written, risk-based AML programme containing the elements prescribed for their sector, commonly internal controls, a responsible person, training and independent testing.
- Action d’implémentation
- Map the applicable programme regulation to owned policies and controls; obtain governing-body approval where required and document independence and authority.
- Preuves à conserver
- Approved AML programme, responsibility charter, organisation chart, training records, test plan, findings and remediation log.
- Source primaire
- 31 U.S.C. 5318(h); applicable 31 CFR Chapter X sector part
The CDD Rule requires covered institutions to understand the nature and purpose of customer relationships, develop risk profiles, monitor for suspicious activity and update customer information on a risk basis.
- Action d’implémentation
- Define risk factors, scoring logic, expected-activity capture, event-driven refresh triggers and escalation rules; do not rely solely on fixed periodic review dates.
- Preuves à conserver
- Risk methodology, customer profile, model governance, alert scenarios, trigger catalogue, review samples and approvals.
- Source primaire
- 31 CFR 1010.210; FinCEN, CDD Final Rule; FFIEC BSA/AML Manual, CDD
An effective programme must address products, services, customers, entities, delivery channels and geographic exposure, including new or materially changed activity.
- Action d’implémentation
- Run a documented enterprise and product risk assessment before launch and after material change; link residual risks to controls and accepted exceptions.
- Preuves à conserver
- Enterprise risk assessment, product approval, control inventory, residual-risk decisions and change log.
- Source primaire
- 31 U.S.C. 5318(h); FFIEC BSA/AML Manual, BSA/AML Risk Assessment
Outsourcing a control does not remove the regulated institution's responsibility for compliance and effective oversight.
- Action d’implémentation
- Perform due diligence before appointment, set measurable contractual requirements, control data and model changes, test performance and maintain exit capability.
- Preuves à conserver
- Vendor due diligence, contract, service levels, audit rights, monitoring reports, issue register and exit plan.
- Source primaire
- FFIEC BSA/AML Manual, Developing Conclusions and Finalizing the Exam
03Customer identification and identity verificationCustomer Identification Program rules are sector-specific. The bank rule below is a useful control benchmark but must not be copied to an entity governed by a different CIP provision without confirming scope.4 éléments+
Before opening a bank account, the CIP must obtain at least name, date of birth for an individual, address and an identification number, subject to the rule's detailed alternatives and exceptions.
- Action d’implémentation
- Configure mandatory fields by person and entity type; prevent opening or restrict use when required information is missing under the approved policy.
- Preuves à conserver
- CIP policy, field rules, onboarding screenshots, test cases, exception approvals and sampled customer files.
- Source primaire
- 31 CFR 1020.220(a)(2)
A bank CIP must contain risk-based procedures to verify identity to the extent reasonable and practicable within a reasonable time after account opening, using documentary, non-documentary or combined methods.
- Action d’implémentation
- Define acceptable documents, database and device checks, fraud controls, discrepancy handling and a reasonable verification deadline by risk and channel.
- Preuves à conserver
- Verification matrix, vendor configuration, decision logs, false-positive testing, discrepancy cases and quality assurance results.
- Source primaire
- 31 CFR 1020.220(a)(2)(ii)
The CIP must explain when the institution will not open an account, restrict it, close it or file a SAR when it cannot form a reasonable belief that it knows the customer's true identity.
- Action d’implémentation
- Implement explicit unresolved-identity states, permitted activity, time limits, escalation ownership, closure and SAR decisioning.
- Preuves à conserver
- CIP failure procedure, case workflow, restriction rules, closure samples and SAR decision records.
- Source primaire
- 31 CFR 1020.220(a)(2)(iii)
Bank CIP notice must be provided before account opening in a form reasonably designed to inform the customer that identifying information is being requested.
- Action d’implémentation
- Place approved notice before submission in every assisted and digital channel and retain the deployed version and effective date.
- Preuves à conserver
- Notice text, channel screenshots, version history, localisation review and deployment record.
- Source primaire
- 31 CFR 1020.220(a)(5)
04Legal entities and beneficial ownershipKeep customer due diligence under 31 CFR 1010.230 separate from Corporate Transparency Act reporting. They have different covered parties, tests and current exemptions.4 éléments+
Covered institutions identify and verify each individual owning 25 percent or more of a legal-entity customer and one control person, subject to exclusions and exemptions.
- Action d’implémentation
- Separate ownership and control prongs, test direct and indirect holdings, document exclusions and verify each in-scope person.
- Preuves à conserver
- Ownership chart, certification, calculations, identity evidence, control-person rationale and exemption.
- Source primaire
- 31 CFR 1010.230(d)-(e); FinCEN, CDD Final Rule
FinCEN's 2026 relief permits covered institutions to limit collection to the first account, when reliability is questioned and as needed through risk-based ongoing CDD.
- Action d’implémentation
- Use the relief only within its terms, retain the verified record and refresh when facts call its reliability into question.
- Preuves à conserver
- Relief analysis, policy, first-account marker, trigger logic, refresh cases and audit trail.
- Source primaire
- FinCEN Ruling FIN-2026-R001; 2026 CDD Rule FAQs
U.S.-created entities and U.S. persons are exempt from CTA BOI reporting; qualifying foreign-formed entities registered in the U.S. remain potentially in scope.
- Action d’implémentation
- Classify formation and registration, document exemptions and keep CTA status separate from financial-institution CDD.
- Preuves à conserver
- Formation and registration records, CTA memo, exemption proof and CDD-to-CTA reconciliation.
- Source primaire
- 31 CFR 1010.380 as amended by 2025 interim final rule; FinCEN IFR Q&A
A qualifying foreign company registered on or after 26 March 2025 generally has 30 days from the earlier of actual or public registration notice to file initial BOI; U.S. persons are not reported.
- Action d’implémentation
- Calendar each deadline, collect only reportable BOI, file through FinCEN and monitor final-rule changes.
- Preuves à conserver
- Deadline calculation, filing and receipt, supporting records, update monitoring and rule watch.
- Source primaire
- FinCEN, BOI Interim Final Rule Questions and Answers
05Higher-risk customers, PEPs and enhanced due diligenceUse risk-based enhanced diligence. U.S. rules do not impose a single general domestic PEP-screening mandate, but specific foreign private-banking and correspondent-account rules can apply.4 éléments+
The CDD Rule does not create a unique general requirement to screen for or apply specific procedures to customers solely because they may be politically exposed persons.
- Action d’implémentation
- Treat PEP information as a risk factor within CDD rather than an automatic prohibition; document the risk rationale, source of wealth or funds work and approval proportionate to the case.
- Preuves à conserver
- PEP policy, risk factors, screening configuration, enhanced review, approvals and periodic quality testing.
- Source primaire
- Joint Statement on BSA Due Diligence Requirements for Customers Who May Be Considered PEPs, 2020
Covered U.S. financial institutions that maintain qualifying private-banking accounts for non-U.S. persons must perform enhanced scrutiny where a senior foreign political figure is involved.
- Action d’implémentation
- Detect private-banking accounts and beneficial interests in scope; establish source-of-funds, purpose, expected activity and corruption-proceeds controls before and during the relationship.
- Preuves à conserver
- Account classification, ownership analysis, source-of-wealth and funds evidence, senior approval, monitoring and reviews.
- Source primaire
- 31 CFR 1010.620
Correspondent accounts for specified foreign financial institutions require due diligence and, for higher-risk categories, enhanced due diligence under the conditions in the rule.
- Action d’implémentation
- Inventory foreign correspondent accounts, classify the foreign institution and jurisdiction, assess ownership and shell-bank exposure, and apply the required enhanced measures.
- Preuves à conserver
- Correspondent inventory, foreign-bank questionnaire, ownership and licence checks, risk assessment and monitoring results.
- Source primaire
- 31 CFR 1010.610; 31 CFR 1010.630
Customer information must be updated through risk-based ongoing monitoring when events reveal material changes or call existing information into question.
- Action d’implémentation
- Trigger review for ownership, control, product, geography, sanctions, adverse activity and unexplained behaviour changes; record why the profile remains reliable or was revised.
- Preuves à conserver
- Trigger catalogue, event logs, refreshed files, investigator rationale, approvals and overdue-review reporting.
- Source primaire
- FinCEN, CDD Final Rule; 2026 CDD Rule FAQs; FFIEC BSA/AML Manual, CDD
06Monitoring, suspicious activity and information sharingSAR thresholds and obligations depend on institution type. The bank rule below must be replaced with the applicable sector rule for MSBs, broker-dealers, casinos and other covered businesses.4 éléments+
A bank generally files a SAR for a transaction conducted or attempted by, at or through it involving at least $5,000 in aggregate when it knows, suspects or has reason to suspect one of the regulatory bases.
- Action d’implémentation
- Map scenarios to the exact bank or other sector SAR rule, aggregate related activity, investigate promptly and document both filing and non-filing decisions.
- Preuves à conserver
- Scenario inventory, alert and case data, aggregation tests, decision rationale, approvals and filed SAR receipt.
- Source primaire
- 31 CFR 1020.320(a); use applicable sector rule
A bank SAR is generally due within 30 calendar days after initial detection of facts that may constitute a basis for filing, extended to 60 days only when no suspect is identified; urgent ongoing threats require immediate contact with appropriate law enforcement in addition to filing.
- Action d’implémentation
- Start and evidence the regulatory clock at initial detection, distinguish research from impermissible delay, escalate deadline risk, and maintain an emergency contact procedure.
- Preuves à conserver
- Clock logic, case timestamps, deadline dashboard, escalation records, law-enforcement contact log and filing confirmation.
- Source primaire
- 31 CFR 1020.320(b)
SARs and information revealing their existence are confidential, with disclosure limited by the applicable regulation.
- Action d’implémentation
- Restrict SAR access, redact customer-facing material, train staff against tipping off, control subpoenas and external requests, and log permitted disclosures.
- Preuves à conserver
- Access-control list, training, disclosure procedure, audit logs, legal holds and tested response playbook.
- Source primaire
- 31 CFR 1020.320(e); applicable sector SAR rule
Section 314(a) requests and voluntary 314(b) information sharing operate under defined scope, confidentiality and procedural protections; 314(b) participation requires a current notice to FinCEN.
- Action d’implémentation
- Separate compulsory 314(a) search workflow from voluntary 314(b) sharing, validate counterparties and notices, secure transmissions and document use limitations.
- Preuves à conserver
- 314 procedures, current certification or notice, request log, search proof, response record and access controls.
- Source primaire
- 31 CFR 1010.520; 31 CFR 1010.540; FinCEN Section 314 resources
07Currency, funds transfers and cash reportingBuild separate decision paths for financial-institution CTRs, funds-transfer records and non-financial trade-or-business cash reports. They are not interchangeable with SARs.4 éléments+
A financial institution files a CTR for each deposit, withdrawal, exchange or other payment or transfer involving more than $10,000 in currency, aggregated for the same person during one business day when the institution has the required knowledge.
- Action d’implémentation
- Aggregate across branches, channels and accounts; identify conductors and beneficiaries; apply exemptions only when documented and current.
- Preuves à conserver
- Aggregation logic, CTR file and acknowledgement, identity record, exemption status, tests and exception report.
- Source primaire
- 31 CFR 1010.311; 31 CFR 1010.313; FinCEN CTR FAQs
A CTR is generally filed within 15 calendar days after the reportable transaction date.
- Action d’implémentation
- Calculate and monitor the deadline from transaction date, reconcile reportable activity to accepted filings and remediate rejects promptly.
- Preuves à conserver
- Filing calendar, transaction-to-filing reconciliation, BSA E-Filing acknowledgement and reject handling.
- Source primaire
- 31 CFR 1010.306(a)(1); FinCEN CTR FAQs
For transmittals of funds of $3,000 or more, covered roles must collect, retain and transmit specified information, subject to exclusions and the precise role-based requirements.
- Action d’implémentation
- Determine whether the business is an originator's, intermediary or beneficiary's institution; configure the required data, preservation and transmission for domestic and cross-border flows.
- Preuves à conserver
- Funds-flow map, message-field rules, transfer samples, exception logic, retention proof and quality tests.
- Source primaire
- 31 CFR 1010.410(e)-(f); FinCEN Funds Travel Regulations FAQs
A trade or business that receives more than $10,000 in cash in one or related transactions generally files Form 8300 within 15 days and provides the required annual written statement to each named person by 31 January.
- Action d’implémentation
- Detect cash and related transactions outside financial-institution CTR scope, file electronically when required, provide statements and retain records for five years.
- Preuves à conserver
- Form 8300 assessment, filing and receipt, aggregation workpaper, customer statement and retention log.
- Source primaire
- 26 U.S.C. 6050I; 31 U.S.C. 5331; IRS, Form 8300 guidance
08Sanctions and prohibited activityOFAC sanctions are separate from the BSA and can apply without a monetary threshold. Screening alone is insufficient without ownership, blocking, reporting and programme controls.4 éléments+
U.S. persons must comply with applicable OFAC sanctions, including U.S.-organised entities and their foreign branches; some programmes also extend to foreign subsidiaries or non-U.S. persons in specified circumstances.
- Action d’implémentation
- Map persons, entities, branches, products, currencies, locations and counterparties to each applicable sanctions programme and licence.
- Preuves à conserver
- Sanctions applicability map, programme inventory, licences, legal interpretations and geographic controls.
- Source primaire
- OFAC FAQ 11; applicable sanctions programme regulations
Property owned 50 percent or more in the aggregate, directly or indirectly, by one or more blocked persons is itself blocked even when the entity is not named on OFAC's list.
- Action d’implémentation
- Collect and calculate relevant ownership chains, aggregate blocked interests, assess control-related risk and escalate uncertainty before releasing property.
- Preuves à conserver
- Ownership chart, calculations, screening result, legal escalation, disposition decision and audit trail.
- Source primaire
- OFAC, Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked
Initial reports of blocked or rejected transactions are generally due to OFAC within 10 business days; holders of blocked property file an annual report by 30 September.
- Action d’implémentation
- Freeze or reject as the programme requires, preserve funds, notify OFAC through the current channel, reconcile blocked property and calendar annual reporting.
- Preuves à conserver
- Block or reject decision, account restriction, report and acknowledgement, blocked-property ledger and annual filing.
- Source primaire
- 31 CFR 501.603-604; OFAC Reporting FAQ
OFAC expects a risk-based sanctions compliance programme; its framework describes management commitment, risk assessment, internal controls, testing or auditing and training as essential components.
- Action d’implémentation
- Implement the five components, tune screening for names, ownership, geography, IP and transaction context, and independently test end-to-end effectiveness.
- Preuves à conserver
- Sanctions programme, risk assessment, screening configuration, alert decisions, test report, training and remediation.
- Source primaire
- OFAC, A Framework for OFAC Compliance Commitments
09Records, audit trail and regulator accessRetention periods often last five years, but different records use different start events. Preserve provenance and retrieval as well as the document itself.4 éléments+
Bank CIP identifying information is retained for five years after the account is closed or becomes dormant; descriptions of verification documents, methods, results and discrepancy resolution are retained for five years after the record is made.
- Action d’implémentation
- Configure separate retention clocks for identifying data and verification records and test closure, dormancy and record-creation events.
- Preuves à conserver
- Retention schedule, data map, clock logic, deletion holds, retrieval test and sampled records.
- Source primaire
- 31 CFR 1020.220(a)(3)
A bank retains each SAR and supporting documentation for five years from filing and provides supporting documentation to FinCEN or appropriate law enforcement on request.
- Action d’implémentation
- Bind supporting evidence to the filing, preserve confidentiality, control authorised requests and prove complete retrieval within the response procedure.
- Preuves à conserver
- SAR archive, supporting-document index, request log, access audit and retrieval test.
- Source primaire
- 31 CFR 1020.320(d)
Unless a more specific rule provides otherwise, records required under 31 CFR Chapter X are generally retained for five years and kept accessible as specified by the rule.
- Action d’implémentation
- Map every BSA record to its governing provision, trigger event, format, location, owner, legal hold and destruction approval.
- Preuves à conserver
- Regulatory retention schedule, data inventory, immutable logs, legal-hold procedure and destruction certificates.
- Source primaire
- 31 CFR 1010.430
MSBs must maintain the registration form and specified supporting and agent-list records for five years and make them available as required.
- Action d’implémentation
- Keep the registration package, owner or controlling-person records and agent list current, retrievable and linked to renewal and material changes.
- Preuves à conserver
- Registration archive, agent list, update log, renewal file and retrieval test.
- Source primaire
- 31 CFR 1022.380; FinCEN, MSB Registration
10Privacy, biometrics, security and breach responseThere is no single general U.S. privacy rule or regulator for every business. Determine sector, state, data type, residency and threshold before selecting notices, rights, security and breach deadlines.4 éléments+
FTC-jurisdiction financial institutions maintain a written security programme; specified events involving at least 500 consumers' unencrypted information require FTC notice no later than 30 days after discovery.
- Action d’implémentation
- Confirm scope, appoint a qualified individual, assess risk, implement the prescribed safeguards, oversee providers and apply the 500-consumer notice test.
- Preuves à conserver
- Scope memo, security programme, qualified-individual report, risk assessment, tests, vendor oversight and notice decision.
- Source primaire
- 16 CFR Part 314; FTC, Safeguards Rule guidance
Covered SEC institutions maintain incident-response policies and generally notify affected individuals as soon as practicable, no later than 30 days after awareness of unauthorised access or use, subject to the rule's investigation-based exception.
- Action d’implémentation
- Confirm scope, assess customer-information incidents, document any exception and oversee service-provider notice duties.
- Preuves à conserver
- Scope memo, response programme, investigation, notice, exception rationale and vendor contract.
- Source primaire
- SEC Regulation S-P amendments, Release No. 34-100155 (2024)
A banking organisation notifies its primary federal regulator no later than 36 hours after determining that a qualifying computer-security incident occurred.
- Action d’implémentation
- Define the incident test and decision authority, maintain regulator contacts and preserve each determination and notice timestamp.
- Preuves à conserver
- Incident taxonomy, decision log, regulator notice, acknowledgement, contacts and exercise results.
- Source primaire
- 12 CFR 53.3, 225.302 and 304.23; federal banking-agency notification rule
State privacy, biometric and breach laws apply independently; examples include California's CCPA and breach rules and Illinois BIPA's biometric-data controls.
- Action d’implémentation
- Map state scope by person, data and threshold; implement the required notices, consent, rights, retention, security and breach workflows.
- Preuves à conserver
- State matrix, notices, biometric consent, retention schedule, rights log, breach analysis and filings.
- Source primaire
- California Consumer Privacy Act and regulations; California Civ. Code 1798.82; Illinois 740 ILCS 14
11Product overlays and regulatory change controlApply product-specific overlays without importing vacated, postponed or proposed requirements into the current-law checklist.4 éléments+
A person engaged as a business in accepting and transmitting convertible virtual currency, or buying or selling it, may be a FinCEN money transmitter unless an exemption applies; a person using it solely to purchase goods or services is not an MSB on that basis.
- Action d’implémentation
- Document each custody, exchange, transmission, hosted-wallet, kiosk and payment flow against FinCEN's function-based CVC analysis and state virtual-currency rules.
- Preuves à conserver
- CVC flow diagrams, legal classification, MSB registration, state licences, exemptions and transaction-monitoring design.
- Source primaire
- FinCEN FIN-2013-G001; FinCEN CVC Business Models Guidance, 2019
Virtual-currency transactions are subject to the same OFAC compliance obligations as transactions involving traditional currency.
- Action d’implémentation
- Screen wallet and counterparty data, blockchain exposure, geolocation and ownership; apply blocking or rejection and reporting according to the relevant programme.
- Preuves à conserver
- Blockchain-risk policy, analytics configuration, address and party screening, case files, block or reject reports and testing.
- Source primaire
- OFAC FAQ 560; OFAC Sanctions Compliance Guidance for the Virtual Currency Industry
The federal Residential Real Estate Rule currently has no legal effect while the March 2026 vacatur order remains in force; reporting persons are not presently required to file Real Estate Reports and FinCEN's appeal is pending.
- Action d’implémentation
- Do not present Real Estate Reports as currently mandatory. Monitor the appeal and FinCEN guidance, preserve launch readiness and apply other existing BSA, sanctions or state duties that independently cover the activity.
- Preuves à conserver
- Court-status watch, FinCEN update log, applicability memo, dormant control plan and reactivation checklist.
- Source primaire
- FinCEN Residential Real Estate FAQs, issued 18 May 2026
Material legal, court, product, channel, vendor, model and geographic changes require reassessment before the affected control or customer flow is released.
- Action d’implémentation
- Operate a dated regulatory inventory and change process with accountable owners, source snapshots, impact assessment, implementation testing and approval.
- Preuves à conserver
- Regulatory inventory, change tickets, source archive, impact assessment, test results, approvals and next-review date.
- Source primaire
- 31 U.S.C. 5318(h); risk-based programme and supervisory expectations
Registre des sources primaires
39 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Bank Secrecy ActU.S. Government Publishing Office · Official statutory compilation
- 31 CFR Chapter X - Financial Crimes Enforcement NetworkElectronic Code of Federal Regulations · Primary regulation
- Customer Identification Program for banksElectronic Code of Federal Regulations · Primary regulation
- Customer Due Diligence requirements for legal entity customersElectronic Code of Federal Regulations · Primary regulation
- CDD Final Rule overview and 2026 exceptive reliefFinancial Crimes Enforcement Network · Official regulator guidance
- CDD Rule consolidated FAQs updated May 2026Financial Crimes Enforcement Network · Official regulator guidance
- Suspicious Activity Reports by banksElectronic Code of Federal Regulations · Primary regulation
- Records relating to funds transfers and transmittalsElectronic Code of Federal Regulations · Primary regulation
- General BSA record retention ruleElectronic Code of Federal Regulations · Primary regulation
- Due diligence for foreign correspondent accountsElectronic Code of Federal Regulations · Primary regulation
- Due diligence for private-banking accountsElectronic Code of Federal Regulations · Primary regulation
- Section 314(a) information requestsElectronic Code of Federal Regulations · Primary regulation
- Section 314(b) voluntary information sharingElectronic Code of Federal Regulations · Primary regulation
- Currency Transaction Report FAQsFinancial Crimes Enforcement Network · Official regulator guidance
- Funds Travel Regulations FAQsFinancial Crimes Enforcement Network · Official regulator guidance
- Money Services Business registrationFinancial Crimes Enforcement Network · Official regulator guidance
- Convertible virtual currency guidance FIN-2013-G001Financial Crimes Enforcement Network · Official regulator guidance
- Convertible virtual currency business models guidanceFinancial Crimes Enforcement Network · Official regulator guidance
- BOI interim final rule questions and answersFinancial Crimes Enforcement Network · Official regulator guidance
- Investment Adviser AML Rule effective date postponed to 2028Financial Crimes Enforcement Network · Official regulator publication
- Residential Real Estate Rule current status FAQsFinancial Crimes Enforcement Network · Official regulator guidance
- Joint PEP due-diligence statementFederal banking agencies, FinCEN and State Bank Regulators · Official interagency statement
- FFIEC BSA/AML Manual - Customer Due DiligenceFederal Financial Institutions Examination Council · Official examination guidance
- Form 8300 cash-reporting guidanceInternal Revenue Service · Official regulator guidance
- OFAC compliance frameworkOffice of Foreign Assets Control · Official regulator framework
- OFAC 50 Percent Rule guidanceOffice of Foreign Assets Control · Official regulator guidance
- OFAC FAQ 11 - persons required to complyOffice of Foreign Assets Control · Official regulator guidance
- OFAC reporting requirements FAQsOffice of Foreign Assets Control · Official regulator guidance
- OFAC virtual-currency FAQ 560Office of Foreign Assets Control · Official regulator guidance
- FTC Safeguards Rule guidanceFederal Trade Commission · Official regulator guidance
- SEC Regulation S-P amendmentsU.S. Securities and Exchange Commission · Official regulator publication
- Computer-security incident notification ruleFederal Deposit Insurance Corporation · Official interagency rule guidance
- California Consumer Privacy Act regulationsCalifornia Privacy Protection Agency · Primary and official state material
- California data-breach reporting guidanceCalifornia Department of Justice · Official state guidance
- Illinois Biometric Information Privacy ActSupreme Court of Illinois · Official judicial explanation of state legislation
- California money-transmitter laws and regulationsCalifornia Department of Financial Protection and Innovation · Official state material
- New York virtual-currency business licensingNew York State Department of Financial Services · Official state guidance
- FATF United States country pageFinancial Action Task Force · Official international assessment
- FATF black and grey listsFinancial Action Task Force · Official current-status source
Réponses directes
Questions KYC, KYB et AML pour États-Unis
Is there one AML checklist for every U.S. business?+
No. BSA programme, customer-identification and SAR rules vary by institution type, while licensing, privacy and some financial-services requirements vary by state. Start with an entity, activity, product and state-nexus analysis.
What is the bank SAR deadline?+
A bank generally files within 30 calendar days after initial detection of facts that may require a SAR, extended to 60 days only when no suspect is identified. Other institution types must use their own sector rule.
What is the U.S. currency-reporting threshold?+
A financial institution generally files a CTR for more than $10,000 in currency aggregated for the same person during one business day, normally within 15 days.
Does the CDD Rule still require beneficial ownership at every account opening?+
Not if the institution elects to use FinCEN's February 2026 relief. It may limit collection and verification to the first account, when prior information's reliability is questioned and as needed through risk-based ongoing CDD.
Must a U.S.-created company file BOI with FinCEN?+
Not under the current rule. U.S.-created entities and U.S. persons are exempt; qualifying foreign-formed entities registered to do business in a U.S. jurisdiction remain potentially in scope. This does not remove a financial institution's separate CDD duties.
Does FinCEN MSB registration authorise nationwide money transmission?+
No. Federal MSB registration and state licensing are separate. Each activity and state nexus needs a licensing or exemption analysis.
Are investment advisers subject to the new FinCEN AML rule in 2026?+
No. FinCEN postponed the rule's effective date to 1 January 2028. Other laws or statuses can still create separate obligations.
Are Real Estate Reports currently required?+
No. FinCEN states that the Residential Real Estate Rule has no legal effect while the March 2026 court order vacating it remains in force; the appeal is pending.
Is there one nationwide privacy and breach deadline?+
No. U.S. privacy and breach obligations are sectoral and state-specific. The applicable regulator, consumer state, data type and threshold must be mapped for each event.
Is the United States on a FATF public list?+
The United States was not named on FATF's current public-list page reviewed on 31 July 2026. It remains a FATF member with a published mutual evaluation and follow-up history.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice, a licence determination or a statement that every row applies to every U.S. business. It reflects primary and authoritative material reviewed on 31 July 2026. Confirm entity type, activity, customer, product, charter, federal functional regulator, state nexus, tribal or territorial issues, licensing exemptions, live BSA E-Filing instructions, sanctions programmes, privacy scope and later legal or court developments with qualified U.S. counsel and the competent authorities before launch.