You've built a robust transaction monitoring system. Your team generates alerts. Your analysts investigate. Then a relationship manager walks the client's transactions past your desk with a note: "This account generates $2 million in annual revenue."
That's where the system breaks down.
The Epstein case isn't just about one set of accounts. It's about a structural conflict that exists in every bank: compliance teams operate as cost centers while business lines drive profit. When those incentives collide over a high-net-worth client, compliance often loses.
What This Checklist Covers
This checklist addresses the governance, escalation, and documentation controls you need when profit pressure threatens to override your SAR filing obligations under the Bank Secrecy Act. It's designed for AML/KYC teams managing accounts where relationship managers have financial incentives to maintain the business relationship despite red flags.
Use this when you're facing internal resistance to filing, when business-side employees are contesting your risk assessments, or when you need to document that compliance decisions were made independently of revenue considerations.
Prerequisites
Before using this checklist:
- Your bank has automated transaction monitoring systems generating alerts per Bank Secrecy Act requirements.
- You have documented customer due diligence procedures for account opening and ongoing monitoring.
- Your SAR filing process includes defined timelines: 30 days from detection for transactions over $5,000 with no apparent business purpose, or 60 days if additional investigation is needed.
- You have access to account profiling data: expected transaction types, volumes, and counterparties established during onboarding.
Checklist Items
1. Alert review is conducted by compliance personnel with no revenue targets tied to the account.
Your transaction monitoring system flags the activity. The first review must happen outside the business line. If a relationship manager is involved in the initial assessment of whether an alert is suspicious, you've already compromised independence.
Good looks like: A compliance analyst with no P&L responsibility reviews the alert, documents the review in your case management system, and makes the initial escalation decision based solely on BSA red flags.
2. High-net-worth accounts have documented expected activity profiles that include specific transaction types and counterparty categories.
Banks are required to conduct customer due diligence under the Bank Secrecy Act. For accounts generating significant revenue, that profile needs to be detailed enough to identify deviations. "Wealth management activities" isn't sufficient.
Good looks like: Your CDD file states "monthly wire transfers to investment managers in New York and London, quarterly distributions to family trusts, annual tax payments to IRS" with documented sources of wealth and anticipated transaction volumes.
3. When an alert involves an account designated high-risk (PEP, prior legal issues, reputational concerns), escalation to senior compliance occurs within 48 hours.
The Epstein accounts were flagged as high-risk as early as 2008 due to trafficking connections. That designation should trigger enhanced scrutiny and faster escalation timelines.
Good looks like: Your procedures specify that high-risk account alerts bypass initial triage and route directly to a SAR committee or designated senior compliance officer within two business days of generation.
4. Business line input on alerts is documented separately from compliance analysis.
Relationship managers have context about clients. That context can be valuable. But it can't be the deciding factor in whether you file.
Good looks like: Your case file includes a section for "Business Line Comments" that's clearly separated from "Compliance Analysis." The compliance section drives the SAR decision; the business section provides context only.
5. SAR filing decisions are made by compliance personnel who do not report to business line management.
If your compliance team's budget, headcount, or performance reviews are controlled by revenue-generating divisions, you don't have independence.
Good looks like: Your AML/KYC function reports directly to the Chief Risk Officer or Chief Compliance Officer, with a dotted line to the board's audit or risk committee. Compensation and promotion decisions are made outside the business line.
6. Retroactive SAR filings (more than 60 days after detection) trigger root cause analysis and documentation of the delay.
Banks filed 469 SARs on Epstein accounts in August 2019, then 4,725 more the following month. That pattern indicates systemic failure. When you file late, you need to document why.
Good looks like: Every SAR filed outside the 30-60 day window includes a documented explanation: staffing shortage, complex investigation requiring extended analysis, system failure that delayed alert generation. Generic "oversight" isn't acceptable.
7. Large round-dollar wire transfers to individuals with no documented business relationship are flagged and investigated within 5 business days.
The FFIEC exam procedures specifically identify large incoming or outgoing funds transfers with no logical business purpose as red flags. Your monitoring system should catch these automatically.
Good looks like: A $7.4 million wire to an individual triggers an immediate alert. Your analyst reviews the account profile, identifies no business relationship or documented purpose, and escalates to SAR review within one week.
8. Accounts with repetitive payments to multiple individuals in the same demographic category (age, location, occupation) are reviewed for potential structuring or illicit activity.
Repeated payments to young men or women, payments to individuals in high-risk jurisdictions, or payments that follow unusual patterns all appear in the FFIEC's red flag list.
Good looks like: Your monitoring rules include velocity checks (number of unique payees per month), demographic pattern analysis where data is available, and geographic concentration reviews. Alerts trigger when patterns deviate from the account's expected profile.
9. When compliance recommends account closure or SAR filing and business line objects, the objection and resolution are documented with sign-off from senior management.
This is where the conflict becomes visible. If a relationship manager pushes back, that pushback needs to be on the record.
Good looks like: Your escalation log shows the compliance recommendation, the business line objection, and the final decision with signatures from both sides and a managing director or C-level officer. If compliance is overruled, that decision is documented and reported to the board risk committee.
10. Accounts involving payments to or from financial secrecy havens or high-risk jurisdictions are subject to enhanced due diligence regardless of account size.
The FFIEC specifically flags funds transfer activity to or from countries known as financial secrecy havens. Your monitoring can't exempt high-value accounts from geographic risk screening.
Good looks like: Your transaction monitoring system applies the same geographic risk rules to all accounts. A $50 million account sending wires to shell companies in the Cayman Islands gets the same scrutiny as a $50,000 account doing the same thing.
Common Mistakes
Filing thousands of SARs retroactively after a client becomes publicly problematic. JPMorganChase filed 4,725 SARs in one month covering prior activity. That's not compliance; it's damage control. If your monitoring systems were working, you'd have filed those SARs when the transactions occurred.
Accepting "privacy concerns" or "client sensitivity" as reasons to delay investigation. High-net-worth clients often object to due diligence questions. That discomfort doesn't override your BSA obligations. If a client won't explain the purpose of a $156 million payment, that's a red flag, not a reason to stop asking.
Treating relationship manager attestations as sufficient due diligence. "The client says this is for consulting services" isn't documentation. You need invoices, contracts, or other evidence that the payment has a legitimate business purpose.
Allowing business line personnel to control the SAR filing timeline. "Let's wait until after quarter-end" or "Can we hold off until the client closes this deal" are requests to violate the Bank Secrecy Act's 30-60 day filing requirement.
Next Steps
If you're facing pressure from business lines to overlook suspicious activity:
Document the pressure. Email trails, meeting notes, and escalation logs create a record that compliance made the right call even if business lines objected.
Escalate to your board risk committee. If senior management is siding with revenue over compliance, your board needs to know. Sen. Ron Wyden's proposed legislation would require signed attestations by individual bankers for ultra-high-net-worth accounts, modeled on Sarbanes-Oxley. That's where this is heading.
Review your monitoring system's exemptions. If high-value accounts have different alert thresholds or longer review timelines, you've built the conflict into your technology.
The Bank Secrecy Act doesn't include a revenue exception. Your monitoring system shouldn't either.



