Skip to main content
Category: Regulations and Standards

Bank Secrecy Act

Also known as: BSA, Currency and Foreign Transactions Reporting Act, BSA/AML
Simply put

The Bank Secrecy Act (BSA) is a United States law, originally enacted in 1970, that requires banks and other financial institutions to keep certain records and file reports that help the government detect and prevent money laundering. It obligates these institutions to maintain records and report specific transactions, such as those involving currency, so that suspicious financial activity can be identified. It is commonly associated with broader anti-money laundering (AML) efforts.

Formal definition

The Bank Secrecy Act of 1970, also known as the Currency and Foreign Transactions Reporting Act, is a U.S. statute that establishes recordkeeping and reporting requirements for private individuals, banks, and other financial institutions. Its purpose is to require U.S. financial institutions to maintain appropriate records and file certain reports involving currency and related transactions to support the detection and prevention of money laundering and the financing of terrorism. In practice, the BSA is often referenced collectively with its implementing regulations and related AML obligations under the term BSA/AML; specific reporting and recordkeeping requirements, thresholds, and examination expectations are defined by the governing regulations and supervisory guidance and should be confirmed against current published sources.

Why it matters

The Bank Secrecy Act establishes the foundational U.S. framework for detecting and preventing money laundering by requiring banks and other financial institutions to maintain records and file reports involving currency and related transactions. For payment processors, acquirers, and merchant risk teams, the BSA is significant because financial crime detection depends on these institutions systematically capturing and reporting transaction information that helps the government identify suspicious financial activity. Without such recordkeeping and reporting obligations, illicit funds could move through the financial system with far less visibility.

The BSA is commonly referenced collectively with its implementing regulations and related anti-money laundering obligations under the term BSA/AML. This distinction matters: the statute itself sets the broad requirement, while the specific reporting thresholds, recordkeeping details, and examination expectations are defined by the governing regulations and supervisory guidance. Compliance officers should treat these implementing rules and guidance as the operative source of detailed obligations rather than assuming fixed requirements from the statute's plain text.

Because the exact thresholds, forms, and supervisory expectations under BSA/AML change over time and are set by governing regulations and examination guidance, teams responsible for compliance should confirm current requirements against published regulatory and supervisory sources rather than relying on general summaries. The BSA is a compliance and financial-crime framework and is separate from payment security standards such as PCI DSS; it addresses money laundering and terrorist financing detection rather than the protection of cardholder or sensitive authentication data.

Who it's relevant to

Compliance Officers
Compliance officers at banks and other financial institutions are directly responsible for meeting BSA/AML recordkeeping and reporting obligations. Because the detailed thresholds and examination expectations are defined by implementing regulations and supervisory guidance, these professionals must track the current governing sources rather than rely on the statute's general language.
Fraud Analysts and Financial Crime Teams
Fraud and financial-crime analysts use the records and reports mandated under the BSA as part of detecting and investigating suspicious financial activity. The framework supports identification of potential money laundering, though it is a detection and reporting regime and does not on its own eliminate financial crime.
Acquirers, Payment Processors, and Merchant Risk Teams
Acquirers, processors, and merchant risk teams intersect with BSA/AML obligations to the extent they are financial institutions or partner with them. The BSA governs money laundering and terrorist financing detection and is distinct from payment security standards such as PCI DSS, which address the protection of cardholder and sensitive authentication data.

Inside BSA

Anti-Money Laundering (AML) Program Requirement
The BSA requires covered financial institutions to establish and maintain a written AML program, which typically includes internal controls, a designated compliance officer, ongoing employee training, and independent testing of the program. Payment processors and other entities may fall within scope depending on how they are classified under applicable regulation; institutions should confirm their obligations against current statutory and regulatory guidance.
Recordkeeping Obligations
The BSA imposes recordkeeping requirements intended to create a traceable record of certain financial transactions. These records are distinct from, and should not be confused with, cardholder data retention rules under PCI DSS; BSA recordkeeping is driven by financial-crime regulation rather than payment card security standards.
Reporting Requirements (SARs and CTRs)
The BSA framework is associated with the filing of reports such as Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) when defined conditions are met. Specific thresholds, forms, and filing timelines are set by the governing regulator and may change, so practitioners should verify current requirements rather than relying on fixed figures.
Customer Identification and Due Diligence
BSA-related obligations commonly include customer identification and due diligence measures intended to help institutions understand who their customers are and to support detection of illicit activity. These identity-focused controls address financial-crime risk and are separate from transaction-level authentication controls such as EMV chip authentication, 3-D Secure, or multi-factor authentication.
Regulatory Oversight and Enforcement
Compliance with the BSA is subject to regulatory oversight and enforcement, which can result in supervisory findings or penalties for deficient programs. The scope of oversight and the applicable enforcement authority depend on the institution type and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about BSA.

Is the Bank Secrecy Act a PCI DSS requirement or part of the PCI standards?
No. The Bank Secrecy Act is U.S. anti-money-laundering and financial-recordkeeping law administered through federal regulators and FinCEN; it is separate from PCI DSS and the other PCI standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. PCI DSS governs the protection of cardholder data and sensitive authentication data, not BSA reporting obligations. An organization may be subject to both, but compliance with one does not satisfy the other, and controls should be mapped to each framework independently.
Does the Bank Secrecy Act mainly require organizations to keep transactions secret?
No, despite the name. The BSA is oriented toward transparency to regulators rather than secrecy from them. It is intended to help detect and report activity that may indicate money laundering or other financial crime, through obligations such as recordkeeping and certain reporting to authorities. The 'secrecy' in the title reflects historical framing, not a mandate to conceal transactions. Specific obligations, thresholds, and reporting mechanics depend on the applicable regulation and the type of institution, and readers should confirm requirements against current published rules rather than the statute's name.
How does a payment organization determine whether it is subject to BSA obligations?
Applicability depends on how the entity is classified under the relevant regulations, for example as a financial institution or money services business, rather than on whether it handles card data. Because classification and the resulting obligations turn on legal definitions and business activities, organizations typically confirm their status with qualified legal or compliance counsel and against current FinCEN and regulator guidance. This assessment is separate from PCI DSS scoping, which is driven by where cardholder data and sensitive authentication data are stored, processed, or transmitted.
How do BSA recordkeeping obligations interact with PCI DSS data-retention controls?
The two can apply at the same time and should be reconciled carefully. PCI DSS is intended to limit retention of cardholder data to what is necessary and prohibits storing sensitive authentication data such as full track data, card verification values, and PIN blocks after authorization, even when encrypted. BSA may require retaining certain transaction records for defined periods. These obligations generally concern different data: BSA recordkeeping does not create an exception permitting storage of sensitive authentication data. Organizations typically design retention so required records are kept while prohibited authentication data is not stored, and validate that design against both frameworks.
Can tokenization or truncation help satisfy both BSA recordkeeping and PCI DSS scope reduction?
It can help, but the effect depends on implementation and validation rather than on the label. Tokenization, truncation, masking, and hashing transform or reduce data differently, and their impact on PCI DSS scope depends on how they are deployed and verified. For BSA purposes, retained records must still meet the applicable recordkeeping requirements, so any de-identification must preserve the information the regulation requires. Teams should confirm that a chosen method leaves adequate records for BSA obligations while reducing exposure of cardholder data, and validate PCI DSS scope impact accordingly.
How should fraud monitoring and BSA suspicious-activity processes be coordinated without conflating them?
They address related but distinct goals and are best kept as separate, coordinated workflows. Payment fraud monitoring targets card-present and card-not-present fraud, account takeover, first-party or chargeback fraud, and synthetic identity fraud, and any detection control involves false-positive and false-negative trade-offs. BSA suspicious-activity processes focus on potential money laundering and related financial crime under specific regulatory criteria. Shared data or tooling may support both, but the triggers, thresholds, and required outputs differ, and reporting obligations under BSA are defined by regulation. Organizations typically document each process separately and align them only where governance and legal review permit.

Common misconceptions

The BSA is a payment card security standard similar to PCI DSS.
The BSA is a financial-crime and anti-money-laundering framework, not a payment card security standard. It is separate from PCI DSS and from related payment standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. An organization can be subject to BSA obligations and PCI DSS obligations concurrently, but each addresses different objectives and is governed differently.
Meeting BSA recordkeeping and reporting requirements satisfies PCI DSS data storage and protection rules.
BSA recordkeeping serves financial-crime traceability and does not substitute for PCI DSS controls. In particular, sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks must not be stored after authorization even when encrypted, and cardholder data such as PAN may be stored only under defined PCI DSS controls. BSA obligations do not override these payment-data requirements.
A robust BSA/AML program eliminates fraud.
BSA/AML measures are intended to help detect and report suspicious or illicit activity and may mitigate certain financial-crime risks, but they do not eliminate fraud. They address different risks than transaction authentication and fraud-detection controls, and detection-based measures involve false-positive and false-negative trade-offs. No single control prevents fraud outright.

Best practices

Maintain a documented AML program that includes internal controls, a designated compliance officer, employee training, and independent testing, and periodically review it against current regulatory guidance rather than assumed requirements.
Confirm your institution's specific BSA classification and obligations with qualified regulatory or legal resources, since scope, thresholds, forms, and filing timelines are set by the governing regulator and may change.
Keep BSA recordkeeping and reporting processes distinct from PCI DSS data-handling controls, and ensure retention practices do not conflict with the prohibition on storing sensitive authentication data after authorization.
Verify current SAR and CTR conditions, thresholds, and timelines against published regulatory sources before filing, and avoid relying on outdated or assumed figures.
Coordinate BSA/AML functions with fraud-detection and payment-security teams so financial-crime controls and payment-data protections complement each other while remaining governed by their respective frameworks.
Treat detection outputs as one input among several, accounting for false-positive and false-negative trade-offs, and avoid presenting any single control as a guarantee against fraud or money laundering.