Bank Secrecy Act
The Bank Secrecy Act (BSA) is a United States law, originally enacted in 1970, that requires banks and other financial institutions to keep certain records and file reports that help the government detect and prevent money laundering. It obligates these institutions to maintain records and report specific transactions, such as those involving currency, so that suspicious financial activity can be identified. It is commonly associated with broader anti-money laundering (AML) efforts.
The Bank Secrecy Act of 1970, also known as the Currency and Foreign Transactions Reporting Act, is a U.S. statute that establishes recordkeeping and reporting requirements for private individuals, banks, and other financial institutions. Its purpose is to require U.S. financial institutions to maintain appropriate records and file certain reports involving currency and related transactions to support the detection and prevention of money laundering and the financing of terrorism. In practice, the BSA is often referenced collectively with its implementing regulations and related AML obligations under the term BSA/AML; specific reporting and recordkeeping requirements, thresholds, and examination expectations are defined by the governing regulations and supervisory guidance and should be confirmed against current published sources.
Why it matters
The Bank Secrecy Act establishes the foundational U.S. framework for detecting and preventing money laundering by requiring banks and other financial institutions to maintain records and file reports involving currency and related transactions. For payment processors, acquirers, and merchant risk teams, the BSA is significant because financial crime detection depends on these institutions systematically capturing and reporting transaction information that helps the government identify suspicious financial activity. Without such recordkeeping and reporting obligations, illicit funds could move through the financial system with far less visibility.
The BSA is commonly referenced collectively with its implementing regulations and related anti-money laundering obligations under the term BSA/AML. This distinction matters: the statute itself sets the broad requirement, while the specific reporting thresholds, recordkeeping details, and examination expectations are defined by the governing regulations and supervisory guidance. Compliance officers should treat these implementing rules and guidance as the operative source of detailed obligations rather than assuming fixed requirements from the statute's plain text.
Because the exact thresholds, forms, and supervisory expectations under BSA/AML change over time and are set by governing regulations and examination guidance, teams responsible for compliance should confirm current requirements against published regulatory and supervisory sources rather than relying on general summaries. The BSA is a compliance and financial-crime framework and is separate from payment security standards such as PCI DSS; it addresses money laundering and terrorist financing detection rather than the protection of cardholder or sensitive authentication data.
Who it's relevant to
Inside BSA
Common questions
Answers to the questions practitioners most commonly ask about BSA.