Skip to main content
Category: AML and KYC

Currency Transaction Report Threshold

Also known as: CTR Threshold, CTR reporting threshold, $10,000 currency reporting threshold, cash transaction reporting threshold
Simply put

The Currency Transaction Report threshold is the dollar amount above which a financial institution in the United States must file a report with the government about a cash transaction. Under federal law, that threshold is currency transactions of more than $10,000 conducted by, through, or to the institution. Customers are generally not told about the threshold unless they ask, and the reporting obligation is on the institution rather than the customer.

Formal definition

The CTR threshold is the regulatory trigger, set by U.S. Bank Secrecy Act regulations, requiring a financial institution to file a Currency Transaction Report for each deposit, withdrawal, exchange of currency, or other payment or transfer of currency (cash or coin) of more than $10,000 by, through, or to the institution (31 CFR 1010.311). The threshold applies not only to a single transaction but also to multiple related currency transactions that aggregate to more than $10,000 conducted by or on behalf of the same person during a single business day, which the institution must treat as a single transaction for reporting purposes. The $10,000 figure is the amount established under current regulation; note that proposed legislation could alter this threshold, so practitioners should confirm the applicable amount and aggregation rules against the current published regulation and FinCEN guidance. This threshold is distinct from payment-card security standards such as PCI DSS and is a matter of anti-money-laundering regulatory reporting, not cardholder data protection.

Why it matters

The Currency Transaction Report threshold is a foundational trigger in the U.S. anti-money-laundering regime. It defines the point at which a financial institution must document and report cash movement to the government, giving regulators and law enforcement visibility into large currency flows that could otherwise obscure the proceeds of criminal activity. Because the reporting obligation rests on the institution rather than the customer, and because customers are generally not told about the threshold unless they ask, the burden of accurate identification, aggregation, and filing falls squarely on the institution's compliance function.

A critical practical nuance is that the threshold is not limited to a single large transaction. It also applies to two or more related currency transactions that aggregate to more than $10,000 conducted by or on behalf of the same person during a single business day, which the institution must treat as a single reportable transaction. Failing to aggregate correctly is a common source of reporting gaps, and it also intersects with the separate risk of structuring, where a person deliberately breaks up cash to stay under the threshold. Institutions that get aggregation logic wrong may under-report and expose themselves to regulatory findings.

The threshold amount itself is a live policy question. The $10,000 figure is set under current Bank Secrecy Act regulation, but bipartisan legislation has been introduced that would raise the cash-transaction reporting threshold. Because the applicable amount and aggregation rules can change, compliance teams should confirm the current figure and rules against the published regulation and FinCEN guidance rather than assuming a fixed number. This is a matter of AML regulatory reporting and is distinct from payment-card security standards such as PCI DSS, which govern cardholder data protection rather than currency reporting.

Who it's relevant to

BSA/AML Compliance Officers
Responsible for ensuring the institution correctly identifies, aggregates, and files Currency Transaction Reports for currency transactions exceeding $10,000, including related transactions that aggregate to more than $10,000 by or on behalf of the same person in a single business day. They must monitor for any regulatory change to the threshold amount and update procedures against current FinCEN guidance.
Bank Operations and Teller Staff
Front-line staff who conduct and record cash deposits, withdrawals, and currency exchanges. They apply the identification and documentation procedures that support CTR filing and must recognize that the threshold applies to aggregated same-day activity, not only single large transactions, while generally not disclosing the threshold to customers unless asked.
Fraud and Financial Crime Analysts
Analysts who investigate patterns that may indicate structuring or attempts to evade currency reporting. Because customers are not told the threshold unless they ask, deliberate splitting of cash to stay just under $10,000 is a signal of potential concern, though such patterns require investigation and carry the usual detection trade-offs of false positives and false negatives.
Regulatory and Audit Teams
Internal and external auditors and examiners who assess whether the institution's currency reporting controls satisfy 31 CFR 1010.311, including correct application of the aggregation rule. They should verify procedures against the current published regulation, given that the applicable threshold could change under proposed legislation.

Inside CTR Threshold

Reporting Threshold Amount
The Currency Transaction Report (CTR) threshold is generally set at cash transactions exceeding $10,000. This is a regulatory reporting trigger under U.S. Bank Secrecy Act rules and is separate from PCI DSS or card brand requirements; it concerns physical currency handling rather than cardholder data protection.
Aggregation of Related Transactions
The threshold applies not only to a single cash transaction but also to two or more related cash transactions that aggregate to more than $10,000 conducted by or on behalf of the same person in a single business day. Institutions are expected to identify and combine such transactions rather than treating each in isolation.
Covered Cash Transactions
The threshold pertains to transactions in physical currency (cash in and cash out). It is distinct from card-based payment flows; card transactions, tokenized values, and account credits are not currency for CTR purposes unless they involve physical cash movement.
Reporting Obligation and Timeframe
When the threshold is met, a report must be filed with the appropriate regulatory authority within the timeframe defined by applicable regulation. Practitioners should confirm current filing deadlines, forms, and thresholds against the published regulation rather than assuming fixed values, since these can be revised.
Relationship to Suspicious Activity Reporting
Meeting or approaching the CTR threshold is a separate obligation from filing suspicious activity reports. Structuring transactions to stay below the threshold may itself be reportable as suspicious, but the CTR threshold and suspicious activity thresholds are governed by different rules.

Common questions

Answers to the questions practitioners most commonly ask about CTR Threshold.

Is a Currency Transaction Report a PCI DSS requirement or something payment security teams handle under PCI compliance?
No. The Currency Transaction Report is a cash-reporting obligation arising from anti-money-laundering regulation applicable to certain financial institutions, not a control defined by PCI DSS or any related PCI standard such as PA-DSS, PCI PIN, PCI P2PE, or PCI 3DS. PCI DSS governs the protection of cardholder data and sensitive authentication data; it does not establish currency reporting thresholds. Teams should treat CTR obligations and PCI DSS controls as separate compliance programs that may coexist but are governed by different authorities.
Does the reporting threshold only apply when a single transaction exceeds $10,000?
No. This is a common misconception. The threshold applies to currency transactions of more than $10,000, but it is not limited to one large transaction. Two or more related cash transactions that aggregate to more than $10,000 in a single business day can also trigger the reporting obligation. Structuring activity to keep individual transactions below the threshold does not remove the obligation and may itself raise concerns under applicable law. Confirm the precise aggregation and business-day rules against the current governing regulation.
How should transactions be aggregated to determine whether the threshold is met?
Aggregation generally considers related cash transactions conducted in a single business day, combined to determine whether the total exceeds $10,000. Implementation depends on how your institution defines relatedness (for example, transactions by or on behalf of the same person) and its business-day boundaries. Because these determinations affect whether a report is required, they should be documented in policy and validated against the current governing regulation and applicable guidance rather than assumed.
What information typically needs to be captured to support a currency transaction report?
Reporting typically requires identifying information about the person conducting the transaction and, where applicable, the person on whose behalf it is conducted, along with details of the currency amounts and the accounts or transactions involved. Because exact data elements and formats are set by the governing regulation and reporting forms, teams should map their data capture to the current published requirements and avoid relying on outdated field lists.
How does the threshold interact with detecting and reporting suspicious activity?
The currency transaction reporting threshold is a dollar-value trigger and is distinct from suspicious activity reporting, which is based on the nature of the activity rather than a fixed amount. A transaction below the threshold may still warrant a suspicious activity assessment, and a reportable currency transaction may also independently warrant such review. Implementations should treat threshold-based reporting and suspicious activity detection as complementary processes with different criteria, and confirm both against the current governing regulation.
What controls help ensure the threshold is applied consistently across systems and staff?
Consistent application is typically supported by documented policies defining relatedness and business-day boundaries, automated aggregation logic where feasible, staff training, and periodic review of flagged and reported transactions. Automated detection can help reduce missed reportable events but may produce false positives or false negatives depending on how relatedness and aggregation are configured, so human review and reconciliation against the current governing regulation remain important.

Common misconceptions

The CTR threshold only applies to a single cash transaction above $10,000, so multiple smaller cash transactions never trigger reporting.
The threshold also applies to two or more related cash transactions that aggregate to more than $10,000 by or on behalf of the same person in a single business day. Institutions are expected to aggregate related transactions, and deliberate splitting to avoid reporting can raise separate compliance concerns.
Currency Transaction Report thresholds are part of PCI DSS compliance.
CTR thresholds arise from anti-money-laundering and Bank Secrecy Act regulation, not from PCI DSS, PA-DSS, the PCI Software Security Framework, or any card brand rule. They address physical currency reporting, which is a different domain from cardholder data protection.
The $10,000 figure is fixed and never changes.
Thresholds, filing timeframes, and reporting forms are defined by regulation and can be revised. Practitioners should verify current requirements against the published regulation rather than relying on an assumed fixed value.

Best practices

Implement controls that aggregate related cash transactions by or on behalf of the same person within a single business day, so that combined amounts exceeding $10,000 are identified rather than assessed transaction by transaction.
Confirm the current threshold amount, filing deadlines, and required forms against the published regulation rather than assuming fixed values, since these can be revised over time.
Keep CTR reporting processes distinct from PCI DSS and card brand compliance workflows, recognizing that currency reporting addresses a different regulatory domain than cardholder data protection.
Establish procedures to flag potential structuring, where transactions appear split to stay below the threshold, and route such patterns for separate review since they may carry additional reporting obligations.
Document how transaction aggregation logic is applied and validated, so reviewers can confirm that same-day, same-person cash activity is being combined correctly.
Train staff who handle physical currency on both single-transaction and aggregate reporting triggers, and provide qualified guidance rather than implying any single control fully eliminates reporting risk.