Skip to main content
Category: Regulations and Standards

FFIEC BSA/AML Examination Manual

Also known as: FFIEC Bank Secrecy Act/Anti-Money Laundering Examination Manual, BSA/AML Examination Manual
Simply put

The FFIEC BSA/AML Examination Manual is a guidance document that tells bank examiners how to check whether financial institutions are following anti-money laundering and Bank Secrecy Act rules. It explains how examinations should be planned and carried out, including a risk-focused approach to reviewing an institution's controls. It is published by the Federal Financial Institutions Examination Council and is available to view and download online.

Formal definition

The FFIEC Bank Secrecy Act (BSA)/Anti-Money Laundering (AML) Examination Manual is guidance issued by the Federal Financial Institutions Examination Council to examiners for conducting BSA/AML and OFAC examinations of financial institutions. It sets out scoping and planning guidance, promotes risk-focused supervision, and includes structured examination procedures covering areas such as BSA/AML training. Practitioners use it as the reference framework against which supervised institutions' anti-money laundering programs are assessed; readers should confirm current content, structure, and effective dates against the published manual, as it is periodically updated.

Why it matters

Anti-money laundering supervision in the United States depends on consistency: examiners across multiple federal agencies need a shared reference for how to assess a financial institution's BSA/AML and OFAC compliance. The FFIEC BSA/AML Examination Manual serves as that shared reference, setting out how examinations should be scoped, planned, and conducted using a risk-focused approach. For institutions, the manual effectively signals what examiners will look for, making it a practical benchmark against which anti-money laundering programs are measured.

Because the manual is published openly and available to view and download online, compliance officers and program managers can align their internal controls, documentation, and training with the same examination procedures that supervisors use. This transparency helps reduce gaps between what an institution believes is adequate and what an examiner is guided to evaluate, though it does not guarantee a favorable examination outcome, since findings depend on the specific facts, the institution's risk profile, and examiner judgment.

The manual is periodically updated, so its structure, content, and effective dates change over time. Relying on an outdated version can leave an institution misaligned with current examination expectations. Practitioners should confirm the current manual and its examination procedures against the published source rather than assuming any particular section or requirement remains fixed.

Who it's relevant to

BSA/AML Compliance Officers
Compliance officers use the manual as a benchmark for designing and maintaining their institution's anti-money laundering program, aligning internal controls, documentation, and training with the examination procedures examiners are guided to follow. They should confirm they are working from the current published version.
Bank Examiners and Supervisory Staff
Examiners across the FFIEC member agencies use the manual as their primary guidance for scoping, planning, and conducting BSA/AML and OFAC examinations, applying a risk-focused approach to evaluate an institution's controls.
Financial Institution Risk and Audit Teams
Internal audit and risk functions reference the manual's examination procedures to perform self-assessments and identify gaps ahead of a supervisory examination, though alignment with the manual supports readiness rather than guaranteeing examination results.
Payment Processors and Merchant Risk Teams with Banking Relationships
Organizations that interact with supervised financial institutions may find the manual useful for understanding the BSA/AML and OFAC expectations their banking partners are examined against, informing how they structure their own due diligence and monitoring. Note that PCI DSS and card brand rules govern payment security separately from BSA/AML supervision.

Inside FFIEC BSA/AML Examination Manual

Regulatory Framework Overview
Guidance issued by the Federal Financial Institutions Examination Council to help examiners assess a financial institution's compliance with the Bank Secrecy Act and anti-money laundering obligations. Note that this manual addresses BSA/AML supervision, which is a separate discipline from the payment security and PCI DSS standards, and is not itself a PCI standard.
Risk-Based Examination Approach
Describes how examiners are expected to evaluate an institution's risk assessment, controls, and program adequacy based on its specific products, services, customers, and geographies rather than a one-size-fits-all checklist.
Program Pillars
Covers the core expectations of a BSA/AML compliance program, generally including internal controls, independent testing, a designated compliance officer, training, and customer due diligence expectations. Confirm the exact structure and terminology against the current published manual, as content is updated over time.
Customer Due Diligence and Beneficial Ownership
Addresses expectations for understanding customer relationships and identifying beneficial owners of legal entity customers, intended to help institutions detect and report suspicious activity.
Suspicious Activity and Currency Transaction Reporting
Covers regulatory reporting obligations, such as filing suspicious activity reports and currency transaction reports, and examiner review of the processes supporting those filings.
Sanctions and OFAC Considerations
Notes that examiners may review controls related to economic sanctions screening. Sanctions administration is governed by the Office of Foreign Assets Control, which is a distinct authority from the BSA/AML reporting regime, though the manual addresses examination of related controls.

Common questions

Answers to the questions practitioners most commonly ask about FFIEC BSA/AML Examination Manual.

Is the FFIEC BSA/AML Examination Manual a PCI DSS requirement or something that governs payment card security?
No. The FFIEC BSA/AML Examination Manual is guidance used by U.S. federal banking agency examiners to assess compliance with the Bank Secrecy Act and anti-money-laundering obligations. It is distinct from PCI DSS, which addresses the protection of cardholder data and sensitive authentication data. The two serve different purposes, are issued by different bodies, and one does not satisfy or substitute for the other. Confirm applicability of each against its own published source.
Does following the FFIEC BSA/AML Examination Manual mean an institution has met its anti-money-laundering legal obligations?
Not necessarily. The manual is examination guidance that describes how examiners evaluate a program; it is not itself the law and is not a checklist that guarantees compliance. The underlying legal obligations arise from the Bank Secrecy Act and related regulations. An institution should treat the manual as a reference for examiner expectations while confirming its obligations against the current statutes, regulations, and any applicable guidance, which can change over time.
How should a compliance officer use the manual when preparing for an examination?
It can be used as a reference to understand the areas and procedures examiners may cover, helping teams organize documentation and self-assessments accordingly. Because the manual is periodically updated, verify you are working from the current version and cross-reference against the applicable regulations rather than relying solely on the manual's wording.
Who within an organization typically references this manual?
It is generally referenced by BSA/AML compliance officers, internal audit, and risk teams at institutions subject to Bank Secrecy Act obligations. Payment security and PCI DSS teams may need awareness of it where responsibilities overlap, but they should keep BSA/AML scope separate from cardholder data protection scope, which is governed by different standards.
How does the manual relate to other controls a payment processor already maintains for card data?
The manual addresses BSA/AML program areas rather than the technical controls that protect cardholder data or sensitive authentication data. An organization may need both: BSA/AML controls informed by this manual and payment data protection controls validated against the applicable PCI standard. Mapping between the two should be done carefully so that satisfying one is not assumed to satisfy the other.
How can a team stay current with changes to the manual?
Because the manual is updated over time and section content and organization can change between editions, teams should monitor the official issuing source for the current version and confirm any cited section or procedure against that published edition rather than relying on a prior copy or a fixed reference.

Common misconceptions

The FFIEC BSA/AML Examination Manual is part of or interchangeable with PCI DSS or other PCI standards.
The manual governs anti-money laundering and Bank Secrecy Act supervision and is unrelated to PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS. Controls such as PAN protection, tokenization, and sensitive authentication data handling are addressed by PCI standards, not by this manual.
Following the manual guarantees an institution will pass examination or prevent all money laundering.
The manual is intended to guide examiners and inform institutions, but it does not guarantee outcomes. A risk-based program helps reduce and may mitigate exposure, and detection controls carry inherent false-positive and false-negative trade-offs rather than eliminating risk.
The manual is a fixed rulebook with static requirements and citations.
The manual is periodically updated, and section content, terminology, and referenced regulations change over time. Practitioners should confirm specific expectations against the current published version rather than assuming fixed wording or structure.

Best practices

Confirm current expectations against the latest published version of the FFIEC BSA/AML Examination Manual rather than relying on remembered or outdated sections, since content is updated periodically.
Ground your compliance program in a documented, institution-specific risk assessment that reflects your actual products, services, customers, and geographies.
Keep BSA/AML supervision distinct from payment security compliance; where PCI DSS or related standards apply, address cardholder data protection and sensitive authentication data handling under those standards separately.
Maintain the core program elements the manual emphasizes, including internal controls, independent testing, a designated compliance officer, training, and appropriate customer due diligence.
Tune suspicious activity monitoring with attention to false-positive and false-negative trade-offs, and document the rationale for thresholds and dispositions rather than treating any single control as sufficient.
Verify sanctions screening controls against current OFAC requirements, recognizing that sanctions administration is a separate authority from BSA/AML reporting obligations.