Bank Secrecy Act reporting thresholds for 2026: the CTR and SAR dollar triggers, filing deadlines, the five pillars, who must comply, and BSA penalties.
Table of contents
- The Bank Secrecy Act is the cornerstone United States anti-money laundering law, enacted in 1970 and administered by the Financial Crimes Enforcement Network (FinCEN), a bureau of the Treasury.
- The two core BSA reporting thresholds are the Currency Transaction Report for cash over 10,000 dollars in a business day, and the Suspicious Activity Report at 5,000 dollars for banks and 2,000 dollars for money services businesses.
- Compliance rests on five pillars: a designated officer, internal controls, independent testing, training, and customer due diligence added by the 2016 CDD Rule.
- Willful BSA violations carry up to 250,000 dollars and five years in prison, rising to 500,000 dollars and ten years for aggravated cases. Binance paid a 3.4 billion dollar FinCEN penalty in 2023.
- The 10,000 dollar threshold has not moved since 1972. The October 2025 STREAMLINE Act would raise it to 30,000 dollars, but it is not yet law.
- BSA recordkeeping forces firms to retain identity data for five years, which is why the storage architecture, not the verification itself, is the real breach risk.
The Bank Secrecy Act is the foundational United States anti-money laundering statute, enacted in 1970, that requires financial institutions to keep records and file reports on cash and suspicious transactions. Administered by FinCEN, it underpins every US AML programme. Its name misleads: it compels disclosure to the government, not customer secrecy.
TL;DR
The Bank Secrecy Act, enacted in 1970, is the main United States law against money laundering. It makes banks, money services businesses and, since FinCEN guidance, crypto firms keep records and file reports so the government can trace illicit money. The two reporting thresholds you must know are the Currency Transaction Report for cash over 10,000 dollars in a day, filed within fifteen days, and the Suspicious Activity Report at 5,000 dollars for banks and 2,000 dollars for money services businesses, filed within thirty days. Compliance runs on five pillars and on collecting and retaining customer identity for five years. That retention duty, not the verification, is where the breach risk hides.
What is the Bank Secrecy Act?
The Bank Secrecy Act, or BSA, is the foundational anti-money laundering statute in the United States. Its full legal name is the Currency and Foreign Transactions Reporting Act of 1970, and it is codified at 31 U.S.C. 5311 et seq., with implementing regulations at 31 CFR Chapter X. It is administered by the Financial Crimes Enforcement Network (FinCEN), a bureau of the United States Department of the Treasury, which writes the rules, collects the filings and brings civil enforcement. Almost every later US money laundering measure builds on this single 1970 framework.
The name is the most misunderstood thing about the law. The BSA does not protect bank customer secrecy. The statute at 31 U.S.C. 5311 states its purpose plainly: to require records and reports that have "a high degree of usefulness in criminal, tax, or regulatory investigations" and in protecting against terrorism. In other words, the BSA is a recordkeeping-and-reporting regime that obligates institutions to disclose information to the government, not a confidentiality shield. Our Bank Secrecy Act glossary entry gives the short definition for quick reference; this guide is the deep version.
Why does the BSA exist, and how has it changed?
The 1970 statute was thin on its own. The framework that compliance teams run today is the product of five decades of amendments. The Money Laundering Control Act of 1986 made money laundering a federal crime in its own right. The Annunzio-Wylie Anti-Money Laundering Act of 1992 introduced the Suspicious Activity Report. The USA PATRIOT Act of 2001, in its Title III, mandated the Customer Identification Program under Section 326 and pulled far more businesses into scope. Each layer widened what the BSA covers and who has to file.
The modern chapter is the Anti-Money Laundering Act of 2020, which, despite its name, became law on 1 January 2021 as part of the National Defense Authorization Act for fiscal year 2021. It contains the Corporate Transparency Act, which created the FinCEN beneficial ownership registry for entities with 25 percent ownership or substantial control. The debate has now turned to modernisation. In October 2025 FinCEN issued new SAR guidance to cut low-value filings under a "less noise, more signal" banner, and senators introduced the STREAMLINE Act to lift the reporting thresholds for the first time in over fifty years.
What does the BSA require under the five pillars?
A compliance programme under the statute is built on what practitioners call the five pillars. The first four are the original programme requirements: a designated BSA compliance officer with real authority; a system of internal controls and written policies that match the institution's risk; independent testing or audit of the programme; and ongoing training for relevant staff. These four have anchored BSA examinations for decades and are what an examiner checks first.
The fifth pillar is customer due diligence, or CDD. FinCEN's Final CDD Rule, issued on 11 May 2016 with a compliance date of 11 May 2018, formalised CDD as a programme requirement and added beneficial ownership: covered institutions must identify and verify the natural persons who own 25 percent or more of, or exercise significant control over, a legal-entity customer. The fifth pillar is where identity verification, the KYC layer, enters the BSA. It is also where the recordkeeping burden becomes a data question, because verifying people means collecting and holding their personal information.
What are the BSA reporting thresholds for CTRs and SARs?
These reporting thresholds are the heart of day-to-day compliance, and getting the dollar figures and deadlines exactly right matters. There are two filings every team must know, the Currency Transaction Report and the Suspicious Activity Report, plus several supporting reports. The table below sets out the bank secrecy act reporting thresholds that trigger each one, the deadline, the form and where it is filed.
| Report | What triggers it | Dollar threshold | Filing deadline | Form | Where filed | Retention |
|---|---|---|---|---|---|---|
| Currency Transaction Report (CTR) | Cash-in or cash-out currency, aggregated per customer in one business day | More than 10,000 dollars | 15 calendar days | FinCEN CTR | FinCEN (e-file) | 5 years |
| Bank SAR | Known or suspected illicit activity at a bank | 5,000 dollars or more | 30 days from detection, up to 60 if no suspect | FinCEN SAR (Form 111) | FinCEN (e-file) | 5 years |
| MSB SAR | Activity by, at or through a money services business or its agent | 2,000 dollars or more | 30 days from detection | FinCEN SAR (Form 111) | FinCEN (e-file) | 5 years |
| MSB SAR (issuer review) | Money-order or traveller's-cheque issuer review of clearance records | 5,000 dollars or more | 30 days from detection | FinCEN SAR (Form 111) | FinCEN (e-file) | 5 years |
| Form 8300 | Cash received in a trade or business | More than 10,000 dollars | 15 calendar days | IRS/FinCEN Form 8300 | IRS (e-file) | 5 years |
| CMIR (FinCEN 105) | Physical transport of currency across the US border | More than 10,000 dollars | At time of transport | FinCEN Form 105 | CBP | 5 years |
The CTR is mechanical: file for more than 10,000 dollars in cash moving in or out, aggregated across a single customer's transactions in one business day, within fifteen calendar days. That 10,000 dollar figure has not changed since 1972. The bank SAR is judgement-based: file within thirty days when a transaction of 5,000 dollars or more involves activity you know, suspect or have reason to suspect is illicit. For a money services business, the SAR threshold drops to 2,000 dollars for activity at or through the business, with a separate 5,000 dollar trigger for issuers reviewing clearance records.

Download: the BSA reporting thresholds one-pager (PDF) is a print-ready version of this threshold matrix you can keep beside your filing rules and share with compliance and operations teams.
One proposed change is worth tracking. The STREAMLINE Act, introduced in October 2025 by Senate Banking Chair Tim Scott and Senator John Kennedy, would raise the CTR threshold from 10,000 to 30,000 dollars, lift the money services business SAR trigger from 2,000 to 3,000 dollars and the bank SAR trigger from 5,000 to 10,000 dollars, and index the CTR for inflation every five years. As of June 2026 it is a proposal, not law, so the figures in the table above remain the ones you file against.
Who must comply with the Bank Secrecy Act?
The BSA reaches far beyond high-street banks. The statute defines "financial institution" broadly, and the list of covered businesses includes banks and credit unions, broker-dealers in securities, mutual funds, casinos and card clubs, certain insurers, and money services businesses such as money transmitters and currency exchangers. Each category has a primary supervisor: the Office of the Comptroller of the Currency, the Federal Reserve, the Federal Deposit Insurance Corporation and the National Credit Union Administration examine depository institutions, the Securities and Exchange Commission and FINRA cover broker-dealers, and the Internal Revenue Service examines most money services businesses.
Crypto firms are squarely in scope, which is the point most often missed. FinCEN's March 2013 guidance classified administrators and exchangers of convertible virtual currency as money transmitters, and therefore money services businesses, and its May 2019 guidance reaffirmed and expanded that position. A virtual-asset exchange has the same BSA obligations as a money transmitter: register, run a programme and file the reports. Our guide to KYC for crypto exchanges and the money services businesses glossary entry cover what that means for onboarding.
What is the difference between the BSA and AML?
People use BSA and AML interchangeably, but they are not the same thing. The Bank Secrecy Act is a specific United States statute and the body of regulation that sits under it. Anti-money laundering, or AML, is the broader global discipline: the programmes, controls and risk assessments that institutions everywhere run to detect and deter laundering and terrorist financing. The BSA is the legal foundation of any US AML programme, but AML as a field is larger than any one law and applies across jurisdictions that have their own statutes.
A useful way to hold it is that the BSA tells a US institution what it must do, while AML describes how the whole industry thinks about the problem. Counter-financing of terrorism, or CFT, sits alongside AML as the parallel goal of cutting off funding for terrorism, and the BSA explicitly names both in its purpose. For a wider view of how monitoring controls work in practice, see our guide to AML transaction monitoring.
How do KYC, CIP and CDD fit into BSA compliance?
Know your customer, the practice of verifying who you are dealing with, is not a single BSA rule but the result of several. The Customer Identification Program, mandated by the PATRIOT Act, requires you to collect and verify a customer's name, date of birth, address and an identification number before or shortly after opening an account. Customer due diligence, the fifth pillar, layers on understanding the nature of the relationship and, for legal entities, verifying the beneficial owners. Together, CIP and CDD are how an institution satisfies the identity side of the BSA.
The practical consequence is that BSA compliance forces you to gather a large, sensitive data set: names, dates of birth, addresses, government identifiers and often images of identity documents, for every customer, retained for five years. Building the verification flow is well understood. The harder question, the one this framework forces and the next section takes up, is where all that verified identity data lives once you have collected it. Our decentralised KYC explainer and the KYC software page show how the checks can run without warehousing the data centrally.
Why is centralised PII the hidden risk in BSA recordkeeping?
Here is the frame most BSA explainers skip. The BSA tells you to verify customers and retain proof of that verification for five years. It never tells you to build a central honeypot of customer personal data. Yet the default architecture every legacy KYC vendor sells does exactly that: it pools names, dates of birth, addresses and government-ID images into one database. The five-year retention duty then keeps that store standing as a target for years. The verification logic is rarely the failure point. The storage model is.
The evidence is named and recent. In October 2025 Discord disclosed a breach through a third-party support vendor, 5CA, that exposed roughly 70,000 government-ID photos along with names, emails and IP addresses. Separately, in February 2026 Fortune reported that around 2,500 front-end files tied to Discord age verification, attributed to the vendor Persona, were found exposed on a cloud endpoint, a characterisation Persona disputes as non-sensitive code. In November 2025 the identity-verification provider IDMerit was reported to have left roughly one billion records exposed in an unsecured database, a claim IDMerit disputes, saying its own systems were never compromised. Treat the disputed cases as reported, not confirmed. The pattern across all three is the same: centralised identity stores are the breach surface.
The steelman is fair: plenty of well-run institutions hold KYC data centrally, encrypt it, pass their examinations and never suffer a breach. Centralisation is not illegal and SOC 2 controls are real. The counter is that the BSA does not require it, and the asymmetry is brutal. One bribed insider or one misconfigured vendor turns a routine compliance file into a headline. Compliant alternatives exist: data minimisation, tokenisation, and decentralised storage where verified data is sharded so no single system holds a complete record. The architecture you choose to meet BSA recordkeeping is itself a risk decision, not a given. Our analysis of why your KYC vendor is your biggest breach risk goes deeper on this.
What are the penalties for BSA non-compliance?
BSA penalties are steep and come in civil and criminal flavours. Under 31 U.S.C. 5322, a willful violation can bring a fine of up to 250,000 dollars and up to five years in prison. An aggravated violation, meaning a willful breach committed while breaking another US law or as part of a pattern of illegal activity involving more than 100,000 dollars in a twelve-month period, doubles the exposure to up to 500,000 dollars and ten years. Separately, FinCEN and the banking regulators can assess large civil money penalties, and structuring transactions to dodge the 10,000 dollar CTR threshold is a distinct crime.
The figures are not theoretical. In November 2023, Binance Holdings agreed to a resolution of roughly 4.3 billion dollars, including a 3.4 billion dollar FinCEN civil penalty, the largest in Treasury history, for willful BSA violations, specifically the failure to maintain an effective AML programme as a money services business. Its chief executive, Changpeng Zhao, pleaded guilty to a BSA violation. The case is the textbook crypto-MSB failure: a firm in scope under FinCEN's virtual-currency guidance that did not run the programme the BSA requires. The lesson for any fintech or exchange is that scope plus a missing programme equals nine-figure, sometimes ten-figure, exposure.
How do you build a BSA compliance programme in 2026?
Building a BSA programme means turning the five pillars into operating reality. Appoint a named BSA compliance officer with authority and a direct line to the board. Write risk-based policies and internal controls that fit your products and customers. Automate CTR and SAR detection and filing, and run transaction monitoring so the alerts that matter surface above the noise, exactly the "less noise, more signal" goal behind FinCEN's October 2025 SAR guidance. Commission independent testing, train your staff, and verify identity at onboarding through CIP and CDD. Tools such as our AML software and emerging AI compliance agents cut the manual filing burden.
The final pillar is the one to design carefully, because it sets your long-term risk. Verify and retain proof of verification, as the BSA demands, but do not assume that means centralising customer PII. A privacy-first model that shards or minimises stored identity data lowers breach exposure while staying fully audit-ready, and reducing manual review and breach liability is also where compliance costs come down. You can meet every BSA recordkeeping and identity requirement and still hold no central honeypot. That is the build decision worth making deliberately rather than by vendor default.
The bottom line
The Bank Secrecy Act is the spine of United States anti-money laundering law, and in 2026 it reaches banks, money services businesses and crypto firms alike. The thresholds are concrete: a Currency Transaction Report over 10,000 dollars in cash, a Suspicious Activity Report at 5,000 dollars or 2,000 dollars for money services businesses, both filed to FinCEN within fixed deadlines, all retained five years. Build the five pillars, file accurately, and treat scope seriously, because Binance shows what a missing programme costs. Then make the architecture decision the law leaves open: verify and retain proof without turning a compliance duty into a central honeypot.
Related resources
- Bank Secrecy Act glossary definition
- Money services businesses (MSB) glossary
- Why your KYC vendor is your biggest data breach risk
- Decentralised KYC: what it is and how it works
- AML transaction monitoring guide
- Zyphe AML software
Cited sources
- FinCEN, The Bank Secrecy Act overview, statutes and regulations
- 31 U.S.C. 5311, purpose of the Bank Secrecy Act (Cornell Law)
- 31 U.S.C. 5322, criminal penalties (Cornell Law)
- 31 CFR 1020.320, bank Suspicious Activity Report requirement (Cornell Law)
- FFIEC BSA/AML Examination Manual, Currency Transaction Reporting
- FinCEN SAR FAQs, October 2025
- Department of Justice, Binance and CEO plead guilty in 4 billion dollar resolution
- Congressional Research Service, Anti-Money Laundering Act of 2020 (R47255)
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.