---
title: "BSA/AML program"
description: "The anti-money-laundering program the Bank Secrecy Act requires — internal controls, a designated officer, training, independent testing, and customer due diligence."
reviewedBy: "Krisan Nichani, Chief Compliance Officer"
updated: "July 2026"
canonical: "https://infinite.net/learn/glossary/bsa-aml-program"
---

# BSA/AML program

A BSA/AML compliance program is the written anti-money-laundering program US financial institutions must maintain under the Bank Secrecy Act — board-approved at banks. Its five pillars: internal controls, a designated BSA officer, employee training, independent testing, and customer due diligence. The program must be risk-based — matched to the institution’s size and exposure — and regulators examine institutions against it, with weak programs drawing public enforcement actions.

In practice the program is the compliance function’s operating system: a risk assessment that says what the institution will and won’t touch, due diligence at onboarding, transaction monitoring behind every payment, investigation and SAR filing when something looks wrong, and documentation throughout — so an examiner can reconstruct every decision.

The program requirement never says reviews must be slow — it says they must be complete and documented. Infinite Agents assemble and document every case before an analyst opens it, with every decision made by a human, so BSA-grade files get built in days instead of weeks.

## Frequently asked questions

### What are the pillars of an AML program?

Internal controls, a designated BSA officer, employee training, and independent testing — plus customer due diligence, often called the fifth pillar. Each must be documented and examinable. [Bank Secrecy Act (BSA)](https://infinite.net/learn/glossary/bank-secrecy-act.md)

### Who is required to have a BSA/AML program?

Any US financial institution with Bank Secrecy Act obligations — banks and credit unions, money services businesses and money transmitters, broker-dealers, casinos, and others. Nonbank institutions carry the same program obligation as banks, scaled to their risk profile.

### Do stablecoin payments require a BSA/AML program?

Institutions handling them carry the same obligations as for fiat. On Infinite, stablecoin transfers run through the same screening and monitoring as fiat payments, so the program covers every rail. [Are stablecoin payments compliant for B2B?](https://infinite.net/learn/guides/stablecoin-payments-compliance.md)

## Where it fits on Infinite

- [Compliance AI](https://infinite.net/compliance/ai)
- [Stablecoin compliance](https://infinite.net/use-cases/global-compliance)
- [Are stablecoin payments compliant for B2B?](https://infinite.net/learn/guides/stablecoin-payments-compliance.md)

## See also

- [Bank Secrecy Act (BSA)](https://infinite.net/learn/glossary/bank-secrecy-act.md)
- [AML transaction monitoring](https://infinite.net/learn/glossary/aml-transaction-monitoring.md)
- [Know Your Business (KYB)](https://infinite.net/learn/glossary/know-your-business.md)
