Start Free Trial
Home/Regulations/Bank Secrecy Act (BSA) — Regulatory Reference
Regulatory Reference
Financial Services Federal (US) high

Bank Secrecy Act (BSA) — Regulatory Reference

AML compliance, CTRs, SAR filing — AI agents accessing transaction data need need-to-know enforcement and tamper-evident audit.

Key Provisions
  • 31 CFR Chapter X — FinCEN regulations implementing the BSA
  • Currency Transaction Reports (CTRs) for transactions over $10,000
  • Suspicious Activity Reports (SARs) — confidentiality of filing required
  • Customer Identification Program (CIP) and Customer Due Diligence (CDD) rules
How AutoPIL Enforces It
  • Pre-retrieval enforcement keeps AI agents out of SAR filings unless explicitly authorized — SAR confidentiality is a hard regulatory floor
  • Sensitivity ceilings classify CTR, SAR, and customer identification data at HIGH
  • Tamper-evident audit chain logs every AI access to AML data for regulator inspection
Audit LogPolicy EngineSensitivity LabelsAgent RegistryKey Scoping
AutoPIL Policy IDs
FS-BSA-SAR-001SAR Confidentiality Enforcement
FS-BSA-CTR-001CTR Data Access Logging
FS-BSA-CDD-001Customer Due Diligence Agent Scope
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does the Bank Secrecy Act require for AI agents handling transaction data?
The BSA, implemented through 31 CFR Chapter X, requires financial institutions to file Currency Transaction Reports (CTRs) for cash transactions over $10,000 and Suspicious Activity Reports (SARs) for suspected money laundering or fraud. When AI agents are involved in transaction monitoring or AML workflows, the BSA's underlying obligations apply to the institution regardless of whether a human or an automated agent accessed the data. That means any AI agent touching SAR-related data must operate under documented need-to-know controls, and every access must be auditable for FinCEN examination.
What are the SAR confidentiality requirements under the BSA and how do they apply to AI?
Under 31 CFR § 1020.320 and parallel rules for other covered institutions, SAR filings and the fact that a SAR was filed are strictly confidential. Disclosure to any party named in a SAR — or to unauthorized personnel — violates federal law. AI agents create a new exposure vector: a poorly scoped agent querying transaction records or case management systems can inadvertently retrieve SAR data or infer a filing from related records. BSA compliance for AI requires hard pre-retrieval enforcement that blocks agent access to SAR data unless the agent has an explicit, logged authorization — not a post-hoc redaction or output filter.
How does AutoPIL help financial institutions meet BSA compliance for AI agent deployments?
AutoPIL enforces a need-to-know gate before any AI agent query reaches AML data. Policy FS-BSA-SAR-001 blocks unauthorized agent access to SAR filings at the retrieval layer — before data enters the agent's context window. CTR and customer due diligence data is classified at HIGH sensitivity under FS-BSA-CTR-001 and FS-BSA-CDD-001, restricting which agents can request it. Every decision — allow or deny — is written to a tamper-evident cryptographic audit chain that FinCEN examiners can inspect. This covers the three BSA obligations most directly impacted by AI: SAR confidentiality, CTR data handling, and Customer Identification Program scope.
What are the penalties for BSA violations and does AI agent access create new liability?
FinCEN can impose civil money penalties up to $1 million per willful violation. Criminal penalties under 31 USC § 5322 reach $500,000 per violation with potential imprisonment for willful conduct. The 'willful blindness' standard is particularly relevant to AI: an institution that deploys agents with access to AML data but no documented access controls cannot claim it was unaware of unauthorized access. Regulators have increasingly treated inadequate oversight of automated systems as a control failure, not a technology limitation. Maintaining a complete audit record of every AI agent access to BSA-covered data is a practical defense against that standard.
What BSA data should be classified as high sensitivity for AI governance purposes?
For AI governance, BSA-covered data warrants HIGH sensitivity classification at minimum: SAR filings and case notes, CTR records and underlying transaction data, CIP (Customer Identification Program) identity documents and verification records, CDD (Customer Due Diligence) beneficial ownership files, and any data that would reveal whether a SAR was filed on a specific customer or transaction. These categories carry distinct handling obligations — SAR data has the strictest confidentiality requirements, while CTR data requires both a filing record and a retention trail. Classifying all of them at HIGH sensitivity ensures that AI agents must satisfy explicit policy rules before any retrieval, with the decision logged regardless of outcome.
Covered Industries

The Bank Secrecy Act applies directly to US-chartered financial institutions — banks, credit unions, broker-dealers, money services businesses, and casinos — that file CTRs and SARs with FinCEN. As these organizations deploy AI agents for transaction monitoring and AML workflows, the BSA's confidentiality and audit obligations extend to every automated access to covered data.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries