Return to Lesson 25

SmartiExamPrep · SIE Lesson 25

SIE AML: SAR, CTR, FinCEN & OFAC Explained | Lesson 25

Read along with the lesson video.

Watch this explainer on YouTube

Four questions guide the AML decision

Welcome to Smarti Exam Prep. In Lesson twenty five for the Securities Industry Essentials Exam, we will build the anti-money laundering decision tree. Identity asks who the customer really is. Suspicious activity asks whether the facts require review and reporting. Currency asks whether physical money crosses the reporting threshold. Sanctions asks whether a transaction is prohibited or property must be blocked. These are separate checks, and more than one can apply to the same event. A currency report does not resolve suspicious behavior. A sanctions alert is not automatically a confirmed match. We will connect the rules to clear examples, keeping multiple-choice practice in the companion review.

FinCEN and OFAC have different jobs

Money laundering disguises criminal proceeds so they appear to have a legitimate source. FinCEN administers key Bank Secrecy Act reporting and anti-money laundering requirements and receives suspicious activity and currency transaction reports. OFAC administers United States economic and trade sanctions. Both are Treasury offices, but a report to one is not a substitute for duties involving the other. FINRA also requires member firms to maintain an appropriate written anti-money laundering program. A representative's role is to notice relevant facts and follow the firm's escalation process, not to promise a customer that one filing resolves every issue. Start by identifying the legal duty and the correct authority.

Recognize the laundering process

The usual teaching framework has three stages. Placement introduces illicit proceeds into the financial system. Layering moves them through transactions or accounts to make the trail harder to follow. Integration returns value in a form that appears legitimate. A suspicious customer relationship can involve any of these stages, and the sequence is not a checklist that must be completed before a firm responds. Terrorist financing can also involve money from apparently lawful sources, so AML controls do more than detect cash from a completed crime. Keep the process separate from reporting rules. Neither the word layering nor the absence of physical cash determines the reporting result by itself.

Collect the individual’s identifying information

Customer identification starts with facts that distinguish the actual person. Name is the first element. Date of birth is required for an individual. Address ordinarily means a residential or business street address. An identification number supplies the fourth element, with United States and non United States rules and specific exceptions. Collect the minimum information before opening unless a stated exception applies, such as the procedure for someone who has applied for a tax number. A person without a street address has specified alternatives. A client's desired return or risk tolerance cannot replace a missing date of birth. Those facts describe investment preferences; they do not establish identity.

Verification must reach a reasonable belief

Collecting a form and verifying identity are different steps. Verification procedures use documents, non-documentary methods or both, within a reasonable time before or after opening under the written program. Unresolved identity requires the response specified by that program, including circumstances for not opening, limits on use while verification continues, closure and consideration of a suspicious activity report. The rule seeks a reasonable belief that the firm knows the customer's true identity; it does not demand absolute certainty or allow unlimited delay. A missing or inconsistent identity document cannot be solved by adding an investment objective. Follow the risk-based procedures and escalate the problem to the people responsible for applying them.

Acceptance and customer records remain distinct

Identity controls operate alongside account records. The customer record identifies the client, legal-age status and relevant responsible or authorized people. Reasonable-effort information includes applicable occupation, employer, tax and other-member association facts under the FINRA rule, with its initial-settlement timing and account exceptions. Firm acceptance requires the appropriate documented acceptance under the firm's procedures. None of those labels replaces the C I P requirements. The ordinary cash-account record rule does not itself require a customer signature on every new-account form, but other agreements and firm policies can require signatures. Do not assume that a principal's approval proves every check is complete before any possible activity. Apply each requirement to its actual scope.

Records and labels cannot replace identity

Two account-record concepts also remain relevant to AML. Required updates keep the applicable SEC customer record current, with thirty-day initial furnishing, no-greater-than-thirty-six-month periodic furnishing, specific change notices and the rule's applicability and statement options. A numbered designation requires a signed customer ownership statement and does not hide the true owner from the firm. An account may use a number or symbol; that is different from carrying it in somebody else's name. Neither periodic mailing nor a private-looking account code eliminates ongoing identity and monitoring responsibilities. Recordkeeping shows what the firm knows and when it communicated it. AML review asks whether the actual customer relationship and transactions create concerns requiring action.

CDD connects the customer to expected activity

Customer due diligence, or C D D, connects identity to a relationship. The nature and purpose of the account help the firm understand why it exists. A risk profile uses relevant facts to describe the relationship's risks. Ongoing monitoring compares actual activity with that understanding and supports suspicious-transaction reporting and risk-based information updates. Suppose an account described as long-term personal saving suddenly becomes a conduit for unexplained third-party transfers. That mismatch calls for review; it does not alone prove a crime. Customer due diligence does not grant a representative investment discretion, and it does not promise investment performance. It supports the firm's ability to recognize and assess meaningful changes.

Look through covered legal entities

A legal entity can require identification of people behind it. The ownership prong generally identifies individuals with at least twenty five percent of equity in a covered legal entity customer. The control prong identifies one individual with significant management or control responsibility, subject to the rule's exclusions and details. Current account-opening relief, issued by FinCEN in February twenty twenty six, permits institutions to limit repeated identification and verification to the first account relationship, circumstances that call prior information's reliability into question, and risk-based ongoing due diligence triggers. It does not remove ongoing AML duties, and a firm may keep stricter account-opening procedures. This institution C D D rule is different from Corporate Transparency Act reporting and from OFAC's separate fifty percent blocking rule.

An AML program must operate continuously

A written program needs more than a policy saved in a folder. Internal controls are designed to achieve compliance and detect reportable activity. A designated AML compliance person implements and monitors day-to-day operations and is identified to FINRA. Ongoing training prepares appropriate personnel to perform their responsibilities. Customer due diligence connects relationship understanding with monitoring and risk-based updates. Senior management approves the written program, and independent testing checks whether it works. In the original example, training only after a problem occurs leaves an essential element missing. Training is ongoing and should fit the people and risks involved. Staff should know how to escalate an issue promptly without improvising customer disclosures.

Independent testing cannot be self-review

Independent testing generally occurs each calendar year under FINRA's AML rule. The two-year exception applies to the specified business model: firms that do not execute customer transactions, hold customer accounts or act as introducing brokers for them. Small size alone is not the exception. Tester independence also matters: the person cannot perform the functions being tested, be the designated AML compliance person or report to one of those people. A small firm therefore needs a qualified, independent tester instead of the officer testing the same work they run. Testing can use qualified firm personnel or an outside party. Circumstances may warrant more frequent testing, and finding a problem should lead to correction rather than merely a completed calendar entry.

A red flag starts review; it does not prove a crime

Consider what makes a pattern worth investigating. Unexplained funds may conflict with the customer's stated business. Inconsistent identity information may make the relationship difficult to verify. Unusual movement may show rapid transfers with no apparent economic reason. These examples call for review in context. A large transaction can be legitimate, and a smaller one can be suspicious. Document the facts and follow the firm's process for obtaining an explanation and deciding on further action. Do not accuse a customer solely because a screening tool or one pattern produced an alert. The goal is a supported compliance decision, not a guess based on a single dollar amount or the customer's appearance.

CTR starts with currency, not account cash

A currency transaction report, or C T R, concerns covered transactions in physical money. Physical currency means coins and paper money that circulate as legal tender; it is not every balance labeled cash in a brokerage account. More than ten thousand dollars is the federal reporting threshold for covered currency transactions, subject to applicable rules and aggregation. Exactly ten thousand dollars by itself does not cross that more-than threshold. Buying securities with already settled account funds is not automatically a currency transaction. A wire transfer is not physical currency merely because its value is stated in dollars. First classify what moved, then apply the amount and aggregation rules. Separate suspicion review can still be necessary.

Known same-day currency activity can combine

Assume the institution knows two same-business-day deposits are by or for the same person. A six thousand dollar currency deposit at one domestic branch is the first transaction. A five thousand dollar currency deposit at another domestic branch is the second. The combined cash-in amount is eleven thousand dollars, so splitting the deposits between those branches does not avoid the aggregation rule. The institution looks at known transactions by or on behalf of the person across its domestic offices. Cash in and cash out are evaluated separately; a withdrawal does not simply cancel a deposit for this purpose. Aggregation depends on the rule's facts, not on whether each individual receipt exceeds ten thousand dollars.

CTR has a filing and retention rule

Once a covered currency transaction is identified, the report follows its own process. Filing generally must occur within fifteen calendar days after the reportable transaction. FinCEN receives the electronic report through its filing system. Retention keeps a copy for five years from the report date under the rule. Do not apply an old twenty-five-day electronic-filing allowance; FinCEN states that the fifteen-calendar-day requirement has applied to all C T R filings since April twenty thirteen. A report does not by itself accuse the customer of wrongdoing. It records a covered currency event. Firm procedures determine staff responsibilities and review, and bank-specific exemptions should not be imported automatically into a broker-dealer example.

Evasive purpose changes the analysis

Structuring involves arranging transactions for the purpose of evading applicable reporting or recordkeeping requirements. The transaction pattern can span multiple transactions, locations or days, so a simple same-day total does not exhaust suspicious-activity review. Evasive purpose is the key distinction from legitimate smaller transactions. A customer may have an ordinary business reason for several deposits. But a request to break up future deposits specifically to avoid reporting is a red flag that staff should escalate. Do not help design a way around the requirement or reassure the customer that staying below one amount guarantees no review. The compliance process evaluates the facts and any applicable suspicious-activity reporting obligation.

One event can create two reporting questions

Consider a twelve thousand five hundred dollar deposit. The currency deposit crosses the more-than-ten-thousand-dollar threshold for the covered event. The customer's request to divide future deposits to avoid reports separately raises a structuring concern. The firm applies the currency-reporting rules and escalates the suspicious conduct under its AML procedures. One report does not cancel the other analysis. Nor does the representative need to establish a completed criminal prosecution before escalating the facts. Record the event accurately, preserve relevant information and let the authorized compliance process decide the applicable filings. Do not tell the customer that a suspicious activity report is being considered or filed.

SAR requires the facts as well as the amount

A suspicious activity report, or S A R, uses a different test. A conducted or attempted transaction by, at or through a broker-dealer is within the reporting framework. At least five thousand dollars in funds or other assets, individually or in aggregate, meets the broker-dealer amount element. Suspicious circumstances must also be present under the rule, such as illegal proceeds, evasion of Bank Secrecy Act requirements, unexplained activity without an apparent lawful purpose, or use of the firm to facilitate crime. Five thousand dollars alone does not require a S A R for every ordinary trade. Conversely, the rule permits voluntary reports when suspicion exists below the mandatory threshold. Currency is not a prerequisite.

SAR timing starts with detected facts

The ordinary filing deadline is thirty calendar days after the initial detection of facts that may form a basis for filing. If no suspect is identified at that initial point, a limited extension allows up to another thirty calendar days to identify one, with an absolute sixty-day limit from the initial detection. Record retention covers the filed report and supporting documentation for five years from filing. This is not a routine sixty-day investigation allowance for every case. Matters needing immediate attention, such as terrorist financing or an ongoing money laundering scheme, also require immediate telephone notification to appropriate law enforcement in addition to a timely report. Follow the exact trigger and urgency requirements rather than waiting for a calendar reminder.

Do not disclose the existence of a SAR

A customer calls after unusual wire activity and asks whether the firm reported it. Protected information includes the suspicious activity report and information that would reveal its existence. Underlying facts and ordinary business documents are different, although privacy rules and the specific disclosure context still apply. The rule permits specified disclosures to authorities and other authorized recipients; it does not authorize tipping off the customer. Staff should follow the firm's process rather than confirm, deny or speculate about a report. The customer's curiosity, insistence or request for transparency does not override S A R confidentiality. At the same time, confidentiality should not be misdescribed as a ban on all ordinary communication about the underlying account activity.

Review the relationship, not an isolated receipt

Consider repeated smaller cash transactions and a customer reluctant to explain the source of funds. The pattern is reviewed across relevant activity rather than dismissed because each deposit is below a threshold. The explanation is assessed against the available facts and the customer relationship. The decision follows the firm's escalation and reporting procedures. A representative should preserve accurate facts instead of labeling the customer a criminal or promising no report will be filed. Some alerts have reasonable explanations; others support suspicion and a filing. The rule asks what the broker-dealer knows, suspects or has reason to suspect after the required review. Proof beyond a reasonable doubt is not the filing standard.

Sanctions screening has a different purpose

Sanctions review is not just another way to count suspicious transactions. The S D N list identifies Specially Designated Nationals and Blocked Persons. Other sanctions restrictions can apply through additional lists, programs or covered ownership relationships. The applicable rule determines whether a transaction may proceed, is prohibited or involves property that must be blocked. A name appearing in a search result is the start of a match assessment, not the end. A missing name on one list also does not establish that every transaction with the entity is allowed. Applicable authorizations and exemptions matter. Keep sanctions decisions separate from the dollar thresholds used for currency and broker-dealer suspicious-activity reports.

Resolve a possible match using identifiers

A new customer's name resembles a sanctions entry but is not an exact match. First identify which list or sanctions restriction produced the alert. Then compare available identifying details, such as person or entity type, name, location and relevant identification information. Escalate unresolved findings under the firm's procedures and contact the appropriate authority when required or appropriate. A similar name can be a false hit, but a slightly different spelling can also be meaningful. Do not assume either outcome from the name alone. OFAC's guidance includes checks for program-based and non-listed targets as well as names. Keep the review documented and avoid taking an unauthorized transaction action while the issue remains unresolved.

Blocking and rejection are different actions

A confirmed sanctions issue does not always have the same operational result. Blocking generally freezes property in which a blocked person has an interest when the applicable sanctions rule requires it; the property is not simply returned or moved at the customer's request. Rejection means the institution does not process a prohibited transaction when there is no blockable interest under the applicable rule. Both require attention to the specific sanctions program and any authorization or exemption. Do not use the words freeze, reject and file a S A R as if they were interchangeable. A suspicious-activity report informs FinCEN. It does not authorize the firm to process a transaction that OFAC rules prohibit.

Blocked ownership can reach an unlisted entity

Assume two blocked persons directly own interests in an entity. The first blocked owner holds thirty percent. The second blocked owner holds twenty percent. Aggregate blocked ownership is fifty percent, so the entity is treated as blocked under OFAC's fifty percent rule even if its own name does not appear separately on the S D N list. This simple example assumes those are the relevant direct interests and no authorization changes the result. Indirect structures require careful analysis under OFAC guidance. Do not substitute FinCEN's twenty-five-percent beneficial-owner identification threshold for this blocking rule. They use ownership information for different purposes and have different tests.

Sanctions actions have their own reports

After the required sanctions action, separate reporting rules apply. A blocked-property report is generally due to OFAC within ten business days of the initial blocking. A rejected-transaction report is generally due within ten business days of rejection under the applicable rule. Other duties include keeping required records and any continuing reports required for the property or program. The word business matters: these deadlines are not the fifteen calendar days used for a currency report or the thirty-calendar-day starting deadline for a suspicious activity report. Record the action and its date accurately so the compliance team can apply the correct rule. Sending a report never substitutes for taking the required blocking or rejection action itself.

Run the checks in parallel

The complete decision tree now has four independent branches. Identity review establishes the real customer and responds to unresolved verification. Currency reporting tests physical money, amount and known same-day aggregation. Suspicious-activity review tests the facts, the broker-dealer threshold and possible voluntary reporting. Sanctions review tests the applicable prohibitions, matches and property interests. A transaction can reach more than one branch at once. A legitimate large currency deposit may require a currency report without establishing suspicion. A non-currency transfer may still raise suspicion or sanctions issues. Do not stop the analysis merely because the first branch gave an answer. Each branch protects a different part of the compliance process.

A wire can need review without a CTR

Consider a final example: an established account receives an eight thousand dollar wire and immediately requests an unexplained transfer to a third party. The currency branch does not trigger merely from this wire because no physical currency transaction is described. The suspicious-activity branch still needs review because the amount can meet the broker-dealer threshold and the pattern may lack a reasonable explanation. The facts determine the result; the amount alone does not. Sanctions and customer-information checks continue independently. If an OFAC issue exists, the firm must follow the applicable sanctions action even if a S A R is also filed. This case shows why one report label cannot replace the whole decision tree.

Match the facts to the right rule

Bring the lesson together. Know the customer through identification, verification and ongoing due diligence. Recognize suspicious facts and escalate them without tipping off the customer about a report. Count covered currency using the more-than-ten-thousand-dollar and aggregation rules. Apply sanctions requirements by resolving matches and distinguishing blocking from rejection. Remember the broker-dealer S A R test uses at least five thousand dollars plus the required suspicion, while a C T R concerns covered physical currency. Neither filing gives permission to ignore OFAC. Your practical sequence is to identify the facts, apply each relevant branch, document the decision and follow the authorized compliance process.

Continue learning

Continue with Lesson twenty six on records, privacy and custody, or review the Trading and Accounts practice. Study smart with Smarti Exam Prep.