AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Anti Money Laundering

skill-joellewis-finance-skills-anti-money-laundering · by JoelLewis

Guide BSA/AML compliance program design, ongoing transaction monitoring, and FinCEN reporting for broker-dealers, banks, and investment advisers. Use when the user asks about suspicious activity reports, currency transaction reports, OFAC screening, structuring detection, ongoing risk-rating reviews and escalation, or FinCEN requirements. Also trigger when users mention 'large cash deposit', 'san…

No reviews yet
0 installs
3 views
0.0% view→install

Install

$ agentstack add skill-joellewis-finance-skills-anti-money-laundering

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-joellewis-finance-skills-anti-money-laundering)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Anti Money Laundering? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Anti-Money Laundering Compliance

Regulatory status current as of June 2026 — verify effective dates, dollar thresholds, and pending rulemakings against current SEC/FINRA/FinCEN sources before advising.

Core Concepts

BSA Framework — Key Hooks

The operative statutes and authorities: the Bank Secrecy Act (31 U.S.C. §§ 5311–5332) as expanded by the USA PATRIOT Act (2001), which added enhanced due diligence requirements, information-sharing provisions (Sections 314(a) and 314(b)), and the written AML program requirement. FinCEN, a bureau of the U.S. Treasury, administers the BSA, issues implementing rules (31 CFR Chapter X), and collects CTRs and SARs.

FINRA Rule 3310 — AML Compliance Program

FINRA Rule 3310 requires every FINRA member firm to establish and implement a written AML compliance program that includes four pillars:

  1. Written procedures — Policies and procedures reasonably designed to detect and cause the reporting of suspicious activity. Must be tailored to the firm's business model, products, customer types, and geographic exposure.
  2. Designated AML Compliance Officer (AMLCO) — A qualified individual responsible for day-to-day AML oversight. The AMLCO must be identified by name and title in the firm's written procedures and registered with FINRA. The AMLCO must have sufficient authority, resources, and expertise.
  3. Independent testing (audit) — The AML program must be tested independently at least every calendar year (or every two years if the firm does not execute transactions or hold customer funds/securities). Testing may be performed by qualified internal personnel not involved in the AML program or by an outside party.
  4. Ongoing training — All relevant personnel must receive AML training appropriate to their responsibilities. Training must cover applicable BSA/AML regulations, the firm's own policies, red flags, and how to escalate suspicious activity. Training frequency and content should be documented.

Currency Transaction Reports (CTRs)

Financial institutions must file FinCEN Form 112 (CTR) for each cash transaction exceeding $10,000 in a single business day (31 CFR § 1010.311). Key rules:

  • $10,000 threshold — Applies to cash received or disbursed, including currency, coin, cashier's checks (under certain circumstances), and money orders purchased with cash.
  • Aggregation rule — Multiple cash transactions by or on behalf of the same person during a single business day must be aggregated. If the aggregate exceeds $10,000, a CTR is required.
  • Filing deadline — CTRs must be filed within 15 calendar days of the transaction date.
  • Structuring prohibition (31 U.S.C. § 5324) — It is a federal crime to structure transactions (i.e., break up a transaction into smaller amounts) to evade CTR reporting requirements. Both the customer and any employee who assists are liable. Structuring is illegal regardless of the source of the funds — even legitimate funds structured to avoid reporting trigger criminal liability.
  • Exemptions — Certain customers (e.g., listed companies, government agencies, banks) may be exempt from CTR filing under 31 CFR § 1020.315, but exemptions must be documented and periodically reviewed.

Suspicious Activity Reports (SARs)

SARs are filed using FinCEN Form 111 to report known or suspected violations of law, suspicious transactions, or transactions with no apparent lawful purpose. Filing thresholds and obligations vary by institution type:

  • Broker-dealers (FINRA members) — Must file a SAR for transactions of $5,000 or more that the firm knows, suspects, or has reason to suspect involve funds from illegal activity, are designed to evade BSA requirements, lack a business or apparent lawful purpose, or involve use of the firm to facilitate criminal activity (31 CFR § 1023.320).
  • Banks — Must file a SAR for transactions of $5,000 or more involving known suspects, or $25,000 or more regardless of suspect identification (31 CFR § 1020.320).
  • Filing deadline — SARs must be filed within 30 calendar days of initial detection. If no suspect is identified, the deadline extends to 60 days.
  • Continuing activity — If suspicious activity continues, the firm must file continuing SARs at least every 90 days.
  • Tipping-off prohibition — It is a violation to notify the subject of the SAR that a SAR has been or will be filed (31 U.S.C. § 5318(g)(2)). This prohibition extends to all employees, officers, and directors. Disclosure of a SAR filing can result in criminal penalties.
  • Safe harbor — Financial institutions and their employees are protected from civil liability for filing SARs in good faith (31 U.S.C. § 5318(g)(3)). This safe harbor applies even if the reported activity turns out to be legitimate.
  • SAR confidentiality — SARs are confidential. They cannot be produced in response to subpoenas, discovery requests, or FOIA requests (with narrow law enforcement exceptions). The underlying facts that triggered the SAR, however, are not themselves privileged.

OFAC Screening

The Office of Foreign Assets Control (OFAC), a bureau within the U.S. Treasury, administers and enforces U.S. economic and trade sanctions. Financial institutions must screen customers, counterparties, and transactions against OFAC-maintained lists:

  • SDN List (Specially Designated Nationals and Blocked Persons) — Individuals and entities owned or controlled by targeted countries, or designated as narcotics traffickers, terrorists, or proliferators. Transactions with SDN-listed parties must be blocked (frozen), and the blocked property must be reported to OFAC within 10 business days.
  • Sectoral Sanctions (SSI List) — Restrictions on specific types of transactions with identified entities (e.g., prohibiting new debt or equity issuance). The transaction is not fully blocked; only the prohibited type of dealing is restricted.
  • Geographic sanctions — Comprehensive sanctions programs prohibit virtually all transactions with certain countries or regions (e.g., North Korea, Iran, Cuba, the Crimea region). Any transaction touching a comprehensively sanctioned jurisdiction must be blocked or rejected.
  • Screening obligations — Firms must screen at account opening, upon receipt of wire transfers or other transactions, and when OFAC updates its lists. Screening must cover all relevant identifiers: names, aliases, addresses, dates of birth, passport numbers, and other identifying information.
  • Strict liability — OFAC violations are a strict liability regime. A firm can be penalized even if it did not know the counterparty was sanctioned. Penalties can reach millions of dollars per violation.
  • Voluntary self-disclosure — OFAC looks favorably on voluntary self-disclosure and considers it a significant mitigating factor in enforcement actions.

Red Flags for Money Laundering

Key red flags, mapped to the placement/layering/integration stages:

  • Structuring — Deposits or withdrawals just below $10,000 (e.g., $9,500, $9,800), especially if repeated across days or accounts. Multiple deposits at different branches in a single day.
  • Rapid movement of funds — Funds received and immediately wired out, particularly to unrelated third parties or foreign jurisdictions. No economic rationale for the speed of movement.
  • Layering patterns — Multiple transfers between accounts at different institutions, use of intermediary accounts, frequent conversion between asset types (cash to securities to wire transfers), round-dollar transactions with no apparent business purpose.
  • Integration patterns — Purchase of high-value assets (real estate, luxury goods, securities) with funds of unclear origin. Use of investment accounts to create the appearance of legitimate investment returns.
  • Shell company activity — Accounts held by entities with no apparent business operations, nominal capital, nominee directors, or registered in secrecy jurisdictions. Transactions that do not correspond to the entity's stated business purpose.
  • Unusual customer behavior — Reluctance to provide identification, use of multiple SSNs or TINs, frequent changes to account ownership or signatory authority, unexplained wealth inconsistent with known employment or business.
  • Geographic risk — Transactions involving jurisdictions identified as high risk by FATF, FinCEN advisories, or the firm's own risk assessment. Unexplained connections to countries with weak AML regimes or under comprehensive sanctions.
  • Third-party transactions — Deposits or payments by unrelated third parties with no clear explanation, especially if the third party has no apparent relationship to the account holder.

AML for Investment Advisers

Historically, registered investment advisers (RIAs) have not been subject to BSA/AML program requirements. In 2024, FinCEN issued a final rule (31 CFR Part 1032) that would require SEC-registered investment advisers and exempt reporting advisers to establish AML/CFT programs, file SARs, and comply with other BSA requirements. The rule's original January 1, 2026 effective date was postponed: FinCEN granted exemptive relief in August 2025 and finalized a delay rule on December 31, 2025, pushing the effective date to January 1, 2028. FinCEN has stated it intends to revisit the substance of the rule (and, with the SEC, the companion proposed CIP rule for advisers) through new rulemaking before that date — verify the current status and any revised requirements before advising. Key elements as adopted:

  • Covered advisers must implement risk-based AML programs with the same four pillars as broker-dealers (written procedures, designated compliance officer, independent testing, training).
  • Covered advisers must file SARs and comply with FinCEN information-sharing requests under Section 314(a).
  • Advisers with bank or broker-dealer affiliates should coordinate their AML programs to avoid gaps.
  • State-registered advisers are not covered.

Correspondent and Omnibus Account Considerations

Enhanced due diligence applies to correspondent accounts for foreign financial institutions (Section 312 of the USA PATRIOT Act, 31 CFR § 1010.610):

  • Firms must assess the AML risk posed by each foreign correspondent relationship, considering the jurisdiction's AML regime, the institution's AML controls, and the nature of the correspondent services provided.
  • For shell banks, correspondent accounts are prohibited. Firms must obtain certifications that the foreign institution is not a shell bank and that it will not permit its accounts to be used by shell banks.
  • Omnibus accounts (where a single account holds positions for multiple underlying clients) present heightened risk because the firm may have limited visibility into the ultimate beneficial owners. Firms should obtain sufficient information to identify and monitor for suspicious activity, and may need to "look through" the omnibus structure in certain circumstances.

Customer Risk Rating

A risk-based approach requires firms to assess and assign risk ratings to customers based on factors including:

  • Customer type — Individuals, entities, trusts, PEPs (politically exposed persons), non-resident aliens, foreign financial institutions.
  • Geographic risk — Customer domicile, transaction counterparties, and fund flow jurisdictions.
  • Product/service risk — Higher-risk products include private banking, correspondent accounts, wire transfers, and accounts holding securities in bearer form.
  • Transaction patterns — Volume, frequency, and nature of transactions relative to the customer's profile.

Risk ratings should be documented, periodically reviewed, and updated when new information becomes available. Higher-risk customers warrant enhanced due diligence (EDD), which may include more frequent transaction monitoring, senior management approval for account opening, and collection of additional documentation on source of funds and source of wealth.

Recordkeeping Requirements

BSA/AML regulations impose specific recordkeeping obligations:

  • SARs — Supporting documentation must be retained for 5 years from the date of filing (31 CFR § 1010.320(d)). The SAR itself and all supporting documentation must be made available to FinCEN and law enforcement upon request.
  • CTRs — Records must be retained for 5 years from the date of the report (31 CFR § 1010.306(a)).
  • CIP records — Customer identification records (copies of identification documents or descriptions of documents reviewed, methods used to verify identity) must be retained for 5 years after the account is closed (31 CFR § 1023.220(a)(3)).
  • Correspondence and transaction records — Generally retained for 5 years under BSA and FINRA Rules (FINRA Rule 3110, SEC Rule 17a-4).
  • Firms should ensure that AML records are organized, retrievable, and protected from unauthorized access or alteration.

FinCEN Enforcement Trends and Penalties

FinCEN has significantly increased enforcement activity in recent years. Key trends include:

  • Escalating penalties — Civil money penalties for willful violations can reach the greater of the amount involved in the transaction (up to $1 million) or $77,651 per violation (the figure as of FinCEN's January 2025 inflation adjustment under 31 U.S.C. § 5321; re-indexed annually in 31 CFR 1010.821 — verify the current amount). Criminal penalties can include imprisonment of up to 10 years.
  • Individual accountability — FinCEN and DOJ increasingly pursue enforcement actions against individual compliance officers and senior management, not just institutions.
  • Willful blindness — Firms and individuals can be held liable for willfully failing to implement adequate AML controls, even without direct knowledge of specific illicit transactions.
  • Areas of focus — Virtual currency exchanges and administrators, money services businesses, and firms with repeated examination deficiencies. FinCEN has also focused on failures to file timely and complete SARs.
  • Coordination with other regulators — FinCEN actions are frequently accompanied by parallel actions from the SEC, FINRA, OCC, or DOJ, resulting in cumulative penalties and remedial orders.
  • Beneficial Ownership Information (BOI) — The Corporate Transparency Act (effective 2024) requires many companies to report beneficial ownership information to FinCEN, creating a new tool for AML enforcement and due diligence.

Worked Examples

Example 1: Detecting structuring across multiple accounts

Scenario: A customer at a broker-dealer makes the following cash deposits over a five-day period: Monday — $8,000 into Account A; Tuesday — $7,500 into Account B (same customer, different registration); Wednesday — $9,000 into Account A; Thursday — $6,000 into Account A; Friday — $8,500 into Account B. No individual deposit or single-day aggregate exceeds $10,000, so no CTR is filed. A compliance analyst reviewing weekly transaction reports notices the pattern. Compliance Issues:

  • Although no individual day triggers a CTR, the pattern of repeated cash deposits just below $10,000 across multiple accounts is a classic structuring indicator (31 U.S.C. § 5324).
  • The firm has an obligation to monitor for structuring regardless of whether CTR thresholds are met.
  • If the analyst has reason to suspect that the transactions are designed to evade CTR requirements, a SAR must be filed.

Analysis: The compliance analyst should escalate the pattern to the AMLCO. The AMLCO should review the customer's profile, transaction history, and stated source of funds. If the cash deposits are inconsistent with the customer's known business or employment, or if the customer has no apparent reason to make frequent cash deposits into a brokerage account, the firm should file a SAR on FinCEN Form 111 within 30 days of the analyst's detection of the pattern. The SAR narrative should describe th

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.