Almost every recurring obligation a compliance team tracks arrives with a date attached to it by somebody else. A certificate carries an expiry. A license carries a renewal month. A filing is due a fixed number of days after a year-end. Even the obligations that let an institution set its own interval usually set an outer limit around that choice — a maximum you are free to work inside but not past.
BSA/AML independent testing is not like that, and the distance is bigger than it first appears. Under the Bank Secrecy Act every covered financial institution has to maintain a written anti-money-laundering program, and independent testing is one of its required components. But for a bank, neither the statute at 31 U.S.C. 5318(h) nor the implementing regulation at 31 CFR 1020.210 says how often that testing must happen. The regulation's entire text on the point is that the program must provide for “independent testing for compliance to be conducted by bank personnel or by an outside party.” No number. No maximum. No anniversary.
The only number anyone quotes comes from somewhere else entirely. The FFIEC BSA/AML Examination Manual — a document written to instruct examiners, not to bind banks — states outright that there is no regulatory requirement establishing BSA/AML independent testing frequency, and then adds, parenthetically, that a bank may conduct testing over periodic intervals, “for example, every 12-18 months.” That parenthesis is where the industry's most-repeated compliance interval comes from. It is an illustration inside a manual, and it has been retold so often that most people who cite it believe it is the rule.
So the institution sets its own date, and then discovers at the next examination whether the date it set was defensible — judged against a risk profile that has been moving the whole time. And the interval only ever moves one way. Findings pull the next test closer; nothing pushes it further out. Here is how that obligation actually behaves, and how to hold a deadline that no one will ever send you.
General information, not compliance or legal advice. Requirements differ by institution type and by regulator, and FinCEN has proposed significant changes to the program rules that are not final. Confirm what applies to you with your regulator, your examiners and your own counsel, and with the official sources in section 11.
1. What is a BSA/AML compliance program?
A BSA/AML compliance program is the written system a covered financial institution maintains to comply with the Bank Secrecy Act. The statutory requirement sits at 31 U.S.C. 5318(h), which obliges financial institutions to establish anti-money-laundering and countering-the-financing-of-terrorism programs with, at a minimum, internal policies, procedures and controls; a designated compliance officer; ongoing employee training; and an independent audit function to test the program. For banks, Treasury's implementing rule at 31 CFR 1020.210 restates those components and adds appropriate risk-based procedures for ongoing customer due diligence. Remindax helps you hold the recurring dates that program generates and reminds the people who own them; it doesn't conduct or scope your independent testing, run your AML program, monitor transactions, screen sanctions, file SARs or CTRs, or provide compliance or legal advice.
A detail worth knowing before anything else, because it explains why so much BSA/AML guidance seems to come from unexpected places: for banks the requirement lives in two parallel rulebooks at once. Treasury's rule is at 31 CFR 1020.210, and each federal banking agency maintains its own program regulation alongside it — 12 CFR 208.63(c)(2) for the Federal Reserve, 326.8(c)(2) for the FDIC, 748.2(c)(2) for the NCUA and 21.21(d)(2) for the OCC. An institution is answering to both, and the examiner at the door is applying the agency's manual rather than Treasury's regulation.
The components are usually called the pillars. What matters for tracking is that they are not equivalent obligations: only one of them recurs on anything resembling a clock, and it is the one with the least guidance attached to it.
1.1 The pillars, and which of them carries a date
- →A system of internal controls. The written policies, procedures and processes that make ongoing compliance work. This is a document set that is maintained rather than renewed — it has a review habit, not a due date, and it changes when the business does.
- →Independent testing. The one with a recurring interval, and the subject of this page. Its frequency is not stated in the statute or the regulation; it is chosen by the institution and judged afterwards. The FFIEC manual treats “independent testing” and “audit” as synonymous terms.
- →A designated BSA compliance officer. A named individual, or individuals, responsible for coordinating and monitoring day-to-day compliance. This is a designation rather than a deadline — but it is the fact that decides who is not allowed to perform the testing, which makes a change of officer quietly relevant to the audit.
- →Training for appropriate personnel. Recurring, tailored to specific functions and positions, and expected to be evidenced by supporting documentation. The FFIEC manual lists training among the things independent testing reviews, so the training record is part of what the audit is measured against.
- →Risk-based customer due diligence. Added to the bank rule as a fifth component, covering the understanding of customer relationships and ongoing monitoring. Continuous by nature rather than dated.
It is common to hear the risk assessment described as the foundation of the program, and functionally that is right: independent testing is expected to be risk-based, and risk-based testing focuses on the areas the risk assessment identifies as highest-risk. But the FFIEC manual is careful about its status, saying that while not a specific legal requirement, a well-developed BSA/AML risk assessment assists the bank in identifying risk, and that documenting it in writing is a sound practice. So an institution's risk assessment currently has no mandated form, no mandated content and no mandated refresh date — while being the thing the audit is calibrated to. FinCEN's proposed AML/CFT program rule, published in April 2026 and not final, would change this by requiring programs to be based on a documented risk assessment process. Watch it; don't plan on it.
2. How often is BSA/AML independent testing required?
The FFIEC BSA/AML Examination Manual states it plainly: “There is no regulatory requirement establishing BSA/AML independent testing frequency.” Frequency should be commensurate with the institution's money-laundering and illicit-finance risk profile and its overall risk management strategy. The manual offers 12–18 months as an example of a periodic interval, not as a requirement or a recommended practice.
31 CFR 1022.210 requires a money services business to provide for independent review to monitor and maintain an adequate program, and states in the rule itself that the scope and frequency of the review shall be commensurate with the risk of the financial services provided. Here the risk-based standard is in the regulation, not only in a manual.
FINRA Rule 3310(c) requires annual (on a calendar-year basis) independent testing by member personnel or a qualified outside party — every two years, again on a calendar-year basis, for members that don't execute transactions for customers, hold customer accounts or act as an introducing broker.
More frequent testing may be appropriate where errors or deficiencies have been identified, or to verify or validate remedial actions — and testing may also be triggered by significant changes to the risk profile, systems, compliance staff or processes.
The party conducting the testing should report directly to the board of directors, or to a designated board committee comprised primarily or completely of outside directors. That reporting line is what makes the testing independent.
Set the three rows beside each other and the useful observation is not that the answers differ. It is that they differ in kind. A broker-dealer has a deadline and can be late for it. An MSB has a standard written into the regulation it will be measured against. A bank has neither — it has an expectation held by an examiner it has not met yet, expressed in a manual addressed to that examiner.
The broker-dealer case repays a second look, because it contains a trap that the word “annual” hides. FINRA's testing obligation is annual on a calendar-year basis, which means the unit is the named year, not a rolling twelve months. A firm that completes its testing in January 2026 has satisfied 2026, and its next test is due at some point in 2027 — potentially December. Two consecutive tests, both perfectly compliant, can sit nearly twenty-three months apart. A firm that habitually tests in December has a real-world gap of twelve months; a firm that habitually tests in January has the same paper obligation and a far longer exposure, and nothing in the rule distinguishes them. The compliant calendar and the prudent one are not the same calendar.
Older versions of the FFIEC manual described testing every 12 to 18 months as a sound practice, and that phrasing has outlived the text. The current manual does not recommend the interval; it lists it as an example inside a sentence whose subject is that no requirement exists, immediately after saying frequency should be commensurate with risk. The distinction is not academic. If 12–18 months were a recommended practice, an institution meeting it would have a defense. Because it is an illustration of what a periodic interval can look like, an institution meeting it has not answered the question the examiner is actually asking — which is whether the interval matched this institution's risk. A higher-risk bank testing at eighteen months has complied with nothing in particular.
3. Why tracking independent testing matters
Institutions rarely forget that independent testing exists. What makes it a date to be tracked rather than a project to be scheduled is that four of its properties are unlike anything else on a compliance calendar:
Nobody issues the date, and no rule caps it
There is no certificate, no renewal notice, no expiry and no outer limit written anywhere for a bank. The interval exists only in the institution's own records, which means losing the record is losing the obligation.
The interval only ever contracts
Findings and material change pull the next test closer. Nothing in the guidance pushes it further out — so a good audit result never buys time, and the thing that shortens the clock is the audit's own output.
Independence is a reporting line, not a qualification
The same person can be independent of one function and not another. What decides it is who they report to and what else they do at the institution — both of which change without anyone revisiting the audit plan.
The dated evidence sits in the board's records
Examiners confirm the program was approved by the board and that the approval was noted in the minutes, and check that findings were reported to the board. The proof lives in a governance file the compliance team doesn't own.
Property 3.1 is the structural one, and it separates this obligation from every neighboring page in this library. Several compliance regimes let an institution choose its own interval, but they nearly all bound the choice. A process safety management program lets an operator determine its own mechanical-integrity frequency, but sets a hard five-year revalidation ceiling around the process hazard analysis. An importer running a foreign supplier verification program authors its own verification frequency, and then sits under a three-year backstop that catches anyone whose authored interval drifts. In both cases the self-set interval is a choice made inside a stated maximum, and a compliance calendar can hold the maximum even when it cannot hold the judgment.
BSA/AML independent testing has no maximum. Not a long one — none. There is no paragraph anywhere in 31 U.S.C. 5318(h), in 31 CFR 1020.210, or in the four banking-agency regulations that would let an institution say it tested within the outer limit, because no outer limit is stated. What exists instead is a standard of reasonableness applied retrospectively by somebody who was not in the room when the schedule was set. An institution cannot be late in the ordinary sense. It can only be found, afterwards, to have chosen wrongly.
Property 3.2 is where this obligation inverts something most compliance calendars assume. On a great many recurring obligations, doing the work resets the clock and buys the maximum interval back — a completed process-safety update pushes the next resubmission out by a fresh five years. Independent testing runs the other way. A clean report does not extend the interval; it merely fails to shorten it. A report with findings shortens it, because more frequent testing may be appropriate to verify or validate the remedial actions those findings required. The output of the audit is an input to the audit schedule, and it can only compress it.
The practical consequence is a perverse-looking incentive that well-run institutions feel and badly-run ones don't. An audit that finds nothing changes nothing. An audit that does its job — that surfaces a gap in transaction testing, an under-scoped monitoring rule, a training population that missed a function — obliges the institution to test again sooner. A thorough tester therefore generates more work than a superficial one, and the person deciding how much scope to buy is often the person whose budget it comes out of. Nothing in the guidance resolves that tension. What tracking can do is make sure the shortened interval that a finding implies is actually written down as a date somewhere, rather than remaining an intention in the remediation memo.
Property 3.3 is the failure that catches institutions who did everything else right. Independence here is not a credential you buy once and rely on. The FFIEC manual is specific: testing should be conducted by the internal audit department, outside auditors, consultants or other qualified independent parties; an institution without any of those may use qualified staff who are not involved in the function being tested; and an institution engaging outside auditors or consultants should ensure the people conducting the testing are not involved in other BSA-related functions that would present a conflict or a lack of independence — the manual names training and developing policies and procedures as examples. Regardless of who performs it, the party should report directly to the board or a designated board committee comprised primarily, or completely, of outside directors.
Read that carefully and you can see how independence is lost without anybody deciding to lose it. A consultant who tested the program last year and was engaged in the meantime to help rewrite a procedure is no longer independent of the thing being tested. An internal auditor who takes on the BSA training program has moved to the other side of the line. Neither event looks like a compliance change when it happens; both look like using a good resource twice. The date the audit was performed will be perfectly recorded. The fact that made it not count is in an engagement letter nobody re-read. It is a close cousin of the question about who may certify an SPCC plan — but there the qualification is a professional credential a person either holds or doesn't, while here the same qualified person moves in and out of eligibility depending on what else they were asked to do.
Property 3.4 explains why an institution's own compliance file is not sufficient evidence that any of this happened. The FFIEC examination procedures direct examiners to confirm that the program is written, has been approved by the board of directors, and that the approval was noted in the board minutes, and separately to determine whether independent testing findings have been reported to the board or a designated committee. Both proofs are governance records. The BSA officer does not draft the minutes, does not control what they say, and often does not learn what they omitted until an examiner reads them. A program that was approved in a meeting where the minute-taker recorded a general update carries an evidential gap that no amount of compliance-side documentation closes.
4. Who needs to track BSA/AML program dates
Large institutions have an audit plan and a committee calendar that carries this. The exposure concentrates where the compliance function is small, where the institution type changed, or where the person who chose the interval has since left:
Banks & credit unions
The institutions with no stated frequency to fall back on, answering to both Treasury's rule and their own agency's. Community institutions carry the same expectation as large ones with a fraction of the audit infrastructure to hold it.
Learn MoreMSBs & money transmitters
Carrying an independent review whose risk-based standard is in the regulation itself, on top of a federal registration and a state license in every state served. Three obligations, three different kinds of date.
Learn MoreBroker-dealers
The only ones in this list with a stated deadline — and the ones most exposed to the calendar-year trap, where two compliant tests can sit almost two years apart and the paper record shows nothing wrong.
Learn MoreFintechs & payment companies
Where the risk profile changes faster than the audit plan. An interval that was defensible at one product line and one geography is being judged against the business as it is now, not as it was when somebody wrote the schedule.
Learn MoreBSA officers & internal auditors
The two roles the independence rule holds apart. One owns the program and cannot test it; the other tests it and must stay clear of the functions being tested. Both need to see the same calendar without sharing the work on it.
Learn MoreBoards & audit committees
The recipients the reporting line points at, and the holders of the minutes an examiner will ask for. A committee that meets quarterly is a scheduling constraint on an audit whose results have to reach it.
Learn More5. What happens when BSA/AML independent testing lapses
The BSA/AML failure that draws attention is rarely a missing program. It is a program that has stopped being tested at a rhythm its risk justifies — and because no rule states that rhythm, the failure has no moment at which it becomes visible from inside. It takes four recognizable shapes, and only the first resembles a missed deadline.
The interval quietly stretched. No single decision extended it. A test was scheduled for the spring, the auditor's engagement slipped, a system migration made the timing awkward, and by the time anyone counted it had been twenty-two months. Nothing alerted anyone, because there is nothing to alert: no expiry passed, no filing came due, no regulator wrote. The institution's own belief that it tests “roughly annually” survives intact, because the belief is about a habit and the record is about dates, and nobody put the two side by side.
The interval stayed the same while the institution changed. The more serious version, and the one that catches growing institutions rather than neglectful ones. Testing frequency is supposed to be commensurate with the risk profile, and the manual explicitly directs risk-based testing to consider expansion into new product lines, services, customer types and geographic locations, whether through organic growth or merger. An institution that has doubled its footprint, added a higher-risk customer segment or absorbed a portfolio and kept the same audit cadence has not maintained a schedule. It has let the schedule fall behind the business, and the interval that was defensible at the last examination is being judged against facts that did not exist then.
The testing happened and did not count. The independence failure. The work was scoped, performed, reported and filed, and the person who performed it was involved in a BSA-related function — wrote a procedure, ran part of the training, sat inside the compliance line. The manual's requirement that the tester report directly to the board or to a designated committee of primarily outside directors exists precisely so this cannot be resolved by good intentions. An institution in this position did the work and has no independent test, and it will usually learn that from an examiner rather than from its own file, because its own file records a completed audit.
The findings were never validated. The one that turns a manageable problem into a pattern. Findings call for more frequent testing to verify or validate the mitigating or remedial actions taken, and examiners are directed to look at whether findings were reported to the board and tracked through to correction. A deficiency identified, accepted, assigned and then carried into the following year without a validating test is a worse fact than the original deficiency, because it converts a one-off gap into evidence that the institution's own control over its program does not close what it opens.
Independent testing is one of the few compliance artifacts whose findings are retrospective by construction. A deficiency identified in month fourteen is usually a deficiency that existed for some part of the fourteen months before it was found — so the report the institution commissioned is also the dated evidence of how long the condition ran. That is not an argument against testing; it is an argument for testing on an interval short enough that the answer to “how long was this true?” is short. The longer the gap between tests, the longer the period any finding implicates. An interval that stretched is not only a scheduling failure. It widens the window every future finding will be read against.
The consequences sit at the severe end of financial regulation. BSA/AML deficiencies drive supervisory findings, formal enforcement actions and civil money penalties, and in serious cases restrictions on what the institution is permitted to do — expansion and acquisition approvals among the first things affected. What makes the exposure worth tracking rather than worrying about is that the mechanism is so undramatic. Nothing arrives to say the clock ran out, because there is no clock except the one the institution keeps for itself.
6. How Remindax keeps the testing interval honest
Remindax holds the dates and reminds the people who have to act on them. It does not conduct or scope your independent testing, run your AML program, monitor transactions, screen sanctions, file SARs or CTRs, or advise you on compliance matters.
The interval you chose, held as a date
Set the testing interval your risk profile supports and it becomes a dated obligation with an owner, rather than an intention living in an audit plan. Because no rule supplies this date, the record you keep is the only version of it there is.
An interval you can tighten, deliberately
When a finding calls for earlier validation, or the risk profile moves, shorten the interval and the next date moves with it — so the compressed schedule a remediation memo implies actually exists somewhere as a date.
Reminders with real lead time
Staged alerts by Email, SMS and WhatsApp, timed backwards from the date — because engaging an independent party, scoping the work and getting results in front of a board committee that meets quarterly is a months-long sequence, not a task.
Reminders that reach the board side too
The BSA officer and the audit committee can be reminded of the same obligation without either owning the other's work — which suits a requirement whose whole point is that the two roles stay apart.
The cadence underneath the audit
The risk-assessment refresh and the training cycle tracked as their own recurring dates, alongside the officer designation — the things the testing is calibrated against, each with its own reminder.
Every entity and charter separately
Affiliated institutions, a bank and its MSB subsidiary, or entities sitting under different regulators, each with its own interval and its own reminders. One entity being current says nothing about the next.
A history that survives a BSA officer handover
When each test fell due, when it was completed, and whether the interval was changed and why — the record that answers an examiner's question about how the schedule was set, after the person who set it has gone.
Dates and status only
Remindax records that an obligation exists, when it falls due and whether it has been met. It holds no customer data, no transaction data, no audit workpapers, no SAR information and no risk-assessment contents.
7. Why spreadsheets fail for BSA/AML program tracking
A workbook is a good record of dates somebody already decided to write down. Three properties of this obligation sit outside that.
A spreadsheet has no way to distinguish a date that was given to it from a date it made up. Every other row on a compliance calendar traces back to something external — a certificate, a license, a filing deadline — and if the row is wrong, the external document eventually corrects it. The independent-testing row has no external counterpart at all. If somebody typed the wrong year, or copied a cadence over from a previous employer, or inherited a tab whose original owner had a different risk profile in mind, nothing in the world disagrees. The cell is the obligation. That is a bad property for a value stored in a file that gets duplicated, filtered and re-saved.
It cannot express an interval that responds to events. The whole shape of this obligation is that findings and material changes shorten the next due date, and a static date in a cell has no relationship to either. In practice the remediation plan lives in one document, the audit schedule in another, and the connection between them is a person remembering. What is needed is a due date that can be deliberately moved forward with a record of why — the same discipline a third-party compliance review needs when a vendor's own circumstances change between scheduled checks.
And it treats the tester as an attribute rather than a condition. A workbook column reading “performed by: internal audit” is true and useless. It does not know what else internal audit was asked to do this year, and it will still say the same thing in the year the answer stops being acceptable. Independence is the property most likely to be lost quietly, and a static field is the worst possible place to record something that changes without notice.
A system that holds the interval as a real dated obligation, lets it be tightened when findings demand and records that it was, keeps the risk-assessment and training dates beside it, and reminds both the compliance side and the board side is what turns a program that is tested when someone remembers into one an examiner can follow.
8. Key takeaways
- ✓A BSA/AML compliance program is ongoing, not a registration. Its components under 31 U.S.C. 5318(h) and 31 CFR 1020.210 are internal controls, independent testing, a designated compliance officer, training and risk-based customer due diligence.
- ✓For banks there is no stated testing frequency anywhere — the FFIEC manual says there is no regulatory requirement establishing one, and offers 12–18 months only as an example of a periodic interval, not as a rule or a recommendation.
- ✓MSBs must provide for an independent review under 31 CFR 1022.210 whose scope and frequency the regulation itself requires to be commensurate with risk — a risk-based standard written into the rule rather than into a manual.
- ✓Broker-dealers have a real deadline under FINRA Rule 3310(c), but it is annual on a calendar-year basis, not a rolling twelve months — so two fully compliant tests can sit almost two years apart.
- ✓The interval only ever contracts. Findings call for more frequent testing to validate remediation, and material changes to risk, systems, staff or processes pull the date closer. A clean report never buys time.
- ✓Independence is a reporting line and a set of exclusions, not a credential: the tester must not be involved in the function being tested or in other BSA-related work, and must report directly to the board or a committee of primarily outside directors.
- ✓The evidence lives in governance records — examiners confirm board approval of the program was noted in the minutes and that testing findings reached the board. The risk assessment, meanwhile, is currently expected practice rather than a specific legal requirement, though FinCEN's proposed 2026 program rule would change that.
- ✓Because nothing external supplies this date, the interval exists only where you record it — which makes recording it somewhere that reminds you the entire control.
Never let the testing interval quietly stretch too far
Track independent testing, risk-assessment refreshes and training as dated obligations — automatically. Remindax reminds the BSA officer and the board side while there is still time to scope the work.
GDPR-ready · AWS secure cloud · Encrypted storage · Setup in under 5 minutes
9. Frequently Asked Questions
It depends which rulebook you sit under, and for banks the honest answer is that no rule says. The FFIEC BSA/AML Examination Manual states that there is no regulatory requirement establishing BSA/AML independent testing frequency, and that frequency should instead be commensurate with the institution's money-laundering and illicit-finance risk profile and its overall risk management strategy. The manual mentions periodic intervals of, for example, every 12 to 18 months, but it offers that as an illustration rather than as a rule or a recommended practice - which is why an institution meeting it has not by itself answered the question an examiner asks. Money services businesses work to 31 CFR 1022.210, which requires independent review whose scope and frequency the regulation itself says shall be commensurate with risk. Broker-dealers have an actual deadline under FINRA Rule 3310(c): annual, on a calendar-year basis.
Someone independent of the function being tested. The FFIEC manual points to the internal audit department, outside auditors, consultants or other qualified independent parties, and says an institution with none of those may use qualified staff who are not involved in the function being tested. Where outside auditors or consultants are engaged, the institution should make sure the people conducting the testing are not involved in other BSA-related functions that would create a conflict or a lack of independence - the manual names training and developing policies and procedures as examples. Whoever performs it, the party should report directly to the board of directors or to a designated board committee comprised primarily, or completely, of outside directors. That reporting line is what makes the testing independent, which means independence is a relationship rather than a qualification: the same capable person can be independent one year and not the next.
For banks, 31 CFR 1020.210 requires a written program approved by the board that provides for a system of internal controls to assure ongoing compliance; independent testing for compliance conducted by bank personnel or by an outside party; designation of an individual or individuals responsible for coordinating and monitoring day-to-day compliance; training for appropriate personnel; and appropriate risk-based procedures for conducting ongoing customer due diligence. The statutory basis is 31 U.S.C. 5318(h). Worth knowing: for banks the requirement lives in two parallel rulebooks, because each federal banking agency maintains its own program regulation alongside Treasury's - 12 CFR 208.63 for the Federal Reserve, 326.8 for the FDIC, 748.2 for the NCUA and 21.21 for the OCC.
Yes, and only in one direction. The FFIEC manual says more frequent independent testing may be appropriate when errors or deficiencies in some aspect of the program have been identified, or to verify or validate mitigating or remedial actions. Testing may also be prompted by significant changes in the risk profile, systems, compliance staff or processes. What the guidance never does is extend the interval: a clean report does not buy an institution more time, it simply fails to shorten the clock. That asymmetry is unusual. On many recurring obligations, completing the work resets the interval to its maximum. Here the audit's own output is an input to the audit schedule, and it can only compress it - so the practical task is making sure the shorter interval a finding implies is written down as an actual date rather than left as an intention in a remediation memo.
Not as a specific legal requirement today, which surprises people given how central it is. The FFIEC manual says that while not a specific legal requirement, a well-developed BSA/AML risk assessment assists the bank in identifying money-laundering and illicit-finance risks and in developing appropriate internal controls, and that documenting it in writing is a sound practice. So it currently has no mandated form, content or refresh date - while being the thing risk-based independent testing is calibrated against, since risk-based testing focuses on the areas the risk assessment identifies as highest-risk. FinCEN published a proposed AML/CFT program rule in April 2026 that would require programs to be based on a documented risk assessment process. That rule is proposed and not in force, so treat it as something to watch rather than to plan around.
Because no rule states a bank's testing frequency, nothing goes overdue in the ordinary sense - no expiry passes and no regulator writes. What happens instead is that examiners assess whether the interval the institution chose was commensurate with its risk, judged after the fact and against a risk profile that has been moving the whole time. The common failures are an interval that quietly stretched while nobody counted, an interval that stayed the same while the institution grew into new products, customer types or geographies, testing that does not count because the person who performed it was not independent, and findings that were never validated by a follow-up test. BSA/AML deficiencies sit at the severe end of financial regulation, driving supervisory findings, formal enforcement actions, civil money penalties and in serious cases restrictions on the institution, including on expansion and acquisitions.
No. Remindax tracks the independent-testing, risk-assessment and training dates and reminds the people responsible for them. It does not conduct or scope independent testing, run an AML program, monitor transactions, screen sanctions, file SARs or CTRs, hold customer or transaction data, or provide compliance or legal advice. The testing itself is performed by internal audit, outside auditors, consultants or other qualified independent parties, and the program is yours. What Remindax adds is that the interval exists somewhere other than in one person's memory - which matters more here than on most obligations, because nothing external supplies this date.
Yes. Each entity carries its own independent-testing interval, risk-assessment refresh and training cycle, with its own reminders and its own record - affiliated institutions, a bank and its MSB subsidiary, or entities that sit under different regulators and therefore under genuinely different rules. That separation matters because one entity being current says nothing about the next, and because a broker-dealer subsidiary on a calendar-year FINRA obligation and a bank with no stated frequency are not on the same clock even inside one group.
Yes - a forever-free plan, no credit card required.
Bank Secrecy Act obligations differ by institution type and are administered by FinCEN alongside the federal banking agencies, FINRA and other functional regulators, each with its own rules and examination expectations. FinCEN's April 2026 proposed AML/CFT program rule is not final and would change parts of what is described here. Remindax tracks the dates and reminds you; it doesn't conduct testing, run your program, monitor transactions, file reports or advise on compliance matters. Confirm what applies to your institution with your regulator, your examiners and your own counsel; this is general information, not compliance or legal advice.
11. Sources & references
This page summarizes public requirements and isn't compliance or legal advice. Independent testing frequency is risk-based and, for banks, is not set by any rule — what is adequate for one institution is not adequate for another. Requirements also differ by institution type and regulator, and FinCEN's proposed program rule is not final. Confirm what applies to you with your regulator, your examiners and your own counsel, and with the official sources below.
- •FFIEC — BSA/AML Examination Manual: BSA/AML Independent Testing — the source of the statement that there is no regulatory requirement establishing BSA/AML independent testing frequency; of the guidance that frequency should be commensurate with the institution's risk profile and overall risk management strategy, with periodic intervals “for example, every 12-18 months”; of the expectation of more frequent testing where errors or deficiencies are identified or to verify remedial actions; of who may perform the testing and the exclusions that keep it independent; and of the requirement that the party conducting it report directly to the board or a designated board committee comprised primarily, or completely, of outside directors.
- •31 U.S.C. 5318(h) — Anti-money laundering programs — the statutory basis described in section 1: the requirement that financial institutions establish AML/CFT programs including, at a minimum, internal policies, procedures and controls, a designated compliance officer, an ongoing employee training program and an independent audit function to test the programs. It also carries the national AML/CFT priorities the Secretary must establish and update not less frequently than once every four years.
- •31 CFR 1020.210 — AML program requirements for banks — Treasury's implementing rule for banks, and the source of the components listed in section 1.1, including “independent testing for compliance to be conducted by bank personnel or by an outside party” and the risk-based ongoing customer due diligence procedures. It is also the demonstration of the central point of this page: the rule states no testing frequency.
- •31 CFR 1022.210 — AML program requirements for money services businesses — the MSB rule referenced in section 2: it requires the program to provide for independent review to monitor and maintain an adequate program, states that the scope and frequency of the review shall be commensurate with the risk of the financial services provided, and permits an officer or employee of the MSB to conduct it provided they are not the person designated for day-to-day compliance.
- •FINRA Rule 3310 — Anti-Money Laundering Compliance Program — the source of the broker-dealer position described in section 2: annual independent testing on a calendar-year basis by member personnel or a qualified outside party, reduced to every two years (also on a calendar-year basis) for members that do not execute transactions for customers, hold customer accounts or act as an introducing broker, together with the requirement to designate and identify the responsible individuals to FINRA.
- •FinCEN — Anti-Money Laundering and Countering the Financing of Terrorism Programs (proposed rule, April 2026) — the proposal referred to in sections 1.1 and 9. It is a proposed rule, published 10 April 2026 with the comment period closed in June 2026, and it is not in force. It would revise the program requirements described on this page, including by requiring programs to be based on a documented risk assessment process. Check its status before relying on anything it contains.
- •Your federal functional regulator and examiners — the Federal Reserve, FDIC, NCUA or OCC for banks and credit unions, each maintaining its own program regulation alongside Treasury's (12 CFR 208.63, 326.8, 748.2 and 21.21 respectively), plus FinCEN, FINRA or the SEC as applicable. Because the adequacy of a testing interval is assessed at examination against a particular institution's risk profile, this is the only place a specific institution's position can be confirmed.