BSA/AML 5 Pillars Program Review Checklist
Updated: Aug 12
Last updated: July 25, 2026 | By: Kristin Parker, SVP of Customer Success
Key Summary
FinCEN requires every BSA program to stand on five pillars: internal controls, independent testing, a designated BSA officer, training, and customer due diligence. RiskScout's downloadable checklist walks compliance teams through 34 checkable items across all five pillars so gaps surface before examiners find them.
FinCEN outlines 5 essential pillars for all BSA compliance programs, explained further in the FFIEC Exam Manual. This interactive checklist gives BSA Officers and AML teams a structured framework to assess their program against all five required pillars before gaps become exam findings.
Work through each section to see where your program is solid and where it needs attention. Built around the same framework examiners use, it covers Internal Controls, Independent Testing, BSA Compliance Officer, Training, and Customer Due Diligence.
What's included:
34 checkable items across all five BSA/AML compliance program pillars
Plain-language descriptions of what each pillar requires
A practical tool for annual reviews, new hire onboarding, or exam prep
The Five Pillars
Internal Controls: policies, procedures, and system limits matched to the institution's risk profile.
Independent Testing: periodic program reviews by parties not involved in running it.
BSA Compliance Officer: a designated, qualified individual with real authority and resources.
Training: ongoing, role-specific training with documented completion.
Customer Due Diligence: risk-based CDD including beneficial ownership requirements under FinCEN's CDD Rule.
The downloadable checklist turns each pillar into specific questions your program either passes or doesn't, before your examiner asks them.
Frequently Asked Questions
What are the five pillars of a BSA/AML compliance program?
Internal controls, independent testing, a designated BSA compliance officer, training, and customer due diligence. The first four come from the Bank Secrecy Act's original program requirements; customer due diligence was added by FinCEN's CDD Rule and is commonly called the fifth pillar.
What is the fifth pillar of BSA compliance?
Customer due diligence. FinCEN's CDD Rule, effective in 2018, made risk-based customer due diligence and beneficial ownership identification an explicit program requirement, and the industry has called it the fifth pillar since.
How often should a BSA program be reviewed against the five pillars?
At least annually, as well as any time the institution's risk profile changes: new markets, significant growth, or new products. Many teams align the five-pillar review with their independent testing cycle so findings feed directly into remediation.
What helps community bankers reduce BSA exam prep time?
A current risk assessment, a documented five-pillar review, and casework that lives in one system instead of spreadsheets. RiskScout's
Related: Risk Assessment Template | BSA/AML Platform was built by former examiners to keep programs examiner-ready year-round rather than scrambling before an exam.
Meet the Author:

Kristin Parker, SVP of Customer Success
Kristin is a seasoned expert in BSA/AML and fraud prevention, with extensive experience building and implementing monitoring programs for higher-risk industries. She has contributed to significant updates in the FFIEC manual, provided practical, risk-based AML guidance at industry events, and played a key role in the development of RiskScout’s innovative, actionable BSA solutions. Recognized by her peers as PBC's 2024 Compliance Person of the Year, Kristin continues to champion efficient, technology-driven approaches that empower financial institutions to confidently manage regulatory requirements.




