How to Choose a BSA/AML Replacement for Your Credit Union
- 11 minutes ago
- 6 min read
Last updated: August 13, 2026 | By: Justin Fischer, CEO and Co-Founder
Key Summary
Replacing a BSA/AML platform takes longer than most credit unions expect. Evaluation, demos, references, negotiations, implementation, testing, training, and a parallel run each take time, and delays can add up across the process. RiskScout recommends starting the search a full year before renewal.
Why might a credit union consider replacing its BSA/AML system?
Credit unions are already making these replacement decisions. Cornerstone Advisors' 2026 What's Going On in Banking report found that 13% of credit unions planned to select a new or replacement fraud/BSA/AML system in 2026, after 15% completed one in 2025. Credit unions use these systems for transaction monitoring, alert investigation, customer or member risk assessment, case management, and regulatory filings. A replacement search usually begins because the current system creates too much work outside the platform, requires spreadsheets or constant tab switching, costs too much, misses needed activity, or lacks capabilities such as fraud.
When should a credit union start looking for a replacement?
RiskScout recommends that credit unions start looking for a replacement a full year before their current contract renews. Evaluation takes time once demos, references, negotiations, and contract redlines are counted. Then implementation begins, and core data extraction, configuration, testing, and training each take time to ensure all transaction and member information is flowing and processing as expected.
Vendors may quote shorter implementation timelines, but cores can be slow to deliver files, staff take time off, and priorities shift mid-project. Estimate how long each step can take at the credit union, then assume the longer path. Institutions that get caught short may end up re-signing with the vendor they wanted to leave or be on the hook to pay two different vendors while the project wraps up.
Why do examiners want a side-by-side parallel run?
Examiners want your new and old BSA systems to run in parallel because differences in alert results can show whether the new system is tuned correctly. If one system catches activity the other does not, the BSA Officer should investigate why and whether the alert should have triggered. Running both systems for a period of time lets the BSA Officer find those gaps before an examiner does, and document the comparison as evidence the transition was controlled.
How can a slow start increase replacement costs?
Typical BSA/AML contracts run three to five years. A credit union with less than a year before renewal should confirm whether a one-year extension is available with their current system to better understand their true timeline before moving too far into the evaluation. Shorter renewals may offer less pricing flexibility, and your board may need to approve old and new system costs at the same time. Starting early preserves more options and reduces the risk of a delayed switch becoming too expensive.
How should a credit union define what it needs in a replacement?
Start with a list of what the current solution already covers, why the credit union is leaving, and what the program will need next.
What does the current solution already do well?
Which limitations or missing capabilities are driving the search?
Which spreadsheets, separate tabs, or third-party tools should the replacement absorb?
Has growth changed how many staff members or teams need access?
Should fraud and BSA casework share one system and audit trail?
Have you entered new markets like money services business, private ATMs, or cannabis that require different due diligence, monitoring, or reporting workflows?
The RiskScout BSA/AML platform combines behavior-based transaction monitoring, dynamic risk scoring, case management, direct SAR and CTR filing, integrated OFAC scanning, and due diligence workflows in one platform designed by former regulators and BSA Officers.
What questions belong in every demo?
As the credit union evaluates BSA/AML systems, keep one consistent list of questions for every vendor. Record the answers for easy comparison across platforms.
How does data migrate from the current system, and who does that work?
What does implementation support include, and what is the realistic timeline for an institution this size?
How does alert tuning work, and can rules be tested before they go live? (Some vendors sell the test environment separately; RiskScout includes a built-in sandbox for trying rules before they touch production.)
How is pricing structured as assets grow?
What do examiners say about the platform in the field?
How frequently do alerts come into the system: nightly, intraday, or real-time? Are there different costs associated with each method?
How often does the vendor's product team add new features and improvements? (Some platforms have stopped active development entirely, while RiskScout continues adding product improvements.)
What does examiner-readiness look like in a new platform?
Examiner-readiness starts with documented risk coverage, explainable alerts, and filing audit trails an examiner can trace end to end. The FFIEC BSA/AML Examination Manual provides the regulatory framework, while FinCEN's filing information page covers filing requirements. Every alert should show why it fired, every case should show its decision history, and every filing should preserve a traceable audit trail.
Platforms built by people who have run exams tend to structure records this way by default. RiskScout's Chief Product Officer is a former OCC bank examiner, and many team members are former BSA Officers who joined to build the solution they wish they had in the role. The platform provides one-click access to examiner-ready documentation, including CTR Exempt reports, No SAR lists, Quality Assurance testing, and other examiner-ready records. For a structured program review, use RiskScout's BSA/AML 5 Pillars Program Review Checklist.
Talk through a replacement timeline
Before the first vendor conversation, gather the current renewal date, contract notice period, required integrations, outside spreadsheets, user needs, and planned program changes. RiskScout offers a free advisory session to walk through the timeline, migration path, and questions to resolve before a demo to help you get started. Reach the team through the contact page.
Frequently Asked Questions
What are the alternatives to an outdated BSA/AML system for credit unions?
Options range from manual processes to integrated platforms, with greater scope and complexity at each step.
Manual processes and spreadsheets for monitoring, documentation, and follow-up.
Pros: Very low overhead costs.
Cons: High risk and not examiner-friendly. This approach relies on institutional knowledge and can create serious issues during examinations or when a BSA Officer leaves or retires. It also does little to detect fraud or support new market opportunities.
A core-provided BSA solution.
Pros: Often inexpensive, especially when bundled with the core contract. Provides basic BSA capabilities without increasing vendor sprawl.
Cons: Growing institutions may still need manual processes and third-party systems. Common concerns include limited product support, slow development of new features and regulatory updates, and staff-intensive workflows for basic tasks.
Standalone tools for functions such as OFAC scanning, negative news monitoring, due diligence, or fraud detection.
Pros: Allows institutions to select specialized vendors that excel in specific areas and expand their capabilities without replacing existing solutions or committing to a large new system.
Cons: Managing more vendors can become expensive and time-consuming. Data may not flow between systems, making it difficult to create a complete member profile. A collection of disconnected tools can also become costly to operate.
An integrated platform that combines BSA/AML and fraud in one system.
Pros: Work can be completed within one unified system, with fewer vendors and contracts to manage. Consolidated data simplifies maintenance and reporting, while user permissions allow multiple teams to use the platform without creating confusion. BSA/AML and fraud work can be completed without repeatedly switching tabs or signing in to separate systems.
Cons: Depending on the vendor, an integrated platform may cost more and require a longer implementation period, particularly when coordination with the core provider is involved.
RiskScout is an integrated option for community financial institutions, offering direct FinCEN filing and support for higher-risk market programs. Its BSA solution combines transaction monitoring, risk scoring, 314(a) support, onboarding and due diligence, case management, fraud tools, and support for higher-risk markets in one system.
What data needs to migrate when switching BSA/AML systems?
The migration covers transaction history from the core, member risk profiles, open and historical cases, and any watchlist or exemption records. The migration plan should name who extracts each dataset, who validates it, and how open investigations transfer without losing their history.
The FFIEC BSA record-retention appendix explains that most specified BSA records must remain accessible for at least five years, although the exact retention period depends on the record type. Before leaving the old system, confirm who owns the historical data, how it can be exported, and how the credit union will access retained records after the contract ends.
Does switching BSA/AML software draw examiner scrutiny?
Examiners expect a documented transition. That means a project plan, validation that the new system covers the institution's risks, and proof the old and new systems were compared before cutover. A controlled, documented switch shows examiners a program in charge of its own transition.
Who should be involved in the platform decision?
Who participates depends on the credit union's size, structure, and available resources. At minimum, involve the BSA Officer, IT or the core liaison, fraud leadership when it is separate, the CFO or another finance leader, executive leadership, and appropriate board or committee oversight. The decision should be a group effort with one clear owner.
Meet the Author:

Justin Fischer, CEO and Co-Founder of RiskScout
Justin Fischer, CAMS, is Co-Founder and CEO of RiskScout. He has more than 21 years of financial technology experience, with a focus on community financial institutions, business growth, and user experience. Before founding RiskScout, Justin held executive roles at Q2, including Senior Vice President of Operations during the company’s path toward its 2014 IPO. He has also been featured in Forbes for his expertise in BSA compliance technology and higher-risk banking.




