AML/BSA Compliance Is Not Just a Banking Issue: What Banks and Insurance Companies Need to Know
- John C. Blackshire, Jr.

- Aug 13
- 6 min read
Why Bank Secrecy Act and Anti-Money Laundering Controls Matter Across Financial Services
The Bank Secrecy Act is usually associated with banks.
That is understandable.
Banks are on the front line of the U.S. financial system. They process deposits, wires, ACH payments, cash transactions, loans, and international transfers, all of which create exposure to money laundering, terrorist financing, fraud, and other illicit finance risks.
But banks are not the only financial organizations with AML responsibilities.
Certain insurance companies also fall within the federal anti-money laundering framework, particularly when they issue or underwrite products with cash value or investment characteristics. FinCEN requires covered insurance companies to establish written, risk-based AML programs and file Suspicious Activity Reports when appropriate.
That makes AML/BSA knowledge relevant to professionals across both the banking and insurance industries.
Corporate Compliance Seminars’ AML/BSA Basics and Compliance program is designed to provide professionals with a practical foundation in Bank Secrecy Act requirements, Anti-Money Laundering concepts, suspicious activity, red flags, Customer Due Diligence, KYC, reporting, fraud risk, and internal controls. The live webinar provides 2 NASBA-approved CPE credits.
Banks Remain at the Center of BSA/AML Compliance
Banks are required to maintain BSA/AML compliance programs that are commensurate with their risk profiles. FinCEN has long described core bank program elements as including internal controls, independent testing, a designated BSA compliance officer, and appropriate personnel training.
For banking organizations, the risk universe can include:
Cash transactions
Wire transfers
ACH activity
Correspondent banking
Private banking
Customer onboarding
Beneficial ownership
Structuring
Fraud
Sanctions exposure
Suspicious transaction monitoring
The compliance challenge is not simply to maintain policies.
The bank must be able to demonstrate that its controls actually identify, assess, and mitigate relevant financial-crime risks.
Insurance Companies Can Also Be Subject to AML Requirements
The insurance industry's exposure is narrower than banking, but it is still significant.
FinCEN's insurance rules apply to companies that issue or underwrite certain covered products, including:
Permanent life insurance policies other than group life
Annuity contracts other than group annuities
Other insurance products with cash-value or investment features
Why?
Because these products can sometimes be used to:
Introduce illicit funds into the financial system
Move value
Accumulate cash value
Surrender products for proceeds
Transfer ownership
Conceal beneficial interests
The insurance company therefore needs to understand not only who purchased the product, but how the product could be abused.
Insurance AML Programs Must Be Risk-Based
FinCEN requires covered insurance companies to maintain a written AML program reasonably designed to prevent covered products from being used to facilitate money laundering.
The program must be approved by senior management and should be based on the insurer's actual risk profile. FinCEN specifically notes that risk can arise from customers, products, services, and jurisdictions, and that higher-risk areas should receive greater compliance attention.
That is an important principle for auditors:
AML compliance should follow risk, not a generic checklist.
A small insurer selling straightforward products to a limited customer base should not necessarily look like a large multinational insurer offering complex products through multiple distribution channels.
The same principle applies to banks.
Banks and Insurers Share the Same Basic Control Problem
The products differ.
The control challenge is very similar.
Both industries need to ask:
Who is the customer?
What activity is expected?
What activity would be unusual?
What red flags exist?
Who investigates those red flags?
When should suspicious activity be escalated?
What evidence demonstrates that the process actually worked?
That makes AML a classic internal-control problem.
Suspicious Activity Reporting Is Critical
Suspicious Activity Reports are one of the most important elements of the AML framework.
For covered insurance companies, FinCEN's rules require suspicious activity reporting in appropriate circumstances, just as banks operate under their own SAR obligations.
A strong compliance function needs a process that moves from:
Red Flag
↓
Alert
↓
Investigation
↓
Escalation
↓
Decision
↓
SAR Filing, if required
↓
Documentation
The weakness may occur anywhere in that chain.
Red Flags Are Only Useful If Someone Acts on Them
The CCS program places significant emphasis on identifying red flags and managing AML alerts. It covers structuring, identity-theft indicators, suspicious activity, fraud overlap, alert investigation, and regulatory reporting.
That distinction matters.
A sophisticated monitoring system can produce thousands of alerts.
If:
Alerts are not investigated timely
Investigations are superficial
High-risk cases are closed without support
Escalation criteria are unclear
then the institution does not really have an effective monitoring program.
It has an alert-generation program.
Structuring Remains a Core Banking Risk
Banks have long faced structuring risk.
A customer may deliberately break a larger cash transaction into smaller transactions to avoid reporting requirements.
The CCS course includes structuring techniques, including more sophisticated approaches such as micro-structuring and cuckoo smurfing.
The auditor or compliance professional should ask:
Are transactions linked across accounts?
Across branches?
Across days?
Across related customers?
Across channels?
The transaction should not always be evaluated in isolation.
Patterns matter.
Insurance Products Create Different Red Flags
Insurance-related AML risk can look different from banking.
Potential concerns may include:
Large premium payments inconsistent with customer profile
Early surrender of a cash-value product
Unusual third-party premium payments
Frequent changes in ownership or beneficiary
Rapid movement into and out of annuity products
Payments involving higher-risk jurisdictions
The exact red flag depends on the product and customer relationship.
That is why FinCEN emphasizes risk-based programs for insurers rather than a one-size-fits-all model.
Customer Due Diligence and KYC Still Matter
CCS includes Customer Due Diligence and Know Your Customer principles as core learning topics.
For banks, CDD and KYC are fundamental parts of the compliance framework.
For insurers, the regulatory structure differs. FinCEN's insurance guidance specifically states that insurance companies are not subject to the same Customer Identification
Program rule that applies to banks, although covered insurers still need relevant customer information to operate an effective AML program.
That distinction is important.
Insurance professionals should not simply copy a bank AML program.
They need a program appropriate to the products and regulatory requirements that actually apply to them.
Internal Audit Has a Critical Role in Both Industries
Internal Audit should not own AML compliance.
Management and Compliance own the program.
Internal Audit provides independent assurance.
That assurance may include evaluating:
Governance
Risk assessment
Policies
Training
Customer due diligence
Alert handling
Investigations
SAR processes
Documentation
Corrective action
Independent testing
The auditor's central question should be:
Is the AML program operating as management says it is?
Independent Testing Is Not a Formality
Independent testing is one of the fundamental components of AML programs in both banking and covered insurance contexts. FinCEN identifies independent testing as a core element of insurer AML programs, alongside written controls, a compliance officer, and ongoing training.
The testing should be designed to determine whether the program works.
It should not simply verify that:
A policy exists
Training was scheduled
A compliance officer was named
The better questions are:
Is the risk assessment current?
Are controls aligned with risk?
Are alerts investigated?
Are suspicious cases escalated appropriately?
Are identified deficiencies corrected?
Fraud and AML Increasingly Overlap
Fraud and money laundering are frequently connected.
A fraudster must not only obtain the money.
They frequently need to:
Move it
Conceal it
Convert it
Reintroduce it into the legitimate financial system
That creates overlap among:
Fraud monitoring
AML monitoring
Cybersecurity
Identity theft
Customer due diligence
CS specifically includes fraud detection and internal controls as part of the AML/BSA curriculum.
Technology Creates Both Opportunity and Risk
Modern financial institutions use:
Transaction-monitoring systems
Sanctions-screening systems
Case-management platforms
Identity-verification tools
Analytics
AI
These systems can improve detection.
They can also produce:
False positives
Poorly calibrated rules
Excessive alert volumes
Missed suspicious activity
CCS explicitly addresses false-positive alerts, analytics engines, and fraud overlap as current compliance challenges.
The auditor should therefore understand not only whether the system exists, but whether it is working as intended.
The Regulatory Environment Is Still Evolving
The federal AML framework continues to change. FinCEN's AML Act implementation materials show ongoing modernization efforts, including an April 2026 proposed rule addressing AML/CFT program requirements.
That means training cannot be treated as a one-time exercise.
Professionals in both banking and insurance need to understand:
Current requirements
Emerging expectations
Industry-specific differences
Risk-based compliance
What Participants Will Learn
Corporate Compliance Seminars' AML/BSA Basics and Compliance program is designed to provide a practical foundation in the major concepts financial professionals need to understand.
The course covers:
AML/BSA fundamentals
Bank Secrecy Act requirements
USA PATRIOT Act provisions
Currency Transaction Reports
Suspicious Activity Reports
Customer Due Diligence
Know Your Customer
AML alert management
Structuring
Identity theft red flags
Fraud overlap
Internal controls
Compliance challenges and solutions
Who Should Attend?
The program is appropriate for:
Banking compliance professionals
Insurance compliance professionals working with covered products
AML specialists
Internal Auditors
Risk management professionals
Fraud prevention personnel
Professionals new to AML/BSA compliance
CCS lists the program at the Basic level with no prerequisites or advance preparation required. The course is presented live online and provides 2 NASBA-approved CPE credits.
The Bottom Line
AML/BSA compliance is not exclusively a banking issue.
Banks remain central to the Bank Secrecy Act framework, but certain insurance companies also have important AML obligations when they issue or underwrite products with cash-value or investment features.
The products differ.
The core compliance logic does not:
Know the risk.
Understand the customer.
Recognize unusual activity.
Investigate red flags.
Escalate suspicious activity.
Maintain strong controls.
Test whether those controls work.
Corporate Compliance Seminars' AML/BSA Basics and Compliance program is designed to give professionals in financial services the practical knowledge needed to understand those responsibilities and strengthen their organizations' defenses against money laundering, fraud, and other financial crime.
Comments