Skip to content
complianceofficer

Bank compliance software for financial institutions, built around BSA/AML and your compliance management system

Bank compliance software has to carry two loads that general GRC tools were never built for: a BSA/AML program that meets 31 CFR 1020.210 element by element, and a compliance management system an examiner can walk through in the order the FDIC manual describes it. Complianceofficer watches the federal sources directly, maps each obligation to the policy and control you already have, and flags the line that moved when FinCEN, the OCC, the FDIC or the CFPB publishes.

Verified against the eCFR and the Federal Register API on 5 August 2026. Every regulatory claim on this page links to the primary source, not to a vendor summary.

Scan your institution's obligations now

Pick banking or credit union below. The scan returns the register of federal obligations that applies to an institution of your type and size, with the last 12 months of regulatory movement and every source linked. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 22 What it has to cover

What bank compliance software has to cover that generic GRC does not

A SaaS company buying compliance software is usually chasing one certification. A bank is supervised continuously, by more than one agency, against rules that sit in three different titles of the Code of Federal Regulations. The software has to hold consumer compliance, the BSA/AML program, safety and soundness expectations and third party risk in one place, and it has to produce evidence in the shape the examiner asks for rather than in the shape the vendor's dashboard prefers.

The practical test is simple. Ask whether the tool can answer, for any single obligation, three questions at once: which rule requires this, which policy and control satisfies it, and when did either of those last change. Most platforms answer two of the three. The third is where exam findings come from.

Domain Primary authority What the software must hold Where it usually breaks
BSA/AML program 31 CFR 1020.210 Five program elements, each with named owner and evidence Independent testing scope drifts from the risk assessment
Suspicious activity reporting 31 CFR 1020.320 Detection date, 30 and 60 day clocks, decision rationale Clock starts at case assignment, not initial detection
Currency transaction reporting 31 CFR 1010.311 Aggregation logic and exemption records Exemptions granted once and never re-reviewed
Consumer compliance CMS FDIC Consumer Compliance Examination Manual II-3 Board oversight plus the four program components Complaint response treated as a service metric, not compliance
Consumer lending and deposits Regulations B, C, E, Z, DD Rule to procedure to control mapping, with change history Threshold and indexing updates missed at year end
Risk governance 12 CFR part 30, appendix D Three lines of defense, escalation, board reporting Applied at the wrong asset threshold (see below)
Third party risk Interagency guidance, 2023 Vendor inventory tied to the obligations they touch Fintech partners onboarded outside the vendor process

Transaction monitoring itself is covered on AML transaction monitoring, and the risk governance side on enterprise risk management software.

The five BSA/AML program elements, as the regulation words them

31 CFR 1020.210 is short, and worth reading in the original rather than in summary. A bank regulated by a federal functional regulator satisfies 31 USC 5318(h)(1) if its program includes, at a minimum, the five items below. Nothing in the text sets a testing frequency, a sample size or a scoring model. Those come from examiner expectation and practice, which is exactly why they drift.

  • § 01 A system of internal controls to assure ongoing compliance 1020.210(a)(2)(i)
  • § 02 Independent testing, by bank personnel or an outside party (a)(2)(ii)
  • § 03 A designated individual for day-to-day compliance (a)(2)(iii)
  • § 04 Training for appropriate personnel (a)(2)(iv)
  • § 05 Risk-based ongoing CDD, including beneficial ownership (a)(2)(v)
  • § 06 The proposed AML/CFT reform, not yet final pending

The fifth element is the one that ages fastest. Ongoing customer due diligence is not a onboarding checkbox: the regulation requires understanding the nature and purpose of the relationship to build a customer risk profile, and then monitoring on a risk basis to keep that profile current. A program that collects beneficial ownership at account opening and never revisits it satisfies the form of the rule and not the substance, and independent testing is where that gets written down.

§ 23 What the market gets wrong

Three things vendor pages in this category state incorrectly

1. The new FinCEN AML/CFT program rule is not in force

A lot of banking compliance content now sells against a deadline that does not exist. FinCEN's rule to reform AML/CFT program requirements under the AML Act of 2020 is still a proposed rule. The current notice of proposed rulemaking was published on 10 April 2026 (Federal Register document 2026-07033), comments closed on 9 June 2026, and FinCEN proposes that any final rule take effect 12 months after issuance. The FDIC, OCC and NCUA issued a parallel proposal to align their own program rules. A Federal Register query for final rules under that title returns nothing for the bank program as of 5 August 2026.

So the operative standard today is still 31 CFR 1020.210. If a platform tells you its roadmap is built around an effectiveness-based program requirement that is already binding, it is describing a proposal.

2. A compliance management system has two elements, not three pillars

The FDIC's Consumer Compliance Examination Manual is explicit: an effective CMS is commonly comprised of two interdependent elements, board and management oversight, and a consumer compliance program. The program then has four components: policies and procedures, training, monitoring and/or audit, and consumer complaint response. The widely repeated three pillars framing collapses the structure and usually drops consumer complaint response, which is the component examiners reach for first because complaints are the cheapest available signal that a control is not working.

3. The OCC heightened standards threshold is still $50 billion

Appendix D to 12 CFR part 30 continues to apply at $50 billion in average total consolidated assets. A proposed rule to raise that to $700 billion was published on 30 December 2025 and comments closed on 2 March 2026, but the Federal Register API confirms no final rule as of 5 August 2026. Institutions between those two figures are still inside the standards, whatever a vendor comparison chart says.

Reporting thresholds and clocks, in one place

These are the numbers that get miscited most often in internal procedures, usually because someone copied them from a training deck rather than from Chapter X. Each row below is the regulation's own wording.

Report Trigger Deadline Citation
SAR Involves or aggregates at least $5,000 and the bank knows, suspects or has reason to suspect 30 calendar days from initial detection; 60 if no suspect identified 31 CFR 1020.320
CTR Currency transaction of more than $10,000 Per FinCEN filing instructions 31 CFR 1010.311
Immediate notice Violations requiring immediate attention, such as an ongoing money laundering scheme Telephone law enforcement immediately, in addition to timely SAR filing 31 CFR 1020.320(a)(3)

Two details worth putting in your procedure verbatim. The SAR clock runs from initial detection of the facts, not from the day an analyst opens the case, and the 60 day extension exists only to identify a suspect. The CTR trigger is more than $10,000, so an exact $10,000 transaction does not require a CTR by itself.

§ 24 Who this fits

Community banks, credit unions and fintech partner banks

The institutions this fits best are the ones where compliance is two to six people rather than a department: a community bank under a few billion in assets, a credit union, or a bank running a fintech partnership program where the obligations move faster than the policy review cycle. In all three, the constraint is not knowing what the rules are. It is noticing, in the same week it happens, that one of them changed and that a procedure now describes something the bank no longer does.

Larger institutions with an established GRC suite generally use this alongside it, as the regulatory watch layer that feeds change into the system of record. That path is described on regulatory change management, and the broader platform on GRC software.

Run the compliance scan
  • § 01 Sources watched directly FinCEN, OCC, FDIC, CFPB, NCUA
  • § 02 Each obligation, not just a feed mapped to your policy
  • § 03 Rulemaking status on every alert proposed vs final, labelled
  • § 04 Evidence with change history exam-ready export

Bank compliance software questions, answered

What software do banks use for compliance?

Most US banks run three separate systems: a BSA/AML transaction monitoring platform, a GRC or compliance management system holding policies, risk assessments and control testing, and a regulatory change feed. Core processor vendors bundle some of this. Larger institutions add a separate internal audit tool, which is why examiner-ready reporting usually still has to be assembled by hand.

What is a compliance management system in banking?

The FDIC Consumer Compliance Examination Manual defines a CMS as two interdependent elements: board and management oversight, and a consumer compliance program. The program has four components, being policies and procedures, training, monitoring and/or audit, and consumer complaint response. It is two elements, not the three pillars most vendor pages describe. Full detail is in our guide to the bank compliance management system.

What are the pillars of a BSA/AML program?

Under 31 CFR 1020.210 a bank AML program must include, at a minimum, internal controls, independent testing, a designated compliance individual, training for appropriate personnel, and risk-based ongoing customer due diligence including beneficial ownership. The fifth element, CDD, arrived with the 2016 rule, which is why the program is now commonly called five pillars rather than four.

Did FinCEN finalize the new AML/CFT program rule?

No. As of August 2026 the AML/CFT program reform is still a proposed rule. FinCEN published its notice of proposed rulemaking on 10 April 2026, document 2026-07033, with comments closing 9 June 2026, and proposes a 12-month effective date after any final rule. Until a final rule issues, 31 CFR 1020.210 remains the operative program standard.

When does a bank have to file a SAR?

A bank files no later than 30 calendar days after initial detection of the facts that may justify filing. If no suspect has been identified, filing may be delayed a further 30 days, but never beyond 60 calendar days from initial detection. The threshold is transactions involving or aggregating at least $5,000 where the bank knows, suspects or has reason to suspect one of the listed conditions.

What is the CTR threshold for banks?

Under 31 CFR 1010.311 a financial institution files a currency transaction report for each deposit, withdrawal, exchange or transfer in currency of more than $10,000. The wording is more than $10,000 rather than $10,000 or more, so a single transaction of exactly $10,000 does not trigger a CTR on its own. Aggregation rules still apply.

How much does bank compliance software cost?

Recorded purchase data puts broad GRC platforms used by financial institutions between roughly $12,000 and $136,000 a year, with medians near $45,000 to $54,000 for the enterprise suites. Dedicated BSA/AML transaction monitoring is priced separately, usually on account or transaction volume. The full vendor-by-vendor breakdown is on compliance software pricing.

Does this replace our transaction monitoring system?

No, and you should be wary of anything claiming it does. Transaction monitoring scores customer activity against typologies and needs your core banking data. Complianceofficer watches the rulebook that governs the program around it, then maps changes onto your policies and controls. Banks that run both get the alert and the regulation behind it in the same place.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.