NewsWhat Are AML Internal Controls for Cash and Who They Apply To
AML internal controls for cash are the documented policies, procedures, monitoring rules, and operational safeguards used to detect, prevent, and report money laundering that flows through physical currency. Banks, credit unions, money services businesses, and other institutions covered by the Bank Secrecy Act (BSA) must build these controls into a written, board-approved AML program that FinCEN and their federal or state regulator can examine.
Ordinary cash-intensive businesses, retailers, restaurants, contractors, and car dealers aren't automatically subject to that same bank-style program just because they handle cash. Their main BSA-related obligation is usually Form 8300 reporting, covered later in this guide, not a full five-pillar program. This framework is written primarily for covered financial institutions, with cash-intensive-business obligations called out separately where the two diverge.
Cash carries a distinct compliance risk: physical currency has fewer built-in data points than an electronic payment, which typically carries originator, beneficiary, and routing information across every institution that touches it. That doesn't make electronic channels low-risk, and wire and ACH layering are real problems too, but a cash deposit relies more on what the institution independently verifies than on data the transaction itself supplies. Cash programs need controls layered on top of a general AML framework, not a substitute for one.
The BSA's Minimum Program Requirements and Where Cash Controls Fit
The BSA requires covered institutions to build their AML program around four minimum components: a system of internal controls, independent testing, a designated BSA compliance officer, and training for personnel whose duties touch BSA/AML compliance. FinCEN's 2016 Customer Due Diligence (CDD) Final Rule added risk-based CDD, commonly described as a fifth pillar, and made beneficial ownership identification and verification for legal entity customers a requirement within that CDD pillar, not a separate sixth pillar.
Together, industry practice shorthands these as the five pillars:
-
Internal controls — written policies and procedures that govern how cash is handled, monitored, and reported at every stage of the transaction lifecycle
-
Designated compliance officer — a named individual with actual authority over the AML program, including cash monitoring, SAR filing decisions, and training oversight
-
Training — for personnel whose duties require BSA/AML knowledge, covering red flag recognition, CTR triggers, and escalation procedures
-
Independent testing — periodic audits of the AML program conducted by a party without day-to-day compliance responsibility
-
Risk-based customer due diligence (CDD), including beneficial ownership identification and verification for legal entity customers, enhanced due diligence applies on top of standard CDD for higher-risk relationships, not as a separate statutory pillar
Cash programs apply all five pillars to physical currency, and BSA/AML examiners assess the program and each component as part of a risk-focused exam. Consequences scale with severity: FFIEC guidance treats isolated or technical deficiencies differently from failures significant enough to render a program ineffective as a whole. A structured Anti-Money Laundering (AML) and Fraud Prevention course gives compliance officers and cash-handling staff a shared baseline across all five pillars.
Risk Assessment Comes Before Cash-Specific Controls

A BSA/AML risk assessment determines which cash-specific controls a program actually needs; it isn't a fixed checklist applied uniformly. FFIEC's internal-controls guidance states that internal controls "should be commensurate with the bank's size or complexity and organizational structure," built from an assessment of customer types, products, geographies, cash volume, and delivery channels. A community bank with modest retail cash deposits needs a different control set than a regional bank processing high cash volumes for money services businesses. Every control described below should scale from that assessment.
Worth watching, though not yet a requirement: on April 7, 2026, the federal banking agencies proposed a new AML/CFT Program Requirements rule that would build a mandatory risk-assessment process directly into the internal-controls pillar. The proposal remained in its public comment period as of this writing, a preview of where the framework is headed, not a current obligation.
The beneficial ownership piece of CDD also changed in 2026. On February 13, 2026, FinCEN issued an exceptive relief order letting institutions verify a legal entity customer's beneficial owners at three triggers: account opening, facts that call existing information into question, or the institution's own risk-based ongoing due diligence schedule instead of at every new account. Adopting the narrower standard is a choice, not a mandate: FinCEN's CDD Rule FAQs confirm an institution may elect the relief or keep its existing verification process and either satisfy the rule or not.
Cash Transaction Monitoring Scenarios: Building Rules That Catch Real Risk
Cash transaction monitoring requires scenario design that accounts for how physical currency actually moves, not how wire transfers or ACH payments move. A monitoring rule built for digital transactions will consistently miss the patterns that matter most in cash environments.
Depending on an institution's risk profile, cash-monitoring scenarios may include:
-
Structuring detection — rules that identify below- $10,000 deposits made across multiple days or branches in a pattern consistent with avoiding Currency Transaction Report (CTR) filing obligations
-
Velocity monitoring — alerts triggered when deposit frequency or volume increases significantly over a rolling window without a documented business reason; 30 or 60 days is a common configuration, not a fixed standard
-
Round-dollar deposit rules — flags for recurring deposits in even amounts with no supporting sales data
-
CTR-adjacent activity — monitoring for deposits that cluster just below the $10,000 CTR filing threshold over time
-
Peer group anomalies — alerts triggered when cash volume is a statistical outlier against a customer's assigned peer group by industry, size, and geography; a 90th-percentile cutoff is illustrative, not a federal standard
Thresholds set too low produce alert fatigue; too high, they miss real activity. Institutions should document their threshold rationale and tuning history FFIEC doesn't mandate specific numbers, but expects a program to explain the ones it chose.
FRAML: Integrating Fraud and AML Controls for Cash
Framework for the integration of fraud and AML compliance functions is an operational approach more institutions are adopting to close the gap between fraud detection and AML monitoring. Cash programs are a natural place to start, since many behaviors that indicate first-party fraud can also indicate money laundering.
A teller who underreports a cash deposit and pockets the difference creates a record that can overlap with or obscure a structuring pattern. A business owner who inflates daily sales to justify large deposits may be layering illicit cash through legitimate-looking revenue. A customer who presents false identification for below-threshold transactions may be committing identity fraud while also smurfing on behalf of a laundering network.
Siloed fraud and AML teams can miss this overlap when they aren't sharing alert data a fraud case opened on a teller for cash shortages may never reach the BSA officer, leaving a structuring pattern underneath it undetected. Building a FRAML framework for cash means putting a shared escalation path in writing, with a business-day timeline the institution sets based on its own risk, rather than assuming the two teams will coordinate informally.
AI-Driven AML Compliance for Cash Programs: What Machine Learning Changes
AI-driven tools can complement rules-based monitoring by flagging statistical anomalies that predefined scenarios miss, which is useful in cash programs, where laundering typologies evolve faster than any static rule set. A rules-based system flags behavior matching a known pattern; an unsupervised machine learning model flags behavior that's statistically anomalous for a given customer, including patterns compliance teams haven't documented yet.
That raises a documentation question: when a model generates an alert leading to a SAR filing, examiners generally expect the institution to explain why. As of April 17, 2026, the reference point is SR 26-2, the Federal Reserve, OCC, and FDIC's revised model risk management guidance, replacing the 2011 SR 11-7 framework and the 2021 interagency statement on BSA/AML model risk. SR 26-2 is supervisory guidance, not an enforceable rule; the agencies say non-compliance alone won't trigger supervisory criticism aimed primarily at institutions above $30 billion in assets, though smaller ones with meaningful model risk may still be expected to apply it.
It keeps the old substance document model logic, validates outputs, and keeps human review in the loop but excludes generative and agentic AI tools from its model definition. That doesn't leave those tools ungoverned; institutions still need their own governance over generative or agentic AI used in monitoring, just not necessarily through the SR 26-2 process. Ask a vendor which category its "AI-driven" tool falls into before assuming SR 26-2 governs it.
Whatever the model, an AI-generated alert should feed the institution's own documented investigation and SAR decision process rather than substitute for it. The SAR narrative should reflect an investigator's assessment, not a model's output copied into a text field. Vendor selection deserves the same risk-based lens: model validation against U.S. cash typologies and alert explanations that meet the institution's documentation standards are reasonable questions, not a federal checklist.
Cash-Specific Operational Controls: The Layer Beneath the AML Program
Cash-specific operational controls are the physical and procedural safeguards that make AML monitoring data reliable. If the underlying cash handling process isn't controlled, the transaction data feeding the monitoring system isn't trustworthy, and that system can't detect what it can't see accurately.
Examples of cash-specific operational controls, scaled to what the institution's size and risk assessment call for, include:
-
Dual control for cash counting and deposit preparation — two employees independently verifying the cash count, to the extent possible, reduces the chance a single employee manipulates a deposit amount undetected
-
Daily cash reconciliation — reconciling each drawer, vault, or register to the day's transaction records before close of business, with unexplained variances escalated and documented rather than adjusted and closed
-
Surprise cash counts — periodic unannounced counts conducted by someone outside the cash-handling chain, functioning as both a control check and a deterrent
-
Cash handling limits — maximum drawer amounts and transaction limits for individual cashiers, sized to the institution's own risk tolerance
-
Physical access logs — vault access logged by employee name and timestamp, which examiners and fraud investigators both rely on
These sit underneath the same risk-based compliance framework that governs the rest of the AML program: written procedures, a named owner, and evidence the control actually ran on the day in question.
CTR and Form 8300 Internal Controls: The Filing Process That Must Be Airtight

Banks generally file a Currency Transaction Report (CTR) with FinCEN when currency transactions by or on behalf of the same person aggregate to more than $10,000 during a single business day. The internal controls surrounding CTR preparation, review, and submission are themselves an examination focus, not just the filings.
A practical CTR control framework should address four process steps: trigger identification (the procedure that recognizes when a transaction meets or aggregates to the filing threshold), aggregation logic (combining same-day transactions from the same customer across tellers, branches, or accounts), quality review (a designated reviewer checking accuracy before submission), and deadline tracking (FinCEN requires CTR filing within 15 calendar days of the triggering transaction).
Form 8300 applies to non-bank businesses, auto dealerships, jewelers, real estate brokers, and other cash-intensive trades receiving more than $10,000 in cash in a single transaction or related transactions. Businesses can use a similar control structure for Form 8300, adapted to its specifics: a named trigger-identification process, an aggregation procedure for related transactions, a review step before filing, and a recordkeeping system that retains copies for five years.
One 2026 correction worth flagging: FinCEN removed the Corporate Transparency Act's beneficial ownership reporting requirement for U.S. companies and persons in 2025 and made that permanent in August 2026, so domestic Form 8300 filers no longer have a parallel CTA filing obligation. That's a separate population and rule from a bank's own CDD-rule beneficial ownership requirements, which the CTA change doesn't touch. A bank still identifies and verifies its legal entity customers' beneficial owners under CDD via its existing account-opening process or the narrower triggers under FinCEN's February 2026 exceptive relief, at its election.
Employee Training Controls What Cash-Handling Staff Must Know

BSA-mandated AML training is required for personnel whose duties require BSA/AML knowledge in a cash-handling environment, generally tellers, cash-services staff, and their supervisors. Examiners test whether training occurred, what it covered, how it was documented, and whether personnel can demonstrate the knowledge it conveyed.
Depending on the role, cash-specific AML training may need to cover:
-
Structuring recognition — identifying customer behavior that indicates attempts to break transactions below the CTR threshold, including customers who make multiple trips in a single day or ask about the $10,000 limit
-
CTR filing obligations — the $10,000 threshold, the 15-day filing deadline, and the aggregation requirement for same-day related transactions
-
Form 8300 obligations — for personnel at non-bank businesses subject to the form, the filing threshold, the 15-day deadline, and the requirement to give each customer named on the form a written statement by January 31 of the following year (a business voluntarily filing Form 8300 to report a suspicious transaction of $10,000 or less is exempt from that customer-statement requirement)
-
Red flag escalation — the specific steps an employee takes when they observe suspicious cash handling, including who they report to and what they document
-
Tipping-off — employees can't disclose that a SAR has been filed or share information revealing a SAR's existence, to the customer it concerns; unauthorized disclosure is a federal crime under 31 U.S.C. § 5318(g)(2). That doesn't bar ordinary internal discussion of suspicious activity through proper channels the restriction is specifically about tipping off the person the report concerns
Training frequency should be periodic and risk-based: FFIEC's training guidance calls for training that reflects current developments rather than a fixed annual cycle for every role. Records should include training materials, session dates, attendance, and any failures to complete required training, available for examiner review.
It's worth pairing that training with a broader look at what AML compliance work actually requires so new hires understand the skill set behind the checklist, not just the checklist itself.
Independent Testing of Cash AML Controls: What the Audit Covers
Independent testing of a BSA/AML program must be conducted by a party without day-to-day compliance responsibility: internal audit staff outside the BSA/AML team, a third-party BSA consultant, or a qualified external firm, depending on the institution's size.
What gets tested is risk-based rather than fixed by regulation: policy adequacy, monitoring alert generation and disposition, CTR and SAR filing completeness, training documentation, and CDD records for high-cash-volume accounts may all be covered, as applicable to the institution's size, complexity, and risk profile.
Testing filing completeness typically involves sampling. FFIEC's testing guidance doesn't specify a methodology, so testers generally use risk-based transaction sampling to verify required filings were made, aggregation was applied correctly, and SAR referrals were generated for suspicious patterns. Deficiencies identified should be documented and reported to the board or a designated committee in a timely manner.
The written report should document scope, methodology, sample size, findings, and corrective actions with assigned owners and target dates. Examiners review relevant testing reports and workpapers as part of risk-focused BSA/AML supervision. Testing frequency isn't fixed by regulation; FFIEC cites every 12 to 18 months only as an example, tied to the institution's own risk profile.