Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

AML compliance in United States: who is in scope and what is owed

How AML applies to companies operating in or serving the United States — scope tests, the obligations that follow, and the primary sources to verify each one against.

Anti-money laundering and sanctions compliance in the United States applies to financial institutions and designated non-financial businesses through frameworks administered by FinCEN and OFAC. Organizations operating within or interacting with the United States market must establish risk-based controls to identify customers, screen transactions, and report suspicious activities. This page details jurisdictional reach, statutory obligations, and areas requiring legal verification against primary authorities.

Extraterritorial Reach and Jurisdictional Scope

United States anti-money laundering and sanctions laws apply not only to domestic entities incorporated or operating within the country, but also to foreign financial institutions and commercial enterprises that have a nexus to the United States. This jurisdictional reach encompasses foreign entities that maintain correspondent accounts in the United States, clear transactions in US dollars, or target customers residing in the US market. The Financial Crimes Enforcement Network enforces rules that capture various financial intermediaries, while the Office of Foreign Assets Control administers broad economic sanctions that apply to any person or entity subject to US jurisdiction, regardless of their physical location.

Entities must evaluate whether their operational footprint triggers registration or licensing requirements under federal or state statutes. For financial intermediaries, foreign branches and certain foreign parent companies may fall under specific regulatory definitions depending on their US activities. When organizations engage in cross-border commerce or handle funds originating from or destined for US financial institutions, they must assess their exposure to domestic enforcement actions. Determining whether a specific entity is in scope requires a careful analysis of transactional flows, physical presence, and the nature of commercial interactions with US residents or entities.

Compliance teams frequently use a cross-border-compliance framework to map out jurisdictional triggers and identify potential exposures across multiple operating units. Under the framework of the Bank Secrecy Act, outlined in 31 CFR Chapter X — FinCEN Bank Secrecy Act regulations, covered entities must implement adequate procedures to detect illicit finance risks. Organizations that fail to recognize their US nexus risk severe regulatory penalties, operational disruptions, and potential civil or criminal liabilities administered by federal authorities. Legal counsel should review foreign corporate structures to confirm whether specific business units or product lines meet the statutory thresholds for regulatory oversight.

Categorization of Covered Entities and Money Services Businesses

The regulatory perimeter in the United States categorizes entities based on their financial activities rather than their self-described industry. Traditional depository institutions, broker-dealers, and insurance providers are subject to comprehensive anti-money laundering rules. In addition, entities engaging in money transmission, currency exchange, or the issuance of traveler's checks are classified as money services businesses. These businesses must evaluate their operational models against federal definitions to determine if registration with regulatory bodies is mandatory. Guidance on formal registration obligations is detailed in FinCEN — Money Services Business registration.

Failing to properly classify an organization can result in operating an unregistered financial business, which carries significant legal consequences. Entities providing emerging financial services, including digital asset activities and payment processing, must pay close attention to how regulatory definitions apply to their technology stack. The application of these rules to financial intermediaries is further examined through the money-services-business regulatory definitions provided by FinCEN. Organizations often utilize specialized agents or internal compliance teams to audit product offerings and ensure accurate entity classification across all operating jurisdictions.

To assist compliance officers in identifying operational overlap, the following table summarizes common entity types and their primary regulatory touchpoints under US law:

| Entity Type | Primary Activity | Regulatory Touchpoint | |---|---|---|> | Depository Institution | Accepting deposits, lending | Federal banking agencies | | Money Services Business | Transmission, currency exchange | FinCEN registration | | Commercial Enterprise | General goods and services | OFAC sanctions screening | | Investment Vehicle | Asset management | SEC or state regulators |

Organizations must periodically review their operational scope as business models evolve, particularly when launching new product lines or expanding into new geographic markets within the United States.

Core Obligations: Customer Identification and Due Diligence

Covered entities operating within the US regulatory perimeter must implement robust procedures to verify the identity of their customers and understand the nature of their business relationships. This obligation begins with establishing a formal customer identification program that collects baseline verification data before opening accounts or executing transactions. Organizations are required to verify the identity of individuals and legal entities using reliable, independent source documents. These foundational verification steps form the basis of effective know-your-customer processes required under federal regulations.

Beyond basic identification, institutions must perform ongoing due diligence to assess customer risk profiles and monitor transactional activity. When onboarding legal entity customers, firms are required to identify and verify the natural persons who own or control the company, adhering to specific beneficial ownership thresholds. Detailed requirements for identifying these controlling individuals are set out in the beneficial-owner regulatory definitions. Compliance teams must also deploy customer-due-diligence protocols to ensure that high-risk accounts receive appropriate scrutiny throughout the lifecycle of the business relationship.

When dealing with higher-risk relationships, such as foreign politically exposed persons or high-value accounts, standard verification is insufficient. In these instances, firms must execute enhanced-due-diligence measures to uncover the source of wealth and the ultimate purpose of the business relationship. Identifying individuals who hold prominent public functions is a critical component of assessing politically-exposed-person risk factors. Documenting these steps provides the evidentiary foundation required during regulatory examinations and independent compliance audits.

Transaction Monitoring and Suspicious Activity Reporting

Establishing an effective compliance program requires continuous monitoring of financial transactions to detect patterns indicative of money laundering, terrorist financing, or other illicit activities. Covered entities must deploy automated or risk-based transaction monitoring systems capable of reviewing payment flows, wire transfers, and account activity against established risk parameters. This ongoing oversight relies on systematic transaction-monitoring tools that flag anomalies, sudden volume spikes, or unusual geographic routing for manual review by compliance analysts. The design of these monitoring controls should reflect the institution's specific risk profile and customer base.

When monitoring uncovers activity that appears suspicious or lacks an apparent lawful purpose, institutions have an affirmative legal obligation to report these findings to federal authorities. This reporting mechanism requires the timely preparation and electronic filing of formal disclosure documents to FinCEN. Detailed procedures for documenting and submitting these disclosures are governed by suspicious-activity-report filing requirements. Specific cash transactions exceeding statutory thresholds require the submission of a currency-transaction-report to maintain transparency in cash-heavy operational sectors.

Maintaining adequate records of all monitoring alerts, investigative notes, and filed reports is essential for demonstrating regulatory adherence. Compliance teams often leverage structured methodology-library resources to document their transaction monitoring rules, escalation paths, and testing methodologies. Internal audit functions should regularly test the calibration of monitoring systems to ensure that threshold settings effectively capture suspicious behavior without generating an unmanageable volume of false positives.

Sanctions Compliance and Screening Mandates

Independent of traditional anti-money laundering statutes, organizations operating in or touching the United States must strictly adhere to economic and trade sanctions administered by the federal government. These restrictions prohibit commercial interactions, financial transactions, and trade with designated countries, entities, and individuals. The primary authority responsible for developing and enforcing these economic restrictions is the Office of Foreign Assets Control, which publishes detailed program guidelines available at OFAC — sanctions programs and country information. Compliance with these directives is mandatory for all US persons and entities, as well as foreign entities operating within US jurisdiction.

To prevent prohibited transactions, firms must implement systematic screening protocols that cross-reference customer databases, payment originators, and beneficiaries against restricted party lists. This operational requirement is fulfilled through continuous sanctions-screening procedures during onboarding and transactional processing. The primary database utilized for these checks contains individuals, groups, and entities owned or controlled by targeted governments, as detailed in the sdn-list reference registry. Entities must also monitor broader geographic restrictions that prohibit trade with entire nations or regions.

Organizations must adopt a risk-based-approach to calibrate their sanctions screening filters based on their industry, customer demographics, and geographic exposure. When complex ownership structures obscure the ultimate beneficiary of a transaction, compliance officers must conduct thorough research to prevent inadvertent sanctions evasion. Any confirmed or blocked transactions involving designated parties must be reported to the regulatory authority within mandated timeframes. Legal counsel should be consulted immediately if an organization identifies a potential sanctions nexus in its existing asset portfolios or customer base.

Global Standards, International Alignment, and Open Questions

United States regulatory expectations do not exist in a vacuum; they intersect with international standards established by global standard-setting bodies. The intergovernmental framework established by the Financial Action Task Force sets out global best practices for combating money laundering and terrorist financing. Compliance officers can review these foundational international expectations through the FATF Recommendations guidelines. Understanding how domestic rules align with international standards helps multinational organizations harmonize their compliance programs across different operating jurisdictions.

Despite detailed federal rulemakings, certain operational areas remain subject to interpretation and evolving regulatory guidance, particularly regarding emerging technologies and decentralized financial services. Organizations engaging with virtual assets must evaluate how international standards apply to their operations, drawing on guidance related to the virtual-asset-service-provider sector. Transmitting originator and beneficiary information across payment chains requires strict adherence to international messaging standards, as outlined in travel-rule compliance protocols. For traditional banking relationships, managing cross-border flows requires specialized oversight of correspondent-banking networks to mitigate foreign corruption risks.

Compliance teams facing ambiguous regulatory interpretations should consult local legal counsel and review agency-specific frequently asked questions, such as those maintained in the site faq section. Organizations may also utilize quantitative tools and calculators to benchmark their risk exposure and evaluate resource allocation. Because regulatory interpretations can shift with enforcement priorities, continuous monitoring of official regulatory updates remains essential for maintaining an effective compliance posture.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does a foreign software company with US-based users need to register with FinCEN?

Registration depends on whether the company's activities meet the statutory definition of a money services business under US law. Providing software alone typically differs from engaging in money transmission, but businesses processing customer funds or facilitating currency exchange must evaluate their direct US nexus with legal counsel.

How frequently must a covered entity screen its existing customer base against sanctions lists?

Institutions generally screen their customer databases whenever sanctions lists are updated by regulatory authorities. A risk-based approach dictates the frequency of batch screening and real-time transaction filtering to ensure blocked persons are immediately identified and restricted.

What is the primary difference between customer due diligence and enhanced due diligence?

Customer due diligence involves standard identity verification and risk profiling for all onboarding accounts. Enhanced due diligence requires deeper investigative measures, such as verifying the source of wealth and funds, applied to higher-risk relationships like politically exposed persons.

Are commercial enterprises that do not offer financial services required to screen for sanctions?

Yes, OFAC economic sanctions apply to all US persons and entities operating within US jurisdiction, regardless of industry. Commercial companies must ensure they do not engage in prohibited transactions with designated individuals or embargoed jurisdictions.

Where should compliance officers verify official interpretations of federal anti-money laundering rules?

Officers should review primary statutory sources, including FinCEN regulations codified in Title 31 of the Code of Federal Regulations and official guidance published by the Department of the Treasury. Legal counsel should be consulted for binding interpretations.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact