Questions to Ask Management: BSA/AML
A bank of specific questions a supervisory committee member can bring to a meeting with the CEO or BSA officer about the credit union's Bank Secrecy Act program.
Nothing on this page is saved anywhere — there's no in-browser save state to lose to a stray click. Download the checklist below as a spreadsheet, or print it, and do the actual filling-in wherever you already keep your committee's records.
These are questions built from NCUA’s own examiner guidance and its most recent supervisory priorities letter — the same material an examiner is working from. Pick the group most relevant to your next meeting rather than trying to cover all of them at once. Nothing here is saved on this page — download it as a spreadsheet or print it to pick which questions you’re bringing and jot notes on the answers you get.
25 questions across 6 groups.
BSA/AML Risk Assessment & Resource Allocation
When did we last update our BSA/AML risk assessment, and what specifically changed since the last version?
NCUA's exam guide says the risk assessment should be refreshed when the credit union adds products or services, merges or expands geographically, when part of its service area gets designated a high-intensity drug trafficking or financial crime area, or when federal AML priorities are updated (at minimum every four years). A stale assessment is one of the first things an examiner checks.
Which products, services, member types, and geographies does our risk assessment identify as our highest money-laundering or terrorist-financing risk, and what controls are we relying on to offset that risk?
NCUA's guide requires the risk assessment to cover all products/services, membership, and geography, and to pair each identified risk with a compensating control — not just list risks in the abstract.
How do we know our BSA program is putting the most effort into the areas the risk assessment flags as highest-risk, instead of spreading attention evenly across everything?
NCUA's 2026 supervisory priorities letter singles out BSA/AML/CFT for the first time as a named 2026 exam focus, and specifically says examiners will look at whether a credit union directs its resources to the areas of greatest money-laundering and terrorist-financing risk rather than applying a one-size-fits-all program.
If an examiner concluded our risk assessment was inadequate, they'd write their own version to base the exam on — how confident are we that wouldn't happen?
NCUA's exam guide states plainly that if a credit union's risk assessment is inadequate, the examiner completes one based on available information and proceeds from there — a real, documented consequence of a weak or outdated assessment, not a hypothetical.
BSA Officer Authority & Board Oversight
Who is our designated BSA/AML compliance officer, and do their other job duties ever put them in the position of reviewing their own work?
NCUA regulation 12 CFR 748.2(c)(3) requires a designated officer, and the exam guide's independence standard for BSA testing excludes anyone involved in day-to-day BSA functions — a useful lens for asking whether the officer role itself is structurally independent from operations.
Does our BSA officer have the authority, staffing, and budget to change the program without needing sign-off from someone whose area the change affects?
NCUA's exam guide says examiners specifically evaluate whether the AML/CFT officer has the knowledge, authority, independence, and resources to administer an effective program — all four are named as distinct things examiners check, not just competence.
When did the board last receive BSA training, and what did it actually cover?
12 CFR 748.2(c)(4), as described in NCUA's exam guide, requires the board to receive BSA training and stay current on regulatory changes and supervisory guidance — this is a distinct requirement from staff training and one boards can overlook.
Beyond approving the BSA policy once a year, what does the board actually see on an ongoing basis about how the program is performing?
NCUA's exam guide frames board oversight as an active, ongoing responsibility exercised through senior management, not a single annual sign-off — worth checking that oversight in practice matches that expectation.
Customer Due Diligence & High-Risk Members
How do we assign member risk ratings, and who reviews or challenges a rating besides the person who set it?
NCUA's exam guide notes there are no required risk-profile categories — credit unions design their own — so examiners test the process by reviewing individual risk-rating decisions. A rating nobody double-checks is a gap worth naming before an examiner finds it.
Which of our members or business accounts are currently classified high-risk — money services businesses, cash-intensive businesses, politically exposed persons — and how often does each one actually get reviewed?
NCUA's exam guide names these categories specifically as examples of higher-risk accounts requiring more frequent review, and examiners check whether the stated review frequency is followed in practice.
How do we keep beneficial ownership information on our business members current after the account is opened, not just at account opening?
NCUA's exam guide describes beneficial ownership information as something that must be maintained and updated on a risk basis over the life of the relationship, not collected once and filed away.
What's our process for screening members and transactions against OFAC's sanctions lists, and what happens internally when there's a potential match?
NCUA's own BSA exam-resource list cites the OFAC blocked-property and rejected-transaction reporting rules (31 CFR 501.603-604) and includes OFAC items in its standard BSA document request — sanctions screening is treated as part of the same exam, not a side issue.
Suspicious Activity & Currency Transaction Reporting
Are we consistently meeting the 30-day SAR filing deadline — or 60 days when no suspect has been identified — and if we've missed one, why?
NCUA's exam guide states these specific deadlines and notes the clock starts at detection, not the transaction date, which is a common source of late filings worth checking directly.
When we investigate something and decide not to file a SAR, do we document why?
NCUA's exam guide lists documenting the rationale for not filing as a specific thing examiners check — an undocumented 'we looked into it and it was fine' doesn't hold up in an exam.
Has the board or supervisory committee actually been notified each time a SAR was filed this year, even without the identifying details?
NCUA's exam guide requires senior management to promptly notify the board or a designated committee whenever a SAR is filed, while keeping identifying details confidential — this is a compliance step separate from the filing itself.
Do any members show up repeatedly in our SAR filings, and if so, what's our escalation path — enhanced monitoring, account closure, something else?
NCUA's exam guide specifically calls out escalating issues from repeat SAR filings as something examiners look for, rather than treating each filing as a standalone event.
Do we periodically re-check our CTR-exempt businesses to confirm they still qualify and aren't showing suspicious activity?
NCUA's exam guide notes that a currency transaction reporting exemption doesn't remove the obligation to monitor — a business that no longer fits the exemption or starts showing suspicious deviations still needs a SAR, not just a pass on CTR filing.
Independent Testing of the BSA Program
Who performed our last independent BSA test, and can we confirm they had no involvement in day-to-day BSA compliance work?
NCUA's exam guide is explicit that only someone with no role in BSA-related functions has the independence to perform this testing — internal audit, an external auditor, a consultant, or the supervisory committee itself, but not BSA staff testing their own work.
Did the last independent test actually cover our higher-risk products, services, and geographies, or was it a general review?
NCUA's exam guide says examiners check whether testing scope covers higher-risk products/services, field of membership, and geography — a test that skips the highest-risk areas doesn't give the board a real read on the program.
What did the last independent test find, and what's the status of management's corrective action on each finding?
NCUA's exam guide says management should promptly report testing deficiencies and corrective actions to the board or a designated committee — findings without a tracked resolution are exactly what an examiner will ask about.
How did we decide how often to schedule independent testing, and does that match what our risk assessment says about our risk level?
The regulation doesn't set a fixed testing frequency; NCUA's exam guide notes credit unions typically align testing intervals to their money-laundering/terrorist-financing risk profile — worth confirming that link was made deliberately, not by default.
BSA/AML Training
Which staff and volunteers received BSA training this year, and how was it tailored to what their specific job actually requires them to catch?
NCUA's exam guide says training should ideally be tailored to each person's job responsibilities, and examiners review materials to see whether that's true in practice rather than a single generic module for everyone.
What did our board-level BSA training cover — specifically the consequences of noncompliance and the money-laundering risks particular to our credit union?
NCUA's exam guide lists these as required content for leadership training, distinct from the general awareness training given to frontline staff.
If we changed anything meaningful in our AML/CFT program this year, did training get updated to reflect it, or is everyone still working from last year's material?
NCUA's exam guide notes that more frequent or updated training sessions are warranted when a credit union significantly modifies its AML/CFT program — training that lags a program change is a gap examiners can spot easily.
Can we produce training records — materials, attendance, and any assessments — going back far enough to cover a full exam cycle?
NCUA's exam guide lists training materials, assessments, session dates, and attendance records as documentation examiners expect to be available and complete.