Money Services Businesses are subject to FinCEN examination. Here is what MSB audits cover, what examiners look for, how to prepare, and what the most common findings are.
MSB Audit Requirements: What FinCEN Examiners Look For
Money Services Businesses are subject to examination by FinCEN and, where applicable, state regulators and sponsor bank compliance teams. Understanding what examiners look for — and preparing your program accordingly — is one of the most important things an MSB can do to protect its business.
This article covers how MSB examinations work, what the primary focus areas are, the most common findings, and how to prepare.
How MSB Examinations Work
FinCEN has authority to examine MSBs directly to assess BSA compliance. In practice, many MSBs are examined through their sponsor bank's oversight rather than directly by FinCEN — but direct FinCEN examinations do occur, particularly for MSBs with significant transaction volumes or compliance concerns.
State regulators in states where your MSB holds money transmitter licenses also conduct periodic compliance examinations of licensees. These state examinations often cover both state-specific licensing compliance and BSA/AML program adequacy.
Most examinations follow a similar structure: an information request phase where the examiner requests documentation, a review phase where documentation is assessed, and a findings phase where any compliance gaps are communicated. In-person or remote interviews with compliance personnel are also common.
What Examiners Evaluate
AML Program Adequacy
The first thing examiners assess is whether your written AML program covers all required elements — internal controls, designated compliance officer, ongoing training, independent testing, and customer due diligence — and whether it is tailored to your specific business model rather than a generic template.
Examiners compare your written program to your actual operations. A program that describes one thing and actual operations that reflect something else is the most common and most serious finding type.
Risk Assessment
Examiners review your AML risk assessment to assess whether it accurately reflects your current products, customers, and geographies and whether your controls are calibrated to the risks identified.
KYC and CDD Implementation
Examiners typically pull a sample of customer files and assess whether your KYC and CDD procedures were actually followed for each customer — not just whether the procedures exist on paper.
Common findings include incomplete identity verification, customer risk ratings not applied or not documented, EDD not applied for customers who triggered EDD criteria, and beneficial ownership not collected or not verified for business customers.
Transaction Monitoring
Examiners review your transaction monitoring program including whether rules are appropriately calibrated for your risk profile, whether alerts are being reviewed within your defined SLA timelines, and whether alert review documentation is complete and specific.
SAR Filing
Examiners review your SAR filing program — whether investigations are being conducted and documented before filing decisions are made, whether SARs are being filed within the 30-day deadline, and whether SAR narratives are specific and complete.
Sanctions Screening
Examiners assess whether OFAC sanctions screening is occurring at onboarding and for ongoing transactions, whether your screening technology uses fuzzy matching, and whether hits are being reviewed and documented appropriately.
Training
Training records are reviewed to confirm that AML training is occurring at minimum annually, that it is role-specific, and that completion is documented.
Recordkeeping
Examiners assess whether required BSA records are being retained for the required period and whether they are retrievable on reasonable notice.
Most Common MSB Examination Findings
The most common examination findings for MSBs consistently include inadequate or generic AML programs not tailored to the business, failure to actually verify customer identity despite having CIP procedures, lack of risk rating documentation for customers, inadequate transaction monitoring rules or unreviewed alert backlogs, late SAR filings or failure to file SARs that should have been filed, absence of independent testing, and inadequate training documentation.
How to Prepare
Maintain your compliance program throughout the year — not just before examination notice arrives. Know your program well enough that you can explain every element to an examiner. Have documentation organized and retrievable. Conduct your own internal compliance review against examination criteria annually. Conduct an independent review at least once every 12 to 18 months.
Frequently Asked Questions
How often are MSBs examined by FinCEN?
There is no fixed examination schedule. FinCEN and state regulators select MSBs for examination based on risk indicators, tips, referrals, and periodic sweeps of specific MSB categories. Higher-risk or higher-volume MSBs are examined more frequently than lower-risk businesses.
What happens after an examination?
If examiners identify findings, they will issue a formal report with required remediation. More serious findings may result in civil money penalties, consent orders, or referral for criminal prosecution. Voluntary self-disclosure and proactive remediation are treated as significant mitigating factors.
How ComplyOne Helps
ComplyOne provides MSB audit preparation services — gap assessments, documentation organization, examination coaching, and remediation support — through advisory services, compliance technology, or both.
Talk to the ComplyOne team to get started.
The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.