Hero background
Compliance Updates23 min read

FinCEN AML Requirements: 10 Red Flags Every Lender Must Know

By Michael Dunleavey
July 24, 2026
aml red flags lenderssuspicious activity report lendersaml kyc requirements
FinCEN AML red flag detection framework for lenders showing ten suspicious activity categories and SAR filing workflow

Red Flags Are Not Optional — They Are the Evidence Trail FinCEN Expects to Find

Anti-money laundering compliance begins with detection. FinCEN AML requirements — rooted in the Bank Secrecy Act (31 U.S.C. §§ 5311 et seq.) and implemented through FinCEN's regulatory guidance — do not simply require lenders to file Suspicious Activity Reports when they find something wrong. They require lenders to build and maintain a program that is capable of finding it in the first place.

The Financial Action Task Force (FATF), the global standard-setter for AML policy, has published detailed red-flag guidance across multiple typologies — transactions, transaction patterns, source of funds, anonymity, sender and recipient indicators, and geographic risk. FinCEN's own advisories build on the FATF framework with U.S.-specific typologies, and the May 2026 Executive Order on financial system integrity added six new red-flag categories — payroll structuring, ITIN account risk, shell and nominee account structures, off-the-books wage payments, labor trafficking financial flows, and beneficial ownership concealment — that the Treasury's forthcoming advisory is expected to formalize.

For lenders, the red-flag detection obligation is operational before it is legal. A SAR filed after a loan is booked to a money laundering operation does not satisfy the BSA's requirements if the institution's transaction monitoring program was not configured to detect the pattern that made the filing necessary. Examiners evaluate whether your compliance program was built to catch what it should have caught — not only whether you filed correctly after catching it.

Lenders using Salesforce-native compliance infrastructure can embed red-flag monitoring directly into their loan origination and servicing workflow — making detection the natural output of the operational process rather than a separate compliance function running in parallel. If your institution needs to assess whether its current monitoring configuration covers the red flags FinCEN and FATF expect, a compliance discussion is the right starting point.

What Makes Something a Red Flag — and What You Are Required to Do About It

A red flag in the AML context is a warning indicator that a customer, transaction, or relationship presents a higher risk of money laundering, terrorist financing, or other illicit financial activity. Red flags do not require certainty — they require investigation. The BSA's SAR filing obligation (31 C.F.R. § 1020.320) attaches when a financial institution knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA reporting requirements, or lacks a lawful purpose.

The critical operational implication: "reason to suspect" is evaluated against what your compliance program was designed and configured to detect. A pattern that your transaction monitoring rules were never set up to flag is not an exculpatory fact when that pattern surfaces in an examination — it is evidence that your AML program failed its design requirement.

FinCEN's four-step red-flag response framework:

StepActionBSA Basis
DetectionIdentify the red flag through transaction monitoring, KYC review, or customer activityAML program requirement — 31 C.F.R. § 1020.210
InvestigationConduct a documented internal investigation to determine whether the activity is suspiciousFinCEN SAR guidance; examiner expectations
DeterminationDocument the conclusion — whether a SAR is warranted or the activity is explainableSAR confidentiality provisions — 31 U.S.C. § 5318(g)
FilingIf suspicious activity is confirmed, file a SAR within 30 days of detection (60 days if no identified suspect)31 C.F.R. § 1020.320
FinCEN AML four-step red flag response framework diagram showing detection investigation determination and SAR filing for lenders

FinCEN's four-step red-flag response: detection, investigation, documented determination — including every "no SAR" decision — and timely filing.

Note that the decision not to file a SAR must also be documented. Examiners regularly review "no SAR" decisions to assess whether the investigation was thorough and the determination was reasonable.

So what does this mean for your institution? Red-flag detection is not a front-line compliance activity — it is the test of whether your AML program is functioning as designed. The ten red flags below are the categories that FinCEN, FATF, and the May 2026 Executive Order have identified as the highest-priority detection requirements for lenders. Each one must be reflected in your transaction monitoring rules, your customer risk-rating methodology, or your enhanced due diligence triggers — or your program has a gap.

Red Flag #1: Opaque or Unverifiable Sources of Funds

The most fundamental AML red flag is a customer or transaction where the origin of funds cannot be verified or is deliberately obscured. For lenders, this surfaces most commonly in commercial loan applications where business revenue sources are inconsistent with the borrower's stated business activity, in large cash deposits used as down payments without documentation of source, and in accounts that show large incoming transfers from unknown counterparties immediately before a credit application.

FATF guidance specifically flags: deposits significantly higher than ordinary with unknown source; source of wealth derived primarily from unverifiable investment returns; and funds associated with known fraud, ransomware, or darknet activity. The May 2026 Executive Order adds a lending-specific dimension — funds flowing through ITIN accounts where employment authorization is unverified, or through nominee structures designed to obscure beneficial ownership.

Lender-specific detection triggers:

  • Loan application where stated income cannot be verified against tax records, employment documentation, or bank statements
  • Business borrower whose revenue deposits are inconsistent with the scale or type of business described in the application
  • Large cash contributions to a down payment or equity injection without documented source
  • Wire transfers to or from unknown third parties in the period immediately before or after loan closing

Red Flag #2: Unusual or Inconsistent Transaction Patterns

Transaction patterns that diverge from a customer's established profile — or that are structurally inconsistent with their stated business purpose — are among the most actionable red flags in a lender's monitoring toolkit because they are detectable through automated transaction monitoring rules without requiring individual human review of every account.

Key patterns: multiple transactions just below CTR thresholds ($10,000 for cash transactions) — a practice known as structuring, which is itself a federal crime under 31 U.S.C. § 5324; large round-number transfers with no clear commercial purpose; rapid movement of funds through an account with no net accumulation (layering); and payroll-cycle transactions in amounts and frequencies inconsistent with the borrower's stated number of employees.

The May 2026 Executive Order specifically identifies payroll-related structuring as a named red-flag category for the forthcoming Treasury advisory — repetitive sub-threshold cash transactions on weekly or biweekly payroll cycles that are inconsistent with reported employment counts or payroll tax filings.

Lender-specific detection triggers:

  • Loan servicing account that receives large deposits and immediately transfers out most of the balance
  • Business borrower making frequent cash withdrawals in amounts just under $10,000
  • Revolving credit line drawn and repaid in patterns inconsistent with stated business operations
  • Wire transfers to foreign accounts from a business with no disclosed international operations

Red Flag #3: Secretive or Evasive Customer Behavior

When a customer is unwilling or unable to provide the identity documentation, beneficial ownership information, or source-of-funds explanation that your KYC procedures require, that resistance is itself a red flag — independent of what the investigation ultimately reveals. Under FinCEN CIP requirements (31 C.F.R. § 1020.220), covered institutions must collect and verify specific identity information at account opening. A customer who provides incomplete documentation, inconsistent information across multiple channels, or implausible explanations for why they cannot produce required documents has triggered an EDD obligation.

FATF guidance identifies the following as secretive-customer red flags: refusal to disclose beneficial ownership; use of legal structures specifically designed to obscure identity; providing inconsistent identification information at different stages of the relationship; and requesting that transaction records not be maintained.

Lender-specific detection triggers:

  • Commercial loan applicant who declines to complete beneficial ownership certification or provides incomplete information
  • Borrower who provides different identification information on the loan application versus income verification documents
  • Customer who requests that loan proceeds be disbursed to a third party without explanation of the business relationship
  • Borrower who cannot explain the purpose of a credit facility in terms consistent with their stated business

Red Flag #4: Negative Track Record — Criminal History and Prior Suspicious Activity

A customer with a prior conviction for financial crime, money laundering, or fraud is a named red flag that requires documented enhanced due diligence before any credit relationship is extended. The obligation extends beyond direct convictions: close associates and family members of known financial criminals are also elevated-risk customers under FATF guidance, because they are commonly used as intermediaries to distance the primary actor from the financial activity.

For lenders, this red flag operates through adverse screening: background screening for criminal history, review of prior SAR filings if accessible through information-sharing programs, and review of prior bankruptcy, judgment lien, and civil litigation history that may reflect patterns of financial fraud.

Lender-specific detection triggers:

  • Loan applicant with prior conviction for fraud, embezzlement, identity theft, or financial crime
  • Business borrower whose principals appear on prior regulatory enforcement actions or consent orders
  • Applicant with multiple prior bankruptcies in a pattern inconsistent with legitimate business activity
  • Customer referred by a counterparty that the institution has previously filed a SAR about

Red Flag #5: Adverse Media References

Adverse media screening — the systematic review of negative news coverage and public records about a customer — is a component of enhanced due diligence for higher-risk customer segments. For commercial lenders, this includes searches for news coverage of fraud allegations, regulatory enforcement actions, civil litigation, reputational controversies, and associations with sanctioned entities or politically exposed persons.

The challenge with adverse media is scale and recency: a customer who was clean at onboarding may have become the subject of enforcement action, investigation, or adverse coverage during the lending relationship. Ongoing monitoring for adverse media is as important as the onboarding screen — and in the lending context, it may surface red flags that affect the credit relationship as much as the compliance relationship.

Lender-specific detection triggers:

  • Business borrower whose principals are named in news reports alleging fraud, tax evasion, or regulatory violations during the lending relationship
  • Customer associated in adverse media with individuals or entities that are known to be under law enforcement investigation
  • News coverage suggesting material misrepresentation in financial statements used to support the loan application
AML red flags framework showing source of funds unusual transactions secretive customers track record and adverse media for lenders

Red flags #1–#5: opaque source of funds, unusual transaction patterns, evasive customer behavior, adverse track record, and adverse media.

Red Flag #6: OFAC Sanctions List Matches

A customer who appears on an OFAC Specially Designated Nationals (SDN) list or any other U.S. government sanctions list is not an AML red flag that requires investigation — it is a legal prohibition on the transaction. Under OFAC regulations implementing multiple Executive Orders and statutory authorities, U.S. financial institutions are prohibited from conducting transactions with SDN-listed individuals or entities, and must block or reject transactions involving sanctioned countries, entities, or individuals.

For lenders, OFAC screening must occur at account opening (CIP), at the point of credit decisioning, and as an ongoing monitoring function throughout the lending relationship. Beneficial owners of legal entity borrowers must also be screened — a sanctions hit on a 30% owner of a corporate borrower triggers the same prohibition as a direct hit on the borrower.

Lender-specific detection triggers:

  • Loan applicant whose name, address, or identification information matches an SDN list entry
  • Beneficial owner of a commercial borrower who appears on a sanctions list
  • Wire transfer instruction to or from a financial institution in a sanctioned country or jurisdiction
  • Loan proceeds disbursed to a counterparty that matches a blocked-person designation

AML and KYC compliance for lenders requires OFAC screening to be embedded at multiple points in the credit workflow — not treated as a one-time onboarding check.

Red Flag #7: Politically Exposed Persons (PEPs)

A politically exposed person is an individual who holds or has held a prominent public position — elected officials, senior government appointees, military officers, judicial officials, executives of state-owned enterprises, and senior officials of international organizations. PEPs present elevated AML risk because their position gives them access to government funds and processes that could be exploited for corruption or money laundering. Their close family members and known associates are also treated as elevated-risk under FATF guidance.

Being a PEP is not a disqualifying factor for a lending relationship — it is a trigger for enhanced due diligence. EDD for PEPs requires: verification of the source of funds used in the transaction; more frequent ongoing monitoring; senior management approval for the relationship; and documented review of whether the funds or transaction purpose is consistent with the PEP's known income and assets.

Lender-specific detection triggers:

  • Loan applicant who is identified as a current or former senior government official during KYC screening
  • Commercial borrower whose principal is identified as a PEP's close family member or known business associate
  • Transaction amount or structure inconsistent with the PEP's known compensation level or disclosed assets
  • Loan proceeds used to acquire real estate or other hard assets without a clear business purpose

Red Flag #8: Unusual Geographic Patterns and High-Risk Jurisdictions

Transactions involving parties in high-risk jurisdictions — countries subject to FATF's increased monitoring, OFAC sanctions programs, or identified by FinCEN as jurisdictions of primary money laundering concern — carry elevated AML risk that must be reflected in your transaction monitoring configuration and customer risk-rating methodology.

Geographic red flags for lenders extend beyond direct counterparties: a business borrower whose supply chain includes counterparties in high-risk jurisdictions, whose cash flows show regular transfers to or from those jurisdictions, or who uses correspondent banking relationships in non-transparent financial centers presents elevated risk that standard commercial risk assessment may underweight.

The May 2026 Executive Order adds a specific geographic dimension for lenders — cross-border P2P payment platforms used to transmit wages or funds in patterns consistent with off-the-books labor arrangements are named as a risk category in the forthcoming Treasury red-flag advisory.

Lender-specific detection triggers:

  • Loan proceeds disbursed to accounts in FATF-monitored jurisdictions without documented commercial purpose
  • Business borrower with regular wire transfer activity to or from countries on FinCEN's jurisdictions-of-concern list
  • Commercial real estate transaction where the beneficial owner of the purchasing entity is in a high-risk jurisdiction
  • P2P payment platform deposits from high-risk jurisdictions into a loan servicing account

Red Flag #9: High-Risk Industry or Business Activity

Certain industries carry elevated inherent AML risk based on the nature of their operations — the volume of cash transactions, the opacity of their customer base, or the structure of their revenue. For lenders, extending credit to borrowers in high-risk industries triggers EDD obligations regardless of whether any specific transaction has raised a concern.

FinCEN has identified the following as high-risk industries requiring enhanced monitoring: money services businesses; cannabis-related businesses (even where state-licensed); cash-intensive businesses including restaurants, car washes, and laundromats; pawnbrokers; dealers in precious metals and stones; real estate developers and brokers; and gaming and gambling operations.

Beyond the officially-designated categories, the May 2026 Executive Order's focus on employment authorization creates a new lending-specific risk category: businesses in industries with high concentrations of unverified or unauthorized workers — certain agricultural operations, construction contractors, and hospitality businesses — may warrant enhanced due diligence on the source and flow of funds used to service the lending relationship.

Lender-specific detection triggers:

  • Commercial loan application from a business in an industry with high cash intensity inconsistent with the stated revenue model
  • Business borrower in a FinCEN-designated high-risk industry without EDD documentation on file
  • Loan proceeds used for acquisition of a business in a high-risk industry without appropriate due diligence
  • Business borrower whose transaction patterns are inconsistent with the normal cash flow patterns of their stated industry

Red Flag #10: Shell Companies, Nominee Structures, and Beneficial Ownership Concealment

The deliberate use of complex ownership structures — layers of holding companies, nominee directors and shareholders, trust arrangements, and multi-jurisdiction corporate formations — to conceal the true beneficial owner of assets or funds is one of the most significant money laundering methods identified by FATF and FinCEN. For lenders, this red flag is most commonly encountered in commercial real estate transactions, business acquisition financing, and high-value commercial lending.

FinCEN's CDD Rule (31 C.F.R. § 1010.230) already requires the identification and verification of beneficial owners at the 25% ownership threshold for legal entity customers. The May 2026 Executive Order's proposed BSA CDD amendments may tighten that threshold and add additional documentation requirements for structures that show indicators of concealment.

Indicators of problematic shell or nominee structures include: legal entity customers with no employees, no physical address, and no discernible business operations; ownership structures with multiple layers of holding companies in different jurisdictions; beneficial owners who appear to have no connection to the stated business; and structures created recently — often in the weeks before a credit application — with no operational history.

Lender-specific detection triggers:

  • Commercial borrower whose ownership structure includes more than two layers of holding companies without operational rationale
  • Legal entity customer whose registered address is a registered agent office with no physical operations
  • Beneficial ownership certification that lists individuals who cannot be verified through public records or credit history
  • Commercial real estate purchaser using an LLC formed within 90 days of the transaction without disclosed beneficial ownership

Understanding how the May 2026 Executive Order is expanding AML KYC requirements for lenders directly covers the proposed CDD amendments that will affect how shell company and beneficial ownership red flags must be documented and escalated.

So what does this mean for your institution? Shell company and beneficial ownership concealment is the red flag most likely to surface in a commercial lending examination — because it is the one most commonly associated with the large-dollar, sophisticated money laundering operations that FinCEN's enforcement priorities focus on. A lender whose beneficial ownership documentation workflow produces incomplete or unverifiable certifications is carrying exam risk in every commercial credit file that lacks a complete beneficial ownership record.

AML red flags ten-category framework for lenders showing source of funds through shell company structures with FinCEN SAR filing workflow

All ten red-flag categories feed a single monitoring and SAR-escalation workflow — from source of funds through shell-company concealment.

Why LASER for AML Red-Flag Detection on Salesforce

Detecting AML red flags at the scale and speed that FinCEN AML requirements demand is an infrastructure problem as much as a compliance problem. Transaction monitoring rules that are not embedded in your loan management system cannot surface the patterns that define red flags #1 through #10 automatically — they depend on individual compliance staff to recognize patterns that no individual can consistently detect at portfolio volume.

Salesforce-native credit access, built-in compliance, and decisioning — unified in a single app, ready from day one.

LASER Credit Access is built natively inside Salesforce, connecting lenders to credit bureau access and OFAC screening in a single operational environment. The COMPLY pillar's built-in compliance infrastructure provides permissible purpose documentation, OFAC screening integration, customer risk-rating workflow, and audit trail — as a natural output of the origination and servicing process. For AML red-flag detection, the native Salesforce architecture means that customer identity data, transaction patterns, beneficial ownership documentation, and risk-rating history are all visible in the same record — allowing compliance staff to see the full picture without assembling it from multiple disconnected systems.

When the May 2026 Executive Order's Treasury advisory formalizes new red-flag categories for ITIN accounts, payroll structuring, and beneficial ownership concealment, lenders on LASER adapt their monitoring configuration within the platform they already operate — rather than rebuilding a separate monitoring system from scratch.

How proper KYC timing strengthens compliance and prevents identity fraud is directly relevant to red flags #3, #7, and #10 specifically — the PEP, secretive customer, and beneficial ownership categories where getting KYC right at onboarding determines whether the red flag is caught before credit is extended or only after a loss is realized.

Building Red-Flag Detection Into Your Lending Compliance Program

1. Map your transaction monitoring rules to each of the ten red-flag categories. For every category above, confirm that your transaction monitoring configuration includes at least one rule that would detect the pattern — not rely on human recognition. Document the mapping so it can be produced during an examination to demonstrate that your program was designed to detect what it should detect.

2. Configure EDD triggers for red flags #6, #7, #8, and #9 automatically. OFAC hits, PEP identification, high-risk jurisdiction involvement, and high-risk industry classification should each trigger documented EDD procedures automatically in your compliance workflow — not only when a compliance officer manually recognizes the need.

3. Establish a documented "no SAR" decision process. Every red-flag investigation that does not result in a SAR filing must be documented — what the red flag was, what the investigation revealed, why the determination was made that filing was not warranted, and who made that determination. Examiners review "no SAR" decisions as carefully as SAR filings.

4. Update your beneficial ownership documentation for commercial borrowers. Review the beneficial ownership certification on file for every active commercial credit relationship. Confirm that the identified owners have been verified — not only certified — and that the certification has been updated if ownership structure has changed since origination.

5. Assess your monitoring configuration against the May 2026 Executive Order red-flag categories. Before the Treasury advisory is published, review whether your current rules would detect payroll structuring, ITIN account activity inconsistent with the customer's profile, and P2P payment patterns associated with off-the-books wage arrangements. Document the review.

So what does this mean for your institution? The federal AML and KYC requirements that create pre-account-opening verification obligations are the baseline that red-flag monitoring builds on. An institution whose KYC is weak produces customer risk profiles that cannot support meaningful transaction monitoring — because there is no established baseline to compare against. Red-flag detection at the compliance standard FinCEN expects requires both layers to be functioning correctly.

Frequently Asked Questions

Q: What is the BSA SAR filing deadline for lenders, and what triggers the 30-day clock?

A: Under 31 C.F.R. § 1020.320, a covered financial institution must file a SAR no later than 30 calendar days after the date of initial detection of facts that may constitute a basis for filing. If no suspect can be identified at the time of detection, the deadline extends to 60 days. "Initial detection" is not the date the suspicious activity occurred — it is the date the institution's compliance process identified it as potentially suspicious. This is why the design of your transaction monitoring program matters: if a pattern that should have triggered detection in January is not flagged until March because the monitoring rule was not configured to detect it, the 30-day clock still runs from March — but the institution has also failed its AML program design obligation.

Q: Are all ten red flags equally likely to surface in a lending examination?

A: No. The red flags most commonly cited in FinCEN examination findings and enforcement actions for lending institutions are: opaque source of funds in commercial loan applications (Red Flag #1), structuring in loan servicing accounts (Red Flag #2), beneficial ownership concealment in commercial real estate transactions (Red Flag #10), OFAC screening failures (Red Flag #6), and inadequate EDD for high-risk industries (Red Flag #9). Shell company and beneficial ownership documentation failures are the single most frequent source of examination findings in commercial lending AML programs. PEP identification failures are the most common finding in consumer lending programs where the monitoring is designed for transaction patterns rather than customer profile review.

Q: What is the difference between a red flag and a SAR filing trigger?

A: A red flag is a warning indicator that requires investigation. A SAR filing is the outcome of that investigation when the investigation confirms that the activity is suspicious and meets the filing threshold. Not every red flag results in a SAR. The BSA's SAR filing obligation applies when the institution "knows, suspects, or has reason to suspect" that a transaction involves funds from illegal activity, is designed to evade BSA reporting, lacks a lawful purpose that a reasonable person could not explain, or involves a use of the institution to facilitate criminal activity. Red flags that are investigated and explained by legitimate business activity do not require a SAR — but the investigation and the explanation must be documented.

Q: How should our transaction monitoring rules be calibrated for a loan portfolio versus a deposit account portfolio?

A: Loan portfolio monitoring requires rules calibrated to lending-specific patterns that deposit monitoring systems are not designed to detect: payoff sources inconsistent with the borrower's income profile; draw patterns on revolving credit facilities inconsistent with stated business activity; third-party payment of loan obligations without explanation; and proceeds disbursed to counterparties that do not match the stated purpose of the credit. Deposit monitoring rules tuned for cash structuring, wire transfer patterns, and account turnover do not automatically translate to loan portfolio risk. Lenders with both deposits and loans should maintain monitoring configurations that address the distinct risk patterns of each product line.

Q: What documentation is required at the account level to demonstrate that a red-flag investigation was conducted?

A: FinCEN examination expectations for red-flag investigation documentation include: identification of the specific red flag that triggered the review; the date the red flag was detected; the scope of the internal investigation (what records, transaction history, and external sources were reviewed); the findings of the investigation; the determination of whether to file a SAR or close without filing; the basis for the determination; and the identity of the compliance officer who made the decision. This documentation should be maintained at the account level and retained for the BSA's minimum five-year recordkeeping period. Note: if a SAR was filed, the existence and content of the SAR is confidential under 31 U.S.C. § 5318(g)(2) and must not be disclosed to the subject of the report or included in the borrower's customer-facing file.

Abstract illustration guiding lenders toward Salesforce-native AML red flag monitoring tools and compliance discussion next steps

From detection to escalation — AML red-flag monitoring built into the Salesforce lending workflow lenders already operate.

Ready to Embed AML Red-Flag Detection Into Your Salesforce Lending Workflow?

FinCEN AML requirements do not grade compliance programs on whether they filed a SAR after something went wrong. They evaluate whether the program was designed and configured to detect what it should have detected before the damage was done. The ten red flags in this post are the categories that FinCEN, FATF, and the May 2026 Executive Order have identified as the highest-priority detection requirements for lenders — and each one must be reflected in your transaction monitoring rules, customer risk-rating methodology, or enhanced due diligence triggers.

LASER Credit Access delivers Salesforce-native credit bureau access, OFAC screening integration, and built-in compliance workflow in a single application. If your institution needs to assess whether its current AML monitoring configuration covers the red flags FinCEN expects to find — or needs to close gaps in beneficial ownership documentation, OFAC screening, or SAR escalation procedures — a compliance discussion is the right starting point.

Schedule a Compliance Discussion

Frequently Asked Questions

What is the BSA SAR filing deadline for lenders, and what triggers the 30-day clock?

Under 31 C.F.R. § 1020.320, a covered financial institution must file a SAR no later than 30 calendar days after the date of initial detection of facts that may constitute a basis for filing. If no suspect can be identified at the time of detection, the deadline extends to 60 days. 'Initial detection' is not the date the suspicious activity occurred — it is the date the institution's compliance process identified it as potentially suspicious. This is why the design of your transaction monitoring program matters: if a pattern that should have triggered detection in January is not flagged until March because the monitoring rule was not configured to detect it, the 30-day clock still runs from March — but the institution has also failed its AML program design obligation.

Are all ten red flags equally likely to surface in a lending examination?

No. The red flags most commonly cited in FinCEN examination findings and enforcement actions for lending institutions are: opaque source of funds in commercial loan applications (Red Flag #1), structuring in loan servicing accounts (Red Flag #2), beneficial ownership concealment in commercial real estate transactions (Red Flag #10), OFAC screening failures (Red Flag #6), and inadequate EDD for high-risk industries (Red Flag #9). Shell company and beneficial ownership documentation failures are the single most frequent source of examination findings in commercial lending AML programs. PEP identification failures are the most common finding in consumer lending programs where the monitoring is designed for transaction patterns rather than customer profile review.

What is the difference between a red flag and a SAR filing trigger?

A red flag is a warning indicator that requires investigation. A SAR filing is the outcome of that investigation when the investigation confirms that the activity is suspicious and meets the filing threshold. Not every red flag results in a SAR. The BSA's SAR filing obligation applies when the institution 'knows, suspects, or has reason to suspect' that a transaction involves funds from illegal activity, is designed to evade BSA reporting, lacks a lawful purpose that a reasonable person could not explain, or involves a use of the institution to facilitate criminal activity. Red flags that are investigated and explained by legitimate business activity do not require a SAR — but the investigation and the explanation must be documented.

How should our transaction monitoring rules be calibrated for a loan portfolio versus a deposit account portfolio?

Loan portfolio monitoring requires rules calibrated to lending-specific patterns that deposit monitoring systems are not designed to detect: payoff sources inconsistent with the borrower's income profile; draw patterns on revolving credit facilities inconsistent with stated business activity; third-party payment of loan obligations without explanation; and proceeds disbursed to counterparties that do not match the stated purpose of the credit. Deposit monitoring rules tuned for cash structuring, wire transfer patterns, and account turnover do not automatically translate to loan portfolio risk. Lenders with both deposits and loans should maintain monitoring configurations that address the distinct risk patterns of each product line.

What documentation is required at the account level to demonstrate that a red-flag investigation was conducted?

FinCEN examination expectations for red-flag investigation documentation include: identification of the specific red flag that triggered the review; the date the red flag was detected; the scope of the internal investigation (what records, transaction history, and external sources were reviewed); the findings of the investigation; the determination of whether to file a SAR or close without filing; the basis for the determination; and the identity of the compliance officer who made the decision. This documentation should be maintained at the account level and retained for the BSA's minimum five-year recordkeeping period. Note: if a SAR was filed, the existence and content of the SAR is confidential under 31 U.S.C. § 5318(g)(2) and must not be disclosed to the subject of the report or included in the borrower's customer-facing file.

Michael Dunleavey

Founder — LASER Credit Access

Michael Dunleavey brings over 15 years of experience in credit infrastructure and lending compliance, helping financial institutions streamline operations on Salesforce.

Ready to Transform Your Credit Operations?

Discover how LASER Credit Access streamlines compliance and decisioning natively inside Salesforce — unified in a single app, ready from day one.