Public beta — features are evolving and AI-generated outputs may contain errors. Not legal, regulatory or compliance advice. Review before relying on any output. Share feedback
All starter packs

Banking starter pack

Three example deliverables a community or digital bank is commonly expected to maintain under US federal banking and AML rules.

Example company: Cascade Community Bank (US, $1.2B assets, 320 employees)

Educational examples only. Fictional data; not legal, regulatory or compliance advice.

Bank Secrecy Act
FFIEC BSA/AML Examination Manual

BSA / AML Risk Assessment

Documents inherent ML/TF risks across products, customers and geographies, the mitigating controls, and the residual risk rating.

Regulator
FinCEN / OCC / FDIC · United States
Frequency
At least annual; on material change

Inherent risk — products & services

Wire transfers (domestic)
Moderate — 18,400 wires / month, avg $12k
Wire transfers (international)
High — corridors include MX, PH, NG
Remote deposit capture
Moderate — 6,200 active business users
Cash-intensive business customers
High — 41 MSB-like relationships

Mitigating controls

Transaction monitoring
Verafin scenarios tuned quarterly; SAR decisioning queue staffed by 6 analysts; 30-day case ageing SLA.
↳ Cited: BSA Policy §6 (2025)
Customer Due Diligence (CDD)
Tiered KYC with enhanced due diligence on MSBs, foreign correspondents, PEPs and high-cash businesses; refreshed annually for high risk.
↳ Cited: 31 CFR § 1020.210
Training
Annual role-based AML training; board attestation recorded each January.

Residual risk rating

Overall residual risk
Moderate — driven by international wires and MSB-like relationships.
Approved by
BSA Officer, with ratification by the Risk Committee on 2026-02-12.
Reviewer notes

Sample structure based on the FFIEC manual; tailor product lists, control descriptions and ratings to your institution's actual operations.

Gramm-Leach-Bliley Act
16 CFR Part 314

GLBA Safeguards Rule Written Information Security Program

Written program describing administrative, technical and physical safeguards for customer information.

Regulator
FTC / federal banking regulators · United States
Frequency
Maintained continuously; reviewed annually

Program governance

Qualified Individual
M. Okafor, Chief Information Security Officer
Board / governing body reporting
Written report to the Risk Committee at least annually
Last risk assessment
October 2025

Required safeguards

Access controls
Role-based access with quarterly recertification; MFA on all internet-facing systems and privileged accounts.
Encryption
AES-256 at rest; TLS 1.2+ in transit; documented exceptions for legacy ACH file transfer (migration tracked).
Monitoring
24x7 SOC, SIEM with 90-day hot retention, file integrity monitoring on core banking servers.
Service provider oversight
SOC 2 Type II review on onboarding and annually; contractual safeguards & breach notification clauses.

Incident response

Plan owner
CISO; tested via tabletop in March 2026
Notification obligations
Notify federal regulator within 36 hours of determining a 'notification incident' per 12 CFR Part 30 App. B; customer notice per state laws.
↳ Cited: 12 CFR Part 30 Appendix B; 16 CFR § 314.4(h)
Reviewer notes

Example program outline. Final program must reflect a current written risk assessment and address all eight required elements of the Safeguards Rule.

Bank Secrecy Act
FinCEN Form 111

Suspicious Activity Report (illustrative narrative)

Narrative section a bank files via the BSA E-Filing System when it identifies suspicious activity.

Regulator
FinCEN · United States
Frequency
Within 30 days of detection (60 with no identified subject)

Subject & accounts

Subject
[Sample] John D. Sample, DOB 1981-04-12
Accounts involved
Checking xxxx-4421; opened 2024-08; current balance $3,210
Branch / channel
Online channel, IP geolocated to varied US states

Activity

Date range
January 5 – April 2, 2026
Total activity
$184,300 in 23 inbound P2P payments; $179,000 outbound wires to one foreign beneficiary
Pattern
Funds received in amounts just below $10,000 from unrelated individuals across the US, consolidated, and wired same-day to a single beneficiary in [country]. No apparent business rationale.

Narrative

Five Ws
Between Jan 5 and Apr 2, 2026, subject received 23 inbound P2P transfers totalling $184,300 from 21 unrelated senders. Within 24 hours of each batch, subject originated outbound international wires to a single beneficiary in [country], totalling $179,000. Activity is inconsistent with the stated occupation (graphic designer) and historical account behaviour (avg monthly turnover $4,200 prior to Jan 2026). Pattern is consistent with possible money mule / funnel account activity.
Actions taken
Account placed on enhanced monitoring; outbound wire limits reduced; CDD refresh requested; relationship review scheduled.
Reviewer notes

Sample narrative only — do not submit. Real SARs must use the actual FinCEN Form 111 fields and be filed through the BSA E-Filing System; the SAR itself and its existence are confidential under 31 USC § 5318(g)(2).

Want forms tailored to your business?

The free AI assessment maps these requirements to your industry, region and data profile.