Select your language

Blog

Blog description

AML Whistleblowers: BSA and SAR Violations, FinCEN Awards, Retaliation Protections, and Financial Crime Enforcement

AML Whistleblowers: BSA and SAR Violations, FinCEN Awards, Retaliation Protections, and Financial Crime Enforcement

An AML analyst is instructed to close suspicious-transaction alerts without reviewing the underlying payments. A customer due diligence specialist discovers that an account’s disclosed beneficial owner is a nominee. A compliance officer repeatedly warns that required Suspicious Activity Reports are not being filed, only to be told that the customer relationship is too profitable to disrupt.

Each situation could begin as an internal compliance concern. With credible evidence of a covered violation, however, it could also become a federal whistleblower matter.

The federal anti-money laundering whistleblower framework gives individuals a potentially significant financial incentive to report qualifying misconduct. It also creates legal considerations that extend beyond the underlying transactions: originality of information, award eligibility, confidentiality, lawful evidence preservation, employment retaliation, and the institution’s response to internal warnings.

2026 may mark a turning point for AML whistleblower enforcement in the United States.

The program is entering an important phase in 2026. On April 1, FinCEN published proposed regulations addressing whistleblower submissions, eligibility, award applications, and related protections. FinCEN is already accepting tips, although its current guidance states that award processing and payment will begin after the implementing regulation is finalized. A submission can therefore be made now, but submitting information does not itself establish entitlement to an award.

531

For financial institutions, the practical lesson is not that every compliance disagreement will generate an enforcement action. It is that credible internal warnings should be evaluated through a process capable of distinguishing reasonable compliance judgment from serious misconduct—and demonstrating what the institution did once the issue was identified.

The Federal AML Whistleblower Framework

The principal statutory authority is 31 U.S.C. § 5323, substantially strengthened by the:

  • Anti-Money Laundering Act of 2020
  • Anti-Money Laundering Whistleblower Improvement Act of 2022. 

FinCEN administers the program, which covers qualifying violations of the: 

  • Bank Secrecy Act (“BSA”),
  • International Emergency Economic Powers Act (“IEEPA”),
  • Trading With the Enemy Act (“TWEA”),
  • Foreign Narcotics Kingpin Designation Act, including covered conspiracies.

The framework is consequently broader than conventional money laundering. Information may concern failures involving AML programs, suspicious activity reporting, customer identification, recordkeeping, money-services-business registration, or covered sanctions violations.

Nevertheless, the program is not a general reward mechanism for every financial dispute or unlawful act. A commercial disagreement, suspected fraud, or state licensing violation does not automatically establish a FinCEN award claim. The analysis must connect the facts to a covered enforcement action and the applicable eligibility requirements.

This distinction is particularly important for fintech companies, payment processors, and digital-asset businesses. Commercial labels do not determine regulatory obligations. The relevant questions concern what the particular entity actually does, whether it falls within an applicable regulatory category, and which requirements govern the activity under review.

A well-founded whistleblower matter therefore begins with the legal obligations of the specific entity, not simply with an allegation that its business practices appear suspicious.

FinCEN Awards: Significant Incentives, but No Automatic Payment

The statute generally provides aggregate awards of 10% to 30% of qualifying monetary sanctions collected when voluntarily supplied original information leads to a successful covered action resulting in sanctions exceeding $1 million. Where several whistleblowers qualify, they may share the applicable award rather than each receiving a separate entitlement to the full percentage range.

The distinction between a penalty announced and money collected is material. So is the composition of the recovery. The statute’s award calculation includes qualifying penalties, disgorgement, and interest but excludes forfeiture, restitution, and victim-compensation payments. A settlement’s headline amount should not simply be multiplied by 30%.

The strength of the information also matters. A whistleblower may identify a genuine problem without providing information that ultimately satisfies the award requirements. Conversely, a comparatively small set of documents may have substantial value if it reveals previously unknown conduct, identifies responsible participants, or explains how controls were deliberately circumvented.

Potential claimants should distinguish four stages: reporting information, assisting an investigation, qualifying for an award, and receiving payment. Progress at one stage does not guarantee the next.

Who May Have a Potential Whistleblower Matter?

Potential sources include:

532

The individual’s title is less important than the information possessed and how it was obtained.

Employees working directly with customer files or transaction systems may be able to explain facts that are difficult to reconstruct externally. An analyst may know why an alert was closed. An onboarding employee may know that an ownership discrepancy was never resolved. An auditor may possess contemporaneous evidence that a promised correction was not implemented.

Original information generally must come from independent knowledge or analysis and satisfy statutory restrictions concerning information already known to authorities or derived exclusively from specified public sources. Merely repeating published allegations is different from providing previously unknown records or a substantiated analysis.

The program also has an international dimension. FinCEN expressly recognizes that individuals outside the United States may potentially qualify. A foreign-based employee or counterparty should therefore not assume that geography alone prevents a submission. The underlying conduct must still have the necessary jurisdictional connection; a transaction’s denomination in U.S. dollars does not, by itself, resolve every jurisdictional question.

A preliminary assessment should also address the individual’s participation in the conduct. Reporting suspected violations does not provide general immunity, and personal exposure may require advice separate from an evaluation of possible award rights.

BSA and SAR Violations: When Internal Failures Become Evidence

Deliberate Failure to File Required SARs

Suspicious Activity Reports are a central component of the BSA framework. Applicable requirements differ by institution, but they generally require reporting when specified transaction, suspicion, and monetary criteria are satisfied. A financial institution need not prove an underlying crime before filing a required SAR. Equally, the generation of an automated alert does not automatically mean that filing is required.

A potentially significant matter arises when personnel identify reportable activity and management suppresses filing for an improper reason. Consider a hypothetical institution that receives repeated written recommendations concerning a customer’s unexplained transfers. If management acknowledges the concerns but directs employees not to report because the customer generates substantial revenue, the internal communications may be especially important.

The relevant evidence would explain the transactions, applicable reporting standard, information available to decision-makers, and reasons for the decision. An employee’s disagreement with a filing determination is not enough on its own.

Delayed or incomplete reporting may also be relevant. Investigators may examine whether material counterparties were omitted, whether a narrative concealed the known pattern, or whether a backlog repeatedly prevented timely reporting.

Manipulation of Transaction Monitoring

Monitoring systems require adjustment. Reducing false positives, improving data quality, and directing resources toward higher-risk activity can be legitimate compliance objectives.

The concern is different when changes are designed to suppress inconvenient findings. Examples might include removing particular customers from surveillance, disabling scenarios after repeated warnings, or increasing thresholds without a defensible assessment of the resulting coverage gaps.

A useful submission should explain what changed and why it mattered. Configuration records, validation findings, quality-control results, and management instructions can reveal more than a general statement that the monitoring system was inadequate.

The distinction is between improving a control and making risk less visible.

Improper Alert Closure and Misleading Compliance Records

Backlog pressure can create another source of exposure. An institution may report that thousands of alerts were resolved even though analysts lacked the time or information necessary to investigate them.

A hypothetical complaint would be stronger if it identified instructions to use standardized closure language without reviewing transactions, together with records showing that management knew the resulting statistics were unreliable.

The same reasoning applies to audit remediation. A control failure is one issue; falsely representing that the failure has been corrected is another. FinCEN’s 2026 Canaccord action emphasized prolonged monitoring and due-diligence deficiencies, inadequate resources, and failures to address previously identified weaknesses.

KYC and Customer Due Diligence: The Foundation of Meaningful AML Controls

Know Your Customer (“KYC”) practices are central to financial-crime compliance because transaction monitoring depends on understanding the customer relationship. An institution cannot meaningfully assess whether payments are consistent with a business it has inaccurately identified or misunderstood.

KYC is an industry term encompassing several functions rather than one uniform legal requirement. These may include customer identification, beneficial-ownership identification, understanding the nature and purpose of the relationship, developing customer risk profiles, and ongoing monitoring. FinCEN’s Customer Due Diligence (“CDD”) framework applies to specified categories of covered financial institutions; its requirements should not automatically be attributed identically to every payment or technology business.

 

Customer Identification Is More Than a Completed File

For banks, Customer Identification Program (“CIP”) procedures must enable a reasonable belief that the institution knows the customer’s true identity. Verification may involve documentary or non-documentary methods, and procedures must address circumstances in which identity cannot be adequately verified.

A potential whistleblower may identify approvals issued despite unresolved identity discrepancies, instructions to bypass failed verification results, or records describing checks that were never performed.

The issue is not whether every onboarding file contains a minor omission. It is whether the institution’s practices satisfy its applicable obligations and whether material discrepancies were knowingly disregarded.

For example, an employee might discover that several apparently unrelated customers are using inconsistent identification documents but share the same representative and payment beneficiaries. A credible submission would explain those connections, the institution’s response, and why the unresolved information mattered.

Customer Risk Profiles Must Reflect the Actual Relationship

Customer due diligence should inform how the institution understands expected activity. A customer described as a domestic retailer presents a different profile from an international intermediary moving funds for third parties. Ongoing monitoring and risk-based updates are important where information changes or contradicts the original description.

Suppose a customer onboarded as a small distributor begins receiving substantial transfers from unrelated overseas entities and rapidly forwarding the proceeds. The transactions do not automatically establish wrongdoing. They do, however, create questions about the accuracy of the customer profile and the adequacy of the institution’s response.

A whistleblower’s information may become significant when it shows that employees identified the discrepancy but were instructed to preserve a low-risk classification to avoid further review.

Source-of-funds or source-of-wealth inquiries may also become relevant, depending on the relationship and applicable requirements. The objective is not to demand identical documentation from every customer, but to assess whether the diligence reasonably addresses the identified risk.

Beneficial Ownership and Concealed Control

Corporate structures, trusts, holding companies, and nominees can serve lawful purposes. Their existence alone is not evidence of misconduct.

The concern arises when the institution possesses reliable information contradicting the ownership or control represented in its records. Under the generally applicable CDD beneficial-ownership framework, covered institutions identify relevant individuals under an ownership prong (generally 25% or more) and a control prong, subject to exclusions and exceptions. Reliance on customer-supplied information is qualified where known facts reasonably call its reliability into question.

A potentially serious hypothetical involves an employee discovering documents showing that a disclosed shareholder is a nominee for another person, followed by instructions to retain the original certification and avoid further inquiry.

That information could affect more than onboarding. It may change the customer’s risk classification, sanctions analysis, transaction-monitoring expectations, and evaluation of suspicious activity.

The February 2026 Beneficial-Ownership Relief

On February 13, 2026, FinCEN issued FIN-2026-R001, providing relief from repeating beneficial-owner identification and verification at every additional account opening. The order preserves those steps at the first account opening, when known facts reasonably call previous information into question, and as required by risk-based ongoing CDD procedures. Other applicable BSA obligations remain in place.

This development matters to both institutions and whistleblowers. Failure to repeat a check covered by valid relief is not automatically a violation. Conversely, the relief does not justify ignoring credible evidence that existing ownership information is false.

The relevant question remains whether the institution complied with the requirements actually applicable to the relationship—not whether it followed an outdated checklist or collected the greatest possible volume of documents.

SAR Confidentiality and the September 2026 Clarification

SAR confidentiality presents a distinct legal issue. Applicable rules generally protect a SAR and information revealing its existence, subject to authorized disclosures. The restrictions are not limited to telling the customer that a report was filed. Specified disclosures to FinCEN and appropriate government authorities are permitted, but unrestricted circulation is not.

533

The underlying transaction evidence must be distinguished from the SAR itself. An invoice, payment record, or customer communication does not automatically become SAR-confidential merely because it supports a filing. Other privacy, privilege, or access restrictions may nevertheless apply.

On September 2, 2026, FinCEN and the federal banking agencies clarified that SAR confidentiality does not prevent appropriate customer communications about potentially fraudulent transactions, other suspicious activity, or account closures, provided protected SAR information is not disclosed. The statement does not alter existing legal requirements or create new supervisory expectations.

For whistleblower matters, this distinction has practical consequences. Institutions should not invoke SAR confidentiality as a blanket reason to avoid examining underlying conduct. Individuals should not assume that a legitimate reporting objective authorizes copying SARs to personal email accounts, sharing them publicly, or using them indiscriminately in employment litigation.

The material, intended recipient, legal authorization, and transmission method should be considered before disclosure.

Digital Assets and the September 2026 Scam Analysis

Digital-asset activity can generate whistleblower information involving customer identity, suspicious payment patterns, wallet ownership, fraud complaints, and management decisions about known risks.

On September 3, 2026, FinCEN published an analysis and alert concerning digital-asset investment scams associated with overseas scam centers. Its review of 33,904 BSA reports filed between September 8, 2023, and December 31, 2025 identified approximately $12.7 billion in financial activity tied to suspected scams. The figure represents reported suspicious activity, not adjudicated criminal proceeds or losses occurring exclusively in 2026.

The significance for whistleblower analysis is the connection between external transaction data and internal knowledge. A blockchain-analysis result may identify suspicious exposure, while customer files, complaints, and employee communications explain who controlled the accounts and what the institution knew.

For example, an insider might possess evidence that repeated fraud complaints and wallet-risk warnings were presented to management but disregarded because the accounts generated significant transaction revenue.

The analysis should remain disciplined. A wallet-risk score is not proof of a legal violation, and cryptocurrency activity is not inherently suspicious. A persuasive submission explains the reliability of the indicators, the relevant obligations, and the institution’s response.

These issues also extend beyond cryptocurrency platforms. Banks and payment intermediaries may possess the fiat-side records necessary to understand a broader digital-asset scheme.

Internal Reporting and FinCEN’s Proposed Procedures

Internal reporting can give an institution an opportunity to investigate, preserve evidence, stop misconduct, and correct deficiencies. It can also establish when responsible personnel became aware of a problem.

Other circumstances require greater caution. Senior management may be implicated, earlier warnings may have been ignored, or the individual may reasonably fear that evidence will be altered. Reporting strategy should therefore reflect the facts rather than a universal instruction either to bypass internal channels or to exhaust them first.

The April 2026 proposal includes an important potential eligibility condition: certain individuals obtaining information through specified organizational roles, internal reporting processes, or audit and compliance functions would be required to wait at least 120 calendar days after obtaining the information before providing it to FinCEN to qualify for an award. This remains a proposed condition, not a universal currently effective instruction to delay reporting.

Award procedures must also be distinguished from an institution’s reporting duties and an employee’s retaliation deadlines. A proposed award-related waiting period should not be assumed to suspend any separate legal obligation.

The practical question is how to report lawfully and effectively while preserving potentially applicable rights, not simply how quickly a complaint can be submitted.

Potentially significant information may include:

535

Retaliation Can Create a Separate Legal Claim

A company facing an AML allegation can create an additional problem by penalizing the individual who raised it. Qualifying protected activity can include internal reports and reports to government authorities. FinCEN expressly recognizes that retaliation complaints may be pursued through the Department of Labor and, in appropriate circumstances, federal court.

The underlying violation and retaliation should be analyzed separately. An employee need not receive a monetary award before potentially having a retaliation claim. Nor does an investigation’s failure to substantiate every allegation automatically establish that the employee’s report was unprotected.

Potential retaliation includes termination, demotion, threats, harassment, blacklisting, and other discriminatory treatment. Where the AMLA provisions apply, available remedies can include reinstatement, twice the back pay owed with interest, compensatory damages, and recoverable litigation expenses.

Coverage requires care. Section 5323(g)(6) excludes employers subject to specified banking and credit-union whistleblower statutes from that subsection. Employees of those institutions may need to rely on separate protections; award eligibility does not establish that every employee has the same employment-law remedy.

Deadlines can be short. For claims governed by the Department of Labor’s AMLA procedures, the regulations generally require filing with OSHA within 90 days of the alleged retaliation. An employee should not assume that waiting for a FinCEN investigation or award decision preserves a separate employment claim.

Whistleblower status does not immunize unrelated misconduct or prevent legitimate performance management. Employment decisions should nevertheless be supported by accurate, independently defensible reasons—not hostility toward protected reporting.

Preserving Evidence and Presenting a Credible Case

A strong submission explains the alleged conduct rather than merely attaching documents. FinCEN encourages specific information about participants, relevant events, the source of the submitter’s knowledge, supporting evidence, and the location of additional evidence outside the submitter’s possession.

The presentation should enable investigators to understand the relevant entities, transactions, time period, approximate financial magnitude, applicable obligations, and potential U.S. connection. A chronology can connect customer onboarding, suspicious transactions, internal warnings, management decisions, and subsequent events.

Documents may implicate:

537

Document quality matters more than volume. A few contemporaneous records identifying a deliberate override may be more useful than thousands of unexplained pages. An evidence index should explain what each significant record establishes and where the analysis remains uncertain.

The basis of knowledge must be transparent. Conduct personally observed, instructions received, information learned from others, and conclusions inferred from records should not be presented as though they were the same.

Evidence collection also requires restraint. A reporting objective is not a general authorization to bypass access controls, use another employee’s credentials, remove unrelated customer files, or alter records. Where important material remains in company systems, identifying its location may be more appropriate than obtaining it through improper means.

A credible submission should help investigators answer five fundamental questions:

536

Confidentiality restrictions require legal analysis rather than blanket assumptions. The Defend Trade Secrets Act, for example, provides qualified protection for certain confidential disclosures to government officials or counsel made solely to report or investigate suspected legal violations. That protection does not generally authorize unlawful access or eliminate unrelated restrictions.

Anonymous reporting may also be available, including through counsel, but anonymity should not be confused with a guarantee that the individual can never be identified. FinCEN’s current submission guidance expressly permits anonymous tips.

How Institutions Should Respond to a Credible Complaint

An institution’s response should be proportionate, independent, and capable of surviving later scrutiny. It should neither assume that the allegation is correct nor dismiss it because the employee is junior, dissatisfied, or commercially inconvenient.

Evidence preservation comes first. Relevant material may include customer files, transaction records, monitoring configurations, internal messages, audit findings, and personnel records. Where appropriate, automatic deletion should be suspended and the original state of affected systems preserved before remediation changes obscure what happened.

Investigative independence is equally important. A manager accused of suppressing alerts should not determine whether those allegations are examined. Matters involving senior executives or the compliance function may require independent board oversight or outside counsel.

The institution should separate its investigation from employment decisions concerning the complainant. Relevant managers and human-resources personnel should understand the need to prevent retaliation, including less visible actions such as removing responsibilities, isolating the employee, or threatening future employment.

The legal assessment should follow the facts. A complaint described as a KYC issue may also implicate SARs, sanctions, registration, or misleading regulatory submissions. Investigators should distinguish legal requirements from internal policies and preferred practices, including considering any applicable 2026 relief.

Where a deficiency is substantiated, corrective action should not necessarily await completion of every investigative step. Appropriate measures may include customer reviews, changes to monitoring, additional resources, revised escalation, training, or retrospective transaction analysis. The institution should test whether the correction works, not merely document that a policy was revised.

Finally, counsel should assess mandatory reporting separately from voluntary disclosure. Management should not assume that the government will learn of the conduct only if the company elects to disclose it.

Other circumstances may raise concerns about:

538

The appropriate strategy therefore depends on the facts.

What the 2026 Enforcement Actions Demonstrate

Recent enforcement illustrates the potential consequences of substantial BSA failures.

On March 6, 2026, FinCEN assessed an $80 million civil penalty against Canaccord Genuity LLC. Its findings included AML-program deficiencies, inadequate risk-based customer diligence, ineffective monitoring, and failures to file required SARs.

On August 3, 2026, FinCEN assessed a $125 million civil penalty against UBS Financial Services Inc. The agency identified continuing monitoring deficiencies, inadequate customer diligence, and untimely suspicious activity reporting, including problems that persisted after an earlier enforcement action.

These matters should not be described as whistleblower-generated without supporting evidence. Their relevance is that prolonged and serious failures can result in substantial sanctions—and that the institution’s response to earlier warnings can become central to the enforcement analysis.

The enforcement developments should be read alongside FinCEN’s April 7, 2026 proposed AML/CFT program reforms, which emphasize risk-based, reasonably designed programs and effectiveness. The proposal is not permission to abandon existing duties.

Taken together, the developments reinforce a useful distinction. A tested decision to direct resources toward meaningful risk is different from a decision to make inconvenient risk disappear from management reports. Contemporaneous evidence may help investigators determine which occurred.

Counsel and Coordinated Financial-Crime Analysis

Whistleblower counsel’s work extends beyond preparing a complaint. It may include assessing jurisdiction, eligibility, confidentiality, personal exposure, evidence preservation, reporting strategy, and separate retaliation procedures.

Company counsel faces a different responsibility: establishing an independent investigation, identifying applicable obligations, evaluating remediation, protecting against retaliation, and assessing government communications.

Complex matters may also implicate other programs. DOJ’s Corporate Whistleblower Awards Pilot Program addresses specified corporate misconduct and may reward information leading to successful forfeiture. Its criteria differ from FinCEN’s statutory framework; multiple agency interests do not create an automatic right to cumulative awards.

The objective in either setting should be a reliable factual record and accurate legal analysis, not an exaggerated accusation, a guaranteed award, or a predetermined internal conclusion.

Conclusion

The federal AML whistleblower framework gives credible information about financial-crime violations a potentially significant enforcement role and financial value. Its importance extends across BSA compliance, SAR reporting, KYC, beneficial ownership, transaction monitoring, sanctions, and digital assets.

The 2026 developments make precision especially important. Proposed whistleblower procedures must be distinguished from existing rights. Beneficial-ownership relief must not be confused with permission to disregard unreliable customer information. SAR confidentiality must protect restricted information without obscuring underlying conduct.

For potential whistleblowers, the priorities are specificity, credibility, lawful evidence handling, and careful attention to reporting and retaliation procedures. A compelling matter explains what occurred, why it may violate an applicable requirement, who knew about it, and what evidence supports the account. An award remains a possible statutory outcome, not a promised result.

539

For institutions, effective compliance includes a credible response when employees identify problems. Preserving records, investigating independently, preventing retaliation, and correcting substantiated deficiencies are essential to that response.

An internal AML warning can become an external whistleblower submission. The most defensible response is not to suppress the warning, but to establish the facts and act on them.

Select your language