Money Transmitter AML Compliance: MTL, MSB Registration and BSA Obligations
Most AML guidance is written for banks. Money transmitters carry a materially different burden: federal obligations under the Bank Secrecy Act, plus a state-by-state licensing regime with its own examiners, its own standards and its own timetable.
Two regimes, not one
Federal: FinCEN and the BSA
A money transmitter is a money services business under FinCEN's regulations. MSBs must register with FinCEN, renew that registration periodically, and maintain a list of agents. Registration is not a licence and confers no authorisation to operate — a point that confuses new entrants.
The MSB AML programme requirement has four pillars: policies, procedures and internal controls; a designated compliance officer; ongoing training; and independent review. "Independent review" is the MSB analogue of internal audit — it need not be performed by an external firm, but it must be performed by someone not responsible for the programme.
State: money transmitter licensing
Transmission is separately licensed by each state in which you do business, generally through NMLS. Licensing brings net worth and surety bond requirements, permissible investment rules requiring transmission obligations to be backed by qualifying assets, change-of-control approval, and periodic state examinations.
The Money Transmission Modernization Act has driven meaningful convergence across adopting states, but divergence remains — particularly around what activity constitutes transmission, and in the treatment of digital assets. Multi-state operations need a licensing matrix mapping activity to each state's requirements.
Thresholds that differ from banking
Several MSB-specific rules catch teams accustomed to bank BSA requirements.
- Currency Transaction Reports. The familiar threshold applies to currency transactions above $10,000 in a day by or on behalf of one person, with aggregation.
- Suspicious Activity Reports. The MSB SAR threshold is $2,000 — materially lower than the bank threshold. Programmes ported from a banking environment have been found filing against the wrong threshold entirely.
- The funds transfer and travel rules. Recordkeeping obligations attach at $3,000 for transmittals of funds, with originator and beneficiary information required to travel with the transmittal. Note this is the BSA travel rule, distinct from the FATF travel rule for virtual assets, though firms handling both must comply with each.
- Monetary instrument logs. Recordkeeping for cash purchases of monetary instruments in the $3,000–$10,000 range.
Aggregation is where most findings originate. Structuring detection requires linking transactions across agents, locations, and — where identifiers are partial — across probable identity matches. See structuring detection.
The agent oversight problem
Principals bear responsibility for BSA compliance at their agent locations. This is the single largest structural risk in the model, and the most common source of enforcement action.
An adequate agent oversight programme has four components. Risk-based due diligence before appointment, covering ownership, criminal history, and the risk profile of the location. Ongoing transaction monitoring at agent level — not merely customer level — to detect agents whose activity pattern is anomalous relative to peers. Periodic on-site or remote review, with frequency driven by risk. And a documented termination process with evidence it is used, because an oversight programme that has never terminated an agent invites scrutiny of whether it is real.
Agent-level monitoring deserves emphasis. Complicit agents generate patterns invisible at customer level: unusual proportions of transactions just below thresholds, activity outside business hours, customer identifiers reused across nominally unrelated transactions, or volumes inconsistent with the location's demographics.
Customer identification in a transmitter context
Transmitters frequently serve occasional customers rather than account holders, which changes the CDD problem. Identification obligations attach at transaction thresholds rather than at account opening, and much activity is non-recurring.
This makes two capabilities disproportionately valuable: identity resolution across transactions, so a sequence of occasional transactions by one person is recognised as such; and rapid verification, because a transmitter's customer is standing at a counter or waiting in an app, not completing a multi-day onboarding. See eKYC and digital identity verification.
Preparing for a state examination
State examiners test the BSA programme, but they also test matters federal examiners do not: permissible investments and whether transmission liabilities are adequately backed, the accuracy of transaction reporting to the state, bond adequacy against volume, and consumer protection obligations including disclosures and refund handling.
Maintain a single evidence pack covering both regimes. Firms that maintain separate federal and state files typically find the two have drifted, and reconciling them under examination conditions is not the moment to discover it. See examination preparation for the general approach.
Summary
The money transmitter compliance burden is not simply a bank programme scaled down. The SAR threshold is lower, recordkeeping attaches at transaction thresholds rather than relationships, agent oversight has no banking analogue, and a second supervisor with different priorities examines the same business. Programmes designed for one regime and assumed adequate for the other are where enforcement actions come from.
This is a summary of a complex and state-variable regime, not legal advice — verify current requirements for each state in which you operate.
Building the State Licensing Matrix
Multi-state operations need a single authoritative record of what is permitted where. Without it, product and compliance drift apart and the first sign of a gap is an examination.
The matrix should hold, per state: licence status and number, the activities that licence authorises, net worth and surety bond requirements against current volume, permissible investment obligations, authorised agent locations, change-of-control and material-change notification triggers, and the examination cycle with the date of the last visit.
Two columns matter more than the rest. Activity scope, because what constitutes money transmission varies — payroll processing, agent-of-the-payee arrangements and digital-asset activity are treated differently across states, and operating outside scope is a licensing violation independent of any AML consideration. Volume against bond, because surety and net worth requirements scale with transmission volume in many states; growth quietly moves a firm out of compliance without anyone making a decision.
Review the matrix on a defined cycle and whenever a product changes. The Money Transmission Modernization Act has reduced divergence among adopting states, but adoption is uneven and the differences that remain are precisely the ones that catch firms out.
Sanctions Obligations Do Not Scale Down
Unlike several BSA obligations, US sanctions requirements are not calibrated to institution size or licence type. A small transmitter carries the same prohibition on dealing with blocked persons as a global bank.
Three implications follow. Screening must cover every party — sender, recipient, and where relevant the beneficiary institution and any intermediary — not only the paying customer. List currency matters operationally: designations take effect on publication, so a screening system refreshed weekly carries a real exposure window. Blocking and rejecting are different actions with different reporting consequences and timelines, and staff need to know which applies.
Transmitters serving corridors with heavy sanctions exposure should also expect requests about indirect exposure — whether funds are ultimately destined for a sanctioned jurisdiction despite an unremarkable immediate counterparty. See sanctions evasion red flags for the typologies that matter most in a remittance context.
Agent Offboarding and Termination
Agent oversight programmes are usually built around onboarding and monitoring, and thin at the point where they matter most. Termination is where the risk concentrates.
Three questions should have documented answers before an agent is terminated. What happens to pending transactions at the point of termination, and who completes or unwinds them. What records the principal retains, and for how long — the BSA recordkeeping obligation survives the relationship and the records are frequently held at the location. Whether a report is required, because termination prompted by suspected complicity ordinarily indicates a filing obligation that termination does not discharge.
There is also a re-entry risk specific to this model. An agent terminated for cause can reappear under a different entity name, sometimes at the same address with the same principals. Screening new agent applications against terminated-agent records — including principals and addresses, not just entity names — is a cheap control that few programmes implement.
Finally, keep the FinCEN agent list current. It is a registration obligation in its own right, and a list that does not reflect terminations is both a compliance gap and evidence that the oversight programme is not operating as described.
Built for MSB and Transmitter Volumes
One Constellation handles identity resolution across occasional customers, agent-level monitoring and the reporting thresholds specific to money services businesses.
