The independent test your examiner, bank partner and board will ask for.
Annual independent BSA/AML reviews for money services businesses and fintechs, second- and third-line testing for banks, and validation of remediation under enforcement. Risk-based test scripts, workpapers an examiner can follow, and findings your board can act on.
An Independent Test That Holds Up to a Second Look
A BSA/AML program generally has to be tested by someone independent of the people who run it. For banks, independent testing is one of the required pillars of the program. For money services businesses, the BSA rules require the AML program to provide for an independent review, with its scope and frequency commensurate with the risk of the services offered. Fintechs under a sponsor bank often find the same expectation written into their program agreement.
A review is only as useful as the testing behind it. Your examiner, your bank partner and your board may each read the report, and each tends to ask the same questions: what was tested, how, and what the evidence showed. We build the review so every conclusion traces back to a test script, a sample and a workpaper.
Independent testing is part of our bank and fintech compliance practice, and every review is principal-led, with direct access to senior expertise from scoping to the final report. Our principal brings 15+ years across Big 4 advisory firms and Fortune 500 financial institutions, and has led AML/BSA validations and consent order remediation programs, most recently leading third-line FDIC consent order validation.
Regulator-facing experience: direct engagement with FinCEN, state banking departments, FDIC and OCC exam teams and the DOJ, plus Big Four and national-firm validation work.
Where Clients Start
The need for an independent review usually arrives with a date attached. Start where you are.
An exam is on the calendar
Your federal examiner or state regulator has scheduled a visit. The first request list typically asks for your most recent independent test, its scope, and what you did about its findings.
Your bank partner asked for the annual review
Your program agreement calls for an independent review, and the bank wants the report, the scope and the reviewer's qualifications by a set date.
Sponsor bank readinessThe program changed since the last test
A new product, a new market, a new monitoring system or a rebuilt program since your last review. Examiners and bank partners are likely to want evidence that the new version works, not only that it is written.
Under a consent order or MRA
Remediation is done, or close to it, and you need independent validation that each corrective action is in place and operating before you ask for closure.
Consent order and MRA remediationOne Testing Discipline, Three Settings
The method is the same wherever we test: risk-based scripts, documented evidence and findings management can act on. What changes is who relies on the result.
Annual Independent Review
For money transmitters, payments companies and other money services businesses, and for fintechs under a sponsor bank. The review tests the whole AML program against the BSA rules that apply to you, any state license requirements and your program agreement, and is built for your state examiner and your bank partner to review. Remittance MSBs can also start with U.S.-Africa remittance corridor compliance.
Which U.S. rules require an independent review2LOD and 3LOD Testing
For community banks, regional institutions and larger banks. We test as part of a second-line compliance testing function, or alongside internal audit as a third-line co-source or outsourced provider, across the full BSA/AML program or targeted areas such as transaction monitoring, sanctions or CDD/EDD. Sponsor banks can extend the same testing to the fintech programs they oversee.
Fintech partner oversight for sponsor banksRemediation Validation
For institutions under a consent order or working through MRAs. We test whether each corrective action addresses the finding and is operating as intended, using risk-based test scripts and sampling, and document the evidence that supports closure for your board and your regulator.
Consent order and MRA remediationWe Do Not Test What We Built
An independent review is only independent if the reviewer had no hand in the work being tested. We decline to test programs we designed. If Ethixera wrote your policies, built your procedures, tuned your monitoring or holds your compliance seat, we will tell you so at scoping and will not take on the review of that work.
The rules leave some room in who performs the test. Banks can use internal audit, outside auditors or consultants. For money services businesses, the BSA rule allows the review to be done by an officer or employee, as long as the reviewer is not the person designated as compliance officer.
Examiners generally look at whether the reviewer is independent of the function tested and qualified to test it, and, for banks, whether results are reported to the board or a committee of it.
If you need a program built and later tested, plan for two providers. Ethixera can be either one, not both. If what you need is someone in the seat rather than someone testing it, see BSA/AML officer of record.
Scope, Test, Report, Validate
Every review runs in four steps. Timing depends on your size, your products and the period under review, and we confirm it at scoping.
- 01
Scope
We start from your risk assessment, your license or charter, your products and customers, prior findings, and what your regulator and bank partner require. We confirm independence, then agree the areas in scope, the review period, the sampling approach and the timeline in writing.
- 02
Test
We write a risk-based test script for each area, walk through processes with the people who run them, review documentation, re-perform key controls, and sample customer files, alerts, cases, SAR decisions and screening hits. Every test is documented in workpapers with the evidence behind it.
- 03
Report
Findings are rated by severity, tied to a root cause and paired with a recommendation. Exceptions go back to management before anything is final, management responses are recorded with owners and dates, and the report goes to your board or its committee.
- 04
Validate
When management reports a finding as fixed, we test that the fix is in place and operating, and document the closure evidence finding by finding, so the next examiner or bank review sees closure, not a promise.
What You Receive
Each deliverable is built so someone who was not in the room, whether an examiner, a bank partner or next year's reviewer, can follow it.
Scope and Test Plan
The areas in scope, the review period, the risk basis for each area, the sampling approach and the timeline, agreed with you before testing starts.
Test Scripts
A risk-based script for each area, setting out the requirement, the test steps, the sample and what counts as an exception. Scripts are written for your program, not pulled from a generic checklist.
Workpapers
The record of every test performed: what was sampled, what was reviewed, what was found and the evidence behind each conclusion, organized so a reviewer can follow it from start to finish.
Findings Report
Findings rated by severity, with root cause, recommendation, management response, owner and target date, alongside the areas tested without exception.
Board and Bank-Partner Summary
A short summary for your board or committee, and a version for your bank partner where your program agreement calls for one, covering scope, overall conclusion, findings and remediation status, written with SAR confidentiality in mind.
Closure Evidence
For each finding, the evidence that the fix is in place and the follow-up testing that confirms it operates, ready for the next exam, bank review or independent test.
Testing and Validation Experience
Anonymized engagements reflecting the scope and impact of our work.
Mid-Size Community Bank · Southeast
Led independent 3rd-line validation testing under FDIC consent order. Developed risk-based test scripts and executed validation across 20+ remediation initiatives spanning AML, GRC, and enterprise governance workstreams.
Top 10 U.S. Financial Institution
Directed BSA/AML testing and MRA validation across a multi-year remediation program. Managed quality assurance across the KYC customer file refresh program evaluating CDD/EDD standards.
Top 25 U.S. Banking Institution
Conducted comprehensive 2LOD compliance testing and transactional reviews across the Banking division. Identified deficiencies and recommended actionable remediation strategies.
Reading for Teams Preparing for an Independent Review
What the 2026 BSA/AML exam cycle is signaling to mid-size institutions
For banks preparing for their next BSA/AML exam or independent test.
2026 BSA/AML exam cycle signalsThe independent BSA/AML review for MSBs: what examiners and bank partners expect to see
For money services businesses with a review coming due, or a bank partner asking for one.
The independent BSA/AML review for MSBsQuestions we hear
How often does an MSB need an independent review?
The BSA rules require a money services business's AML program to provide for an independent review, and they tie its scope and frequency to the risk of the services the business provides. They do not set a fixed calendar interval.
In practice, many state regulators and bank partners expect a review at least annually, and some put that expectation in writing, for example in a program agreement. A higher-risk profile, such as cross-border transfers, cash-intensive agents or rapid growth, can justify more frequent or deeper testing of specific areas.
We recommend an interval based on your risk and on what your regulators and bank partner require. Our guide to which U.S. rules require an independent BSA/AML review sets out where the requirement comes from. Ethixera Advisory is not a law firm and does not provide legal advice, so the legal reading of what your license requires stays with your counsel.
Can the firm that built the program test it?
Not if the test is meant to be independent. A reviewer who designed the policies, built the procedures or tuned the monitoring is testing their own work, and examiners and bank partners are likely to discount that. We decline to test programs we designed, and we will not review a program where Ethixera holds the BSA/AML officer or compliance seat.
For money services businesses, the BSA rule does allow the review to be done internally, by an officer or employee other than the designated compliance officer. Examiners still generally expect the reviewer to be independent of the work tested and qualified to test it. If Ethixera built your program, plan for a different reviewer. If another firm or your own team built it, we can test it.
What do you deliver?
Six things. A scope and test plan agreed before testing starts. Risk-based test scripts for each area in scope. Workpapers documenting every test, sample and conclusion, with the evidence behind it. A findings report with severity, root cause, recommendation, management response, owner and target date. A summary for your board or committee, and for your bank partner where your program agreement calls for one. And, once remediation is done, closure evidence and follow-up testing for each finding.
The report is a compliance testing report, not a legal opinion.
Do you test transaction monitoring and sanctions screening?
Yes. Both are core to the review. For transaction monitoring, we test whether the scenarios and thresholds cover the risks in your risk assessment, whether the data feeding the system is complete and accurate from source to alert, whether alerts are worked on time and to a documented standard, and whether investigations reach sound, timely SAR decisions.
For sanctions screening, we test which lists you screen against and whether that matches your program, how matching is configured, whether customers and transactions are screened and rescreened when lists change, and how alerts are dispositioned and documented.
We test inside the systems you already run. If we tuned your monitoring or screening, that area goes to a different reviewer. Tuning is a separate service in our bank and fintech compliance practice.
Will the review satisfy our sponsor bank?
The bank decides that, not the reviewer, so we start from what the bank asks for. Program agreements can specify the scope of the independent review, how often it happens, who may perform it, what qualifications the reviewer needs and how the report is delivered.
We ask for those terms, and for any prior bank findings, before we scope, and we build the review to meet them. Where the bank's requirements go beyond the BSA minimum, the review follows the bank's requirements. The report and workpapers are organized so the bank's own reviewers can follow each conclusion back to the evidence. For the rest of the file a bank will ask for, see sponsor bank readiness.
An Independent Review Coming Due?
Tell us what you are licensed or chartered to do, what your examiner or bank partner expects, and when your program was last tested. We will scope a review that fits your risk and confirm our independence before we start.
