Do you need a designated compliance officer?
A plain-language guide to which U.S. rules require a designated compliance or BSA/AML officer, and which require a periodic independent review, for the markets we work in. Find your row, then decide whether you need the seat, the review, or both.
Two Questions: The Seat and the Test
Alongside internal controls and training, most U.S. anti-money laundering program rules ask two things of a regulated business. First, name a person responsible for day-to-day compliance: the designated compliance officer, usually called the BSA officer or BSA/AML officer. Second, have the program tested by someone independent of the people who run it.
Whether either applies to you depends mainly on what you do and how you are chartered, licensed or registered.
The matrix below sets out, market by market, what each requirement asks for and where it comes from. It covers the markets Ethixera works in: banks, money services businesses and payments companies, fintechs operating under a sponsor bank, digital asset businesses, and gaming and sports wagering. A second table covers securities, insurance and healthcare for reference only.
Two layers sit on top of the federal rules in most cases. State licensing and gaming regulators add their own conditions, and bank partners write program agreements that often ask for more than the rule does. Where the answer depends on your structure, the matrix says "generally" and explains why.
Working through this from one side of a sponsorship? Founders can start with compliance for fintech founders, and banks with fintech partner oversight for sponsor banks.
Which U.S. Rules Require the Seat and the Review
Read across your row. A company can sit in more than one row, for example a fintech under a sponsor bank that also holds its own state money transmitter licenses. Where that is you, each row applies, and the strictest one usually sets your floor.
| Market | Designated officer required? | Independent review or testing required? | Where it comes from | How we help |
|---|---|---|---|---|
| Banks Insured banks and savings associations, whichever federal agency supervises them | Yes. The BSA/AML program must designate an individual or individuals responsible for coordinating and monitoring day-to-day compliance, the role usually called the BSA officer. | Yes. Independent testing is a required element of the program, performed by bank personnel or an outside party. The rules do not fix a frequency; examiners look for one that fits the bank's risk profile. | FDIC: 12 CFR 326.8. OCC: 12 CFR 21.21. Federal Reserve: 12 CFR 208.63. FinCEN: 31 CFR 1020.210. Federally insured credit unions follow a parallel NCUA rule, 12 CFR 748.2. | Second- and third-line testing, remediation validation under enforcement, and support for your BSA officer. Independent BSA/AML review |
| Money services businesses and payments Including money transmitters, dealers in foreign exchange, check cashers, and providers and sellers of prepaid access | Yes. The written AML program must designate a person to assure day-to-day compliance, including filing reports, keeping records, updating the program and training staff. | Yes. The program must provide for an independent review, with scope and frequency commensurate with the risk of the services offered. An officer or employee may perform it, but not the designated compliance person. Many state regulators and bank partners expect it at least annually. | FinCEN: 31 CFR 1022.210. Most MSBs must also register with FinCEN. State money transmitter laws and license conditions add requirements that vary by state. | A named BSA/AML officer of record, or the independent review, but not both for the same program. BSA/AML officer of record Money transmitter licensing |
| Fintechs under a sponsor bank Banking-as-a-service, card, deposit and lending programs offered through a bank partner | Generally not by federal rule, unless your own activity makes you a money services business or another covered institution. The bank generally holds the BSA obligations for the program, and program agreements commonly require you to name a compliance officer. | Generally not by federal rule for the fintech itself. Program agreements commonly require an independent review of your program, and the bank tests your controls as part of its own oversight. | The sponsor bank's own BSA/AML program rules and third-party risk management, including the 2023 interagency guidance on third-party relationships, as written into your program agreement. | Sponsor bank readiness, then either the seat (fractional CCO leadership or a named officer on defined terms) or the independent review your agreement calls for. Sponsor bank readiness |
| Digital assets Businesses that accept and transmit convertible virtual currency, such as exchangers, hosted wallet providers and kiosk operators | Generally yes. FinCEN treats many convertible virtual currency businesses as money transmitters, so the MSB program rule and its designated compliance person apply. | Generally yes, under the same MSB rule. Some state regimes add their own testing requirements. | FinCEN: 31 CFR 1022.210, applied through FinCEN's 2013 and 2019 guidance on convertible virtual currency. State regimes, such as New York's virtual currency rule (23 NYCRR Part 200), add their own compliance officer and testing requirements. | AML program design for digital asset platforms, plus the officer seat or the independent review as for other MSBs. Bank and fintech compliance |
| Gaming and sports wagering Casinos, card clubs, tribal gaming operations and state-licensed sports wagering operators | Yes, for covered casinos and card clubs. The compliance program must name an individual or individuals to assure day-to-day compliance. Coverage generally reaches licensed or authorized casinos and card clubs with more than $1 million in gross annual gaming revenue. Sports wagering and online operators can fall within the casino definition, depending on how they are licensed and their gaming revenue. | Yes, for covered casinos and card clubs: internal or external independent testing, with scope and frequency commensurate with the money laundering and terrorist financing risks of the products and services offered. | FinCEN: 31 CFR 1021.210. State gaming regulators, and tribal gaming regulators for tribal operations, add requirements that vary by jurisdiction. | AML compliance and regulatory architecture for operators in licensed state markets. Financial crimes advisory |
Informational only. Not legal advice. Confirm your obligations with your counsel. This page summarizes general U.S. requirements in plain language. Rules and guidance change, and how they apply turns on your facts, your charter or licenses, and your agreements.
Securities, Insurance and Healthcare: Informational Only
These sectors also have designated officer and testing requirements. We include them so the picture is complete. We do not offer these seats.
| Market | Designated officer required? | Independent review or testing required? | Where it comes from | How we help |
|---|---|---|---|---|
| Securities Broker-dealers and registered investment advisers | Yes. Broker-dealers must designate an AML compliance person under FINRA Rule 3310. Registered investment advisers must designate a chief compliance officer under SEC Rule 206(4)-7. | Broker-dealers: yes, generally annual independent AML testing, or every two years for certain firms without customer business. Advisers: an annual review of compliance policies and procedures, which the rule does not require to be independent. | FINRA Rule 3310 and FinCEN's 31 CFR 1023.210 for broker-dealers. SEC Rule 206(4)-7 under the Investment Advisers Act for registered investment advisers. | Informational only. We do not offer this seat. |
| Insurance Insurers issuing covered products, such as permanent life insurance and annuities other than group policies | Yes, for insurers issuing covered products: the AML program must designate a compliance officer responsible for implementing it effectively. | Yes. Independent testing, including of agents and brokers, with scope and frequency commensurate with the risks of the covered products. The designated compliance officer cannot perform it. | FinCEN: 31 CFR 1025.210. | Informational only. We do not offer this seat. |
| Healthcare Providers, suppliers and health plans | Generally recommended, not required. HHS-OIG compliance program guidance recommends a compliance officer. Some settings make one mandatory, such as Medicare Advantage and Part D sponsors and organizations under a corporate integrity agreement. HIPAA separately requires covered entities to designate a privacy official and a security official. | Recommended, and not a BSA/AML requirement. The guidance calls for regular auditing and monitoring; mandatory programs and agreements set their own terms. | HHS-OIG General Compliance Program Guidance (voluntary). Medicare Advantage and Part D sponsor rules, 42 CFR 422.503 and 423.504. HIPAA, 45 CFR 164.530 and 164.308. | Informational only. We do not offer this seat. |
What the Rules Mean on the Ground
The citations tell you whether a requirement applies. Examiners and bank partners then ask whether it works. Four points hold across most rows.
Designated means named, with authority
The federal rules do not require a particular title or professional certification. What examiners and bank partners generally look for is a named person with the knowledge, authority, independence and resources to run the program day to day, backed by the board or, in a smaller company, its owners.
Independent means independent of the work
Banks can use internal audit, outside auditors or consultants. Money services businesses and insurers can use an officer or employee, but not the designated compliance person. In practice, examiners and bank partners generally expect a reviewer who had no hand in the work tested, is qualified to test it, and reports results to the board or a committee of it.
Risk sets the scope and the frequency
The federal rules expect a program that fits your risk, and for MSBs, casinos and insurers they tie the scope and frequency of the review to risk as well. In practice, examiners, state regulators and bank partners expect a documented risk assessment that drives both the program and the scope of the test.
Your bank partner can ask for more
A program agreement is a contract, and it can go beyond the regulatory floor: a named compliance officer where no rule requires one, an annual independent review, reviewer qualifications and regular reporting to the bank. Where the agreement asks for more than the rule, plan to the agreement.
From Your Row to a Decision
- 01
Find your row
Start from what you do and how you are chartered, licensed or registered, not mainly from your size or stage. If you sit in more than one row, each applies, and the strictest one usually sets your floor.
- 02
Read your agreements
Pull your license conditions, your program agreement with your bank partner and any regulator correspondence. They often set officer and testing terms more precisely than the rule does.
- 03
Choose the seat, the review, or both
If you need a designated officer, decide between a full-time hire and a fractional seat on defined terms. If you need an independent review, choose a reviewer with no hand in the program.
- 04
Confirm with your counsel
Take the answer to your counsel for the legal reading of your obligations, then put the seat and the testing calendar in writing, approved by your board.
Reading for Teams Deciding on the Seat or the Review
Fractional CCO or BSA officer of record: which seat your bank partner is asking for
How to read a bank partner's request and tell whether it wants compliance program leadership, a named BSA/AML officer of record, or both.
Fractional CCO or BSA officer of recordThe independent BSA/AML review for MSBs: what examiners and bank partners expect to see
What the BSA rules require of an MSB's independent review, who may perform it, and what examiners and bank partners read for in the report.
The independent BSA/AML review for MSBsQuestions we hear
Does a pre-launch fintech need a BSA officer?
It depends on how you will operate, not on whether you have launched. If your product makes you a money services business, for example because you will accept and transmit funds for customers, the MSB program rule will apply to you, including a designated compliance person. You will generally also need to register with FinCEN and hold state money transmitter licenses where your activity requires them. License applications and sponsor bank diligence typically ask for that person's name before you go live.
If instead you will operate under a sponsor bank that holds the BSA obligations, no federal rule generally requires you to designate your own officer. Program agreements commonly do, though, and the bank will usually want to meet that person during diligence. For a seat on defined terms, see named BSA/AML officer of record.
Can the CEO be the BSA officer?
The federal program rules do not say who the designated person must be by title, so in a small money services business the owner or CEO sometimes holds the seat. The question examiners and bank partners ask is whether that person has the time, knowledge, authority and independence from revenue to do the job. A CEO who also owns growth targets and approves high-risk customers is a hard case to make to a sponsor bank, and your bank partner may ask for someone else. If the CEO does hold the seat, someone other than the CEO must perform the independent review.
How often is independent testing required?
It depends on the rule and on your risk. The bank program rules require independent testing but do not fix a frequency; examiners expect one that fits the bank's risk profile. For money services businesses and casinos, the rules tie the scope and frequency of the review to risk.
Many state regulators and bank partners expect an MSB or fintech review at least once a year, and some write that into license conditions or program agreements. In practice, the most demanding party sets your calendar: plan to whichever of your regulator, license conditions or program agreement asks for the most. For what a review covers, see independent BSA/AML review and program testing.
Does our sponsor bank's officer cover us?
Not in the way most fintechs hope. The bank's BSA officer is responsible for the bank's program, and that includes overseeing you as a third party. It does not usually extend to running the onboarding, monitoring and investigations that your program agreement assigns to you.
Banks generally expect a named person on your side who owns those controls, reports to them on a set cadence and answers when they call. And if your own activity makes you a money services business, you have your own program obligations, including a designated compliance person, whatever the bank's officer does. For how to prepare for the bank's review of your program, see sponsor bank readiness.
Is this legal advice?
No. Ethixera Advisory is not a law firm and does not provide legal advice. This page summarizes general U.S. regulatory requirements in plain language to help you frame the question. Whether a rule applies to you, and how, depends on your facts, your charter or licenses and your agreements, and rules and guidance change. Confirm your obligations with your counsel.
We work alongside your counsel on the compliance side: building the program, holding a defined compliance seat, or testing a program independently.
Need the Seat, the Review, or Both?
Ethixera can provide either one, but not both for the same program: whoever runs a program cannot independently test it.
Need the seat
Your regulator, license or bank partner expects a designated compliance or BSA/AML officer, and you do not have one, or the one you have lacks the time or authority. Ethixera provides fractional compliance leadership and can take on a named BSA/AML officer seat on defined, written terms.
Fractional CCO and BSA officer servicesNeed the independent review
A review is due, an exam is on the calendar, or your bank partner has asked for the report. We test your BSA/AML program against the rules that apply to you and the terms of your agreements, with test scripts, workpapers and findings your board can act on.
Independent BSA/AML review and program testingRegulator-facing experience: direct engagement with FinCEN, state banking departments, FDIC and OCC exam teams and the DOJ, plus Big Four and national-firm validation work. Engagements are principal-led, with direct access to senior expertise.
Not Sure Which Row You Are In?
Tell us what you do, how you are chartered or licensed, and what your bank partner or regulator has asked for. We will help you work out whether you need the seat, the review or both, and what to confirm with your counsel.
