SECURITIES INDUSTRY ESSENTIALS (SIE) • TRADING, CUSTOMER ACCOUNTS, AND PROHIBITED ACTIVITIES

Apply AML Requirements

Understanding the regulatory framework that protects capital markets from money laundering and terrorist financing.

Historical Context & Motivation

The modern framework for Anti-Money Laundering (AML) in the securities industry did not emerge in a single legislative act but rather evolved across several decades in response to escalating financial crime, drug trafficking, and eventually global terrorism. Money laundering—the process of disguising illegally obtained funds as legitimate income—has existed for centuries, but the scale and sophistication of modern financial markets demanded a coordinated regulatory response. Prior to the 1970s, financial institutions in the United States operated with minimal obligations to report suspicious transactions or verify the identities of their customers. The absence of systematic oversight created fertile ground for criminal enterprises to exploit banks and broker-dealers as conduits for illicit capital.

The catalyst for change arrived with the recognition that the financial system itself could be weaponized. Legislators understood that tracking the flow of money was often more effective than tracking the criminals themselves. This insight drove a series of landmark statutes and regulatory initiatives that transformed the compliance landscape for every participant in the U.S. securities industry, from large wirehouses to independent broker-dealers.

1970
Bank Secrecy Act (BSA)
Congress enacted the Bank Secrecy Act, requiring financial institutions to maintain records and file reports on certain monetary transactions, creating the foundational infrastructure for AML compliance in the United States.
1986
Money Laundering Control Act
For the first time, money laundering was explicitly criminalized as a federal offense. The Act established penalties for individuals who knowingly engage in financial transactions involving proceeds from specified unlawful activities.
2001
USA PATRIOT Act
In the wake of the September 11 attacks, Congress passed the USA PATRIOT Act, which significantly expanded AML obligations for broker-dealers. Title III mandated Customer Identification Programs (CIPs) and enhanced due diligence for foreign correspondent accounts.
2002
FinCEN Rule for Broker-Dealers
The Financial Crimes Enforcement Network (FinCEN) finalized rules requiring broker-dealers to establish comprehensive AML compliance programs, mirroring obligations that had previously applied primarily to banks.
2016
Customer Due Diligence (CDD) Final Rule
FinCEN's CDD rule required financial institutions to identify and verify the identity of beneficial owners of legal entity customers, closing a major gap in the AML framework that had been exploited through shell companies.

The critical question that these successive regulatory measures sought to address remains highly relevant today: how can financial institutions effectively detect, deter, and report illicit financial flows without imposing disproportionate burdens on legitimate market participants? For anyone preparing for the SIE exam, understanding this regulatory evolution is essential because AML compliance is not merely an abstract legal obligation—it is an operational reality that shapes how broker-dealers open accounts, monitor transactions, and interact with regulators on a daily basis.

Core Principles & Definitions

AML compliance in the securities industry rests on several interconnected pillars, each codified through federal statute, regulatory guidance, or self-regulatory organization (SRO) rules. At the highest level, the objective is straightforward: prevent the financial system from being used to launder money or finance terrorism. In practice, achieving this objective requires a layered approach involving customer identification, ongoing monitoring, and timely reporting. The following core principles define the AML compliance framework that every broker-dealer must implement.

1

Customer Identification Program (CIP)

Under Section 326 of the USA PATRIOT Act, broker-dealers must verify the identity of each customer at the time of account opening. Minimum identifying information includes name, date of birth, address, and a government-issued identification number (e.g., Social Security Number or passport number for non-U.S. persons).
2

Suspicious Activity Reporting (SAR)

Broker-dealers must file a Suspicious Activity Report with FinCEN when a transaction of $5,000 or more is suspected to involve funds from illegal activity, is designed to evade BSA requirements, or lacks a lawful business purpose. SARs are confidential—firms may not inform the customer.
3

Currency Transaction Reporting (CTR)

Financial institutions must file a Currency Transaction Report for any cash transaction exceeding $10,000 in a single business day. Structuring transactions to avoid this threshold—known as 'smurfing'—is itself a federal offense.
4

AML Compliance Program

Every broker-dealer must maintain an AML program with four required components: (1) written policies and procedures, (2) a designated AML Compliance Officer, (3) ongoing employee training, and (4) independent testing (audit) of the program.
5

OFAC Screening

Firms must screen customers against the Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) list. Engaging in transactions with sanctioned individuals, entities, or countries is prohibited regardless of the amount involved.
KEY TAKEAWAY
Think of AML compliance as a building's security system. The CIP is the front-door ID check—verifying who enters. Ongoing monitoring is the surveillance camera system—tracking activity inside. SAR filing is the silent alarm—alerting authorities without tipping off the suspect. And OFAC screening is the 'no-fly list'—certain individuals are never permitted through the door, period. Each layer reinforces the others, and a gap in any one component can compromise the entire system.

Visual Explanation: The AML Compliance Framework

This diagram illustrates the sequential AML compliance process at a broker-dealer. The flow begins with customer identification at account opening, proceeds through OFAC screening, and continues with ongoing monitoring and regulatory reporting. The bottom bar represents the continuous obligations—training, testing, and record keeping—that underpin the entire framework.

As the diagram makes clear, AML compliance is not a single checkpoint but a continuous cycle. The process begins before the account is opened—when the firm must collect and verify identifying information and screen the customer against sanctions lists—and continues for the entire life of the customer relationship. Transaction monitoring systems, whether automated or manual, flag patterns that deviate from the customer's expected activity profile. When those flags warrant further investigation, the firm's compliance personnel evaluate whether a SAR should be filed. Critically, the continuous obligations shown at the bottom of the diagram—independent testing, employee training, and record keeping—ensure that the system itself remains effective and auditable over time.

How AML Requirements Work in Practice

The Three Stages of Money Laundering

To understand why AML requirements take the form they do, it is essential to understand the process they are designed to interrupt. Money laundering typically proceeds through three stages, each of which presents different detection opportunities for financial institutions. The first stage, placement, involves introducing illicit cash into the financial system—for example, by depositing large amounts of currency at a bank or purchasing money orders. The second stage, layering, involves moving the funds through multiple transactions to obscure their origin; this might include wire transfers between accounts at different institutions, purchasing and selling securities, or converting funds into different currencies. The third and final stage, integration, involves reintroducing the now-'clean' funds into the legitimate economy—purchasing real estate, businesses, or investment assets.

Key Regulatory Thresholds

CURRENCY TRANSACTION REPORT THRESHOLD
CTR Filing Required: Cash Transaction > $10,000 in a single business day
This threshold applies to cash transactions (currency deposits, withdrawals, exchanges) per customer per business day. Multiple transactions that aggregate above $10,000 also trigger the requirement. The CTR is filed on FinCEN Form 104.
SUSPICIOUS ACTIVITY REPORT THRESHOLD
SAR Filing Required: Suspicious Transaction ≥ $5,000
A SAR must be filed within 30 calendar days of the initial detection of facts that may constitute a basis for filing. If no suspect is identified, the time period extends to 60 calendar days. The SAR is filed on FinCEN Form 111. Tipping off the subject of a SAR is a violation of federal law.

FINRA Rule 3310: AML Compliance Program Requirements

FINRA Rule 3310 operationalizes the BSA and PATRIOT Act requirements specifically for broker-dealers. The rule mandates that each member firm establish and implement a written AML compliance program that is approved by senior management and reasonably designed to achieve compliance with applicable federal law. The program must include four mandatory components, often tested on the SIE exam. First, the firm must develop and implement policies, procedures, and internal controls reasonably designed to detect and report suspicious activity. Second, the firm must designate an AML Compliance Officer responsible for implementing and monitoring the program. Third, the firm must provide ongoing training for appropriate personnel. Fourth, the firm must arrange for independent testing of the program, which can be conducted by qualified internal personnel not involved in the AML function or by an outside party.

⚠️ SIE Exam Tip
The SIE exam frequently tests the distinction between CTRs and SARs. Remember: a CTR is automatic and triggered solely by the $10,000 cash threshold—no suspicion is necessary. A SAR requires a judgment call based on suspicious behavior at the $5,000 threshold. Also note that while CTRs may be discussed with the customer, SAR filings must remain strictly confidential.

Red Flags & Suspicious Activity Indicators

Identifying suspicious activity requires more than simply monitoring dollar thresholds. Broker-dealers must train their personnel to recognize behavioral and transactional patterns—commonly referred to as red flags—that may indicate money laundering, terrorist financing, or other illicit activity. These red flags do not automatically mean criminal conduct is occurring, but they do warrant further investigation and, potentially, the filing of a SAR. The following diagram categorizes the most significant red flags into three domains: customer behavior, transaction patterns, and account characteristics.

The three-column classification organizes AML red flags by their source: customer behavior (who the customer is and how they act), transaction patterns (what the money is doing), and account characteristics (the structural features of the account). Compliance officers must evaluate these indicators holistically, not in isolation.

It is worth emphasizing that the presence of a single red flag does not, by itself, confirm illicit activity. A customer who makes a $9,500 cash deposit, for instance, may simply be depositing a legitimate amount that happens to fall below the CTR threshold. However, when a customer consistently makes deposits just below $10,000 on consecutive days—a pattern known as structuring or 'smurfing'—the cumulative picture becomes far more concerning. Similarly, a dormant account that suddenly receives a large wire transfer from a high-risk jurisdiction, followed by immediate liquidation of securities, presents a cluster of red flags that would likely necessitate a SAR filing. The compliance officer's role is to assess the totality of circumstances rather than relying on any single threshold or indicator.

Worked Example: AML Compliance Scenario

Consider the following scenario, which is representative of the type of fact pattern you may encounter on the SIE exam. A new customer, Mr. Rodriguez, walks into a broker-dealer's branch office and wants to open a brokerage account. He presents a valid U.S. passport but is reluctant to provide his Social Security Number. He says he plans to fund the account with $48,000 in cash over the next several days and wants to purchase large-cap equities. Over the following week, Mr. Rodriguez makes four separate cash deposits of $9,800, $9,700, $9,500, and $9,900. After the shares are purchased, he requests that they be transferred to an account at a foreign broker-dealer within two weeks.

Analyzing the AML Compliance Obligations
1
Step 1 — Apply the CIP RequirementsBefore opening the account, the firm must collect the four required identifying elements: name, date of birth, address, and identification number. Mr. Rodriguez has provided a passport (satisfying the name and document requirements), but he is reluctant to provide his SSN. Under the CIP rule, the firm must obtain a government-issued identification number. If the customer is a U.S. person, an SSN is required. The firm cannot waive this requirement.
Red Flag #1: Reluctance to provide identification information.
2
Step 2 — Screen Against OFAC ListsThe firm must screen Mr. Rodriguez's name and identifying information against the OFAC Specially Designated Nationals (SDN) list and other relevant sanctions lists before opening the account. If there is a match, the firm must reject the account and potentially block the funds. If there is no match, the firm may proceed—but the screening obligation does not end at account opening; it must be repeated periodically.
Assume no OFAC match is found. The account may be opened, but the firm must document the screening.
3
Step 3 — Evaluate the Cash Deposit PatternMr. Rodriguez's four deposits—$9,800, $9,700, $9,500, and $9,900—each fall below the $10,000 CTR threshold. However, the total is $38,900, and the pattern of consistently depositing amounts just below $10,000 is a classic indicator of structuring. Structuring is a federal crime under 31 U.S.C. § 5324, regardless of whether the underlying funds are legitimate.
Red Flag #2: Structuring cash deposits to avoid CTR filing requirements.
4
Step 4 — Assess the Transaction PatternThe rapid purchase of securities followed by an immediate request to transfer them to a foreign broker-dealer is consistent with the layering stage of money laundering. The customer is converting cash into securities and then moving those securities offshore, effectively moving value across borders while obscuring the cash origin. This pattern—fund, purchase, transfer—is a well-documented typology in FinCEN advisories.
Red Flag #3: Rapid purchase and international transfer of securities inconsistent with a stated buy-and-hold strategy.
5
Step 5 — Determine Filing ObligationsGiven the multiple red flags—reluctance to provide identifying information, apparent structuring, and a suspicious transaction pattern—the firm is obligated to file a Suspicious Activity Report (SAR) with FinCEN within 30 calendar days of the initial detection. The total suspicious amount ($38,900) exceeds the $5,000 SAR threshold. The firm must not inform Mr. Rodriguez that a SAR has been or will be filed (no 'tipping off'). Additionally, the firm should consider whether any individual cash deposit or aggregated deposits trigger a CTR obligation, even though each individual deposit was below $10,000; if the firm knows the deposits are related, a CTR may also be warranted.
Action Required: File SAR within 30 days. Do not tip off customer. Evaluate CTR obligations for aggregated deposits. Consider freezing the account pending further review.

Comparing Key AML Tools & Obligations

Students preparing for the SIE exam must be able to distinguish among the various reporting and compliance tools in the AML framework. While these instruments share a common goal—preventing financial crime—they differ significantly in their triggers, filing procedures, confidentiality requirements, and the entities responsible for compliance. The following table provides a side-by-side comparison of the most frequently tested AML tools.

Comparison of SAR, CTR, and OFAC Screening obligations for broker-dealers
FeatureSARCTROFAC Screening
Triggering EventSuspicious transaction ≥ $5,000 involving potential illegal activityCash transaction > $10,000 in a single business dayMatch against SDN list or sanctioned countries/entities
Filing FormFinCEN Form 111 (SAR)FinCEN Form 104 (CTR)No filing—firm must block/reject the transaction
Filing Deadline30 days from detection (60 days if no suspect identified)15 days after the transactionImmediate—must block before transaction is completed
ConfidentialityStrictly confidential—no tipping offNot confidential—customer may be informedCustomer may be informed that the transaction is blocked due to sanctions
Judgment Required?Yes—compliance officer must assess suspicionNo—automatic based on dollar thresholdNo—automatic based on list match
Record Retention5 years from the date of filing5 years from the date of filing5 years from the date of the last transaction or account closure
KEY TAKEAWAY
Think of the three AML tools as analogous to a hospital's patient safety protocols. A CTR is like recording vital signs for every patient admitted—routine, automatic, and threshold-based. A SAR is like a nurse flagging unusual symptoms to the attending physician—it requires professional judgment and must be kept confidential from the patient to avoid influencing behavior. OFAC screening is like checking the 'do not treat' allergy list before administering any medication—if there is a match, the action is stopped immediately, no exceptions.

Connection to Advanced Regulatory Concepts

While the SIE exam tests foundational AML concepts, the securities professional's obligations extend into more sophisticated terrain as one advances through the Series 7, Series 24, or compliance-focused examinations. Understanding how basic AML requirements connect to advanced regulatory concepts helps contextualize the material and prepares students for deeper study. The table below maps SIE-level concepts to their more advanced counterparts.

Mapping SIE-level AML concepts to advanced regulatory topics
SIE-Level ConceptAdvanced Regulatory Extension
Customer Identification Program (CIP)Enhanced Due Diligence (EDD) for high-risk customers, Politically Exposed Persons (PEPs), and foreign financial institutions under Section 312 of the PATRIOT Act
SAR FilingSAR narrative writing best practices, coordination with law enforcement (314(a) and 314(b) information sharing), and the safe harbor provision protecting firms from liability for good-faith filings
OFAC ScreeningSanctions compliance programs, sectoral sanctions (SSI and Crimea-related lists), and extraterritorial application of U.S. sanctions to foreign subsidiaries
AML Compliance Program (FINRA Rule 3310)Enterprise-wide risk assessments, model risk management for automated surveillance systems, and regulatory examinations under FINRA's risk-based examination program
Beneficial Ownership IdentificationCorporate Transparency Act (2024), which requires companies to report beneficial ownership information directly to FinCEN, creating a national registry

One of the most significant recent developments is the Corporate Transparency Act (CTA), which took effect in 2024 and requires certain business entities to report their beneficial ownership information to FinCEN. This legislation directly addresses the shell company loophole that criminals have historically exploited to conceal the true owners of accounts and assets. For the SIE candidate, the key insight is that AML regulation is not static—it continues to evolve in response to new threats, technological changes, and gaps identified through enforcement actions. Understanding the foundational framework prepares you to adapt as these rules are refined and expanded throughout your career in the securities industry.

🔮 Looking Ahead
Emerging technologies such as cryptocurrency and decentralized finance (DeFi) are creating new AML challenges. FinCEN has proposed rules to extend BSA reporting requirements to virtual asset service providers (VASPs). The fundamental principles—know your customer, monitor for suspicious activity, and report—remain the same, but the methods of implementation are evolving rapidly.

Practice Problems

PROBLEM 1CONCEPTUAL
A broker-dealer's AML compliance program must include four mandatory components under FINRA Rule 3310. Identify all four components and explain why each is necessary for an effective compliance framework.
PROBLEM 2BASIC CALCULATION
A customer makes the following cash deposits over three consecutive business days: Day 1: $6,200; Day 2: $4,500; Day 3: $8,800. On which day(s), if any, must the broker-dealer file a Currency Transaction Report (CTR)? Are there any additional AML concerns?
PROBLEM 3INTERMEDIATE
A registered representative notices that a long-standing client, who typically trades blue-chip equities with moderate frequency, has begun wiring large sums from an account at a bank in a high-risk jurisdiction. The client immediately uses these funds to purchase penny stocks, which are then transferred to an overseas account within days. The representative mentions to the client in passing: 'We may need to look into these transactions more closely.' Identify all compliance issues in this scenario.
PROBLEM 4APPLIED
You are the newly appointed AML Compliance Officer at a mid-size broker-dealer. During your first review, you discover that the firm has not conducted independent testing of its AML program in over two years, employee training records are incomplete, and there is no documented procedure for screening customers against the OFAC SDN list. The previous compliance officer retired six months ago and was not replaced until your appointment. Draft an action plan prioritizing the three most urgent remediation steps and justify your prioritization.
PROBLEM 5CRITICAL THINKING
Some critics argue that the current SAR filing regime creates a 'defensive filing' culture in which financial institutions file SARs on marginally suspicious activity to avoid regulatory criticism, resulting in FinCEN being overwhelmed with low-quality reports. Evaluate this critique. Does defensive filing undermine the effectiveness of AML regulation, or does it serve as a reasonable precaution? What reforms, if any, might improve the system?

Lesson Summary

Anti-Money Laundering requirements form a critical pillar of securities industry regulation, originating with the Bank Secrecy Act of 1970 and dramatically expanded by the USA PATRIOT Act of 2001. Every broker-dealer must maintain a comprehensive AML compliance program under FINRA Rule 3310, consisting of four mandatory elements: written policies and procedures, a designated AML Compliance Officer, ongoing employee training, and independent testing. The program begins with a Customer Identification Program (CIP) that verifies each customer's identity at account opening and includes OFAC screening against sanctions lists.

Ongoing monitoring is designed to detect the three stages of money laundering—placement, layering, and integration—through the identification of red flags in customer behavior, transaction patterns, and account characteristics. When suspicious activity is detected at or above $5,000, firms must file a confidential Suspicious Activity Report (SAR) with FinCEN within 30 days. Cash transactions exceeding $10,000 trigger an automatic Currency Transaction Report (CTR). Mastering these requirements is essential for SIE exam success and foundational for every career in the securities industry.

Varsity Tutors • Securities Industry Essentials (SIE) • Apply AML Requirements