MSB examination readiness: what a first BSA or FINTRAC exam asks for
MSB examination readiness: what a FinCEN or FINTRAC examiner asks for in a first exam, in what order, and how to hold the evidence to answer quickly.
- An examination does not test whether a compliance programme exists. It tests whether it ran on a named date for a named customer, and whether you can prove it.
- The four programme requirements are the spine of every US examination: written policies and internal controls, a designated compliance officer, ongoing training, and independent testing.
- The risk assessment is the hinge. Controls that do not trace back to a dated, approved risk assessment read as generic, and generic is the most common finding.
- FINTRAC examinations mirror the US model but add a distinct obligation: a review of the effectiveness of the whole compliance programme at least every two years.
- Adding stablecoin settlement extends the existing examination rather than creating a new one. Readiness improves when the rail produces structured, joinable records by default.
MSB examination readiness is the difference between a routine review and a finding letter. A money services business does not choose when its first examination arrives. In the United States the Internal Revenue Service examines most MSBs for Bank Secrecy Act compliance under authority delegated by FinCEN. In Canada FINTRAC examines registered money services businesses directly. Both start from the same premise. You told the regulator what you do, and the examination tests whether your programme matches that description. This article sets out what an examiner asks for, in what order, and how to hold the evidence so that producing it takes hours rather than weeks.
What triggers a first MSB examination?
Registration is the trigger most firms forget. FinCEN requires an MSB to register on Form 107 and to renew that registration every two years. The register is public. It tells an examiner your services, your states, your agent count and your estimated volume before anyone calls you.
Selection is rarely random. Examiners weight new registrants, firms that changed their service mix, firms with agent networks and firms that added virtual asset activity. Referrals matter as well. A bank that closes your account, a state regulator that finds a gap, or a suspicious activity report filed about your business can each put a file on the list.
Timing varies, but a first examination often follows within the first two years of registration. The notice period is short, and the document request list usually arrives with it. That is why MSB examination readiness has to be a standing condition rather than a project you begin when the letter lands.
What does an examiner look at first?
Every US examination starts from the same four requirements. FinCEN's anti money laundering programme rule at 31 CFR 1022.210 requires written policies, procedures and internal controls, a designated compliance officer, ongoing training for staff, and independent testing of the programme.
The examiner reads those four items against your risk assessment. The risk assessment is the hinge of the whole file. It should name your products, your customer types, your geographies and your delivery channels, rate each one, and point to the control that answers it. A programme that does not trace back to a dated risk assessment reads as generic, and generic is the most common finding.
Independent testing is the second most common gap. The rule does not require an external auditor. It requires that the person testing the programme is not the person running it. Smaller firms satisfy this with a qualified contractor or a properly segregated internal reviewer. Firms that never test at all have no answer to give.
Expect the examiner to interview the compliance officer directly. The questions are practical. How do you clear an alert. Who decides to file a report. What happens when the owner disagrees with you. Answers that do not match the written procedure are treated as evidence that the procedure is not real.
Which records must an MSB produce on request?
The request list is long but predictable. It is assembled from the reporting and recordkeeping rules that apply to your specific services, so a firm that both transmits money and sells monetary instruments answers two lists rather than one.
FinCEN requires a currency transaction report for cash transactions above 10,000 dollars conducted by or on behalf of one person in one business day. FinCEN also requires an MSB to file a suspicious activity report on transactions conducted or attempted at 2,000 dollars or more where the firm knows or suspects illicit activity.
Money transmitters carry two further duties. The funds transfer recordkeeping rule and the travel rule apply to transmittals of 3,000 dollars or more, so originator and beneficiary details must be recorded and passed to the next institution in the chain. Firms that sell monetary instruments for cash of 3,000 dollars or more must keep a monetary instrument log.
Retention under the Bank Secrecy Act rules is five years, measured from the date of the record or the report. Examiners test retention by sampling. They pick transactions from the oldest end of the window and ask for the full file. Gaps at that end of the range surface within minutes.
How does a Canadian FINTRAC examination differ?
The Canadian model rests on the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. FINTRAC registers money services businesses, and that registration must be renewed every two years, as FinCEN registration must.
The programme requirements are close but not identical. FINTRAC requires a compliance officer, written policies and procedures, a documented risk assessment, a training programme for staff and agents, and a review of the effectiveness of the whole programme at least every two years. That two year review is a separate obligation in its own right, and its absence is a standard finding.
Reporting thresholds differ. FINTRAC requires large cash transaction reports and electronic funds transfer reports at 10,000 Canadian dollars or more, aggregated across a 24 hour period, while suspicious transaction reports carry no threshold at all.
Consequences differ as well. FINTRAC publishes administrative monetary penalties, including the name of the penalised business. For a money services business that depends on bank accounts, the reputational effect of a published penalty usually exceeds the amount of it.
What does MSB examination readiness look like day to day?
Readiness is an evidence problem rather than a policy problem. Most firms have the policies. Few can produce, on a single working day, the record that shows a control actually ran.
- Keep the registration current. Check that services, states or provinces, agent counts and estimated volumes still describe the business you run today.
- Refresh the risk assessment on a fixed date each year, and again whenever you add a product, a corridor or a chain. Date it and record who approved it.
- Hold the four programme requirements as one indexed package: policies, the compliance officer appointment, the training log with attendance, and the last independent test with its remediation status.
- Log every alert and its disposition. An examiner samples closed alerts rather than open ones, and asks why each was closed.
- Keep filed reports and their supporting files together. A suspicious activity report without the underlying transaction record and the analyst note is half an answer.
- Run one internal mock examination each year against the published examination manual. Time how long each item takes to produce, then fix the slowest three.
- Name a single owner for the request list. During an examination, one person collects, one person reviews and one person sends.
An examination does not test whether your compliance programme exists. It tests whether it ran, on a specific date, for a specific customer, and whether you can prove that without rebuilding the file from memory.
How does stablecoin settlement change an MSB examination?
Adding stablecoin settlement does not create a separate examination. It extends the existing one. The examiner asks familiar questions about an unfamiliar delivery channel, and expects the risk assessment to have been updated before the first transaction rather than after it.
Three areas draw attention. The first is the travel rule as it applies to virtual assets. The Financial Action Task Force set a 1,000 USD or EUR threshold for virtual asset transfers in its 2019 interpretive note to Recommendation 15, and originator and beneficiary data must travel with the transfer in IVMS101 form.
The second is monitoring across two record types. You now hold a blockchain record that proves value moved and a payment record that names the parties and the purpose. An examiner wants them joined. Where a shared reference joins them, sampling takes minutes. Where it does not, every sample becomes a manual reconstruction.
The third is issuer and counterparty diligence. A regulated payment stablecoin is a claim on its issuer. The GENIUS Act, signed into United States law in 2025, requires payment stablecoin issuers to hold reserves one for one in cash and short dated government securities and to publish monthly reserve reports. Keep the attestations you relied on, with the date you reviewed each one.
The practical lesson is that MSB examination readiness improves when the settlement rail produces structured records by default. ISO 20022 messages do that. A pacs.008 customer credit transfer and a pacs.009 interbank leg, carried in a head.001 envelope and tracked by a single UETR, hand the examiner the parties, the purpose and the chain of handling in one place.
Where StableNet fits
StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs. Settlement is in regulated stablecoins on public blockchains, completing in minutes with on chain auditability, so the ledger record an examiner asks about is produced by the payment itself. The platform is ISO 20022 native, with pacs.008 customer credit transfers, pacs.009 interbank legs, pacs.002 status reports and pacs.004 returns inside head.001 envelopes, tracked end to end by UETR, which is what lets a sampled transaction be reassembled from one reference. Compliance is built in, with KYB and KYC onboarding, KYT, sanctions and PEP screening, FATF Travel Rule data in IVMS101 form, a compliance workbench and a tamper evident audit trail. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.
See it on your corridors
Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.