Use this BSA AML risk assessment template to separate US Bank Secrecy Act exposure from Indian PMLA duties, score risk, assign controls and preserve audit evidence.

An Indian fintech can face a US compliance request on Monday and a Financial Intelligence Unit – India review on Friday. Treating both as one generic “AML checklist” creates gaps in scope, evidence and ownership. Under section 13 of India's Prevention of Money-Laundering Act, 2002, a reporting entity, its designated director or an employee can face a monetary penalty from ₹10,000 to ₹1 lakh for each failure to meet Chapter IV obligations.

This BSA AML risk assessment template gives Indian banks, payment firms, virtual digital asset service providers, fintech vendors and cross-border businesses a practical starting point. It is not a substitute for a legal opinion. Its job is to make the right questions, decisions and supporting evidence visible before an auditor or regulator asks for them.

First decide whether the US BSA applies to your Indian business

The Bank Secrecy Act, or BSA, is a United States law. It does not automatically apply to every Indian company that receives dollars, has a US customer or uses a US bank account. Your first worksheet should therefore be a scope decision, not a risk score.

The Financial Crimes Enforcement Network, or FinCEN, regulates covered US financial institutions and certain money services businesses. FinCEN's official “Am I an MSB?” guide identifies activities such as money transmission, cheque cashing, foreign-exchange dealing and providing or selling prepaid access. A business that meets a regulated definition must follow the BSA requirements applicable to that type of money services business.

Physical location is not the only test. FinCEN's advisory on foreign-located money services businesses says that a foreign entity may be covered when it conducts regulated money-service activity wholly or in substantial part within the United States. Covered foreign-located businesses must register with FinCEN, meet applicable recordkeeping, reporting and AML programme requirements, and appoint a US resident as agent for service of legal process under 31 CFR 1022.380(a)(2).

Record the answers to these questions:

  1. What exact service does the Indian entity provide: software, payment processing, custody, money transmission, currency exchange or another activity?
  2. Does it accept money or value from one person and transmit it to another person or location?
  3. Are services offered to customers located in the United States?
  4. Is there a US branch, subsidiary, agent, licence, registration or regulated partner?
  5. Is the entity itself regulated, or is a US customer merely asking it to support that customer's compliance programme?
  6. Which regulation, licence condition or contract creates each obligation?

Do not write “BSA applicable because we have US clients.” Cite the relevant provision of 31 CFR, a FinCEN ruling, a licence condition or counsel's written conclusion. Equally, do not assume that an India address puts a cross-border payments product outside US scope. Product flow matters more than the footer on the website.

Keep direct duties separate from customer requirements

An Indian software vendor may not itself be a BSA financial institution, but a US bank can still require customer due-diligence support, sanctions screening, audit access, incident reporting and record retention under the contract. Label those as contractual controls supporting a regulated customer, not as the vendor's statutory BSA filing duties.

That distinction prevents two common errors: filing reports the company is not authorised or required to file, and failing to deliver evidence the regulated customer genuinely needs. Your scope sheet should include jurisdiction, legal entity, source of duty, regulator or counterparty, owner and evidence link for every requirement.

Map the Indian PMLA and RBI requirements separately

For an Indian reporting entity, the core law is the Prevention of Money-Laundering Act, 2002, commonly called PMLA, read with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 and sector-regulator directions. Section 12 requires reporting entities to maintain transaction and client-identity records, furnish prescribed information to FIU-IND and verify clients and beneficial owners.

FIU-IND's official PMLA frequently asked questions state that transaction records must be retained for five years from the transaction date. Client identity and account-file records must be kept for five years after the relationship ends or the account closes, whichever is later. The same source confirms the section 13 penalty of ₹10,000 to ₹1 lakh for each failure.

For entities regulated by the Reserve Bank of India, the Master Direction – Know Your Customer (KYC) Direction, 2016 must also be mapped. The RBI master direction requires regulated entities to perform a periodic money-laundering and terrorist-financing risk assessment covering clients, countries or geographic areas, products, services, transactions and delivery channels. It also requires a Board-approved KYC policy and risk-based controls.

Virtual digital asset service providers should use the current FIU-IND sector guidance as well. FIU-IND's 2026 AML/CFT/CPF guidelines for VDA service providers explain that obligations are activity-based and can apply irrespective of physical presence in India when the entity carries on a notified activity.

Create a two-column applicability register:

Question | US BSA track | India track

Covered entity | Relevant BSA financial institution or MSB definition | PMLA “reporting entity” plus sector definition

Main authority | FinCEN and the applicable prudential regulator | FIU-IND and RBI, SEBI, IRDAI or another sector regulator

Primary rule source | 31 CFR Chapters X and applicable guidance | PMLA 2002, PML Rules 2005 and sector directions

Filing owner | Named US BSA compliance function | Principal Officer and Designated Director, where required

Evidence | Registration, programme, testing and filing records | FIU registration, KYC policy, risk assessment, reports and retention records

Never merge the filing columns. A suspicious transaction report to FIU-IND is not evidence that a US suspicious activity reporting obligation was assessed, and the reverse is equally true.

Use this BSA AML risk assessment template

The US Federal Financial Institutions Examination Council's BSA/AML risk assessment guidance uses a sensible two-step process: identify the institution's specific risk categories, then analyse the information within those categories. The guidance highlights products and services, customers and geographic locations, while transaction data and delivery channels help quantify the exposure.

Start with one row for each meaningful combination of product, customer type and geography. A single company-wide “medium risk” score tells an auditor nothing.

Field | What to enter | Example

Risk ID | Stable reference | AML-2026-017

Legal entity | Entity carrying the exposure | India Payments Private Limited

Jurisdiction | US, India or both, with reason | India PMLA; US MSB scope under review

Product or service | Actual money or data flow | Cross-border merchant settlement

Customer type | Segment, not a vague label | Export merchants using marketplace payouts

Geography | Origin, destination and corridor | India–US

Transaction profile | Expected value, volume and frequency | 2,000 monthly payouts; median US$600

Inherent risk | Score before controls | High: 16/20

Key controls | Specific preventive and detective controls | KYB, beneficial-owner check, sanctions screening, velocity rules

Control evidence | Link to proof, not policy text alone | Test CR-204; sample file; alert report

Control effectiveness | Effective, partial or ineffective | Partial: tuning overdue

Residual risk | Risk after tested controls | Medium: 9/20

Action | Fix, owner and due date | Retune corridor rule; MLRO; 30 Sep 2026

Approval | Named accountable decision-maker | Risk Committee, 12 Aug 2026

A simple scoring method that can be defended

Score each inherent factor from 1 to 5:

Add the four values for an inherent score from 4 to 20. Suggested bands are 4–8 low, 9–14 medium and 15–20 high. These are internal design choices, not regulator-prescribed numbers. Document why the organisation selected them.

Then rate control effectiveness:

Do not simply subtract every control score. Explain which inherent risks each control changes. Sanctions screening does not fix weak beneficial-owner identification. A transaction-monitoring rule does not prove that customer risk was correctly classified at onboarding.

Residual risk must drive an action. “High residual risk, accepted” needs a named executive or Board committee, reasons, compensating controls, expiry date and review trigger. Otherwise it is not acceptance; it is neglect with formatting.

Build an evidence pack that survives an examination

A risk assessment is not complete when the spreadsheet has colours. It is complete when another competent person can reproduce the conclusion from current data and evidence.

For each risk row, preserve:

FinCEN and FFIEC do not prescribe one universal spreadsheet format. The FFIEC guidance says the method and level of sophistication should fit the institution's size and complexity. It also says no single indicator automatically establishes high or low risk. That is why a small payments firm can use a disciplined workbook, while a bank with millions of transactions will need governed data pipelines and traceable model logic.

Set event-based review triggers

The FFIEC manual does not impose one fixed update frequency for the BSA risk assessment. It expects updates when the risk profile changes, including new products, services, customer types, geographic expansion, mergers or acquisitions. Indian sector directions may impose their own review requirements, so record those separately.

At minimum, trigger a review when:

  1. A new country, payment rail, token, customer segment or distribution partner is added.
  2. The business becomes licensed or registered in a new jurisdiction.
  3. A law, rule, regulator direction or sanctions list changes.
  4. Transaction-monitoring thresholds or screening systems materially change.
  5. An audit, regulator review, suspicious-report trend or enforcement action exposes a gap.
  6. Transaction volume or value exceeds the approved risk-assessment assumptions.

This is where manual compliance calendars fail. A date reminder cannot detect that a product launch changed the regulated activity or that a foreign MSB rule now applies. Link the risk register to product-change approval and regulatory monitoring.

Turn the template into a working compliance process

The fastest implementation is a 30-day control sprint:

Days 1–5: establish scope. List legal entities, licences, products, money flows, customer locations and regulatory sources. Get written counsel input for disputed BSA or PMLA applicability.

Days 6–12: assemble data. Reconcile customer, transaction, geography, alert and filing populations. Record missing data as a control issue; do not replace it with an unsupported score.

Days 13–18: score inherent risk. Run workshops with compliance, operations, product, information security and finance. Preserve challenge notes and dissenting views.

Days 19–24: test controls. Sample onboarding, beneficial-owner verification, screening, monitoring, escalation, reporting and record retention. A policy marked “approved” is not evidence that the control operates.

Days 25–30: approve and remediate. Assign residual-risk decisions, owners, due dates and review triggers. Present the high and overdue items to the accountable committee.

The commercial test is blunt: can the firm answer “what applies, what changed, who owns it and where is the proof?” within one working day? If not, the business does not have a controlled AML risk assessment. It has scattered documents.

Check your compliance posture free at Compliance Radar. Describe the business once to identify applicable Indian obligations, build a compliance timeline and receive regulatory-change alerts instead of discovering a missed rule during diligence or inspection.

Frequently asked questions

Is a BSA AML risk assessment mandatory for every Indian fintech?

No. BSA applicability depends on the entity's activities and US nexus, not the “fintech” label. A foreign-located business conducting covered money-service activity wholly or substantially in the United States may be a BSA-regulated MSB. An India-only software vendor may instead have contractual duties to a regulated US customer. Record the legal basis either way.

Can an Indian PMLA risk assessment replace a BSA assessment?

No. The two frameworks overlap in risk concepts but differ in covered entities, authorities, reports and regulatory sources. Reuse verified data where sensible, but maintain separate applicability, filing and approval fields.

How often should the risk assessment be updated?

Use event-based triggers and any frequency required by the applicable Indian sector direction or internal policy. The FFIEC BSA/AML manual does not prescribe a universal fixed interval; it expects the assessment to remain accurate when products, customers, services or geographies change.

What are the minimum risk categories?

For a useful assessment, cover products and services, customers, geographies, transactions and delivery channels. The FFIEC does not mandate one universal list, so add factors relevant to the business, such as agents, virtual assets, trade finance or correspondent relationships.

What is the penalty for an Indian reporting entity's PMLA compliance failure?

Section 13 of the Prevention of Money-Laundering Act, 2002 permits FIU-IND's Director to impose ₹10,000 to ₹1 lakh for each failure by a reporting entity, its designated director or an employee, alongside directions or warnings allowed by the section.

Should inherent risk be reduced because controls are strong?

No. Inherent risk describes exposure before controls. Score control effectiveness separately, then determine residual risk. Mixing the two hides whether the business is naturally low-risk or merely dependent on controls that must keep working.

Can a generic online template satisfy an auditor?

Only if it is converted into a business-specific assessment supported by current customer, transaction, geography and control evidence. A template with copied scores, no source dates and no accountable owner is a blank form pretending to be governance.

Make the BSA AML risk assessment template operational

The best BSA AML risk assessment template is not the one with the most tabs. It is the one that separates jurisdictions, cites the source of every duty, uses real exposure data, tests controls and forces action on residual risk.

For an Indian business, that means treating US BSA scope, Indian PMLA duties and customer contracts as related but distinct tracks. Review them when products and regulations change, not only before the annual audit. Check what applies to your business at Compliance Radar and turn those obligations into a monitored timeline with accountable evidence.