bsa-risk-assessment

Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).

11 stars

Best use case

bsa-risk-assessment is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).

Teams using bsa-risk-assessment should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/bsa-risk-assessment/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/legal/bsa-risk-assessment/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/bsa-risk-assessment/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How bsa-risk-assessment Compares

Feature / Agentbsa-risk-assessmentStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# BSA/AML Risk Assessment

Produces examination-ready BSA Risk Assessments evaluating inherent AML/CFT risks against mitigating controls per FFIEC BSA/AML Examination Manual methodology.

## Prerequisites

Gather before drafting:

1. **Institution profile** — entity type, charter/regulator, total assets, branch footprint, international relationships
2. **Products & services** — inventory with volumes for high-risk products (wires, monetary instruments, prepaid, trade finance, crypto on/off ramps)
3. **Customer data** — segments with counts of high-risk categories (cash-intensive businesses, PEPs, NRAs, MSBs, foreign correspondents)
4. **BSA/AML program docs** — policies, CIP/CDD/EDD procedures, monitoring system specs, training records
5. **Filing history** — annual CTR/SAR counts by category
6. **Independent testing** — most recent scope, findings, remediation status
7. **Regulatory history** — outstanding MRAs, MOUs, enforcement actions

## Document Sections

### 1. Executive Summary

Overall risk rating (Low/Moderate/High), key concentrations, control gaps, priority recommendations with owners and target dates.

### 2. Introduction

- Regulatory basis: 31 U.S.C. § 5318(h); 31 C.F.R. § 1020.210
- Scope: all business lines, products, customers, geographies
- Assessment period and update frequency (typically annual)
- FFIEC risk-based methodology alignment

### 3. Institution Overview

Table covering: entity type, charter/regulator, total assets, branch count, high-risk products offered, customer segments, annual CTR/SAR filing counts.

### 4. Inherent Risk Identification

Five risk dimensions, each rated High/Moderate/Low:

- **Customer** — cash-intensive businesses, MSBs, NBFIs, PEPs, NRAs, nonprofits, foreign correspondents, FATF-listed jurisdiction customers
- **Product & Service** — flag products enabling anonymity, rapid movement, or cross-border activity (wires, prepaid, private banking, trade finance, digital channels, crypto)
- **Geographic** — HIDTA/HIFCA areas, FATF grey/black list jurisdictions, FinCEN GTO zones, OFAC sanctioned countries
- **Transaction** — high-volume cash, structuring patterns, funnel accounts, rapid cycling, shell companies, trade-based ML
- **Third-Party** — independent agents, outsourced onboarding/processing, fintech partnerships

### 5. Risk Assessment Matrix

Per risk category:

| Risk | Inherent | Likelihood | Impact | Mitigating Controls | Residual |
|---|---|---|---|---|---|
| [Category] | H/M/L | H/M/L | H/M/L | [Description] | H/M/L |

Reference FATF typology reports and FinCEN advisories for current typologies (ransomware, elder exploitation, human trafficking, real estate, virtual assets).

### 6. Controls & Mitigation

Evaluate each BSA program component against its regulatory basis:

| Component | Citation |
|---|---|
| CIP | 31 C.F.R. § 1020.220 |
| CDD / Beneficial Ownership | 31 C.F.R. § 1010.230 |
| EDD | FFIEC Manual |
| Transaction Monitoring | FFIEC Manual |
| OFAC Screening | 31 C.F.R. Part 501 |
| CTR Filing | 31 U.S.C. § 5313 |
| SAR Filing | 31 U.S.C. § 5318(g) |
| BSA Officer / Governance | 31 C.F.R. § 1020.210 |
| Training | 31 C.F.R. § 1020.210 |
| Independent Testing | 31 C.F.R. § 1020.210 |

For each: document current status and adequacy rating.

### 7. Conclusions & Recommendations

- Overall risk determination with narrative justification
- Residual risks where controls are insufficient
- Prioritized remediation table (recommendation, priority, owner, target date)

## Verification Requirements

These items change over time — confirm before finalizing:

- [ ] FATF grey/black list countries — verify at fatf-gafi.org
- [ ] Active FinCEN GTOs — jurisdiction-specific and time-limited
- [ ] Beneficial ownership threshold (currently 25%) — check for subsequent FinCEN rulemaking
- [ ] FinCEN advisory numbers — verify FIN numbers and dates before citing

## Pitfalls

- **Quantitative support required** — risk ratings must cite transaction volumes, SAR counts, or alert rates; qualitative assertions alone are insufficient
- **Board presentation** — document must be board-approved or presented to senior management with evidence of review
- **Version retention** — keep prior assessments; regulators compare year-over-year
- **Privilege risk** — do not include attorney-client privileged material if document will be produced to examiners
- **FFIEC citations** — reference specific Examination Manual sections when evaluating control adequacy

Related Skills

managing-wound-assessment-nursing

11
from CaseMark/skills

Structures wound assessment with measurement, staging, and treatment plan documentation. Use when assessing wounds, staging pressure injuries, or documenting wound care.

managing-trauma-assessments

11
from CaseMark/skills

Conducts structured primary and secondary trauma surveys following ATLS methodology. Use when assessing trauma patients, documenting trauma workups, or coordinating trauma team activations.

managing-speech-therapy-assessments

11
from CaseMark/skills

Structures speech-language evaluation with articulation, language, swallowing, and cognitive-communication assessment. Use when conducting speech evaluations, assessing swallowing function, or documenting communication disorders.

managing-risk-management-healthcare

11
from CaseMark/skills

Structures healthcare risk management with incident investigation, claims analysis, and loss prevention strategies. Use when managing healthcare risk, investigating incidents, or developing loss prevention programs.

managing-risk-adjustment-coding

11
from CaseMark/skills

Captures HCC codes for risk adjustment with annual assessment and documentation requirements. Use when coding for risk adjustment, capturing HCC conditions, or managing RAF scores.

managing-range-of-motion-assessments

11
from CaseMark/skills

Documents goniometric measurements with active/passive ROM and comparison to normative values. Use when measuring joint ROM, documenting mobility assessments, or tracking ROM progress.

managing-psychological-trauma-assessments

11
from CaseMark/skills

Guides trauma-informed assessment with PTSD screening and trauma history documentation. Use when assessing trauma exposure, screening for PTSD, or documenting trauma history.

managing-periodontal-assessments

11
from CaseMark/skills

Structures periodontal evaluation with probing depths, attachment levels, and disease classification. Use when conducting periodontal assessments, classifying gum disease, or documenting periodontal status.

managing-pain-assessment-nursing

11
from CaseMark/skills

Applies pain assessment scales (NRS, Wong-Baker, FLACC, BPS) with intervention documentation and reassessment. Use when assessing pain, selecting pain scales, or documenting pain management.

managing-orthodontic-assessments

11
from CaseMark/skills

Structures orthodontic evaluation with classification, treatment options, and progress documentation. Use when evaluating orthodontic needs, classifying malocclusion, or documenting treatment progress.

managing-occupational-therapy-assessments

11
from CaseMark/skills

Structures OT evaluation with ADL assessment, adaptive equipment needs, and work readiness evaluation. Use when conducting OT assessments, evaluating ADL independence, or recommending adaptive equipment.

managing-newborn-assessments

11
from CaseMark/skills

Structures newborn examination with Apgar scoring, gestational age assessment, and initial screening. Use when examining newborns, documenting birth assessments, or performing initial newborn evaluations.