bsa-risk-assessment
Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).
Best use case
bsa-risk-assessment is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).
Teams using bsa-risk-assessment should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/bsa-risk-assessment/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How bsa-risk-assessment Compares
| Feature / Agent | bsa-risk-assessment | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
SKILL.md Source
# BSA/AML Risk Assessment Produces examination-ready BSA Risk Assessments evaluating inherent AML/CFT risks against mitigating controls per FFIEC BSA/AML Examination Manual methodology. ## Prerequisites Gather before drafting: 1. **Institution profile** — entity type, charter/regulator, total assets, branch footprint, international relationships 2. **Products & services** — inventory with volumes for high-risk products (wires, monetary instruments, prepaid, trade finance, crypto on/off ramps) 3. **Customer data** — segments with counts of high-risk categories (cash-intensive businesses, PEPs, NRAs, MSBs, foreign correspondents) 4. **BSA/AML program docs** — policies, CIP/CDD/EDD procedures, monitoring system specs, training records 5. **Filing history** — annual CTR/SAR counts by category 6. **Independent testing** — most recent scope, findings, remediation status 7. **Regulatory history** — outstanding MRAs, MOUs, enforcement actions ## Document Sections ### 1. Executive Summary Overall risk rating (Low/Moderate/High), key concentrations, control gaps, priority recommendations with owners and target dates. ### 2. Introduction - Regulatory basis: 31 U.S.C. § 5318(h); 31 C.F.R. § 1020.210 - Scope: all business lines, products, customers, geographies - Assessment period and update frequency (typically annual) - FFIEC risk-based methodology alignment ### 3. Institution Overview Table covering: entity type, charter/regulator, total assets, branch count, high-risk products offered, customer segments, annual CTR/SAR filing counts. ### 4. Inherent Risk Identification Five risk dimensions, each rated High/Moderate/Low: - **Customer** — cash-intensive businesses, MSBs, NBFIs, PEPs, NRAs, nonprofits, foreign correspondents, FATF-listed jurisdiction customers - **Product & Service** — flag products enabling anonymity, rapid movement, or cross-border activity (wires, prepaid, private banking, trade finance, digital channels, crypto) - **Geographic** — HIDTA/HIFCA areas, FATF grey/black list jurisdictions, FinCEN GTO zones, OFAC sanctioned countries - **Transaction** — high-volume cash, structuring patterns, funnel accounts, rapid cycling, shell companies, trade-based ML - **Third-Party** — independent agents, outsourced onboarding/processing, fintech partnerships ### 5. Risk Assessment Matrix Per risk category: | Risk | Inherent | Likelihood | Impact | Mitigating Controls | Residual | |---|---|---|---|---|---| | [Category] | H/M/L | H/M/L | H/M/L | [Description] | H/M/L | Reference FATF typology reports and FinCEN advisories for current typologies (ransomware, elder exploitation, human trafficking, real estate, virtual assets). ### 6. Controls & Mitigation Evaluate each BSA program component against its regulatory basis: | Component | Citation | |---|---| | CIP | 31 C.F.R. § 1020.220 | | CDD / Beneficial Ownership | 31 C.F.R. § 1010.230 | | EDD | FFIEC Manual | | Transaction Monitoring | FFIEC Manual | | OFAC Screening | 31 C.F.R. Part 501 | | CTR Filing | 31 U.S.C. § 5313 | | SAR Filing | 31 U.S.C. § 5318(g) | | BSA Officer / Governance | 31 C.F.R. § 1020.210 | | Training | 31 C.F.R. § 1020.210 | | Independent Testing | 31 C.F.R. § 1020.210 | For each: document current status and adequacy rating. ### 7. Conclusions & Recommendations - Overall risk determination with narrative justification - Residual risks where controls are insufficient - Prioritized remediation table (recommendation, priority, owner, target date) ## Verification Requirements These items change over time — confirm before finalizing: - [ ] FATF grey/black list countries — verify at fatf-gafi.org - [ ] Active FinCEN GTOs — jurisdiction-specific and time-limited - [ ] Beneficial ownership threshold (currently 25%) — check for subsequent FinCEN rulemaking - [ ] FinCEN advisory numbers — verify FIN numbers and dates before citing ## Pitfalls - **Quantitative support required** — risk ratings must cite transaction volumes, SAR counts, or alert rates; qualitative assertions alone are insufficient - **Board presentation** — document must be board-approved or presented to senior management with evidence of review - **Version retention** — keep prior assessments; regulators compare year-over-year - **Privilege risk** — do not include attorney-client privileged material if document will be produced to examiners - **FFIEC citations** — reference specific Examination Manual sections when evaluating control adequacy
Related Skills
managing-wound-assessment-nursing
Structures wound assessment with measurement, staging, and treatment plan documentation. Use when assessing wounds, staging pressure injuries, or documenting wound care.
managing-trauma-assessments
Conducts structured primary and secondary trauma surveys following ATLS methodology. Use when assessing trauma patients, documenting trauma workups, or coordinating trauma team activations.
managing-speech-therapy-assessments
Structures speech-language evaluation with articulation, language, swallowing, and cognitive-communication assessment. Use when conducting speech evaluations, assessing swallowing function, or documenting communication disorders.
managing-risk-management-healthcare
Structures healthcare risk management with incident investigation, claims analysis, and loss prevention strategies. Use when managing healthcare risk, investigating incidents, or developing loss prevention programs.
managing-risk-adjustment-coding
Captures HCC codes for risk adjustment with annual assessment and documentation requirements. Use when coding for risk adjustment, capturing HCC conditions, or managing RAF scores.
managing-range-of-motion-assessments
Documents goniometric measurements with active/passive ROM and comparison to normative values. Use when measuring joint ROM, documenting mobility assessments, or tracking ROM progress.
managing-psychological-trauma-assessments
Guides trauma-informed assessment with PTSD screening and trauma history documentation. Use when assessing trauma exposure, screening for PTSD, or documenting trauma history.
managing-periodontal-assessments
Structures periodontal evaluation with probing depths, attachment levels, and disease classification. Use when conducting periodontal assessments, classifying gum disease, or documenting periodontal status.
managing-pain-assessment-nursing
Applies pain assessment scales (NRS, Wong-Baker, FLACC, BPS) with intervention documentation and reassessment. Use when assessing pain, selecting pain scales, or documenting pain management.
managing-orthodontic-assessments
Structures orthodontic evaluation with classification, treatment options, and progress documentation. Use when evaluating orthodontic needs, classifying malocclusion, or documenting treatment progress.
managing-occupational-therapy-assessments
Structures OT evaluation with ADL assessment, adaptive equipment needs, and work readiness evaluation. Use when conducting OT assessments, evaluating ADL independence, or recommending adaptive equipment.
managing-newborn-assessments
Structures newborn examination with Apgar scoring, gestational age assessment, and initial screening. Use when examining newborns, documenting birth assessments, or performing initial newborn evaluations.