A willful failure to maintain an effective anti-money laundering program can carry a $250,000 fine and five years in federal prison under 31 U.S.C. § 5322, the criminal penalty section of the Bank Secrecy Act.
Reckless disregard is enough to trigger it. Willful blindness works too. For fintech founders, hedge fund managers, banking executives, and compliance officers, that low bar means a compliance gap can now become personal criminal exposure, regardless of whether the institution itself survives.
What Does the Bank Secrecy Act Actually Require?
The Bank Secrecy Act requires financial institutions- a term that now reaches banks, broker-dealers, money services businesses, and most cryptocurrency exchanges- to build a program capable of detecting and reporting suspicious activity. Institutions must file Currency Transaction Reports for cash transactions over $10,000.
They must also file Suspicious Activity Reports whenever a transaction looks designed to launder money or dodge the law. An effective AML program generally needs four components:
- Written policies and procedures tailored to the institution's actual risk profile.
- A designated compliance officer with real authority.
- Ongoing employee training on red flags and reporting duties.
- Independent testing to confirm the program works as designed.
Additionally, institutions must maintain robust Customer Due Diligence (CDD) procedures. This includes verifying customer identities, determining beneficial ownership of corporate entities, and continuously assessing risk profiles to ensure high-risk accounts receive heightened scrutiny.
Skip any one of these and regulators have grounds to call the entire program ineffective. That finding is the door through which criminal exposure walks in.
What Counts as a “Willful” Violation Under 31 U.S.C. § 5322?
Willfulness is the hinge the whole statute turns on. Prosecutors do not need to prove that an executive set out to break the law. Courts have accepted reckless disregard or willful blindness as sufficient. An executive who deliberately avoided learning what compliance staff already knew can still be convicted under that standard.
That matters most for founders who delegate compliance to a small team and then stop asking questions. Put simply, not knowing is not a defense if the not-knowing was itself the choice.
A board that receives quarterly compliance updates and never asks a follow-up question is building the same record a prosecutor would want to see. Internal messages showing an executive knew about a gap.
They chose not to close it are often the centerpiece of a BSA prosecution, more damaging than the underlying compliance failure itself.
Why Are Individual Executives Being Personally Charged?
Two forces explain the shift toward personal liability. The Anti-Money Laundering Act of 2020 added subsection (e) to § 5322, requiring a convicted individual who was a partner, director, officer, or employee to forfeit any bonus paid around the time of the violation.
That sits on top of a separate fine equal to the person's own profit from the misconduct. Congress built the statute to reach compensation, not just corporate revenue.
Enforcement outcomes reflect the change. In 2023, the founder and CEO of a major cryptocurrency exchange personally pleaded guilty to willfully causing his company to operate without an effective AML program.
He paid a $50 million fine and served time in federal prison, even as the exchange itself continued operating under new leadership. When multiple executives share responsibility for a failed program, prosecutors increasingly add a parallel federal conspiracy charge that ties individual willfulness counts into a single theory.
What Are the Criminal Penalties Under § 5322?
A standard willful violation under subsection (a) carries a fine of up to $250,000, imprisonment of up to five years, or both.
Subsection (b) raises the stakes considerably. If the violation occurs alongside another federal law violation, or as part of a pattern of illegal activity involving more than $100,000 in twelve months, the fine climbs to $500,000 and the prison term to ten years.
Subsection (e) adds a profit-based fine and a bonus clawback for financial institution insiders. That clawback provision applies to a partner, director, officer, or employee even if their own conduct never involved a specific illegal transaction, so long as they held the role when the violation occurred.
And because BSA violations frequently accompany fraud or unlicensed money transmitting charges, asset forfeiture is almost always part of the exposure rather than a separate afterthought.
Related Federal Laws
Prosecutions under 31 U.S.C. § 5322 rarely occur in isolation; federal authorities treat Bank Secrecy Act program failures as an entryway to unravel broader financial crime networks.
While § 5322 focuses on the institutional and executive failure to maintain an adequate anti-money laundering program, prosecutors routinely stack related statutory charges—such as transaction structuring (§ 5324), unlicensed money transmission (§ 1960), or substantive money laundering (§ 1956)—to establish a multi-year pattern of illegal activity.
Because secondary violations can trigger mandatory statutory enhancements that double potential prison terms to 10 years, defense counsel must analyze these intersecting statutory frameworks as a whole to dismantle the government's claim of "willful" executive oversight. The related laws include:
-
18 U.S.C. § 1956 (Laundering of Monetary Instruments): Criminalizes conducting financial transactions involving unlawful proceeds to disguise their source, location, or ownership, carrying severe penalties up to 20 years in federal prison.
-
18 U.S.C. § 1960 (Prohibition of Unlicensed Money Transmitting Businesses): Imposes criminal liability on individuals or entities that operate money service businesses or digital asset exchanges without necessary state licenses or FinCEN registrations.
-
31 U.S.C. § 5324 (Structuring Transactions to Evade Reporting Requirements): Prohibits intentionally splitting deposits, withdrawals, or transfers into amounts under $10,000 to circumvent mandatory Currency Transaction Report (CTR) filings.
-
31 U.S.C. § 5336 (Beneficial Ownership Information Reporting / Corporate Transparency Act): Requires reporting companies to disclose their ultimate beneficial owners to FinCEN, establishing criminal penalties for willfully providing false or fraudulent reporting data.
-
18 U.S.C. § 371 (Conspiracy to Commit Offense or to Defraud United States): Permits federal prosecutors to charge two or more executives or compliance officers who agree to impair, obstruct, or defeat lawful regulatory functions like FinCEN monitoring.
Frequently Asked Questions (FAQs)
How do prosecutors prove "willful blindness" in a Bank Secrecy Act case?
Prosecutors establish willful blindness by presenting evidence that an executive was aware of a high probability of compliance failures or illegal activity, but deliberately chose not to investigate.
This is often proven by internal emails showing unheeded compliance alerts, skipped audit reports, or board minutes in which warnings were raised but ignored.
Are cryptocurrency exchanges and Web3 platforms subject to 31 U.S.C. § 5322?
Yes. Under FinCEN regulations, cryptocurrency exchanges, token issuers, and decentralized finance (DeFi) platforms that act as money transmitters are classified as financial institutions.
Executives and founders of digital asset platforms face the exact same AML compliance mandates and § 5322 personal criminal liability as traditional bank officers.
What is the threshold for mandatory Suspicious Activity Report (SAR) filings?
Financial institutions must file a SAR with FinCEN when they detect a known or suspected violation of federal law, or a suspicious transaction involving $5,000 or more ($2,000 or more for money service businesses).
Willfully failing to maintain a system capable of identifying and filing SARs can expose individuals to criminal liability under § 5322.
Can an executive be charged if the financial institution itself is not prosecuted?
Yes. Under the Department of Justice's current enforcement priorities, prosecutors frequently pursue individual corporate officers regardless of whether the institution enters into a non-prosecution agreement (NPA), a deferred prosecution agreement (DPA), or pleads guilty. Executive liability operates independently from corporate liability.
What is the role of a designated BSA Compliance Officer, and do they carry higher personal risk?
A BSA Compliance Officer is responsible for coordinating and monitoring day-to-day AML compliance. Because they receive direct regulatory warnings, internal red flags, and audit reports, prosecutors often scrutinize compliance officers first when determining if a failure to remediate a gap constituted "willful" misconduct.
What is the statutory limitation period for federal Bank Secrecy Act prosecutions?
The standard statute of limitations for non-capital federal crimes, including 31 U.S.C. § 5322 violations, is 5 years under 18 U.S.C. § 3282. However, prosecutors often allege an ongoing conspiracy (§ 371) or multi-year pattern of illegal activity, which can effectively extend the relevant timeframe under review.
How does an effective Customer Due Diligence (CDD) program protect an institution?
A robust CDD program ensures an institution knows the true identities of its customers and the beneficial owners of corporate accounts. Proper CDD prevents high-risk accounts from operating anonymously, reducing the likelihood of money laundering and demonstrating to regulators that the leadership acted in good faith to mitigate risk.
What immediate steps should a compliance officer or founder take if they suspect an internal AML failure?
Executives should immediately retain independent personal legal counsel (separate from corporate counsel) and initiate a confidential internal audit.
Crucially, all internal communications, transaction records, and compliance logs must be preserved, and any corrective measures or remediation efforts must be carefully documented to establish a record of good faith.
How Does Structuring Fit into This Exposure?
Prosecutors frequently pair BSA program failures with charges under a closely related statute, structuring transactions to evade reporting requirements. Structuring does not require the use of illegal source funds.
It only requires breaking transactions into smaller pieces to dodge the $10,000 reporting line, and it can attach to executives personally if they directed or knew about the pattern.
A series of deposits just under the threshold, repeated on a predictable schedule, is often enough to draw an examiner's attention long before any AML program failure comes into view.
An executive facing a BSA program failure should assume investigators are also examining whether individual transactions in the surrounding fact pattern were structured. The two charges are routinely brought together.
The Exchange Compliance Officer Indictment
A mid-sized digital asset exchange registers as a money services business but relies on a two-person compliance team to monitor millions of daily transactions.
The co-founder, who also serves as interim compliance officer, receives internal alerts flagging a cluster of accounts moving funds in patterns consistent with layering. The alerts sit unreviewed for eight months.
Federal prosecutors personally indict the co-founder, alleging a willful failure to maintain an effective AML program and linking several transactions to a separate bank fraud scheme run by exchange customers.
A defense team would push back on four fronts:
- Whether the compliance gaps reflect willful blindness or a genuine, if understaffed, good-faith effort at monitoring.
- Whether the co-founder's dual role as compliance officer created liability that a properly resourced program would have avoided.
- Whether the government can establish the required continuity between the flagged accounts and the underlying fraud.
- Whether reliance on outside AML consultants who reviewed the program undercuts the willfulness element.
None of these defenses erase the compliance failure. But each one narrows what the government can actually prove, and narrowing the theory is often what moves a BSA case toward resolution short of trial.
How Should Executives Respond to a BSA Investigation?
The first move is separating personal counsel from company counsel. A financial institution's lawyer represents the institution, not the individual officer, and their interests can diverge fast once prosecutors start asking who knew what and when.
Executives should also resist the urge to patch the compliance program quietly and hope the issue disappears. Remediation matters, but undocumented fixes made after a known gap surfaces can appear to be an expression of guilt rather than good faith.
A defensible response usually means engaging counsel immediately, preserving all relevant records, auditing the existing compliance program, and building a documented timeline of what compliance staff knew and when leadership acted on that information.
Waiting for a subpoena is the costliest option. By then, the government has usually already built its case of willfulness from the same internal records the executive still has time to get in front of.
A compliance program built after the fact rarely undoes a pattern of ignored warnings, but it can still shape how a prosecutor, or a jury, reads the executive's state of mind.
The Bank Secrecy Act was written to police an industry. Subsection (e) rewrote that assumption. Compliance now belongs to the company, but criminal exposure belongs to whoever ran it.
If you are accused of violating the Bank Secrecy Act, you need a strong defense. Contact Eisner Gorin LLP today for a confidential consultation.
