Back to Blog
BSA/AML Compliance 8 min read Aug 24, 2026

The Customer Explained It at the Window on Day 1. You Decide If That Was Reasonable on Day 30.

A business customer brings in cash three days running, each deposit sitting just under the reporting line. The branch banker asks about it and gets a four minute answer. Nobody writes it down — and under 31 CFR 1020.320(a)(2)(iii), that answer is the entire test.

BSA / AML compliance cover: ‘They Explained It Out Loud. Nobody Kept It.’ — day 1, what they said, ‘The supplier will not take cards,’ against day 30, what you must decide, ‘No reasonable explanation.’

A business customer brings in cash three days running, each deposit sitting just under the reporting line. The branch banker notices, and asks about it. What comes back is a four minute answer about a supplier who will not take cards and a landlord who wants first and last month up front.

It is a perfectly ordinary exchange, and it may well be the truth. Nobody writes it down.

Twenty nine days later you are drafting the narrative.

Your Whole Test Turns on an Answer Nobody Kept

Read what the rule actually asks of you. Under 31 CFR 1020.320(a)(2)(iii), a transaction is reportable when it “has no business or apparent lawful purpose or is not the sort in which the particular customer would normally be expected to engage, and the bank knows of no reasonable explanation for the transaction after examining the available facts, including the background and possible purpose of the transaction.”

That last clause is the entire job. You are not deciding whether the pattern looks strange. You are deciding whether the explanation for it was reasonable.

Pull the provision apart and it asks three questions in sequence, and only the first two have a home in your systems.

The first two prongs are the ones a system was built for, and they are also the ones that rarely decide anything. Unusual activity is the entry ticket, not the finding. The explanation prong is what gates the filing, and it is the only prong whose evidence was spoken out loud, once, to somebody who is not you.

What 31 CFR 1020.320(a)(2)(iii) asks, in three parts: first, is the transaction the sort this customer would normally do — answered, because transaction monitoring holds this already; second, what is the nature and purpose of the relationship — partly answered, because 1020.210(a)(2)(v)(A) puts this on you; third, does the bank know of any reasonable explanation — not captured, because it lives only in a four minute conversation. Unusual is not enough: the explanation prong gates the filing, and two of these live in a system while the third lives in somebody's memory.
Two of these live in a system. The third lives in somebody’s memory.

Thirty Days Is Longer Than a Conversation Survives

Then the clock runs. Section 1020.320(b)(3) gives you 30 calendar days from initial detection. If no suspect was identified you may take another 30, and in no case more than 60.

Those days are not spent staring at this one account. The deposits happen. A monitoring rule fires some time after that. The alert sits in a triage queue behind others. By the time it clears triage and reaches the desk of the person who will actually write the narrative, the conversation at the window is three weeks cold and the banker who had it has served several hundred customers since.

What arrives in the case file is usually one line of escalation note: “Customer said it was for suppliers.”

That sentence now has to carry a legal standard. And it is worth being precise about how much weight it is being asked to hold, because two versions of the same four minutes point in opposite directions.

“My produce supplier will not take cards, so I draw cash every Monday and pay him on delivery” is a specific, checkable account of a business practice. It names a counterparty type, a cadence, and a reason. “It was for suppliers” is a fragment that is consistent with that account and equally consistent with nothing at all. The first is a reasonable explanation you examined. The second is a summary of one you no longer have.

Nothing about that reflects poorly on the banker or the analyst. It is simply what happens to an unrecorded four minute conversation across thirty days and several hundred other customers. The problem is structural, and structural problems have structural fixes.

The thirty day clock: on day 0 the customer explains it at the window in four minutes, spoken once and not recorded; shortly after, the monitoring alert fires holding amounts, counterparties and velocity; further along the alert reaches the BSA analyst, by which point the conversation is three weeks cold; at day 30 the SAR is due under 31 CFR 1020.320(b)(3), and you now rule on an explanation you never heard, with day 60 marked as the hard stop.
The deciding evidence is created on day 0 and consumed on day 30, with nothing holding it in between.

Your Program Already Promises the Thing You Are Not Capturing

Look at what your AML program committed to in writing. Section 1020.210(a)(2)(v)(A) requires risk based procedures for “understanding the nature and purpose of customer relationships for the purpose of developing a customer risk profile,” and (B) requires ongoing monitoring that maintains and updates customer information.

Understanding the nature and purpose of a relationship is not a field in the core system. A NAICS code is not an understanding. It is what the customer told the banker.

The systems you already run capture the wrong half. Transaction monitoring holds amounts, counterparties, velocity, and geography. Case management holds alert IDs, dispositions, timestamps, and reviewer names.

Each of those records that a number moved, or that a review happened. None of them records the sentence that decides the filing. The bank has excellent evidence that it looked, and almost none of what it saw when it did.

That asymmetry compounds, because (B) is a continuing obligation. Next year’s analyst will ask whether this activity is consistent with the profile, and the honest answer will depend on what the customer explained this year. If that explanation was never captured, the profile does not get updated — it gets re-guessed.

Capture the Explanation While It Is Still a Sentence

Nothing in Part 1020 stops you from capturing an interview. Give notice, follow your state consent law and your bank’s policy, and route the file through the SAR governance you already have.

Two provisions are worth reading first, because they are the ones people get backwards.

Under 1020.320(d), anything you identify as supporting documentation is kept five years and “shall be deemed to have been filed with the SAR,” available to FinCEN, law enforcement, and your examiners on request. Under 1020.320(e)(1)(ii)(A)(2), the confidentiality rule does not reach “the underlying facts, transactions, and documents upon which a SAR is based,” which is exactly how joint SARs get built.

So the recording is not the SAR. It is the fact underneath it. Those are different categories with different rules, and conflating them is what makes teams nervous about creating any record at all.

The practical consequence is that designation is a decision, not an accident. Decide on purpose which files you designate as supporting documentation, write that decision into your procedures, and apply it consistently — rather than working it out mid exam under 1020.320(g), with an examiner waiting.

AmyNote runs on the phone already in the banker’s hand. No meeting bot joins anything, nothing external is invited into a BSA file, and it behaves the same at a branch desk as on a relationship call. It captures the audio, transcribes with OpenAI’s Speech API, and runs the analysis through Anthropic’s Claude models to surface what a narrative needs: the stated source of funds, the named counterparty, the reason cash was used, and what changed since the last review.

Because this is a BSA file, here is the architecture. Both OpenAI and Anthropic contractually guarantee zero training on user data. Audio is encrypted in transit and not retained after processing. Transcripts are stored locally on device with end to end encryption. Run the vendor review before the first call rather than after.

What Changes in the Narrative

A SAR narrative is judged on whether it explains what happened and why the bank found it suspicious. The difference a captured conversation makes is not length. It is that the who, what, when, where and why stop being reconstructed and start being quoted.

It also changes the case that gets closed without a filing. A no-file decision supported by a specific, contemporaneous explanation is a defensible decision. The same decision supported by “customer said it was for suppliers” is a judgment call your examiner cannot follow and your successor cannot reconstruct. Both outcomes — filing and not filing — get better when the deciding evidence still exists.

Getting Started

Do not start with the account that already has an alert sitting on it. Start with the next routine annual review call, where nothing is at stake and nobody is guarded.

Build the habit while it costs nothing, so it is automatic on the file where everything turns on it. Give notice, follow policy, and file the record where your BSA team can actually find it. AmyNote takes about a minute to set up, and details are at amynote.app.

The narrative you write on day 30 is only as good as the four minutes nobody kept on day 1.

Originally published as an X Article by @AmyNoteApp.

Keep the Explanation, Not Just the Alert

Bot-free capture from the phone already in the banker's hand — nothing external joins a BSA file, and a branch desk works the same as a relationship call. 140+ transcription languages with translation into 100+. Transcription powered by OpenAI's latest Speech API. AI analysis by Anthropic's Claude models. Both providers contractually guarantee zero training on user data. Audio is encrypted in transit; processing copies may be retained to deliver and recover requested features. Transcripts stored locally on device. iOS only.

3-Day Free Trial — No Credit Card

Related Articles