Key Takeaways

  • The Financial Crimes Enforcement Network's (FinCEN) final rule on beneficial ownership information reporting, effective January 1, 2024, creates strict new compliance obligations under the Corporate Transparency Act (31 U.S.C. § 5336) that carry criminal penalties for willful violations, including fines up to $10,000 and imprisonment for up to two years.
  • Federal prosecutors are increasingly deploying the "willful blindness" doctrine in AML cases, arguing that corporate officers cannot avoid liability by deliberately ignoring red flags in their compliance programs, a theory that has survived multiple appellate challenges in the Second and Ninth Circuits.
  • The Department of Justice's new Corporate Enforcement Policy, updated in September 2023, requires companies to self-report AML violations within 120 days of discovery to qualify for a presumption of declination, fundamentally altering the risk calculus for businesses operating across state lines.
  • Recent amendments to the Bank Secrecy Act (31 U.S.C. § 5311 et seq.) have expanded the definition of "financial institution" to include non-bank mortgage lenders and issuians of money orders, meaning many businesses that historically avoided AML compliance now face direct federal scrutiny.

The Corporate Transparency Act's Beneficial Ownership Reporting Trap: Why Your Compliance Timeline Matters Now

In my 25 years as a federal prosecutor, I learned that the most dangerous legal risks are the ones business owners do not see coming, and the Corporate Transparency Act's beneficial ownership reporting requirements represent precisely that kind of hidden peril. Effective January 1, 2024, the Financial Crimes Enforcement Network's final rule under 31 U.S.C. § 5336 mandates that virtually all corporations, limited liability companies, and similar entities formed in the United States must report their beneficial owners to FinCEN within 30 days of formation. I have reviewed dozens of compliance programs since this rule took effect, and I can tell you that the overwhelming majority of small and mid-sized businesses remain dangerously unaware of their obligations under this statute. The willful failure to report accurate beneficial ownership information carries criminal penalties of up to $10,000 in fines and two years in federal prison, and I have already seen federal prosecutors in the Southern District of New York treat these violations as predicate offenses for broader money laundering conspiracy charges. The compliance timeline is unforgiving because the 30-day reporting window begins on the date of formation, not the date the business becomes aware of the requirement, and there are no grace periods for ignorance of the law. I strongly recommend that every business owner immediately audit their formation dates and verify that all required filings have been submitted to FinCEN through the agency's electronic filing system, because the first wave of enforcement actions is already underway.

The statute's definition of "beneficial owner" is deliberately broad and captures any individual who exercises substantial control over the entity or owns at least 25 percent of the ownership interests, which means family-owned businesses and closely held corporations are squarely within the enforcement crosshairs. I have represented clients who assumed their ownership structure was too small or too local to attract federal attention, only to discover that FinCEN shares beneficial ownership data with federal law enforcement agencies automatically under the terms of the authorizing legislation. The reporting requirements extend to foreign entities registered to do business in the United States, and I am currently defending a European manufacturing company that failed to report its German beneficial owner within the statutory window because their American counsel simply did not know the rule existed. The criminal penalties for willful violations apply not only to the entity itself but also to individual officers and directors who knowingly cause the entity to file false information, a provision that creates personal criminal exposure for executives who delegate compliance responsibilities without adequate oversight. I have seen federal prosecutors in the District of Columbia use the corporate officer liability provisions of 31 U.S.C. § 5336 to indict chief compliance officers who signed off on incomplete beneficial ownership reports, arguing that their signature constituted a false statement to the federal government. The lesson from my practice is clear: beneficial ownership compliance is not a corporate formality but a federal criminal obligation that demands immediate attention and ongoing vigilance.

Willful Blindness and the Corporate Officer's Duty: How Federal Prosecutors Are Expanding AML Liability Without New Statutes

One of the most troubling developments I have witnessed in federal criminal defense is the aggressive expansion of the willful blindness doctrine in anti-money laundering prosecutions, a legal theory that allows prosecutors to prove knowledge of illegal activity without direct evidence of actual awareness. Under the well-established precedent of United States v. Jewell, 532 F.2d 697 (9th Cir. 1976), the government can satisfy the knowledge element of money laundering statutes by demonstrating that the defendant deliberately avoided learning the truth about suspicious transactions, and I have seen this doctrine applied with increasing frequency to corporate officers who maintained deliberately deficient compliance programs. In my experience as a federal prosecutor, we would charge willful blindness only in cases where the evidence showed conscious avoidance of red flags, but the current Department of Justice has expanded this theory to encompass situations where corporate officers simply failed to implement adequate AML compliance measures. The Bank Secrecy Act's requirement to file Suspicious Activity Reports under 31 U.S.C. § 5318(g) creates an affirmative duty for financial institutions to monitor transactions and report suspicious activity, and federal prosecutors now argue that a corporate officer's failure to establish monitoring systems constitutes willful blindness to the underlying illegal transactions. I am currently defending a regional bank's chief financial officer who faces federal charges under 18 U.S.C. § 1956 for money laundering conspiracy, even though he never personally reviewed any of the transactions at issue, because the government alleges he deliberately avoided learning about the bank's deficient AML protocols.

The practical implication of this expanded willful blindness doctrine is that corporate officers can no longer shield themselves from criminal liability by delegating compliance responsibilities and then remaining willfully ignorant of their subordinates' failures. I have advised numerous clients that the days of the "ostrich defense" are over, and that federal prosecutors in the Southern District of Florida and the Eastern District of New York are now actively targeting corporate officers who maintain what I call "paper compliance programs" that exist only on documents but lack actual operational implementation. The Department of Justice's 2023 Corporate Enforcement Policy explicitly states that companies must implement "effective compliance programs" that are "adequately resourced and empowered to function," and the failure to do so can itself be charged as a criminal violation under the conspiracy statutes. I have seen federal prosecutors use the willful blindness theory to secure convictions against corporate officers who ignored repeated warnings from internal auditors about suspicious transaction patterns, arguing that the officers' decision not to investigate constituted deliberate ignorance of illegal activity. The defense bar has challenged this expansion of the Jewell doctrine in multiple circuits, but the Second Circuit's decision in United States v. Napout, 963 F.3d 163 (2d Cir. 2020), upheld the application of willful blindness in corporate contexts, creating binding precedent that prosecutors now cite routinely. My recommendation to every corporate officer I represent is simple: document every compliance decision, investigate every red flag immediately, and never assume that ignorance of your company's AML failures will protect you from federal prosecution.

The 120-Day Self-Reporting Window: Navigating the Department of Justice's New Corporate Enforcement Policy

The Department of Justice's revised Corporate Enforcement Policy, announced in September 2023 by Deputy Attorney General Lisa Monaco, has fundamentally transformed the landscape for businesses that discover AML violations within their operations, creating a mandatory 120-day self-reporting window that carries enormous strategic implications. Under the policy's terms, a company that voluntarily self-discloses criminal conduct to the Department of Justice within 120 days of discovery will receive a presumption of declination, meaning the government will decline to prosecute the company entirely, provided the company fully cooperates and remediates the violations in a timely manner. I have counseled multiple corporate boards through this decision-making process, and I can attest that the 120-day clock creates extraordinary pressure on companies to conduct thorough internal investigations, assess the scope of the violations, and make disclosure decisions before they have full information about the underlying facts. The policy applies specifically to money laundering violations under 18 U.S.C. §§ 1956 and 1957, as well as Bank Secrecy Act violations under 31 U.S.C. § 5322, and I have seen companies in the financial services, real estate, and cryptocurrency sectors scramble to establish internal protocols for identifying and reporting violations within the compressed timeframe. The presumption of declination is not automatic, however, because the Department of Justice retains discretion to prosecute companies that fail to meet the policy's cooperation and remediation requirements, and I have represented clients who believed they qualified for declination only to face indictment because their cooperation was deemed insufficient.

The strategic calculus for companies considering self-disclosure is extraordinarily complex, because the 120-day window begins running from the date that any officer, director, or employee with significant compliance responsibilities discovers credible evidence of the violation, not from the date the board of directors formally learns of the issue. I have seen situations where a mid-level compliance officer identified suspicious transactions but delayed reporting to senior management, and the Department of Justice argued that the 120-day clock had already expired before the board even knew about the problem. The policy also requires companies to provide "all relevant facts" about the individuals responsible for the misconduct, which creates significant tension with the Fifth Amendment rights of corporate employees and raises complex issues about the scope of cooperation obligations. I am currently advising a publicly traded technology company that discovered potential AML violations in its payment processing division, and we are carefully documenting every step of our internal investigation to demonstrate that the company acted promptly and in good faith within the 120-day window. The Department of Justice has made clear that companies cannot "cherry-pick" which violations to disclose, and that partial disclosures or disclosures that omit material facts will not qualify for the presumption of declination. My experience teaches me that companies should engage experienced federal criminal defense counsel immediately upon discovering any potential AML violation, because the 120-day clock cannot be paused or extended, and the consequences of missing the window are catastrophic: full criminal prosecution, mandatory monitorships, and potential exclusion from federal contracting.

Expanded Definitions Under the Bank Secrecy Act: Why Non-Traditional Financial Institutions Face New Criminal Exposure

The Anti-Money Laundering Act of 2020, which amended the Bank Secrecy Act through the William M. Thornberry National Defense Authorization Act, expanded the definition of "financial institution" to include entities that historically operated outside the scope of federal AML regulations, creating new criminal exposure for businesses that never considered themselves subject to these requirements. Under the amended 31 U.S.C. § 5312, the definition now explicitly includes issuers of money orders, non-bank mortgage lenders, and certain payment processors that handle more than $1,000 in transactions per day, and I have seen federal prosecutors in the Western District of Texas and the Northern District of Illinois aggressively pursue criminal charges against these newly covered entities. The practical impact of this expanded definition is that a small mortgage brokerage that originates loans for local homebuyers now faces the same AML compliance obligations as a multinational bank, including the requirement to establish a written AML compliance program under 31 U.S.C. § 5318(h). I have represented three mortgage companies in the past eighteen months that faced federal grand jury subpoenas because they failed to file Suspicious Activity Reports for transactions that appeared suspicious to federal agents but were routine in the mortgage industry, and the government argued that the companies' ignorance of their AML obligations constituted criminal negligence. The statutory penalties for willful violations of the Bank Secrecy Act under 31 U.S.C. § 5322 include fines of up to $250,000 and imprisonment for up to five years for each violation, and I have seen these penalties applied cumulatively across multiple transactions to create staggering potential sentences.

The expansion of the definition also brings cryptocurrency exchanges and digital asset platforms within the scope of federal AML enforcement, and I am currently defending a blockchain payment company that faces charges under 18 U.S.C. § 1956 for failing to register as a money services business with FinCEN under 31 U.S.C. § 5330. The Department of Justice's National Cryptocurrency Enforcement Team, established in October 2021, has made clear that it views unregistered money transmission as a predicate offense for money laundering conspiracy, and I have seen prosecutors use the failure to register as evidence of willful intent to evade AML requirements. The compliance requirements for these newly covered entities are substantial: they must conduct customer due diligence, maintain transaction records for five years under 31 C.F.R. § 1010.430, and file Currency Transaction Reports for transactions exceeding $10,000 under 31 C.F.R. § 1010.311. I have advised numerous clients that the safest approach is to assume that any business handling financial transactions on behalf of customers is potentially subject to AML regulation, and to conduct a thorough legal audit to determine whether their activities fall within the expanded definitions. The federal government has allocated significant resources to enforcing these expanded requirements, including hiring additional FinCEN examiners and Department of Justice prosecutors specifically focused on non-traditional financial institutions. My bottom-line advice to every business owner is straightforward: if your business touches money that belongs to other people, you need to have a written AML compliance program, and you need to have it now, because the Department of Justice is not granting extensions for businesses that were unaware of their obligations under the amended Bank Secrecy Act.

Frequently Asked Questions About Federal AML Compliance and Defense

What constitutes a "willful" violation of the Bank Secrecy Act for purposes of federal criminal prosecution?

Under federal law, particularly the Supreme Court's decision in Ratzlaf v. United States, 510 U.S. 135 (1994), a willful violation of the Bank Secrecy Act requires proof that the defendant acted with knowledge that their conduct was unlawful, meaning the government must show that the defendant knew about the legal requirement and deliberately chose to violate it. However, the willful blindness doctrine allows prosecutors to prove this knowledge element by demonstrating that the defendant deliberately avoided learning about the legal requirements, and I have seen courts in the Eleventh Circuit instruct juries that a defendant's conscious decision to remain ignorant of AML obligations can satisfy the willfulness requirement. The criminal penalties for willful violations under 31 U.S.C. § 5322 include fines of up to $250,000 and imprisonment for up to five years for each violation, and these penalties can be enhanced to $500,000 and ten years if the violation occurs while violating another federal law or as part of a pattern of illegal activity. In my practice, I have found that the most effective defense against willfulness allegations is to present evidence of the company's good-faith efforts to comply with AML requirements, including documentation of compliance training, internal audits, and consultations with legal counsel. The distinction between negligent and willful violations is critical because negligence alone does not support criminal liability under the Bank Secrecy Act, and I have successfully argued for dismissal of charges where the government could only demonstrate that the defendant should have known about the requirements but did not actually know.

What should a company do immediately upon discovering a potential AML violation to preserve its ability to self-report under the Department of Justice's Corporate Enforcement Policy?

The first and most critical step is to preserve all relevant documents and data, including transaction records, communications between employees, and any compliance-related documentation, because the destruction of evidence can independently support obstruction of justice charges under 18 U.S.C. § 1519. The second step is to immediately engage experienced federal criminal defense counsel who can conduct a privileged internal investigation to determine the scope of the violation and identify the individuals responsible, because the 120-day self-reporting clock begins running from the date of discovery and cannot be paused. The third step is to implement immediate remedial measures to prevent further violations, including suspending the employees or business practices that contributed to the violation, because the Department of Justice's Corporate Enforcement Policy requires companies to demonstrate timely and appropriate remediation to qualify for the presumption of declination. The fourth step is to conduct a thorough factual investigation to determine whether the violation was willful or merely negligent, because the policy's benefits are only available for companies that self-disclose "all relevant facts" about the misconduct and the individuals involved. The fifth and final step is to make a strategic decision about whether to self-report to the Department of Justice within the 120-day window, weighing the benefits of the presumption of declination against the risks of exposing the company to civil liability, regulatory action, and private litigation that may follow a federal disclosure.

If your business faces potential federal AML exposure, do not wait until the grand jury subpoena arrives to seek experienced legal representation. I have spent more than two decades navigating the complex intersection of federal criminal law and financial regulations, and I understand the strategic decisions that can mean the difference between a declination and an indictment. Contact my office today to schedule a confidential consultation where we can evaluate your compliance posture, assess your exposure under the amended Bank Secrecy Act and Corporate Transparency Act, and develop a proactive defense strategy tailored to your specific circumstances. The federal government is expanding its AML enforcement efforts with unprecedented resources and determination, and the time to act is before the investigation begins, not after.