Call for a Free Consultation Today: +1 (833) RADD-LLC

Your First BSA/AML Audit as an ISO or Payment Facilitator – A Practical Game Plan

At many payment companies, the first serious BSA/AML audit does not happen because someone internally planned it. It happens because a sponsor bank suddenly says, “You need to get a BSA/AML audit done.”

If you are new in the risk seat at an ISO or a Payfac‑in‑formation, that can feel like being thrown into the deep end. You may have banking‑side exam experience, but the expectations and constraints are different when you are the program being audited instead of the bank doing the auditing.

Let’s walk through a practical game plan for that first BSA/AML review, based on real conversations with risk leaders in exactly this situation.


1. Understand the context you are walking into

When a sponsor bank mandates a BSA/AML audit, it is usually for one of three reasons:

  • A new payments program is being stood up, such as moving from ISO to Payfac.
  • The company has hit a growth or risk threshold that changes how the bank views the relationship.
  • A prior review or internal assessment has raised questions the bank wants closed out by an independent party.

At the same time, early‑stage payment companies often share similar realities:

  • Policies exist, but procedures are still being written or refined.
  • Governance structures (such as board committees and formal minutes) are light or evolving.
  • Transaction history is short, and there may be few or no SARs yet.

The key is to acknowledge these constraints and build them into the approach, rather than pretending the program is as mature as a long‑established bank.


2. Turn the audit scope into your readiness checklist

A good BSA/AML scope is more than a document for the auditor; it is a readiness checklist for the internal team. Use the draft scope this way:

  • Map each area to current reality For each component (CDD, EDD, monitoring, sanctions, governance, SARs, etc.), confirm whether there is a policy, a procedure, and evidence that the practice is actually happening.
  • Flag clearly non‑applicable items Some elements, like certain board committee requirements or SAR history, may not apply at the current stage. Instead of ignoring them, mark them and be ready to explain why they are not relevant yet.
  • Backfill missing procedures Many newer companies have policies but lack detailed procedures. Use the scope as a prioritized to‑do list for the procedures that must exist before fieldwork begins.

This approach turns the scope from a threat into a planning tool.


3. Pull your sponsor bank into the process

One of the most underused moves is simply asking:

“Do you have a preferred BSA/AML audit scope or checklist you want us to follow?”

Many sponsor banks have internal expectations they would like to see covered, but they do not always offer them proactively. If they do share a scope:

  • Compare it to the auditor’s standard scope.
  • Identify overlaps and gaps.
  • Work with the auditor to integrate the bank’s expectations into the final scope.

This single step can prevent the scenario where a complete audit is followed by the bank saying, “We expected to see more on certain topics.”


4. Get clear on timing and milestones early

For a first‑time BSA/AML review, lack of timing clarity is a major source of stress. A transparent, structured process might look like this:

  • Scope and high‑level sizing discussion, including transaction volumes and merchant count.
  • Fixed‑fee proposal and engagement letter, avoiding hourly surprises.
  • Document request list provided about 45 days before the start date.
  • A 30‑day window to upload documents, with the audit “clock” starting once about 80 percent of requested items are in.
  • Two to four weeks of fieldwork, depending on volume and complexity.
  • Draft report, discussion, and then finalized report plus workpapers.

With a roadmap like this, teams can work backwards from the audit window and make sure internal stakeholders are ready for each step rather than scrambling.


5. Handle “we do not have that yet” without panic

There will almost always be areas where the program is not yet where it should be:

  • No SARs yet, or very limited SAR experience.
  • Incomplete board or committee structures.
  • Certain controls not implemented because the business is still maturing.

Instead of hiding those gaps, document them. A well‑run audit can:

  • Note “not applicable at this stage” with a clear rationale.
  • Highlight what should be in place by year two or three.
  • Provide practical recommendations and a remediation tracker to guide next steps.

Regulators and sponsor banks care that the risks are understood and there is a plan to address them, not that a young program looks identical to a large, mature institution.


6. Treat the audit as the start of a program, not a one‑off project

For ISOs and Payfacs, BSA/AML reviews are not going away. Once the first audit is complete:

  • Decide whether a multi‑year review cadence with the same firm makes sense, often with an opt‑out to keep performance accountable.
  • Use the findings and recommendations as the roadmap for the next 12–24 months of program build‑out.
  • Update policies, procedures, monitoring, and governance as volumes and risk profiles grow.

When the first audit is treated as the foundation of a continuing compliance program, it becomes an asset rather than a one‑time obligation.If you are an ISO, Payfac, or fintech staring down your first sponsor‑bank‑driven BSA/AML audit, the most important move is to get proactive: use the scope as your checklist, involve your sponsor bank early, and demand a clear process and timeline from your audit partner.

Click here to reach out to Radd’s team for help with your BSA/AML audit.