Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Bsa Risk Assessment

ASecurity

Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
businessgoshelltestinggitapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill bsa-risk-assessment --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Bsa Risk Assessment?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Bsa Risk Assessment
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-bsa-risk-assessment/badge)](https://www.skillsdirectory.com/skills/lev-os-bsa-risk-assessment)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: bsa-risk-assessment
description: Drafts a BSA/AML Risk Assessment for U.S. financial institutions per FinCEN, FFIEC, and OCC standards. Evaluates inherent risks (customer, product, geographic, transaction, third-party), control adequacy, and residual risk. Use when preparing annual BSA compliance assessments, post-acquisition integration reviews, or when business changes trigger reassessment under 31 U.S.C. § 5318(h).
---

# BSA/AML Risk Assessment

Produces examination-ready BSA Risk Assessments evaluating inherent AML/CFT risks against mitigating controls per FFIEC BSA/AML Examination Manual methodology.

## Prerequisites

Gather before drafting:

1. **Institution profile** — entity type, charter/regulator, total assets, branch footprint, international relationships
2. **Products & services** — inventory with volumes for high-risk products (wires, monetary instruments, prepaid, trade finance, crypto on/off ramps)
3. **Customer data** — segments with counts of high-risk categories (cash-intensive businesses, PEPs, NRAs, MSBs, foreign correspondents)
4. **BSA/AML program docs** — policies, CIP/CDD/EDD procedures, monitoring system specs, training records
5. **Filing history** — annual CTR/SAR counts by category
6. **Independent testing** — most recent scope, findings, remediation status
7. **Regulatory history** — outstanding MRAs, MOUs, enforcement actions

## Document Sections

### 1. Executive Summary

Overall risk rating (Low/Moderate/High), key concentrations, control gaps, priority recommendations with owners and target dates.

### 2. Introduction

- Regulatory basis: 31 U.S.C. § 5318(h); 31 C.F.R. § 1020.210
- Scope: all business lines, products, customers, geographies
- Assessment period and update frequency (typically annual)
- FFIEC risk-based methodology alignment

### 3. Institution Overview

Table covering: entity type, charter/regulator, total assets, branch count, high-risk products offered, customer segments, annual CTR/SAR filing counts.

### 4. Inherent Risk Identification

Five risk dimensions, each rated High/Moderate/Low:

- **Customer** — cash-intensive businesses, MSBs, NBFIs, PEPs, NRAs, nonprofits, foreign correspondents, FATF-listed jurisdiction customers
- **Product & Service** — flag products enabling anonymity, rapid movement, or cross-border activity (wires, prepaid, private banking, trade finance, digital channels, crypto)
- **Geographic** — HIDTA/HIFCA areas, FATF grey/black list jurisdictions, FinCEN GTO zones, OFAC sanctioned countries
- **Transaction** — high-volume cash, structuring patterns, funnel accounts, rapid cycling, shell companies, trade-based ML
- **Third-Party** — independent agents, outsourced onboarding/processing, fintech partnerships

### 5. Risk Assessment Matrix

Per risk category:

| Risk | Inherent | Likelihood | Impact | Mitigating Controls | Residual |
|---|---|---|---|---|---|
| [Category] | H/M/L | H/M/L | H/M/L | [Description] | H/M/L |

Reference FATF typology reports and FinCEN advisories for current typologies (ransomware, elder exploitation, human trafficking, real estate, virtual assets).

### 6. Controls & Mitigation

Evaluate each BSA program component against its regulatory basis:

| Component | Citation |
|---|---|
| CIP | 31 C.F.R. § 1020.220 |
| CDD / Beneficial Ownership | 31 C.F.R. § 1010.230 |
| EDD | FFIEC Manual |
| Transaction Monitoring | FFIEC Manual |
| OFAC Screening | 31 C.F.R. Part 501 |
| CTR Filing | 31 U.S.C. § 5313 |
| SAR Filing | 31 U.S.C. § 5318(g) |
| BSA Officer / Governance | 31 C.F.R. § 1020.210 |
| Training | 31 C.F.R. § 1020.210 |
| Independent Testing | 31 C.F.R. § 1020.210 |

For each: document current status and adequacy rating.

### 7. Conclusions & Recommendations

- Overall risk determination with narrative justification
- Residual risks where controls are insufficient
- Prioritized remediation table (recommendation, priority, owner, target date)

## Verification Requirements

These items change over time — confirm before finalizing:

- [ ] FATF grey/black list countries — verify at fatf-gafi.org
- [ ] Active FinCEN GTOs — jurisdiction-specific and time-limited
- [ ] Beneficial ownership threshold (currently 25%) — check for subsequent FinCEN rulemaking
- [ ] FinCEN advisory numbers — verify FIN numbers and dates before citing

## Pitfalls

- **Quantitative support required** — risk ratings must cite transaction volumes, SAR counts, or alert rates; qualitative assertions alone are insufficient
- **Board presentation** — document must be board-approved or presented to senior management with evidence of review
- **Version retention** — keep prior assessments; regulators compare year-over-year
- **Privilege risk** — do not include attorney-client privileged material if document will be produced to examiners
- **FFIEC citations** — reference specific Examination Manual sections when evaluating control adequacy

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →