NYDFS Part 504: transaction monitoring and sanctions filtering
Last reviewed 27 September 2026. A summary for orientation, not legal advice.
Part 504 of the New York Department of Financial Services' regulations (3 NYCRR Part 504), in force since 1 January 2017, requires regulated institutions to maintain a transaction monitoring programme and a sanctions filtering programme, and to certify compliance each year. It applies to institutions regulated under the New York Banking Law, including banks, trust companies, private bankers, savings banks and savings and loan associations, check cashers and money transmitters, and branches and agencies of foreign banks.
The transaction monitoring programme
- Based on the institution's risk assessment, and reviewed and updated periodically.
- Detection scenarios with thresholds that reflect the institution's risks, documented with the reasons behind them.
- End-to-end testing before and after implementation, including data mapping and scenario logic.
- Protocols for investigating alerts, deciding them and documenting the decision, including whether to file a suspicious activity report.
The filtering programme
- Screening of customers and transactions against the OFAC sanctions lists, based on the risk assessment.
- Matching logic, including fuzzy matching, suited to that risk, with end-to-end testing.
- Ongoing analysis of whether the filtering still works as intended, and documentation of the approach.
What both programmes need
- Complete and accurate data flowing from source systems into monitoring and filtering.
- Governance and management oversight, and adequate funding and qualified staff.
- A documented process for selecting any vendor.
Annual certification
Each year, by 15 April, the board of directors or a senior officer must file a certification with the Department, supported by documentation, that the programmes comply with Part 504.
How Praman Labs supports this
- Sanctions screening against OFAC and other sanctions and watchlist sources, with fuzzy name matching and a recorded decision on every hit.
- Transaction monitoring rules with configurable thresholds, where a change needs a backtest first and every version is kept.
- Every screening records the list version it ran against, supporting testing and certification evidence.
Official sources
Related: UK AML and sanctions · FATF Recommendations · EU AML Regulation