Back to Insights
War RoomSeptember 8, 2026

Banking Services: Cannabis Businesses Face Access Challenges

GAO reviewed banking access for cannabis-related businesses (CRBs) and found that FinCEN’s 2014 guidance and ongoing BSA exam oversight frame how financial institutions may serve state‑sanctioned CRBs.…

3 reports in this intelligence package
Blog post hero image

TL;DR

GAO reviewed banking access for cannabis-related businesses (CRBs) and found that FinCEN’s 2014 guidance and ongoing BSA exam oversight frame how financial institutions may serve state‑sanctioned CRBs. Financial institutions weigh legal/regulatory risk and BSA compliance costs against community needs and business opportunity; FinCEN data show the number of institutions filing CRB-related suspicious activity reports rose from 2015–2019 and then remained relatively steady through 2024, with about 1,000 banks and credit unions filing such reports in 2024. GAO also found CRBs continue to face account closures, higher fees and loan costs, payment acceptance barriers (including prohibition by two major credit card companies), and employee personal banking challenges. The outcome: financial access for plant‑touching and some ancillary CRBs remains constrained, and institutions’ reporting does not fully indicate which firms are ongoing customers. Immediate implications for contractors: expect continued regulatory scrutiny around BSA/AML/SAR obligations, persistent operational friction in serving CRB clients, and opportunities for compliant financial services and ancillary support subject to institutional risk tolerance.

Key Points

  • What happened: GAO examined how FinCEN guidance (2014) and federal BSA oversight affect institutions’ decisions to provide banking services to cannabis‑related businesses; FinCEN data show a rise in institutions filing CRB‑related SARs from 2015–2019 and stability through 2024.
  • Who is affected: Financial services and banking segments, including credit unions, and the cannabis industry; Segmentation lists NAICS 522110, 522120, 522130, 522190, 522210, 522220, 522291, 522292, 522293, 522294, 522298, 522320, 111419, 325411, 424590, 453998 and agencies including Treasury, FinCEN, Federal Reserve, FDIC, OCC, NCUA.
  • Timeline: FinCEN guidance issued in 2014; FinCEN SAR reporting trends reviewed for fiscal years 2015–2024; current status through 2024 per GAO.
  • What contractors should do NOW: Immediately inventory contracts and pipelines for exposure to CRB clients; confirm BSA/AML/SAR compliance responsibilities; notify capture, compliance, and finance leads; and configure Cabrillo Signals to surface agency and NAICS activity related to CRB banking and BSA oversight.

Who Is Affected

  • Financial institutions and banks, credit unions, and businesses serving the cannabis industry (both plant‑touching and ancillary businesses).
  • Compliance regimes implicated include the Bank Secrecy Act (BSA), suspicious activity reporting (SAR), and AML obligations.
  • Specific NAICS codes, agencies, and contract vehicles are listed in Segmentation and should be monitored; see segmentation for exact codes and agencies.

Specific NAICS codes, agencies, and contract vehicles pending source review.

Frequently Asked Questions

A: FinCEN issued guidance in 2014 describing how financial institutions can serve CRBs while complying with BSA requirements. Institutions that do serve CRBs must gather detailed customer information and file SARs for specified transactions per the guidance.

A: GAO reports that FinCEN data indicate about 1,000 banks and credit unions filed CRB‑related SARs in 2024. The number of institutions filing such reports rose from 2015–2019 and then remained relatively steady through 2024.

Q: Do SAR filings indicate which institutions have CRBs as ongoing customers?

A: No. GAO notes FinCEN data do not identify how many institutions accept CRBs as ongoing customers. Institutions may not report, may not know they are providing services to CRBs, or may have filed SARs for occasional transactions or for ancillary businesses rather than plant‑touching businesses.

Definitions

  • Cannabis‑related businesses (CRB): State‑licensed businesses that grow, manufacture, or sell cannabis products (plant‑touching) and businesses that support those operations (ancillary).
  • Financial Crimes Enforcement Network (FinCEN): Federal agency that issues guidance and collects BSA/AML reporting, including SARs, related to CRBs.
  • Bank Secrecy Act (BSA): Federal law establishing reporting and recordkeeping obligations to prevent financial crimes; underlies SAR filing requirements discussed in the GAO review.
  • Suspicious Activity Reports (SAR): Reports that financial institutions must file under BSA guidance for certain transactions involving CRBs, as specified by FinCEN.

Intelligence Response

  • Which Cabrillo products to leverage
  • Use Cabrillo Signals War Room — Already detected this event and delivered this briefing; maintain continuous monitoring of updates to FinCEN guidance, GAO follow‑ups, and agency exam focus.
  • Use Cabrillo Signals Match Engine — Rescore and reprioritize opportunity pipelines where BSA/AML risk or CRB exposure shifts competitive dynamics.
  • Use Cabrillo Signals Intelligence Hub — Track the listed NAICS codes and affected agencies (Treasury, FinCEN, Federal Reserve, FDIC, OCC, NCUA) and create saved searches for related solicitations and policy notices.
  • Use Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker — Prepare compliant capture artifacts and run bid/no‑bid analysis with automated compliance routing for proposals touching financial services or CRB support.
  • Who to notify
  • Capture Lead — assess pipeline and bid posture for affected opportunities.
  • Compliance Officer / BSA/AML Lead — confirm reporting obligations and control gaps.
  • CFO / Finance Lead — review potential financial exposure (fees, loan terms).
  • Business Development / Sales Leadership — adjust outreach and messaging for CRB market segments.
  • First 48‑hour playbook
  • Hour 0–4: Confirm receipt of this War Room brief; notify Capture Lead, Compliance Officer, and CFO. Stand up a focused issue thread in Proposal Studio Workflow Tracker.
  • Hour 4–12: Run Cabrillo Signals Match Engine to rescore active opportunities and flag those with CRB exposure; use Intelligence Hub saved searches to pull recent agency guidance and SAR‑related notices.
  • Hour 12–24: Compliance team performs rapid gap assessment of BSA/AML/SAR obligations for affected workstreams; begin drafting compliance language and mitigation in Proposal OS.
  • Hour 24–48: Capture Lead decides bid/no‑bid based on Proposal Studio outputs; Compliance finalizes required control statements and the Workflow Tracker documents audit trail for decisions.

Primary hub: Winning Federal Contracts Guide (/insights/winning-federal-contracts)

Related guides: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)