Banking Services: Cannabis Businesses Face Access Challenges
A GAO review found that FinCEN's 2014 guidance and BSA/SAR obligations continue to shape how financial institutions serve cannabis-related businesses. Institutions weigh legal/regulatory risk and BSA/AML compliance costs; FinCEN data show filings rose 2015–2019 and were steady through 2024, with…
Cabrillo Club
Editorial Team · September 8, 2026 · 4 min read

Also in this intelligence package
Overview
A GAO review of banking access for cannabis-related businesses (CRBs) highlights persistent operational and compliance challenges for financial institutions and their CRB customers. FinCEN’s 2014 guidance remains the baseline for how banks and credit unions can serve state‑sanctioned CRBs while meeting Bank Secrecy Act (BSA) and suspicious activity reporting (SAR) obligations. Financial institutions balance legal and regulatory risk, the costs of BSA/AML compliance, and community or business considerations when deciding whether to serve CRBs. FinCEN data show the number of institutions filing CRB-related SARs rose from 2015–2019 and then stayed relatively steady through 2024, with about 1,000 banks and credit unions filing such reports in 2024. Despite that activity, CRBs continue to face account closures, high fees and loan costs, difficulty accepting customer payments (noting two major credit card companies prohibit cannabis purchases), and employee access problems. Contractors supporting financial services, banking programs, or the cannabis industry need to act now to reassess risk, update compliance and onboarding processes, and prepare capture/proposal materials that address heightened BSA/AML scrutiny.
Immediate Actions (This Week)
- [ ] Brief your compliance and business development leads on the GAO findings, FinCEN guidance, and BSA/SAR obligations highlighted in the report.
- [ ] Run an internal inventory of any engagements, contracts, or proposals that touch the Cannabis Industry, Financial Services, Banking Services, or Credit Unions market segments; flag those with potential BSA/AML exposure.
- [ ] Assign legal/AML ownership to review your existing customer acceptance, due diligence, and SAR-reporting procedures for CRBs and ancillary businesses; schedule a rapid gap assessment.
- [ ] Notify account teams working with CRB clients to prepare documentation requests that demonstrate enhanced due diligence and BSA controls.
- [ ] Configure Cabrillo Signals War Room and Cabrillo Signals Intelligence Hub saved searches (see Automation below) to deliver alerts on follow‑on developments from FinCEN, Treasury, and federal banking regulators.
Short-Term Actions (30 Days)
- [ ] Complete the gap assessment and produce a short remediation roadmap for BSA/AML controls relevant to CRB-related activity (onboarding, transaction monitoring, SAR content requirements).
- [ ] Map your service lines and proposals to the relevant NAICS categories in your target list to ensure opportunity coverage and to prioritize capture resources (NAICS in scope: 522110, 522120, 522130, 522190, 522210, 522220, 522291, 522292, 522293, 522294, 522298, 522320, 111419, 325411, 424590, 453998).
- [ ] Engage banking partners and legal counsel to confirm current tolerances for CRB work, expected documentation, and fee/crediting practices; document acceptable counterparty criteria.
Long-Term Actions (90+ Days)
- [ ] Build or strengthen a documented BSA/AML program for CRB exposure that includes enhanced due diligence, ongoing monitoring rules, SAR filing templates that include FinCEN‑specified terms, and escalation pathways for regulatory exams.
- [ ] Develop capture and proposal materials (technical approach, risk mitigation narrative, past performance tie‑ins) that clearly describe how your delivery will maintain BSA/AML compliance while enabling service continuity for CRB or ancillary clients.
- [ ] Diversify product and payment acceptance strategies for CRB clients where feasible (ancillary services, cash-handling controls, alternative merchant onboarding approaches), documenting compliance tradeoffs and controls.
- [ ] Track trends in FinCEN SAR filings and federal regulator exam focus areas and iterate your compliance program and proposals accordingly.
Compliance Checklist
- [ ] Bank Secrecy Act (BSA) compliance program review and update for CRB-related activity.
- [ ] Suspicious Activity Reporting (SAR) templates updated to capture FinCEN‑specified terms for CRB transactions.
- [ ] AML/customer due diligence policies enhanced for state‑licensed plant‑touching and ancillary CRBs.
- [ ] SAR filing and retention processes tested and audit‑ready for BSA examinations by federal banking regulators (Treasury/FinCEN, Federal Reserve, FDIC, OCC, NCUA).
- [ ] Employee training on CRB risks, SAR filing triggers, and escalation procedures.
Resources
- FinCEN (agency): https://www.fincen.gov
- Bank Secrecy Act (regulatory resource): https://www.fincen.gov/resources/statutes-regulations
- GAO report contact (from summary): Courtney LaFountain — [email protected]
Also see: Winning Federal Contracts Guide (/insights/winning-federal-contracts)
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard→
Related reading: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) | CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide)
How Cabrillo Club Automates This
- Cabrillo Signals War Room — Already detected this event and delivered this briefing within minutes. War Room continuously monitors FinCEN, Treasury, and federal banking regulator channels and will surface follow‑up guidance, regulator statements, or GAO updates so your compliance and capture teams never miss a development. For this event, War Room will prioritize alerts on SAR guidance revisions, exam focus changes, and agency advisories relevant to BSA/AML and CRBs.
- Cabrillo Signals Match Engine — When this event shifts the competitive or regulatory landscape, the Match Engine automatically rescors and reorders opportunity priorities in your pipeline. It updates keyword relevance (e.g., “cannabis,” “BSA,” “SAR”), agency alignment, and risk indicators so capture managers can quickly identify which pursuits need revised win strategies or elevated legal/AML review.
- Cabrillo Signals Intelligence Hub — Use the Intelligence Hub to track affected agencies (Treasury, FinCEN, Federal Reserve, FDIC, OCC, NCUA) and the NAICS codes listed in your tag set. Configure saved searches and alerts to notify you when FinCEN posts guidance updates, when follow‑on solicitations or regulator notices appear on SAM.gov (System for Award Management) matching the event profile, or when SAR‑reporting trends change.
- Proposal Studio (Proposal OS) — Proposal Studio generates compliance matrices, draft technical approaches, and risk mitigation narratives tailored to BSA/AML obligations using your past performance library. For CRB‑adjacent pursuits, it can assemble SAR‑readiness statements, compliance control descriptions, and sample SOPs that address the GAO findings, significantly reducing first‑draft time.
- Proposal Studio Workflow Tracker — The Workflow Tracker orchestrates a 9‑gate capture process from opportunity ID through post‑submission. For CRB risk events it will route compliance and legal reviews automatically, track required evidence (due diligence checklists, bank acceptance letters, SAR templates), and produce audit‑ready submission packages.
Call to action: log into your Cabrillo Club workspace, review the War Room alert for this event, and enable the Intelligence Hub saved searches and Proposal Studio templates to begin generating compliant capture materials.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard→

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.