Retain authenticated confidential 314(a) request originals and exact extracted search instructions
/bsa-filings/information-requestsConfidential bounded 314(a) request custody. Actual svc_bsa_bridge and separately configured environment-bound information_request signature authority admit exact original portal bytes plus extracted manifest (names, US tax identifiers, date of birth, addresses, phones, typed identification numbers, account and routing numbers); no FinCEN signature or live portal adapter is claimed. Two staff members review the original and exact plan before request-bound source queries. Four planned native sources cut the core under one explicit normalization: customers (current, evidenced historical, as-filed and tax-document identities, keyed tax blind index or the salted hash on records without one, corrected-tax hashes, tokenized names as lower-confidence candidates, date of birth as confirmation), accounts (every deposit account in the window, current and former owners from database-maintained ownership history, every account number, the subject's own account numbers), payments (wires, instant payments, ACH transfers and receipts, official checks, check deposits, lockbox and inclearing items, saved counterparties inside the transaction window) and lending (loans and facilities, the credit accounts 31 CFR 1010.505(a) counts as accounts, by candidate borrower or the subject's own account numbers). Each verifies exact planned query authority with compliance using the actual incoming svc_compliance token and existing scopes only. Cuts, decisions and handoffs are immutable, purpose-audited and excluded from general bank/customer discovery; the review view pages evidence items. A search is complete only when every source scanned its whole cut with no declared hole. A complete search with independent decisions on every candidate yields a response_ready handoff of positive evidence, or a no_match_recorded handoff with the exact identifiers, windows, row counts and hashes searched and no reply, because FinCEN instructs no reply without a match. Positives under a declared hole or an unresolved decision are partial_coverage. Passport, licence and other document numbers, which no native customer record retains, are an explicit hole. Nothing transmits: the handoff stays not_transmitted and never submission_ready; the BSA officer reports positives through the FinCEN portal by hand.
Headers
Idempotency-KeystringOptionalSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
manifestobjectRequiredManifest is a configured bridge's extraction from retained real portal bytes, not a FinCEN wire format or a FinCEN digital signature. PostedAt, receipt and deadline are explicit request facts, including emergency/retrospective cases.
11 child attributes
accounts_fromstring · dateRequiredA business date, YYYY-MM-DD
cutoffstring · date-timeRequireddeadlinestring · date-timeRequiredenvironmentstringRequiredposted_atstring · date-timeRequiredreceived_atstring · date-timeRequiredrequest_referencestringRequiredretrospectivebooleanRequiredsubjectsarray of objectsRequired9 child attributes
account_numbersarray of stringsOptionaladdressesarray of objectsOptional6 child attributes
citystringOptionalcountrystringOptionalline1stringRequiredline2stringOptionalpostal_codestringOptionalstatestringOptionaldate_of_birthstringOptionalidentification_numbersarray of objectsOptional3 child attributes
jurisdictionstringOptionalkindstringRequirednumberstringRequirednamesarray of stringsRequiredphonesarray of stringsOptionalreferencestringRequiredrouting_numbersarray of stringsOptionaltax_idsarray of stringsOptionaltransactions_fromstring · dateRequiredA business date, YYYY-MM-DD
versionstringRequiredoriginalstring · byteRequiredreceiptobjectRequired2 child attributes
payloadobjectRequired8 child attributes
document_sha256stringRequiredenvironmentstringRequiredissued_atstring · date-timeRequiredkey_idstringRequiredmanifest_sha256stringRequiredobserved_atstring · date-timeRequiredreceipt_idstringRequiredExample achr_2tVh8nqLxq4GbDe0K1F6S9zRcWm
versionstringRequiredsignaturestringRequiredReturns
200 OK
content_sha256stringRequiredcurrent_planintegerRequireddeadlinestring · date-timeRequiredenvironmentstringRequiredidstringRequiredimport_sha256stringRequiredimported_atstring · date-timeRequiredimported_bystringRequiredmanifest_sha256stringRequiredoriginal_sha256stringRequiredoverduebooleanRequiredplansarray of objectsRequired7 child attributes
actorstringRequiredatstring · date-timeRequiredbasis_sha256stringRequiredcontent_sha256stringRequiredrequest_idstringRequiredExample req_2tVh8nqLxq4GbDe0K1F6S9zRcWm
reviewobject or nullOptional4 child attributes
actorstringRequiredapprovebooleanRequiredatstring · date-timeRequiredcontent_sha256stringRequiredversionintegerRequiredreceived_atstring · date-timeRequiredstagestringRequiredsubject_countintegerRequiredverified_public_keystringRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503