Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

FinCEN Delayed the Investment Adviser AML Rule to January 2028. Here's What Changes — and What Doesn't.

FinCEN published a final rule on December 31, 2025 postponing the investment adviser AML/CFT compliance deadline from January 2026 to January 2028. Here's what the delay actually says, why bank partners aren't waiting for FinCEN's timeline, and what to build in the next 18 months.

By Rebecca Leung · June 24, 2026 ·
Table of Contents

TL;DR

  • FinCEN delayed the investment adviser AML/CFT rule effective date from January 1, 2026 to January 1, 2028 via final rule published December 31, 2025
  • FinCEN confirmed intent to revise and tailor the rule’s scope before the 2028 date — some aspects may change, but the obligation will not be withdrawn
  • Bank partners, prime brokers, and custodians are already requiring AML documentation as a condition of service, regardless of where FinCEN’s regulatory timeline sits
  • January 2028 is 18 months away — advisers that use the delay as permission to defer have a compressed compliance sprint ahead

FinCEN gave investment advisers an extra two years. Most are treating it like a free pass. That’s a mistake.

On December 31, 2025 — the last business day of the year — FinCEN published a final rule postponing the effective date of its investment adviser AML/CFT rule from January 1, 2026 to January 1, 2028. The original proposed rule, issued in August 2024, would have subjected approximately 14,000 registered investment advisers (RIAs) and 6,000 exempt reporting advisers (ERAs) — collectively managing approximately $119 trillion in assets — to the same Bank Secrecy Act compliance obligations that have applied to banks, broker-dealers, and money services businesses for decades.

The postponement was widely welcomed. The two-year extension felt like room to breathe. But the text of the delay rule, and the context around why FinCEN issued it, makes plain why treating this as a 24-month vacation is a strategic miscalculation.

What the Postponement Actually Says

The December 31, 2025 final rule does three things.

It moves the deadline. The compliance date shifts from January 1, 2026 to January 1, 2028. Investment advisers that had been building programs under the original timeline — and there were advisers who had already started — now have additional runway. But the new date is hard: FinCEN did not propose a further delay.

It explains why. FinCEN cited significant stakeholder feedback received during the comment period on the proposed rule. Comment letters raised concerns about scope calibration, the treatment of exempt reporting advisers (ERAs) versus fully registered advisers, and the operational burden of building first-time BSA programs. FinCEN concluded it needed more time to address those concerns before the rule took effect.

It signals revision, not withdrawal. This is the part most advisers underweight. The postponement rule states explicitly that FinCEN intends to revise and tailor the rule during the delay period. The 2028 rule may look different in scope, in how requirements are calibrated to the AML/CFT risk profile of investment adviser business models, and in how ERAs are treated relative to fully registered RIAs. What FinCEN did not say — and shows no sign of intending — is that it plans to drop the rule entirely. Investment advisers have been on the agency’s AML coverage gap list since the early 2000s. The policy direction has been settled for over two decades.

Why the Clock Is Still Running

The regulatory compliance deadline moved. The counterparty expectations did not.

Sponsor banks, prime brokers, and custodians operating under their own BSA/AML programs have third-party risk obligations that require them to assess the AML/CFT controls of their business partners. As FinCEN’s rulemaking made the investment adviser AML gap more visible — and as FATF’s 2024 US Mutual Evaluation explicitly called out investment adviser coverage as a structural weakness in the US AML/CFT framework — those counterparties began incorporating documented AML program requirements into their due diligence and onboarding processes.

This trend has been accelerating. Prime brokers that provide services to hedge funds are asking for written AML policies. Custodians that hold assets for RIA clients are asking about SAR escalation processes and customer screening procedures. Sponsor banks evaluating new adviser relationships are adding AML documentation to their standard due diligence checklists — the same way they do for fintech partners.

The April 2026 FinCEN enforcement action against Canaccord Genuity, which resulted in a record AML penalty against a broker-dealer, sent a secondary signal to every firm in the securities sector: documented AML programs are not optional for the industry’s institutions, and the gap between what’s technically required of investment advisers and what counterparties expect is shrinking. The full enforcement analysis at the Canaccord Genuity AML enforcement post covers what the documentation failures looked like.

There’s also an international dimension. FATF’s 2024 US Mutual Evaluation called out the investment adviser sector’s exclusion from BSA requirements as a structural gap. That finding is visible to foreign prime brokers, institutional investors in non-US jurisdictions, and foreign counterparties doing due diligence on US-registered advisers. Advisers with documented AML frameworks have a competitive advantage in those conversations — independent of whether FinCEN’s rule is technically in effect.

What the Rule Will Require

While FinCEN may revise specifics before January 2028, the core structure of the rule follows the standard BSA/AML program framework applied to other financial institutions:

Written program. A documented AML/CFT program tailored to the adviser’s business model, client base, and risk profile. Generic boilerplate doesn’t satisfy this — the program needs to reflect actual exposure: where clients come from, what their source of wealth looks like, what products and transactions the adviser handles.

Customer due diligence. The rule would require investment advisers to perform CDD: identifying beneficial owners of entity clients, understanding the nature of client relationships, and risk-scoring clients for AML purposes. High-risk categories — politically exposed persons, clients from FATF-identified high-risk jurisdictions, entity clients with opaque ownership structures — require enhanced due diligence.

Suspicious activity reporting. Advisers would need to file SARs with FinCEN when they identify transactions or patterns suggesting money laundering, fraud, or other financial crimes. This requires a defined internal escalation path — someone needs to be responsible for identifying red flags, making filing decisions, and maintaining documentation that supports each filing decision.

BSA recordkeeping and reporting. Alongside SARs, the rule extends other BSA reporting requirements: 314(a) information sharing responses (requiring institutions to search records for FinCEN-named subjects and respond within two weeks), currency transaction reporting obligations, and the record-retention requirements that underpin everything.

Compliance officer and training. Someone needs to own the program. The rule requires designation of a responsible compliance officer and an ongoing training program for relevant staff.

The FinCEN AML/CFT program modernization NPRM — a separate, parallel rulemaking — would update the underlying minimum requirements for AML programs across all institution types. Following both tracks simultaneously is important: the modernization rule may shape what “adequate” looks like for the investment adviser program when the 2028 deadline arrives.

What to Build in the Next 18 Months

January 2028 is 18 months from today. That’s enough runway to build well — and not enough to waste.

Start with the customer risk assessment. Before you can write a defensible AML program, you need to know your client base: who they are, where they come from, how their assets were generated, and what the ownership structures of any fund or entity clients look like. Advisers who haven’t done this systematically discover, when they start, that client data is incomplete in ways that take months to resolve. Starting now creates time to address those gaps.

Map your transaction patterns. Investment advisers managing separately managed accounts (SMAs) or accepting external fund transfers have a different monitoring challenge than advisers who only take ACH subscriptions from domestic custodians. Mapping actual cash flow patterns — and identifying which ones could theoretically be used for layering — lets you design proportionate controls rather than importing a bank’s transaction monitoring framework wholesale.

Build and test your SAR escalation path. The most common AML program weakness, across all institution types, is a SAR process that exists on paper but has never been tested: no one knows who makes the filing decision, no one has been trained on red flags, the documentation infrastructure isn’t in place. A tabletop exercise before you’re under examination pressure costs an afternoon. Doing it for the first time during an examination costs far more.

Audit your service provider relationships. Portfolio management software, CRM systems, and document management platforms that hold client information will intersect with AML program requirements — particularly the BSA’s information-sharing provisions and record-retention requirements. Review what data your vendors hold and whether you’d be able to respond to a 314(a) request with the information you actually have.

The underlying risk-control mapping for an AML program — documenting which controls address which risks, how they’re tested, and what the residual exposure looks like — is exactly what a well-designed RCSA supports. The RCSA template provides the risk-control documentation structure that makes AML program requirements traceable and auditable. For the monitoring side, the BSA/AML KRI metrics framework covers what a well-structured monitoring program looks like once the policy foundation is in place.

The ERA Question

One specific calibration question FinCEN signaled it will revisit: whether all 6,000 exempt reporting advisers face the same requirements as fully registered RIAs.

ERAs — advisers to private funds that file exemption reports with the SEC rather than full registration — were included in the original proposal because the private fund sector presents distinct AML/CFT concerns: beneficial ownership opacity, complex fund structures, international investor bases, and the potential for layering through fund subscriptions and redemptions. FATF and FinCEN’s own assessments have identified private funds as a higher-risk segment precisely because of those structural features.

Whether FinCEN carves out a lighter-touch approach for smaller or simpler ERAs is genuinely uncertain. What’s not uncertain: ERAs managing funds with complex ownership structures or international investor bases are the segment with the highest risk profile — and are therefore the least likely to benefit from any scope carve-out that does emerge. If your ERA manages a fund with politically exposed persons, offshore investors, or layered ownership structures, waiting to see what FinCEN does before starting program development is the highest-risk path available to you.

So What?

FinCEN’s December 31, 2025 postponement is a useful development for investment advisers that needed more time to build thoughtfully. It’s not a signal that the rule is going away, that the political appetite for investment adviser AML coverage has softened, or that counterparties will wait for a regulatory deadline before asking for documentation.

The advisers that will handle January 2028 cleanly are the ones treating the next 18 months as an implementation runway: customer risk assessment now, SAR escalation path built and tested before 2027, bank partner documentation ready regardless of how FinCEN retails the final scope.

The ones that won’t are the ones reading “2028 deadline” and scheduling their first program meeting for Q4 2027.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Did FinCEN finalize the investment adviser AML rule?
Partially. FinCEN published a final rule on December 31, 2025 that postpones the compliance deadline from January 1, 2026 to January 1, 2028. The underlying rule — requiring investment advisers to maintain written AML/CFT programs, file SARs, and comply with BSA recordkeeping requirements — was not withdrawn. FinCEN stated it intends to revise and tailor the rule before the 2028 effective date.
Which investment advisers does the rule apply to?
The rule applies to SEC-registered investment advisers (RIAs) and exempt reporting advisers (ERAs). State-registered investment advisers are not covered. Approximately 14,000 RIAs and 6,000 ERAs managing approximately $119 trillion in combined assets fall within the rule's scope as proposed.
What will the investment adviser AML/CFT rule require when it takes effect?
At minimum, investment advisers would need to establish a written AML/CFT program with risk-based internal controls, conduct customer due diligence and risk screening, file Suspicious Activity Reports (SARs) with FinCEN, comply with BSA recordkeeping and reporting requirements, and designate a compliance officer responsible for the program. FinCEN may revise specific requirements before January 2028.
If the rule is delayed to 2028, why should investment advisers start building AML programs now?
Two reasons. First, bank partners, prime brokers, and custodians are independently requiring documented AML frameworks as a condition of service — the delay affects regulatory timelines, not counterparty due diligence expectations. Second, the 2028 deadline will apply in some form regardless of any scope revisions, and building program foundations now (risk assessment, customer screening, SAR escalation) is dramatically cheaper than a compressed compliance sprint in 2027.
How does this rule relate to FinCEN's broader AML/CFT program modernization NPRM?
They're related but separate. The investment adviser AML rule is a standalone rulemaking extending BSA program obligations to a previously excluded sector. FinCEN's broader AML/CFT modernization NPRM would revise the baseline requirements for all financial institutions' AML programs, potentially affecting what the investment adviser program requirements look like when they take effect.
What BSA obligations already apply to investment advisers without the new rule?
Some obligations already attach. Investment advisers that are also SEC-registered broker-dealers face full BSA program requirements through the broker-dealer rule. Advisers that are also transfer agents or mutual fund operators face those rules. Most standalone registered investment advisers, however, currently have no specific BSA program obligation — that's the structural gap the FinCEN rule is designed to close.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.