Feature Compliance Strategy
AML/CFT Program Reform in 2026: Three Proposals, Three Rulemaking Tracks
FinCEN, OCC/FDIC/NCUA, and the Federal Reserve have distinct AML/CFT proposals. None was final as of August 17, 2026.
Table of Contents
TL;DR
- FinCEN issued an AML/CFT program NPRM in April 2026.
- OCC, FDIC, and NCUA issued a coordinated but separate April proposal for their supervised institutions.
- The Federal Reserve issued a separate Regulation H proposal on July 7, 2026; comments are due September 8 under Docket R-1835.
- None of those proposals was final as of August 17. Do not use proposed enforcement language to dismiss lesser deficiencies or current supervisory risk.
August 17, 2026 Status Update
The 2026 AML/CFT reform effort is not one document. It is a set of parallel rulemakings that share policy themes but differ in issuer, authority, coverage, and docket.
| Rulemaking | Issuer | Official artifact | Status on August 17, 2026 |
|---|---|---|---|
| AML/CFT program proposal | FinCEN | FR Doc. 2026-07033 | Proposed; April comment period closed |
| Coordinated banking-agency proposal | OCC, FDIC, NCUA | FR Doc. 2026-06948 | Proposed; separate agency rule text |
| Regulation H proposal | Federal Reserve | Docket R-1835 | Proposed; comments due September 8, 2026 |
The FinCEN announcement calls its action a proposal. The Federal Reserve announcement does the same. No final-rule implementation clock should appear in policy until an agency publishes final action.
Track 1: FinCEN’s April NPRM
FinCEN’s Federal Register NPRM proposes changes to AML/CFT program requirements across categories of financial institutions subject to FinCEN rules.
The proposal emphasizes a risk-based and effective program, formal risk-assessment processes, governance, priorities, and allocation of resources. Exact duties vary by institution type and final text. A bank, money services business, broker-dealer, insurer, mutual fund, or casino should not assume every provision applies identically.
Track 2: The OCC/FDIC/NCUA Proposal
OCC, FDIC, and NCUA published a coordinated proposal alongside FinCEN’s work. It would amend the agencies’ own program rules for institutions they supervise.
“Coordinated” does not mean the documents are interchangeable. Maintain separate citations and map:
- agency and supervised population;
- CFR provisions;
- definitions;
- examination and supervisory language;
- comment record; and
- any final action.
A consolidated implementation plan can share controls, but its legal inventory should retain each rulemaking identity.
Track 3: The Federal Reserve’s Regulation H Proposal
On July 7, the Federal Reserve issued its own proposal. The proposal text identifies Docket R-1835 and the September 8, 2026 comment deadline.
For a state member bank, this track requires a specific gap analysis against Regulation H. Do not tell an OCC-supervised national bank that the Fed deadline governs its agency proposal, and do not tell a state member bank that the April coordinated banking-agency document is its only rulemaking.
A useful charter-and-agency inventory includes:
- legal entity;
- charter;
- primary federal regulator;
- current AML/CFT program rule;
- relevant proposed rule and docket;
- proposal owner; and
- comment or implementation decision.
Be Careful With “Significant or Systemic Failure”
Proposal summaries have sometimes turned the phrase “significant or systemic failure” into a claim that minor or isolated deficiencies can no longer lead to supervisory criticism. That is too broad.
At least four distinctions must remain visible:
- Proposed versus current law. Proposed language does not suspend existing requirements.
- Formal enforcement versus supervision. A threshold for a particular action does not necessarily eliminate findings, recommendations, MRAs, ratings effects, monitoring, or other supervisory responses.
- Agency-specific text. FinCEN and each banking agency act under their own authorities and rules.
- Facts and accumulation. Repeated, connected, or poorly remediated deficiencies may present a different risk from one isolated documentation error.
The safe statement is that the proposals seek to focus programs and agency response on material, risk-based effectiveness. The unsafe statement is that lesser deficiencies no longer matter.
What to Do Before Any Final Rule
Keep the current program operative
Continue current customer due diligence, monitoring, reporting, training, independent testing, officer, governance, and recordkeeping obligations. Do not replace a current procedure with proposed text.
Build a proposal crosswalk
For each legal entity, compare current text with each applicable proposal. Classify items as current requirement, proposed requirement, existing practice, gap, or open interpretation.
Strengthen the risk-to-control trail
Document how products, customers, geographies, channels, transactions, and emerging typologies affect controls and resources. This is useful today even if final text changes.
Test outcomes without inventing universal metrics
Review alert quality, escalation, SAR decisions, issue recurrence, data quality, model changes, and independent-testing results. Label internal thresholds as institution-calibrated rather than regulator-prescribed.
Use the Fed comment window accurately
If the Federal Reserve proposal applies, decide whether to comment on scope, definitions, burden, transition, examination treatment, or coordination. Cite Docket R-1835 and September 8. Do not describe a comment submission as compliance with a final rule.
So What?
The common direction is toward risk-based, effective AML/CFT programs. The legal route is still fragmented across three proposals.
Build one control architecture where that is efficient, but keep three source records. Preserve current compliance, challenge overconfident interpretations of proposed enforcement language, and wait for final text before starting an implementation clock.
The AML/BSA Risk Assessment Template can structure the risk-to-control record. It must be adapted to the institution’s legal entity, regulator, products, data, and current rule.
Primary sources: FinCEN proposal announcement | FinCEN NPRM, FR Doc. 2026-07033 | OCC/FDIC/NCUA NPRM, FR Doc. 2026-06948 | Federal Reserve announcement | Federal Reserve proposal, Docket R-1835
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
How many AML/CFT program proposals were active in August 2026?
Are the new AML/CFT program requirements final?
When are comments due on the Federal Reserve proposal?
Does a proposed 'significant or systemic failure' standard eliminate lesser supervisory findings?
What preparation is safe before final rules?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Compliance Strategy
DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.
The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.
Sep 9, 2026
Compliance Strategy
FinCEN's Scam Center Alert: What BSA Officers Need to Do with FIN-2026-Alert005
FinCEN's September 3, 2026 alert identified nearly $13 billion in suspected illicit activity tied to overseas scam centers running pig butchering, romance baiting, and cryptocurrency confidence schemes. Here's what the red flags are, who needs to file SARs, and how to update your transaction monitoring program.
Sep 6, 2026
Compliance Strategy
H.R. 10184 Would Cut the Maximum CFPB Penalty to $50,120 Per Day and Move Supervision to $30 Billion. What the CFPB Reform Act Means for Your Compliance Program.
The Consumer Financial Protection Accountability and Reform Act of 2026, introduced August 31, proposes to raise the CFPB supervision threshold to $30B, slash maximum daily penalties, narrow the UDAAP 'abusive' standard, and subject the bureau to congressional appropriations. Here's what it means for your compliance program — and what to watch regardless of whether it passes.
Sep 5, 2026