Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

FinCEN's AML/CFT Overhaul Is the Biggest BSA Change in Decades. Here's What Your Compliance Program Needs Before the Final Rule.

FinCEN's April 2026 NPRM would fundamentally reform AML/CFT program requirements for every financial institution — and the Federal Reserve just issued its own separate proposal. Here's what the effectiveness mandate, risk assessment overhaul, and 'significant or systemic' enforcement standard mean for your compliance team.

By Rebecca Leung · July 15, 2026 ·
Table of Contents

TL;DR

  • FinCEN published a sweeping AML/CFT program NPRM on April 10, 2026 — described by regulators as the most significant overhaul of BSA program requirements in decades. Comments closed June 9.
  • The proposed rule formalizes risk assessment as a required program component, mandates event-triggered risk assessment updates, and requires the AML/CFT officer to be US-based and accessible to regulators.
  • A new “significant or systemic failure” enforcement standard would raise the bar for triggering AML/CFT enforcement actions — but neither FinCEN nor the Federal Reserve has defined what that phrase means.
  • On July 7, the Federal Reserve issued its own separate AML/CFT proposal — largely parallel but with one material difference: the Fed explicitly excluded FinCEN’s proposed gatekeeper role in enforcement decisions.

Two days ago, the Federal Reserve issued its own proposal to fundamentally reform AML/CFT program requirements for member banks. It largely follows the framework FinCEN and other banking agencies proposed in April — but with one deliberate omission that signals something about where regulatory authority over bank AML enforcement is headed.

That’s the context for reading both proposals together. They’re not redundant. They’re two regulators agreeing on the outcome but disagreeing on who controls enforcement.

If you’re a compliance officer, BSA officer, or risk manager at any regulated financial institution, this combination of proposals — one from FinCEN covering the full universe of regulated entities, one from the Fed covering state member banks — is the most consequential rulemaking for your AML program since the USA PATRIOT Act amendments that created the four-pillar framework in the first place.

Here’s what both proposals actually say, where they diverge, and what you should be doing before the final rule lands.

What FinCEN Actually Proposed

FinCEN published the NPRM (FR Doc. 2026-07033) in the Federal Register on April 10, 2026, jointly with the OCC, FDIC, NCUA, and other banking agencies. The comment period closed June 9, 2026.

The scope is broad. This isn’t a bank-only rule. It applies to banks, savings associations, credit unions, broker-dealers, mutual funds, insurance companies, futures commission merchants, introducing brokers in commodities, money services businesses, and casinos. If you’re regulated under the Bank Secrecy Act, this proposal touches your program.

The headline framing from FinCEN: a “fundamental reform” focused on shifting the AML/CFT compliance culture from checkbox documentation to demonstrated effectiveness.

The four traditional BSA program pillars survive: internal policies/procedures/controls, independent testing, a designated compliance officer, and training. But each pillar gets materially revised.

The Risk Assessment Change That Will Affect the Most Programs

The first pillar — internal policies, procedures, and controls — gets the most significant expansion. Under the proposed rule, a formal risk assessment process becomes an explicit required component of that pillar.

This matters more than it might sound. Most sophisticated financial institutions have maintained some form of AML/CFT risk assessment for years. But current program rules don’t uniformly require them. Some institutions — particularly smaller MSBs and community banks — have operated with thin or informal risk assessment documentation, relying on the implicit assumption that a well-designed program is inherently risk-based.

The proposed rule eliminates that assumption. Risk assessment becomes a documented, mandatory program element, subject to examination.

More significantly, the update trigger changes. Under the proposed rule, institutions must update their risk assessments “promptly upon any change that the financial institution knows or has reason to know significantly changes the institution’s ML/TF risks.”

That’s not a calendar requirement. It’s an event trigger. New product launch? Reassess. New geographic footprint? Reassess. Material change in customer mix? Reassess. Acquisition? Reassess.

For institutions running purely annual risk assessment cycles on a fixed schedule, the operational shift required here is real. You need a defined protocol for identifying triggering events and launching timely risk assessment updates — not just an annual date in the compliance calendar.

The Compliance Officer Requirement: US-Based and Accessible

The proposed rule introduces a new geographic requirement for the AML/CFT Officer: they must be located in the United States and accessible to FinCEN and the appropriate federal regulators.

For US-headquartered institutions with domestic compliance teams, this is a non-issue. For global institutions with AML/CFT functions that have migrated offshore or operate through international shared services centers, it requires attention.

The rule does allow other personnel involved in AML/CFT functions to reside outside the United States. The geographic restriction applies specifically to the designated Officer — the accountable individual regulators will look to for program ownership.

The board approval requirement also gets clarified: the AML/CFT program must be approved by the board of directors, an equivalent governing body, or appropriate senior management. This harmonizes existing approval requirements while allowing flexibility for institutions without traditional board structures.

The Federal Reserve’s Parallel Proposal — and the Key Difference

On July 7, 2026, the Federal Reserve Board requested comment on its own AML/CFT program reform proposal. The comment period closes September 8, 2026.

The Fed’s proposal covers Board-supervised banks — state member banks and bank holding companies. It adopts the same risk-based effectiveness framework: the same four pillars, the same event-triggered risk assessment update requirement, the same “significant or systemic failure” enforcement standard.

But there’s one deliberate omission that compliance and legal teams should note.

The April FinCEN/banking agency NPRM included a provision establishing FinCEN as a gatekeeper for major AML enforcement and significant supervisory actions — a notice-and-consultation framework under which FinCEN would be involved before a banking agency could take major AML/CFT enforcement action. The idea was to centralize AML enforcement accountability with the agency that owns the BSA.

The Federal Reserve declined to include that provision.

This is not an oversight. WilmerHale’s analysis of the Fed’s proposal notes that the Board “made clear that it is taking an independent path by specifically not including a significant provision of the April rulemaking that would see FinCEN as the gatekeeper of AML/CFT enforcement actions or of significant AML/CFT supervisory actions.” The Fed is preserving its own supervisory authority over member bank AML programs.

For state member banks, this divergence matters for exam dynamics. If the final FinCEN rule includes the gatekeeper provision but the Fed’s final rule excludes it, Fed-supervised institutions will have a different enforcement process than OCC-supervised or FDIC-supervised peers.

The “Significant or Systemic Failure” Standard: What It Changes — and What It Doesn’t Define

Both proposals establish a new enforcement threshold: only “significant or systemic failures” to maintain an AML/CFT program would warrant enforcement action or significant supervisory action.

This is a meaningful departure from the current examination environment, where minor technical deficiencies — inadequate documentation, slightly stale training records, narrow gaps in independent testing coverage — can produce Matters Requiring Attention (MRAs) or informal enforcement.

The intent is clear: regulators should focus on program failures that meaningfully impair the institution’s ability to detect and report money laundering and terrorist financing, not administrative compliance with paperwork requirements.

But neither proposal defines “significant or systemic.” WilmerHale’s Federal Reserve analysis flags this as a gap — “the absence of a definition of the ‘significant or systemic’ standard for issuing matters requiring attention and enforcement actions may shape how examiners and enforcement staff apply the new framework.”

Until the definition is settled in a final rule or subsequent examination guidance, exam teams retain meaningful discretion. Don’t interpret “significant or systemic” as a blanket reduction in AML examination scrutiny — read it as a signal that programs need to demonstrate they actually work, not just that they exist.

What Needs to Change in Your AML Program Before the Final Rule

The final rule isn’t here yet — but pre-compliance work now is the right move. AML/CFT program changes take time to design, socialize with the board, train staff on, and embed in operational workflows. Institutions that wait for a final rule to start will be scrambling through a 12-month implementation period.

The areas that need attention now:

Risk assessment documentation: If your risk assessment is a static annual document that lives in a shared folder and gets updated on a fixed calendar cycle, build event-triggered review protocols into your risk assessment methodology before the final rule arrives. Document what constitutes a triggering event, who owns the assessment update, and what the target timeframe for completion is.

Program effectiveness metrics: The emphasis on effectiveness over documentation means your independent testing and management reporting need to answer a harder question than “did we run the controls?” The question becomes “did the controls find what they were supposed to find?” Build outcome metrics into your program: SAR quality, transaction monitoring alert-to-report conversion rates, training completion against risk-weighted job families.

Officer designation review: If your designated BSA/AML Officer is located outside the United States, that designation needs to change before the final rule takes effect. If offshore personnel perform AML/CFT functions, document which functions remain domestic (specifically the Officer role) and which can lawfully operate internationally.

Board approval documentation: Confirm your AML/CFT program has documented board or senior management approval. If the approval is implicit or embedded in a broader governance document that doesn’t clearly attribute AML/CFT program sign-off, update it.

Independent testing scope: Review whether your current independent testing scope covers program effectiveness or just control existence. If your AML audit function tests whether controls are documented and operated but doesn’t assess whether the program is generating quality SARs and identifying risk, the scope needs expanding.

When to Expect the Final Rule

The comment period for FinCEN’s proposal closed June 9, 2026. The Federal Reserve comment period closes September 8, 2026. FinCEN proposed a 12-month implementation period following issuance of a final rule. Based on the regulatory timeline, the most plausible scenario is a final FinCEN rule in late 2026 or Q1 2027, with implementation required in 2027-2028.

The Federal Reserve is on a slower comment timeline and may finalize separately from FinCEN’s coordinated rule. Whether the two agencies produce a single harmonized framework or parallel rules with material differences — particularly around the FinCEN enforcement gatekeeper provision — will be one of the most consequential compliance architecture questions of the next 18 months.

On the FinCEN 314(b) side, voluntary information sharing between financial institutions remains one of the most underutilized tools in AML program design — and it’s untouched by either proposal. For institutions looking to demonstrate program effectiveness, 314(b) program utilization is an area where improvement is relatively low-cost and examiner-visible.

For institutions already managing heightened standards compliance under OCC’s framework, the OCC’s heightened standards governance requirements for banks crossing the $700B threshold provide a useful model for what “board-level program approval” and “senior management accountability” look like when regulators scrutinize them closely.

So What?

The AML/CFT overhaul isn’t a rewrite of what’s required — it’s a formalization of what should already be happening. A risk assessment that’s documented, event-triggered, and board-approved. An officer who’s in-country and reachable. Independent testing that asks whether the program works, not just whether it exists.

Most institutions with mature BSA programs will find they’re closer than they think. The gap is usually in documentation and process formality — not in the underlying risk management activity.

But “closer than you think” isn’t “ready.” The 12-month implementation clock starts from the final rule date, not from today. And the Federal Reserve’s parallel proposal means state member banks may be living under a slightly different framework than their OCC-supervised peers.

Start the gap assessment now. The comment period is closed — it’s too late to shape the rule. The work is in being ready when the final rule arrives.


Sources: FinCEN NPRM, Federal Register April 10, 2026 | FinCEN Program NPRM Fact Sheet | WilmerHale: Federal Reserve AML/CFT Proposal, July 14, 2026 | National Law Review: Federal Reserve Risk-Based AML Proposal | Greenberg Traurig: FinCEN AML/CFT Reform Analysis | Sullivan & Cromwell: FinCEN and Banking Agencies AML Reform

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does FinCEN's 2026 NPRM actually change about AML/CFT programs?
The most significant changes are three: risk assessment is now a formal required element of the first pillar (not assumed), the AML/CFT officer must be US-based and accessible to regulators, and the program must demonstrate effectiveness — not just existence. The 'significant or systemic' enforcement standard signals that minor technical failures won't automatically trigger enforcement, but the program must genuinely function. The rule applies to banks, MSBs, broker-dealers, insurance companies, futures commission merchants, mutual funds, and casinos.
How does the Federal Reserve's July 2026 proposal differ from FinCEN's approach?
The Fed's proposal takes the same risk-based effectiveness framework but explicitly excluded a key provision: FinCEN's gatekeeper role in enforcement actions. Under FinCEN's framework, major AML enforcement or supervisory actions would require FinCEN notification and consultation. The Federal Reserve declined to include that provision, maintaining its own independent supervisory authority over member banks. The Fed's comment period closes September 8, 2026.
What does 'significant or systemic failure' mean as an enforcement standard?
The proposed rule would require 'significant or systemic failures' to maintain a program before FinCEN or banking agencies could take enforcement action — a meaningful departure from the current environment where minor technical deficiencies can produce MRAs. Neither FinCEN nor the Federal Reserve has defined 'significant or systemic' specifically, which leaves examiner discretion intact and creates uncertainty about where exactly the line sits.
Does the NPRM change how often I need to update my AML/CFT risk assessment?
Yes. Under the proposed rule, institutions must update their risk assessments 'promptly upon any change that the financial institution knows or has reason to know significantly changes the institution's ML/TF risks.' This isn't a fixed annual cycle — it's event-triggered. New products, new geographies, new customer segments, and acquisitions all trigger reassessment obligations. Institutions running purely calendar-based annual reviews need to add event-triggered update protocols.
When will the final rule take effect?
FinCEN proposed a 12-month implementation period following issuance of a final rule. The comment period closed June 9, 2026. No final rule has been issued. Assuming a final rule publishes in late 2026 or early 2027, implementation would be in 2027-2028. The Federal Reserve's comment deadline is September 8, 2026. Start pre-compliance work now — risk assessment methodology, officer designation, and program documentation realignment take months.
Does my existing AML program already satisfy the new requirements?
Probably partially. If you have a formal written risk assessment updated on event-triggered and periodic schedules, a US-based compliance officer, independent testing by internal audit or an external firm, and documented training records, you're close. The main gaps for most institutions will be: formalizing risk assessment as a program component with documented trigger-based update protocols, demonstrating program effectiveness through outcomes metrics, and ensuring independent testing scope covers effectiveness — not just existence of controls.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Operational Risk Program

Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.