Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Compliance Strategy

AML/CFT Program Reform in 2026: Three Proposals, Three Rulemaking Tracks

FinCEN, OCC/FDIC/NCUA, and the Federal Reserve have distinct AML/CFT proposals. None was final as of August 17, 2026.

By Rebecca Leung · July 16, 2026 ·
Table of Contents

TL;DR

  • FinCEN issued an AML/CFT program NPRM in April 2026.
  • OCC, FDIC, and NCUA issued a coordinated but separate April proposal for their supervised institutions.
  • The Federal Reserve issued a separate Regulation H proposal on July 7, 2026; comments are due September 8 under Docket R-1835.
  • None of those proposals was final as of August 17. Do not use proposed enforcement language to dismiss lesser deficiencies or current supervisory risk.

August 17, 2026 Status Update

The 2026 AML/CFT reform effort is not one document. It is a set of parallel rulemakings that share policy themes but differ in issuer, authority, coverage, and docket.

RulemakingIssuerOfficial artifactStatus on August 17, 2026
AML/CFT program proposalFinCENFR Doc. 2026-07033Proposed; April comment period closed
Coordinated banking-agency proposalOCC, FDIC, NCUAFR Doc. 2026-06948Proposed; separate agency rule text
Regulation H proposalFederal ReserveDocket R-1835Proposed; comments due September 8, 2026

The FinCEN announcement calls its action a proposal. The Federal Reserve announcement does the same. No final-rule implementation clock should appear in policy until an agency publishes final action.

Track 1: FinCEN’s April NPRM

FinCEN’s Federal Register NPRM proposes changes to AML/CFT program requirements across categories of financial institutions subject to FinCEN rules.

The proposal emphasizes a risk-based and effective program, formal risk-assessment processes, governance, priorities, and allocation of resources. Exact duties vary by institution type and final text. A bank, money services business, broker-dealer, insurer, mutual fund, or casino should not assume every provision applies identically.

Track 2: The OCC/FDIC/NCUA Proposal

OCC, FDIC, and NCUA published a coordinated proposal alongside FinCEN’s work. It would amend the agencies’ own program rules for institutions they supervise.

“Coordinated” does not mean the documents are interchangeable. Maintain separate citations and map:

  • agency and supervised population;
  • CFR provisions;
  • definitions;
  • examination and supervisory language;
  • comment record; and
  • any final action.

A consolidated implementation plan can share controls, but its legal inventory should retain each rulemaking identity.

Track 3: The Federal Reserve’s Regulation H Proposal

On July 7, the Federal Reserve issued its own proposal. The proposal text identifies Docket R-1835 and the September 8, 2026 comment deadline.

For a state member bank, this track requires a specific gap analysis against Regulation H. Do not tell an OCC-supervised national bank that the Fed deadline governs its agency proposal, and do not tell a state member bank that the April coordinated banking-agency document is its only rulemaking.

A useful charter-and-agency inventory includes:

  • legal entity;
  • charter;
  • primary federal regulator;
  • current AML/CFT program rule;
  • relevant proposed rule and docket;
  • proposal owner; and
  • comment or implementation decision.

Be Careful With “Significant or Systemic Failure”

Proposal summaries have sometimes turned the phrase “significant or systemic failure” into a claim that minor or isolated deficiencies can no longer lead to supervisory criticism. That is too broad.

At least four distinctions must remain visible:

  1. Proposed versus current law. Proposed language does not suspend existing requirements.
  2. Formal enforcement versus supervision. A threshold for a particular action does not necessarily eliminate findings, recommendations, MRAs, ratings effects, monitoring, or other supervisory responses.
  3. Agency-specific text. FinCEN and each banking agency act under their own authorities and rules.
  4. Facts and accumulation. Repeated, connected, or poorly remediated deficiencies may present a different risk from one isolated documentation error.

The safe statement is that the proposals seek to focus programs and agency response on material, risk-based effectiveness. The unsafe statement is that lesser deficiencies no longer matter.

What to Do Before Any Final Rule

Keep the current program operative

Continue current customer due diligence, monitoring, reporting, training, independent testing, officer, governance, and recordkeeping obligations. Do not replace a current procedure with proposed text.

Build a proposal crosswalk

For each legal entity, compare current text with each applicable proposal. Classify items as current requirement, proposed requirement, existing practice, gap, or open interpretation.

Strengthen the risk-to-control trail

Document how products, customers, geographies, channels, transactions, and emerging typologies affect controls and resources. This is useful today even if final text changes.

Test outcomes without inventing universal metrics

Review alert quality, escalation, SAR decisions, issue recurrence, data quality, model changes, and independent-testing results. Label internal thresholds as institution-calibrated rather than regulator-prescribed.

Use the Fed comment window accurately

If the Federal Reserve proposal applies, decide whether to comment on scope, definitions, burden, transition, examination treatment, or coordination. Cite Docket R-1835 and September 8. Do not describe a comment submission as compliance with a final rule.

So What?

The common direction is toward risk-based, effective AML/CFT programs. The legal route is still fragmented across three proposals.

Build one control architecture where that is efficient, but keep three source records. Preserve current compliance, challenge overconfident interpretations of proposed enforcement language, and wait for final text before starting an implementation clock.

The AML/BSA Risk Assessment Template can structure the risk-to-control record. It must be adapted to the institution’s legal entity, regulator, products, data, and current rule.


Primary sources: FinCEN proposal announcement | FinCEN NPRM, FR Doc. 2026-07033 | OCC/FDIC/NCUA NPRM, FR Doc. 2026-06948 | Federal Reserve announcement | Federal Reserve proposal, Docket R-1835

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

How many AML/CFT program proposals were active in August 2026?
Three related but legally distinct tracks matter: FinCEN's April 2026 program NPRM; the coordinated April proposal from OCC, FDIC, and NCUA for their supervised institutions; and the Federal Reserve's July Regulation H proposal. They should not be described as one joint final rule.
Are the new AML/CFT program requirements final?
No. As of August 17, 2026, all three actions remained proposals. Continue meeting current BSA/AML requirements while treating proposal-based work as change readiness.
When are comments due on the Federal Reserve proposal?
The Federal Reserve's July 7, 2026 proposal identifies Docket R-1835 and a September 8, 2026 comment deadline. That deadline applies to the Fed's proposal, not retroactively to the April FinCEN or OCC/FDIC/NCUA dockets.
Does a proposed 'significant or systemic failure' standard eliminate lesser supervisory findings?
No categorical conclusion is supported. Proposed language about significant or systemic failures must be read in the context of the particular agency text. It does not justify ignoring deficiencies, assuming MRAs are barred, or treating current enforcement and supervisory authority as suspended.
What preparation is safe before final rules?
Maintain a current risk assessment, trace controls and resources to material risks, test program outcomes, document governance, and compare each proposal with the current rule that applies to the institution. Label proposal gaps and target dates as provisional.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

◆ Keep reading

Related posts.

Compliance Strategy

DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.

The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.

Sep 9, 2026

Compliance Strategy

FinCEN's Scam Center Alert: What BSA Officers Need to Do with FIN-2026-Alert005

FinCEN's September 3, 2026 alert identified nearly $13 billion in suspected illicit activity tied to overseas scam centers running pig butchering, romance baiting, and cryptocurrency confidence schemes. Here's what the red flags are, who needs to file SARs, and how to update your transaction monitoring program.

Sep 6, 2026

Compliance Strategy

H.R. 10184 Would Cut the Maximum CFPB Penalty to $50,120 Per Day and Move Supervision to $30 Billion. What the CFPB Reform Act Means for Your Compliance Program.

The Consumer Financial Protection Accountability and Reform Act of 2026, introduced August 31, proposes to raise the CFPB supervision threshold to $30B, slash maximum daily penalties, narrow the UDAAP 'abusive' standard, and subject the bureau to congressional appropriations. Here's what it means for your compliance program — and what to watch regardless of whether it passes.

Sep 5, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.