Skip to content
RiskTemplates · The Daily Brief Friday, August 7, 2026
Wire SEC’s New Financial Reporting and Accounting Unit: The ICFR Review to Start Now AUG 5

Feature Operational Risk

AML's Board Accountability Moment: What the 2026 Examination Standard Expects Beyond Transaction Monitoring

FinCEN's April 2026 NPRM proposes formal board oversight as a required AML program component. OCC's revised exam procedures took effect February 2026. TD Bank's $3B penalty set the precedent. Here's what examiners now look for at the board level.

By Rebecca Leung · August 5, 2026 ·
Table of Contents

TL;DR

  • FinCEN’s April 2026 NPRM would formally add board oversight as a required component of all AML/CFT programs, with board approval of the risk assessment built in.
  • TD Bank’s $3.09 billion penalty (Oct 2024) — the largest BSA enforcement action in US history — explicitly named inadequate board oversight as a root cause. TD responded by creating a dedicated board-level AML committee.
  • OCC Bulletin 2025-37a, effective February 2026, updated community bank examination procedures: well-documented programs get streamlined review; programs with weak governance documentation get the same scrutiny as before.
  • UBS’s $125M FinCEN penalty (Aug 2026) reinforced the pattern: monitoring failures went unescalated to the regulator for years despite a prior consent order.
  • Examiners now look for documented board approval of the risk assessment, substantive minutes, an independent BSA reporting line, and evidence the board engaged with MLRO reporting — not just received it.

For most of the past decade, the AML examination question was about the transaction monitoring system. Did it exist? Was it tuned? Were the alert volumes reasonable? Did SARs file within required timeframes?

That question hasn’t disappeared. But a second question has moved up the stack — one that goes directly to your board: does the board understand your AML program, and do you have the documentation to prove it?

This shift has been building since TD Bank’s $3 billion settlement in October 2024. FinCEN’s April 2026 proposed rule codifies it. And the UBS penalty from three days ago puts fresh evidence in front of every compliance officer about what happens when program failures don’t get escalated.

Why TD Bank reset the standard

TD Bank’s October 2024 guilty plea — entered across the DOJ, FinCEN, OCC, and Federal Reserve, totaling $3.09 billion in combined penalties — is the event that redefined board-level AML expectations for the current examination cycle.

The DOJ’s findings were specific about the board dimension: TD Bank prioritized growth over controls, and the compliance architecture couldn’t hold against business line pressure. The board received AML reporting, but not in a way that positioned them to identify or challenge the systemic gaps. After the settlement, TD Bank established a dedicated committee at its US boards specifically for AML/BSA oversight — a structural change that acknowledged the prior governance arrangement was inadequate.

Regulators have referenced this case consistently since then. When examiners assess board oversight in an AML context, TD Bank is the implicit benchmark: what did that board know, when did they know it, and what did they do about it? The expectation isn’t that every board acts as an AML review committee. The expectation is that the board received substantive information and engaged with it substantively.

What FinCEN’s April 2026 NPRM adds

FinCEN published a proposed rule in April 2026 that would fundamentally rewrite the structure of AML/CFT program requirements for covered financial institutions. The proposal withdraws and supersedes a prior July 2024 NPRM.

On board oversight, the April 2026 NPRM would require all covered institutions’ AML/CFT programs to be subject to formal board oversight and approval. The proposed rule also integrates the risk assessment into the internal controls requirement rather than treating it as a standalone sixth pillar — which means the board-approved document you’re building is the risk assessment itself, not a summary of it.

The rule proposes a 12-month implementation period following finalization. It has not yet been finalized as of this writing. But the direction is unambiguous: the board’s role in AML is moving from passive recipient of reporting to documented approver of program design. FinCEN’s fact sheet is the primary source if you’re tracking the rulemaking.

What OCC examiners look for in 2026

OCC Bulletin 2025-37a, effective February 1, 2026, revised the community bank BSA/AML examination procedures. The stated goal was reducing unnecessary regulatory burden on banks with well-functioning programs while preserving risk-based scrutiny where deficiencies exist.

The practical effect: examiners now have more discretion to rely on satisfactory independent testing and to tailor examination scope to a bank’s risk profile. For banks with clean programs, this means a more efficient exam. For banks whose programs have documentation gaps — including gaps in board-level governance — the scrutiny is the same as before the revision.

What the updated procedures do not change: the expectation that the board understands and oversees the AML program. The Wolters Kluwer BSA/AML 2025–2026 analysis summarizes the shift as moving from “do you have an AML program” to “can you demonstrate it is effectively working, with governance that reaches the board level.”

At the board level, OCC examiners have consistently flagged four specific gaps:

Gap 1: The risk assessment was presented, not approved. There’s a meaningful difference between the BSA officer presenting the annual risk assessment to the board and the board formally approving it. If your board minutes show the presentation but not a documented approval vote or resolution, that’s a gap examiners flag.

Gap 2: Minutes don’t show engagement. Board minutes that say “BSA officer presented annual report; no questions” create an exam problem. Examiners look for evidence that the board engaged: questions documented, concerns raised, action items assigned. Minutes that show a report was received but not discussed suggest the board is not functioning as an oversight body for AML purposes.

Gap 3: The BSA officer reports through business lines. When the person responsible for AML compliance reports upward through a business line manager rather than to the board or audit committee, examiners identify a structural independence problem. Commercial pressure can displace compliance judgment when the reporting line creates a conflict of interest.

Gap 4: The board has no documented AML risk appetite. The board is expected to set the institution’s risk tolerance — including for AML risk. If there is no documented position on which customer types, geographies, or product categories the institution will and won’t serve based on BSA risk, the board’s role in program governance is incomplete.

The UBS case as a governance failure, not just a monitoring failure

The UBS $125 million FinCEN penalty from August 3, 2026 is the most recent illustration of what happens when escalation doesn’t reach regulators.

FinCEN’s findings described a two-phase failure. From 2019 to 2021, UBS’s legacy monitoring system excluded certain FX wire transactions from surveillance due to a booking anomaly. From 2021 to 2023, the new monitoring system — itself implemented more than 18 months behind UBS’s own schedule — had data-transmission problems that left thousands of transactions unsurveilled.

The outcome of the new settlement was largely driven by FinCEN being kept in the dark. The gaps were discovered during a subsequent examination, not disclosed proactively. UBS had entered a prior consent order with FinCEN, the SEC, and FINRA promising to fix the exact problem that persisted for years afterward.

This is a board-level governance failure as much as a monitoring failure. The question FinCEN would ask in any follow-on governance review: how did the board know the remediation committed to under the prior consent order was actually complete? What did the board see, and when?

What board-level AML oversight actually looks like in practice

Translating the examination standard into something operational:

Annual risk assessment approval. Once a year, the board or its risk/audit committee formally reviews and approves the institution’s BSA/AML risk assessment. The approval is documented with a board resolution or a documented vote in the minutes. The risk assessment covers the four FFIEC categories — products and services, customer types, geographies, delivery channels — with the inherent risk and control strength matrix that supports the residual risk conclusion.

MLRO/BSA officer annual report with documented engagement. The BSA officer presents an annual summary covering SAR filing volumes, alert volumes and disposition, transaction monitoring coverage (including any known gaps), audit findings, open regulatory findings, training completion, and any significant suspicious activity patterns. The board minutes document what was reviewed, what questions were asked, and what actions were assigned.

Independent reporting line. The BSA officer or MLRO has a direct path to the board or audit committee that does not run through business line leadership. This doesn’t require a separate chain of command for everything — it means that when the BSA officer has a concern that business line pressure is affecting compliance judgment, they have a documented route to the board that bypasses the conflict.

Documented risk appetite for high-risk categories. The board has explicitly reviewed and approved the institution’s approach to high-risk customer types (MSBs, PEPs, marijuana-related businesses, offshore shell companies), high-risk geographies, and high-risk products. This doesn’t mean the institution must exit all high-risk relationships — it means the board has documented that it understands the risk and has set a boundary.

The FinCEN student aid fraud alert from July 2026 is a useful example of the kind of emerging typology that should reach the board as part of the MLRO annual report — not because every alert type needs board attention, but because significant emerging typologies represent program-level decisions about monitoring coverage that require board awareness.

The documentation burden is real, but it’s finite

None of the above requires a large compliance team or a GRC platform. What it requires is discipline:

  • A written BSA/AML risk assessment, updated annually, submitted to the board for formal approval
  • Board minutes that reflect engagement with AML reporting
  • A documented escalation path from the BSA officer to the board
  • A written risk appetite statement that covers AML risk categories

For fintechs and smaller financial institutions, the BSA/AML risk assessment is almost always the first document an examiner requests — and the first document a bank partner asks for during onboarding and annual review. It’s not a theoretical governance artifact. It’s the operational record that determines whether your program is examined as well-governed or examined as a concern.

The AML/BSA Risk Assessment Template (Fintech Edition) provides the complete assessment in the FFIEC examination manual structure — four risk categories, inherent-to-residual scoring, a 30-control inventory mapped to the five BSA pillars, and a Board Summary Dashboard. It’s pre-populated with 32 fintech-specific risk factors so you’re editing a credible draft rather than starting from a blank page.

So what?

If your BSA/AML program has the monitoring system, the SAR workflow, and the training calendar — but the board’s involvement is passive or undocumented — you have a gap that FinCEN’s proposed rule will eventually formalize and that examiners are already flagging under current guidance.

The cases from 2024 and 2026 tell a consistent story: the transaction monitoring gap is almost never the only finding. Behind it is a governance failure — someone who should have known, didn’t. Someone who should have escalated, didn’t. A board that should have pushed for answers, didn’t.

The monitoring system is table stakes. The governance around it is where the next examination cycle is focused.

Check your BSA/AML KRIs for board-reportable metrics before your next exam cycle starts. If your board hasn’t seen the SAR filing rate, the alert false-positive rate, or the open regulatory findings in the past year — that’s the gap to close first.

FAQ

What does FinCEN’s April 2026 AML NPRM require of boards?

FinCEN’s April 2026 proposed rule would formally require all covered institutions’ AML/CFT programs to be subject to board oversight and approval. The proposed rule integrates risk assessment as part of the internal controls requirement, meaning boards would need to approve the risk assessment rather than just receive a summary. The rule proposes a 12-month implementation period after finalization.

What did TD Bank’s AML settlement mean for board accountability standards?

TD Bank’s October 2024 $3.09 billion settlement — the largest BSA enforcement action in US history — explicitly cited inadequate board oversight as a root cause. The bank prioritized growth over controls, and the compliance architecture could not hold against business line pressure. As a direct result, TD Bank created a dedicated US board committee for AML/BSA oversight. Regulators now reference this case when defining adequate board engagement.

What changed in the OCC’s BSA/AML examination procedures?

OCC Bulletin 2025-37a, effective February 1, 2026, revised community bank BSA/AML examination procedures to streamline oversight for well-documented programs while preserving scrutiny for programs with deficiencies. Banks with documented risk-based AML governance benefit from more efficient examinations; banks with weak documentation face the same level of scrutiny as before the change.

What do AML examiners look for at the board level?

Four things: (1) documented board approval of the AML risk assessment, not just a presentation; (2) board meeting minutes reflecting substantive discussion of AML risks; (3) an independent reporting line from the BSA officer to the board, separate from business line management; and (4) evidence that the board set and reviewed risk appetite for high-risk AML categories.

What is the MLRO annual report and why do examiners review it?

The BSA officer or MLRO annual report summarizes the year’s AML program performance for the board: risk assessment status, SAR volumes, monitoring coverage, audit findings, open regulatory findings, and significant suspicious activity patterns. Examiners assess whether the board engaged substantively — not just whether the report was presented. A board that received the report without questions or follow-up creates an exam risk.

How should a fintech without a dedicated MLRO handle board-level AML accountability?

The title isn’t required — the substance is. The designated BSA compliance officer must have a direct reporting line to the board or equivalent. At minimum, the board should annually: (1) approve the AML risk assessment, (2) review SAR filing activity and monitoring coverage, and (3) review any open exam findings. Document all three. If your board has never seen your BSA risk assessment, that’s the gap examiners will find first.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does FinCEN's April 2026 AML NPRM require of boards?
FinCEN's April 2026 proposed rule on AML/CFT program requirements would formally require all covered institutions' AML/CFT programs to be subject to board oversight and approval. The proposed rule also integrates risk assessment as part of the internal controls requirement — meaning the board would need to approve the institution's risk assessment, not just receive a summary. The rule proposes a 12-month implementation period after finalization.
What did TD Bank's AML settlement mean for board accountability standards?
TD Bank's October 2024 guilty plea and $3.09 billion settlement — the largest BSA enforcement action in US history — explicitly cited inadequate board oversight as a contributing factor. The DOJ found the bank prioritized growth over controls, with a compliance architecture that could not hold against business line pressure. As a direct result, TD Bank established a dedicated committee at its US boards for AML/BSA oversight. Regulators now reference this case when setting expectations for what adequate board engagement looks like.
What changed in the OCC's BSA/AML community bank examination procedures?
OCC Bulletin 2025-37a, effective February 1, 2026, revised community bank BSA/AML examination procedures to streamline oversight while preserving risk-based scrutiny. The revised procedures give examiners more discretion to rely on satisfactory independent testing and tailor examination scope to risk profile. However, banks with documented, risk-based programs benefit from the streamlining; banks with weak documentation face the same level of scrutiny as before the change.
What do AML examiners look for when they review board-level governance?
Examiners look for four things: (1) documented evidence that the board approved the institution's BSA/AML risk assessment — not just received a presentation, but formally approved it; (2) board meeting minutes that reflect substantive discussion of AML risks, not just a compliance officer's report; (3) an independent reporting line from the BSA officer to the board or audit committee, separate from business line management; and (4) evidence that the board set and reviewed risk appetite for AML, including how the institution handles high-risk customer types and geographies.
What is the MLRO annual report and why do examiners review it?
The MLRO (Money Laundering Reporting Officer) or BSA officer annual report is a document presented to the board summarizing the year's AML program performance: risk assessment status, SAR filing volumes, training completion, audit findings, open issues, and significant suspicious activity patterns. Examiners assess whether the board engaged with the report in a way that demonstrates they understood the program's condition — not just whether the report was presented. A board that received the report and moved on without questions or follow-up action creates an exam risk.
How should a small fintech without a dedicated MLRO handle board-level AML accountability?
The function doesn't require a dedicated title, but the substance does. Someone at the institution must be the designated BSA compliance officer, and that person should have a direct reporting line to the board or its equivalent. At minimum, the board or senior leadership should annually: (1) approve the institution's AML risk assessment, (2) review a written summary of SAR filing activity and transaction monitoring coverage, and (3) review any open exam findings or regulatory inquiries. Document all three. If your board has never seen your BSA risk assessment, that's the gap.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.