Feature Regulatory Compliance
FinCEN’s Banque Misr UAE Section 311 Rule: What U.S. Banks Need to Build Now
FinCEN’s Banque Misr UAE Section 311 proposal would require screening, correspondent notices, and documented controls at U.S. financial institutions.
Table of Contents
TL;DR
- On August 28, 2026, FinCEN proposed using section 311 special measure five to cut Banque Misr’s five UAE branches off from U.S. correspondent banking.
- FinCEN says it identified about $1.8 billion in potential Iranian shadow-banking activity through 103 companies between January 2024 and June 2026. That is FinCEN’s assessment, not an adjudicated penalty.
- If finalized, the rule would reach beyond direct accounts: covered U.S. institutions would need risk-based procedures to stop foreign correspondent accounts from processing transactions involving Banque Misr UAE.
- BSA officers should open a readiness issue now covering entity scoping, payment-message testing, correspondent notices, escalation, and evidence retention.
FinCEN’s Banque Misr UAE Section 311 rule is a correspondent-banking control test disguised as a one-bank prohibition.
The August 28 FinCEN release says the agency has proposed finding Banque Misr’s five UAE branches to be a financial institution of “primary money laundering concern.” FinCEN wants to impose the fifth—and strongest—special measure available under section 311 of the USA PATRIOT Act: prohibit U.S. correspondent access rather than collect more information about the activity.
The proposal is not final, and it does not impose a fine. But waiting for a final rule would be a poor operating choice for institutions with foreign correspondent accounts. The notice of proposed rulemaking already identifies the entity scope, covered institutions, expected screening behavior, notification language, and evidence obligation. Compliance teams have enough detail to test whether their systems could execute the rule.
What FinCEN alleges about Banque Misr UAE
Banque Misr UAE consists of five branches of Egypt’s state-owned Banque Misr: two in Dubai—Deira and Business Bay—and one each in Abu Dhabi, Sharjah, and Ras Al Khaimah. The proposal expressly excludes Banque Misr’s Egypt operations and its branches elsewhere. That distinction matters. A blunt global block on the parent name could reject legitimate activity outside the rule’s intended scope.
FinCEN says it analyzed public and non-public information and identified 103 potential Iranian shadow-banking front companies that transacted approximately $1.8 billion through Banque Misr UAE from January 2024 through June 2026. The NPRM says approximately $520 million occurred in the most recent 12-month period it analyzed.
The agency named several examples:
| Entity named in the NPRM | FinCEN’s description | Activity FinCEN says Banque Misr UAE processed |
|---|---|---|
| Alpa Trading FZCO | UAE company designated by OFAC in September 2025 for supporting an Iranian financial facilitator | More than $32 million in 2024–2025 |
| Naba Alzaki Raw Materials Trading LLC | UAE company designated by OFAC in July 2026 for operating in Iran’s financial sector | More than $29 million from March–July 2025 |
| Midas Oil Trading DMCC | UAE entity described in the NPRM as linked through reporting to money laundering for Iran’s supreme leader | One transaction exceeding $1 million in January 2025 |
These are FinCEN’s findings and assessments in a proposed rule, not a court judgment. The distinction belongs in board papers, customer decisions, and public statements.
The broader Treasury release says Banque Misr UAE has approximately $6 billion in assets and three direct U.S. correspondent relationships. Treasury also announced related OFAC designations under “Operation Economic Outcast.” Do not collapse those actions into one list update: the Section 311 proposal targets Banque Misr UAE, while the same-day OFAC designations concern other named persons and entities under separate authorities.
What the Banque Misr UAE Section 311 proposal would require
Section 311, codified at 31 U.S.C. § 5318A, gives Treasury five escalating special measures. Measures one through four can add recordkeeping, beneficial-ownership, and reporting obligations. Special measure five can prohibit or condition correspondent and payable-through accounts.
FinCEN says more information would not solve this problem. The NPRM explains that front companies can obscure the true originator or beneficial owner even when institutions collect additional fields. FinCEN therefore concluded that nothing short of a correspondent prohibition would adequately address the risk.
The proposed rule would create four concrete obligations:
| Proposed obligation | What it means operationally | Primary owner | Evidence to retain |
|---|---|---|---|
| No direct correspondent account | Do not open or maintain a U.S. correspondent account for or on behalf of Banque Misr UAE | Correspondent Banking + Legal | Customer/account search, disposition, approval record |
| Stop indirect access | Take reasonable steps not to process transactions through another foreign bank’s U.S. correspondent account when the transaction involves Banque Misr UAE | BSA/AML + Payments Operations | Alert logic, test cases, blocked/rejected transaction records |
| Apply special due diligence | Use risk-based procedures across foreign correspondent accounts to identify prohibited use | BSA Officer + Financial Crime Technology | Requirements document, model/rule configuration, validation results |
| Notify relevant correspondents | Notify a foreign correspondent when the institution knows or has reason to believe it provides services to Banque Misr UAE | Correspondent Relationship Manager + Legal | Final notice, delivery proof, recipient, date, follow-up disposition |
Covered financial institutions would generally include banks, broker-dealers, futures commission merchants, introducing brokers in commodities, and mutual funds. The proposal cross-references 31 CFR 1010.605(e)(1), so the scope is broader than insured depository institutions.
There is no new standalone report in the proposal. Existing suspicious-activity and sanctions obligations still apply, while the new Section 311 requirement would specifically require documentation of correspondent notification compliance.
The hard part is indirect access, not the name-list update
FinCEN says an institution could use existing sanctions-screening and AML-monitoring tools. That does not mean adding “Banque Misr” to a watchlist completes the work.
The proposed rule expects screening capable of identifying a payment order that lists Banque Misr UAE as the originator’s or beneficiary’s financial institution—or otherwise references it in a way detectable through normal mechanisms. The operational risk sits in how names, branches, bank identifiers, addresses, and intermediary fields survive the payment chain.
A useful test pack should include at least these scenarios:
- Exact branch name in a structured institution field. Confirm the alert fires and routes to an analyst who can distinguish a UAE branch from the excluded Egyptian parent operation.
- Bank identifier without a recognizable name. Test relevant BIC/SWIFT and routing identifiers after Compliance confirms them from authoritative sources. Do not invent or infer identifiers from public naming conventions.
- Name variation in free text. Test spacing, punctuation, transliteration, “Banque Misr UAE,” and branch-address references using verified entity data.
- Nested correspondent payment. Place Banque Misr UAE deeper in the payment chain rather than as the direct originator or beneficiary bank.
- Excluded Banque Misr operation. Verify the system does not automatically treat every Banque Misr branch worldwide as within the proposed prohibition. A broader risk-based restriction may be defensible, but it should be an explicit policy decision—not an accidental false positive.
- Previously cleared counterparty. Replay a realistic transaction pattern where static customer screening passed but payment-message data creates the Section 311 concern.
The human failure mode is familiar: the sanctions team updates a vendor list, correspondent banking sends a notice, and nobody proves the payment engine uses the same entity scope. The BSA Officer should require end-to-end evidence from source message through alert, analyst decision, transaction outcome, and retained audit trail.
For a broader look at using information-sharing controls in financial crime investigations, see the FinCEN 314(b) fraud information-sharing guide. Teams rebuilding program governance should also compare this readiness work with the 2026 BSA/AML board accountability proposal.
Five things to check Monday morning
1. Open one governed readiness issue
Create an issue titled “Banque Misr UAE Section 311 readiness,” even though the rule is proposed. Set the regulatory trigger to FinCEN NPRM RIN 1506-AB76 and docket FINCEN-2026-0232. The issue owner should be the BSA Officer, with named workstream owners in Correspondent Banking, Sanctions, Payments Operations, Financial Crime Technology, and Legal.
Record the decision point: configuration in test now; production activation only after Legal confirms the final rule and effective date, unless the institution separately chooses a risk-based restriction.
2. Build the entity package before writing rules
The package should capture the five in-scope UAE locations, verified aliases and identifiers, excluded operations, source URLs, and effective dates. Require second-line approval before sending it to screening technology.
This is where ownership gets messy. Sanctions may own list ingestion, but Section 311 is a BSA authority and the proposal is not itself an OFAC designation of Banque Misr UAE. The control record should state which team owns legal interpretation and which team owns technical deployment.
3. Map direct and indirect exposure
Search customer, counterparty, nostro/vostro, trade finance, treasury, and historical payment data. Separate:
- direct accounts or relationships with Banque Misr UAE;
- foreign correspondents known or reasonably believed to serve it;
- transactions naming one of the UAE branches; and
- Banque Misr activity outside the UAE that falls outside the proposed definition.
Use a documented lookback selected from actual data availability and risk. The NPRM does not prescribe a universal retrospective period, so avoid presenting an arbitrary number as a regulatory requirement.
4. Draft the notice and control its delivery
The NPRM supplies model notice language. Legal should compare the final text against the rule when issued, while Correspondent Relationship Management validates recipients and delivery channels.
A sent email is not enough. Retain the approved notice, relationship covered, reason the institution knew or had reason to believe the correspondent served Banque Misr UAE, recipient, timestamp, delivery confirmation, response, and any follow-up restriction. FinCEN says certification from the foreign correspondent is not required, so do not create a certification process and call it mandatory.
5. Run evidence-based acceptance testing
Financial Crime Technology should test positive and negative cases before activation. Compliance Testing or Internal Audit should independently sample the evidence rather than accept screenshots selected by the implementation team.
At minimum, acceptance criteria should confirm:
- all verified in-scope branches and identifiers are covered;
- excluded operations are handled according to approved policy;
- nested message fields are screened;
- alerts reach the correct queue and service level;
- investigators see the Section 311 rationale and disposition options;
- prohibited access can be stopped; and
- notices and transaction decisions remain retrievable.
If those criteria fail, log the defect under the same readiness issue with severity, owner, target date, compensating control, and retest evidence. The restricted-business due diligence framework offers a useful parallel: scope the actual activity and control path rather than relying on a broad category label.
A practical 30/60/90-day plan
| Timing | Deliverable | Accountable role | Exit evidence |
|---|---|---|---|
| Days 0–30 | Regulatory analysis, in-scope entity package, direct/indirect exposure search, gap assessment | BSA Officer | Approved memo, search results, issue record |
| Days 31–60 | Screening requirements, draft correspondent notice, test data, operating procedures, training delta | Head of Financial Crime Technology | Signed requirements, sample notice, UAT plan |
| Days 61–90 | End-to-end UAT, defect remediation, independent challenge, production-change package ready for final rule | CCO or CRO | Test results, challenge memo, change approval, retained evidence index |
The schedule is a readiness plan, not FinCEN’s prescribed implementation calendar. Calibrate it to the institution’s exposure and change process. A direct correspondent relationship demands faster escalation than a bank that confirms no relevant foreign correspondent activity.
So what?
This proposed rule is newsworthy because it joins a targeted national-security action to detailed, testable obligations for U.S. institutions. FinCEN is not merely saying “screen this bank.” It is describing how indirect access through foreign correspondents must be controlled, when notices are expected, and what evidence must be documented.
The first task is not a policy rewrite. It is one owned readiness issue with a verified entity scope, exposure results, payment-message tests, correspondent-notice evidence, and a clear final-rule activation gate.
If that work is currently scattered across email and meeting notes, the Issues Management Tracker & Template gives the BSA and compliance teams one place to assign, evidence, challenge, and close the remediation.
This article is for general informational purposes and is not legal advice. The FinCEN action discussed is a proposed rule, and factual allegations or assessments attributed to FinCEN and Treasury have not been presented here as adjudicated findings.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did FinCEN propose for Banque Misr UAE?
Is the Banque Misr UAE Section 311 rule final?
Which institutions would be covered by the proposed rule?
Does the proposal cover all Banque Misr operations?
Would institutions need to file a new report under the proposed rule?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal
The SEC sued 38 entities over false Form ADV filings. Here is how compliance teams should verify advisers when a public filing is not proof of approval.
Aug 28, 2026
Regulatory Compliance
The DOL Reverts to 1975: What the Retirement Security Rule Vacatur Means for Rollover Recommendations, PTE 2020-02, and Your Compliance Program
The DOL's 2024 Retirement Security Rule was vacated by the courts. The 1975 five-part test is back. Here's what that means for rollover recommendations, PTE 2020-02, and investment advice compliance programs that built controls around a rule that no longer exists.
Aug 27, 2026
Regulatory Compliance
SEC Free-Riding Case: The Instant Deposit Credit Controls Broker-Dealers Need to Test
The SEC's Mayur Baviskar free-riding case exposes instant deposit credit gaps across nine broker-dealers. Here is the control test to run now.
Aug 26, 2026