Feature Compliance Strategy
FinCEN's Eight AML/CFT Priorities Have Been Effective for Five Years. Here's Why Most Programs Still Treat Them as Compliance Wallpaper.
FinCEN issued the first-ever national AML/CFT priorities in June 2021 — a legal mandate to redesign risk-based programs around current threats. Five years later, most compliance programs acknowledge the priorities exist while doing nothing structurally different. That gap is becoming an examination risk.
Table of Contents
TL;DR
- In June 2021, FinCEN issued the first-ever national AML/CFT priorities under the AML Act of 2020 — eight specific threat categories that financial institutions are required to incorporate into their risk-based programs.
- Five years later, most BSA programs haven’t changed their risk assessment structure, transaction monitoring scenarios, or training content to reflect these priorities. They mention the list in a footer and move on.
- Two priorities that most programs still mishandle: proliferation financing (no TM scenarios exist) and cybercrime (treated as an IT issue, not an AML issue).
- The fraud priority — covering elder fraud, advance fee fraud, and consumer scams — is the most consequential for fintech AML programs and the one most likely to drive examination findings.
If your AML/CFT program has a section that says “this program incorporates FinCEN’s national AML/CFT priorities” and then lists the eight priorities without changing anything about how the program actually works, you have compliance wallpaper.
FinCEN’s June 30, 2021 national AML/CFT priorities are not a suggestion. They are a legal mandate, issued under Section 6101 of the Anti-Money Laundering Act of 2020, requiring financial institutions to incorporate specific threat categories into their risk-based AML/CFT programs. The priorities don’t require you to rebuild your program. They do require you to demonstrate that the risk assessment actually reflects these threats — and that the monitoring, controls, and SAR filings that flow from that assessment respond to them.
Five years on, the gap between what most programs say and what they actually do is real, measurable, and increasingly visible to examiners.
Why the AML Act of 2020 Mattered More Than Most Programs Recognized
The Anti-Money Laundering Act of 2020 (AMLA) was enacted as part of the National Defense Authorization Act for Fiscal Year 2021, signed into law on January 1, 2021. For the AML compliance community, it was the most significant reform to the Bank Secrecy Act since the USA PATRIOT Act of 2001.
The AMLA made several structural changes to AML/CFT program requirements, but two are most relevant to the priorities discussion:
Section 6101: National AML/CFT Priorities. FinCEN was directed to issue national AML/CFT priorities on a periodic basis, working with law enforcement, national security agencies, and regulators. The priorities were to reflect current and near-term threats. Financial institutions were required to incorporate those priorities into their programs.
Section 6102: AML/CFT Program Effectiveness. The AMLA added an explicit effectiveness standard to AML/CFT program requirements. Programs must be risk-based and effective — not just formally complete. FinCEN was directed to revise the program rules to reflect this standard. This change matters because it shifts the regulatory standard from “does the program check the required boxes” to “does the program actually address current risks.”
Together, these provisions changed the legal standard. An AML/CFT program that has a policy manual, a BSA officer, annual training, and an independent audit — but no risk assessment that reflects the national priorities — is not a compliant risk-based program under the post-AMLA standard.
FinCEN issued the first national AML/CFT priorities on June 30, 2021. The eight priorities have been in effect since that date. The question for every AML compliance program is: what actually changed?
The Eight Priorities: What They Mean Operationally
FinCEN’s priorities aren’t abstract. Each one has operational implications for risk assessments, transaction monitoring, suspicious activity reporting, and customer due diligence. Here’s where most programs fall short on each:
1. Corruption
Foreign and domestic public corruption — bribery, embezzlement, kleptocracy, politically exposed person (PEP) risk — is the priority most likely to already exist in some form in AML programs. Most programs have PEP screening. What many programs lack is a risk assessment that distinguishes between different categories of corruption risk (domestic versus foreign PEPs, state-level officials versus federal, different geographic risk concentrations) and maps those distinctions to differentiated CDD and monitoring procedures.
The corruption priority also captures domestic public corruption, which gets less attention than foreign PEP risk but is explicitly included in the priority.
2. Cybercrime
This is where most programs have the most significant gap. The cybercrime priority covers ransomware payments, cyber-enabled fraud, darknet market proceeds, and virtual currency exploitation. Most AML programs treat cybercrime as an IT security issue. It is also a financial crime issue.
The operational implication: your transaction monitoring scenarios need to detect typologies associated with cybercrime proceeds. This includes transactions to and from known cryptocurrency mixer services (which FinCEN designated as money laundering concerns under the BSA), structuring patterns consistent with crypto-to-fiat conversion following a ransomware attack, and high-velocity small-dollar transactions characteristic of credential-stuffing or account takeover fraud.
FinCEN has issued multiple advisories specifically addressing cybercrime typologies and red flags. Those advisories are part of the framework your risk assessment should reference — and your TM scenarios should operationalize.
3. Foreign and Domestic Terrorist Financing
Terrorist financing risk is a standard element in most AML/CFT programs, particularly for banks and larger fintechs. What the national priority requires is explicit — not assumed — risk assessment of terrorist financing as a threat category, with documented rationale for the likelihood that the institution’s products, services, customers, and geographies create terrorist financing risk. Programs that note “we have OFAC screening” and treat that as equivalent to addressing the terrorist financing priority are missing the point. OFAC compliance is separate from AML/CFT monitoring for terrorist financing.
4. Fraud
This is the priority with the most significant operational impact for consumer-facing fintechs, and the one where the gap between nominal compliance and substantive compliance is widest.
The fraud priority covers securities fraud, healthcare fraud, elder fraud, advance fee fraud, consumer fraud, and Ponzi schemes. For most fintech AML programs historically organized around payment typologies and BSA mechanics, this is new territory. The practical question is whether your transaction monitoring detects proceeds of consumer fraud moving through your platform — pig-butchering, romance scams, grandparent scams, tech support fraud — not just whether you file SARs when law enforcement asks about a specific account.
FinCEN has issued multiple alerts specifically on romance scam/pig-butchering activity (including an alert in September 2023 regarding cryptocurrency-based pig-butchering scams). Those alerts describe specific transaction patterns associated with these fraud typologies. A program whose TM scenarios predate those alerts and hasn’t been updated is not incorporating the fraud priority.
For a detailed breakdown of FinCEN’s pig-butchering typology guidance and what it means for transaction monitoring, see our analysis of FinCEN’s scam-center alert and transaction monitoring design.
5. Transnational Criminal Organization Activity
TCO activity overlaps heavily with drug trafficking and human trafficking, but it’s listed separately because it covers the financial infrastructure of criminal organizations — including front companies, shell structures, and professional money launderers. For most US financial institutions, this priority is addressed through geographic risk assessment (higher risk for transactions to and from known TCO operating regions) and through business relationship due diligence.
6. Drug Trafficking Organization Activity
Drug trafficking is a well-established AML/CFT risk category and most programs have it addressed in some form through geographic risk, cash-intensive business CDD, and transaction monitoring for cash-to-fund structuring. The priority reinforces the expectation that DTO activity is explicitly named in the risk assessment — not assumed to be covered by generic “criminal activity” language.
7. Human Trafficking and Human Smuggling
The human trafficking priority has generated the most specific new TM guidance from FinCEN. FinCEN’s Human Trafficking Advisory (FIN-2014-A008) and subsequent updated guidance (FIN-2020-A008) provide explicit red flags for human trafficking proceeds. These include specific patterns in hotel and motel payments, prepaid card usage, escort service payments, and unusual patterns in commercial sex advertisement payments.
Most programs with human trafficking addressed in their risk assessments have it as a listed risk. What the national priority requires is that the red flags from FinCEN’s advisories are actually incorporated into TM scenarios — not just listed in the risk assessment narrative.
8. Proliferation Financing
Proliferation financing is the priority where most AML programs have the largest gap — and the most understandable reason for it. Until the 2021 priorities, proliferation financing was primarily addressed through OFAC sanctions compliance (specifically, designations related to weapons proliferation programs in North Korea, Iran, and Russia). It wasn’t typically treated as an AML/CFT risk category requiring independent TM scenarios.
The national priority changed that. FinCEN’s guidance makes clear that proliferation financing risk — the risk that financial transactions support weapons development programs — requires BSA program attention beyond OFAC screening. This includes enhanced due diligence for customers or counterparties in sectors associated with dual-use goods exports, specific attention to transactions that match procurement patterns for weapons-related components, and risk assessment of correspondent banking relationships with jurisdictions subject to weapons-related sanctions.
Most TM platforms have zero built-in proliferation financing scenarios. Building them requires understanding what the procurement pattern looks like — which means engaging with the threat intelligence that FinCEN and the Departments of Commerce and State have published on proliferation financing typologies.
What a Risk Assessment That Actually Incorporates the Priorities Looks Like
The current standard for a risk assessment that genuinely incorporates the national priorities has four components:
1. Threat mapping. Each of the eight priorities is mapped against the institution’s specific products, services, customer base, and geographic footprint. The risk assessment doesn’t just acknowledge that proliferation financing exists — it explains why the institution’s specific business does or doesn’t present material proliferation financing risk, and what that conclusion is based on.
2. Differentiated risk ratings. The mapping exercise produces differentiated risk ratings by priority. A fintech with heavy consumer payment volume should rate fraud risk as high and proliferation financing risk as low — with documented reasoning. That’s a different document from a generic “high/medium/low” rating across generic risk categories.
3. Program design traceability. The risk assessment explicitly connects to program design: where fraud risk is rated high, TM scenarios address fraud typologies. Where the cybercrime priority elevates the risk of crypto-related transactions, CDD procedures include specific attention to virtual asset service provider relationships. The assessment produces program changes, not just a document.
4. Annual refresh with priority alignment. The annual risk assessment refresh explicitly reviews whether the priorities remain appropriately reflected — and whether new FinCEN advisories (which function as updates to the priority guidance) have been incorporated into TM scenarios and training content.
The Connection to SAR Filing Quality
One of the most concrete operational consequences of the national priorities is what examiners expect to see in Suspicious Activity Reports.
A SAR that accurately reflects current AML/CFT priority threats provides law enforcement with actionable intelligence. SARs that don’t reference the relevant priority typology — even when the suspicious activity clearly relates to fraud, cybercrime, or trafficking proceeds — provide less useful intelligence and suggest a program that hasn’t incorporated the priorities at the operational level.
FinCEN’s guidance on SAR narrative quality has consistently emphasized specificity: describing the suspicious activity in terms that connect to known typologies and national priorities. Examiners reviewing SAR quality as part of an AML examination look specifically at whether SARs filed by the institution reflect current threat typologies or generic suspicious activity language.
For a concrete example of what enforcement looks like when SAR quality and program structure fall short of current standards, see our analysis of the CFSB consent order and BSA/AML scaling failures.
What Examiners Are Actually Testing
Since the 2021 priorities were issued, examiners from the OCC, FDIC, Federal Reserve, NCUA, and FinCEN itself have explicitly asked about priority incorporation during BSA/AML examinations. The specific examination questions that have emerged:
Can you show how the national priorities are reflected in your risk assessment? This is a documentation question. The examiner wants to see where in the risk assessment each priority appears and how it was evaluated.
What changed about your TM scenarios after the priorities were issued? This is a program change question. If the answer is “nothing changed because our scenarios were already adequate,” the examiner may test that claim by reviewing which priorities your current TM coverage addresses.
How do you incorporate FinCEN advisories related to the priorities into your program? This is a currency question. FinCEN issues advisories and alerts throughout the year that provide updated typology guidance on priority areas. Examiners want to see a process for tracking and incorporating those updates — not just a one-time 2021 review.
What does your training program say about the priorities? Annual BSA training that doesn’t mention the national priorities or the specific typologies associated with them is a gap the examiner will note.
For context on how enforcement actions related to BSA/AML program failures — specifically recidivist broker-dealer cases — illustrate what examiners find when programs lack structure, see our analysis of the FinCEN-FINRA UBS AML case.
The KRI Question: Are You Measuring Priority Risk?
One of the most visible gaps between programs that talk about the national priorities and programs that have genuinely incorporated them is the absence of priority-specific KRIs.
A BSA/AML KRI program that reports SAR filing volumes and CTR counts but has no metrics tied to specific priority areas leaves management blind to whether the program is actually detecting the threats the priorities identify. Priority-specific KRIs look like:
- Fraud: percentage of SARs filed with fraud-related activity codes; rate of consumer dispute and chargeback patterns suggesting authorized push payment fraud
- Cybercrime: alerts generated on transactions to or from virtual asset service providers; monitoring hits on cryptocurrency mixer addresses
- Human trafficking: TM alerts on hotel/motel payment concentration, escort service payments, or unusual prepaid card reload patterns
- Corruption: PEP alert rate, enhanced due diligence completion rate for PEP accounts, outbound transaction volumes to known high-corruption jurisdictions
These KRIs don’t need to be reported at board level — but they need to exist at the management level so someone responsible for the AML/CFT program can track whether the priority-adjacent monitoring is actually generating activity. A program that has never generated a fraud-typology SAR while processing millions of consumer transactions has a monitoring gap, a filing gap, or both.
So What?
The national AML/CFT priorities are now five years old. Examiners have had time to develop examination techniques specifically around priority incorporation. The institutions that are well-positioned are those where the priorities actually changed how the risk assessment works, which TM scenarios run, what training content covers, and what KRIs management reviews.
The institutions that are exposed are those where “incorporates FinCEN’s 2021 national AML/CFT priorities” is a sentence in a policy document, not a description of how the program operates.
The practical steps:
Map your risk assessment explicitly against each priority. If your current risk assessment document doesn’t mention proliferation financing, cybercrime typologies, or the fraud priority by name, it needs to be updated.
Audit your TM scenarios for priority alignment. Which of your current scenarios address cybercrime proceeds? Fraud typologies? Trafficking red flags? If the answer is none or unknown, that’s the gap to address.
Update training content. Annual BSA training should reference the national priorities and include at least one example typology from each relevant priority for your institution’s customer base.
Build priority-specific KRIs. At minimum, fraud and cybercrime KRIs. For institutions with higher risk profiles, add trafficking and corruption KRIs.
Document the process for incorporating new FinCEN advisories. Examiners expect to see a repeatable process, not a one-time 2021 review.
The priorities didn’t change the underlying mechanics of the BSA — SARs, CTRs, CIP, CDD, and independent testing still all apply. What they changed is the standard for whether those mechanics are oriented toward current threats. That’s the gap most programs haven’t closed.
External Sources:
- FinCEN Anti-Money Laundering and Countering the Financing of Terrorism National Priorities (June 30, 2021)
- Anti-Money Laundering Act of 2020 — P.L. 116-283, Division F
- FinCEN Advisory FIN-2021-A004: Ransomware and the Use of the Financial System to Facilitate Ransom Payments
- FinCEN Bank Secrecy Act Regulations and Guidance
- FinCEN Anti-Human Trafficking Advisory (FIN-2014-A008 and updated guidance)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are FinCEN's 2021 AML/CFT national priorities?
Are all financial institutions required to change their AML programs because of the 2021 priorities?
What does 'proliferation financing' mean and how does it fit into a BSA program?
How does FinCEN's cybercrime priority change transaction monitoring requirements?
What changed about the 'four pillars' of a BSA/AML program under the AML Act of 2020?
Does the fraud priority mean transaction monitoring programs need to detect consumer scams?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Compliance Strategy
Your BSA/AML Compliance Program Can't Scale in Arrears: What the CFSB Consent Order Means for Every Fintech
In April 2026, the OCC issued a consent order against Community Federal Savings Bank — sponsor bank for Wise, Crypto.com, Airwallex, ChipperCash, and LemFi — for BSA/AML compliance failures so severe that its alert system was auto-closing a very high percentage of suspicious-activity flags. Here's what that means for the fintechs riding those rails, and what every fintech compliance team can learn about scaling a BSA program that doesn't collapse under its own transaction volume.
Sep 14, 2026
Compliance Strategy
The CFPB Dropped Disparate Impact. State AGs Didn't.
Five months after the CFPB eliminated disparate impact liability under ECOA, state attorneys general are filling the gap with coordinated enforcement targeting AI lending models, pricing algorithms, and redlining — and they're better organized than they've ever been.
Sep 12, 2026
Compliance Strategy
OFAC Just Sanctioned the $36 Billion Scam Factory. Here's What Your Compliance Program Needs to Find Next.
On September 9, 2026, Treasury sanctioned Xinbi Guarantee — a Chinese-language escrow marketplace that moved $36B+ in illicit funds via TRON USDT. Here's what financial institutions need to verify now.
Sep 11, 2026