Skip to content
RiskTemplates · The Daily Brief Thursday, September 17, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Compliance Strategy

FinCEN's Eight AML/CFT Priorities Have Been Effective for Five Years. Here's Why Most Programs Still Treat Them as Compliance Wallpaper.

FinCEN issued the first-ever national AML/CFT priorities in June 2021 — a legal mandate to redesign risk-based programs around current threats. Five years later, most compliance programs acknowledge the priorities exist while doing nothing structurally different. That gap is becoming an examination risk.

By Rebecca Leung · September 17, 2026 ·
Table of Contents

TL;DR

  • In June 2021, FinCEN issued the first-ever national AML/CFT priorities under the AML Act of 2020 — eight specific threat categories that financial institutions are required to incorporate into their risk-based programs.
  • Five years later, most BSA programs haven’t changed their risk assessment structure, transaction monitoring scenarios, or training content to reflect these priorities. They mention the list in a footer and move on.
  • Two priorities that most programs still mishandle: proliferation financing (no TM scenarios exist) and cybercrime (treated as an IT issue, not an AML issue).
  • The fraud priority — covering elder fraud, advance fee fraud, and consumer scams — is the most consequential for fintech AML programs and the one most likely to drive examination findings.

If your AML/CFT program has a section that says “this program incorporates FinCEN’s national AML/CFT priorities” and then lists the eight priorities without changing anything about how the program actually works, you have compliance wallpaper.

FinCEN’s June 30, 2021 national AML/CFT priorities are not a suggestion. They are a legal mandate, issued under Section 6101 of the Anti-Money Laundering Act of 2020, requiring financial institutions to incorporate specific threat categories into their risk-based AML/CFT programs. The priorities don’t require you to rebuild your program. They do require you to demonstrate that the risk assessment actually reflects these threats — and that the monitoring, controls, and SAR filings that flow from that assessment respond to them.

Five years on, the gap between what most programs say and what they actually do is real, measurable, and increasingly visible to examiners.

Why the AML Act of 2020 Mattered More Than Most Programs Recognized

The Anti-Money Laundering Act of 2020 (AMLA) was enacted as part of the National Defense Authorization Act for Fiscal Year 2021, signed into law on January 1, 2021. For the AML compliance community, it was the most significant reform to the Bank Secrecy Act since the USA PATRIOT Act of 2001.

The AMLA made several structural changes to AML/CFT program requirements, but two are most relevant to the priorities discussion:

Section 6101: National AML/CFT Priorities. FinCEN was directed to issue national AML/CFT priorities on a periodic basis, working with law enforcement, national security agencies, and regulators. The priorities were to reflect current and near-term threats. Financial institutions were required to incorporate those priorities into their programs.

Section 6102: AML/CFT Program Effectiveness. The AMLA added an explicit effectiveness standard to AML/CFT program requirements. Programs must be risk-based and effective — not just formally complete. FinCEN was directed to revise the program rules to reflect this standard. This change matters because it shifts the regulatory standard from “does the program check the required boxes” to “does the program actually address current risks.”

Together, these provisions changed the legal standard. An AML/CFT program that has a policy manual, a BSA officer, annual training, and an independent audit — but no risk assessment that reflects the national priorities — is not a compliant risk-based program under the post-AMLA standard.

FinCEN issued the first national AML/CFT priorities on June 30, 2021. The eight priorities have been in effect since that date. The question for every AML compliance program is: what actually changed?

The Eight Priorities: What They Mean Operationally

FinCEN’s priorities aren’t abstract. Each one has operational implications for risk assessments, transaction monitoring, suspicious activity reporting, and customer due diligence. Here’s where most programs fall short on each:

1. Corruption

Foreign and domestic public corruption — bribery, embezzlement, kleptocracy, politically exposed person (PEP) risk — is the priority most likely to already exist in some form in AML programs. Most programs have PEP screening. What many programs lack is a risk assessment that distinguishes between different categories of corruption risk (domestic versus foreign PEPs, state-level officials versus federal, different geographic risk concentrations) and maps those distinctions to differentiated CDD and monitoring procedures.

The corruption priority also captures domestic public corruption, which gets less attention than foreign PEP risk but is explicitly included in the priority.

2. Cybercrime

This is where most programs have the most significant gap. The cybercrime priority covers ransomware payments, cyber-enabled fraud, darknet market proceeds, and virtual currency exploitation. Most AML programs treat cybercrime as an IT security issue. It is also a financial crime issue.

The operational implication: your transaction monitoring scenarios need to detect typologies associated with cybercrime proceeds. This includes transactions to and from known cryptocurrency mixer services (which FinCEN designated as money laundering concerns under the BSA), structuring patterns consistent with crypto-to-fiat conversion following a ransomware attack, and high-velocity small-dollar transactions characteristic of credential-stuffing or account takeover fraud.

FinCEN has issued multiple advisories specifically addressing cybercrime typologies and red flags. Those advisories are part of the framework your risk assessment should reference — and your TM scenarios should operationalize.

3. Foreign and Domestic Terrorist Financing

Terrorist financing risk is a standard element in most AML/CFT programs, particularly for banks and larger fintechs. What the national priority requires is explicit — not assumed — risk assessment of terrorist financing as a threat category, with documented rationale for the likelihood that the institution’s products, services, customers, and geographies create terrorist financing risk. Programs that note “we have OFAC screening” and treat that as equivalent to addressing the terrorist financing priority are missing the point. OFAC compliance is separate from AML/CFT monitoring for terrorist financing.

4. Fraud

This is the priority with the most significant operational impact for consumer-facing fintechs, and the one where the gap between nominal compliance and substantive compliance is widest.

The fraud priority covers securities fraud, healthcare fraud, elder fraud, advance fee fraud, consumer fraud, and Ponzi schemes. For most fintech AML programs historically organized around payment typologies and BSA mechanics, this is new territory. The practical question is whether your transaction monitoring detects proceeds of consumer fraud moving through your platform — pig-butchering, romance scams, grandparent scams, tech support fraud — not just whether you file SARs when law enforcement asks about a specific account.

FinCEN has issued multiple alerts specifically on romance scam/pig-butchering activity (including an alert in September 2023 regarding cryptocurrency-based pig-butchering scams). Those alerts describe specific transaction patterns associated with these fraud typologies. A program whose TM scenarios predate those alerts and hasn’t been updated is not incorporating the fraud priority.

For a detailed breakdown of FinCEN’s pig-butchering typology guidance and what it means for transaction monitoring, see our analysis of FinCEN’s scam-center alert and transaction monitoring design.

5. Transnational Criminal Organization Activity

TCO activity overlaps heavily with drug trafficking and human trafficking, but it’s listed separately because it covers the financial infrastructure of criminal organizations — including front companies, shell structures, and professional money launderers. For most US financial institutions, this priority is addressed through geographic risk assessment (higher risk for transactions to and from known TCO operating regions) and through business relationship due diligence.

6. Drug Trafficking Organization Activity

Drug trafficking is a well-established AML/CFT risk category and most programs have it addressed in some form through geographic risk, cash-intensive business CDD, and transaction monitoring for cash-to-fund structuring. The priority reinforces the expectation that DTO activity is explicitly named in the risk assessment — not assumed to be covered by generic “criminal activity” language.

7. Human Trafficking and Human Smuggling

The human trafficking priority has generated the most specific new TM guidance from FinCEN. FinCEN’s Human Trafficking Advisory (FIN-2014-A008) and subsequent updated guidance (FIN-2020-A008) provide explicit red flags for human trafficking proceeds. These include specific patterns in hotel and motel payments, prepaid card usage, escort service payments, and unusual patterns in commercial sex advertisement payments.

Most programs with human trafficking addressed in their risk assessments have it as a listed risk. What the national priority requires is that the red flags from FinCEN’s advisories are actually incorporated into TM scenarios — not just listed in the risk assessment narrative.

8. Proliferation Financing

Proliferation financing is the priority where most AML programs have the largest gap — and the most understandable reason for it. Until the 2021 priorities, proliferation financing was primarily addressed through OFAC sanctions compliance (specifically, designations related to weapons proliferation programs in North Korea, Iran, and Russia). It wasn’t typically treated as an AML/CFT risk category requiring independent TM scenarios.

The national priority changed that. FinCEN’s guidance makes clear that proliferation financing risk — the risk that financial transactions support weapons development programs — requires BSA program attention beyond OFAC screening. This includes enhanced due diligence for customers or counterparties in sectors associated with dual-use goods exports, specific attention to transactions that match procurement patterns for weapons-related components, and risk assessment of correspondent banking relationships with jurisdictions subject to weapons-related sanctions.

Most TM platforms have zero built-in proliferation financing scenarios. Building them requires understanding what the procurement pattern looks like — which means engaging with the threat intelligence that FinCEN and the Departments of Commerce and State have published on proliferation financing typologies.

What a Risk Assessment That Actually Incorporates the Priorities Looks Like

The current standard for a risk assessment that genuinely incorporates the national priorities has four components:

1. Threat mapping. Each of the eight priorities is mapped against the institution’s specific products, services, customer base, and geographic footprint. The risk assessment doesn’t just acknowledge that proliferation financing exists — it explains why the institution’s specific business does or doesn’t present material proliferation financing risk, and what that conclusion is based on.

2. Differentiated risk ratings. The mapping exercise produces differentiated risk ratings by priority. A fintech with heavy consumer payment volume should rate fraud risk as high and proliferation financing risk as low — with documented reasoning. That’s a different document from a generic “high/medium/low” rating across generic risk categories.

3. Program design traceability. The risk assessment explicitly connects to program design: where fraud risk is rated high, TM scenarios address fraud typologies. Where the cybercrime priority elevates the risk of crypto-related transactions, CDD procedures include specific attention to virtual asset service provider relationships. The assessment produces program changes, not just a document.

4. Annual refresh with priority alignment. The annual risk assessment refresh explicitly reviews whether the priorities remain appropriately reflected — and whether new FinCEN advisories (which function as updates to the priority guidance) have been incorporated into TM scenarios and training content.

The Connection to SAR Filing Quality

One of the most concrete operational consequences of the national priorities is what examiners expect to see in Suspicious Activity Reports.

A SAR that accurately reflects current AML/CFT priority threats provides law enforcement with actionable intelligence. SARs that don’t reference the relevant priority typology — even when the suspicious activity clearly relates to fraud, cybercrime, or trafficking proceeds — provide less useful intelligence and suggest a program that hasn’t incorporated the priorities at the operational level.

FinCEN’s guidance on SAR narrative quality has consistently emphasized specificity: describing the suspicious activity in terms that connect to known typologies and national priorities. Examiners reviewing SAR quality as part of an AML examination look specifically at whether SARs filed by the institution reflect current threat typologies or generic suspicious activity language.

For a concrete example of what enforcement looks like when SAR quality and program structure fall short of current standards, see our analysis of the CFSB consent order and BSA/AML scaling failures.

What Examiners Are Actually Testing

Since the 2021 priorities were issued, examiners from the OCC, FDIC, Federal Reserve, NCUA, and FinCEN itself have explicitly asked about priority incorporation during BSA/AML examinations. The specific examination questions that have emerged:

Can you show how the national priorities are reflected in your risk assessment? This is a documentation question. The examiner wants to see where in the risk assessment each priority appears and how it was evaluated.

What changed about your TM scenarios after the priorities were issued? This is a program change question. If the answer is “nothing changed because our scenarios were already adequate,” the examiner may test that claim by reviewing which priorities your current TM coverage addresses.

How do you incorporate FinCEN advisories related to the priorities into your program? This is a currency question. FinCEN issues advisories and alerts throughout the year that provide updated typology guidance on priority areas. Examiners want to see a process for tracking and incorporating those updates — not just a one-time 2021 review.

What does your training program say about the priorities? Annual BSA training that doesn’t mention the national priorities or the specific typologies associated with them is a gap the examiner will note.

For context on how enforcement actions related to BSA/AML program failures — specifically recidivist broker-dealer cases — illustrate what examiners find when programs lack structure, see our analysis of the FinCEN-FINRA UBS AML case.

The KRI Question: Are You Measuring Priority Risk?

One of the most visible gaps between programs that talk about the national priorities and programs that have genuinely incorporated them is the absence of priority-specific KRIs.

A BSA/AML KRI program that reports SAR filing volumes and CTR counts but has no metrics tied to specific priority areas leaves management blind to whether the program is actually detecting the threats the priorities identify. Priority-specific KRIs look like:

  • Fraud: percentage of SARs filed with fraud-related activity codes; rate of consumer dispute and chargeback patterns suggesting authorized push payment fraud
  • Cybercrime: alerts generated on transactions to or from virtual asset service providers; monitoring hits on cryptocurrency mixer addresses
  • Human trafficking: TM alerts on hotel/motel payment concentration, escort service payments, or unusual prepaid card reload patterns
  • Corruption: PEP alert rate, enhanced due diligence completion rate for PEP accounts, outbound transaction volumes to known high-corruption jurisdictions

These KRIs don’t need to be reported at board level — but they need to exist at the management level so someone responsible for the AML/CFT program can track whether the priority-adjacent monitoring is actually generating activity. A program that has never generated a fraud-typology SAR while processing millions of consumer transactions has a monitoring gap, a filing gap, or both.

So What?

The national AML/CFT priorities are now five years old. Examiners have had time to develop examination techniques specifically around priority incorporation. The institutions that are well-positioned are those where the priorities actually changed how the risk assessment works, which TM scenarios run, what training content covers, and what KRIs management reviews.

The institutions that are exposed are those where “incorporates FinCEN’s 2021 national AML/CFT priorities” is a sentence in a policy document, not a description of how the program operates.

The practical steps:

Map your risk assessment explicitly against each priority. If your current risk assessment document doesn’t mention proliferation financing, cybercrime typologies, or the fraud priority by name, it needs to be updated.

Audit your TM scenarios for priority alignment. Which of your current scenarios address cybercrime proceeds? Fraud typologies? Trafficking red flags? If the answer is none or unknown, that’s the gap to address.

Update training content. Annual BSA training should reference the national priorities and include at least one example typology from each relevant priority for your institution’s customer base.

Build priority-specific KRIs. At minimum, fraud and cybercrime KRIs. For institutions with higher risk profiles, add trafficking and corruption KRIs.

Document the process for incorporating new FinCEN advisories. Examiners expect to see a repeatable process, not a one-time 2021 review.

The priorities didn’t change the underlying mechanics of the BSA — SARs, CTRs, CIP, CDD, and independent testing still all apply. What they changed is the standard for whether those mechanics are oriented toward current threats. That’s the gap most programs haven’t closed.


External Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are FinCEN's 2021 AML/CFT national priorities?
FinCEN issued eight national AML/CFT priorities on June 30, 2021, as required by Section 6101 of the Anti-Money Laundering Act of 2020. The priorities are: (1) Corruption, including foreign and domestic public corruption and kleptocracy; (2) Cybercrime, including ransomware, cyber-enabled fraud, and virtual currency exploitation; (3) Foreign and Domestic Terrorist Financing; (4) Fraud, including consumer fraud, securities fraud, healthcare fraud, elder fraud, and advance fee fraud; (5) Transnational Criminal Organization activity; (6) Drug Trafficking Organization activity; (7) Human Trafficking and Human Smuggling; and (8) Proliferation Financing. Financial institutions are required to incorporate these priorities into their AML/CFT programs.
Are all financial institutions required to change their AML programs because of the 2021 priorities?
Yes, substantively. Section 6102 of the AML Act of 2020 directed FinCEN to issue regulations requiring financial institutions to establish risk-based AML/CFT programs that incorporate the national priorities. FinCEN has been clear that existing programs don't need to be rebuilt from scratch — but they must demonstrate that the priorities informed the risk assessment and program design. An AML/CFT risk assessment that never references the national priorities is difficult to defend as genuinely risk-based under current regulatory expectations.
What does 'proliferation financing' mean and how does it fit into a BSA program?
Proliferation financing refers to the financing of the development, production, or acquisition of weapons of mass destruction and their delivery systems. For most US financial institutions, the practical compliance obligations overlap heavily with OFAC sanctions compliance — specifically screening for SDN-listed entities associated with weapons programs. But the AML/CFT priorities add a transaction monitoring dimension: detecting unusual patterns in payments for dual-use goods, technology transfers, or layered transactions with counterparties in proliferation-risk jurisdictions. Most legacy TM systems have no proliferation financing scenarios.
How does FinCEN's cybercrime priority change transaction monitoring requirements?
The cybercrime priority expanded the definition of financial crime that AML programs must monitor for. Ransomware payment proceeds, cybercrime proceeds, and darknet market activity can move through accounts at US financial institutions. FinCEN's cybercrime priority, combined with specific ransomware advisories issued since 2020, makes clear that monitoring for proceeds of cybercrime — not just traditional fraud — is an AML program obligation. This means adding ransomware payment typologies to TM scenarios, flagging transactions with known cryptocurrency mixer services, and monitoring for structuring patterns consistent with crypto-to-fiat conversion.
What changed about the 'four pillars' of a BSA/AML program under the AML Act of 2020?
The traditional four pillars (written policies and procedures, designated BSA compliance officer, ongoing employee training, independent testing) remain required. The AML Act of 2020 effectively added a fifth pillar: customer due diligence and risk assessment that explicitly incorporates the national priorities. FinCEN was directed to add risk-based CDD and ongoing monitoring as formal program requirements, and to require that programs demonstrate effectiveness — not just existence. A program that looks good on paper but doesn't connect to current threat priorities is no longer compliant under the post-AMLA standard.
Does the fraud priority mean transaction monitoring programs need to detect consumer scams?
Yes. The fraud priority — which includes elder fraud, advance fee fraud, and consumer fraud — significantly expanded what AML programs at consumer-facing fintechs must detect. Historically, many fintech AML programs focused on BSA mechanics (CIP, high-velocity monitoring, MSB typologies) without treating pig-butchering scams, romance fraud, and authorized push payment fraud as AML concerns. The 2021 priorities changed that: fraud proceeds moving through accounts are explicitly an AML/CFT risk. FinCEN's subsequent alerts on romance scam/pig-butchering activity have reinforced the expectation that transaction monitoring programs detect these patterns.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.