Feature Regulatory Compliance
The BSA's Biggest Overhaul in Decades Just Cleared Its Last Comment Deadline. Here's What the FinCEN Program Reform NPRM Actually Changes.
FinCEN's April 2026 NPRM to fundamentally reform AML/CFT programs — combined with the Federal Reserve's companion rulemaking, whose comment period just closed September 8 — is the most significant BSA update since the PATRIOT Act. Here's what effectiveness-based evaluation means for your compliance program.
Table of Contents
TL;DR
- FinCEN’s April 2026 NPRM is the most significant BSA reform since the PATRIOT Act — moving from technical compliance to effectiveness-based evaluation
- Risk assessment becomes an explicit regulatory requirement embedded in the internal controls pillar
- The Federal Reserve’s companion NPRM comment period closed September 8, 2026 — both NPRMs are now past public comment and moving toward finalization
- BSA officers should start gap analysis and effectiveness documentation now, before final rules issue
The Federal Reserve’s comment period on its AML/CFT program reform rulemaking closed September 8, 2026. That deadline is easy to scroll past, but it marks something practitioners should flag: both major pieces of the most consequential BSA reform in decades are now through public comment and moving toward finalization.
FinCEN called its April 2026 NPRM a plan to “fundamentally reform” how BSA compliance programs are structured and evaluated. That language is not hyperbole. The proposed changes would rewrite what “reasonably designed” means under the BSA — and if your program was built around the current five-pillar checkbox model, you have a gap that needs to close before examiners start using the new framework.
Why the Current Framework Has a Problem
The current BSA/AML program framework, established in the PATRIOT Act era, requires financial institutions to implement five basic pillars: written policies and procedures, a designated compliance officer, ongoing employee training, independent testing, and customer due diligence. The model works as a minimum structural floor — it ensures some formal coverage of BSA obligations.
What it doesn’t ensure is that any of those components actually work.
The record $145 million in combined FinCEN and FINRA penalties against UBS Financial Services is the clearest recent illustration. UBSFS had a transaction monitoring program. It had a compliance officer. It had written policies. What it didn’t have was monitoring calibrated to cover the specific transaction type — foreign currency wires — that carried its highest money laundering risk. For four years, the program existed on paper while 61,500 FX wires totaling more than $10.5 billion went inadequately monitored.
The current five-pillar framework has no mechanism to catch that gap before an eight-figure enforcement action surfaces it. FinCEN’s NPRM is designed to change that.
What the NPRM Actually Changes
FinCEN’s proposed reform shifts the evaluation standard in four concrete ways:
1. Effectiveness-based evaluation. Under the proposed framework, the question isn’t “do you have a monitoring system?” — it’s “does your monitoring system detect suspicious activity?” Examiners would evaluate whether programs produce results: useful alerts, accurate risk assessments, timely SAR filings that reflect genuine suspicion. The existence of program components is necessary but no longer sufficient.
2. Risk assessment as an explicit requirement. FinCEN’s April NPRM incorporates risk assessment as a core element of the internal controls pillar, making it a regulatory requirement rather than a recommended practice. The formalization matters. It gives examiners a clear hook to scrutinize whether your risk assessment exists, is current, and actually drives the design of your monitoring rules, CDD thresholds, and SAR triggers.
The connection between the risk assessment and program design is what the new standard tests. A risk assessment that sits in a folder and hasn’t shaped a single monitoring rule isn’t going to satisfy an effectiveness examiner. FinCEN’s proposed standard asks whether your program was designed based on your risk profile — not just whether you can produce a document labeled “risk assessment.”
3. FinCEN’s expanded supervisory role. The NPRM introduces a consultation requirement that gives FinCEN more direct influence over how federal banking regulators take enforcement action against institutions for AML/CFT deficiencies. This is a structural shift in BSA supervision — FinCEN moves from being a rule-setter to an active participant in how those rules get enforced at the institution level.
4. Outcome measurement. The framework moves toward expecting institutions to demonstrate that their programs are effective, not just compliant. For transaction monitoring, that means being able to show alert quality: conversion rates from alert to SAR, false positive rates, evidence that monitoring rules are calibrated to actual risk. Alert volume is not an effectiveness metric.
The Risk Assessment Connection
The most immediately actionable change in the NPRM is the formalization of risk assessment as a program design driver. The five-pillar structure remains intact under the proposed rule — what changes is how each pillar gets evaluated, through the lens of whether it was designed to address the institution’s specific risk profile.
This means the questions BSA officers should be asking right now are:
- Can you trace a direct line from your risk assessment to your transaction monitoring rules?
- Does your risk assessment identify specific high-risk products, customer types, geographies, and delivery channels — and are those the areas where your monitoring is calibrated?
- If an examiner asked why your SAR filing threshold is set where it is, could you point to risk assessment documentation that supports the choice?
- When did your risk assessment last change, and what program design changes followed from it?
For a detailed look at how FinCEN’s national priorities should already be shaping program design, see our analysis of why most BSA programs still treat the 2021 AML/CFT priorities as compliance wallpaper — the NPRM’s effectiveness standard makes the priorities integration problem much more urgent.
The Federal Reserve’s Companion NPRM
On July 7, 2026, the Federal Reserve Board issued its own NPRM to reform AML/CFT program requirements for state member banks and U.S. operations of foreign banking organizations supervised by the Fed. The comment period closed September 8, 2026 — less than two weeks ago.
The Fed’s proposal is substantively aligned with FinCEN’s: it adopts the same effectiveness-based framework and the same expectation that risk assessments drive program design. The primary distinction is institutional scope. The Fed’s rule applies specifically to state member banks and U.S. branches of foreign banking organizations, while FinCEN’s NPRM applies across covered financial institutions.
Both proposals are moving together. When final rules issue, institutions supervised by the Fed will need to comply with both the FinCEN rule and the Fed-specific rule. The comment period architecture — FinCEN’s closing in June, the Fed’s closing in September — suggests coordinated rulemaking aimed at a unified final standard.
The Enforcement Signal That’s Already There
It’s worth naming what makes this reform different from routine rulemaking: the enforcement direction has been clear for years, and the NPRM is catching the regulatory standard up to where enforcement already is.
Examiners have been asking effectiveness questions informally for years. The UBS case isn’t unusual in kind — it’s unusual in dollar amount. BSA program weaknesses that look like “technical” compliance gaps under the current standard (monitoring system scope, CDD calibration for specific risk segments, SAR conversion rates) are already what enforcement actions get built on.
The NPRM formalizes what good examiners were already evaluating. The firms that have been building effectiveness into their programs — documenting the risk assessment connection, measuring alert quality, regularly refreshing their monitoring calibration — are already positioned. The ones that built to the five-pillar minimum and called it done have the most exposure.
What Your Program Needs Before Final Rules Issue
1. A documented effectiveness narrative. Build documentation showing how your risk assessment drove program design. Not just what you have, but why you built it that way: which risk factors your monitoring rules address, which customer segments your CDD thresholds are designed for, which geographies trigger enhanced due diligence and why. This documentation is the core artifact the new standard demands.
2. Alert quality metrics. Start measuring what your transaction monitoring system actually produces: alert volume, false positive rate, SAR conversion rate, and alert aging. An examiner asking “is your monitoring effective?” needs a data answer, not a description of your system configuration.
3. A risk assessment refresh. If your BSA risk assessment was last updated more than a year ago, or doesn’t reflect material changes to your products, customer base, or delivery channels, refresh it now. FinCEN’s proposed rule makes risk assessment a compliance requirement — and the effectiveness standard means the assessment needs to reflect your current risk profile, not a snapshot from three exams ago.
For investment advisers navigating how the program reform intersects with the delayed investment adviser AML timeline, see our analysis of FinCEN’s 2028 investment adviser AML implementation delay.
So What?
The FinCEN AML/CFT program reform is not a documentation exercise. It’s a regulatory signal that BSA enforcement is shifting from “do you have the program?” to “does your program work?” — and that shift has enforcement teeth, as the $145 million UBS penalty already demonstrated under the current standard.
The final rule will set the legal timeline. But the effectiveness gap in your BSA program exists right now. The right time to close it is before an examiner asks you to explain why your risk assessment hasn’t changed your monitoring design in three years.
Start with the risk assessment. Everything else follows from there.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the FinCEN AML/CFT program reform NPRM?
What does 'effectiveness-based evaluation' mean in practice?
Where does risk assessment fit in the new framework?
What is the Federal Reserve's companion NPRM?
When does the final rule take effect?
What should BSA officers do right now to prepare?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Regulatory Compliance
FDIC Just Proposed Faster Bank Merger Reviews. Here's What Community Banks, Sponsor Banks, and Their Fintech Partners Need to Know.
The FDIC's September 17, 2026 proposed rule would cut bank merger review to as little as five business days for small deals and create a predictable 90-day track for standard transactions. Here's what state nonmember banks — and the fintechs that partner with them — need to understand before the 60-day comment window closes.
Sep 21, 2026
Regulatory Compliance
Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme
The Nodus Bank fraud mixed insider self-dealing with sanctions evasion. Here are the controls bank boards and compliance teams should test now.
Sep 21, 2026
Regulatory Compliance
Vitol Trader Sentenced in FCPA Bribery Scheme: The Payment Controls That Failed
The Vitol bribery scheme used sham invoices, shell companies, and alias email. Here is how compliance teams should test anti-bribery payment controls.
Sep 21, 2026