Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Regulatory Compliance

FinCEN's A7 Network Rule: A Rejection Control, Not Another Watchlist Refresh

FinCEN's A7 Network rule and Alert007 require payment rejection, sub-agent screening, notice evidence, and new sanctions-evasion monitoring.

By Rebecca Leung · October 1, 2026 ·
Table of Contents

TL;DR

  • On October 1, FinCEN issued Alert FIN-2026-Alert007 and proposed a rule that would prohibit covered financial institutions from transmitting funds involving identified A7 Network sub-agents.
  • This is broader than an SDN-list refresh. The proposed control set includes a nonpublic sub-agent list delivered through FinCEN’s FI-Portal, payment rejection, notice to directly affected customers or counterparties, risk-based due diligence, and documented evidence.
  • The alert is already actionable. It supplies specific indicators involving shell companies, suspicious invoice features, VPN infrastructure, A7A5 exposure, stablecoin liquidity providers, and the SAR keyword FIN-2026-A7NETWORK.
  • BSA Officers should split the response into two tracks: current alert implementation and proposed-rule readiness. Combining them in one vague “sanctions update” ticket will miss critical owners and evidence.

FinCEN’s A7 Network rule is not another name-screening exercise. It is a proposed payment-rejection regime aimed at companies designed to look like ordinary counterparties.

On October 1, 2026, the Financial Crimes Enforcement Network announced a coordinated package under Treasury’s Operation Economic Outcast. FinCEN issued Alert FIN-2026-Alert007 and a notice of proposed rulemaking under section 9714. OFAC simultaneously sanctioned the A7 Network as a significant transnational criminal organization.

The distinction between those artifacts matters:

  • The OFAC action creates blocking obligations under existing sanctions rules.
  • The FinCEN alert asks institutions now to detect and report suspicious activity tied to the network.
  • The proposed FinCEN rule would prohibit certain transmittals involving identified sub-agents and add notice, screening and documentation duties if finalized.

That three-part response is operationally messy. It crosses sanctions screening, transaction monitoring, correspondent banking, trade finance, fraud document review, digital-asset analytics, customer communications and regulatory change management. One owner cannot close it with a list-upload screenshot.

What is the A7 Network?

FinCEN describes A7 as a wholesale sanctions-evasion and money-laundering service with ties to Russia. Its customers can satisfy international payment obligations without the sanctioned Russian or Iranian party appearing in the external payment chain.

The mechanism is more important than the label. According to pages 2 through 4 of FIN-2026-Alert007, a customer supplies payment and trade details to A7. The network records value internally through settlement mechanisms such as bills of exchange, then assigns a sub-agent to appear on invoices, sales agreements and payment instructions. A non-Russian account sends the fiat payment through correspondent banking and SWIFT. Separately, digital assets—including the ruble-backed A7A5 stablecoin—can move value inside the network.

The result is a mirror structure: an apparently ordinary third-country company pays a supplier while A7 settles with the sanctioned customer elsewhere.

FinCEN says that, as of June 2026, A7 operated hundreds of companies with accounts at approximately 435 financial institutions in at least 83 countries. The alert also states that more than 180 entities processed at least $179.1 billion in A7A5 transactions between February 2025 and June 2026. Those are FinCEN’s figures, not estimates produced by this article.

The network touches both traditional and digital rails:

LayerWhat FinCEN describesControl implication
Customer-facing tradeSub-agent appears as buyer, seller or payerVerify counterparty business profile against goods, invoices and shipping evidence
Fiat settlementThird-country bank accounts use correspondent and SWIFT channelsScreen all payment parties and investigate unexplained multi-jurisdiction routing
Internal value ledgerA7A5 and other mechanisms balance obligations within the networkDo not assume the token must appear directly in a U.S. institution’s records
Liquidity conversionA7A5 may bridge into USDT or fiat through exchanges and OTC brokersMonitor newly formed or fast-growing stablecoin businesses in relevant jurisdictions
ConcealmentVPNs, shells, false records and AI-altered invoices hide Russian controlJoin device, customer, transaction and document signals in one investigation

This is distinct from the Iranian aviation typologies in the site’s earlier Operation Economic Outcast sanctions-screening analysis. The earlier alert centered on aviation procurement. The new A7 action targets payment infrastructure that can service Iran, North Korea, ransomware actors, Russian illicit finance and other customers.

What FinCEN’s A7 Network rule would require

The proposed rule is RIN 1506-AB77, proposed 31 CFR 1010.668. Comments are due 30 days after Federal Register publication; the pre-publication version did not yet supply the calendar date.

1. Reject covered transmittals

The proposal would prohibit a covered financial institution from sending or receiving funds involving an identified A7 sub-agent. “Funds” includes convertible virtual currency. The prohibition reaches a transfer to or from a sub-agent and a transfer involving an account or CVC address administered for one.

The proposed response is generally rejection, but OFAC blocking still takes priority. The NPRM states that if sanctions require property to be blocked, the institution should block and report to OFAC; doing so would satisfy the proposed FinCEN measure.

That is a procedure-writing trap. A frontline analyst needs a decision tree that distinguishes:

  1. possible sub-agent alert requiring investigation;
  2. identified FinCEN-list sub-agent requiring rejection if the rule is final and applicable;
  3. blocked person, owned entity or blocked property requiring OFAC blocking and reporting; and
  4. suspicious but legally processable activity requiring escalation and possible SAR filing.

A single “decline/close” disposition cannot evidence those different legal outcomes.

2. Screen against a secure list

FinCEN proposes to distribute a periodically updated sub-agent list through its FI-Portal, not publish the complete list openly. The public proposal names Galadriel Trading FZCO, Gimli Trade LLC-FZ, Hydrofusion Resources FZ-LLC, Pearl Bridge, Power Sphere LLC-FZ and Sigizmund FZCO, while anticipating additions and removals.

That creates a new change-control problem. Institutions need a named owner who retrieves the secure update, validates it, converts it into the screening platform’s accepted format, tests record counts and matching behavior, records deployment time and preserves the superseded version.

The anti-gaming test is simple: select a sample from the source list and prove each record is searchable in production. A ticket saying “vendor updated” is not enough.

3. Notify directly affected parties

If an institution knows or has reason to believe a prohibited transfer involves a listed sub-agent, the proposal would require notice to affected persons with whom the institution has a direct commercial relationship. The NPRM contemplates mail, fax or email and does not propose a certification requirement.

Operations and Legal should prepare controlled language, but the workflow also needs evidence: who received notice, when, through which channel, tied to which transaction and legal disposition. FinCEN proposes that institutions document compliance with the notification requirement.

4. Apply risk-based due diligence

The proposal expects procedures designed to identify use of accounts for sub-agent transactions and an appropriate screening mechanism. FinCEN says existing commercially available sanctions-screening tools may be used. That does not eliminate the current alert’s behavioral work: known-list screening will catch identified entities, while transaction and document indicators help surface the next sub-agent.

Alert007 gives investigators unusually concrete indicators

The eight-page alert is unusually implementable. It gives exact infrastructure and document clues rather than telling institutions merely to watch for “complex transactions.”

Sub-agent and account behavior

FinCEN flags recently formed companies generating unusually high volumes of large transactions over short periods, payments layered through shells without a clear purpose, and counterparties spread across unrelated business lines. It identifies Hong Kong, Indonesia, the Kyrgyz Republic, Seychelles, Türkiye and the UAE as jurisdictions where A7 has formed, acquired or partnered with companies.

The alert also identifies domains muzpan[.]com and sodkamus[.]com, plus specified serving IP ranges. Cybersecurity or fraud teams may already collect login IP and email-domain data that AML investigators cannot see. The control fix is not a new siloed rule; it is a case-enrichment feed that makes those signals available to the BSA investigation.

Invoice manipulation

FinCEN highlights invoice templates that differ from prior standards, vague product details, implausible total prices, nonsensical dates, an analog company stamp on an otherwise digital document, stray Cyrillic characters, and malformed letters or seals suggesting AI alteration.

Trade finance should turn those into review prompts. For higher-risk customers, preserve both the submitted file and extracted metadata. A PDF screenshot stripped of creation history makes the investigator’s job harder.

Digital-asset conversion

Direct A7A5 visibility may be rare at a U.S. bank. FinCEN says A7A5 can move into USDT and then fiat, and flags OTC or stablecoin businesses that suddenly expand in jurisdictions with A7 touchpoints. Investigators should avoid a false binary of “A7A5 detected / not detected.” Indirect liquidity behavior is the more likely U.S. touchpoint.

For relevant SARs, include FIN-2026-A7NETWORK in field 2 and the narrative. This is separate from the FIN-2026-IRANAIR keyword used for the September aviation alert.

A 30-day control build that produces evidence

TimingActionOwnerEvidence
Days 1–3Issue an alert implementation memo separating current SAR guidance from proposed-rule obligationsBSA Officer and Sanctions OfficerApproved applicability memo and workstream owners
Days 1–5Add FIN-2026-A7NETWORK to SAR procedures and quality assuranceSAR GovernanceUpdated procedure, test SAR and QA check
Days 3–10Map every Alert007 indicator to an existing rule, investigator prompt, data field or documented gapTransaction MonitoringCoverage matrix with accountable gaps
Days 5–15Test access, retrieval and controlled ingestion for FI-Portal updatesRegulatory Change and Screening OpsAccess test, runbook, sample reconciliation
Days 10–20Draft reject/block/escalate decision tree and affected-party notice workflowLegal, Sanctions and Payments OpsApproved decision tree, notice template and evidence fields
Days 15–25Run a targeted lookback based on jurisdiction, shell-company, invoice and stablecoin-liquidity combinationsAML InvestigationsPopulation logic, case list and disposition rationale
Days 20–30Tabletop one fiat wire and one inbound CVC scenarioBSA Officer, Payments, Digital Assets and LegalScenario record, timing, defects and remediation tickets

Thresholds for a lookback should be calibrated to the institution’s products and history. Start with combinations, not single indicators: a newly formed Kyrgyz company plus sharp payment growth plus unrelated counterparties is stronger than geography alone. Validate the population by mapping source transactions to generated cases so no one can improve the alert rate by silently excluding a payment channel.

The practical risk is treating a proposal as tomorrow’s problem. The prohibition may change before finalization, but the alert, SAR keyword and public red flags exist now. The data and ownership work needed for a future secure-list rejection process will not appear overnight.

For teams updating their documented exposure, controls and residual risk, the AML/BSA Risk Assessment Template provides a structured assessment and control inventory rather than another loose alert memo.

Sources

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did FinCEN propose for transactions involving the A7 Network?
FinCEN proposed 31 CFR 1010.668, which would prohibit covered financial institutions from sending or receiving funds, including convertible virtual currency, involving A7 Network sub-agents identified by FinCEN. The proposal also includes customer or counterparty notification, risk-based due diligence, screening, and documentation requirements. It is a proposal, not yet a final rule.
What is the SAR keyword in FinCEN Alert FIN-2026-Alert007?
FinCEN asks financial institutions to include FIN-2026-A7NETWORK in SAR field 2, Filing Institution Note to FinCEN, and in the narrative when reporting suspicious activity related to the A7 Network.
Is an A7 Network transaction rejected or blocked?
The proposed FinCEN rule generally requires covered financial institutions to reject prohibited transmittals involving identified sub-agents. Existing OFAC obligations still control when property is blocked under sanctions: the institution should block and report to OFAC, and that action would satisfy the proposed special measure.
Who would be covered by FinCEN's proposed A7 Network rule?
The proposal uses the broad definition of financial institution in 31 CFR 1010.100(t). It is not limited to banks. Applicability should be assessed by each institution's legal and BSA compliance teams against the final rule if adopted.
What should financial institutions do now?
Treat the alert as current even while the prohibition remains proposed: add the SAR keyword, map the published red flags to monitoring and investigations, test trade-document review, assess A7A5 and related stablecoin exposure, establish ownership for FinCEN FI-Portal list updates, and design rejection and notification evidence before a final rule arrives.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.