Feature Regulatory Compliance
FinCEN's A7 Network Rule: A Rejection Control, Not Another Watchlist Refresh
FinCEN's A7 Network rule and Alert007 require payment rejection, sub-agent screening, notice evidence, and new sanctions-evasion monitoring.
Table of Contents
TL;DR
- On October 1, FinCEN issued Alert FIN-2026-Alert007 and proposed a rule that would prohibit covered financial institutions from transmitting funds involving identified A7 Network sub-agents.
- This is broader than an SDN-list refresh. The proposed control set includes a nonpublic sub-agent list delivered through FinCEN’s FI-Portal, payment rejection, notice to directly affected customers or counterparties, risk-based due diligence, and documented evidence.
- The alert is already actionable. It supplies specific indicators involving shell companies, suspicious invoice features, VPN infrastructure, A7A5 exposure, stablecoin liquidity providers, and the SAR keyword FIN-2026-A7NETWORK.
- BSA Officers should split the response into two tracks: current alert implementation and proposed-rule readiness. Combining them in one vague “sanctions update” ticket will miss critical owners and evidence.
FinCEN’s A7 Network rule is not another name-screening exercise. It is a proposed payment-rejection regime aimed at companies designed to look like ordinary counterparties.
On October 1, 2026, the Financial Crimes Enforcement Network announced a coordinated package under Treasury’s Operation Economic Outcast. FinCEN issued Alert FIN-2026-Alert007 and a notice of proposed rulemaking under section 9714. OFAC simultaneously sanctioned the A7 Network as a significant transnational criminal organization.
The distinction between those artifacts matters:
- The OFAC action creates blocking obligations under existing sanctions rules.
- The FinCEN alert asks institutions now to detect and report suspicious activity tied to the network.
- The proposed FinCEN rule would prohibit certain transmittals involving identified sub-agents and add notice, screening and documentation duties if finalized.
That three-part response is operationally messy. It crosses sanctions screening, transaction monitoring, correspondent banking, trade finance, fraud document review, digital-asset analytics, customer communications and regulatory change management. One owner cannot close it with a list-upload screenshot.
What is the A7 Network?
FinCEN describes A7 as a wholesale sanctions-evasion and money-laundering service with ties to Russia. Its customers can satisfy international payment obligations without the sanctioned Russian or Iranian party appearing in the external payment chain.
The mechanism is more important than the label. According to pages 2 through 4 of FIN-2026-Alert007, a customer supplies payment and trade details to A7. The network records value internally through settlement mechanisms such as bills of exchange, then assigns a sub-agent to appear on invoices, sales agreements and payment instructions. A non-Russian account sends the fiat payment through correspondent banking and SWIFT. Separately, digital assets—including the ruble-backed A7A5 stablecoin—can move value inside the network.
The result is a mirror structure: an apparently ordinary third-country company pays a supplier while A7 settles with the sanctioned customer elsewhere.
FinCEN says that, as of June 2026, A7 operated hundreds of companies with accounts at approximately 435 financial institutions in at least 83 countries. The alert also states that more than 180 entities processed at least $179.1 billion in A7A5 transactions between February 2025 and June 2026. Those are FinCEN’s figures, not estimates produced by this article.
The network touches both traditional and digital rails:
| Layer | What FinCEN describes | Control implication |
|---|---|---|
| Customer-facing trade | Sub-agent appears as buyer, seller or payer | Verify counterparty business profile against goods, invoices and shipping evidence |
| Fiat settlement | Third-country bank accounts use correspondent and SWIFT channels | Screen all payment parties and investigate unexplained multi-jurisdiction routing |
| Internal value ledger | A7A5 and other mechanisms balance obligations within the network | Do not assume the token must appear directly in a U.S. institution’s records |
| Liquidity conversion | A7A5 may bridge into USDT or fiat through exchanges and OTC brokers | Monitor newly formed or fast-growing stablecoin businesses in relevant jurisdictions |
| Concealment | VPNs, shells, false records and AI-altered invoices hide Russian control | Join device, customer, transaction and document signals in one investigation |
This is distinct from the Iranian aviation typologies in the site’s earlier Operation Economic Outcast sanctions-screening analysis. The earlier alert centered on aviation procurement. The new A7 action targets payment infrastructure that can service Iran, North Korea, ransomware actors, Russian illicit finance and other customers.
What FinCEN’s A7 Network rule would require
The proposed rule is RIN 1506-AB77, proposed 31 CFR 1010.668. Comments are due 30 days after Federal Register publication; the pre-publication version did not yet supply the calendar date.
1. Reject covered transmittals
The proposal would prohibit a covered financial institution from sending or receiving funds involving an identified A7 sub-agent. “Funds” includes convertible virtual currency. The prohibition reaches a transfer to or from a sub-agent and a transfer involving an account or CVC address administered for one.
The proposed response is generally rejection, but OFAC blocking still takes priority. The NPRM states that if sanctions require property to be blocked, the institution should block and report to OFAC; doing so would satisfy the proposed FinCEN measure.
That is a procedure-writing trap. A frontline analyst needs a decision tree that distinguishes:
- possible sub-agent alert requiring investigation;
- identified FinCEN-list sub-agent requiring rejection if the rule is final and applicable;
- blocked person, owned entity or blocked property requiring OFAC blocking and reporting; and
- suspicious but legally processable activity requiring escalation and possible SAR filing.
A single “decline/close” disposition cannot evidence those different legal outcomes.
2. Screen against a secure list
FinCEN proposes to distribute a periodically updated sub-agent list through its FI-Portal, not publish the complete list openly. The public proposal names Galadriel Trading FZCO, Gimli Trade LLC-FZ, Hydrofusion Resources FZ-LLC, Pearl Bridge, Power Sphere LLC-FZ and Sigizmund FZCO, while anticipating additions and removals.
That creates a new change-control problem. Institutions need a named owner who retrieves the secure update, validates it, converts it into the screening platform’s accepted format, tests record counts and matching behavior, records deployment time and preserves the superseded version.
The anti-gaming test is simple: select a sample from the source list and prove each record is searchable in production. A ticket saying “vendor updated” is not enough.
3. Notify directly affected parties
If an institution knows or has reason to believe a prohibited transfer involves a listed sub-agent, the proposal would require notice to affected persons with whom the institution has a direct commercial relationship. The NPRM contemplates mail, fax or email and does not propose a certification requirement.
Operations and Legal should prepare controlled language, but the workflow also needs evidence: who received notice, when, through which channel, tied to which transaction and legal disposition. FinCEN proposes that institutions document compliance with the notification requirement.
4. Apply risk-based due diligence
The proposal expects procedures designed to identify use of accounts for sub-agent transactions and an appropriate screening mechanism. FinCEN says existing commercially available sanctions-screening tools may be used. That does not eliminate the current alert’s behavioral work: known-list screening will catch identified entities, while transaction and document indicators help surface the next sub-agent.
Alert007 gives investigators unusually concrete indicators
The eight-page alert is unusually implementable. It gives exact infrastructure and document clues rather than telling institutions merely to watch for “complex transactions.”
Sub-agent and account behavior
FinCEN flags recently formed companies generating unusually high volumes of large transactions over short periods, payments layered through shells without a clear purpose, and counterparties spread across unrelated business lines. It identifies Hong Kong, Indonesia, the Kyrgyz Republic, Seychelles, Türkiye and the UAE as jurisdictions where A7 has formed, acquired or partnered with companies.
The alert also identifies domains muzpan[.]com and sodkamus[.]com, plus specified serving IP ranges. Cybersecurity or fraud teams may already collect login IP and email-domain data that AML investigators cannot see. The control fix is not a new siloed rule; it is a case-enrichment feed that makes those signals available to the BSA investigation.
Invoice manipulation
FinCEN highlights invoice templates that differ from prior standards, vague product details, implausible total prices, nonsensical dates, an analog company stamp on an otherwise digital document, stray Cyrillic characters, and malformed letters or seals suggesting AI alteration.
Trade finance should turn those into review prompts. For higher-risk customers, preserve both the submitted file and extracted metadata. A PDF screenshot stripped of creation history makes the investigator’s job harder.
Digital-asset conversion
Direct A7A5 visibility may be rare at a U.S. bank. FinCEN says A7A5 can move into USDT and then fiat, and flags OTC or stablecoin businesses that suddenly expand in jurisdictions with A7 touchpoints. Investigators should avoid a false binary of “A7A5 detected / not detected.” Indirect liquidity behavior is the more likely U.S. touchpoint.
For relevant SARs, include FIN-2026-A7NETWORK in field 2 and the narrative. This is separate from the FIN-2026-IRANAIR keyword used for the September aviation alert.
A 30-day control build that produces evidence
| Timing | Action | Owner | Evidence |
|---|---|---|---|
| Days 1–3 | Issue an alert implementation memo separating current SAR guidance from proposed-rule obligations | BSA Officer and Sanctions Officer | Approved applicability memo and workstream owners |
| Days 1–5 | Add FIN-2026-A7NETWORK to SAR procedures and quality assurance | SAR Governance | Updated procedure, test SAR and QA check |
| Days 3–10 | Map every Alert007 indicator to an existing rule, investigator prompt, data field or documented gap | Transaction Monitoring | Coverage matrix with accountable gaps |
| Days 5–15 | Test access, retrieval and controlled ingestion for FI-Portal updates | Regulatory Change and Screening Ops | Access test, runbook, sample reconciliation |
| Days 10–20 | Draft reject/block/escalate decision tree and affected-party notice workflow | Legal, Sanctions and Payments Ops | Approved decision tree, notice template and evidence fields |
| Days 15–25 | Run a targeted lookback based on jurisdiction, shell-company, invoice and stablecoin-liquidity combinations | AML Investigations | Population logic, case list and disposition rationale |
| Days 20–30 | Tabletop one fiat wire and one inbound CVC scenario | BSA Officer, Payments, Digital Assets and Legal | Scenario record, timing, defects and remediation tickets |
Thresholds for a lookback should be calibrated to the institution’s products and history. Start with combinations, not single indicators: a newly formed Kyrgyz company plus sharp payment growth plus unrelated counterparties is stronger than geography alone. Validate the population by mapping source transactions to generated cases so no one can improve the alert rate by silently excluding a payment channel.
The practical risk is treating a proposal as tomorrow’s problem. The prohibition may change before finalization, but the alert, SAR keyword and public red flags exist now. The data and ownership work needed for a future secure-list rejection process will not appear overnight.
For teams updating their documented exposure, controls and residual risk, the AML/BSA Risk Assessment Template provides a structured assessment and control inventory rather than another loose alert memo.
Sources
- FinCEN, “Operation Economic Outcast Takes Unprecedented Action Against Sanctions Evasion Network Used by Iran,” October 1, 2026
- FinCEN Alert FIN-2026-Alert007, “FinCEN Alert on the A7 Network,” October 1, 2026
- FinCEN NPRM, RIN 1506-AB77, proposed 31 CFR 1010.668
- U.S. Treasury, Operation Economic Outcast coordinated action
- OFAC recent action, October 1, 2026
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did FinCEN propose for transactions involving the A7 Network?
What is the SAR keyword in FinCEN Alert FIN-2026-Alert007?
Is an A7 Network transaction rejected or blocked?
Who would be covered by FinCEN's proposed A7 Network rule?
What should financial institutions do now?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Regulatory Compliance
SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake
SEC v. Meyer Global turns a missed SpaceX capital call into a control lesson for private fund advisers. Here is what compliance teams should test.
Oct 1, 2026
Regulatory Compliance
SEC Private Markets Proposal: What Fund Sponsors Must Build Before Retailization Becomes a Product
The SEC private markets proposal could expand performance fees, interval funds and accredited-investor pathways. Here is the control build list.
Oct 1, 2026
Regulatory Compliance
Travel + Leisure SEC Settlement: The $77M Loan-Portfolio Disclosure Failure
Travel + Leisure's SEC settlement shows how targeted loan removals can turn a portfolio metric into a disclosure-controls failure.
Sep 30, 2026