Feature Compliance Strategy
FinCEN's AML/CFT Program Overhaul NPRM: What the April 2026 Proposed Rule Means for Your BSA Compliance Program
FinCEN's April 2026 NPRM would fundamentally restructure AML/CFT program requirements — adding a mandatory codified risk assessment, tying programs to National AML/CFT Priorities, and replacing the checkbox compliance standard with an effectiveness-based framework. Here's what BSA officers need to know before the final rule drops.
Table of Contents
TL;DR:
- FinCEN issued a major AML/CFT program restructuring NPRM on April 7, 2026; the comment period closed June 9, 2026.
- The proposed rule adds a mandatory codified risk assessment as a fifth program pillar — institutions must document risk across products, services, channels, customer types, and geography, incorporating FinCEN’s National AML/CFT Priorities.
- The compliance standard shifts from technical rule adherence (do you have policies?) to demonstrated effectiveness (does your program actually work?).
- A 12-month implementation window is proposed after finalization — meaning BSA officers who start the risk assessment documentation work now will be well ahead of institutions that wait.
The Most Consequential BSA Change Since 2016
When FinCEN issued the Customer Due Diligence final rule in 2016 — adding the beneficial ownership requirement and formally codifying the five pillars of an AML program — it was the most significant structural change to BSA compliance in a decade. The April 2026 NPRM may be the next one.
On April 7, 2026, FinCEN published a proposed rule that would fundamentally restructure AML/CFT program requirements across all covered financial institutions. The public comment period closed June 9, 2026 — six days ago — which means the agency has everything it needs to proceed to finalization. For BSA officers and compliance teams, the window to react when this becomes final is going to be short.
[The proposed rule retains the traditional four-pillar framework but adds a mandatory, codified risk assessment as a fifth program element.](https://www.mayer brown.com/en/insights/publications/2026/04/fincen-issues-major-aml-cft-nprm) More consequentially, it replaces the current technical compliance standard with an effectiveness-based standard: your program needs to actually detect the money laundering and terrorist financing risks relevant to your institution, not just document that you have one.
Here’s what the proposed rule changes, what it keeps, and what BSA officers need to do before the final rule drops.
What’s Not Changing: The Four Pillars Stay
The traditional four-pillar structure — internal policies and controls, independent testing, a designated compliance officer, and employee training — is explicitly retained in the NPRM. Institutions that have built their programs around this framework aren’t starting over.
What changes is the compliance standard applied to each pillar. Under current rules, the technical question is: do you have documented policies? A named BSA officer? Training records? Annual independent testing? Check those boxes, and you’ve satisfied the structural requirements.
Under the proposed rule, the question becomes: do those elements actually work? Are your policies calibrated to your specific risk profile? Is your monitoring identifying the suspicious activity patterns actually relevant to your customer base and products? Does your training address the typologies your staff will actually encounter?
The practical implication: if your AML program is technically complete but operationally thin — transaction monitoring rules that were set in 2018 and never recalibrated, training that covers statutory requirements but doesn’t address your institution’s specific customer risk profile — the proposed rule creates a clearer path for examiners to characterize that as inadequate.
What’s New: The Mandatory Risk Assessment
The most operationally significant addition in the proposed rule is the mandatory, codified risk assessment. Under current requirements, risk assessments are best practice — examiner guidance and the FFIEC BSA/AML Examination Manual reference them, and sophisticated institutions maintain them. But the rule itself doesn’t require a documented risk assessment as a distinct program component.
The proposed rule specifies what the risk assessment must cover:
| Required Risk Assessment Dimension | What It Means |
|---|---|
| Products and services | Money laundering risk associated with each product type the institution offers — wires, ACH, remote deposit, crypto-linked accounts, etc. |
| Customer types | Risk profiles by customer segment — high-risk businesses, PEPs, MSBs, foreign nationals, cash-intensive businesses |
| Distribution channels | Risk introduced by digital channels, third-party originators, brokers, agent networks |
| Geographic locations | Jurisdictional risk from the institution’s service area, correspondent relationships, and customer locations |
| FinCEN National AML/CFT Priorities | Formal incorporation of FinCEN’s published national priorities into the risk assessment |
The National AML/CFT Priorities piece is mandatory, not advisory. FinCEN published its initial priorities in June 2021; the current priorities include corruption, cybercrime, human trafficking, drug trafficking, fraud, terrorist financing, and proliferation financing. Under the proposed rule, every covered institution must document how those priorities map to their specific risk profile — or explicitly document why a given priority doesn’t apply to their business.
For a community bank in rural Iowa with no international wire activity and no crypto exposure, the proliferation financing priority may genuinely have minimal relevance — but you need to document why, not just ignore it.
The Effectiveness Standard: What It Changes in Practice
The shift from technical compliance to an effectiveness standard is the change that will drive the most examiner scrutiny — and the most operational work for BSA teams.
Under the proposed effectiveness framework, regulators will evaluate whether your program is:
Risk-calibrated. Your controls should reflect your institution’s actual risk profile. A bank that originates significant volume from money services business customers but runs the same monitoring rules as a bank with no MSB customers is not calibrated to its risk. The examiner question becomes: show me how your monitoring threshold and typology coverage reflect your customer mix.
Responsive. When SAR filings, examination findings, law enforcement feedback, or FinCEN advisories signal that a particular typology is active in your market, your program should respond. Institutions that haven’t updated their monitoring rules or typology coverage in response to published FinCEN guidance on active fraud typologies are going to have a harder time demonstrating effectiveness.
Documented. Effectiveness isn’t just operational — it’s documented. If your compliance officer made a deliberate decision to prioritize monitoring for trade-based money laundering because your customer base includes significant import/export businesses, that reasoning should be documented in the risk assessment. “We just know our customers” isn’t a compliance record.
FinCEN’s proposed rule explicitly contemplates a two-tiered enforcement approach: significant or systemic program failures trigger enforcement, while isolated deficiencies are addressed through examination. This is real protection for programs making good-faith efforts with minor gaps — but it’s not protection for programs that haven’t done the risk assessment work and can’t demonstrate calibration.
Who’s Covered and What That Means Across Institution Types
The proposed rule applies across all FinCEN-supervised institution types, but the practical implications differ:
Banks and credit unions — For most banks, the structural challenge is documentation depth. Banks generally have AML programs; what they often lack is a formal, written risk assessment that explicitly ties the program’s controls to the institution’s specific risk dimensions. The proposed rule requires that linkage to be documented and demonstrable.
Money services businesses (MSBs) — MSBs face the largest adjustment. Many MSBs — particularly smaller check cashers, money transmitters, and prepaid providers — have relied on relatively minimal program documentation. The effectiveness standard and mandatory risk assessment raise the bar significantly for institutions that have operated with thin compliance infrastructure.
Broker-dealers and investment advisers — The proposed rule’s scope reinforces FinCEN’s ongoing attention to investment product money laundering risks, including layering through securities accounts and the use of investment products in beneficial ownership structuring.
Insurance companies — Insurance companies subject to BSA requirements (primarily those issuing permanent life products) face a risk assessment requirement that specifically needs to address distribution channel risk — agent networks introduce third-party AML risk that the formal risk assessment must capture.
Fintechs and lending-as-a-service operators — For fintech lenders operating through bank partnership structures, the proposed rule adds clarity to the question of program responsibility. Where the fintech is itself a covered institution (as an MSB or state-licensed lender), it has its own program obligation that must meet the effectiveness standard. Bank partners with significant fintech origination volume should review whether their BSA programs adequately address the customer risk introduced through those channels.
The Implementation Window: Why Starting Now Matters
FinCEN’s proposed 12-month implementation window — running from finalization of the rule — is more aggressive than it sounds. Here’s the practical math:
The comment period closed June 9, 2026. Regulatory finalization, given FinCEN’s review of comments and drafting of the final rule, typically takes 6 to 18 months after the comment period closes. Assume a final rule in late 2026 or early 2027. Add 12 months for implementation. That puts compliance expected by late 2027 or early 2028 — which is roughly 18 months away at best.
Eighteen months is not a long runway for institutions that need to:
- Conduct a formal, documented AML/CFT risk assessment for the first time
- Map FinCEN’s National Priorities to their specific business lines and risk profile
- Recalibrate monitoring rules to reflect the risk assessment findings
- Update BSA/AML policies to reflect the effectiveness standard
- Brief the board and senior management on the program changes
For institutions that already maintain a documented risk assessment and have periodic recalibration processes, this is primarily a documentation exercise and a gap analysis. For institutions starting from scratch, 18 months is tight.
Three Things BSA Officers Should Do Before the Final Rule
1. Draft your risk assessment now, even if it’s informal. The proposed rule’s risk assessment requirements are not surprising — they track the FFIEC examination manual’s existing guidance on what a risk assessment should cover. Draft a version now, covering the five dimensions (products, customers, channels, geography, national priorities). When the final rule drops, you’ll have a starting point rather than a blank page, and you’ll have already surfaced the gaps in your current program documentation.
2. Map your monitoring rules to your risk assessment. The effectiveness standard requires that your controls be calibrated to your risk profile. Pull your current transaction monitoring alert rules and typology coverage, and compare them against the risk dimensions in your risk assessment. Where are the mismatches? High-risk customer segments with no dedicated typology coverage? Products with known money laundering exposure and no monitoring rule tuned to that product? Document the mapping now.
3. Review your independent testing scope. The BSA/AML independent testing requirements should validate program effectiveness, not just check whether a BSA officer exists and policies are in place. If your most recent audit or testing report focused on documentation completeness rather than operational effectiveness, it may not satisfy the proposed standard. Frame this with your auditors before the final rule requires it of you.
Connecting the Risk Assessment to Your Broader Compliance Program
The mandatory risk assessment isn’t just a FinCEN compliance deliverable — it’s the foundation that makes the rest of your BSA program defensible. A well-documented risk assessment is the document that:
- Justifies your monitoring rule thresholds to an examiner who asks why you set the SAR review threshold where you did
- Explains your staffing levels relative to your transaction volume and risk profile
- Documents your rationale for the customer risk rating cutoffs in your KYC policy and CDD procedures
- Supports your ALLL/ACL qualitative factors if you’re a bank with significant BSA-sensitive lending exposures
For the BSA/AML KRIs that your monitoring generates — SAR filing rates, alert volumes, false positive ratios — the risk assessment is the context that explains what those metrics should look like for your institution specifically. An examiner who sees a SAR rate that looks low relative to peers will ask about it; your risk assessment is the document that explains why your rate is appropriate for your risk profile.
So What? The Effectiveness Standard Is Already the Real Standard
Here’s the practical reality: FinCEN examiners and federal banking regulators have been applying an effectiveness-based evaluation to AML programs for years. The proposed rule codifies what sophisticated BSA officers already know — “we have a program” isn’t enough, and “the program finds the actual suspicious activity” is the real test.
What the NPRM does is make the effectiveness standard explicit in the rule text and add the mandatory risk assessment as the formal mechanism for documenting how your controls connect to your risk profile. This creates both a compliance obligation and a paper trail — an institution that has done the risk assessment work now has a document that demonstrates effectiveness; an institution that hasn’t has both a compliance gap and a documentation gap.
The public comment period has closed. FinCEN is reviewing comments and working toward a final rule. The 12-month implementation window will feel short when it starts — the time to begin the risk assessment work is now.
For the operational templates that support BSA program documentation — risk assessment frameworks, compliance program structures, and monitoring documentation tools — the Compliance Essentials bundle includes the program components that map to both current FFIEC expectations and the proposed AML/CFT effectiveness standard.
Sources: FinCEN AML/CFT Program NPRM Fact Sheet (April 2026); Mayer Brown — FinCEN Issues Major AML/CFT NPRM; Covington & Burling — FinCEN Proposes Sweeping Changes to AML/CFT Program Requirements; Norton Rose Fulbright — FinCEN AML/CFT NPRM: Risk Assessment Codification; Jones Day — FinCEN AML/CFT NPRM: Enforcement Implications
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does FinCEN's April 2026 AML/CFT NPRM propose to change?
Who does the FinCEN AML/CFT NPRM apply to?
What is required under the proposed mandatory risk assessment?
What is the 'effectiveness' standard in the proposed rule and how is it different from current requirements?
When would the FinCEN AML/CFT NPRM take effect, and what is the implementation timeline?
How does the two-tiered enforcement standard in the proposed rule affect compliance risk?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Compliance Strategy
Policy Exception Management: Stop Temporary Waivers From Becoming the Real Policy
Add policy exception management to your policy management framework with approvals, compensating controls, expiry, and a waiver register.
Jul 25, 2026
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026