Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

FinCEN's AML/CFT Program Overhaul NPRM: What the April 2026 Proposed Rule Means for Your BSA Compliance Program

FinCEN's April 2026 NPRM would fundamentally restructure AML/CFT program requirements — adding a mandatory codified risk assessment, tying programs to National AML/CFT Priorities, and replacing the checkbox compliance standard with an effectiveness-based framework. Here's what BSA officers need to know before the final rule drops.

By Rebecca Leung · June 14, 2026 ·
Table of Contents

TL;DR:

  • FinCEN issued a major AML/CFT program restructuring NPRM on April 7, 2026; the comment period closed June 9, 2026.
  • The proposed rule adds a mandatory codified risk assessment as a fifth program pillar — institutions must document risk across products, services, channels, customer types, and geography, incorporating FinCEN’s National AML/CFT Priorities.
  • The compliance standard shifts from technical rule adherence (do you have policies?) to demonstrated effectiveness (does your program actually work?).
  • A 12-month implementation window is proposed after finalization — meaning BSA officers who start the risk assessment documentation work now will be well ahead of institutions that wait.

The Most Consequential BSA Change Since 2016

When FinCEN issued the Customer Due Diligence final rule in 2016 — adding the beneficial ownership requirement and formally codifying the five pillars of an AML program — it was the most significant structural change to BSA compliance in a decade. The April 2026 NPRM may be the next one.

On April 7, 2026, FinCEN published a proposed rule that would fundamentally restructure AML/CFT program requirements across all covered financial institutions. The public comment period closed June 9, 2026 — six days ago — which means the agency has everything it needs to proceed to finalization. For BSA officers and compliance teams, the window to react when this becomes final is going to be short.

[The proposed rule retains the traditional four-pillar framework but adds a mandatory, codified risk assessment as a fifth program element.](https://www.mayer brown.com/en/insights/publications/2026/04/fincen-issues-major-aml-cft-nprm) More consequentially, it replaces the current technical compliance standard with an effectiveness-based standard: your program needs to actually detect the money laundering and terrorist financing risks relevant to your institution, not just document that you have one.

Here’s what the proposed rule changes, what it keeps, and what BSA officers need to do before the final rule drops.

What’s Not Changing: The Four Pillars Stay

The traditional four-pillar structure — internal policies and controls, independent testing, a designated compliance officer, and employee training — is explicitly retained in the NPRM. Institutions that have built their programs around this framework aren’t starting over.

What changes is the compliance standard applied to each pillar. Under current rules, the technical question is: do you have documented policies? A named BSA officer? Training records? Annual independent testing? Check those boxes, and you’ve satisfied the structural requirements.

Under the proposed rule, the question becomes: do those elements actually work? Are your policies calibrated to your specific risk profile? Is your monitoring identifying the suspicious activity patterns actually relevant to your customer base and products? Does your training address the typologies your staff will actually encounter?

FinCEN’s proposed effectiveness standard doesn’t eliminate the four pillars — it raises the bar for what satisfies them.

The practical implication: if your AML program is technically complete but operationally thin — transaction monitoring rules that were set in 2018 and never recalibrated, training that covers statutory requirements but doesn’t address your institution’s specific customer risk profile — the proposed rule creates a clearer path for examiners to characterize that as inadequate.

What’s New: The Mandatory Risk Assessment

The most operationally significant addition in the proposed rule is the mandatory, codified risk assessment. Under current requirements, risk assessments are best practice — examiner guidance and the FFIEC BSA/AML Examination Manual reference them, and sophisticated institutions maintain them. But the rule itself doesn’t require a documented risk assessment as a distinct program component.

The NPRM would change that by formally codifying the risk assessment as a required element of every covered institution’s AML/CFT program.

The proposed rule specifies what the risk assessment must cover:

Required Risk Assessment DimensionWhat It Means
Products and servicesMoney laundering risk associated with each product type the institution offers — wires, ACH, remote deposit, crypto-linked accounts, etc.
Customer typesRisk profiles by customer segment — high-risk businesses, PEPs, MSBs, foreign nationals, cash-intensive businesses
Distribution channelsRisk introduced by digital channels, third-party originators, brokers, agent networks
Geographic locationsJurisdictional risk from the institution’s service area, correspondent relationships, and customer locations
FinCEN National AML/CFT PrioritiesFormal incorporation of FinCEN’s published national priorities into the risk assessment

The National AML/CFT Priorities piece is mandatory, not advisory. FinCEN published its initial priorities in June 2021; the current priorities include corruption, cybercrime, human trafficking, drug trafficking, fraud, terrorist financing, and proliferation financing. Under the proposed rule, every covered institution must document how those priorities map to their specific risk profile — or explicitly document why a given priority doesn’t apply to their business.

For a community bank in rural Iowa with no international wire activity and no crypto exposure, the proliferation financing priority may genuinely have minimal relevance — but you need to document why, not just ignore it.

The Effectiveness Standard: What It Changes in Practice

The shift from technical compliance to an effectiveness standard is the change that will drive the most examiner scrutiny — and the most operational work for BSA teams.

Under the proposed effectiveness framework, regulators will evaluate whether your program is:

Risk-calibrated. Your controls should reflect your institution’s actual risk profile. A bank that originates significant volume from money services business customers but runs the same monitoring rules as a bank with no MSB customers is not calibrated to its risk. The examiner question becomes: show me how your monitoring threshold and typology coverage reflect your customer mix.

Responsive. When SAR filings, examination findings, law enforcement feedback, or FinCEN advisories signal that a particular typology is active in your market, your program should respond. Institutions that haven’t updated their monitoring rules or typology coverage in response to published FinCEN guidance on active fraud typologies are going to have a harder time demonstrating effectiveness.

Documented. Effectiveness isn’t just operational — it’s documented. If your compliance officer made a deliberate decision to prioritize monitoring for trade-based money laundering because your customer base includes significant import/export businesses, that reasoning should be documented in the risk assessment. “We just know our customers” isn’t a compliance record.

FinCEN’s proposed rule explicitly contemplates a two-tiered enforcement approach: significant or systemic program failures trigger enforcement, while isolated deficiencies are addressed through examination. This is real protection for programs making good-faith efforts with minor gaps — but it’s not protection for programs that haven’t done the risk assessment work and can’t demonstrate calibration.

Who’s Covered and What That Means Across Institution Types

The proposed rule applies across all FinCEN-supervised institution types, but the practical implications differ:

Banks and credit unions — For most banks, the structural challenge is documentation depth. Banks generally have AML programs; what they often lack is a formal, written risk assessment that explicitly ties the program’s controls to the institution’s specific risk dimensions. The proposed rule requires that linkage to be documented and demonstrable.

Money services businesses (MSBs) — MSBs face the largest adjustment. Many MSBs — particularly smaller check cashers, money transmitters, and prepaid providers — have relied on relatively minimal program documentation. The effectiveness standard and mandatory risk assessment raise the bar significantly for institutions that have operated with thin compliance infrastructure.

Broker-dealers and investment advisers — The proposed rule’s scope reinforces FinCEN’s ongoing attention to investment product money laundering risks, including layering through securities accounts and the use of investment products in beneficial ownership structuring.

Insurance companies — Insurance companies subject to BSA requirements (primarily those issuing permanent life products) face a risk assessment requirement that specifically needs to address distribution channel risk — agent networks introduce third-party AML risk that the formal risk assessment must capture.

Fintechs and lending-as-a-service operators — For fintech lenders operating through bank partnership structures, the proposed rule adds clarity to the question of program responsibility. Where the fintech is itself a covered institution (as an MSB or state-licensed lender), it has its own program obligation that must meet the effectiveness standard. Bank partners with significant fintech origination volume should review whether their BSA programs adequately address the customer risk introduced through those channels.

The Implementation Window: Why Starting Now Matters

FinCEN’s proposed 12-month implementation window — running from finalization of the rule — is more aggressive than it sounds. Here’s the practical math:

The comment period closed June 9, 2026. Regulatory finalization, given FinCEN’s review of comments and drafting of the final rule, typically takes 6 to 18 months after the comment period closes. Assume a final rule in late 2026 or early 2027. Add 12 months for implementation. That puts compliance expected by late 2027 or early 2028 — which is roughly 18 months away at best.

Eighteen months is not a long runway for institutions that need to:

  • Conduct a formal, documented AML/CFT risk assessment for the first time
  • Map FinCEN’s National Priorities to their specific business lines and risk profile
  • Recalibrate monitoring rules to reflect the risk assessment findings
  • Update BSA/AML policies to reflect the effectiveness standard
  • Brief the board and senior management on the program changes

For institutions that already maintain a documented risk assessment and have periodic recalibration processes, this is primarily a documentation exercise and a gap analysis. For institutions starting from scratch, 18 months is tight.

Three Things BSA Officers Should Do Before the Final Rule

1. Draft your risk assessment now, even if it’s informal. The proposed rule’s risk assessment requirements are not surprising — they track the FFIEC examination manual’s existing guidance on what a risk assessment should cover. Draft a version now, covering the five dimensions (products, customers, channels, geography, national priorities). When the final rule drops, you’ll have a starting point rather than a blank page, and you’ll have already surfaced the gaps in your current program documentation.

2. Map your monitoring rules to your risk assessment. The effectiveness standard requires that your controls be calibrated to your risk profile. Pull your current transaction monitoring alert rules and typology coverage, and compare them against the risk dimensions in your risk assessment. Where are the mismatches? High-risk customer segments with no dedicated typology coverage? Products with known money laundering exposure and no monitoring rule tuned to that product? Document the mapping now.

3. Review your independent testing scope. The BSA/AML independent testing requirements should validate program effectiveness, not just check whether a BSA officer exists and policies are in place. If your most recent audit or testing report focused on documentation completeness rather than operational effectiveness, it may not satisfy the proposed standard. Frame this with your auditors before the final rule requires it of you.

Connecting the Risk Assessment to Your Broader Compliance Program

The mandatory risk assessment isn’t just a FinCEN compliance deliverable — it’s the foundation that makes the rest of your BSA program defensible. A well-documented risk assessment is the document that:

  • Justifies your monitoring rule thresholds to an examiner who asks why you set the SAR review threshold where you did
  • Explains your staffing levels relative to your transaction volume and risk profile
  • Documents your rationale for the customer risk rating cutoffs in your KYC policy and CDD procedures
  • Supports your ALLL/ACL qualitative factors if you’re a bank with significant BSA-sensitive lending exposures

For the BSA/AML KRIs that your monitoring generates — SAR filing rates, alert volumes, false positive ratios — the risk assessment is the context that explains what those metrics should look like for your institution specifically. An examiner who sees a SAR rate that looks low relative to peers will ask about it; your risk assessment is the document that explains why your rate is appropriate for your risk profile.

So What? The Effectiveness Standard Is Already the Real Standard

Here’s the practical reality: FinCEN examiners and federal banking regulators have been applying an effectiveness-based evaluation to AML programs for years. The proposed rule codifies what sophisticated BSA officers already know — “we have a program” isn’t enough, and “the program finds the actual suspicious activity” is the real test.

What the NPRM does is make the effectiveness standard explicit in the rule text and add the mandatory risk assessment as the formal mechanism for documenting how your controls connect to your risk profile. This creates both a compliance obligation and a paper trail — an institution that has done the risk assessment work now has a document that demonstrates effectiveness; an institution that hasn’t has both a compliance gap and a documentation gap.

The public comment period has closed. FinCEN is reviewing comments and working toward a final rule. The 12-month implementation window will feel short when it starts — the time to begin the risk assessment work is now.

For the operational templates that support BSA program documentation — risk assessment frameworks, compliance program structures, and monitoring documentation tools — the Compliance Essentials bundle includes the program components that map to both current FFIEC expectations and the proposed AML/CFT effectiveness standard.


Sources: FinCEN AML/CFT Program NPRM Fact Sheet (April 2026); Mayer Brown — FinCEN Issues Major AML/CFT NPRM; Covington & Burling — FinCEN Proposes Sweeping Changes to AML/CFT Program Requirements; Norton Rose Fulbright — FinCEN AML/CFT NPRM: Risk Assessment Codification; Jones Day — FinCEN AML/CFT NPRM: Enforcement Implications

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does FinCEN's April 2026 AML/CFT NPRM propose to change?
The April 7, 2026 NPRM proposes to restructure AML/CFT program requirements across all covered financial institutions. It retains the traditional four-pillar framework (internal policies and controls, independent testing, a designated compliance officer, and ongoing training) but adds a fifth mandatory element: a codified, structured risk assessment process. The proposed rule would also formally require institutions to incorporate FinCEN's National AML/CFT Priorities into their risk assessments and shift the compliance standard from technical rule adherence to demonstrated program effectiveness.
Who does the FinCEN AML/CFT NPRM apply to?
The proposed rule applies broadly to all institutions currently subject to BSA program requirements: banks, credit unions, money services businesses (MSBs), broker-dealers, mutual funds, insurance companies, futures commission merchants (FCMs), and other non-bank financial institutions covered by existing FinCEN program rules. The scope is not limited to large institutions — the risk assessment requirement applies regardless of asset size, and the effectiveness standard applies to all covered entities.
What is required under the proposed mandatory risk assessment?
Under the proposed rule, financial institutions must conduct and document a structured AML/CFT risk assessment that covers: the institution's products and services, customer types and risk profiles, distribution channels (including digital and third-party channels), and geographic locations of operations and customers. The risk assessment must incorporate FinCEN's National AML/CFT Priorities — which currently include corruption, cybercrime, human trafficking, drug trafficking, fraud, terrorist financing, and proliferation financing — and must be updated periodically and when material changes occur.
What is the 'effectiveness' standard in the proposed rule and how is it different from current requirements?
Current AML/CFT program rules are largely structured around technical compliance: do you have written policies? A designated BSA officer? Training records? The proposed effectiveness standard requires institutions to demonstrate that their programs actually work — that controls are calibrated to the institution's specific risk profile, that monitoring identifies the typologies relevant to the institution's business, and that the program responds to changes in risk. A program that checks every technical box but fails to detect obvious patterns of suspicious activity no longer satisfies the standard.
When would the FinCEN AML/CFT NPRM take effect, and what is the implementation timeline?
FinCEN issued the NPRM on April 7, 2026. The public comment period closed June 9, 2026. FinCEN has not announced a final rule date, but the proposed rule included a 12-month implementation period after finalization. Given typical rulemaking timelines, covered institutions should plan for a final rule no earlier than late 2026 or early 2027, with compliance required approximately 12 months after that. BSA officers should begin risk assessment documentation work now rather than waiting for the final rule.
How does the two-tiered enforcement standard in the proposed rule affect compliance risk?
The proposed rule includes a two-tiered enforcement framework: 'significant or systemic' program failures trigger enforcement action, while minor design flaws or isolated deficiencies are addressed through the examination process rather than penalties. This is meaningful guidance on what regulators consider actionable — but 'significant or systemic' is not defined with numerical precision. Institutions should read this as protection for good-faith programs with minor gaps, not as a license to defer structural problems.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.