FinCEN on April 7 proposed a sweeping rewrite of Bank Secrecy Act program requirements that would recast anti-money laundering and counter-terrorist financing compliance around whether institutions maintain “effective,” risk-based, and reasonably designed programs, rather than around largely procedural or technical failures.
Treasury said the proposal is meant to modernize the AML/CFT framework, align it with statutory changes in the Anti-Money Laundering Act of 2020, and reduce unnecessary compliance burden.
The proposal would fully supersede FinCEN’s July 3, 2024 AML/CFT program proposal, which the agency said it is withdrawing. Public comments will be due 60 days after the proposal is published in the Federal Register. The NPRM is docketed as FINCEN-2026-0034 under RIN 1506-AB72.
Treasury Secretary Scott Bessent framed the move as a direct response to longstanding industry criticism that AML examinations reward paperwork over actual threat detection. “For too long, Washington has asked financial institutions to measure success by the volume of paperwork rather than their ability to stop illicit finance threats,” he said in FinCEN’s release.
At the center of the proposal is a shift toward a more explicitly risk-based structure. FinCEN says institutions would be required to establish and maintain AML/CFT programs that are reasonably designed to identify, assess, and document money laundering, terrorist financing, and other illicit finance risks through risk assessment processes, then allocate more attention and resources to higher-risk customers and activities.
The fact sheet says the rule would preserve four core pillars: internal policies, procedures and controls; independent testing; a U.S.-based compliance officer; and ongoing employee training.
The agency also proposes to distinguish more clearly between failures in program “establishment” and failures in program “maintenance,” a change meant to separate defects in design from breakdowns in day-to-day execution. FinCEN says that distinction should promote more consistent supervisory expectations and prevent criticism of implementation from being conflated with criticism of program design.
Another consequential feature is the proposed strengthening of FinCEN’s role in bank supervision. Proposed 31 CFR 1020.221(c) would create a notice-and-consultation framework requiring federal banking agencies, when acting under authority delegated by FinCEN, to give the FinCEN director an opportunity to review and comment before initiating a significant AML/CFT supervisory action. The agencies would have to provide written notice at least 30 days in advance.
FinCEN also says the proposal incorporates the government-wide AML/CFT Priorities into revised program requirements. Under the fact sheet, institutions would be required to review those priorities and, where appropriate, incorporate them into their risk assessment processes, though not into their risk-based programs until a final rule takes effect.
The practical significance for banks and other covered institutions is that the proposal would move examinations further away from a “check-the-box” model and toward judgments about whether a firm’s controls are calibrated to its own risk profile and implemented in all material respects.
FinCEN’s one-page summary says the rule is intended to reduce burden by allowing firms to focus resources on higher-risk areas while giving regulators a more consistent effectiveness standard. That appears to answer years of complaints that examiners sometimes substituted subjective preferences for institution-specific risk judgments.
The NPRM applies across a wide range of covered financial institutions, including banks, casinos, money services businesses, broker-dealers, mutual funds, insurance companies, futures commission merchants, dealers in precious metals, loan and finance companies, and housing GSEs.
For industry, the immediate task will be to assess whether the proposal in fact narrows examiner discretion or merely reframes it. The rule promises flexibility and reduced burden, but it also formalizes effectiveness standards and embeds risk assessment more deeply into program design, which could require substantial revisions to governance, documentation, testing, and escalation practices once finalized.
Comments
No comments on this item Please log in to comment by clicking here