FinCEN Proposes Risk-Based Overhaul of U.S. AML/CFT Program Rules

Date: 7 April 2026
Category: Regulation / Compliance
Region: United States
FinCEN has proposed a major revision of the rules governing anti-money laundering and countering the financing of terrorism programs at U.S. financial institutions.
The proposal seeks to move the regulatory framework away from evaluating compliance primarily through the volume of policies, alerts and documentation produced. Instead, institutions would be expected to maintain programs that are:
- Effective;
- Risk-based; and
- Reasonably designed for the institution’s specific risk profile.
FinCEN also wants institutions to direct more attention and resources toward higher-risk customers and activities, rather than applying the same level of control to every relationship regardless of risk.
The proposal does not remove the core elements of an AML/CFT program. Institutions would still need internal controls, independent testing, a designated AML/CFT officer and ongoing employee training.
The more significant change is how those elements would be designed, implemented and assessed.
Which Financial Institutions Are Covered?
The proposed amendments apply to the AML/CFT program rules for 11 categories of financial institution:
- Banks;
- Casinos and card clubs;
- Money services businesses;
- Securities broker-dealers;
- Mutual funds;
- Insurance companies;
- Futures commission merchants and introducing brokers in commodities;
- Dealers in precious metals, precious stones or jewels;
- Operators of credit card systems;
- Loan and finance companies; and
- Housing government-sponsored enterprises.
The proposal would standardise several program requirements that are currently expressed differently across these sectors.
Certain supervisory and enforcement provisions—including the proposed requirement for regulators to consult FinCEN before taking significant supervisory action—would initially apply only to banks.
What Would an “Effective” AML/CFT Program Mean?
FinCEN acknowledges that no financial institution can detect every potentially illicit transaction or prevent every instance of criminal misuse.
Under the proposal, effectiveness would not be measured by whether a program produces a perfect outcome.
A program would generally be considered effective where the institution:
- Properly establishes the required AML/CFT program; and
- Implements that program in all material respects.
This creates a two-part framework:
- Program establishment: Whether the institution has designed an appropriate program containing the required components.
- Program implementation: Whether the institution follows and operates that program in practice.
The distinction is important because a poorly designed program and a properly designed program that is not followed represent different compliance failures.
They may also require different remediation.
Program Design Deficiency vs. Implementation Deficiency
Program Design Deficiency
A design deficiency exists where the AML/CFT framework itself is missing, incomplete or not reasonably designed for the institution’s risks.
Examples may include:
- A risk assessment that omits a material product or customer segment;
- Policies that do not address a significant geographic or distribution-channel risk;
- Transaction monitoring that is not designed for the institution’s actual activities;
- No meaningful process for incorporating emerging threats;
- An AML/CFT officer without adequate authority or access to resources;
- Independent testing that is not genuinely independent;
- No ongoing employee training program; or
- Failure to obtain the required leadership approval for the program.
A program may therefore be implemented exactly as written and still be deficient if its design does not adequately address the institution’s risks.
Implementation Deficiency
An implementation deficiency arises where an appropriate program exists but is not being carried out as intended.
Examples may include:
- Customer reviews not completed within the institution’s stated timetable;
- Transaction monitoring alerts left unreviewed;
- Required enhanced due diligence not performed;
- Employees not receiving the training required by the program;
- Suspicious activity not escalated under established procedures;
- Insufficient staffing to operate the approved controls;
- Known data-quality problems not addressed; or
- Remediation plans repeatedly delayed.
The proposal would require institutions to implement their programs in all material respects.
For banks, isolated, technical or immaterial implementation issues would generally not, by themselves, justify a significant supervisory or enforcement action under the program rule.
Significant or systemic failures could still lead to action.
Why the Distinction Matters
Under the existing framework, supervisory findings may not always state clearly whether the regulator believes:
- The institution designed the wrong control;
- The control was reasonable but not followed;
- The institution lacked sufficient resources;
- The examiner would simply have chosen a different approach; or
- A limited operational error represents a broader program weakness.
FinCEN’s proposal seeks to make that distinction more explicit.
A design failure should be supported by evidence that the established program is not reasonably designed to address the institution’s risk profile or does not contain the required components.
An implementation failure should focus on whether the institution materially failed to execute its own program.
This should also make remediation more targeted.
A design deficiency may require a new risk methodology, monitoring framework or governance structure. An implementation deficiency may require better staffing, training, operational discipline or management oversight.
Risk Assessment Becomes an Explicit Program Requirement
The proposal would expressly require financial institutions to maintain risk assessment processes that identify, assess and document their money laundering and terrorist financing risks.
Those processes should consider the institution’s:
- Products and services;
- Customers;
- Geographic exposure;
- Distribution channels; and
- Business activities.
FinCEN would not prescribe a single risk assessment model or require every institution to produce one standalone risk assessment document.
An institution could use several connected processes, provided they collectively identify and assess its material risks.
The risk assessment would also need to remain current. New products, delivery methods, customer types or geographic markets should be considered as the institution’s business changes.
FinCEN does not propose a mandatory fixed timetable for updating the assessment. The appropriate frequency would depend on the institution’s risks and changes in its activities.
National AML/CFT Priorities Must Be Considered Proportionately
Financial institutions would be required to review the U.S. government’s national AML/CFT priorities and incorporate them into their programs where appropriate.
This does not mean that every institution must treat every national priority as equally relevant.
A financial institution with no material digital asset activity, for example, may reasonably determine that certain digital asset risks have limited relevance to its business.
However, a superficial review would not be sufficient. The institution should consider how each relevant priority could appear through its customers, products, services, geographies and delivery channels.
The resulting controls should reflect both:
- National illicit-finance priorities; and
- The institution’s own risk profile.
Greater Flexibility to Focus on Higher Risks
One of the proposal’s central objectives is to allow institutions to devote more resources to higher-risk activity while reducing unnecessary attention to lower-risk customers and transactions.
This could support more differentiated controls, such as:
- More frequent reviews for higher-risk customers;
- Less intensive monitoring for demonstrably lower-risk products;
- Greater investigative resources for priority threats;
- Risk-based alert thresholds;
- Targeted use of enhanced due diligence; and
- Reduced duplication in low-value compliance processes.
However, risk-based allocation does not mean that institutions can ignore mandatory BSA requirements.
Recordkeeping, reporting and customer identification obligations would continue to apply where required by law.
An institution should also be able to explain why a customer, product or activity was treated as lower risk and how that conclusion was supported by its risk assessment.
Reducing a control solely to lower cost or manage an alert backlog would not constitute a defensible risk-based decision.
How Independent Testing Could Change
Independent testing would remain a mandatory component of an AML/CFT program.
The proposal clarifies that its purpose is to assess whether the institution complies with applicable requirements relative to its risk profile and whether its program is effective.
Testing should use objective criteria to examine whether:
- Risk assessment processes are reasonably designed;
- Resources are allocated consistently with identified risks;
- Internal controls operate as intended;
- Governance is sufficient;
- Material weaknesses are identified;
- Compensating controls are effective; and
- Remediation is properly managed.
FinCEN cautions that an auditor should not replace the institution’s reasonable risk-based judgement with the auditor’s personal preference.
This does not prevent an auditor from challenging weak assumptions or unsupported decisions. It means a finding should be based on an objective deficiency—not simply on the fact that the auditor would have designed the program differently.
Independence Will Still Be Closely Examined
The person conducting the testing must remain independent from the functions being tested.
The AML/CFT officer and individuals directly involved in operating or overseeing the program would generally not be sufficiently independent.
An external consultant may also lack independence if the same consultant designed the controls, delivered key program functions and then audited their own work.
Smaller institutions may use internal personnel or shared testing resources, but the arrangement must avoid conflicts of interest.
Independent testers should also have sufficient knowledge of:
- The institution’s risk profile;
- Applicable AML/CFT requirements;
- The relevant products and services; and
- The methods needed to test the program effectively.
What Could Change in Regulatory Examinations?
The proposed framework would encourage examiners to focus on whether the institution’s program is reasonably designed and materially implemented.
Examiners would still be able to challenge:
- Unsupported risk decisions;
- Material control gaps;
- Inadequate resources;
- Known problems that remain unresolved;
- Failures to follow established procedures; and
- Programs that do not reflect the institution’s actual risks.
However, examiners should not substitute their own preferred methodology for a reasonable approach selected by the institution.
For example, an examiner should not criticise an institution simply because it uses a different risk-scoring model or review frequency, provided the institution’s approach is supported by its risk assessment and operates effectively.
The focus should move from:
“Did the institution follow the examiner’s preferred process?”
toward:
“Was the institution’s process reasonably designed, supported by risk and implemented in all material respects?”
Additional Safeguards for Significant Bank Findings
For banks, the proposal would introduce a new consultation process before a federal banking regulator takes a significant AML/CFT supervisory action under authority delegated by FinCEN.
The relevant regulator would generally need to notify FinCEN at least 30 days before initiating the action and provide the supporting examination information.
FinCEN would then have an opportunity to review the proposed action and offer its view on the effectiveness of the bank’s AML/CFT program.
The objective is to promote greater consistency among banking regulators and reduce significant supervisory actions based on isolated, subjective or immaterial concerns.
Informal examiner observations and suggestions would not automatically be treated as significant supervisory actions.
The consultation mechanism would not prevent action where a bank:
- Failed to establish a compliant program;
- Experienced a significant or systemic failure to implement its program;
- Violated another BSA requirement; or
- Faced potential criminal liability.
What Financial Institutions Should Do Now
The proposal is not yet a final rule, but institutions can begin reviewing whether their current frameworks clearly distinguish design from implementation.
Priority questions include:
- Does the risk assessment cover all material products, customers, geographies and delivery channels?
- Can the institution explain how controls are connected to identified risks?
- Are resources directed toward genuinely higher-risk activity?
- Are lower-risk controls supported by documented reasoning?
- Does the written program reflect what operations actually do?
- Are material implementation gaps visible to senior management?
- Does independent testing use objective, risk-based criteria?
- Are auditors sufficiently independent from program design and operation?
- Can examination findings be classified clearly as design or implementation issues?
- Is evidence available to demonstrate that risk-based decisions are reasonable?
Institutions should not interpret the proposal as an invitation to reduce controls immediately.
The stronger approach is to ensure that each control has a clear purpose, each resource decision follows the risk assessment and low-value processes can be distinguished from legally required or risk-significant activities.
The Compliance Takeaway
FinCEN’s proposal represents a shift from process-heavy compliance toward outcome-focused supervision, but it does not lower the expectation that institutions maintain effective AML/CFT programs.
A risk-based program must still be:
- Properly established;
- Reasonably designed;
- Adequately resourced;
- Independently tested;
- Approved by appropriate leadership; and
- Implemented in all material respects.
The distinction between design and implementation may become particularly important.
Institutions should be able to show not only that their policies are well designed, but also that those policies operate in practice. Regulators and auditors, in turn, would be expected to identify objective deficiencies without treating personal preferences as binding standards.
The proposed framework does not eliminate compliance obligations.
It seeks to make institutions more accountable for choosing controls that address their real risks—and less accountable for producing activity that has little practical value.
Main Sources
FinCEN — FinCEN Proposes Rule to Fundamentally Reform Financial Institution Programs Designed to Fight Illicit Finance
Federal Register — Anti-Money Laundering and Countering the Financing of Terrorism Programs



