Changeflow GovPing Banking & Finance FinCEN AML Reset Proposes New AML/CFT Program R...
Routine Notice Added Consultation

FinCEN AML Reset Proposes New AML/CFT Program Requirements

Favicon for www.jdsupra.com JD Supra Finance & Banking
Published
Detected
Email

Summary

FinCEN issued a Notice of Proposed Rulemaking on April 7, 2026, that would significantly revise Bank Secrecy Act (BSA) anti-money laundering and countering terrorism financing (AML/CFT) program requirements across banks, credit unions, casinos, money services businesses, broker-dealers, mutual funds, insurance companies, futures commission merchants, and other covered financial institutions. The proposal introduces a formal definition of an "effective" AML/CFT program, requires integration of FinCEN's AML/CFT priorities into risk assessments, and establishes new governance and independent testing expectations. Comments are due 60 days after Federal Register publication (Docket No. FINCEN-2026-0034; RIN 1506-AB72), with a proposed 12-month implementation period following a final rule.

What changed

FinCEN's proposed rule would replace technical, process-driven AML/CFT compliance with a demonstrable effectiveness standard. Covered institutions would need to formally integrate FinCEN's AML/CFT priorities into risk assessment processes, document risk-based resource allocation decisions, and satisfy new governance expectations including a U.S.-based AML/CFT officer. The proposal supersedes FinCEN's July 3, 2024 AML program NPRM and would apply to banks, casinos, MSBs, broker-dealers, mutual funds, certain insurers, FCMs, precious metals dealers, and housing GSEs.

Financial institutions subject to these requirements should carefully review their existing AML/CFT programs and identify gaps against the new effectiveness standard. Registered investment adviser AML/CFT rules are being addressed in separate rulemaking and are not affected by this proposal. Institutions should allocate resources to participate in the comment period and begin planning for the anticipated 12-month implementation timeline.

What to do next

  1. Monitor for Federal Register publication and submit comments within 60 days
  2. Prepare for 12-month implementation period following final rule
  3. Reassess existing AML/CFT programs against new effectiveness standards

Archived snapshot

Apr 14, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

April 14, 2026

FinCEN’s AML Reset: Proposed Rule Rewrites the Playbook for AML/CFT Programs

Ryan Last, Michael Lowe, Edward Nogay Troutman Pepper Locke + Follow Contact LinkedIn Facebook X Send Embed

On April 7, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued a Notice of Proposed Rulemaking (NPRM) that would significantly revise Bank Secrecy Act (BSA) anti-money laundering and countering the financing of terrorism (AML/CFT) program requirements across a broad range of financial institutions. The proposal is a central element of the U.S. Department of the Treasury’s effort to modernize the AML/CFT framework by moving away from purely technical, process-driven compliance toward demonstrable effectiveness in identifying, mitigating, and reporting money laundering, terrorist financing, and related illicit finance risks.

If adopted, the rule would require covered institutions to recalibrate their AML/CFT programs to be genuinely risk-based, to integrate FinCEN’s AML/CFT priorities into their risk assessment processes, and to satisfy clear expectations regarding governance, independent testing, and the defined role of a U.S.-based AML/CFT officer. For banks, the proposal would also introduce a new supervision and enforcement framework that concentrates significant actions on material failures to implement an otherwise properly established program and strengthens FinCEN’s central role in AML/CFT oversight.

The proposal supersedes and withdraws FinCEN’s July 3, 2024, AML program NPRM. Financial institutions should anticipate that, once finalized, the rule will require a careful reassessment of existing AML/CFT programs to ensure they meet the new standards for program establishment and maintenance, including integration of AML/CFT priorities and documentation of risk-based resource allocation decisions.

Comments are due 60 days after publication in the Federal Register (Docket No. FINCEN-2026-0034; RIN 1506-AB72), and FinCEN proposes a 12‑month implementation period following issuance of a final rule.

Scope of the Proposal

The NPRM would amend AML/CFT program requirements in 31 CFR Part 1010 and Parts 1020–1030 for banks (including credit unions and banks without a federal functional regulator), casinos and card clubs, money services businesses (MSBs), broker-dealers, mutual funds, certain insurance companies, futures commission merchants (FCMs) and introducing brokers in commodities (IBCs), dealers in precious metals, stones, or jewels (DPMSJs), operators of credit card systems, loan or finance companies, and housing government-sponsored enterprises (GSEs). Registered investment adviser AML/CFT rules are being addressed in separate rulemaking and are not affected by this proposal.

Key Material Changes to AML/CFT Program Requirements

“Effective” Program Standard Definition and Maintenance

The proposal introduces a formal definition of an “effective” AML/CFT program. A program is “effective” if the institution: (i) properly establishes it in accordance with the minimum regulatory components; and (ii) maintains it by implementing the program in all material respects. FinCEN expressly acknowledges that no program can eliminate all illicit activity or capture every suspicious transaction; rather, the standard focuses on whether the program is reasonably designed to ensure BSA compliance, identify and mitigate the institution’s actual money laundering and terrorist financing risks, and generate information that is highly useful to law enforcement and national security agencies.

Risk-Based Internal Controls and Mandatory Risk Assessment Processes

Every covered financial institution would be required to establish a risk-based set of internal policies, procedures, and controls that are reasonably designed to ensure BSA compliance and to: (i) identify, assess, and document money laundering, terrorist financing, and other illicit finance risks through risk assessment processes; and (ii) mitigate those risks consistent with those assessments.

The risk assessment processes must evaluate risks arising from the institution’s products and services, distribution channels, customers, intermediaries, and geographic exposure, and must be updated promptly when the institution knows or has reason to know that its risk profile has significantly changed (for example, due to new products, markets, or customer types).

Incorporation of FinCEN AML/CFT Priorities into Risk Assessments

The Anti-Money Laundering Act of 2020 requires FinCEN to issue governmentwide AML/CFT priorities and to incorporate them into AML/CFT program requirements. Under the NPRM, covered institutions would be required to review FinCEN’s AML/CFT priorities and, as appropriate, incorporate them into their risk assessment processes. Institutions are expected to evaluate the relevance of each priority to their business and risk profile and to be able to explain why certain priorities are or are not material. FinCEN cautions that superficial treatment of the priorities will not satisfy supervisory expectations.

Explicit Risk-Based Resource Allocation

The proposal embeds the AML Act’s expectation that AML/CFT programs be risk-based, including by directing more attention and resources toward higher-risk customers and activities, consistent with the institution’s risk profile, rather than toward lower-risk customers and activities. FinCEN intends this formulation to give institutions greater comfort in reallocating resources away from lower-risk areas without fear that such reallocation, by itself, will be cited adversely, so long as it is grounded in reasonably designed risk assessments and controls.

US-Based AML/CFT Officer and Standardized Governance Requirements

Consistent with the AML Act, each covered institution would be required to designate an AML/CFT officer who is located in the U.S., accessible to, and subject to oversight and supervision by FinCEN and, where applicable, the appropriate federal functional regulator or self-regulatory organization. That individual must be responsible for establishing and implementing the AML/CFT program and coordinating and monitoring day-to-day compliance. The NPRM also standardizes governance expectations by requiring that the written AML/CFT program be approved by the board of directors, an equivalent governing body, or appropriate senior management, and be made available to FinCEN or its designee upon request.

Harmonized Independent Testing and Training Requirements

The NPRM aims to harmonize and clarify the existing “independent audit” pillar by requiring independent AML/CFT program testing, conducted either by internal personnel who are independent of the AML/CFT function and relevant business lines or by a qualified external party. Testing is expected to be risk based and focused on program effectiveness, not merely technical completeness. The rule also seeks to standardize the requirement for an ongoing employee training program across all covered institution types, with content and frequency calibrated to the institution’s risk profile and personnel roles.

Bank-Specific Supervision and Enforcement Framework

For banks, the proposal would create a new supervisory and enforcement framework. Where a bank has properly established an AML/CFT program under the rule, FinCEN and the federal banking agencies, when acting under FinCEN’s delegated authority, would not base an AML/CFT enforcement action or “significant AML/CFT supervisory action” solely on the program rule absent a significant or systemic failure to implement the program — that is, a failure to implement the program in all material respects. The NPRM also would require the federal banking agencies to consult with FinCEN before initiating such significant AML/CFT supervisory actions, and would direct FinCEN to consider, among other statutory factors, a bank’s contributions to AML/CFT priorities and responsible use of innovative tools (such as advanced analytics and artificial intelligence) in assessing program effectiveness and potential enforcement.

Practical Considerations for Financial Institutions

Even before the rule is finalized, covered institutions should begin assessing their existing AML/CFT programs against the proposed framework. Key initial steps include:

  • Mapping current policies and controls to the new establishment criteria (risk assessments, internal controls, independent testing, AML/CFT officer, training, and CDD where applicable);
  • Evaluating whether risk assessment processes meaningfully incorporate FinCEN’s AML/CFT priorities;
  • Documenting how AML/CFT resources are currently allocated across higher- and lower-risk areas;
  • Confirming governance structures and the location and authority of the AML/CFT officer align with the proposal;
  • Reviewing the independence and focus of AML/CFT testing; and
  • Considering where technology and innovation could enhance program effectiveness and efficiency. Given the breadth and significance of the proposed changes — and the explicit shift toward an effectiveness-and risk-based paradigm — many institutions should consider submitting comments, individually or through industry associations, to help shape the contours of the final rule, including definitions of “significant or systemic failure” to implement, expectations for risk assessment updates, and the treatment of model risk management and advanced analytics.

Send Print Report

Related Posts

Latest Posts

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.
Attorney Advertising.

©
Troutman Pepper Locke

Written by:

Troutman Pepper Locke Contact + Follow Ryan Last + Follow Michael Lowe + Follow Edward Nogay + Follow more less

PUBLISH YOUR CONTENT ON JD SUPRA

  • ✔ Increased readership
  • ✔ Actionable analytics
  • ✔ Ongoing writing guidance Join more than 70,000 authors publishing their insights on JD Supra

Start Publishing »

Published In:

AML/CFT + Follow Anti-Money Laundering + Follow Bank Secrecy Act + Follow Banks + Follow BSA/AML + Follow Financial Institutions + Follow FinCEN + Follow Notice of Proposed Rulemaking (NOPR) + Follow NPRM + Follow Proposed Rules + Follow Regulatory Oversight + Follow Regulatory Requirements + Follow Risk Assessment + Follow Risk Management + Follow Risk-Based Approaches + Follow U.S. Treasury + Follow Finance & Banking + Follow Insurance + Follow more less

Troutman Pepper Locke on:

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra: Sign Up Log in ** By using the service, you signify your acceptance of JD Supra's Privacy Policy.* - hide - hide

CFR references

31 CFR Part 1010 31 CFR Parts 1020-1030

Get daily alerts for JD Supra Finance & Banking

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from Troutman Pepper Locke.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
Troutman Pepper Locke
Published
April 14th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Consultation
Change scope
Substantive
Document ID
Docket No. FINCEN-2026-0034; RIN 1506-AB72
Docket
FINCEN-2026-0034
Supersedes
July 3, 2024 AML program NPRM

Who this affects

Applies to
Banks Broker-dealers Insurers
Industry sector
5221 Commercial Banking 5231 Securities & Investments 5241 Insurance
Activity scope
AML/CFT compliance BSA compliance Financial crime risk assessment
Geographic scope
United States US

Taxonomy

Primary area
Anti-Money Laundering
Operational domain
Compliance
Compliance frameworks
BSA/AML
Topics
Banking Securities Financial Services

Get alerts for this source

We'll email you when JD Supra Finance & Banking publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!