Home

Services

About Us

INSIGHTS

Contact Us

The End of One-Size-Fits-All AML/CFT: Why Risk-Based Programs Matter More Than Ever

 

Ask a compliance officer what their AML/CFT program is really designed to do, and the honest answer is often “pass the exam.” For years, financial institutions have built AML programs around that objective, even though the Bank Secrecy Act has always called for a risk-based approach. Policies, procedures, independent testing, employee training, and governance structures became the checklist examiners expected,  A  standardized model  built to satisfy examiners rather than to reflect the risks each institution actually carries.

FinCEN’s proposed rule to modernize AML/CFT programs is a direct response to that dynamic.

At a glance:

  • FinCEN issued the NPRM on April 7, 2026, superseding a prior 2024 proposal; it was published in the Federal Register on April 10, 2026.
  • The proposal separates program deficiencies into “establishment” (design) and “maintenance” (execution) — a two-pronged framework intended to focus supervisory action on significant or systemic failures.
  • Institutions gain more discretion over program design but are expected to justify their choices with a defensible, risk-based rationale.
  • The public comment period closes June 9, 2026; FinCEN has indicated a 12-month implementation window following issuance of a final rule.
  • Three of the four federal banking regulators — the OCC, FDIC, and NCUA — issued a parallel, aligned proposal; the Federal Reserve Board did not join it.

 

On April 7, 2026, the Financial Crimes Enforcement Network issued a Notice of Proposed Rulemaking (NPRM) that would rewrite the AML/CFT program requirements financial institutions have operated under for decades [1]. The proposal fully supersedes and withdraws a prior AML program proposal FinCEN had issued in July 2024 [2]. Treasury Secretary Scott Bessent described the shift as a move away from measuring compliance “by the volume of paperwork” institutions generate, toward a framework focused on “keeping bad actors out of the financial system.” [1]  That framing comes from Treasury’s own announcement of the rule, and institutions should treat it as a statement of policy intent rather than a neutral technical description of what the rule does — the operative substance is in the two-pronged framework and risk-assessment requirements described below. 

Risk Ownership Moves to the Center

The most consequential change in the proposal may be its emphasis on institutional ownership of risk. Rather than leaning on prescriptive checklists, the proposal reflects FinCEN’s view that financial institutions are best positioned to understand the risks tied to their own customers, products, services, delivery channels, and geography. That puts the institution’s risk assessment at the center of the entire AML/CFT program.

FinCEN formalizes this through what it calls a “two-pronged framework,” separating deficiencies in how a program is designed (“establishment”) from deficiencies in how it’s carried out day to day (“maintenance”) [3]. Establishing a program means building a risk-based framework around four required pillars: internal policies, procedures, and controls (including risk assessment processes and ongoing customer due diligence); independent testing; a U.S.-based compliance officer; and an ongoing employee training program [3]. Maintaining a program means actually running it that way, in all material respects. A weak or outdated risk assessment undermines both obligations at once.

For compliance leaders, that raises the bar. Decisions about monitoring, due diligence, governance, and resourcing now need to trace back to a documented, defensible view of where the institution’s risk actually sits.

Resources Should Follow Risk

The Anti-Money Laundering Act of 2020 already directs FinCEN to ensure AML/CFT programs are risk-based, with institutions directing more attention and resources toward higher-risk customers and activities and less toward lower-risk ones [3]. The proposed rule operationalizes that mandate. Many institutions have historically applied similar levels of monitoring across broad customer populations, in part to avoid criticism during exams. Under this proposal, that approach is unlikely to hold up.

Institutions are expected to direct staffing, technology, and investigative resources toward higher-risk customers and activities, while applying lighter, proportionate controls elsewhere. FinCEN frames the goal as reducing “unnecessary regulatory burden” [4], not adding more compliance, but making the compliance that already exists more effective. That has real budget implications: technology investment, transaction monitoring design, and customer due diligence processes should be driven by the institution’s actual risk profile rather than by peer practice.

Greater Flexibility, With Greater Accountability

The proposed rule gives institutions more latitude in how they design and run their programs. A community bank, a global bank, a fintech, and a money services business operate in very different risk environments, and the proposal is explicit that program design should reflect those differences. Among the structural changes, FinCEN proposes consolidating separate bank program rules into a single standard, alongside harmonized — though not identical — requirements for casinos and money services businesses. 

The proposal also states that examiners and independent auditors “should not substitute their own subjective judgment in place of” an institution’s risk-based and reasonably designed AML/CFT program [3]. That language is aimed squarely at the exam-driven culture the industry has pushed back on for years. Notably, FinCEN’s Director would also weigh “whether the bank is employing innovative tools such as artificial intelligence that demonstrate the effectiveness of the bank’s AML/CFT program” when deciding whether to pursue enforcement or supervisory action [3]. That gives institutions real room to modernize legacy compliance infrastructure.

This additional discretion should not be mistaken for lower expectations. Institutions are getting more flexibility, but they are also expected to justify the decisions they make and show that those decisions rest on a genuine understanding of risk.

One coordination note worth flagging: while the OCC, FDIC, and NCUA issued a parallel proposal aligned with FinCEN’s framework, the Federal Reserve Board did not join it. Bank holding companies and institutions supervised by the Fed should watch for whether and how the Board aligns its own expectations, since divergence here could complicate implementation for institutions supervised across multiple regulators..

A Weak Risk Assessment Creates Regulatory Exposure

Because risk ownership sits at the foundation of the proposed framework, the quality of the risk assessment becomes one of the clearest things regulators will look at. An outdated or poorly built assessment can send resources toward low-risk activity while leaving real exposure in transaction monitoring, customer due diligence, sanctions screening, or investigations unaddressed.

The proposed rule draws a line between minor deficiencies and significant or systemic failures to maintain a program [4]. Under FinCEN’s outlined supervisory approach, once a bank has properly established its program, FinCEN and federal banking regulators generally would not pursue enforcement or a significant supervisory action except for serious implementation failures – the kind driven by inadequate resources, ineffective controls, or material data problems. The rule also proposes a notice-and-consultation requirement: before taking a significant AML/CFT supervisory action against a bank, federal banking regulators would generally need to give FinCEN’s Director 30 days’ written notice [3]. In practice, institutions are no longer being judged only on whether controls exist. They are being judged on whether those controls match actual risk and produce results.

What Financial Institutions Should Do Next 

FinCEN has indicated a 12-month implementation window once a final rule is issued [5], giving institutions a real, if not unlimited, runway to prepare. Rather than wait for the final text, institutions should begin working through the following:

  • Does our enterprise-wide risk assessment accurately reflect our current products, customers, geographies, and delivery channels?
  • Are compliance resources allocated according to our highest-risk exposures?
  • Can we clearly explain and document why specific controls have been implemented?
  • Are the AML/CFT Priorities incorporated into our risk assessment, monitoring, investigations, and governance processes?
  • Are we using technology and data analytics to improve program effectiveness in a way we could defend to an examiner?

Working through these questions now, rather than after a final rule takes effect, is what separates institutions that treat this as a documentation update from those that build something genuinely risk-based.

How Integro Advisers Can Help

Meeting that bar set by NPRM requires an honest, external look at where a compliance program actually stands. Integro Advisers works with banks on exactly this kind of preparation: testing whether an enterprise-wide risk assessment genuinely reflects current products, customers, and geographies; validating that transaction monitoring and screening models are tuned to that risk profile rather than legacy thresholds; and reviewing internal controls and due diligence processes to confirm they’d hold up under the new establishment-and-maintenance framework. For institutions still deciding whether this rule means a documentation update or a real overhaul, that kind of independent assessment is often the fastest way to find out. 

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Introducing Integro Talks, an engaging podcast series presented by Integro Advisers.  Join us as we delve into the dynamic realm of compliance, risk management, and due diligence, delivering expert insights and analysis to empower you in making well-informed business decisions.

Find us on:

Find us on:

Podcast