Share

FinCEN and Banking Agencies Propose Rules to Update AML/CFT Program Requirements

Alert
06.11.2026
By Heidi Wicker, Audrey Carroll, Matthew Grimaldi & Marisa Perfetti

Recent companion proposed rulemakings, from each of (1) the Financial Crimes Enforcement Network (FinCEN) and (2) the Office of the Comptroller of the Currency, Federal Deposit Insurance Corporation, and National Credit Union Administration (collectively, the Banking Agencies) would fundamentally modify and update existing anti-money laundering (AML) and counter the financing of terrorism (CFT) programs for financial institutions regulated under the Bank Secrecy Act (BSA). Comments on the proposed rules were due June 9, 2026.

A central objective of both proposals is to shift the focus of AML/CFT program requirements with an effectiveness standard. Under the proposed rules, a financial institution would have an "effective" AML/CFT program if it (1) is established in accordance with the proposed rule's requirements, and (2) is implemented in all material respects.

The proposed rules also incorporate risk assessment processes as a mandatory component of an effective AML/CFT program. Both proposed rules require financial institutions to establish risk-based policies, procedures, and controls that are reasonably designed to ensure compliance with the BSA, and that:

(i) evaluate the money laundering, terrorist financing, and other illicit finance activity risks of the financial institution’s business;

(ii) review and, as appropriate, incorporate the AML/CFT priorities issued by FinCEN; and

(iii) are promptly updated upon any change that the financial institution knows or has reason to know changes its money laundering, terrorist financing, or other illicit finance activity risks.

Additionally, the proposed rules would require that an effective AML/CFT program direct more attention and resources to higher-risk customers and activities, consistent with the risk profile of the specific financial institution. Regulators will not "second-guess" a financial institution's resource allocation; however, examiners will be expected to assess whether: (1) a financial institution's resource allocation decisions are informed by, and consistent with, reasonably designed risk assessment processes; and (2) when making resource allocation determinations, whether the financial institution knows or should know of resource-related issues that may result in the failure to implement the AML/CFT program in all material respects, and failing to address such issues.

Another significant change to the existing AML/CFT framework is that both proposals introduce a new supervision and enforcement framework that significantly enhances FinCEN's role. Under the proposals, the relevant Banking Agency would be required to provide at least 30 days' written notice to the FinCEN Director before initiating an AML/CFT enforcement action or a significant AML/CFT supervisory action1, to allow the FinCEN Director to review the action and provide input to the Banking Agency.

The proposed rules also standardize the requirement that regulated financial institutions designate an AML/CFT officer who is located in the United States and is accessible to, and subject to oversight by, federal financial regulators. Personnel located outside of the United States may still perform certain AML/CFT functions, but the U.S.-based AML/CFT officer must be responsible for establishing and implementing the AML/CFT program and coordinating day-to-day compliance. The officer must be qualified and not overburdened with other responsibilities, and it is critical that the officer have authority, independence, and access to resources within the institution.

FinCEN and the Banking Agencies are encouraging financial institutions to evaluate whether new technology or innovative approaches, including machine learning and generative artificial intelligence, may help to more effectively combat financial crime. In fact, under the proposal, financial institutions that responsibly incorporate innovative technologies into their AML/CFT programs will not incur any additional risk of being subject to a significant supervisory action or enforcement action solely for such use of innovative technologies.

Stinson LLP attorneys routinely advise financial institutions in their compliance with AML/CFT program requirements and are actively following these proposed rulemakings. For additional information, reach out to Heidi Wicker, Audrey Carroll, Matthew Grimaldi, Marisa Perfetti or the Stinson LLP contact with whom you regularly work.


1. "Significant AML/CFT supervisory action" is defined in the Banking Agencies' proposed rule as "any written communication or other formal supervisory determination that – (i) Identifies one or more alleged deficiencies, weaknesses, violations of law, or unsafe or unsound practices or conditions relating to an AML/CFT requirement; (ii) Communicates supervisory expectations to a national bank or Federal savings association regarding actions or remedial measures required to correct the deficiency, weakness, violation, or practice or condition; and (iii) Contemplates significant or programmatic actions or remedial measures to be taken by the national bank or Federal savings association." A similar definition is contained in FinCEN's proposed rule.

Subscribe to Stinson's
News & Insights
Jump to Page

We use cookies on our website to improve functionality and performance, analyze website traffic and enable social media features. For more information, please see our Cookie Policy.