NPRM: Anti-Money Laundering and Countering the Financing of Terrorism Programs (all FIs, incl. MSBs) (91 FR 18704) (Part 1 of 5)
Document text
Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.
18704 Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
DEPARTMENT OF THE TREASURY Strategic Affairs Division, Financial services businesses (MSBs); (4) brokers
Crimes Enforcement Network, P.O. Box or dealers in securities (broker-dealers);
Financial Crimes Enforcement Network 39, Vienna, VA 22183. Refer to Docket (5) mutual funds; (6) insurance
Number FINCEN–2026–0034 and RIN companies; (7) futures commission
31 CFR Parts 1010, 1020, 1021, 1022, 1506–AB72. Mailed comments must be merchants (FCMs) and introducing
1023, 1024, 1025, 1026, 1027, 1028, received by the close of the comment brokers in commodities (IBCs); (8)
1029, and 1030 period. dealers in precious metals, precious
Do not include any personally stones, or jewels (DPMSJs); (9) operators
RIN 1506–AB72 identifiable information (such as name, of credit card systems; (10) loan or
Anti-Money Laundering and address, or other contact information) or finance companies; and (11) housing
Countering the Financing of Terrorism confidential business information that government sponsored enterprises
you do not want publicly disclosed. All (housing GSEs).
Programs
comments are public records; they are
publicly displayed exactly as received, II. Background
AGENCY: Financial Crimes Enforcement
Network (FinCEN), Treasury. and will not be deleted, modified, or A. Anti-Money Laundering Programs
ACTION: Proposed rule. redacted. Comments may be submitted Under the Bank Secrecy Act
anonymously. Enacted in 1970 and amended several
SUMMARY: Pursuant to the Department of Follow the search instructions on
times since, the BSA is designed to
the Treasury (Treasury) and FinCEN’s https://www.regulations.gov to view
combat money laundering, the financing
efforts to modernize the Bank Secrecy public comments. In accordance with 5
of terrorism, and other illicit finance
Act (BSA) and to implement provisions U.S.C. 553(b)(4), a summary of this rule
activity risks 3 (collectively, ML/TF
of the Anti-Money Laundering Act of may be found at www.regulations.gov
risks).4 Congress has authorized the
2020 (AML Act), FinCEN is proposing a under Docket FINCEN–2026–0034.
Secretary of the Treasury (Secretary) to
rule to fundamentally reform the FOR FURTHER INFORMATION CONTACT: The administer the BSA. The Secretary has
requirements for financial institutions’ FinCEN Regulatory Support Section at in turn delegated the authority to
anti-money laundering and countering www.fincen.gov/contact. implement, administer, and enforce
the financing of terrorism (AML/CFT) SUPPLEMENTARY INFORMATION: compliance with the BSA and its
programs. Among other changes, this associated regulations to the Director of
I. Scope
proposed rule aims to ensure that FinCEN (Director).5
financial institutions establish and The proposed rule would amend Since its original enactment, Congress
maintain effective AML/CFT programs FinCEN’s regulations that prescribe anti- has continued to address various
that better achieve the purposes of the money laundering program aspects of AML/CFT compliance,
BSA and lead to more effective requirements for financial institutions including through expansion of the
outcomes for financial institutions as (AML program rules) 1 under the BSA.2 BSA.6 In 1992, the Annunzio-Wylie
well as law enforcement and national For purposes of the AML program rules Anti-Money Laundering Act 7 gave the
security agencies. Through this and this proposed rule, ‘‘financial Secretary authority to prescribe
rulemaking, consistent with its statutory institutions’’ are: (1) banks; (2) casinos minimum standards for AML programs,
authority as the administrator of the and card clubs (casinos); (3) money including: ‘‘(A) the development of
BSA, FinCEN is also proposing
1 When referring to the existing program rules, the
measures to modernize and reform 3 As defined in section 281(5) of the Countering
term ‘‘AML program rules’’ is used; when referring America’s Adversaries Through Sanctions Act, the
Federal supervision of AML/CFT to the requirements that this NPRM is proposing, term ‘‘illicit finance’’ means ‘‘the financing of
programs by enhancing FinCEN’s role in the term ‘‘AML/CFT program rules’’ is used. terrorism, narcotics trafficking, or proliferation,
AML/CFT supervision and enforcement 2 Certain parts of the Currency and Foreign
money laundering, or other forms of illicit financing
in coordination with Federal banking Transactions Reporting Act, its amendments, and domestically or internationally, as defined by the
the other statutes relating to the subject matter of President.’’ Public Law 115–44 (Aug. 2, 2017).
regulators. In addition, FinCEN is that Act, have come to be referred to as the BSA. 4 31 U.S.C. 5311.
proposing regulatory amendments to These statutes are codified at 12 U.S.C. 1829b, 12 5 Treasury Order 180–01 (Jan. 14, 2020), para. 3,
promote clarity and consistency across U.S.C. 1951–1960, and 31 U.S.C. 5311–5314 and
https://home.treasury.gov/about/general-
FinCEN’s program rules for different 5316–5336 and notes thereto, with implementing
regulations at 31 CFR chapter X. Certain criminal information/orders-and-directives/treasury-order-
types of financial institutions. statutes—namely, 18 U.S.C. 1956, 1957, and 1960— 180-01; see also 31 U.S.C. 310(b)(2)(I) (providing
that the Director of FinCEN shall ‘‘[a]dminister the
DATES: Comments must be received by are included in the BSA definition at 31 CFR
1010.100(e). Section 6003 of the AML Act, however, requirements of subchapter II of chapter 53 of this
June 9, 2026. title, chapter 2 of title I of Public Law 91–508, and
does not include these provisions in its BSA
ADDRESSES: Comments must be definition, and thus FinCEN is not considering section 21 of the Federal Deposit Insurance Act, to
the extent delegated such authority by the
submitted in one of the following two them part of the BSA for the purposes of this
Secretary.’’).
proposed rule. The AML program rules are located
ways (please choose only one of the at 31 CFR 1020.210 (banks), 1021.210 (casinos), 6 Most recently, Congress enacted the Guiding
ways listed): 1022.210 (MSBs), 1023.210 (broker-dealers), and Establishing National Innovation for U.S.
• Electronically at https:// 1024.210 (mutual funds), 1025.210 (insurance Stablecoins (GENIUS) Act on July 18, 2025. Public
www.regulations.gov. Follow the companies), 1026.210 (FCMs and IBCs), 1027.210 Law 119–27, codified at 12 U.S.C. 5901 et seq. The
(DPMSJs), 1028.210 (operators of credit card GENIUS Act requires that permitted payment
‘‘Submit a comment’’ instructions. If systems), 1029.210 (loan or finance companies), and stablecoin issuers be treated as financial institutions
you are reading this document on 1030.210 (housing GSEs). FinCEN notes this for purposes of the BSA including being required
federalregister.gov, you may use the proposed rule does not propose any amendments to to maintain ‘‘an effective anti-money laundering
program.’’ See 12 U.S.C. 5903(a)(5)(A)(i). The
lotter on DSK8BHNXB4PROD with PROPOSALS4
green ‘‘SUBMIT A PUBLIC COMMENT’’ the final rule establishing AML/CFT and suspicious
activity report (SAR) filing requirements for GENIUS Act also requires the Agencies to issue
button beneath this rulemaking’s title to registered investment advisers and exempt regulations relating to PPSIs, including regulations
submit a comment to the regulations.gov reporting advisers, which has been delayed until pertaining to BSA compliance standards. 12 U.S.C.
docket. Refer to Docket Number January 1, 2028. See FinCEN, Delaying the Effective 5903(a)(4)(iv). These AML/CFT requirements and
FINCEN–2026–0034 and RIN 1506– Date of the Anti-Money Laundering/Countering the standards for PPSIs are addressed separately from
Financing of Terrorism Program and Suspicious this rulemaking.
AB72. Activity Report Filing Requirements for Registered 7 Section 1517 of the Annunzio-Wylie Anti-
• You may mail written comments to Investment Advisers and Exempt Reporting Money Laundering Act, Public Law 102–550, 106
the following address: Regulatory and Advisers Final Rule, 91 FR 36 (Jan. 2, 2026). Stat. 3672 (Oct. 28, 1992).
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00002 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules 18705
internal policies, procedures, and Congress stated that it was seeking to Secretary must promulgate regulations,
controls, (B) the designation of a modernize and strengthen the AML/CFT as appropriate, to incorporate those
compliance officer, (C) an ongoing regulatory framework, which ‘‘had not priorities into revised program rules,
employee training program, and (D) an seen comprehensive reform or and incorporation of the priorities must
independent audit function to test modernization’’ since the BSA was be included as a measure on which
programs’’—what are often called the enacted in the 1970s.14 Among other financial institutions are supervised and
‘‘four pillars’’ of AML programs.8 Later, objectives, Congress intended for the examined. FinCEN issued the first
the Uniting and Strengthening America AML Act to require ‘‘more routine and AML/CFT Priorities on June 30, 2021.17
by Providing Appropriate Tools systemic coordination, communication, Third, section 6101(b) expands the
Required to Intercept and Obstruct and feedback among financial BSA’s program rule requirement to
Terrorism Act of 2001 (USA PATRIOT institutions, regulators, and law formally include an express reference to
Act) further amended the BSA to enforcement to identify suspicious CFT in addition to AML.
include, among other things, customer financial activities, better focusing bank Fourth, section 6101(b) provides that
identification program (CIP) resources to the AML task, which will the duty to establish, maintain, and
requirements and the expansion of AML increase the likelihood for better law enforce an AML/CFT program shall
program rules to cover certain other enforcement outcomes.’’ 15 remain the responsibility of, and be
financial industry participants (e.g., Section 6101(b) of the AML Act made performed by, persons in the United
credit unions and FCMs).9 The USA several changes to the BSA’s AML/CFT States who are accessible to, and subject
PATRIOT Act also made it mandatory program requirements. to, oversight and supervision by, the
for financial institutions to maintain First, section 6101(b) amended the Secretary and the appropriate Federal
AML programs that meet minimum BSA at 31 U.S.C. 5318(h)(2)(B) to state functional regulator.
prescribed standards.10 Through the that, ‘‘[i]n prescribing the minimum
B. FinCEN’s Effectiveness Advance
exercise of its delegated authority, standards [for AML/CFT programs], and
Notice of Proposed Rulemaking
FinCEN is authorized to require each in supervising and examining
(ANPRM)
financial institution to establish an AML compliance with those standards, the
Secretary of the Treasury, and the Prior to the enactment of the AML
program to ensure compliance with the Act, and as informed by the
BSA and guard against ML/TF risks.11 appropriate Federal functional regulator
(as defined in section 509 of the Gramm- recommendations of the AML
Over time, FinCEN incorporated these Effectiveness Bank Secrecy Act
standards into the AML program rules Leach-Bliley Act) 16 shall take into
account’’ certain factors, which are Advisory Group working group, FinCEN
and implemented additional published an ANPRM seeking public
requirements for certain covered further described in section IV.A.
Second, section 6101(b) requires the comment on potential regulatory
financial institutions, such as customer amendments to increase the
Secretary, in consultation with the
due diligence (CDD) requirements effectiveness of the current program
Attorney General, appropriate Federal
(sometimes referred to as the ‘‘fifth rules (Effectiveness ANPRM).18 The
functional regulators, relevant State
pillar’’ of AML programs).12 financial regulators, and relevant Effectiveness ANPRM sought public
On January 1, 2021, Congress enacted national security agencies, to establish comment on a number of issues,
the William M. (Mac) Thornberry and make public government-wide including whether FinCEN should
National Defense Authorization Act for AML/CFT priorities (AML/CFT define an effective and reasonably
Fiscal Year 2021 (FY21 NDAA), of Priorities). After consultation with the designed AML program as one that: (1)
which the AML Act was a component.13 Federal functional regulators and identifies, assesses, and reasonably
With the passage of the AML Act, relevant State financial regulators, the mitigates the risks resulting from illicit
8 31 U.S.C. 5318(h)(1), as added by section
financial activity, including terrorist
1517(b) of the Annunzio-Wylie Anti-Money
14 Congress noted in its Joint Explanatory financing, money laundering, and other
Laundering Act, Public Law 102–550 (Oct. 28,
Statement of the Committee of Conference related financial crimes, consistent with
accompanying the FY21 NDAA that: ‘‘the current both the institution’s risk profile and the
1992). FinCEN notes the proposed rule sequences
[AML/CFT] regulatory framework is an
these AML/CFT program components—the four
amalgamation of statutes and regulations that are risks communicated by relevant
pillars—in the order of the existing AML program government authorities as national AML
grounded in the [BSA], which the Congress enacted
rule for banks, rather than the order used in 31
in 1970. This decades-old regime, which has not
U.S.C. 5318(h)(1): namely, (i) a system of internal
seen comprehensive reform and modernization 17 See FinCEN, AML/CFT Priorities (June 30,
controls to assure ongoing compliance; (ii)
since its inception, is generally built on individual 2021). As required by 31 U.S.C. 5318(h)(4)(C), the
independent testing for compliance to be conducted reporting mechanisms (i.e., currency transaction
by bank personnel or by an outside party; (iii) AML/CFT Priorities are consistent with Treasury’s
reports (CTRs) and SARs) and contemplates aging, National Strategy for Combating Terrorist and Other
designation of an individual or individuals decades-old technology, rather than the current,
responsible for coordinating and monitoring day-to- Illicit Financing (May 16, 2024) and supported by
sophisticated AML compliance systems now Treasury’s National Risk Assessments on Money
day compliance; and (iv) training for appropriate managed by most financial institutions.’’ Congress
personnel. See 31 CFR 1020.210(a)(2). FinCEN, Laundering, Terrorist Financing, and Proliferation
further stated that the AML Act ‘‘comprehensively Financing. See U.S. Department of the Treasury,
however, does not intend the change in sequencing update[s] the BSA for the first time in decades and
to modify or signify changes in any substantive 2026 National Money Laundering Risk Assessment
provide[s] for the establishment of a coherent set of (March 2026), https://home.treasury.gov/system/
requirements. risk-based priorities.’’ Among other objectives,
9 31 U.S.C. 5312(a)(2)(E) and 31 U.S.C. 5312(c), as files/246/2026-NMLRA.pdf; 2026 National Terrorist
Congress intended for the AML Act to require Financing Risk Assessment (March 2026), https://
added by section 321 of the USA PATRIOT Act, ‘‘more routine and systemic coordination, home.treasury.gov/system/files/246/2026-
Public Law 107–56, 115 Stat. 272 (Oct. 26, 2001). communication, and feedback among financial
10 31 U.S.C. 5318(h), as added by section 352 of
NTFRA.pdf; 2026 National Proliferation Financing
institutions, regulators, and law enforcement to Risk Assessment (March 2026), https://
the USA PATRIOT Act, Public Law 107–56, 115 identify suspicious financial activities, better home.treasury.gov/system/files/246/2026-
lotter on DSK8BHNXB4PROD with PROPOSALS4
Stat. 272 (Oct. 26, 2001). focusing bank resources to the AML task, which NPFRA.pdf. As also required by 31 U.S.C.
11 31 U.S.C. 5318(a)(2), (h)(1), (h)(2); supra note will increase the likelihood for better law 5318(h)(4)(B), the Secretary, in consultation with
5 enforcement outcomes.’’ H.R. Rep. No. 6395 (2020) the Attorney General, Federal functional regulators,
12 See FinCEN, Customer Due Diligence at pp. 731–732 (Joint Explanatory Statement of the relevant State financial regulators, and relevant
Requirements for Financial Institutions, 81 FR Committee of Conference). national security agencies, must update the AML/
29398 (May 11, 2016). 15 H.R. Rep. No. 6395 (2020) at pp. 731–732 (Joint CFT Priorities not less frequently than once every
13 William M. (Mac) Thornberry National Defense Explanatory Statement of the Committee of four years.
Authorization Act for Fiscal Year 2021, Public Law Conference). 18 FinCEN, Anti-Money Laundering Program
116–283, 134 Stat. 3388 (Jan. 1, 2021). 16 15 U.S.C. 6809(2). Effectiveness, 85 FR 58023 (Sept. 17, 2020).
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00003 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
18706 Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
priorities; (2) assures and monitors under section 6101(b) of the AML Act. overseen by the financial institution’s
compliance with the recordkeeping and Additionally, on August 9, 2024, the board of directors (board) or equivalent
reporting requirements of the BSA; and Office of the Comptroller of the governing body and would have made
(3) provides information with a high Currency (OCC), the Board of Governors AML/CFT program approval and
degree of usefulness to government of the Federal Reserve System (FRB), the oversight requirements consistent across
authorities consistent with both the Federal Deposit Insurance Corporation financial institution types. Furthermore,
financial institution’s risk assessment (FDIC), and the National Credit Union the 2024 Program NPRM reflected the
and the risks communicated by relevant Administration (NCUA) (collectively, requirement in the BSA, as amended by
government authorities as national AML the ‘‘Agencies’’) 22 issued an NPRM the AML Act, that the duty to establish,
priorities.19 proposing amendments to their maintain, and enforce a financial
Additionally, the Effectiveness respective AML program rules institution’s AML/CFT program shall
ANPRM sought comment on whether applicable to the financial institutions remain the responsibility of, and be
FinCEN should amend its regulations to they regulate.23 performed by, persons in the United
explicitly require financial institutions The 2024 Program NPRM proposed States who are accessible to, and subject
to implement risk assessment processes that financial institutions establish to oversight and supervision by, the
and whether FinCEN should publish AML/CFT programs that would include, Secretary and the appropriate Federal
AML priorities that financial at minimum, the following components: functional regulator.
institutions would incorporate into their (1) a risk assessment process; (2) FinCEN does not intend to finalize the
risk assessments.20 Congress enacted the reasonable management and mitigation 2024 Program NPRM, and it should be
AML Act shortly after FinCEN received of illicit finance risks through internal considered withdrawn and superseded
comments on the Effectiveness ANPRM. policies, procedures, and controls; (3) a by this proposed rule.
As a result, many of the Effectiveness qualified AML/CFT officer; (4) an
ANPRM’s proposals have been 2. Comments FinCEN Received on the
ongoing employee training program; (5)
superseded by statutory amendments. 2024 Program NPRM
independent, periodic testing conducted
FinCEN received 111 comments in by qualified personnel of the financial In response to the 2024 Program
response to the Effectiveness ANPRM, institution or by a qualified outside NPRM, FinCEN received 86 comments
many of which generally supported the party; and (6) other requirements (such from the public. Submissions came from
goals underlying the ANPRM. Some as customer due diligence) depending a broad array of individuals and
comments covered specific topics that on the type of financial institution. organizations, including members of
would later be addressed in section The 2024 Program NPRM further Congress, the financial industry and
6101 of the AML Act and that are proposed that financial institutions related trade associations, groups
related to the proposed rule. For would be expected to base their AML/ representing small business interests,
example, many commenters supported CFT program on the results of a risk corporate transparency advocacy
the Effectiveness ANPRM’s concepts of assessment process. The risk assessment groups, regulatory associations, legal
effective and reasonably designed AML process would identify, evaluate, and associations, and other interested
programs. Commenters further noted document a financial institution’s ML/ groups and individuals.
that prioritizing and allocating resources TF risks, taking into account the A small number of commenters
can be challenging if there is regulatory following considerations: (1) the AML/ expressed support for the 2024 Program
ambiguity or if examiner expectations CFT Priorities issued by FinCEN, as NPRM’s effort to modernize and
are unclear or inconsistent, and that appropriate; (2) the ML/TF risks of the strengthen AML/CFT programs in line
requirements for effective and financial institution based on the with the reform goals of the AML Act.
reasonably designed programs should be institution’s business activities, Some supporters of the 2024 Program
tailored based on a financial including products, services, NPRM agreed with its emphasis on
institution’s size, activities, or other distribution channels, customers, ‘‘effective, risk-based, and reasonably
characteristics. Finally, commenters intermediaries, and geographic designed’’ AML/CFT programs that
expressed widespread concern about locations; and (3) reports filed by the would promote ‘‘effectiveness,
added burden on financial institutions, financial institution pursuant to efficiency, innovation, and
especially burden related to updating FinCEN’s regulations at 31 CFR chapter flexibility.’’ 24 Others commended
AML programs to incorporate national X. Additionally, the 2024 Program FinCEN’s efforts to emphasize the risk-
AML priorities. NPRM provided that financial based nature of AML/CFT programs and
C. The 2024 Notice of Proposed institutions would have to review and provide financial institutions with the
Rulemaking Revising AML Programs update their risk assessments on a flexibility to provide financial services
periodic basis, including, at a minimum, based on their risk profile and capacity
1. Summary of 2024 Program Notice of
when there are material changes to a to manage customer relationships.
Proposed Rulemaking (NPRM)
financial institution’s illicit finance Commenters also expressed concerns
On July 3, 2024, FinCEN published an risks. with the 2024 Program NPRM, such as
NPRM proposing revisions to AML/CFT The 2024 Program NPRM would have the proposed program requirements
program requirements (2024 Program also required a financial institution’s being excessively prescriptive and even
NPRM).21 In issuing that proposed rule, AML/CFT program to be approved and redundant in light of the view that
FinCEN consulted with the Federal existing AML/CFT compliance
functional regulators, the Internal 22 As discussed below, these Federal agencies are
programs were already intended to be
lotter on DSK8BHNXB4PROD with PROPOSALS4
Revenue Service (IRS), and relevant also known as the Federal Financial Institutions
Regulatory Agencies (FFIRAs) and proposed
risk-based. A number of commenters
State financial regulators, as required 1010.100(ooo) defines these agencies using this found the proposal to be an additive
term. However, this preamble uses the term regulatory imposition that would
19 85 FR 58026.
‘‘Agencies’’ to refer to the FFIRAs. increase costs and burdens, particularly
20 Id. 23 FRB, FDIC, NCUA, and OCC, Anti-Money
21 FinCEN, Anti-Money Laundering and
to smaller financial institutions, without
Laundering and Countering the Financing of
Countering the Financing of Terrorism Programs, 89 Terrorism Program Requirements, 89 FR 65242
FR 55428 (July 3, 2024). (Aug. 9, 2024). 24 89 FR 55430.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00004 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules 18707
any increase in program effectiveness, the AML Act stating that BSA filings requested that FinCEN interpret this
efficiency, or innovation. should be guided by risk-based provision to allow financial institutions
On behalf of FinCEN, Treasury’s compliance programs, rather than the to maintain staff and operations in non-
Office of Tribal and Native Affairs opposite.26 Commenters also argued U.S. jurisdictions so long as the person
(OTNA) also solicited comments and that even the idea of making the risk with the ‘‘duty to establish, maintain,
conducted Tribal consultations and assessment process serve as the basis of and enforce the AML/CFT program’’ is
coordination with Tribal Nations. the AML/CFT program would be too located in the United States. Some
OTNA received six comments from prescriptive and not correspond to the commenters also requested clarification
Tribal representatives during this various ways financial institutions on how this provision would apply to
process. incorporate these assessments into their financial institutions with third-party
Taken together, the comments programs. Finally, commenters objected service providers located outside the
submitted to the Effectiveness ANPRM to the description of a risk assessment United States.
and 2024 Program NPRM provide process as a singular process that
helpful context that FinCEN has implied a one-time, annual exercise The 2024 Program NPRM also
considered in developing the current whereas financial institutions conduct proposed requiring that a financial
NPRM. numerous and often continuous risk institution’s board or an equivalent
assessments throughout the year. governing body approve and provide
i. Risk-Based Resource Allocation oversight of AML/CFT programs.29
The 2024 Program NPRM proposed a iii. ‘‘Effective, Risk-Based, and Commenters generally expressed
formulation of risk-based resource Reasonably Designed’’ AML/CFT reservations about the board approval
allocation as follows: ‘‘an effective, risk- Programs and oversight provision of the NPRM.
based, and reasonably designed AML/ Commenters generally appreciated Some credit union commenters
CFT program focuses attention and FinCEN’s inclusion of the concept of expressed concern that the requirement
resources in a manner consistent with ‘‘effective, risk-based, and reasonably would impose significant new burdens
the bank’s risk profile that takes into designed’’ AML/CFT programs, but on boards and noted that many credit
account higher risk and lower-risk sought additional guidance on the union boards are volunteers.
customers and activities.’’ 25 meaning of these terms. Some Commenters representing Native Tribes
Commenters criticized this formulation commenters requested that FinCEN were most critical of the board oversight
of risk-based resource allocation in the adopt specific regulatory definitions of and approval requirement because of
NPRM and generally stated that this these terms, while others requested the potential impact on Tribal casinos
framing would not sufficiently enable principles or examples to clarify how and Tribal Councils. Several of these
financial institutions to reallocate FinCEN understands them. Several commenters stated that many Tribal
resources in the manner intended by the commenters urged that the final rule gaming entities are not operated under
AML Act by allowing financial clarify that an ‘‘effective, risk-based, and the authority of a business board.
institutions to direct more resources reasonably designed’’ program does not Commenters expressed concern that the
toward higher-risk customers and mean one that is ‘‘perfect’’ and proposed rule may require Tribal
activity rather than lower-risk customers completely prevents financial crime. Councils to approve and provide
and activity, leaving open the concern oversight of the AML/CFT program
iv. Other Provisions of the 2024 NPRM
that examiners may penalize financial adopted by the casino, detracting from
institutions for doing so. Commenters Proposed § 1020.210(c) of the 2024 other responsibilities of the Tribal
strongly recommended that FinCEN Program NPRM provided that ‘‘[t]he Council.
adopt the statutory language from the duty to establish, maintain, and enforce
AML Act concerning risk-based the AML/CFT program must remain the v. Effective Date
resource allocation. No commenters responsibility of, and be performed by,
persons in the United States who are The 2024 Program NPRM proposed
expressed support for the 2024 Program
NPRM formulation. accessible to, and subject to oversight that financial institutions would have
and supervision by, FinCEN and the six months from the date of issuance of
ii. The Risk Assessment Process appropriate Federal functional the final rule to comply with its
Commenters to the 2024 Program regulator,’’ 27 pursuant to the statutory requirements. A large number of
NPRM were critical of the proposed risk requirement set forth in section 6101 of commenters reacted negatively to the
assessment process. Commenters the AML Act.28 Many commenters six-month implementation period in the
generally supported the idea of a risk discussed this provision. They generally 2024 Program NPRM, and they were
assessment process requirement in the stated that an appropriate interpretation nearly unanimous in requesting
NPRM, as many financial institutions of this provision is critical for many additional time. Some commenters
already conduct risk assessments. financial institutions since many have asked for at least one year after issuance
Commenters argued, however, that the AML/CFT staff and operations overseas, of the final rule to implement the rule,
proposal was insufficiently deferential and it would be extremely costly and and other commenters requested two or
to existing risk assessment practices and disruptive to require relocation to the more years. Some commenters
would impose new compliance costs by United States. Many commenters representing larger financial institutions
creating an additive ‘‘check-the-box’’ cited the need for additional time to
exercise for financial institutions that 26 ‘‘Reports filed under this subsection shall be
review the final rule, make
guided by the compliance program of a covered technological changes or other changes
lotter on DSK8BHNXB4PROD with PROPOSALS4
already conduct risk assessments. financial institution with respect to the Bank
Commenters also stated that financial Secrecy Act, including the risk assessment to existing processes, incorporate the
institutions should not be required to processes of the covered institution that should AML/CFT Priorities into their risk
consider BSA reports, including SARs include a consideration of priorities established by assessment processes, reallocate
the Secretary of the Treasury under section 5318.’’ resources from lower- to higher-risk
and CTRs, as part of their risk 31 U.S.C. 5318(g)(5)(C), as added by section 6202
assessment process, noting language in of the AML Act. areas, and provide training.
27 89 FR 55485.
25 89 FR 55436. 28 31 U.S.C. 5318(h)(5). 29 89 FR 55444.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00005 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
18708 Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
III. BSA Modernization 2025, the Agencies, with FinCEN’s technical compliance. Furthermore, the
The Secretary has identified BSA concurrence, issued an order permitting proposed rule for banks would help
reform and modernization as one of banks, as part of their CIP obligations, ensure that supervisory and
Treasury’s top priorities. In an April to collect Taxpayer Identification enforcement actions related to AML/
2025 speech, the Secretary noted that Number information from a third party CFT programs are focused on significant
Treasury ‘‘will advocate for changes to rather than from the bank’s customer.34 or systemic failures to implement an
the AML/CFT framework to truly focus In October 2025, FinCEN and the effective AML/CFT program (i.e.,
on national security priorities and Agencies issued Frequently Asked deficiencies or issues that arise from
higher-risk areas and explicitly permit Questions to clarify certain SAR failing to implement, in all material
financial institutions to de-prioritize obligations to help ensure financial respects, a properly established AML/
lower risks.’’ 30 Additionally, the institutions are not needlessly CFT program). The proposal would also
Secretary has noted that supervision of expending resources on efforts that do reflect FinCEN’s key role, in accordance
not provide law enforcement and with its statutory authority as the
AML/CFT programs has too often
national security agencies with the administrator of the BSA, in ensuring a
involved a ‘‘zero-tolerance focus on
critical information they need to detect, consistent and holistic approach to
process and documentation and wide
combat, and deter criminal activity.35 In enforcement and supervision of banks’
latitude for supervisory expectations
February 2026, FinCEN issued an order AML/CFT programs that focuses on
and judgments that are not always
granting exceptive relief to covered program effectiveness rather than mere
consistent with the law or our national
financial institutions from certain technical compliance. The Agencies
security priorities.’’ 31 The Secretary
requirements under FinCEN’s CDD have a long history of coordination with
noted that this proposed rule would
Rule, supporting a more efficient, risk- FinCEN in exercising its delegated
ensure that financial institutions’ AML/
based approach to customer due supervisory authority, and FinCEN
CFT programs are focused ‘‘on higher views this proposed rule as a way to
value activities [that] will also better diligence and reducing unnecessary
regulatory burden without weakening further strengthen that relationship to
serve our law enforcement and national promote more consistent supervision.
security objectives.’’ 32 the foundational requirements that
protect the U.S. financial system.36 FinCEN believes this enhanced
In June 2025, Treasury identified its
In addition to advancing the goals of coordination in AML/CFT supervision
guiding principles for BSA reform,
a modernized BSA regulatory and and enforcement will support the goals
recognizing the urgent need to
supervisory regime, Treasury and of E.O. 14192.
modernize the implementation of the Fulfilling the AML Act’s goals of BSA
AML/CFT regime in the United States FinCEN have played a leading role in
supporting Executive Order (E.O.) modernization and reform is a priority
so that it is effective, risk-based, and for Treasury and FinCEN, and this
focused on the greatest threats to 14192, Unleashing Prosperity Through
Deregulation.37 The E.O. announced an proposed rule is a major part of that
financial institutions and national effort.
security.33 Treasury’s vision of a Administration policy to ‘‘significantly
modernized BSA regulatory and reduce the private expenditures IV. Overview of the Proposed Rule
supervisory regime is one where required to comply with Federal
regulations to secure America’s A central objective of Treasury and
financial institutions: FinCEN’s BSA modernization efforts is
• comply with AML/CFT laws and economic prosperity and national
security and the highest possible quality to create an AML/CFT supervisory and
regulations; regulatory regime that is more effective
• are examined for the risk-based and of life for each citizen’’ and ‘‘alleviate
unnecessary regulatory burdens placed in achieving the purposes of the BSA
reasonably designed nature of their and promoting better outcomes for law
AML/CFT programs and set of internal on the American people.’’ 38 Consistent
with E.O. 14192, FinCEN is issuing this enforcement and national security
policies, procedures, and controls; agencies.39 This proposed rule would
• direct more resources to higher-risk proposed rule to ensure that financial
further that objective by explicitly
areas rather than to lower-risk areas; and institutions’ AML/CFT programs are
defining the requirements for a financial
• generate highly useful information appropriately risk-based, such that
institution to establish and maintain an
for law enforcement and national compliance with their program
obligations is focused on the goals of the effective AML/CFT program. It would
security agencies in priority areas also adopt into regulations the AML
defined by Treasury. BSA, including combatting and
preventing ML/TF, rather than mere Act’s expectation that AML/CFT
Treasury and FinCEN, in coordination
programs should be risk-based,
with the Agencies, have taken a number
34 FinCEN, FinCEN Permits Banks to Use including ensuring that financial
of steps to implement this vision of a
Alternative Collection Method for Obtaining TIN institutions direct more attention and
modernized BSA regulatory and Information (June 27, 2025), https:// resources toward higher-risk customers
supervisory regime. In June and July www.fincen.gov/news/news-releases/fincen- and activities, consistent with the risk
permits-banks-use-alternative-collection-method-
30 U.S. Department of the Treasury, Press Release, obtaining-tin-information.
profile of the financial institution, rather
‘‘Treasury Secretary Scott Bessent Remarks before 35 FinCEN, FinCEN Issues Frequently Asked than toward lower-risk customers and
the American Bankers Association’’ (Apr. 9, 2025), Questions to Clarify Suspicious Activity Reporting activities.40
https://home.treasury.gov/news/press-releases/ Requirements (Oct. 9, 2025), https:// As noted in the previous section, the
sb0078. www.fincen.gov/news/news-releases/fincen-issues- proposed rule would also revise the
31 U.S. Department of the Treasury, Press Release, frequently-asked-questions-clarify-suspicious-
‘‘Remarks by Secretary of the Treasury Scott activity-reporting. AML/CFT supervisory and examination
lotter on DSK8BHNXB4PROD with PROPOSALS4
Bessent Before the Fed Community Bank 36 FinCEN, FinCEN Issues Exceptive Relief to process for banks by enhancing
Conference’’ (Oct. 9, 2025), https:// Streamline Customer Due Diligence Requirements FinCEN’s role in the supervision and
home.treasury.gov/news/press-releases/sb0276. (Feb. 13, 2026), https://www.fincen.gov/system/ enforcement process. In support of this
32 Id. files/2026-02/FinCEN-Order-CCDExceptiveRelief.
pdf.
objective, the proposed rule would
33 U.S. Department of the Treasury, Press Release,
‘‘Deputy Secretary Faulkender Lays Out Guiding 37 E.O. 14192, Unleashing Prosperity Through establish a mechanism in which
Principles for Bank Secrecy Act Modernization’’ Deregulation, 90 FR 9065 (issued Jan. 31, 2025;
published Feb. 6, 2025). 39 31 U.S.C. 5311.
(June 18, 2025), https://home.treasury.gov/news/
press-releases/sb0173. 38 Id. 40 31 U.S.C. 5318(h)(2)(B)(iv)(II).
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00006 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules 18709
FinCEN—as the statutory administrator and private benefit. The proposed rule facilitate financial transactions that
of the BSA—has an opportunity to reflects this in several ways—especially simultaneously prevent criminal
review and provide feedback to the in how it endeavors to avoid imposing persons from abusing formal or informal
Agencies prior to a significant unnecessary regulatory burdens and financial services networks.
supervisory action. This change will ensuring that financial institutions are The proposed rule would also provide
promote consistent approaches to AML/ able to tailor their AML/CFT programs financial institutions with the ability to
CFT supervision and better outcomes to their risk profiles. In this way, modernize their AML/CFT programs
for both banks and the law enforcement FinCEN seeks to ensure that financial and to responsibly innovate while still
and national security agencies that institutions are not required to expend managing ML/TF risks, as the financial
depend upon those financial private compliance funds without services industry continues to innovate
institutions’ critical BSA reporting. meaningful benefit to both the public over time. Consistent with previous
and their own operations. guidance,42 FinCEN encourages
A. Factors Rhat FinCEN Considered Second, section 5318(h)(2)(B)(ii) financial institutions to manage
Pursuant to Section 6101(b)(2)(B) of the requires FinCEN to consider the customer relationships on a case-by-case
AML Act (31 U.S.C. 5318(h)(2)(B)) extension of financial services to the basis, and the proposed rule would
Section 6101(b)(2)(B)(ii) of the AML underbanked and the facilitation of provide financial institutions with the
Act (codified at 31 U.S.C. 5318(h)(2)(B)) financial transactions, including framework to make such evaluations
requires FinCEN to take into account remittances, while preventing criminal and provide financial services
certain factors when prescribing persons from abusing formal or informal accordingly, without broad de-risking
minimum AML/CFT program standards: financial services networks. Through its that can result in debanking that may
(i) Financial institutions are spending emphasis on risk-based AML/CFT increase the use of financial services
private compliance funds for a public programs, the proposed rule seeks to that exist outside of the regulated
and private benefit, including protecting provide financial institutions with the financial system and complicate efforts
the United States financial system from flexibility to serve a broad range of to detect and deter illicit finance.
illicit finance risks. customers and avoid one-size-fits-all FinCEN believes that effective AML/
(ii) The extension of financial services approaches to customer risk that can CFT programs are an important
to the underbanked and the facilitation lead to financial institutions declining component in mitigating the effects of
of financial transactions, including to provide financial services to entire de-banking to national security and law
remittances, coming from the United categories of customers. The proposed enforcement interests.
States and abroad in ways that rule would help ensure that decisions Third, as stated in 31 U.S.C.
simultaneously prevent criminal taken by financial institutions with 5318(h)(2)(B)(iii), effective AML/CFT
persons from abusing formal or informal respect to closing customer accounts are programs safeguard national security
financial services networks are key based on legitimate ML/TF risks and and generate significant public benefits
policy goals of the United States. informed by relevant facts and by preventing the flow of illicit funds in
(iii) Effective anti-money laundering circumstances. The proposed rule is the financial system and by assisting
and countering the financing of intended to mitigate the risks of law enforcement and national security
terrorism programs safeguard national financial institutions potentially being agencies with the identification and
security and generate significant public inappropriately pressured into closing prosecution of persons attempting to
benefits by preventing the flow of illicit customer accounts by emphasizing the launder money or undertake other illicit
funds in the financial system and by risk-based nature of AML/CFT activity through the financial system.43
assisting law enforcement and national programs. In doing so, the proposed rule The proposed rule would advance the
security agencies with the identification also furthers the objectives of E.O. BSA modernization and reform goals of
and prosecution of persons attempting 14331, Guaranteeing Fair Banking for the AML Act by providing financial
to launder money and undertake other All Americans, which seeks to combat institutions and their regulators with
illicit activity through the financial ‘‘politicized or unlawful debanking.’’ 41 clarity about the requirements to have
system. Moreover, by establishing a risk-based effective AML/CFT programs.
(iv) Anti-money laundering and AML/CFT program that takes into Likewise, 31 U.S.C.
countering the financing of terrorism account a financial institution’s specific 5318(h)(2)(B)(iv)(I) provides that AML/
programs . . . should be— business activities, the proposed rule CFT programs should be ‘‘reasonably
(I) reasonably designed to assure and will enable financial institutions to designed to assure and monitor
monitor compliance with the avoid debanking customers and extend compliance’’ with the BSA and its
requirements of this subchapter and financial services based on a financial implementing regulations and be risk-
regulations promulgated under this institution’s evaluation of the ML/TF based. As described in more detail in
subchapter; and risks and the financial institution’s section IV, the proposed rule advances
(II) risk-based, including ensuring that ability to manage those risks and these objectives by explicitly requiring
more attention and resources of customer relationships, among other financial institutions to have effective
financial institutions should be directed considerations. This flexibility would AML/CFT programs and by describing
toward higher-risk customers and allow such financial institutions to the minimum components for an AML/
activities, consistent with the risk respond to changing circumstances and CFT program to be effective.
profile of a financial institution, rather evolving risk profiles, including through Specifically, as part of an effective
than toward lower-risk customers and the use of emerging technologies that AML/CFT program, the proposed rule
lotter on DSK8BHNXB4PROD with PROPOSALS4
activities. support transparency and preserve
FinCEN has considered all of these privacy, which may deter debanking 42 See FRB, FDIC, FinCEN, NCUA, and OCC, Joint
factors in developing this proposed rule. and enable financial institutions to Statement on the Risk-Based Approach to Assessing
First, as required by 31 U.S.C. Customer Relationships and Conducting Customer
reach underbanked individuals and Due Diligence (July 6, 2022), https://
5318(h)(2)(B)(i), FinCEN has considered
www.fincen.gov/news/news-releases/joint-
that, through their AML/CFT programs, 41 E.O. 14331, Guaranteeing Fair Banking for All statement-risk-based-approach-assessing-customer-
financial institutions are spending Americans, 90 FR 38925 (issued Aug. 7, 2025; relationships-and.
private compliance funds for a public published Aug. 12, 2025). 43 31 U.S.C. 5318(h)(2)(B)(iii).
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00007 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
18710 Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
requires that a financial institution controls must also be reasonably AML/CFT program) would warrant an
establish and maintain a risk-based set designed to: (1) identify, assess, and ‘‘AML/CFT enforcement action’’ or a
of internal policies, procedures, and document the financial institution’s ‘‘significant AML/CFT supervisory
controls that is reasonably designed to ML/TF risks through risk assessment action,’’ as these terms are defined in
ensure compliance with the BSA and processes that evaluate the risks of the the proposed rule. In this way, the
FinCEN’s regulations. institution’s business activities, review proposed rule is intended to clarify and
The internal policies, procedures, and and, as appropriate, incorporate the reinforce a supervisory and enforcement
controls requirement in the proposed AML/CFT Priorities, and are updated focus on addressing significant or
rule also demonstrates FinCEN’s promptly upon any change that the systemic failures to implement an
consideration of 31 U.S.C. financial institution knows or has effective AML/CFT program, rather than
5318(h)(2)(B)(iv)(II), which states that reason to know significantly changes the on isolated, technical, or immaterial
AML/CFT programs should be risk- institution’s ML/TF risks; (2) mitigate implementation issues.44
based, including ensuring that more the financial institution’s ML/TF risks,
attention and resources of financial Importantly, under the proposed
consistent with the financial
institutions should be directed toward regulations, having an effective AML/
institution’s risk assessment processes;
higher-risk customers and activities, CFT program would be more than a one-
and, for certain financial institutions, (3)
consistent with a financial institution’s time adoption of a risk-based set of
conduct ongoing customer due
risk profile, rather than toward lower- diligence. internal policies, procedures, and
risk customers and activities. While The proposed rule would also require controls. Rather, a financial institution
FinCEN has previously expected a financial institution to establish an would be required to keep its risk-based
financial institutions to adopt risk-based ongoing employee training program and set of internal policies, procedures, and
AML/CFT programs, the proposed rule independent AML/CFT program testing controls—and the risk assessment
incorporates this directive by explicitly as part of its AML/CFT program. processes that inform them—current as
requiring, as part of an institution’s risk- Finally, the proposed rule would the financial institution’s risk profile
based set of internal policies, require a financial institution to changes. For example, while a financial
procedures, and controls, that an designate an individual responsible for institution’s risk-based set of internal
institution identify, assess, and establishing and implementing the policies, procedures, and controls may,
document its ML/TF risks through risk AML/CFT program and coordinating at one time, have been reasonably
assessment processes. These risk and monitoring day-to-day compliance; designed, they may no longer be
assessment processes require a financial that individual would be required to be reasonably designed given changes to
institution to evaluate ML/TF risks and located in the United States and the financial institution’s risk profile.
review and, as appropriate, incorporate accessible to, and subject to oversight Similarly, an effective AML/CFT
the AML/CFT Priorities, with updates to and supervision by, FinCEN and its program would involve more than a
risk assessment processes promptly designee, including the appropriate one-time creation of an employee
upon any change that the financial Federal functional regulator. training program or initiation of an
institution knows or has reason to know Under the proposed rule, in addition independent testing mechanism: the
significantly changes the financial to establishing an AML/CFT program, financial institution would also be
institution’s ML/TF risks. These risk the financial institution would be required to keep such aspects of the
assessment processes are designed to required to maintain that program by AML/CFT program current as the
help financial institutions mitigate ML/ implementing, in all material respects, financial institution’s risk profile
TF risks and ensure that they are its established AML/CFT program. By changes. Thus, even where a financial
allocating resources commensurate with structuring the requirement to have an institution has previously established an
their documented ML/TF risks, effective AML/CFT program as distinct AML/CFT program in accordance with
directing more attention and resources obligations to establish and maintain the proposed rule, a failure to update
toward higher-risk customers rather (via implementation) an AML/CFT the program to reflect significant
than toward lower-risk customers and program, the proposed rule is intended changes to the institution’s risk profile
activities. to clarify and reinforce the distinction may result in the program no longer
between failures to establish an AML/ meeting the program establishment
B. Proposed Rule CFT program and failures to implement requirements, and the financial
As noted above, the proposed rule a properly established program. institution may accordingly be subject
would require financial institutions to The distinction between establishing to supervisory or enforcement action for
establish and maintain effective AML/ a program and implementing a program a failure to establish an effective AML/
CFT programs and define the is particularly important under the CFT program.
requirements for doing so. In order for proposed rule for potential supervisory The proposed rule would provide
an AML/CFT program to be effective, and enforcement actions. The proposed FinCEN with a greater role in the
the proposed rule would require a rule would not limit enforcement or
supervisory process with respect to
financial institution to establish an supervisory actions for failures to
banks and the relevant Agency. To
AML/CFT program and then maintain establish an AML/CFT program.
better ensure that bank examiners are
the AML/CFT program by However, with respect to banks, once a
performing ‘‘risk focused’’ supervision,
implementing, in all material respects, bank has properly established an AML/
the proposed rule would require that the
the established AML/CFT program. CFT program, the proposed rule would
Agencies, when acting under
lotter on DSK8BHNXB4PROD with PROPOSALS4
As described in more detail in section raise the threshold for significant
supervisory authority delegated by
V.D., a financial institution would be actions based solely on implementation
FinCEN, consult with FinCEN prior to
required to establish a risk-based set of deficiencies so only significant or
taking a significant AML/CFT
internal policies, procedures, and systemic failures by a bank to
controls that is reasonably designed to implement an effective AML/CFT 44 FinCEN, FinCEN Statement on Enforcement of
ensure compliance with the BSA and 31 program (i.e., deficiencies or issues that the Bank Secrecy Act (Aug. 18, 2020), https://
CFR chapter X. The risk-based set of arise from failing to implement, in all www.fincen.gov/news/news-releases/fincen-
internal policies, procedures, and material respects, a properly established statement-enforcement-bank-secrecy-act.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00008 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules 18711
supervisory action.45 FinCEN would government; thus, financial institutions ‘‘establish,’’ ‘‘maintain,’’ and
require the Agencies, when acting are best positioned to identify and ‘‘implement’’ an effective AML/CFT
pursuant to FinCEN’s delegated evaluate their ML/TF risks. Financial program. Section V.D describes the
authority, to provide FinCEN written institutions should therefore, and would components of program establishment,
notice at least 30 days prior to taking under this proposed rule, have including: (1) internal policies,
such an action. FinCEN would have an significant flexibility and discretion in procedures, and controls (including risk
opportunity to review the action and the their decisions and determinations assessment processes); (2) independent
underlying information giving rise to it, related to risk identification and program testing; (3) an individual,
and the Agencies would be required to resource allocation. However, examiners located in the United States and
consider any input offered by FinCEN would be expected to assess whether: accessible to FinCEN and the
concerning the effectiveness of the (1) a financial institution’s resource appropriate Federal functional
bank’s AML/CFT program.46 allocation decisions are informed by, regulator, responsible for establishing
By explicitly defining the and consistent with, reasonably and maintaining the program, and
requirements for an institution to designed risk assessment processes; and coordinating and monitoring day-to-day
establish and maintain an effective (2) with respect to implementation, compliance; and (4) ongoing employee
AML/CFT program, and by specifically, whether the financial training. Section V.E discusses the
standardizing the AML/CFT supervision institution knows or should know of requirements that the AML/CFT
and enforcement process for banks and resource-related issues involving its program be written, accessible, and
the Agencies, the proposed rule is internal policies, procedures, and approved by financial institution
expected to better achieve the purposes controls that may result in the financial leadership. Section V.F addresses the
of the BSA and lead to better outcomes institution failing to implement its supervision and enforcement section of
for financial institutions, law AML/CFT program in all material the proposed rule for banks, and Section
enforcement, and national security respects and failing to address such V.G describes several technical changes
agencies. Treasury and FinCEN do not issues. that the proposal makes to existing AML
intend, however, for the proposed rule Similarly, Treasury and FinCEN program rules.
to provide permission for financial expect a financial institution to be
institutions to establish ‘‘paper examined for its implementation of the A. Inserting the Term ‘‘CFT’’ Into the
programs’’ that might be interpreted as established AML/CFT program in all AML Program Rules
meeting the proposed rule’s technical material respects. Merely designating an Section 6101(b)(2)(A) of the AML Act
requirements on their face but do not individual responsible for establishing amends 31 U.S.C. 5318(h)(1) to
achieve the desired outcomes of more and implementing the AML/CFT reference ‘‘countering the financing of
effectively and efficiently detecting and program, and having that individual terrorism’’ 47 in addition to ‘‘anti-money
preventing ML/TF activity. To establish establish internal policies, procedures, laundering’’ when describing the
a compliant AML/CFT program under and controls, an employee training requirement to establish an AML/CFT
the proposed rule, a financial institution program, and an independent testing program. FinCEN proposes to update its
must, among other things, establish a program, are not sufficient to satisfy the regulations in 31 CFR chapter X to
risk-based set of internal policies, proposed rule’s obligations for a reflect this new statutory language. For
procedures, and controls that is financial institution to have an effective example, the proposed rule would
reasonably designed to ensure AML/CFT program. Rather, a financial change the title of 31 CFR 1020.210
compliance with the BSA and 31 CFR institution would be examined for from ‘‘Anti-money laundering program
chapter X, including through the whether it has implemented, in all requirements for banks’’ to ‘‘Anti-money
adoption of risk assessment processes. A material respects, its established AML/ laundering/countering the financing of
critical element of this requirement is CFT program, including whether the terrorism program requirements for
that the financial institution’s internal financial institution is, in fact, banks.’’ Similar changes would apply to
policies, procedures, and controls be allocating resources as contemplated in the titles of the other program rules in
‘‘reasonably designed.’’ For example, if its established AML/CFT program, chapter X.
a financial institution’s program testing which the proposed rule would require The inclusion of ‘‘CFT’’ in the
reveals that a new customer type or new to be consistent with its reasonably program rules would not create new
activity is high risk, but the financial designed risk assessment processes. obligations for financial institutions,
institution does not take any action to Banks with significant or systemic insofar as the USA PATRIOT Act
revise the design of its internal policies, failures to implement an effective AML/ already requires them to account for
procedures, and controls and therefore CFT program may be subject to a risks related to terrorist financing.
treats the customer or activity as significant supervisory action or Accordingly, FinCEN expects any
presenting low risk, then its program enforcement action, whereas isolated, changes to existing AML/CFT programs
should not be considered reasonably technical, or immaterial implementation from the amendments described in this
designed. Treasury and FinCEN believe deficiencies would not be cause for such subsection to be technical and therefore
that financial institutions know their actions. not have any substantive impact on
customer base, businesses, and risks financial institutions’ BSA compliance
V. Section-by-Section Analysis
better than their regulators and the obligations.
This section-by-section analysis
45 Because FinCEN has not delegated any describes the specific proposed changes B. An ‘‘Effective’’ AML/CFT Program
lotter on DSK8BHNXB4PROD with PROPOSALS4
enforcement authority to the Agencies, the Agencies to the program rules. Section V.A As discussed above in section IV.A, in
have no authority to take an enforcement action addresses the proposed incorporation of
under 31 CFR chapter X. As a result, there is no
prescribing the minimum standards for
corresponding rule text related to enforcement CFT into the program rules. Section V.B
actions by the Agencies acting under authority discusses the requirements for an 47 Countering the financing of terrorism (CFT)
provided by FinCEN. ‘‘effective’’ AML/CFT program to includes laws, rules, regulations, or other measures
46 FinCEN anticipates the Agencies imposing a intended to detect and disrupt the solicitation,
similar consultation requirement on themselves
comply with the requirements of 31 collection, or provision of funds to support terrorist
when the Agencies act under other laws, including U.S.C. 5318(h)(1) and the proposed rule. acts or terrorist organizations, or other violent
12 U.S.C. 1786 or 1818. Section V.C explains what it means to extremist groups.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00009 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
18712 Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
an AML/CFT program and in government authorities as national AML FinCEN encourages financial
supervising and examining compliance priorities.50 institutions to evaluate whether new
with those standards, the AML Act The proposed rule would provide that technology or innovative approaches
requires the Secretary and the a financial institution has an ‘‘effective’’ might help to more effectively combat
appropriate Federal functional regulator program if it (1) is established in financial crime. Innovative approaches
to take into account that effective AML/ accordance with the proposed rule’s could involve machine learning,
CFT programs safeguard national establishment requirements; and (2) is generative artificial intelligence
security and help law enforcement maintained, meaning that a properly (GenAI), digital identity, blockchain
prevent the flow of illicit funds in the established program is implemented in monitoring and analytics, or application
financial system.48 Further, the AML all material respects. programming interfaces (APIs). These
Act instructs FinCEN to focus on One of the AML Act’s key purposes is technologies may be especially useful in
to ‘‘encourage technological innovation countering illicit finance activity
achieving effective outcomes rather than
and the adoption of new technology by involving digital assets, an effort for
dictating the processes used to reach
financial institutions to more effectively which FinCEN supports financial
those outcomes, an orientation reflected
counter money laundering and institutions’ responsible use of novel
in the proposed rule. Consistent with financing of terrorism.’’ 51 Consistent
FinCEN and the Agencies’ longstanding models, techniques, or strategies. To
with this purpose and pursuant to the that end, FinCEN encourages financial
expectations regarding what effective Executive order on Removing Barriers to institutions to review the White House
outcomes entail, FinCEN believes that, American Leadership in Artificial report on Strengthening American
as a practical matter, it is not possible Intelligence, the Winning the Race Leadership in Digital Financial
for a financial institution to detect and America’s AI Action Plan, and the Technology as well as Treasury’s report
report all potentially illicit transactions Executive order on Ensuring a National on Innovative Technologies to Counter
that flow through the institution.49 Policy Framework for Artificial Illicit Finance Involving Digital Assets.55
Similarly, a financial institution’s AML/ Intelligence, Treasury has undertaken This report explores how financial
CFT program can be effective without various efforts to research, promote, and institutions can employ innovative and
preventing every minor instance of a take actions that reflect its commitment novel methods to detect and stop
financial institution falling prey to illicit to the role of innovation as part of a financial crime involving digital assets,
finance misuse. Accordingly, the modernized AML/CFT framework.52 and encourages the responsible use of
proposed rule would set out that an Treasury has highlighted the potential novel tools and techniques that can
AML/CFT program is ‘‘effective’’ and for innovative technologies to improve the effectiveness of the U.S.
complies with the requirements of 31 strengthen AML/CFT programs in AML/CFT regime.
U.S.C. 5318(h)(1) so long as it is various strategies and public FinCEN recognizes that adopting new
established and maintained in engagements. The 2024 National Illicit technologies for BSA compliance may
accordance with applicable Finance Strategy highlighted how not be suitable for every financial
requirements. innovative technologies like machine institution, particularly smaller ones,
learning and large language models have and the proposed rule therefore does not
As noted in section II.B and section
potential to strengthen financial reference or require the use of any
II.C, FinCEN has introduced the concept institutions’ AML/CFT programs, particular technology. A financial
of an ‘‘effective’’ AML/CFT program in enabling financial institutions to more institution may find it beneficial to
prior rulemakings, and the public has rapidly and effectively analyze data to consider whether its AML/CFT program
provided valuable feedback on this identify patterns, risks, trends, and appropriately uses the financial
concept. For example, the Effectiveness typologies.53 In addition to discussion institution’s existing resources,
ANPRM considered proposing a of specific types of and applications for including technology and data.
definition of an effective and reasonably technology, Treasury has expressed However, building on longstanding
designed program as one that: (1) broad support for exploring areas where guidance, FinCEN encourages
identifies, assesses, and reasonably AI, blockchain analysis, digital identity, institutions to engage in responsible
mitigates the risks resulting from illicit and other tools can produce a more AML/CFT innovation.56 Institutions
financial activity—including terrorist efficient and more effective AML/CFT that responsibly experiment with
financing, money laundering, and other framework.54 innovative technologies in their AML/
related financial crimes—consistent CFT programs will not incur any
with both the institution’s risk profile 50 85 FR 58026.
additional risk of being subject to a
and the risks communicated by relevant 51 AML Act, section 6002(3) (Purposes).
significant supervisory AML/CFT action
52 E.O. 14179, Removing Barriers to American
government authorities as national AML or AML/CFT enforcement action solely
Leadership in Artificial Intelligence, 90 FR 8741
priorities; (2) assures and monitors (issued Jan. 23, 2025; published Jan. 31, 2025);
compliance with the recordkeeping and White House, Winning the Race America’s AI 55 White House, Strengthening American
reporting requirements of the BSA; and Action Plan (July 2025), https:// Leadership in Digital Financial Technology (July 30,
www.whitehouse.gov/wp-content/uploads/2025/07/ 2025), https://www.whitehouse.gov/wp-content/
(3) provides information with a high Americas-AI-Action-Plan.pdf; E.O. 14179, Ensuring uploads/2025/07/Digital-Assets-Report-
degree of usefulness to government a National Policy Framework for Artificial EO14178.pdf; U.S. Department of the Treasury,
authorities consistent with both the Intelligence, 90 FR 58499 (issued Dec. 11, 2025; Report to Congress from the Secretary of the
institution’s risk assessment and the published Dec. 16, 2025). Treasury on Innovative Technologies to Counter
53 U.S. Department of the Treasury, 2024 National Illicit Finance Involving Digital Assets (Mar. 2026),
risks communicated by relevant
Strategy for Combating Terrorist and Other Illicit https://home.treasury.gov/system/files/246/
lotter on DSK8BHNXB4PROD with PROPOSALS4
Financing (May 2024), https://home.treasury.gov/ GENIUS-Act-Illicit-Finance-Innovation-
48 See 31 U.S.C. 5318(h)(2)(B)(iii). system/files/136/2024-Illicit-Finance-Strategy.pdf. Congressional-Report-March-2026.pdf.
49 Federal Financial Institutions Examination 54 U.S. Department of the Treasury, Press Release, 56 FRB, FDIC, FinCEN, NCUA, and OCC, Joint
Council (FFIEC), FFIEC BSA/AML Examination ‘‘Remarks by Under Secretary for Terrorism and Statement on Innovative Efforts to Combat Money
Manual, Assessing Compliance with BSA Financial Intelligence John K. Hurley at the Laundering and Terrorist Financing (Dec. 3, 2018),
Regulatory Requirements—Suspicious Activity Association of Certified Anti-Money Laundering https://www.fincen.gov/system/files/2018-12/
Reporting, https://bsaaml.ffiec.gov/manual/ Specialists Assembly Conference’’ (Sept. 17, 2025), Joint%20Statement%20on%20Innovation
AssessingComplianceWithBSARegulatory https://home.treasury.gov/news/press-releases/ %20Statement%20%28Final%2011-30-18%29_
Requirements/04. sb0251. 508.pdf.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00010 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules 18713
based on the use of innovative would set out uniform terms for an institution is executing that program in
technologies. To the contrary, FinCEN AML/CFT program across FinCEN’s practice. This distinction matters,
recognizes that fostering the use of regulations for all types of financial particularly for banks, because proposed
innovative technologies is vital to institutions regulated under the BSA 31 CFR 1020.221(b) ties the availability
improving financial crime compliance and delineate the requirements that of AML/CFT enforcement and
and fighting illicit finance and strongly must be met for financial institutions to significant supervisory actions based on
encourages their responsible use. have an effective AML/CFT program. the program rule for an established bank
In addition to new technology, That is, the proposed rule would create program to a significant or systemic
FinCEN is aware of concerns a two-pronged framework under which failure to implement an effective AML/
surrounding model risk management at a financial institution’s AML/CFT CFT program. The distinction between
financial institutions. FinCEN has program would be deemed to be establishing and implementing an AML/
considered comments submitted in effective if the financial institution CFT program is intended to make
response to the 2021 Request for establishes and maintains their transparent how the individual
Information and Comment: Extent to program. Under the proposed rule, a elements of 31 CFR 1020.210 work
Which Model Risk Management financial institution maintains its together to satisfy 31 U.S.C. 5318(h)(1).
Principles Support Compliance With properly established AML/CFT program The concepts of program
Bank Secrecy Act/Anti-Money by implementing it in all material establishment and program maintenance
Laundering and Office of Foreign Assets respects. are closely related to the supervision
Control Requirements (RFI).57 FinCEN and enforcement provisions of the
1. Proposed 31 CFR 10XX.210(b)— proposed program rule for banks. In
received comments including concerns Establishing Versus Maintaining an
that supervisors may expect financial particular, as explained in more detail
AML/CFT Program in section V.F, a bank that has properly
institutions to apply the Supervisory
Guidance on Model Risk Management For a financial institution to have an established an AML/CFT program (i.e.,
(MRMG) to AML/CFT and OFAC-related effective AML/CFT program, the satisfied the proposed rule’s
policies, procedures, and controls.58 proposed 31 CFR 10XX.210(b) (‘‘31 CFR requirements regarding establishment)
While FinCEN has not issued or been 10XX’’ refers to proposed changes to the will not be subject to an AML/CFT
party to any prior MRMG guidance, AML program rules of all eleven enforcement action or a significant
FinCEN shares certain concerns financial institution types) would supervisory action based on the program
articulated in the comments to the RFI require a financial institution to rule except with respect to a significant
establish an AML/CFT program and or systemic failure to implement an
that these models, which are designed
then maintain the AML/CFT program by effective AML/CFT program (i.e., a
to assess different types of risks with
implementing, in all material respects, failure to implement, in all material
different information input, processing,
the established AML/CFT program. The respects, a properly established AML/
and reporting components may be
proposed rule describes the CFT program).60
overly burdensome and ill-fitted to
requirements for a financial institution Separating program establishment
address illicit finance risks. FinCEN
to establish and maintain an effective from program maintenance therefore
welcomes comment on this position and
AML/CFT program that complies with provides needed clarity regarding
intends to work with the Agencies to
the requirements of 31 U.S.C. whether a supervisory concern relates to
address these concerns.
5318(h)(1). The AML/CFT program deficiencies stemming from the
C. Establishing and Maintaining an minimum components constituting program’s design, on the one hand, or
AML/CFT Program program establishment, and described failures in the program’s operation, on
The requirement that financial in further detail in section V.D below, the other. This two-prong framework
are: (1) internal policies, procedures, would help promote consistent
institutions establish and maintain an
and controls (including risk assessment articulation of supervisory expectations
AML/CFT program is not new, although
processes); (2) independent program and prevent conflating criticisms of
over time various formulations of this
testing; (3) an individual, located in the program design—the remediation of
requirement have developed in statutes
United States and accessible to FinCEN which would likely be different in
and regulations.59 The proposed rule
and the Agencies, responsible for kind—with criticisms of day-to-day
57 OCC, FRB, FDIC, NCUA, and FinCEN, Request establishing and maintaining the implementation. The proposed
for Information and Comment: Extent to Which program, and coordinating and distinction does not change the
Model Risk Management Principles Support monitoring day-to-day compliance; and substantive obligations of 31 U.S.C.
Compliance With Bank Secrecy Act/Anti-Money (4) ongoing employee training. 5318(h)(1); rather, it clarifies how those
Laundering and Office of Foreign Assets Control obligations map onto the two statutory
Requirements, 86 FR 18978 (Apr. 12, 2021). ‘‘Establishing’’ an AML/CFT program
58 FRB and OCC, Supervisory Guidance on Model involves designing an AML/CFT requirements at the core of section
Risk Management, (Apr. 4, 2011), https:// program that incorporates all of the 5318(h)(1): having a risk-based and
www.federalreserve.gov/supervisionreg/srletters/ required components. reasonably designed program and
sr1107a1.pdf. adhering to it in operation.
59 For instance, the provision of the BSA which
‘‘Implementation,’’ by contrast,
addresses whether the financial As noted previously, FinCEN intends
requires financial institutions to have AML/CFT
program rules states that ‘‘each financial institution
for the requirements of this proposed
shall establish ’’(emphasis added) such programs, CFT programs. For example, some programs rules rule to not be limited to a one-time
including certain requirements as specified. See 31 use the terms ‘‘implements and maintains’’—31 adoption of the elements required for
U.S.C. 5318(h)(1). The corresponding Federal CFR 1020.210 (banks); 1021.210 (casinos); 1023.210
lotter on DSK8BHNXB4PROD with PROPOSALS4
program establishment, such as internal
statute requiring banks regulated by the Federal (broker-dealers); 1026.210 (FCMs and IBCs) while
banking agencies to have BSA compliance programs others use the terms ‘‘develop, implement, and
policies, procedures, and controls.
states that these banks must ‘‘establish and maintain,’’ 1022.210 (MSBs) and others use Rather, FinCEN intends a financial
maintain procedures reasonably designed to assure ‘‘develop and implement’’ 1024.210 (mutual funds);
and monitor the compliance’’ with the requirements 1025.210 (insurance companies); 1027.210 60 The proposed rule would clarify that this
of the BSA. 12 U.S.C. 1818(s)(1). In addition, the (DPMSJs); 1028.210 (operators of credit card limitation on AML/CFT enforcement actions and
current program rules regulating financial systems); 1029.210 (loan or finance companies); and significant AML/CFT supervisory actions does not
institutions use inconsistent terms to describe 1030.210 (housing GSEs)—with respect to the apply with respect to a failure to properly establish
establishing, implementing, and maintaining AML/ general AML program requirement. an AML/CFT program.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00011 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
18714 Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
institution’s establishment of its AML/ weaknesses in the risk assessment impose internal policies, procedures,
CFT program to require the financial processes that have a material impact on and controls requirements to ensure
institution’s risk-based set of internal the financial institution’s mitigation of compliance, but with differing
policies, procedures, and controls—and ML/TF risks through its internal formulations. The proposed rule would
the risk assessment processes that policies, procedures, and controls, standardize these requirements for
inform them—to remain current as the including due to data-related issues financial institutions required to comply
financial institution’s risk profile involving relevant processes and with FinCEN’s program rules to
changes. For example, if a financial systems. establish a risk-based set of internal
institution begins providing a new Similarly, FinCEN expects that a policies, procedures, and controls in
product or service—or changes how it financial institution could become their AML/CFT programs.
provides an existing product or services, aware of such implementation-related
concerns through a variety of Proposed 31 CFR 10XX.210(b)(1)
such as operating in a new geographic
mechanisms, including, but not limited provides that a financial institution’s
location—under this proposed rule, a
financial institution would need to to: (1) independent testing of the AML/ risk-based set of internal policies,
incorporate its new product or service CFT program; (2) examiner procedures, and controls must be
as part of its risk assessment processes. observations, suggestions, or other reasonably designed to: (1) identify,
The proposed rule would require a informal comments about the AML/CFT assess, and document ML/TF risks
financial institution to make a risk program from FinCEN (or its designee, through risk assessment processes; (2)
determination and, as appropriate, such as a Federal functional regulator); mitigate ML/TF risks consistent with
redesign its internal policies, (3) management information systems the risk assessment processes, including
procedures, and controls to account for and related reports or other outputs by allocating more attention and
the risks that it did not previously (e.g., key performance indicators or key resources toward higher-risk customers
encounter prior to offering the new risk indicators, such as monitoring for and activities rather than toward lower-
product or service, or operating in the potentially material backlogs in relevant risk customers and activities; and, for
new geographic location. Thus, under AML/CFT processes); and (4) issues certain financial institutions (3) conduct
the proposed rule, even where a identified by personnel involved in the ongoing CDD. The preamble addresses
financial institution has previously operation of the financial institution’s each of these features below.
established an AML/CFT program in AML/CFT program. A bank that fails to Under this proposal, a financial
accordance with the proposed rule, a reasonably address such warnings that institution’s risk-based set of internal
failure to update the program to reflect its program is not being implemented policies, procedures, and controls
significant changes in the institution’s would be at risk of being subject to a should be based upon, informed by, and
risk profile may result in the program no significant AML/CFT supervisory consistent with the financial
longer satisfying the proposed rule’s action, an AML/CFT enforcement institution’s risk assessment processes.
requirements regarding establishment. action, or both. The level of sophistication of the
2. Proposed 31 CFR 10XX.210(c)— D. Program Establishment internal policies, procedures, and
Implementation of an AML/CFT controls should be commensurate with
As noted earlier, pursuant to 31 the size, structure, risk profile, and
Program U.S.C. 5318(h), the AML/CFT program complexity of the financial institution.
Once a financial institution has requirements for financial institutions
properly ‘‘established’’ an AML/CFT must have certain minimum elements The requirement that a financial
program, the institution must comprised of: (1) internal policies, institution’s risk-based set of internal
‘‘maintain’’ the program by procedures, and controls; (2) an policies, procedures, and controls be
implementing it, in all material respects. independent audit function to test ‘‘reasonably designed’’ gives financial
Minor deficiencies of an AML/CFT programs; (3) a designated compliance institutions flexibility in how they
program would not necessarily mean officer; (4) an ongoing employee training achieve compliance with the BSA and
that a financial institution has failed to program; and (5) other components, the proposed rule’s other requirements.
implement the program. depending on the type of financial As part of having risk-based set of
Although there are a variety of ways institution. The majority of the internal policies, procedures, and
that a financial institution may not be proposed rule’s AML/CFT program controls reasonably designed to ensure
implementing its program ‘‘in all components are substantially similar to compliance with the BSA and FinCEN’s
material respects,’’ in FinCEN’s the existing statutory and regulatory regulations, financial institutions may
experience, commonly observed requirements for financial institutions. choose to responsibly adopt new
examples may include, but would not However, FinCEN is proposing certain technologies or innovative approaches
be limited to: (1) internal policies, additions and modifications to to comply with BSA requirements.
procedures, and controls are not being modernize and strengthen financial Consistent with this purpose, FinCEN
performed or not being performed on a institutions’ AML/CFT programs to encourages financial institutions to
consistent, regular, and timely basis enable financial institutions to better evaluate whether new technology or
(e.g., consistently ignored warnings or mitigate illicit finance risks. innovative approaches in other
red flags that a program was seriously resources might help to more effectively
deficient) due to the nature or extent of 1. Proposed 31 CFR 10XX.210(b)(1)— combat financial crime. Innovative
required resources becoming Internal Policies, Procedures, and approaches could involve machine
Controls
lotter on DSK8BHNXB4PROD with PROPOSALS4
inadequate; (2) gaps in the risk learning, GenAI, digital identity,
assessment processes that result in the The BSA requires financial blockchain monitoring and analytics, or
financial institution’s program missing institutions to develop ‘‘internal APIs. These technologies may be
or inadequately covering higher ML/TF policies, procedures, and controls’’ as especially useful in countering illicit
risks (e.g., systems used to monitor for part of their AML/CFT programs.61 finance activity involving digital assets,
potentially suspicious activity failing to Existing AML program rules already an effort for which FinCEN supports the
capture material volumes or types of responsible use of novel models,
transactions); or (3) deficiencies or 61 31 U.S.C. 5318(h)(1)(A). techniques, or strategies.
VerDate Sep<11>2014 19:54 Apr 09, 2026 Jkt 268001 PO 00000 Frm 00012 Fmt 4701 Sfmt 4702 E:\FR\FM\10APP4.SGM 10APP4
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules 18715
i. Proposed 31 CFR 10XX.210(b)(1)(i)— TF risks using risk assessment including, for example, through remote
Risk Assessment Processes processes. FinCEN understands that or other non-face-to-face means.
FinCEN is proposing in 31 CFR many financial institutions currently Financial institutions may use a
10XX.210(b)(1)(i) that, as part of a maintain a single, or standalone, risk variety of sources to inform their risk
financial institution’s risk-based set of assessment process either voluntarily or assessment processes. Such sources may
internal policies, procedures, and as required or expected by Federal include information obtained from other
controls, the financial institution regulators. This risk assessment process, financial institutions, such as emerging
establish and maintain risk assessment generally conducted on an annual basis, risks and typologies identified through
processes to: (1) evaluate the ML/TF results in a documented ML/TF risk section 314(b) information sharing or
risks of the financial institution’s assessment. While such a risk payment transactions that other
business activities, including products, assessment process may be appropriate financial institutions returned or flagged
services, distribution channels, under the proposal, the use of the term due to ML/TF risks.65 Information a
customers, and geographic locations; (2) ‘‘risk assessment processes’’ is intended financial institution generates or
review and, as appropriate, incorporate to reflect that a financial institution may maintains could be another source.
the AML/CFT Priorities; and (3) be rely on multiple processes—applied as Such internal information may include,
updated promptly upon any change that appropriate within its AML/CFT for example, customer internet protocol
the financial institution knows or has program—to identify, assess, and (IP) addresses or device logins and
reason to know significantly changes the document its ML/TF risks and will be related geolocation information.
examined based on the totality of these Feedback from FinCEN, law
institution’s ML/TF risks.
While it is common practice among processes rather than the sufficiency of enforcement, and financial regulators
many financial institutions to maintain a single, standalone risk assessment may also inform risk assessment
a risk assessment process or processes, process. processes. For example, if a financial
the requirement that financial FinCEN believes financial institutions institution receives feedback from law
institutions have risk assessment are best positioned to identify and enforcement about a report it has filed
processes when developing their AML/ evaluate their ML/TF risks and is or potential risks at the financial
CFT programs is not stated in a uniform therefore not prescribing any particular institution, the financial institution may
manner for all financial institutions risk assessment processes or incorporate that information into its risk
under the current AML program rules. methodologies other than the critical assessment processes. Similarly, a
Under some program rules, certain elements described in this proposed financial institution may consider
financial institutions—such as rule. Under the proposed rule, financial information identified from responding
insurance companies and loan and institutions will be examined for to section 314(a) requests.
finance companies—are explicitly whether they have established and In addition to feedback, reports, and
required to ‘‘[i]ncorporate policies, implemented, in all material respects, analyses published by Treasury and
procedures, and internal controls based reasonably designed risk assessment FinCEN, the Federal functional
upon . . . [an] assessment of the . . . processes—which need not be in the regulators, or self-regulatory
risks associated with its products and form of a singular risk assessment organizations (SROs) may be
services.’’ 62 Under other program rules, process. Furthermore, as discussed particularly relevant to a financial
some financial institutions—such as further below, FinCEN is not prescribing institution’s business activities, thereby
casinos and MSBs—must develop any particular timeframe for institutions warranting consideration when
internal policies, procedures, and to update their risk assessment evaluating ML/TF risks. Treasury
controls, and independent testing processes. describes changes in the illicit finance
‘‘commensurate with the risks’’ posed The explicit requirement to have risk risk environment in its biennial
by their products.63 This latter assessment processes will be new for National Money Laundering Risk
requirement implicitly requires risk banks, casinos, MSBs, broker-dealers, Assessment, National Terrorist
assessment processes, as an institution mutual funds, and FCMs and IBCs.64 Financing Risk Assessment, and
cannot develop a risk-based set of National Proliferation Financing Risk
internal policies, procedures, and a. Proposed 31 CFR Assessment, which highlight significant
controls without first identifying the 10XX.210(b)(1)(i)(A)—ML/TF Risks illicit finance threats, vulnerabilities,
institution’s risks by way of some Proposed 31 CFR 10XX.210(b)(1)(i)(A) and risks.66 FinCEN also publishes
process. Thus, the proposed rule would would require a financial institution’s advisories and analyses on emerging
standardize the requirement for risk risk assessment processes to evaluate risks and typologies, including
assessment processes across different the ML/TF risks of its business Financial Trend Analyses issued
types of financial institutions subject to activities, including products, services, pursuant to section 6206 of the AML
program rules, thereby clarifying distribution channels, customers, and Act. These reports contain threat pattern
existing expectations and practices. geographic locations. These factors are and trend information derived from
Importantly, the proposed rule generally well known and often BSA filings and may help inform
requires, as part of a financial incorporated into current risk financial institutions’ understanding of
institution’s risk-based set of internal assessment processes of some financial 65 See FinCEN, Section 314(b) Fact Sheet, (Dec.