NPRM: Anti-Money Laundering and Countering the Financing of Terrorism Programs (all FIs, incl. MSBs) (91 FR 18704) (Part 2 of 5)

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

Fincen

2

2026-04-10

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

policies, procedures and controls, that it              institutions. FinCEN considers                         2020), https://www.fincen.gov/system/files/shared/
                                                identify, assess, and document its ML/                  ‘‘distribution channels’’ to refer to the              314bfactsheet.pdf.
                                                                                                        methods and tools through which a                         66 See U.S. Department of the Treasury, 2026

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                   62 See 31 CFR 1029.210 (loan or finance
                                                                                                        financial institution opens accounts and               National Money Laundering Risk Assessment
                                                companies); 1030.210 (housing GSEs); see also 31                                                               (March 2026), https://home.treasury.gov/system/
                                                CFR 1025.210 (insurance companies); 1028.210
                                                                                                        provides products or services,
                                                                                                                                                               files/246/2026-NMLRA.pdf; 2026 National Terrorist
                                                (operators of credit card systems).                                                                            Financing Risk Assessment (March 2026), https://
                                                   63 See 31 CFR 1022.210 (MSBs); 1025.210                64 The current program rules without explicit risk   home.treasury.gov/system/files/246/2026-
                                                (insurance companies); see also 31 CFR 1021.210         assessment requirements are located at 31 CFR          NTFRA.pdf; 2026 National Proliferation Financing
                                                (casinos) (‘‘commensurate with the money                1020.210 (banks); 1021.210 (casinos); 1022.210         Risk Assessment (March 2026), https://
                                                laundering and terrorist financing risks posed by       (MSBs); 1023.210 (broker-dealers); 1024.210            home.treasury.gov/system/files/246/2026-
                                                the products and services’’).                           (mutual funds); and 1026.210 (FCMs and IBCs).          NPFRA.pdf.

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00013   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                18716                     Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules

                                                risks associated with different threats                 extent to which a particular priority is               Priorities. In either case, any changes to
                                                and vulnerabilities as they evolve.67                   applicable and whether and how a                       financial institutions’ AML/CFT
                                                Regardless of the source, financial                     particular AML/CFT Priority should be                  programs, such as internal policies,
                                                institutions should take measures in                    incorporated into its risk assessment                  procedures, or controls, would be based
                                                their risk assessment processes to                      processes.                                             on the results of risk assessment
                                                ensure this information is reasonably                      Further, a financial institution may                processes and their impact on the AML/
                                                current, complete, and accurate.                        use its judgment and apply a reasonable,               CFT program, including how to review
                                                                                                        risk-based determination on whether to                 and, as appropriate, incorporate the
                                                b. Proposed 31 CFR                                      focus on a specific aspect of an AML/                  AML/CFT Priorities before making these
                                                10XX.210(b)(1)(i)(B)—AML/CFT                            CFT Priority (e.g., cyber-enabled fraud),              determinations.
                                                Priorities                                              rather than addressing all aspects of a                   FinCEN recognizes that some AML/
                                                   Proposed 31 CFR 10XX.210(b)(1)(i)(B)                 AML/CFT Priority that may either not                   CFT Priorities describe threats at a high
                                                would require financial institutions to                 be applicable (e.g., digital assets                    level, or at a point in time, and that
                                                review and incorporate the AML/CFT                      cybercrime for a financial institution                 financial institutions may lack the
                                                Priorities. The AML/CFT Priorities set                  that does not offer any digital asset                  context or information necessary on
                                                out the priorities for the U.S.                         products or services, or have any digital              which specific threats, or what time
                                                government’s AML/CFT policy as                          asset customers) or pose lower risks to                frames, to consider or focus on when
                                                required by the AML Act and are                         the financial institution (e.g.,                       conducting their risk assessments. For
                                                designed to ensure that financial                       proliferation financing risks for a                    instance, the AML/CFT Priorities that
                                                institutions’ AML/CFT programs are                      financial institution with no cross-                   FinCEN issued in June 2021 describes
                                                aligned with those priorities.                          border operations, customers,                          ‘‘fraud’’ as one of the eight priorities and
                                                Recognizing the diverse nature of ML/                   transactions, or activities). However,                 discusses specific examples of fraud
                                                TF threats facing the U.S. financial                    FinCEN cautions that a surface-level,                  that were especially salient in 2021.
                                                system and national security, and that                  perfunctory review of an AML/CFT                       However, the government’s priorities
                                                financial institution AML/CFT programs                  Priority by a financial institution and                may have changed since the publication
                                                benefit U.S. national security by                       the foreseeable ways in which it may                   of the AML/CFT Priorities due to
                                                safeguarding the financial system from                  manifest itself within the financial                   emergent ML/TF typologies (e.g.,
                                                ML/TF risks, the AML/CFT Priorities                     institution’s customers, products and                  sanctions evasions by Russian oligarchs)
                                                are intended to ensure that financial                   services, geographies, and distribution                or ML/TF threats (e.g., pig butchering)
                                                institutions are focusing on the greatest               channels would not satisfy this                        not addressed specifically in the AML/
                                                threats to U.S. national security, as                   requirement. For example, patterns of                  CFT Priorities. For example, FinCEN’s
                                                defined by Treasury.                                    transactions that may be consistent with               support to Treasury’s efforts to combat
                                                   Section 6101 of the AML Act requires                 potential structuring should not                       rampant government benefits fraud is
                                                that a financial institution’s review and               automatically be dismissed as lower                    just one example of how the
                                                appropriate incorporation of the AML/                   value to law enforcement and                           government’s focus on specific types of
                                                CFT Priorities into its AML/CFT                         untethered to an AML/CFT Priority                      fraud evolves over time.70 This type of
                                                program be subject to supervision and                   without determining whether there is a                 fraud may not have been a concern for
                                                examination for compliance with the                     potential connection to various types of               a financial institution in prior risk
                                                BSA and other AML/CFT laws and                          other illicit finance activity (e.g.,                  assessment processes, but a financial
                                                regulations.68 FinCEN is implementing                   structuring or similar patterns involving              institution may decide to conduct and
                                                this statutory requirement by proposing                 transactions in narcotics trafficking                  apply risk assessment processes to
                                                that, as part of their risk assessment                  proceeds).                                             identify whether such a risk is
                                                processes, financial institutions must                     Under the AML Act, FinCEN is                        significant for a financial institution,
                                                review and, as appropriate, incorporate                 required to update the AML/CFT                         and that determination may necessitate
                                                the AML/CFT Priorities. The inclusion                   Priorities not less than once every four               changes to a financial institution’s
                                                of the AML/CFT Priorities in risk                       years.69 Whenever the AML/CFT                          AML/CFT program.
                                                assessment processes is meant to help                   Priorities are updated, financial                         To assist financial institutions with
                                                ensure that financial institutions                      institutions would no longer be required               their risk assessment processes, and to
                                                understand their exposure to risks in                   to incorporate prior versions of the                   better identify activity related to the
                                                areas that are of particular importance                 AML/CFT Priorities. Financial                          AML/CFT Priorities, FinCEN issues
                                                nationally, which may help financial                    institutions would only be required to                 products under its Financial Institution
                                                institutions develop risk-based and                     incorporate the most recent AML/CFT                    Advisory Program (Advisory
                                                                                                        Priorities into their risk assessment                  Program).71 FinCEN’s Advisory Program
                                                reasonably designed AML/CFT
                                                                                                        processes.                                             communicates priority ML/TF threats
                                                programs.
                                                                                                           FinCEN anticipates that some                        and vulnerabilities to the U.S. financial
                                                   FinCEN understands that the AML/
                                                                                                        financial institutions may ultimately                  system. Financial institutions may use
                                                CFT Priorities may not always be
                                                                                                        determine that their business models                   this information to support effective,
                                                applicable to a financial institution’s
                                                                                                        and risk profiles have limited exposure                risk-based, and reasonably designed
                                                risk profile and activities. Therefore,
                                                                                                        to some of the threats addressed in the                AML/CFT programs and suspicious
                                                FinCEN requires the incorporation of
                                                                                                        AML/CFT Priorities but instead have                    activity monitoring systems to help
                                                the AML/CFT Priorities in financial
                                                                                                        greater exposure to other ML/TF risks                  generate highly useful information for
                                                institution’s risk assessment processes

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                                                                        not addressed in the AML/CFT
                                                as appropriate. This means that, having
                                                                                                        Priorities. Additionally, some financial                  70 U.S. Department of the Treasury, Press Release,
                                                reviewed the AML/CFT Priorities, a
                                                                                                        institutions’ risk assessment processes                ‘‘Secretary Bessent Announces Initiatives to Combat
                                                financial institution may determine the                                                                        Rampant Fraud in Minnesota’’ (Jan. 9, 2026),
                                                                                                        may determine that their AML/CFT
                                                                                                                                                               https://home.treasury.gov/news/press-releases/
                                                  67 See, e.g., FinCEN, Financial Trend Analyses,
                                                                                                        programs already sufficiently take into                sb0354.
                                                https://www.fincen.gov/resources/financial-trend-       account some, or all, of the AML/CFT                      71 FinCEN, Alerts/Advisories/Notices/Bulletins/
                                                analyses.                                                                                                      Fact Sheets, https://www.fincen.gov/resources/
                                                  68 31 U.S.C. 5318(h)(4)(E).                             69 31 U.S.C. 5318(h)(4)(B).                          advisoriesbulletinsfact-sheets.

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00014   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                                          Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules                                                   18717

                                                law enforcement and national security                   ii. Proposed 31 CFR 10XX.210(b)(1)(ii)—                therefore, does not contemplate
                                                agencies.                                               Mitigate ML/TF Risks Through Risk-                     regulatory second-guessing of a
                                                   Relatedly, since 2021, FinCEN has                    Based Allocation of Attention and                      financial institution’s reasonable
                                                published Financial Trends Analyses                     Resources                                              determinations regarding appropriate
                                                (FTA) highlighting threat pattern and                                                                          resource allocation or conclusions
                                                                                                           Section 6101(b) of the AML Act states
                                                trend information derived from BSA                                                                             regarding specific risks. However, while
                                                                                                        that the AML/CFT programs of financial
                                                data on additional fraud-related topics,                                                                       Treasury and FinCEN do not believe
                                                                                                        institutions should be ‘‘risk-based,
                                                including an FTA on fraud schemes                                                                              that an examiner should substitute his
                                                                                                        including ensuring that more attention
                                                targeting digital identities, mail theft-                                                                      or her own subjective judgment in place
                                                                                                        and resources of financial institutions
                                                related check fraud, and elder financial                                                                       of the financial institution, examiners
                                                                                                        should be directed toward higher-risk
                                                exploitation.72 More recently, FinCEN                                                                          will be expected to assess whether: (1)
                                                                                                        customers and activities, consistent
                                                issued an Alert on Fraud Rings and their                                                                       a financial institution’s resource
                                                                                                        with the risk profile of a financial
                                                Exploitation of Federal Child Nutrition                                                                        allocation decisions are informed by,
                                                programs in Minnesota given the                         institution, rather than toward lower-
                                                                                                                                                               and consistent with, reasonably
                                                rampant financial fraud and improper                    risk customers and activities.’’ 74
                                                                                                                                                               designed risk assessment processes; and
                                                payments in Minnesota.73 As noted in                    Proposed 31 CFR 10XX.210(b)(1)(ii)
                                                                                                                                                               (2) with respect to implementation,
                                                the alert, ongoing investigations into                  would adopt this formulation as part of
                                                                                                                                                               specifically, whether the financial
                                                fraudsters in Minnesota by the U.S.                     a financial institution’s obligation to
                                                                                                                                                               institution knows or should know of
                                                Department of Justice have identified                   establish a risk-based set of internal
                                                                                                                                                               resource-related issues involving its
                                                potentially billions of dollars stolen                  policies, procedures, and controls.                    internal policies, procedures, and
                                                from the Federal child nutrition                        Under the proposed rule, a financial                   controls and other mandatory elements
                                                programs and other Federal and State                    institution’s efforts to mitigate its ML/              that may result in the financial
                                                government benefits programs,                           TF risks would involve ‘‘directing more                institution failing to implement its
                                                including Medicaid.                                     attention and resources toward higher-                 AML/CFT program in all material
                                                   FinCEN requests comment from the                     risk customers and activities, consistent              respects and failing to address such
                                                public on whether additional guidance                   with the risk profile of the [financial                issues.
                                                related to the consideration of the AML/                institution], rather than toward lower-
                                                CFT Priorities as part of an institution’s              risk customers and activities.’’                       iii. Proposed 31 CFR 1020.210(b)(1)(iii),
                                                risk assessment processes would be                         FinCEN views risk-based allocation of               1023.210(b)(1)(iii), 1024.210(b)(1)(iii),
                                                warranted.                                              resources as a critical step in realizing              1026.210(b)(1)(iii), and
                                                                                                        the AML Act’s BSA modernization and                    1028.210(b)(1)(iii)—Conduct Ongoing
                                                c. Proposed 31 CFR                                      reform ambitions, and an important                     Customer Due Diligence
                                                10XX.210(b)(1)(i)(C)—Updates to Risk                    departure from the status quo of AML/                     The existing program rules for certain
                                                Assessment Processes                                    CFT compliance and supervision. The                    financial institutions, referred to here as
                                                   Proposed 31 CFR 10XX.210(b)(1)(i)(C)                 proposed rule envisions financial                      covered financial institutions, contain
                                                would require financial institutions to                 institutions exercising more flexibility               CDD requirements that have commonly
                                                update their risk assessment processes                  in deploying attention and resources in                been referred to as the ‘‘fifth pillar’’ of
                                                promptly upon any change that the                       accordance with the proposed rule                      AML program rules for those types of
                                                financial institution knows or has                      without fear of supervisory criticism or               financial institutions.75 Under these
                                                reason to know significantly changes                    action from examiners for directing                    requirements, covered financial
                                                their ML/TF risk profiles. For example,                 more attention and resources on higher                 institutions must establish and maintain
                                                a financial institution may need to                     risk customers and activities rather than              a written AML program that includes:
                                                update its risk assessment when new                     toward lower risk customers and                        ‘‘appropriate risk-based procedures for
                                                products, services, and customer types                  activities.                                            conducting ongoing customer due
                                                are introduced; if existing products,                      The goal of risk-based resource                     diligence, to include, but not be limited
                                                services, and customer types undergo                    allocation is for financial institutions to            to: understanding the nature and
                                                significant changes; when the financial                 spend less time, energy, and resources                 purpose of customer relationships for
                                                institution adopts new risk mitigation                  on lower priority activities that may                  the purpose of developing a customer
                                                technology; or if the financial institution             result in fewer resources devoted to, and              risk profile; and conducting ongoing
                                                as a whole expands or contracts through                 potentially distract from, more serious                monitoring to identify and report
                                                mergers, acquisitions, divestitures,                    threats. The proposed rule would thus                  suspicious transactions and, on a risk
                                                dissolutions, and liquidations. Financial               enable financial institutions to focus                 basis, to maintain and update customer
                                                institutions may also need to update                    more on higher risk customers and                      information.’’
                                                their risk assessment processes based on                activities, which FinCEN has                              Proposed 31 CFR 1020.210(b)(1)(iii),
                                                factors external to their operations that               determined should result in financial                  1023.210(b)(1)(iii), 1024.210(b)(1)(iii),
                                                they know or have reason to know                        institutions being more effective at                   1026.210(b)(1)(iii), and
                                                significantly change their ML/TF risk                   detecting, reporting, and preventing the               1028.210(b)(1)(iii) would retain these
                                                profiles. FinCEN welcomes comments                      flow of illicit funds and providing law                ongoing CDD obligations without
                                                on whether it should further clarify                    enforcement with more valuable BSA                     alteration but would make them part of
                                                when financial institutions must review                 reporting.                                             the requirement that covered financial
                                                or update their risk assessment                            As noted above, Treasury and FinCEN                 institutions establish a risk-based set of

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                processes.                                              believe that financial institutions are                internal policies, procedures, and
                                                                                                        best positioned to identify and evaluate               controls that is reasonably designed.
                                                  72 FinCEN, Financial Trend Analyses, https://         their ML/TF risks and to make decisions
                                                www.fincen.gov/resources/financial-trend-analyses.      related to risk identification and                       75 See applicable program rules with CDD
                                                  73 FinCEN, FinCEN Alert on Fraud Rings and                                                                   requirements for covered financial institutions
                                                                                                        resource allocation in accordance with
                                                their Exploitation of Federal Child Nutrition                                                                  located at 31 CFR 1020.210(a)(2)(v) and (b)(2)(v)
                                                programs in Minnesota, (Jan. 9, 2026), https://         risk identification. The proposed rule,                (banks); 1023.210(b)(5) (broker-dealers);
                                                www.fincen.gov/system/files/2026-01/FinCEN-                                                                    1024.210(b)(5) (mutual funds); and 1026.210(b)(5)
                                                Alert-Federal-Child-Nutrition-Programs.pdf.               74 31 U.S.C. 5318(h)(2)(B)(iv)(II).                  (FCMs and IBCs).

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00015   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                18718                     Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules

                                                FinCEN proposes this organizational                     meaningful information relevant to                         CFT program, independent testing
                                                change because the activities required                  identifying, assessing, and mitigating                     should be based on objective criteria
                                                by the CDD pillar are, in practice,                     ML/TF risks. Familiarity with local                        designed to assess whether a financial
                                                subsumed by the obligation for a                        businesses, direct interaction between                     institution has established and
                                                covered financial institution to have a                 bank staff and customers, and an                           maintained an effective AML/CFT
                                                risk-based set of internal policies,                    understanding of ordinary patterns of                      program and allocated resources
                                                procedures, and controls that is                        activity within the bank’s community                       consistent with its risk assessment
                                                reasonably designed. The organizational                 may appropriately inform the bank’s                        processes. These criteria should also
                                                change more accurately reflects how                     risk assessment processes and the                          assess whether related program
                                                covered financial institutions                          design of reasonably designed internal                     governance is sufficient to manage risks
                                                operationalize such ongoing customer                    policies, procedures, and controls.                        and apply compensating controls where
                                                due diligence as part of their overall                  While such characteristics do not                          necessary, particularly in areas where
                                                AML programs. This organizational                       reduce a community bank’s obligation                       remediation is underway. This
                                                change, however, is not intended to                     to establish and maintain an effective                     evaluation helps to inform the financial
                                                have any substantive effect on existing                 AML/CFT program in accordance with                         institution’s senior management of
                                                obligations under 31 CFR 1010.230.                      the proposed rule, they may influence                      weaknesses or areas in need of
                                                                                                        how a community bank documents its                         enhancement or stronger controls.
                                                iv. Application to Community Banks
                                                                                                        ML/TF risks and allocates attention and                    Typically, this evaluation includes a
                                                   FinCEN recognizes that financial                     resources consistent with those risks.                     conclusion about the financial
                                                institutions vary significantly in size,                   Further, under the proposed rule’s                      institution’s overall compliance with
                                                structure, complexity, and risk profile.                requirement that a financial institution                   AML/CFT statutory and regulatory
                                                Under the proposed rule, the level of                   review and, as appropriate, incorporate                    requirements and sufficient information
                                                sophistication of a financial institution’s             the AML/CFT Priorities, a community                        for the reviewer (e.g., board of directors,
                                                internal policies, procedures, and                      bank may determine, based on its risk                      senior management, AML/CFT officer,
                                                controls—including its risk assessment                  assessment processes, that certain AML/                    outside auditor, or an examiner) to
                                                processes—should be commensurate                        CFT Priorities may not be applicable to                    reach a conclusion about whether the
                                                with the financial institution’s size,                  its business activities. In such cases, the                risk-based set of internal policies,
                                                structure, risk profile, and complexity.                community bank would not be required                       procedures, and controls is reasonably
                                                Accordingly, financial institutions with                to allocate attention or resources to risks                designed and resources are well-
                                                broader product offerings, more                         for which it has no identified exposure.                   allocated consistent with the
                                                complex corporate structures, or greater                Rather, the bank would be expected to                      institution’s risk assessment processes.
                                                exposure to higher-risk customers,                      direct its attention and resources in a                       Additionally, while financial
                                                products, services, or geographic                       manner consistent with its documented                      institutions retain some flexibility
                                                locations would be expected to establish                ML/TF risks.                                               regarding who conducts the audit or
                                                correspondingly more formalized or                                                                                 testing, the proposed rule would
                                                analytically complex internal policies,                 2. Proposed 31 CFR 10XX.210(b)(2)—                         continue to require that testing be
                                                procedures, and controls—including                      Independent Testing                                        independent. Financial institutions that
                                                risk assessment processes. By contrast,                    The AML Act did not change the BSA                      do not employ outside auditors or
                                                many community banks operate with                       requirement that each financial                            consultants or that do not have internal
                                                more limited business activities,                       institution include ‘‘an independent                       audit departments may comply with
                                                traditional lending and deposit services,               audit function to test programs,’’ 76                      this requirement by using internal staff
                                                a narrower geographic footprint, and                    which is already reflected in AML/CFT                      who are not involved in the function
                                                customer bases concentrated within                      program rule requirements,77 and                           being tested. For these financial
                                                defined local communities. For such                     proposed 31 CFR 10XX.210(b)(2). The                        institutions and financial institutions
                                                banks, risk assessment processes may                    purpose of independent testing is to                       with other types of arrangements for
                                                appropriately be more streamlined or                    assess the financial institution’s                         independent testing, the AML/CFT
                                                qualitative in nature, and a risk-based                 compliance with AML/CFT statutory                          officer or any party who directly, and in
                                                set of internal policies, procedures, and               and regulatory requirements, relative to                   some cases, indirectly reports to the
                                                controls that is reasonably designed for                its risk profile. The independent AML/                     AML/CFT officer, or an equivalent role,
                                                a large, complex financial organization                 CFT program testing should be focused                      would generally not be considered
                                                would not necessarily be required or                    on whether the AML/CFT program is                          sufficiently independent.78 Any
                                                appropriate for a community bank with                   effective, and it should identify issues
                                                a more limited risk profile.                            and areas for remediation accordingly.
                                                                                                                                                                      78 This is consistent with current 31 CFR

                                                   The proposed rule does not prescribe                                                                            1022.210, which provides that independent testing
                                                                                                        Similar to the expectations outlined                       review may be conducted by an officer or employee
                                                any specific methodology for
                                                                                                        above for examiners, Treasury and                          of the MSB so long as the tester is not the AML/
                                                identifying, assessing, and documenting                                                                            CFT officer. Similarly, current 31 CFR 1025.210,
                                                                                                        FinCEN do not believe that an auditor
                                                ML/TF risks. Community banks may use                                                                               1029.210, and 1030.210 provide that independent
                                                                                                        should substitute his or her own
                                                risk assessment processes that are                                                                                 testing at insurance companies, loan or finance
                                                                                                        subjective judgment in place of the                        companies, and housing GSEs, respectively, may be
                                                tailored to their business model and
                                                                                                        financial institution. To support the                      conducted by a third party or by any officer or
                                                operational scale, including processes                                                                             employee of the financial institution, other than the
                                                                                                        effective implementation of an AML/
                                                that rely on direct knowledge of                                                                                   AML/CFT officer. Likewise, 31 CFR 1027.210(b)(4)

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                products, services, customers, and                        76 31 U.S.C. 5318(h)(1)(D).
                                                                                                                                                                   and 1028.210(b)(4) provide that independent testing
                                                geographic locations rather than highly                                                                            of a DPMSJ or an operator of a credit card system,
                                                                                                           77 See 31 CFR 1020.210(a)(2)(ii), (b)(2)(ii) (banks);
                                                                                                                                                                   respectively, can be conducted by an officer or
                                                parameterized or model-driven                           1021.210(b)(2)(ii) (casinos); 1022.210(d)(4) (MSBs);       employee of the institution, so long as the tester is
                                                approaches. Many community banks                        1023.210(b)(2) (broker-dealers); 1024.210(b)(2)            not the AML/CFT officer or a person involved in
                                                maintain longstanding customer                          (mutual funds); 1025.210(b)(4) (insurance                  the operation of the AML/CFT program.
                                                                                                        companies); 1026.210(b)(2) (FCMs and IBCs);                Determining whether testing at U.S. operations of
                                                relationships and operate within                        1027.210(b)(4) (DPMSJs); 1028.210(b)(4) (operators         foreign financial institutions is adequately
                                                defined local markets, which may                        of a credit card system); 1029.210(b)(4) (loan or          ‘‘independent’’ may include a review of the
                                                provide bank personnel with                             finance companies); 1030.210(b)(4) (housing GSEs).         reporting arrangements between the party

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00016   Fmt 4701   Sfmt 4702    E:\FR\FM\10APP4.SGM     10APP4
                                                                           Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules                                                   18719

                                                individual conducting the testing,                      3. Proposed 31 CFR 10XX.210(b)(3)—                     adversely impact the officer’s ability to
                                                whether internal or external, would be                  Designate an AML/CFT Officer Located                   effectively coordinate and monitor day-
                                                required to be independent of other                     in the United States                                   to-day AML/CFT compliance generally
                                                parts of the financial institution’s AML/               i. Duties of the AML/CFT Officer                       would not fulfill this requirement. The
                                                CFT program, including its oversight.                                                                          addition of the explicit requirement that
                                                                                                           The BSA requires that financial                     the AML/CFT officer be responsible for
                                                For financial institutions that engage
                                                                                                        institutions with AML/CFT program                      ‘‘establishing and implementing the
                                                outside auditors or consultants, the                    obligations must have a designated
                                                financial institution would be required                                                                        AML/CFT program’’ in the proposed
                                                                                                        compliance officer. While FinCEN has                   rule would make explicit a long-
                                                to ensure that the outside parties                      adopted this obligation—commonly
                                                conducting the independent testing are                                                                         standing supervisory expectation, rather
                                                                                                        referred to as the BSA/AML officer—in                  than changing current supervisory or
                                                not involved in functions related to the                existing guidance and regulations, the                 regulatory requirements or expectations.
                                                AML/CFT program at the financial                        program rules use slight variations in                    To promote consistency and reduce
                                                institution that may present a conflict of              the specific language to describe this                 redundancy, the proposed rule would
                                                interest or lack of independence, such                  requirement for different types of                     remove some examples of what it means
                                                as AML/CFT training or the                              financial institutions. The proposed rule              to coordinate and monitor day-to-day
                                                development or enhancement of                           provides technical changes to promote                  compliance with AML/CFT
                                                internal policies, procedures, and                      clarity and consistency.                               requirements that are currently listed in
                                                controls. Additionally, for the purposes                   As in the current program rules,                    the AML program rules for MSBs;
                                                of the independent testing component,                   proposed 31 CFR 10XX.210(b)(3) would                   insurance companies; DPMSJs;
                                                outside parties would not include                       provide that an AML/CFT program must                   operators of credit card systems; loan or
                                                government agencies, entities, or                       designate an individual (referred to as
                                                                                                                                                               finance companies; and housing GSEs.81
                                                instrumentalities, such as a financial                  an AML/CFT officer) responsible for
                                                                                                                                                               For example, those AML program rules
                                                                                                        establishing and implementing the
                                                institution’s Federal or State functional                                                                      currently provide that an AML/CFT
                                                                                                        AML/CFT program and coordinating
                                                regulators. Financial institutions with                                                                        officer is responsible for updating the
                                                                                                        and monitoring day-to-day compliance
                                                less complex operations, and lower risk                                                                        financial institution’s AML program and
                                                                                                        with the requirements and prohibitions
                                                profiles may consider utilizing a shared                                                                       ensuring that employees are educated or
                                                                                                        of the BSA and FinCEN’s implementing
                                                resource as part of a collaborative                                                                            trained in accordance with the financial
                                                                                                        regulations. FinCEN’s view is that the
                                                arrangement to conduct testing, as long                                                                        institution’s AML program training
                                                                                                        individual serving as the AML/CFT
                                                as the testing is independent.79                                                                               obligation. Removing this type of
                                                                                                        officer must be qualified for that role
                                                                                                                                                               language in the proposed rule does not
                                                   While all financial institutions are                 and not overburdened with other
                                                                                                                                                               indicate that an AML/CFT officer is not
                                                required under existing regulations to                  responsibilities at the institution.
                                                                                                           The proposed rule is not intended to                responsible for these activities, but
                                                establish independent testing, FinCEN                                                                          rather reflects that such examples in the
                                                is standardizing this requirement across                be primarily concerned with the formal
                                                                                                        title of the individual responsible for                regulatory text are not necessary, and
                                                all financial institution types. For                                                                           that each financial institution should
                                                example, the current rules for broker-                  establishing and implementing the
                                                                                                        AML/CFT program and coordinating                       decide for itself the specific activities
                                                dealers, mutual funds, and FCMs and                                                                            that an AML/CFT officer should
                                                IBCs require outside parties conducting                 and monitoring day-to-day compliance;
                                                                                                        instead, the proposed rule focuses on                  undertake to establish, maintain, and
                                                the independent testing to be                                                                                  implement an AML/CFT program.
                                                                                                        the AML/CFT officer’s position in the
                                                qualified; 80 however, FinCEN does not                                                                            Likewise, the proposed rule would
                                                                                                        financial institution’s organizational
                                                find it necessary to add this ‘‘qualified’’                                                                    remove unnecessary provisions in
                                                                                                        structure that enables the AML/CFT
                                                description as it does not establish a                                                                         certain current program rules—those
                                                                                                        officer to effectively establish and
                                                new substantive requirement. FinCEN                                                                            applicable to DPMSJs; operators of
                                                                                                        implement the financial institution’s
                                                would generally expect, as with the                                                                            credit card systems; loan or finance
                                                                                                        AML/CFT program. The AML/CFT
                                                AML/CFT officer component,                                                                                     companies; and housing GSEs—
                                                                                                        officer’s authority, independence, and
                                                independent testers to have the                                                                                requiring AML/CFT officers to ensure
                                                                                                        access to resources within the financial
                                                expertise and experience necessary to                                                                          that a financial institution’s AML/CFT
                                                                                                        institution are critical. An AML/CFT
                                                perform such testing effectively,                                                                              program is implemented effectively.82
                                                                                                        officer should have decision-making
                                                including having sufficient knowledge                                                                          That expectation is embedded in the
                                                                                                        capability regarding the AML/CFT
                                                of the financial institution’s risk profile                                                                    proposed rule’s requirement that AML/
                                                                                                        program and sufficient functional
                                                and AML/CFT laws and regulations.                                                                              CFT officers coordinate and monitor
                                                                                                        stature within the organization to ensure
                                                                                                                                                               day-to-day compliance.
                                                                                                        that the program meets BSA
                                                                                                                                                                  Similarly, the proposed rule would
                                                                                                        requirements.
                                                                                                                                                               delete an unnecessary reference from
                                                                                                           The AML/CFT officer’s access to
                                                conducting the independent testing and the AML/                                                                current 31 CFR 1022.210(d)(2)(i). That
                                                CFT officer, or equivalent management function          resources may include the following:
                                                                                                                                                               provision provides that an MSB’s AML/
                                                such as a head of business line or a general            adequate compliance funds and staffing
                                                                                                                                                               CFT officer must ensure that the MSB
                                                manager, to assess any conflicts of interests and the   with the skills and expertise appropriate
                                                                                                                                                               properly files reports, and creates and
                                                level of independence with the party conducting         to the financial institution’s risk profile,
                                                                                                                                                               retains records, in accordance with the
                                                the independent testing.                                size, and complexity; an organizational

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                  79 See FRB, FDIC, NCUA, OCC and FinCEN,
                                                                                                        structure that supports compliance and                    81 See 31 CFR 1022.210(d)(2) (MSBs);
                                                Interagency Statement on Sharing Bank Secrecy Act       effectiveness; and sufficient technology
                                                Resources (Oct. 3, 2018), https://www.fincen.gov/                                                              1025.210(b)(2) (insurance companies);
                                                                                                        and systems to support the timely                      1027.210(b)(2) (DPMSJs); 1028.210(b)(2) (operators
                                                news/news-releases/interagency-statement-sharing-
                                                bank-secrecy-act-resources.
                                                                                                        identification, measurement,                           of credit card systems); 1029.210(b)(2) (loan or
                                                                                                        monitoring, reporting, and management                  finance companies); 1030.210(b)(2) (housing GSEs).
                                                  80 See applicable program rules located at 31 CFR
                                                                                                                                                                  82 See 31 CFR 1027.210(b)(2)(i) (DPMSJs);
                                                1023.210(b)(2) (broker-dealers); 1024.210(b)(2)         of the financial institution’s ML/TF                   1028.210(b)(2)(i) (operators of credit card systems);
                                                (mutual funds); and 1026.210(b)(2) (FCMs and            risks. An AML/CFT officer with                         1029.210(b)(2)(i) (loan or finance companies);
                                                IBCs).                                                  conflicting responsibilities that                      1030.210(b)(2)(i) (housing GSEs).

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00017   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                18720                        Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules

                                                BSA. These activities are and remain                    any further clarifications on this point                 Proposed 31 CFR 10XX.210(d) would
                                                part of the AML/CFT officer’s duty to                   would be useful.                                         provide a consistent standard by
                                                monitor and coordinate day-to-day                                                                                requiring that an AML/CFT program be
                                                                                                        4. Proposed 31 CFR 10XX.210(b)(4)—
                                                compliance, and thus it is not necessary                                                                         written, and that a financial institution,
                                                                                                        Ongoing Employee Training Program
                                                to separately list them in the rule. This                                                                        upon request, make available a copy of
                                                deletion and the removal of the other                      The BSA requires AML/CFT programs                     its written AML/CFT program to
                                                redundant references will ensure                        to include an ‘‘ongoing employee                         FinCEN or its designee. FinCEN’s
                                                consistent language across program                      training program.’’ 85 This statutory                    designee, in this instance, includes any
                                                rules.                                                  requirement is reflected in all current                  agency to which FinCEN has delegated
                                                                                                        AML program rules, but in different                      examination authority or the
                                                ii. Proposed 31 CFR 10XX.210(b)(3)—                     formulations.86 Proposed 31 CFR                          appropriate SRO. It is thus assured that
                                                The AML/CFT Officer Must Be Located                     10XX.210(b)(4) would eliminate                           agencies with original or delegated
                                                in the United States and Accessible to                  inconsistency in the AML program                         examination authority over a financial
                                                Regulators                                              rules’ training requirement by adopting                  institution, including for example an
                                                                                                        the BSA’s ‘‘ongoing employee training                    agency with examination authorities
                                                   The AML Act provides that the duty
                                                                                                        program’’ language uniformly. This                       delegated by FinCEN 88 or the
                                                to establish, maintain, and enforce a
                                                                                                        change is clarifying, not substantive.                   appropriate SRO 89 will be among the
                                                financial institution’s AML/CFT
                                                                                                           FinCEN would generally expect                         agencies able to access a financial
                                                program shall remain the responsibility
                                                                                                        training to cover the financial                          institution’s written AML/CFT program.
                                                of, and be performed by, persons in the
                                                                                                        institution’s internal policies,                         In addition to promoting consistency
                                                United States who are accessible to, and                procedures, and controls, which should                   across the program rules, these
                                                subject to oversight and supervision by,                in turn reflect the results of the financial             clarifications are intended to help
                                                the Secretary and the appropriate                       institution’s risk assessment processes,                 financial institutions develop a
                                                Federal functional regulator.83 Proposed                the latest AML/CFT regulatory                            structured AML/CFT program
                                                31 CFR 10XX.210(b)(3) therefore                         requirements, and other relevant                         understood across the enterprise.
                                                requires the very same, noting that the                 information. The frequency with which
                                                designated individual must be                           the training would occur, and the                        2. Proposed 31 CFR 10XX.210(d)—
                                                accessible to, and subject to oversight                 content of the training, would depend                    Financial Institution Approval of a
                                                and supervision by, FinCEN and its                      on the financial institution’s ML/TF risk                Written AML/CFT Program
                                                designee. FinCEN’s designee, in this                    profile and the roles and responsibilities                 Proposed 31 CFR 10XX.210(d) would
                                                instance, includes any agency to which                  of the persons receiving the training.                   also require that a financial institution’s
                                                FinCEN has delegated examination                        FinCEN welcomes comment on whether                       written AML/CFT program be approved
                                                authority or the appropriate SRO.                       any further clarifications of the                        by the financial institution’s board of
                                                   FinCEN recognizes financial                          proposed training requirement are                        directors or an equivalent governing
                                                institutions may currently have AML/                    needed. FinCEN recognizes that                           body within the financial institution, or
                                                CFT staff and operations outside of the                 financial institutions may have                          appropriate senior management.
                                                United States, or they may contract out                 employees and non-employees who may                        Current program rules generally
                                                or delegate parts of their AML/CFT                      have a variety of roles and                              require a financial institution’s board or
                                                operations to third-party providers                     responsibilities in relation to the AML/                 an equivalent governing body within the
                                                located outside of the United States.                   CFT program. The risk-based nature of                    institution, or appropriate senior
                                                These arrangements may serve to                         an AML/CFT program provides                              management, to approve the financial
                                                improve cost efficiencies, to enhance                   flexibility for financial institutions to                institution’s written AML program.
                                                coordination, particularly with respect                 identify both employees and non-                         However, the proposed rule
                                                to cross-border operations, or serve                    employees who must be trained on an
                                                other purposes not in conflict with goals               ongoing basis.                                           maintain, and make available a written anti-money
                                                underlying the BSA. Consequently,                                                                                laundering program. Banks with a Federal
                                                under the proposed rule, while the                      E. Access to and Approval of a Written                   functional regulator are required to have written
                                                                                                        AML/CFT Program                                          anti-money laundering programs under the
                                                AML/CFT officer must be located in the                                                                           regulators’ existing rules. See 12 CFR 21.21(c)(1),
                                                United States, personnel located outside                1. Proposed 31 CFR 10XX.210(d)—                          208.63(b)(1), 326.8(b)(1), 748.2(b)(1). The current
                                                of the United States would still be                     Written AML/CFT Programs Must Be                         program rules require other types of financial
                                                                                                                                                                 institutions to have written programs at 31 CFR
                                                permitted to perform certain AML/CFT                    Made Available Upon Request                              1021.210(b)(1) (casinos); 1022.210(c) (MSBs);
                                                functions. This language does not alter                                                                          1023.210 (broker-dealers); 1024.210(a) (mutual
                                                                                                          Current program rules generally
                                                existing regulations and guidance that                                                                           funds); 1025.210(a) (insurance companies);
                                                                                                        require financial institutions to have                   1026.210 (FCMs and IBCs); 1027.210(a)(1)
                                                generally prohibit the sharing of SARs
                                                                                                        written AML/CFT programs, but there is                   (DPMSJs); 1028.210(a) (operators of credit card
                                                with personnel located outside of the
                                                                                                        variation in how the requirement is                      systems); 1029.210(a) (loan or finance companies);
                                                United States other than in limited                                                                              1030.210(a) (housing GSEs).
                                                                                                        formulated in FinCEN’s regulations for
                                                circumstances such as a bank’s foreign                                                                             88 See 31 CFR 1010.810(b) (FinCEN’s delegation
                                                                                                        certain types of financial institutions.87
                                                head office or controlling company.84                                                                            of ‘‘[a]uthority to examine institutions to determine
                                                FinCEN requests comment on whether                                                                               compliance with the requirements of this chapter’’).
                                                                                                          85 31 U.S.C. 5318(h)(1)(C).                              89 For broker-dealers, FinCEN recognizes the SEC
                                                                                                           86 See 31 CFR 1020.210(a)(2)(iv), (b)(2)(iv)
                                                                                                                                                                 as the relevant Federal functional regulator. See id.
                                                  83 31 U.S.C. 5318(h)(5).                              (banks); 1021.210(b)(2)(iii) (casinos); 1022.210(d)(3)   1010.810(b)(6) (delegating examination authority to

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                  84 See, e.g., FinCEN, Financial Crimes                (MSBs); 1023.210(b)(4) (broker-dealers);                 SEC for broker-dealers). FinCEN recognizes
                                                Enforcement Network; Confidentiality of Suspicious      1024.210(b)(4) (mutual funds); 1025.210(b)(3)            registered national securities exchanges or a
                                                Activity Reports, 75 FR 75593 (Dec. 3, 2010); see       (insurance companies); 1026.210(b)(4) (FCMs and          national securities association, such as the
                                                also FinCEN, FRB, FDIC, OCC, and Office of Thrift       IBCs); 1027.210(b)(3) (DPMSJs); 1028.210(b)(3)           Financial Industry Regulatory Authority (FINRA),
                                                Supervision, Interagency Guidance on Sharing            (operators of credit card systems); 1029.210(b)(3)       as the relevant SROs for member broker-dealers.
                                                Suspicious Activity Reports with Head Offices and       (loan or finance companies); 1030.210(b)(3)              Similarly, for FCMs and IBCs, FinCEN recognizes
                                                Controlling Companies (Jan. 20, 2006), https://         (housing GSEs).                                          the CFTC as the relevant Federal functional
                                                www.fincen.gov/system/files/guidance/sarsharing            87 Current 31 CFR 1020.210(b) requires banks          regulator, 31 CFR 1010.810(b)(9), and the National
                                                guidance01122006.pdf.                                   lacking a Federal functional regulator to establish,     Futures Association (NFA) as the SRO.

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00018   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM     10APP4
                                                                           Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules                                            18721

                                                standardizes this language across all                   within the bank.91 Banks with a Federal                 to these principles is critical to ensuring
                                                financial institution types and provides                functional regulator must also have                     that AML/CFT programs are effective.
                                                financial institutions with significant                 board approval for their AML/CFT                           At the same time, an alternative
                                                flexibility in its chosen approval                      programs under their regulators’                        approach is to refrain from prescribing
                                                method. While some financial                            existing rules, although not FinCEN’s.92                corporate-governance detail in the
                                                institutions may choose to have their                   On the other hand, broker-dealers;                      proposed rule, instead allowing
                                                boards approve the written AML/CFT                      insurance companies; FCMs and IBCs;                     financial institutions to determine the
                                                program, for others, an equivalent                      DPMSJs; operators of credit card                        appropriate approving authority
                                                governing body might be a sole                          systems; loan or finance companies; and                 consistent with their legal structure and
                                                proprietor, general partner, or trustee, or             housing GSEs, must currently obtain                     other regulatory and legal requirements.
                                                a grouping of owners, senior officers                   senior management level approval for                    Leaving firm-level choices to financial
                                                (including board committees or other                    their AML/CFT programs.93 Board                         institutions would preserve flexibility
                                                groups with oversight responsibilities),                approval is not required for these                      across differing corporate structures,
                                                senior management, or other persons                     entities currently, so the proposed rule                avoid imposing a single model for
                                                having functions and authority similar                  would not be a change. The existing                     allocating responsibilities, and reduce
                                                to that of a board. For the U.S. branch                 program rules for casinos and MSBs do                   the risk of unintended conflict with
                                                of a foreign bank, the equivalent                       not contain specific board or senior                    other regulatory or legal requirements.
                                                governing body may be the foreign                       management approval requirements, so                    F. Proposed 31 CFR 1020.221—
                                                banking organization’s board of                         the proposed rule would constitute a                    Supervision and Enforcement
                                                directors or delegates acting under the                 change for these entities.94
                                                                                                           In the case of some financial                           The proposed rule would add new 31
                                                board’s express authority.90
                                                                                                        institutions, there may be existing                     CFR 1020.221 to set forth a supervision
                                                   Alternatively, some financial                        statutes or regulations (other than the                 and enforcement framework for banks’
                                                institutions might have other                           BSA and its implementing regulations)                   AML/CFT programs that is aligned with
                                                individuals or groups with similar                      that will determine whether a financial                 the AML Act’s emphasis on
                                                status or functions as directors approve                institution must have its board approve                 effectiveness and risk-based
                                                the AML/CFT program. Such                               its AML/CFT program. The proposed                       supervision. The proposed section
                                                individuals may include Chief                           rule would not interfere with any such                  defines key terms, describes FinCEN’s
                                                Executive Officer, Chief Financial                      requirements. For instance, mutual                      enforcement and supervision policy
                                                Officer, Chief Operations Officer, Chief                funds must comply with Rule 38a–1                       with respect to the requirements of the
                                                Legal Officer, Chief Compliance Officer,                under the Investment Company Act of                     BSA or 31 CFR chapter X, establishes
                                                Director, and individuals with similar                  1940 requiring board approval of a                      consultation requirements between
                                                status or functions. Also, groups with                  mutual fund’s written policies and                      FinCEN and the Agencies, when acting
                                                oversight responsibilities may include                  procedures, which would include its                     under supervisory authority delegated
                                                board committees such as compliance or                  AML/CFT Program.95 Because of this                      by FinCEN, and specifies factors that the
                                                audit committees as well as a group of                  requirement, FinCEN understands that                    Director would consider in determining
                                                some, or all of these individuals with                  Rule 38a–1 would be controlling in                      whether to take, or in reviewing, an
                                                aforementioned titles, as senior                        practice and require a mutual fund’s                    AML/CFT enforcement action or
                                                management that can provide effective                   board to approve its AML/CFT program;                   significant AML/CFT supervisory
                                                oversight of the AML/CFT program to                     needless to say, such approval would                    action. The supervision and
                                                comply with the proposed rule.                          also satisfy FinCEN’s proposed rule.                    enforcement requirements apply only to
                                                   Although some financial institutions                    The proposed rule’s provision                        banks and the Agencies in the proposed
                                                must already obtain board approval for                  requiring the approval of the AML/CFT                   rule, but FinCEN welcomes comment on
                                                their AML/CFT programs or be subject                    program by a financial institution’s                    whether these provisions should apply
                                                to oversight by a board of directors, or                board of directors, equivalent body, or                 to other financial institutions. Likewise,
                                                an equivalent governing body, this                      appropriate senior management reflects                  the enforcement requirements do not
                                                board or senior management approval                     the importance of a financial institution               apply to and in no way affect criminal
                                                requirement will represent a change in                  maintaining a strong culture of                         enforcement liability under the Bank
                                                requirements for other financial                        compliance. A culture of compliance                     Secrecy Act.
                                                institutions. In some cases, the proposed               involves demonstrable support and
                                                                                                        visible commitment from leadership,                     1. Proposed 31 CFR 1020.221(a)—
                                                rule would provide greater flexibility                                                                          Definitions
                                                than current program rules provide. For                 the dedication of adequate resources to
                                                example, a bank lacking a Federal                       AML/CFT compliance, effective                              Proposed 31 CFR 1020.221(a) would
                                                functional regulator must have an AML/                  information sharing throughout the                      define several terms used throughout
                                                CFT program that is approved by the                     financial institution, qualified and                    the section. The term ‘‘AML/CFT
                                                board or equivalent governing body                      independent testing, and understanding                  requirement’’ would mean a
                                                                                                        across leadership and staff levels of the               requirement of the BSA or 31 CFR
                                                  90 The FRB, FDIC, and OCC each require the U.S.
                                                                                                        importance of BSA reports. Adherence                    chapter X.
                                                branches, agencies, and representative offices of the                                                              The term ‘‘AML/CFT enforcement
                                                foreign banks they supervise operating in the
                                                                                                          91 See 31 CFR 1020.210(b)(3) (banks lacking a
                                                                                                                                                                action’’ as proposed in 31 CFR
                                                United States to develop written BSA compliance         Federal functional regulator).                          1020.211(a)(1) would mean any formal
                                                                                                          92 See 12 CFR 21.21(c)(1), 208.63(b)(1),
                                                programs that are approved by their respective

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                                                                        326.8(b)(1), 748.2(b)(1).
                                                                                                                                                                or informal action taken by FinCEN that
                                                bank’s board and noted in the minutes, or that are
                                                approved by delegates acting under the express            93 See 31 CFR 1023.210 (broker-dealers);              seeks to penalize, remedy, prevent, or
                                                authority of their respective bank’s board to           1025.210(a) (insurance companies); 1026.210 (FCMs       respond to noncompliance with, past or
                                                approve the BSA compliance programs. See                and IBCs); 1027.210(a)(1) (DPMSJs); 1028.210(a)         ongoing violations of, or past or ongoing
                                                208.63(b)(1), 12 CFR 21.21(c)(1), 326.8(b)(1), and      (operators of credit card systems); 1029.210(a) (loan
                                                                                                        or finance companies); 1030.210(a) (housing GSEs).
                                                                                                                                                                deficiencies relating to, an AML/CFT
                                                748.2(b)(1). ‘‘Express authority’’ means the head
                                                office must be aware of its U.S. AML program              94 See applicable AML program rules located at        requirement.
                                                requirements and there must be some indication of       31 CFR 1021.210 (casinos) and 1022.210 (MSBs).             The term ‘‘significant AML/CFT
                                                purposeful delegation.                                    95 See 17 CFR 270.38a–1(a)(2).                        supervisory action’’ as proposed in 31

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00019   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                18722                      Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules

                                                CFR 1020.221(a)(3) would mean any                        3. 31 CFR 1020.221(c)—FinCEN                          or performing other innovative activities
                                                written communication or other formal                    Consultation                                          producing demonstrable outputs
                                                supervisory determination issued by                         Proposed 31 CFR 1020.221(c) would                  evincing the effectiveness of the bank’s
                                                FinCEN or an Agency, when acting                         establish a notice and consultation                   AML/CFT program (including effective
                                                under supervisory authority delegated                    framework applicable when the                         use of artificial intelligence, federated
                                                by FinCEN, that identifies one or more                   Agencies, acting under supervisory                    learning, or other advanced monitoring
                                                alleged deficiencies, weaknesses,                        authority delegated by FinCEN, intend                 tools); and any other factor the Director
                                                violations of law, or unsafe or unsound                  to initiate a significant AML/CFT                     deems appropriate, including the bank’s
                                                practices or conditions relating to an                   supervisory action. Before initiating                 size, complexity, and risk profile, and,
                                                AML/CFT requirement; communicates                        such an action, the Agencies would be                 as relevant, circumstances in which the
                                                supervisory expectations regarding                       required to provide the Director with an              bank’s low-risk customers or limited
                                                actions or remedial measures required                    opportunity to review the action and                  business activities naturally limit the
                                                to correct the issue; and contemplates                   consider any input offered by the                     extent to which the bank can
                                                significant or programmatic actions or                   Director, which may include any view                  meaningfully contribute to AML/CFT
                                                remedial measures to be taken by the                                                                           Priorities.
                                                                                                         as to the effectiveness of the bank’s
                                                                                                                                                                  The Director’s consideration of the
                                                bank. Examiner observations,                             AML/CFT program. To facilitate that
                                                                                                                                                               extent to which a bank has provided
                                                suggestions, or other informal comments                  review, the Agencies would be required                highly useful information to law
                                                would be expressly excluded from this                    to provide written notice to the Director             enforcement or national security
                                                definition.                                              of their intent to take the action at least           agencies reflects that FinCEN considers
                                                                                                         30 days in advance of the proposed                    information sharing to be an important
                                                2. Proposed 31 CFR 1020.221(b)—                          action, unless a shorter period is
                                                FinCEN Enforcement and Supervision                                                                             element of an effective AML/CFT
                                                                                                         necessary, in the sole discretion of the              program. Financial institutions may
                                                Policy                                                   Agencies, to remedy, prevent, or                      share useful information by responding
                                                   Proposed 31 CFR 1020.221(b) would                     respond to an unsafe or unsound                       to 314(a) requests or may use 314(b)
                                                articulate FinCEN’s enforcement and                      practice or condition.                                authorities to share information with
                                                                                                            The notice would be accompanied by                 other financial institutions to identify
                                                supervision policy as it relates to AML/
                                                                                                         the relevant AML/CFT information                      and report to the Federal Government
                                                CFT requirements applicable to banks.96
                                                                                                         underlying the proposed action.                       activities that may involve ML/TF.
                                                Except with respect to a significant or
                                                                                                         Relevant AML/CFT information may                      Financial institutions may also elect to
                                                systemic failure to implement an                         include, but is not limited to: the
                                                effective AML/CFT program (i.e.,                                                                               participate in the FinCEN Exchange
                                                                                                         relevant portions of the draft report                 Program, a voluntary public-private
                                                deficiencies or issues that arise from                   enforcement action; the relevant
                                                failing to implement, in all material                                                                          information sharing partnership among
                                                                                                         examination workpapers supporting the                 FinCEN, law enforcement agencies,
                                                respects, a properly established AML/                    proposed action and the relevant AML/
                                                CFT program), a bank that has properly                                                                         national security agencies, and financial
                                                                                                         CFT information submitted by the bank                 institutions and other private sector
                                                established an AML/CFT program                           to the Agency. FinCEN notes the
                                                would not be subject to an AML/CFT                                                                             entities that aims to support priority
                                                                                                         Agencies would not be obligated to                    national security and counter-illicit
                                                enforcement action based on the                          provide information over which the
                                                program rule by FinCEN or to a                                                                                 finance objectives.99 FinCEN strongly
                                                                                                         bank may claim privilege under Federal                encourages information sharing for the
                                                significant AML/CFT supervisory action                   or State law. The Agencies would also
                                                based on the program rule by FinCEN or                                                                         purpose of advancing the AML/CFT
                                                                                                         be required to respond to requests for                Priorities.
                                                by the Agencies, when acting under                       additional AML/CFT information from                      The Director may consider the above
                                                supervisory authority delegated by                       the Director regarding the proposed                   alongside other factors, including those
                                                FinCEN.                                                  action.                                               outlined in the FinCEN Statement on
                                                   At the same time, the proposed rule                                                                         Enforcement of the Bank Secrecy Act,
                                                                                                         4. 31 CFR 1020.221(d)—FinCEN
                                                would clarify that nothing in this policy                                                                      such as the nature and seriousness of
                                                                                                         Considerations
                                                would restrict an AML/CFT                                                                                      violations, including the extent of
                                                enforcement action or a significant                         Proposed 31 CFR 1020.221(d)                        possible harm to the public and
                                                AML/CFT supervisory action with                          specifies the factors that the Director               amounts involved; impact or harm of
                                                respect to a failure to properly establish               would consider in determining whether                 the violations on FinCEN’s mission to
                                                an AML/CFT program. Moreover, the                        to take an enforcement action or                      safeguard the financial system from
                                                proposed rule would not affect the                       significant supervisory action with                   illicit use, combat money laundering,
                                                factors that FinCEN applies in the                       respect to banks, or when reviewing a                 and promote national security; or
                                                disposition of a violation 97 once                       proposed action by the Agencies.98                    financial gain or other benefit resulting
                                                FinCEN has determined that such                          These factors would include the factors               from, or attributable to, the violations,
                                                violation involves either: (1) a failure to              set forth in 31 U.S.C. 5318(h)(2)(B), as              amongst others.100
                                                properly establish an AML/CFT                            applicable; the extent, if any, to which
                                                                                                         the bank—where appropriate in light of                G. Other Changes for Modernization,
                                                program, or (2) a significant or systemic
                                                                                                         its size, complexity, and risk profile—               Clarification, and Consistency
                                                failure to implement an effective AML/
                                                CFT program.                                             has advanced the AML/CFT Priorities                     In addition to the previously
                                                                                                         by providing highly useful information

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                                                                                                                               described changes, the proposed rule
                                                   96 The proposal is not intended to and does not
                                                                                                         to law enforcement or national security               would make other revisions to increase
                                                affect criminal enforcement liability under the BSA,     officials, conducting proactive analytics
                                                or the related authority of the Department of Justice.                                                           99 FinCEN, FinCEN Exchange, https://
                                                   97 FinCEN, FinCEN Statement on Enforcement of           98 This includes when the Agencies are              www.fincen.gov/resources/fincen-exchange.
                                                the Bank Secrecy Act (Aug. 18, 2020), at pp. 2–3,        consulting with FinCEN as required under the            100 FinCEN, FinCEN Statement on Enforcement of

                                                https://www.fincen.gov/system/files/shared/              proposed rule, or under a consultation requirement    the Bank Secrecy Act (Aug. 18, 2020), https://
                                                FinCEN%20Enforcement%20Statement_                        they have imposed on themselves (which may            www.fincen.gov/system/files/shared/FinCEN%20
                                                FINAL%20508.pdf.                                         include enforcement actions).                         Enforcement%20Statement_FINAL%20508.pdf.

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00020   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                                           Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules                                         18723

                                                clarity and consistency in the program                   As the delegated administrator of the                  2. Conforming and Modernizing
                                                rules. Most of these changes are                         BSA, FinCEN expects banks to adhere to                 Program Rules
                                                technical, such as renumbering                           FinCEN’s rule as promulgated via the                     For purposes of consistency and
                                                provisions, amending cross-references,                   Secretary’s explicit authority to                      clarity, the proposed rule would
                                                and updating statutory references based                  prescribe minimum standards for AML/                   harmonize certain elements, as
                                                on changes to the BSA by the AML Act.                    CFT programs.                                          described below, of the program rules
                                                For example, along with the Agencies,                       The proposed rules for broker-dealers               for casinos and MSBs to the program
                                                references to ‘‘BSA/AML programs’’ are                   and FCMs and IBCs would retain                         rules for banks; broker-dealers; mutual
                                                being updated to ‘‘AML/CFT programs’’                    requirements to comply with the rules,                 funds; insurance companies; FCMs and
                                                for financial institutions subject to CIP                regulations, or requirements of their                  IBCs; DPMSJs; operators of credit card
                                                requirements.101 These technical                         SROs, provided those rules, regulations,               systems; loan or finance companies; and
                                                changes are not anticipated to establish                 or requirements have been made                         housing GSEs.
                                                new obligations.                                         effective under the Securities Exchange                  Additionally, for casinos, the
                                                   The proposed rule also would make                     Act of 1934 for broker-dealers,104 or the              proposed rule would remove the
                                                minor changes to the definitions in                      Commodity Exchange Act for FCMs and
                                                FinCEN regulations, including the                                                                               following language in 31 CFR
                                                                                                         IBCs,105 or by the appropriate Federal                 1021.210(b)(2)(vi): ‘‘For casinos that
                                                definition of ‘‘Bank Secrecy Act’’ at 31                 functional regulator in consultation
                                                CFR 1010.100(e).102 The proposed rule                                                                           have automated data processing
                                                                                                         with FinCEN.                                           systems, the use of automated programs
                                                would also amend the definition of                          The following subsections describe
                                                ‘‘Federal functional regulator’’ at                                                                             to aid in assuring compliance.’’
                                                                                                         more significant changes.                              Similarly, for MSBs, the proposed rule
                                                § 1010.100(r) to remove reference to the
                                                defunct Office of Thrift Supervision and                 1. Combining the Bank Rules                            would remove the following language in
                                                insert ‘‘The Federal Deposit Insurance                                                                          31 CFR 1022.210(d)(1)(ii): ‘‘Money
                                                                                                            Since 2020, banks lacking a Federal                 services businesses that have automated
                                                Corporation’’ in place of ‘‘The Board of                 functional regulator have been subject to
                                                Directors of the Federal Deposit                                                                                data processing systems should
                                                                                                         substantially similar AML/CFT program                  integrate their compliance procedures
                                                Insurance Corporation.’’ The proposed                    requirements (31 CFR 1020.210(b)) as
                                                rule would also add a definition of                                                                             with such systems.’’ The removal of
                                                                                                         banks with a Federal functional                        automated data processing language is
                                                ‘‘AML/CFT priorities’’ at                                regulator (31 CFR 1020.210(a)).106 The
                                                § 1010.100(nnn) to mean the most recent                                                                         not intended to eliminate any
                                                                                                         proposed rule would combine the                        substantive BSA compliance obligations
                                                statement of Anti-Money Laundering                       program rules for both bank types.
                                                and Countering the Financing of                                                                                 for casinos or MSBs. Rather, it reflects
                                                                                                            The most significant difference                     that the application of the same risk-
                                                Terrorism National Priorities issued
                                                                                                         between the existing AML program                       based approach used in the other
                                                pursuant to 31 U.S.C. 5318(h)(4).
                                                                                                         rules is that 31 CFR 1020.210(b)(3)                    program rules, which allows—but does
                                                Finally, as noted above, the proposed
                                                                                                         requires banks lacking a Federal                       not mandate—the use of automated data
                                                rule adds a definition of ‘‘Federal
                                                                                                         functional regulator to: (1) have their                processing systems.
                                                Financial Institutions Regulatory
                                                                                                         AML programs approved by the board of                    A few unique elements of the existing
                                                Agency’’ at § 1010.100(ooo).103
                                                   Additionally, as required under                       directors or, if the bank does not have                program rule for MSBs would be carried
                                                section 6101(b) of the AML Act, FinCEN                   a board of directors, an equivalent                    over into the new rule language. In
                                                consulted with Federal functional                        governing body within the bank; and (2)                particular, the customer identification
                                                regulators, particularly the Agencies, to                make a copy of its AML program                         provisions of current 31 CFR
                                                inform this rulemaking and coordinate                    available to FinCEN or its designee                    1022.210(d)(1)(i)(A) and (d)(1)(iv), and
                                                updates to the bank program rule. The                    upon request. FinCEN’s designee, in this               the agent responsibility provision of
                                                proposed rule is removing the provision                  instance, includes any agency to which                 current 31 CFR 1022.210(d)(1)(iii),
                                                in FinCEN’s program rule for banks                       FinCEN has delegated examination                       would all be retained in the new MSB
                                                requiring them to comply with the                        authority or the appropriate SRO. As                   program rule language. This language
                                                parallel program rule for banks adopted                  previously discussed, the proposed rule                reflects FinCEN’s longstanding
                                                by the Federal functional regulators                     would require banks to obtain the                      appreciation of the special
                                                since these program rules are consistent.                approval of their AML/CFT programs                     circumstances applicable to many
                                                                                                         from the board of directors, an                        members of the extraordinarily diverse
                                                  101 The CIP rules are located at 31 CFR 1020.220       equivalent governing body within the                   category of MSB, an appreciation that
                                                (banks), 1023.220 (broker-dealers), 1024.220             bank, or appropriate senior                            remains as accurate now as it was when
                                                (mutual funds), and 1026.220 (FCMs and IBCs).            management, and it would require that                  these unique elements were included in
                                                  102 In particular, FinCEN first proposes to
                                                                                                         the AML/CFT program be made                            FinCEN’s regulations.
                                                simplify this BSA definition to refer only to the U.S.
                                                Code provisions codifying the BSA, rather than to
                                                                                                         available to FinCEN or its designee
                                                                                                         upon request. With these changes,                      3. Compliance and Implementation
                                                any act of Congress from which these provisions
                                                were originally derived. Second, FinCEN proposes         FinCEN believes it would no longer be                  Dates
                                                removing 18 U.S.C. 1956, 1957, and 1960 from the         necessary to have two sets of program                     Current 31 CFR 1022.210(e),
                                                regulatory BSA definition. These criminal
                                                provisions were included in FinCEN’s BSA
                                                                                                         rules for banks. Therefore, the proposed               1027.210(c), 1029.210(d), and
                                                definition given their relationship to money             rule would consolidate 31 CFR                          1030.210(d) contain compliance and
                                                laundering but are not otherwise linked to the other     1020.210(a) and (b) into a single set of               implementation dates for MSBs;
                                                BSA provisions and are not included in the AML           rules applicable to all banks.

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                                                                                                                                DPMSJs; loan or finance companies; and
                                                Act’s BSA definition in section 6003(1) of the Act.
                                                Third, FinCEN proposes amending its BSA                                                                         housing GSEs, respectively. The
                                                definition to include 31 U.S.C. 5336 (i.e., the           104 15 U.S.C. 78a et seq.                             proposed rule would retain
                                                operative provisions of the Corporate Transparency        105 7 U.S.C. 1 et seq.
                                                                                                                                                                implementation dates for MSBs and
                                                Act), which was added to the BSA by section 6403           106 See FinCEN, Customer Identification
                                                                                                                                                                DPMSJs, respectively, since they set the
                                                of the AML Act.                                          Programs, Anti-Money Laundering Programs, and
                                                  103 Additionally, FinCEN proposes amending the         Beneficial Ownership Requirements for Banks
                                                                                                                                                                time frames in which those specific
                                                authority citations in the relevant CFR sections to      Lacking a Federal Functional Regulator, 85 FR          financial institution types are required
                                                account for relevant statutory changes.                  57129 (Sept. 15, 2020).                                to comply once they conduct certain

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00021   Fmt 4701    Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                18724                     Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules

                                                activities or pass thresholds that subject              institutions are best placed to identify               financial institutions free to use findings
                                                them to AML/CFT program                                 risks and allocate resources, and that                 from one or more processes to
                                                requirements. The proposed rule would                   providing them with greater discretion                 holistically assess their ML/TF risks.
                                                also update the citations for these                     in these areas will improve the quality                Does this description of how financial
                                                provisions (to 31 CFR 1022.210(d) and                   of AML/CFT compliance and reporting                    institutions would assess their ML/TF
                                                1027.210(e)) to reflect other changes                   to law enforcement. Is this correct or                 risk under the proposed rule provide
                                                made to §§ 1022.210(d) and 1027.210(e).                 should FinCEN consider adding more                     sufficient flexibility? How should
                                                   The proposed rule, however, would                    requirements regarding allocation of                   FinCEN describe ‘‘risk assessment
                                                amend these provisions, as well as those                resources? How might financial                         processes’’ to better reflect how
                                                of other types of financial institutions,               institutions assess changes in the total               financial institutions assess ML/TF
                                                such as loan or finance companies and                   allocation of resources devoted to an                  risks?
                                                housing GSEs, to remove compliance                      AML/CFT program in a changing risk                        10. Should risk assessment processes
                                                dates that have passed and are therefore                and cost environment?                                  be required to take into account
                                                irrelevant.                                                                                                    additional or different criteria or risks
                                                                                                        Establishing and Maintaining an AML/
                                                4. Compliance With Other Rules                          CFT Program (V.C.)                                     than those listed in the proposed rule?
                                                   For consistency and clarity, the                                                                            If so, what additional factors should
                                                                                                           3. Do financial institutions                        FinCEN consider requiring?
                                                proposed rule would delete certain                      distinguish between ‘‘establishing a
                                                unnecessary cross-references to other                   program’’ and ‘‘maintaining a program                     11. How long does it generally take a
                                                regulations. Specifically, the proposed                 by implementing the program’’? If so,                  financial institution to incorporate the
                                                rule would no longer state that banks,                  how? Should FinCEN add anything to                     results of a risk assessment into the
                                                broker-dealers, and FCMs and IBCs                       further define these terms in the final                other aspects of its AML/CFT program?
                                                must comply with the 31 CFR 1010.610                    rule?                                                  What factors determine this timeframe?
                                                and 1010.620 due diligence                                 4. Should the proposed rule’s                       Risk Assessment Processes (AML/CFT
                                                requirements for foreign correspondent                  distinction between ‘‘establishing’’ and               Priorities) (V.D.1.i.b.)
                                                and private banking accounts.107                        ‘‘maintaining’’ a program be modified?
                                                Additionally, the proposed rule would                   Is the distinction between                                12. What, if any, difficulties do
                                                no longer state that banks must comply                  ‘‘establishing’’ and ‘‘maintaining’’ a                 financial institutions anticipate when
                                                with the regulations of their Federal                   compliance program useful for financial                incorporating the AML/CFT Priorities as
                                                functional regulators. Those regulations                institutions?                                          part of their risk assessment processes?
                                                and requirements apply irrespective of                     5. Is clarification needed for banks to                13. What additional guidance on how
                                                cross-references in the program rules, so               determine what constitutes a                           to incorporate the AML/CFT Priorities
                                                FinCEN is proposing to remove the                       ‘‘significant or systemic failure’’ to                 into a financial institution’s risk
                                                cross-references to streamline the                      implement an effective AML/CFT                         assessment processes would it be useful
                                                program rules and promote consistency.                  program (i.e., a failure to implement, in              for FinCEN to provide?
                                                FinCEN does not intend for these                        all material respects, a properly
                                                changes to have any substantive effect.                 established AML/CFT program)?                          Risk Assessment Processes (Updates)
                                                                                                           6. Is clarification needed for banks to             (V.D.1.i.c.)
                                                VI. Final Rule Effective Date
                                                                                                        determine what constitutes a ‘‘failure to                 14. The proposed rule requires that
                                                  FinCEN is proposing an effective date                 establish an AML/CFT program’’?
                                                of 12 months from the date of issuance                                                                         risk assessment processes are updated
                                                                                                           7. How should the proposed rule                     promptly upon any change that the bank
                                                of the final rule to allow sufficient time              ensure that the regulations issued by
                                                for financial institutions to review and                                                                       knows or has reason to know
                                                                                                        FinCEN and the appropriate Agencies                    significantly changes the bank’s ML/FT
                                                implement the requirements of the                       function harmoniously? How should the
                                                proposed rule. FinCEN solicits comment                                                                         risks. Would the proposed update
                                                                                                        proposed rule differentiate between the                requirement change the way financial
                                                on the proposed effective date.                         Secretary’s responsibility for issuing                 institutions currently update their risk
                                                VII. Request for Comment                                regulations on establishing and                        assessment processes, and if so, how? Is
                                                  FinCEN welcomes comment on all                        maintaining AML/CFT programs and                       additional explanation needed
                                                aspects of the proposed amendments                      the Agencies’ responsibilities for issuing             concerning when a financial institution
                                                and specifically seeks comment on the                   regulations on establishing and                        would be required to update its risk
                                                questions below. FinCEN encourages                      maintaining AML/CFT programs under                     assessment? In particular, how might
                                                commenters to reference specific                        their respective authorities?                          FinCEN clarify how risk assessment
                                                question numbers when responding.                       Internal Policies, Procedures, and                     processes would be updated
                                                An ‘‘Effective’’ AML/CFT Program (V.B.)                 Controls (V.D.1.)                                      ‘‘promptly’’? Would an alternative
                                                                                                           8. Do financial institutions expect any             approach, such as periodic updates or a
                                                   1. The proposed rule sets forth the                                                                         set schedule for updates, be preferable?
                                                conditions for an effective AML/CFT                     changes to their existing internal
                                                                                                        policies, procedures, and controls under               Would an alternative standard, such as
                                                program. Is the description of an                                                                              ‘‘materially changes,’’ be clearer than
                                                effective program sufficiently clear or is              the proposed rule, which requires that
                                                                                                        internal policies, procedures, and                     ‘‘significantly changes’’?
                                                there anything further that FinCEN
                                                                                                        controls be ‘‘risk-based’’ and                            15. How does a financial institution’s
                                                should consider adding in the final rule

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                                                                        ‘‘reasonably designed’’ to ensure                      monitoring for ML/TF risks and its risk
                                                to clarify the concept of program
                                                                                                        compliance with the BSA?                               assessment processes affect one
                                                effectiveness?
                                                                                                                                                               another? Put differently, if there is a
                                                   2. The proposed rule reflects a                      Risk Assessment Processes (Generally)                  feedback loop between the two, please
                                                determination by FinCEN that financial                  (V.D.1.i.)                                             describe it, including the typical
                                                  107 See applicable program rules located at 31          9. The proposed rule refers to risk                  amount of time between discovering
                                                CFR 1020.210(a)(1), (b)(1) (banks); 1023.210(a)         assessment processes rather than a risk                new risks and incorporating those
                                                (broker-dealers); and 1026.210(a) (FCMs and IBCs).      assessment process. This leaves                        findings into risk assessment processes.

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00022   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                                           Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules                                          18725

                                                Independent AML/CFT Program Testing                     required in writing; (b) what form (e.g.,              only to banks and the Federal banking
                                                To Be Conducted by Bank Personnel or                    narrative descriptions, checklists,                    agencies in the proposed rule. FinCEN
                                                by an Outside Party (V.D.2.)                            system configurations, or electronic                   welcomes comment on whether these
                                                   16. Under the proposed rule, a                       records) should such documentation                     provisions should apply to other
                                                financial institution is required to                    take; and (c) what level of detail is                  financial institutions.
                                                conduct independent AML/CFT                             appropriate for each component?                           21. Is further clarification needed for
                                                                                                        Should FinCEN instead eliminate the                    financial institutions to determine what
                                                program testing. This requirement is
                                                                                                        requirement that an AML/CFT program                    constitutes a ‘‘significant or systemic
                                                already reflected in existing AML
                                                                                                        be expressly required to be ‘‘written’’                failure to implement an AML/CFT
                                                program rule requirements 108 as the
                                                                                                        because, among other reasons, financial                program in accordance with
                                                requirement to include ‘‘an independent
                                                                                                        institutions may be subject to other                   § 1020.210(c)’’?
                                                audit function to test programs.’’ 109                                                                            22. Is further clarification needed for
                                                FinCEN solicits comment on how                          applicable recordkeeping and
                                                                                                        documentation requirements? What                       financial institutions to determine what
                                                financial institutions may interpret and                                                                       constitutes a ‘‘failure to establish an
                                                                                                        would be the benefits or drawbacks of
                                                carry out this requirement, based on the                                                                       AML/CFT program in accordance with
                                                                                                        not prescribing a mandatory written
                                                proposed rule’s description of an                                                                              § 1020.210(b)’’?
                                                                                                        requirement in the regulation?
                                                effective AML/CFT program. Are further                     19. The proposed rule would require                    23. The proposed rule refers to
                                                clarifications on the independent AML/                  that a financial institution’s written                 FinCEN’s ‘‘enforcement and supervision
                                                CFT program testing requirement                         AML/CFT program be approved by its                     policy.’’ Does it introduce confusion to
                                                necessary to ensure that audits carried                 board of directors, an equivalent                      label regulatory provisions having the
                                                out by bank personnel or outside third                  governing body, or appropriate senior                  force of law as ‘‘policy’’? If so, how
                                                parties are well-tailored, risk-based, and              management. Should FinCEN further                      should the proposed regulatory
                                                focused on effectiveness?                               clarify which aspects of the AML/CFT                   language be amended to eliminate that
                                                AML/CFT Officer Located in the United                   program must be subject to such                        confusion?
                                                States (V.D.3.)                                         approval? In particular: (a) should                       24. The proposed rule would add a
                                                                                                        approval be required for each of the core              requirement for an Agency to notify and
                                                   17. Under the proposed rule, while                                                                          consider information provided by
                                                                                                        program components (e.g., the risk
                                                the AML/CFT officer must be located in                                                                         FinCEN before initiating a significant
                                                                                                        assessment processes framework;
                                                the United States, personnel located                                                                           AML/CFT supervisory action when
                                                                                                        internal policies, procedures, and
                                                outside of the United States would still                                                                       acting pursuant to authority delegated
                                                                                                        controls; transaction-monitoring and
                                                be permitted to perform certain AML/                                                                           under this chapter. Should the proposed
                                                                                                        escalation frameworks; independent
                                                CFT functions. This language does not                                                                          consultation process include an asset
                                                                                                        testing structure; training program; and
                                                alter existing regulations and guidance                                                                        threshold—e.g., consultation is required
                                                                                                        designation of responsible personnel),
                                                that generally prohibit the sharing of                                                                         for any significant AML/CFT
                                                                                                        or would approval of the overall
                                                SARs with personnel located outside of                                                                         supervisory actions involving banks
                                                                                                        program framework be sufficient; (b)
                                                the United States other than limited                    should material revisions to particular                with $10 billion or more in assets? In
                                                circumstances, such as a bank’s foreign                 components (such as significant changes                addition, or as an alternative, should the
                                                head office or controlling company. Are                 to the institution’s risk assessment                   proposed rule not require but instead
                                                any further clarifications on what duties               methodology, monitoring architecture,                  provide the option for banks to request
                                                personnel outside the United States may                 or governance structure) require re-                   their Agency consult with FinCEN prior
                                                perform needed?                                         approval at the same level; and (c) what               to initiating a significant AML/CFT
                                                Written AML/CFT Program and                             level of specificity should the approving              supervisory action?
                                                Approval (V.E.1)                                        body be required to review and approve                    25. The definition of significant AML/
                                                                                                        (e.g., high-level program architecture                 CFT supervisory action includes the
                                                  18. The proposed rule standardizes                                                                           term ‘‘any written communication.’’ Is
                                                                                                        versus detailed procedures or
                                                the long-standing requirement that an                                                                          the term ‘‘any written communication’’
                                                                                                        parameter-level settings)? Should
                                                AML/CFT program be written. Should                                                                             too broad? Are there negative
                                                                                                        FinCEN instead eliminate the specified
                                                FinCEN further clarify which specific                                                                          consequences to including the term
                                                                                                        approval requirement, allowing
                                                elements of an institution’s AML/CFT                                                                           ‘‘any written communication’’ in the
                                                                                                        financial institutions flexibility in
                                                program must be written, or is this                                                                            proposed regulatory text? If so, please
                                                                                                        determining how leadership oversight of
                                                requirement generally understood in its                                                                        describe. Should the term ‘‘any written
                                                                                                        the AML/CFT program is structured?
                                                current form? In particular: (a) which                                                                         communication’’ be more clearly
                                                                                                        What would be the benefits or
                                                program components—such as risk                                                                                defined or removed altogether?
                                                                                                        drawbacks of not prescribing a
                                                assessment processes; internal policies,                mandatory approval requirement in the                     26. As described above, the purpose
                                                procedures, and controls; transaction                   regulation? If FinCEN does not                         of the FinCEN consultation requirement
                                                monitoring rules and parameters;                        eliminate the specified approval                       is to ensure consistency in BSA/AML
                                                escalation and reporting protocols;                     requirement, should FinCEN consider                    enforcement and supervision across
                                                independent testing results; training                   amending the requirement? Are there                    banks, and for FinCEN to provide
                                                materials; and documentation of                         alternatives to board of directors, an                 relevant information on the
                                                designated personnel—should be                          equivalent governing body, or                          effectiveness and impact of an
                                                                                                        appropriate senior management that                     institution’s AML/CFT program. While
                                                   108 See 31 CFR 1020.210(a)(2)(ii), (b)(2)(ii)

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                                                                        would be more appropriate?                             Treasury, FinCEN, and the Agencies
                                                (banks); 1021.210(b)(2)(ii) (casinos); 1022.210(d)(4)
                                                (MSBs); 1023.210(b)(2) (broker-dealers);                                                                       believe the benefits of a required
                                                1024.210(b)(2) (mutual funds); 1025.210(b)(4)
                                                                                                        Supervision and Enforcement (V.F.)                     consultation process outweigh the costs,
                                                (insurance companies); 1026.210(b)(2) (FCMs and           20. The proposed rule would add a                    the parties recognize this adds
                                                IBCs); 1027.210(b)(4) (DPMSJs); 1028.210(b)(4)          new § 1020.221 to set forth a                          additional layers of review for financial
                                                (operators of a credit card system); 1029.210(b)(4)
                                                (loan or finance companies); 1030.210(b)(4)             supervision and enforcement framework                  institutions and the Agencies during an
                                                (housing GSEs).                                         for banks. The new supervision and                     examination. Are there any avenues,
                                                   109 31 U.S.C. 5318(h)(1)(D).                         enforcement requirements would apply                   communication channels, or methods in

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00023   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                18726                     Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules

                                                which FinCEN and the Agencies can                       should include a statement identifying                 rule may have a significant economic
                                                streamline the consultation process and                 that the rule or proposed rule is a                    impact on a substantial number of
                                                prevent logistical burdens for financial                criminal regulatory offense and the                    certain types of affected small
                                                institutions or delays in exam report                   authorizing statute.110 E.O. 14294                     entities.117 Pursuant to analysis required
                                                issuance?                                               directs agencies to draft this statement               by UMRA, FinCEN concludes it
                                                   27. Is the definition of the term                    in consultation with the Department of                 unlikely that the proposed rule, if
                                                ‘‘significant AML/CFT supervisory                       Justice.                                               implemented, would result in a novel
                                                action’’ sufficiently clear? Does the                     E.O. 14294 further directs that the                  annual expenditure of more than $193
                                                inclusion of ‘‘unsafe or unsound                        regulatory text of all NPRMs and final                 million by State, local, and Tribal
                                                practices or conditions’’ introduce                     rules with criminal consequences                       governments or by the private sector.118
                                                confusion about what types of                           published in the Federal Register after                While the PRA analysis included in this
                                                supervisory actions would be subject to                 May 9, 2025, should explicitly state a                 NPRM introduces certain new pro forma
                                                the FinCEN consultation requirement,                    mens rea requirement for each element                  accounting estimates to the existing
                                                since those terms are not found in the                  of a criminal regulatory offense,                      Office of Management and Budget
                                                BSA?                                                    accompanied by citations to the relevant               (OMB) control numbers covered by the
                                                   28. FinCEN welcomes comment on                       provisions of the authorizing statute.                 rulemaking, these burdens and costs
                                                provisions related to the use of                          Willful violations of the regulations                largely reflect administrative updates
                                                innovative tools to achieve effective                   set forth in this proposed rule may be                 that are being introduced to more
                                                outcomes, specifically on how the                       subject to criminal penalties pursuant to              accurately represent the activity
                                                Director may consider the performance                   31 U.S.C. 5322 and regulations                         currently undertaken by covered
                                                of innovative activities that produce                   promulgated 31 CFR chapter X. The                      financial institutions to comply with
                                                demonstrable outputs under the                          statutory authority for criminal liability             existing program requirements
                                                proposed supervision and enforcement                    requires a mens rea of willfulness as an               unchanged by the proposed rule. The
                                                framework.                                              element under 31 U.S.C. 5322(a) and 31                 aggregate PRA estimates do not
                                                                                                        U.S.C. 5322(b). FinCEN’s existing                      represent, and should not be interpreted
                                                Final Rule Effective Date (VI.)                         regulation, 31 CFR 1010.840, that sets                 to reflect, novel incremental costs
                                                   29. FinCEN is proposing an effective                 out criminal penalties for violations of               attributable to the proposed rule.119
                                                date of 12 months from the date of                      regulations promulgated in 31 CFR                         In its totality, FinCEN’s regulatory
                                                issuance of the final rule to allow                     chapter X also includes a mens rea of                  impact analysis (RIA) anticipates that
                                                sufficient time for financial institutions              willfulness. In drafting this statement,               the primary aggregate economic effects
                                                to review and implement its                             FinCEN has consulted with the                          of the proposed rule would be
                                                requirements. FinCEN solicits comment                   Department of Justice.                                 reallocative insofar as the requirement
                                                on the proposed effective date.                         X. Regulatory Impact Analysis                          for programs to support law
                                                VIII. Severability                                                                                             enforcement and national security and
                                                                                                           FinCEN has analyzed the proposed
                                                                                                                                                               advance AML/CFT Priorities remains
                                                   As a part of this proposal, FinCEN                   rule as required under E.O. 12866,111
                                                                                                                                                               unchanged. Thus, while total
                                                proposes that if one portion of the                     E.O. 13563,112 E.O. 14192,113 the
                                                                                                                                                               expenditures on program compliance
                                                proposed rule, if finalized, is found to                Regulatory Flexibility Act (RFA),114 the
                                                                                                                                                               may not be reduced, the distribution of
                                                be invalid, the invalidated portion of the              Unfunded Mandates Reform Act of 1995
                                                                                                                                                               which financial institutions incur costs
                                                regulation should be severed with the                   (UMRA),115 and the Paperwork
                                                                                                        Reduction Act (PRA).116                                and what they expended those resources
                                                other portions of the proposed rule, as
                                                                                                           This proposed rule has been                         on would be expected to change
                                                well as the existing FinCEN regulations
                                                                                                        determined to be a ‘‘significant                       responsively to the incentives
                                                for each type of financial institution in
                                                                                                        regulatory action’’ under section 3(f)(1)              introduced by the proposed rule that
                                                chapter X, remaining in full force and
                                                                                                        of E.O. 12866, as it may have an annual                better align institutions’ attention and
                                                effect. FinCEN’s position is that
                                                                                                        effect on the economy of $100 million                  activities with its unique ML/TF risks.
                                                invalidation of any one provision, or
                                                                                                        or more. FinCEN has included an Initial                While aggregate costs would not be
                                                application thereof to any one person or
                                                                                                        Regulatory Flexibility Analysis (IRFA)                 expected to decrease, FinCEN’s analysis
                                                circumstance, does not, and should not,
                                                affect any other provision in this                      pursuant to the RFA as the proposed
                                                                                                                                                                  117 This economic expectation is sensitive to key
                                                proposed regulation or existing                                                                                assumptions about how potentially affected
                                                                                                          110 E.O. 14294, Fighting Overcriminalization in
                                                regulations under chapter X. Each                                                                              financial institutions would respond to the
                                                                                                        Federal Regulations, 90 FR 20367 (issued May 9,        proposed requirements. FinCEN requests comment
                                                provision serves an important, related,                 2025; published May 14, 2025).                         on whether it would instead be more reasonable to
                                                but distinct purpose and application,                      111 E.O. 12866, Regulatory Planning and Review,
                                                                                                                                                               certify that the proposed rule would not have a
                                                designed to benefit the public by                       58 FR 51735 (issued Sept. 30, 1993; published Oct.     significant economic impact on a substantial
                                                protecting the U.S. financial system                    4, 1993).                                              number of small entities. See infra section X.F #16.
                                                                                                           112 E.O. 13563, Improving Regulation and
                                                from illicit financial activity. FinCEN                 Regulatory Review, 76 FR 3821 (issued Jan. 18,
                                                                                                                                                                  118 The UMRA requires an assessment of

                                                accordingly has proposed to incorporate                                                                        mandates with an annual expenditure of $100
                                                                                                        2011; published Jan. 21, 2011).                        million or more, adjusted for inflation. 2 U.S.C.
                                                this position into the respective rules for                113 See E.O. 14192, Unleashing Prosperity
                                                                                                                                                               1532(a). FinCEN has not anticipated material
                                                each type of financial institution, such                Through Deregulation, 90 FR 9065 (issued Jan. 31,      changes in expenditures for State, local, and Tribal
                                                that invalidity to one provision would                  2025; published Feb. 6, 2025); Office of               governments, insofar as they would not participate
                                                                                                        Management and Budget, Guidance Implementing           in the primary activities of monitoring or enforcing
                                                not undermine the operability or                        Section 3 of Executive Order 14192, Titled             compliance of the newly proposed requirements in

lotter on DSK8BHNXB4PROD with PROPOSALS4
                                                usefulness of the other provisions.                     ‘‘Unleashing Prosperity Through Deregulation,’’ M–     a way that differs from current involvement,
                                                                                                        25–20 (Mar. 26, 2025), https://www.whitehouse.gov/     thereby incurring novel incremental costs. But
                                                IX. E.O. 14294                                          wp-content/uploads/2025/02/M-25-20-Guidance-           because the proposed rule would affect entities in
                                                  Section 5 of E.O. 14294 directs that all              Implementing-Section-3-of-Executive-Order-14192-       the private sector that are covered financial
                                                                                                        Titled-Unleashing-Prosperity-Through-                  institutions, FinCEN has considered expenditures
                                                future notices of proposed rulemaking                   Deregulation.pdf.                                      these private entities may incur, pursuant to
                                                and final rules published in the Federal                   114 5 U.S.C. 601 et seq.
                                                                                                                                                               UMRA, as part of the regulatory impact in its
                                                Register, the violation of which may                       115 2 U.S.C. 1532.                                  assessment below.
                                                constitute criminal regulatory offenses,                   116 44 U.S.C. 3501 et seq.                             119 See infra section X.E.

                                           VerDate Sep<11>2014   19:54 Apr 09, 2026   Jkt 268001   PO 00000   Frm 00024   Fmt 4701   Sfmt 4702   E:\FR\FM\10APP4.SGM   10APP4
                                                                           Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules                                                      18727

                                                concludes that they would also not be                   14192; 123 the RFA; 124 the UMRA; 125                    because at best this activity would
                                                expected to increase, and because the