Regulatory updates often bring a wave of questions: What changed? How will it affect us? And how much time do we have to prepare?
Those questions are especially relevant as financial institutions evaluate FinCEN’s proposed Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) rule. The proposal, which closed for public comment on June 9, 2026, has the potential to reshape how banks and credit unions design, manage, and evaluate their compliance programs.
At its core, the proposal reflects a broader shift in regulatory expectations. Financial institutions are increasingly expected to show how their AML/CFT programs identify, manage, and mitigate risk in a meaningful way, with greater focus on outcomes, governance, and risk-based decision-making.
A New Emphasis on Program Effectiveness
For many institutions, AML programs have historically centered around maintaining required policies, procedures, training, and testing activities. Those components remain important, but FinCEN’s proposal places greater attention on how well a program performs in practice.
Regulators appear to be moving toward a framework where institutions can demonstrate that controls are aligned with real-world risks and that compliance efforts are driving measurable results. This approach encourages organizations to take a closer look at the effectiveness of their monitoring, investigations, governance, and resource deployment.
Expanding the Focus to Include CFT
A notable aspect of the proposal is the formal integration of Countering the Financing of Terrorism (CFT) into AML programs.
While many institutions already consider terrorist financing risks as part of their overall compliance efforts, the proposal reinforces the expectation that these risks be incorporated into the broader AML/CFT framework. Bringing these areas together supports a more comprehensive view of financial crime risk and encourages institutions to evaluate threats through a wider lens.
Why the Risk Assessment Matters More Than Ever
One of the most significant elements of the proposal is the increased importance of the AML/CFT risk assessment.
The risk assessment serves as the foundation for many program decisions, from monitoring and reporting activities to staffing and governance. Under the proposed framework, institutions would need to maintain a documented and ongoing assessment that reflects their products, services, customers, delivery channels, and geographic exposure.
A well-developed risk assessment can help leadership make informed decisions about where to focus resources, how to prioritize compliance activities, and which risks warrant the greatest attention.
Steps Institutions Can Take Today
Although the rule has not been finalized, financial institutions have an opportunity to begin evaluating potential impacts.
Review Your Risk Assessment
Start by evaluating whether your current BSA/AML risk assessment adequately addresses both money laundering and terrorist financing risks. Consider whether it reflects the institution’s current operations, customer base, and emerging threats.
Assess the National AML/CFT Priorities
FinCEN’s eight National AML/CFT Priorities are expected to play an important role in the future framework. Institutions should evaluate each priority and document its relevance to their organization, along with any associated controls or monitoring efforts.
Examine Governance and Oversight
Board reporting, management oversight, and AML/CFT officer responsibilities deserve careful review. Strong governance helps ensure that decision-makers receive meaningful information about risks and can respond appropriately as those risks evolve.
Reevaluate Independent Testing
Testing programs may need to evolve alongside regulatory expectations. Institutions should consider whether audits and independent reviews provide insight into program performance and risk management effectiveness, in addition to evaluating procedural compliance.
Align Resources to Risk
The proposal reinforces the importance of risk-based resource allocation. Higher-risk products, services, customer segments, or activities should receive appropriate attention and support, while lower-risk areas may warrant a different level of focus.
Consider Technology Enhancements
Many institutions are exploring technology solutions to strengthen monitoring, investigations, analytics, and reporting capabilities. As compliance expectations continue to evolve, technology can play an important role in improving visibility into risk and supporting more efficient program management.
Looking Ahead
While the final contours of FinCEN’s AML/CFT rule remain to be seen, the direction is becoming increasingly clear. Risk assessments, governance, and program effectiveness are taking on a more prominent role in regulatory expectations.
To prepare for these future changes, financial institutions should begin evaluating these areas today. Beyond regulatory readiness, these efforts can help organizations build a deeper understanding of their risks and enhance their overall approach to financial crime prevention.
If you have any questions or are interested in learning more, we are here to help. Please do not hesitate to reach out to discuss your specific situation.
This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for tax, legal, or accounting advice. Should you require such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.