
On April 7, 2026, FinCEN released a proposed rule that will eventually lead to a (hopefully) different approach to the way AML compliance programs are critiqued by federal and state regulators. The comment period on the rule ends in June 2026 and the final rule would take effect 12 months after publication (April 2027).
As we have noted in previous blogs, the NPRM that will take effect directs examiners to use a different evaluation approach when considering an AML program. There is a two-pronged review that ultimately results in a determination about the overall effectiveness of the AML compliance program
The two prongs of the evaluation are whether the program is:
- Established
- Maintained
An established program is one that contains all of the pillars (e.g. internal controls, training, monitoring, etc.). An AML/CFT program is deemed “maintained” when it is successfully implemented in all material respects. This means a financial institution must actively execute its established policies, procedures, and controls in day-to-day operations rather than just having them written on paper. And while this might seem like a statement of the obvious, there have been myriad cases where the written program of an institution in no way resembles what the actual practices of the company.
According to the proposed AML evaluation described in the NPRM, A compliant, maintained program focuses on three core areas:
- Daily Implementation: Day-to-day operations align exactly with the framework established during the design phase. This means that only practices have be consistent and that staff need to understand why there are limitations and rules in in place.
- Resource Allocation: Resources, controls, and transaction monitoring actively target and mitigate the institution’s highest money laundering and terrorist financing (ML/TF) risks. This means that software should be employed to track transactions that have been determined to be out of the ordinary pattern, including large transactions or aggregated transactions that don’t match expectations.
- Regulatory Exemption: While “minor deficiencies” do not mean an institution has failed to maintain its program, systemic failures (like gaps in monitoring that miss high risks, or data-related issues) will constitute a material failure. This is the area where the examination team will still have the most discretion. In determining whether a program is fully implemented, they will be looking for wholesale “gaps” in the ability to monitor for unusual activity. If 50 new accounts are reviewed and two had an expired license, no enforcement action is likely. However, if, during the review, the examiner notes that the company regularly doesn’t ask for government identification, enforcement action is likely.
- Execution over Paperwork: It is not enough to simply have written policies; an organization must actively enforce them in its daily operations. It is likely that the regulator’s expectation will be that management can document ongoing testing to ensure that staff fully understand rules that are in place.
- Tolerance for Minor Flaws: Regulators and auditors acknowledge that no system is perfect. Isolated errors or minor gaps do not mean a company has failed its program, if the foundation functions as intended. In other words, if the institution can document that on a regular basis, they are checking for complete documentation, that ongoing monitoring is taking place, etc., then individual findings won’t blow up an examination.
- Materiality Threshold: A failure “in all material respects” occurs when deficiencies are large or systemic enough to compromise the program’s primary objective (e.g., preventing money laundering or securing customer data). This means that the program must be effective in terms of identifying and reporting unusual or suspicious activity
Why the Distinction Matters
Historically, regulators primarily evaluated whether a program was designed correctly. Under the NPRM, regulators are instructed to focus heavily on outcomes.
While minor technical deficiencies do not necessarily mean an institution has failed to “maintain” its program, systemic data-related issues, chronic alert fatigue, or massive control weaknesses that have a material impact on mitigating money laundering and terrorist financing risks will be flagged as failures.
Maintaining an effective compliance program will senior management to consider the following:
Dynamic Risk Assessments
- Evaluate Risks: Continuously analyze money laundering and terrorist financing risks specific to your products, services, customers, and geographic locations.
- Adaptability: Update your assessment promptly whenever your risk profile changes (e.g., launching new products or entering new markets).
- Priorities: Incorporate current AML/CFT Priorities published by governing bodies (such as FinCEN’s AML/CFT Priorities).
Tailored Policies, Procedures & Controls
- Risk-Based Approach: Ensure that your controls heavily scrutinize high-risk areas rather than applying blanket scrutiny to all transactions.
- Customer Due Diligence (CDD): Maintain ongoing procedures to verify customer identity, understand the nature of their business, and spot suspicious behavior. This is where building a base case for clients of your institution can documenta basis for al of the monitoring and risk allocation that you do.
- Recordkeeping: Retain all compliance-related records, risk assessments, and reporting logs as mandated by your local regulatory requirements.
Employee Training
- Continuous Education: Provide regular, role-based training to keep employees updated on the latest financial crime red flags and internal reporting procedures. Under this new regulatory approach, training becomes a critical component of the compliance program. Documentation of training performed will be strong documentation maintenance.
- Documentation: Track employee participation and comprehension to maintain a strong internal culture of compliance.
Independent Testing
- Routine Audits: Schedule periodic independent testing (e.g., every 12 to 18 months) or when your risk profile changes significantly.
- Scoping: Management should work directly with audit firm sto develop customized scopes that match the findings of the risk assessment. In addition, areas of perceived weakness should be covered.
- Deficiency Remediation: Use audit results to identify gaps in your assessment processes and implement corrective measures.
***For More Information, please visit http://www.VCM4you.com ***