On April 7, 2026, FinCEN released a proposed rule that will eventually lead to a (hopefully) different approach to the way AML compliance programs are critiqued by federal and state regulators.   The comment period on the rule ends in June 2026 and the final rule would take effect 12 months after publication (April 2027).  

In the edition of this blog series noted that programs will need to be “established” and “maintained”.  As with all federal pronouncements, these words are definitions with significant meaning.  

Fully Established

Under the new evaluation guidelines, a program must be fully established. Specifically, fully established means that: 

  • Established Internal Controls– including a risk assessment and written policies and procedures have been established The program must include a risk-based set of policies, procedures, and controls that are reasonably designed to identify, assess, and mitigate illicit finance risks FDIC
    • Compliance Officer– The program has a U.S.-based, accessible compliance officer designated under the AML Act, who is responsible for establishing and implementing the program FDIC.
    • Independent Testing – Has an independent testing function to verify program effectiveness FDIC.
    • Training– Has an employee training program to ensure staff awareness and capability

This doesn’t simply mean writing policies and procedures using a basic cut and paste. Instead, the written policies and procedures must inculcate the results of the risk assessment.  In addition to stating the legal requirements that the policy is designed to meet, there should also be a discussion of the inherent risks of running the business that have been identified. 

The written policy should state the risks present and identify the internal controls that have been established to mitigate.   So, for example, if the risk that customers will mis-identify themselves (as is often the case in a High Financial Crimes “HIFCA” area), the policy should reflect that there are strict CIP processes in place that must be followed under penalty of termination of employment.   

The risk assessment process will drive the entire AML CFT program under the new evaluation program.  As we previously noted, the risk assessment process was a best practice, but will be required when the new rules take place. 

In the past, it was likely that the risk assessment process was seen as an exercise specifically for the purpose of meeting a regulatory requirement.  In many cases, these assessments were completed and put away without being looked at until it is time to do an annual update.  But there is another way to view the process.  Instead, it is an excellent idea to look at the following at a minimum:

  • The areas where there have been regulatory or internal audit findings in the past
  • The types of products that your company offers, and the risks associated with those products
  • The regulatory environment in the geographic area served (i.e. are you in a HIDTA or HIFCA)
  • New products that are being contemplated
  • The management reports that are currently being generated by software
  • Changes in regulations that might affect operations
  • Changes in staff that have occurred or are planned. 

Use the Risk Assessment as a Resource

Once the assessment is complete, the goal of the new rule is to make sure that its conclusions are being put to use. For example:

Scoping of audits: The assessment can and should be used to help with planning and scoping audits that are to be performed during the year.  The areas of the highest risk should be addressed early and should have the most extensive scope. 

Ongoing Monitoring– The use of monitoring and reporting software should be directly tied to your risk assessment.  The regulators have issued guidance that requires a direct link between your risk assessments and software use. [1]

Training– Rather than setting a basic training schedule, use the assessment to make sure that classes are focused on areas where the potential for findings and violations occur. 

AML/CFT Priorities– The AML Act mandates that FinCEN establish public government-wide AML/CFT Priorities and issue regulations incorporating the AML/CFT Priorities into revised program requirements.  The NPRM proposes requiring financial institutions to review these AML/CFT Priorities and, as appropriate, incorporate them into their risk assessment processes.

The goal of the risk assessment should be to build a “base-case” for customers.  The base case- is the level and type of activity that is expected from a typical customer.  For those customers and products that fall outside of the base case, the higher the risk, the more resource s should be dedicated.  

Evaluation of the Regulators

According to the NPRM, the examiners have been given direction on how to evaluate the establishment of an AML compliance program:

  • Policies and procedures – must be reasonably designed to identify, assess, and document ML/TF risks.  Emphasis on the risk assessment
  • Independent Testing – Be based on objective criteria designed to assess whether the institution has effectively established, implemented, and resourced its AML/CFT program consistent with its risk assessment processes
    • Assess compliance with BSA requirements
    • Focus on program effectiveness — not merely process adherence
    • Be conducted by individuals or parties who are truly independent of the AML/CFT function
    • Avoid conflicts of interest
  • US Based Compliance Officer – financial institutions must designate a person responsible for establishing, implementing, and overseeing day-to-day compliance with BSA requirements — designated the “AML/CFT Officer.”
  • Training – Training should reflect the institution’s internal controls, risk assessment results, and current regulatory requirements, with frequency and content tailored to the institution’s risk profile and the specific roles of the personnel being trained.

Implications   

Under the new rule, an established program must have documented all of the pillars, be based upon the risk assessment of the company and must incorporate the AML/CFT priorities.  Further, the expectation is that resources are distributed most heavily  into the highest areas of risk. 

***For More Information on aligning your Compliance Department with risk, please visit www.VCM4you.com ***


[1] The OCC and the Federal Reserve issued guidance in 2011 titled “Supervisory Guidance on Model Risk Management”.