FinCEN’s AML Overhaul: Why Boards Must Prove Effectiveness, Not Just Compliance

Bank board and audit committee reviewing AML program documentation under FinCEN's new effectiveness standard

FinCEN’s April 2026 proposal reduces prescriptive requirements while increasing the evidentiary burden on boards, audit committees, and testing functions. The question is no longer whether the AML/CFT program exists, but whether the record behind its risk-based judgments holds.

Executive Summary

When the test shifts from presence to effectiveness, an institution no longer demonstrates compliance by showing that each required element exists. It demonstrates compliance by showing that its judgments were risk-based, documented, approved, and independently tested. That makes the proposal an assurance issue before it becomes a compliance issue.

On April 7, 2026, FinCEN proposed reforms to the AML/CFT program requirements that financial institutions have operated under for two decades. The same day, the OCC, FDIC, and NCUA issued a joint conforming proposal, and the Federal Reserve followed on July 7, 2026 [1][2][5][9]. The headline is burden reduction. The consequence for boards and audit committees is increased evidentiary responsibility.

The rule is not final, and the text may change. The direction is unlikely to: with FinCEN and the federal banking regulators advancing the same framework, institutions should expect an effectiveness standard regardless of charter type [5][9]. Boards, audit committees, and testing functions should begin now by strengthening the records that will matter most: risk assessment judgments, design approvals, testing criteria, de-prioritization decisions, and governance of new technology.


Key Takeaways

  • The standard shifts from presence to performance. Today’s rules ask whether the program contains the required elements. Under the proposal, effectiveness turns on whether the program is properly established and maintained in all material respects [3][7].
  • Establishment and maintenance become separate evidentiary records. Once a program is properly established, significant supervisory or enforcement action would require a material or systemic implementation failure, not isolated defects. Institutions that cannot demonstrate proper establishment never reach that higher threshold [2][3][5].
  • The limit on subjective judgment applies to auditors, not only to examiners. Independent testing would assess establishment and maintenance against objective criteria rather than second-guessing the institution’s design decisions [2][4]. Every finding should cite the regulatory requirement, approved policy, or professional standard on which it is based.
  • The risk assessment serves as the load-bearing record. It must evaluate illicit finance risk, incorporate FinCEN’s AML/CFT Priorities as appropriate, and be updated as the institution’s risk profile changes [2][13]. Because the institution controls the design, scope, and frequency, it must also be able to defend those choices.
  • Responsible experimentation is protected, but only when governed. The proposal encourages innovative technology within a well-designed program and protects responsible experimentation from additional enforcement risk [3][4]. That protection depends on documented validation, approval of tuning changes, and human review of automated decisions.
  • Supervision is being recentralized at FinCEN. For the first time, the OCC, FDIC, and NCUA would notify and consult FinCEN before certain significant AML-related supervisory or enforcement actions [3][4][5]. The change aims to reduce inconsistent examiner expectations across charters.

From Presence to Performance

BSA compliance has long posed a structural question: Does the institution have written policies and controls, independent testing, a designated compliance officer, and ongoing training? The proposal retains all four components, adds an explicit risk assessment process and the customer due diligence obligation, and changes what the institution must prove. A program would be deemed effective if it is established in accordance with the rule and maintained in all material respects [5][7].

Effectiveness does not mean flawless. It means risk-based, reasonably designed, calibrated to the institution’s actual risk profile, and capable of producing information useful to law enforcement and national security agencies [1][3]. Treasury has been blunt about the intent. “For too long, Washington has asked financial institutions to measure success by the volume of paperwork rather than their ability to stop illicit finance threats,” Secretary of the Treasury Scott Bessent said when announcing the proposal [4]. Under a checklist standard, the artifact is the checklist. Under an effectiveness standard, the artifact is the record of judgment: why this threshold, who approved it, and what evidence supported the decision at the time it was made.

Two Prongs, Two Records, One Gate

The most consequential structural change is the separation of establishment from maintenance, which produces two records rather than one. Whether an institution properly built its program, including the risk assessment process, the core components, and a U.S.-based compliance officer accessible to regulators, would be evaluated separately from whether that program is being maintained [2][7][8]. Establishment is not a lowered bar. It is the gate.

Once establishment is satisfied, regulators could bring significant supervisory or enforcement actions only for the most serious implementation deficiencies. Isolated or technical shortfalls, standing alone, would not clear that bar [3][5]. But management, not the examiner, bears the burden of showing that the design was sound. Independent testing therefore needs to answer two questions separately for the audit committee: was the program built correctly, and is it being maintained in all material respects? Most audit programs blend those questions into a single conclusion, obscuring the very distinction supervisors will apply.

The asymmetry runs the other way as well. An institution that cannot demonstrate proper establishment never reaches the higher threshold because the protection attaches only after the design prong is satisfied [2][3][5]. Without that establishment record, even isolated or technical maintenance issues are harder to defend.

The Line Drawn Around Examiners Runs Through Internal Audit

The provision drawing the most industry attention would clarify expectations for program functions, including independent testing and auditing, so examiners and auditors do not substitute subjective judgment for a risk-based, reasonably designed program [2][4]. Institutions have welcomed the limit on examiners. Fewer have absorbed that the same clause names auditors in the same breath. The proposed framework directs testing functions to measure establishment and maintenance against objective criteria rather than to challenge the underlying design.

This is not a reduction in internal audit’s role. It is a re-specification of that role, consistent with existing standards. The FFIEC manual requires independent testing to be risk-based, to evaluate the risk assessment itself, to reach an explicit conclusion on overall program adequacy, and to report to the board [10]. The Institute of Internal Auditors’ Global Internal Audit Standards, effective January 9, 2025, require conclusions supported by sufficient, reliable, and relevant evidence, and the IIA has long defined internal audit’s BSA/AML responsibilities [11][12].

Objective criteria have a working definition: a regulatory requirement, an approved internal policy, or a recognized professional standard. A finding that cannot identify one of the three is a preference. An observation grounded in criteria will hold. One grounded in auditor preference will be contested by management and, increasingly, by the proposed rule itself [2][11][12].

Flexibility Transfers the Burden

The proposal would require a risk assessment process that comprehensively evaluates illicit finance risk, incorporates the national AML/CFT Priorities published in June 2021 as appropriate, and is updated as the institution’s risk profile changes [2][6][13]. Compared with the withdrawn 2024 proposal, the expectations would be notably more flexible, allowing the institution to determine design, scope, and frequency [2][4].

That flexibility does not remove work. It relocates it, moving it out of the regulator’s rulebook and into the institution’s own file. When the regulator stops prescribing cadence and scope, those choices stop being compliance steps and become management conclusions. A conclusion is only as good as the evidence a third party can follow. The same logic governs where attention is spent. The proposal’s stated aim is to refocus programs on higher-risk activity, and directing more attention toward higher-risk customers and activities necessarily means directing less elsewhere [3][4][8]. The decision to deprioritize is where the file has to be strongest, showing the analysis performed, the residual risk accepted, the officer who approved it, and the trigger that would reopen the question.

For audit committees, this raises a direct oversight question. If the risk assessment sets its own cadence and scope, independent testing has to conclude whether that cadence and scope were reasonable for the institution’s risk profile, not merely whether the assessment was completed on schedule [10].

Innovation Without a Penalty Is Not Innovation Without Governance

FinCEN also addressed a question that has quietly stalled modernization at community institutions: how much supervisory risk is associated with trying something new. The proposal would encourage the use of innovative technology within a reasonably designed program and would provide that institutions that responsibly experiment do not incur additional enforcement risk [3][4]. For banks and credit unions that have deferred monitoring upgrades or AI-assisted alert triage out of examination anxiety, that is a meaningful signal.

The protection extends to the decision to experiment, not to the results of the experiment. A tool that fails to identify activity it should have can still create a program deficiency, especially if the institution relied on it without adequate validation or controls. What the proposal removes is the separate penalty for having tried [3][4].

The operative word is responsibly, and it sets a documentation standard rather than a technology one. Before the institution relies on a tool, the validation should be on file. Each tuning change should include the hypothesis behind it and the approver’s name. Wherever the system closes an alert without human intervention, the record should show who reviewed that pattern and when. Experimentation that is governed is protected. Undocumented experimentation is simply an unexamined control.

The Supervisory Map Is Being Redrawn

Everything to this point concerns what an institution must prove. This part of the reform concerns who evaluates that proof. For the first time, the OCC, FDIC, and NCUA would notify and consult FinCEN before certain significant AML-related supervisory or enforcement actions, with the AML/CFT Priorities factored into that consideration [2][3][5]. That does not strip the agencies of authority. It gives the administrator of the BSA a formal seat before major actions proceed, which is the most direct answer yet to a decade of complaints about divergent examiner expectations across charters.

Coverage is converging as well. The Federal Reserve did not join the April proposal, but on July 7, 2026, the Board proposed conforming amendments to Regulation H [9]. That matters because it removes the last practical basis for assuming the effectiveness standard will apply unevenly across federal banking regulators. For Board-supervised institutions, the program framework is moving into alignment with the April proposals on effectiveness, establishment, and maintenance, even though the Federal Reserve proposal does not itself adopt the same FinCEN consultation framework.

What Boards and Audit Committees Should Do Before a Final Rule Boards and audit committees need not wait for a final rule to begin. Each step below strengthens the record the institution will need under any effectiveness standard. These items belong in the 2027 audit plan, and the groundwork should be completed over the next two quarters.

  1. Separate the establishment conclusion from the maintenance conclusion. Restructure the independent testing report so the audit committee can assess whether the program was properly designed and whether it is being maintained in all material respects [5][10].
  2. Re-baseline the risk assessment as a decision record. Confirm that it evaluates products, services, channels, customers, and geographies; addresses the AML/CFT Priorities; and shows what changed in staffing, thresholds, and monitoring as a result [2][13].
  3. Document de-prioritization as carefully as escalation. Decide which officer signs off on reduced scrutiny, when the decision must reach the audit committee rather than remain with management, and how often open de-prioritization decisions are re-presented for review [4][8].
  4. Rewrite audit findings to meet objective criteria. For each open BSA finding, ask whether it cites a regulatory requirement, an approved internal policy, or a recognized professional standard. Findings based on preference will not survive [11][12].
  5. Set the evidentiary bar for new tools before selection. If the institution is considering a monitoring upgrade or AI-assisted alert triage, agree now on what validation must be on file before reliance, who approves each tuning change, and how automated dispositions are sampled for human review [3][4].

The proposal does not reduce the compliance obligation. It changes what institutions must be prepared to demonstrate. For twenty years, institutions have shown compliance through evidence of activity. Under an effectiveness standard, they will demonstrate it through evidence of judgment, governance, and the quality of the independent testing behind it. The comment window will close well before a final rule is issued, but the documentation discipline this framework rewards will take longer to build. Boards and audit committees should begin that work now.

About the Author

Ryan McAbee is the BSA Practice Director at AuditOne, where he leads independent BSA/AML program testing and automated AML system validation for community banks, credit unions, and their fintech partners nationwide. He works with boards and BSA officers on the questions this proposal raises: whether a risk assessment truly drives decisions and whether the record supporting those decisions would withstand examination.

References

  1. Financial Crimes Enforcement Network. Anti-Money Laundering and Countering the Financing of Terrorism Programs. Notice of Proposed Rulemaking, 91 FR 18704, April 10, 2026. RIN 1506-AB72, Docket FINCEN-2026-0034. https://www.federalregister.gov/documents/2026/04/10/2026-07033/anti-money-laundering-and-countering-the-financing-of-terrorism-programs
  2. Financial Crimes Enforcement Network. Fact Sheet: Proposed Rule to Fundamentally Reform Financial Institution AML/CFT Programs. April 7, 2026. https://www.fincen.gov/system/files/2026-04/Program-NPRM-FactSheet.pdf
  3. Financial Crimes Enforcement Network. Key Changes in FinCEN’s Proposed Rule to Refocus AML/CFT Programs on Higher-Risk Activity While Reducing Unnecessary Burden. April 7, 2026. https://www.fincen.gov/system/files/2026-04/Key-Changes-Program-NPRM.pdf
  4. Financial Crimes Enforcement Network. FinCEN Proposes Rule to Fundamentally Reform Financial Institution Programs Designed to Fight Illicit Finance. News release, April 7, 2026. https://www.fincen.gov/news/news-releases/fincen-proposes-rule-fundamentally-reform-financial-institution-programs
  5. Office of the Comptroller of the Currency, Federal Deposit Insurance Corporation, and National Credit Union Administration. Anti-Money Laundering and Countering the Financing of Terrorism Programs. Joint Notice of Proposed Rulemaking, 91 FR 18304, April 10, 2026. https://www.federalregister.gov/documents/2026/04/10/2026-06948/anti-money-laundering-and-countering-the-financing-of-terrorism-programs
  6. Office of the Comptroller of the Currency. Anti-Money Laundering and Countering the Financing of Terrorism Program Requirements: Notice of Proposed Rulemaking. OCC Bulletin 2026-11, April 7, 2026. https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-11.html
  7. Federal Deposit Insurance Corporation. Issuance of a New AML/CFT Program Requirements Notice of Proposed Rulemaking. Financial Institution Letter, April 7, 2026. https://www.fdic.gov/news/financial-institution-letters/2026/issuance-new-anti-money-laundering-amlcountering-financing
  8. National Credit Union Administration. Agencies Request Comment on Anti-Money Laundering/Countering the Financing of Terrorism Proposed Rule. April 7, 2026. https://ncua.gov/newsroom/press-release/2026/agencies-request-comment-anti-money-laundering-countering-financing-terrorism-proposed-rule
  9. Board of Governors of the Federal Reserve System. Anti-Money Laundering and Countering the Financing of Terrorism Programs. Notice of Proposed Rulemaking, 91 FR 42363, July 9, 2026. Docket No. R-1835, RIN 7100-AG78. https://www.federalregister.gov/documents/2026/07/09/2026-13919/anti-money-laundering-and-countering-the-financing-of-terrorism-programs
  10. Federal Financial Institutions Examination Council. BSA/AML Examination Manual, BSA/AML Independent Testing (April 2020). https://bsaaml.ffiec.gov/manual/AssessingTheBSAAMLComplianceProgram/03
  11. The Institute of Internal Auditors. Global Internal Audit Standards. Issued January 9, 2024; effective January 9, 2025. https://www.theiia.org/en/standards/documents/
  12. The Institute of Internal Auditors. BSA/AML Compliance: Internal Audit’s Role. Industry Knowledge Brief, July 10, 2018. https://www.theiia.org/en/content/articles/industry-knowledge-brief/2018/bsaaml-compliance-internal-audits-role/
  13. Financial Crimes Enforcement Network. The Anti-Money Laundering Act of 2020, including the AML/CFT National Priorities issued June 30, 2021, under AML Act Section 6101. https://www.fincen.gov/resources/statutes-and-regulations/anti-money-laundering-act-2020
Scroll to Top

We look forward to hearing from you.

Your Name(Required)
Your Email Address(Required)

How can AuditOne help? Are there certain Internal Audits or Risk Assessments you would like to know more information about?

Please let us know what's on your mind. Have a question for us? Ask away.
Consent(Required)