The U.S. Treasury’s Financial Crimes Enforcement Network, known as FinCEN, has proposed a significant rewrite of how financial institutions structure their anti-money laundering and countering the financing of terrorism programs. The rule is designed to modernize Bank Secrecy Act compliance by requiring AML/CFT programs to be effective, risk-based, and reasonably designed, rather than simply documented on paper.
The proposal is part of a larger federal effort to update BSA requirements following the Anti-Money Laundering Act of 2020, which called for a more modern and flexible framework. FinCEN said the changes are intended to strengthen the financial system’s defenses against illicit finance while helping institutions direct resources toward the highest-risk threats, including corruption, fraud, terrorism, ransomware, and cybercrime.
At the center of the proposal is a new emphasis on program effectiveness. FinCEN said existing AML/CFT rules would be amended so financial institutions must establish, implement, and maintain programs that are not only compliant, but also reasonably designed to fit their individual risk profiles. In practical terms, that means firms would be expected to show that their internal controls, monitoring systems, and governance structures actually address the risks they face.
A key element of the proposed rule is a mandatory risk assessment process. FinCEN wants institutions to evaluate money laundering and terrorist financing risks across products, services, distribution channels, customers, and geographic locations, then use that assessment to shape policies and controls. The agency also said institutions should review government-wide AML/CFT priorities and incorporate them where appropriate, which would tie private-sector compliance more closely to national priorities.
The proposal also seeks to improve consistency across the different types of firms covered by the Bank Secrecy Act. FinCEN said the rule is meant to create greater clarity across program rules for financial institutions, including banks and other entities subject to BSA obligations. That consistency push matters because BSA compliance has historically evolved through a patchwork of agency rules and supervisory expectations.
Another major theme is risk-based resource allocation. FinCEN said financial institutions should devote more attention and resources to higher-risk customers and activities, and less to lower-risk areas. The agency framed this as an important move away from the status quo, where compliance teams can sometimes spend substantial time on low-value tasks instead of serious threats.
The proposal also keeps customer due diligence in focus. For certain covered institutions, FinCEN would require ongoing customer due diligence as part of internal controls, including customer risk profiles and continuing monitoring for suspicious activity. FinCEN said the rule would not eliminate existing customer due diligence obligations, but would integrate them more clearly into the overall AML/CFT framework.
Governance is another pillar of the proposal. The rule would require institutions to designate an AML/CFT officer based in the United States who is responsible for establishing and maintaining the program and overseeing day-to-day compliance. FinCEN said this reflects the AML Act’s requirement that the duty to establish, maintain, and enforce AML/CFT programs remain with persons in the United States who are accessible to Treasury and the appropriate federal regulator.
The rule also reinforces the importance of independent testing and audit functions. FinCEN did not change the basic expectation that institutions test their programs independently, but it stressed the need for objective criteria and unconflicted auditors. That approach is intended to ensure compliance programs are reviewed by people who can identify weaknesses without bias.
One of the most closely watched aspects of the proposal is its treatment of supervisory and enforcement expectations. The rule distinguishes between whether a program is properly established and whether it is maintained over time, and it suggests that failures to maintain a program would not automatically trigger action unless there is a significant or systemic breakdown. That structure is likely to be important for banks seeking more clarity about where regulators will draw the line.
FinCEN also wants the framework to encourage innovation. The agency said institutions should be able to modernize their AML/CFT programs where appropriate, including by using advanced analytics and other new tools, so long as they continue to manage illicit finance risk effectively. Supporters of the proposal argue this could reduce overreliance on manual reviews and make monitoring more effective.
The proposal was not issued in isolation. FinCEN said it developed the rule in consultation with the Federal Reserve, OCC, FDIC, and NCUA so those agencies could issue coordinated amendments to their own BSA compliance program rules. That coordination is central to the modernization effort because the agencies oversee different categories of financial institutions but share responsibility for AML supervision.
The broader policy objective is to create a risk-based regime that is more effective against serious financial crime while avoiding unnecessary burdens on institutions and customers. FinCEN said the proposal is meant to reduce one-size-fits-all approaches that can push institutions to de-risk entire customer groups, instead encouraging a more targeted and proportionate approach. The agency also linked the rule to financial inclusion, suggesting that better-designed risk frameworks can reduce overcorrection in customer access decisions.
Public comments are a critical next step, and the proposal remains subject to change before it becomes final. FinCEN said written comments must be submitted within 60 days after publication in the Federal Register. Until then, banks, money services businesses, broker-dealers, and other affected firms are likely to assess how the new framework could affect governance, risk assessments, staffing, technology, and supervisory expectations.