# FDIC FIL-12-2026: Issuance of a new Anti-Money Laundering (AML)/Countering the Financing of Terrorism (CFT) Program Requirements Notice of Proposed Rulemaking

> Federal · Agency guidance · In force

URL: https://www.frixlaw.com/law-library/statutes/FDIC_FIL26012

## Section

- **Citation:** FDIC FIL-12-2026
- **Heading:** Issuance of a new Anti-Money Laundering (AML)/Countering the Financing of Terrorism (CFT) Program Requirements Notice of Proposed Rulemaking
- **Jurisdiction:** Federal
- **Kind:** Agency guidance
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** FDIC Financial Institution Letters / Issuance of a new Anti-Money Laundering (AML)/Countering the Financing of Terrorism (CFT) Program Requirements Notice of Proposed Rulemaking

## Text

This section of the FEDERAL REGISTER
contains notices to the public of the proposed
issuance of rules and regulations. The
purpose of these notices is to give interested
persons an opportunity to participate in the
rule making prior to the adoption of the final
rules.
Proposed Rules
Federal Register
18304
Vol. 91, No. 69
Friday, April 10, 2026
DEPARTMENT OF THE TREASURY
Office of the Comptroller of the
Currency
12 CFR Part 21
[Docket ID OCC–2024–0005]
RIN 1557–AF14
FEDERAL DEPOSIT INSURANCE
CORPORATION
12 CFR Part 326
RIN 3064–AF34
NATIONAL CREDIT UNION
ADMINISTRATION
12 CFR Part 748
[Docket ID NCUA–2024–0033]
RIN 3133–AG08
Anti-Money Laundering and
Countering the Financing of Terrorism
Programs
AGENCY: Office of the Comptroller of the
Currency, Treasury; Federal Deposit
Insurance Corporation; and the National
Credit Union Administration.
ACTION: Notice of proposed rulemaking.
SUMMARY: The Office of the Comptroller
of the Currency (OCC), Federal Deposit
Insurance Corporation (FDIC), and the
National Credit Union Administration
(NCUA) (collectively, ‘‘the Agencies’’ or
‘‘Agency’’ when referencing the
singular) are inviting comment on a
proposed rule that would require banks
to establish and maintain effective anti-
money laundering and countering the
financing of terrorism (AML/CFT)
programs reasonably designed to
identify, assess, and mitigate risks of
illicit finance. The amendments are
intended to align with changes that are
being concurrently proposed by the
Financial Crimes Enforcement Network
(FinCEN) to implement provisions of
the Anti-Money Laundering Act of 2020
(AML Act). Among other changes, this
proposed rule would ensure that
institutions establish and maintain
effective AML/CFT programs that are
intended to better achieve the purposes
of the Bank Secrecy Act (BSA),
culminating in the development of
highly useful information related to
illicit financial transactions for law
enforcement and national security
agencies
y Laundering Act of 2020
(AML Act). Among other changes, this
proposed rule would ensure that
institutions establish and maintain
effective AML/CFT programs that are
intended to better achieve the purposes
of the Bank Secrecy Act (BSA),
culminating in the development of
highly useful information related to
illicit financial transactions for law
enforcement and national security
agencies. Through this rulemaking, the
Agencies also intend to modernize and
reform Federal supervision of AML/CFT
programs by enhancing FinCEN’s role in
AML/CFT supervision and enforcement.
DATES: Written comments may be
submitted on or before June 9, 2026.
ADDRESSES: Comments should be
directed to:
OCC: Commenters are encouraged to
submit comments through the Federal
eRulemaking Portal. Please use the title
‘‘Anti-Money Laundering and
Countering the Financing of Terrorism
Programs’’ to facilitate the organization
and distribution of the comments. You
may submit comments by any of the
following methods:
• Federal eRulemaking Portal—
Regulations.gov:
Go to https://regulations.gov/. Enter
Docket ID ‘‘OCC–2024–0005’’ in the
Search Box and click ‘‘Search.’’ Public
comments can be submitted via the
‘‘Comment’’ box below the displayed
document information or by clicking on
the document title and then clicking the
‘‘Comment’’ box on the top-left side of
the screen. For help with submitting
effective comments, please click on
‘‘Commenter’s Checklist.’’ For
assistance with the Regulations.gov site,
please call 1–866–498–2945 (toll free)
Monday–Friday, 9 a.m.–5 p.m. EST, or
email regulationshelpdesk@gsa.gov.
• Mail: Chief Counsel’s Office,
Attention: Comment Processing, Office
of the Comptroller of the Currency, 400
7th Street SW, Suite 3E–218,
Washington, DC 20219.
• Hand Delivery/Courier: 400 7th
Street SW, Suite 3E–218, Washington,
DC 20219.
Instructions: You must include
‘‘OCC’’ as the agency name and Docket
ID ‘‘OCC–2024–0005’’ in your comment
ST, or
email regulationshelpdesk@gsa.gov.
• Mail: Chief Counsel’s Office,
Attention: Comment Processing, Office
of the Comptroller of the Currency, 400
7th Street SW, Suite 3E–218,
Washington, DC 20219.
• Hand Delivery/Courier: 400 7th
Street SW, Suite 3E–218, Washington,
DC 20219.
Instructions: You must include
‘‘OCC’’ as the agency name and Docket
ID ‘‘OCC–2024–0005’’ in your comment.
In general, the OCC will enter all
comments received into the docket and
publish the comments on the
Regulations.gov website without
change, including any business or
personal information provided such as
name and address information, email
addresses, or phone numbers.
Comments received, including
attachments and other supporting
materials, are part of the public record
and subject to public disclosure. Do not
include any information in your
comment or supporting materials that
you consider confidential or
inappropriate for public disclosure.
You may review comments and other
related materials that pertain to this
action by the following method:
• Viewing Comments Electronically—
Regulations.gov:
Go to https://regulations.gov/. Enter
Docket ID ‘‘OCC–2024–0005’’ in the
Search Box and click ‘‘Search.’’ Click on
the ‘‘Dockets’’ tab and then the
document’s title. After clicking the
document’s title, click the ‘‘Browse All
Comments’’ tab. Comments can be
viewed and filtered by clicking on the
‘‘Sort By’’ drop-down on the right side
of the screen or the ‘‘Refine Comments
Results’’ options on the left side of the
screen. Supporting materials can be
viewed by clicking on the ‘‘Browse
Documents’’ tab. Click on the ‘‘Sort By’’
drop-down on the right side of the
screen or the ‘‘Refine Results’’ options
on the left side of the screen checking
the ‘‘Supporting & Related Material’’
checkbox. For assistance with the
Regulations.gov site, please call 1–866–
498–2945 (toll free) Monday–Friday, 9
a.m.–5 p.m. EST, or email
regulationshelpdesk@gsa.gov
by clicking on the ‘‘Browse
Documents’’ tab. Click on the ‘‘Sort By’’
drop-down on the right side of the
screen or the ‘‘Refine Results’’ options
on the left side of the screen checking
the ‘‘Supporting & Related Material’’
checkbox. For assistance with the
Regulations.gov site, please call 1–866–
498–2945 (toll free) Monday–Friday, 9
a.m.–5 p.m. EST, or email
regulationshelpdesk@gsa.gov.
The docket may be viewed after the
close of the comment period in the same
manner as during the comment period.
FDIC: The FDIC encourages interested
parties to submit written comments.
Please include your name, affiliation,
address, email address, and telephone
number(s) in your comment. You may
submit comments to the FDIC,
identified by RIN 3064–AF34, by any of
the following methods:
• Agency Website: https://
www.fdic.gov/resources/regulations/
federal-register-publications. Follow
instructions for submitting comments
on the FDIC’s website.
• Mail: Jennifer M. Jones, Deputy
Executive Secretary, Attention:
Comments/Legal OES (RIN 3064–AF34),
Federal Deposit Insurance Corporation,
550 17th Street NW, Washington, DC
20429.
• Hand Delivered/Courier: Comments
may be hand-delivered to the guard
station at the rear of the 550 17th Street
NW, building (located on F Street NW)
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00001
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1
4),
Federal Deposit Insurance Corporation,
550 17th Street NW, Washington, DC
20429.
• Hand Delivered/Courier: Comments
may be hand-delivered to the guard
station at the rear of the 550 17th Street
NW, building (located on F Street NW)
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00001
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18305
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
1 In Section V.A., the Agencies describe the
express incorporation of the countering the
financing of terrorism (CFT) requirements as part of
a bank’s anti-money laundering (AML) program
requirements. For consistency throughout this
proposed rule, AML program requirements will be
described as AML/CFT program requirements.
2 The term ‘‘bank’’ is defined in regulations
implementing the BSA, 31 CFR 1010.100(d), and
includes each agent, agency, branch, or office
within the United States of banks, savings
associations, credit unions, and foreign banks. For
purposes of this proposed rule, the term bank solely
refers to institutions whose primary regulator is one
of the Agencies. The proposed rule would remove
language in 12 CFR 21.21, which contains the
OCC’s program rule requirements, applicable to
state savings associations. This language was
adopted as part of the transfer of authorities from
the Office of Thrift Supervision. In 2020, the FDIC
issued a final rule making 12 CFR part 326
applicable to State savings associations, meaning it
is no longer necessary to cover State savings
associations in 12 CFR 21.21.
3 FinCEN is requesting comment on proposed
amendments to its AML/CFT program rule for
banks at the same time as this proposed rule from
the Agencies. FinCEN’s bank program rule is
located at 31 CFR 1020.210, while each Agency has
its own implementing regulation. See 12 CFR 21.21
(OCC); 12 CFR 326.8 (FDIC); and 12 CFR 748.2
(NCUA).
4 FinCEN currently defines this term in 31 CFR
1010.100(e)
3 FinCEN is requesting comment on proposed
amendments to its AML/CFT program rule for
banks at the same time as this proposed rule from
the Agencies. FinCEN’s bank program rule is
located at 31 CFR 1020.210, while each Agency has
its own implementing regulation. See 12 CFR 21.21
(OCC); 12 CFR 326.8 (FDIC); and 12 CFR 748.2
(NCUA).
4 FinCEN currently defines this term in 31 CFR
1010.100(e). However, FinCEN notes in the
preamble to its concurrently issued rule that the
proposed rule also would make minor changes to
the definitions in FinCEN regulations. These
changes include the definition of ‘‘Bank Secrecy
Act’’ at 31 CFR 1010.100(e), adding statutory
references to the Anti-Money Laundering Act of
2020 (AML Act) and the Corporate Transparency
Act, and removing the reference to ‘‘collection of
statutes commonly referred to as . . . .’’ Certain
criminal statutes—namely, 18 U.S.C. 1956, 1957,
and 1960—are currently included in the BSA
definition at 31 CFR 1010.100(e). Section 6003 of
the AML Act, however, does not include these
provisions in its BSA definition, and thus FinCEN
is not considering them part of the BSA for the
purposes of its proposed rule.
5 31 U.S.C. 5311(1).
on business days between 7 a.m. and 5
p.m., eastern time.
• Email: comments@fdic.gov. Include
the RIN 3064–AF34 on the subject line
of the message.
• Public Inspection: Comments
received, including any personal
information provided, may be posted
without change to https://www.fdic.gov/
resources/regulations/federal-register
publications. Commenters should
submit only information that the
commenter wishes to make available
publicly. The FDIC may review, redact,
or refrain from posting all or any portion
of any comment that it may deem to be
inappropriate for publication, such as
irrelevant or obscene material
ovided, may be posted
without change to https://www.fdic.gov/
resources/regulations/federal-register
publications. Commenters should
submit only information that the
commenter wishes to make available
publicly. The FDIC may review, redact,
or refrain from posting all or any portion
of any comment that it may deem to be
inappropriate for publication, such as
irrelevant or obscene material. The FDIC
may post only a single representative
example of identical or substantially
identical comments, and in such cases
will generally identify the number of
identical or substantially identical
comments represented by the posted
example. All comments that have been
redacted, as well as those that have not
been posted, that contain comments on
the merits of this document will be
retained in the public comment file and
will be considered as required under all
applicable laws. All comments may be
accessible under the Freedom of
Information Act.
NCUA: You may submit comments,
identified by RIN 3133–AG08, by any of
the following methods (please send
comments by one method only):
• Federal eRulemaking Portal:
https://www.regulations.gov. The docket
number for this proposed rule is NCUA–
2024–0033. Follow the instructions for
submitting comments. A plain language
summary of the proposed rule is also
available on the docket website.
• Mail: Address to Melane Conyers-
Ausbrooks, Secretary of the Board,
National Credit Union Administration,
1775 Duke Street, Alexandria, Virginia
22314–3428.
• Hand Delivery/Courier: Same as
mailing address.
• Public Inspection: You may view all
public comments on the Federal
eRulemaking Portal at https://
www.regulations.gov, as submitted,
except for those we cannot post for
technical reasons. The NCUA will not
edit or remove any identifying or
contact information from the public
comments submitted
e Street, Alexandria, Virginia
22314–3428.
• Hand Delivery/Courier: Same as
mailing address.
• Public Inspection: You may view all
public comments on the Federal
eRulemaking Portal at https://
www.regulations.gov, as submitted,
except for those we cannot post for
technical reasons. The NCUA will not
edit or remove any identifying or
contact information from the public
comments submitted. If you are unable
to access public comments on the
internet, you may contact the NCUA for
alternative access by calling (703) 518–
6540 or emailing OGCMail@ncua.gov.
FOR FURTHER INFORMATION CONTACT:
OCC: Kenneth Kohrs, BSA/AML Lead
Expert, Office of the Chief National
Bank Examiner; Jina Cheon, Assistant
Director, Melissa Lisenbee, Counsel,
Scott Burnett, Counsel, or Henry
Barkhausen, Counsel, Bank Advisory
Group, Chief Counsel’s Office, (202)
649–5490, Office of the Comptroller of
the Currency, 400 7th Street SW,
Washington, DC 20219. If you are deaf,
hard of hearing, or have a speech
disability, please dial 7–1–1 to access
telecommunications relay services.
FDIC: Patricia Colohan, Deputy
Director, (202) 898–7283, pcolohan@
fdic.gov, Division of Risk Management
Supervision; Chase Lubbock, Associate
Director, (703) 254–0802, clubbock@
fdic.gov, Division of Risk Management
Supervision; Christy Cornell-Pape,
Acting Chief, Financial Crimes, (415)
808–8090, acornell-pape@fdic.gov,
Division of Risk Management
Supervision; Deborah Tobolowsky,
Counsel, (571) 309–2415, dtobolowsky@
fdic.gov, Legal Division; Thomas Krepp,
Senior Attorney, (678) 916–2265,
tkrepp@fdic.gov, Legal Division; J.
Spencer Culp, Senior Attorney, (816)
234–8049, jaculp@fdic.gov, Legal
Division; Nicholas Kazmerski, Counsel,
Acting Chief, Financial Crimes, (415)
808–8090, acornell-pape@fdic.gov,
Division of Risk Management
Supervision; Deborah Tobolowsky,
Counsel, (571) 309–2415, dtobolowsky@
fdic.gov, Legal Division; Thomas Krepp,
Senior Attorney, (678) 916–2265,
tkrepp@fdic.gov, Legal Division; J.
Spencer Culp, Senior Attorney, (816)
234–8049, jaculp@fdic.gov, Legal
Division; Nicholas Kazmerski, Counsel,
(571) 309–3136, nkazmerski@fdic.gov,
Legal Division.
NCUA: Michael Dondarski, Associate
Director, Office of Examination &
Insurance, (703) 772–4751,
mdondarski@ncua.gov; Janell Portare,
Director, Fraud and Anti-Money
Laundering Division, Office of
Examination & Insurance, (703) 548–
2752, jportare@ncua.gov; Gira Bose,
Senior Staff Attorney, Office of General
Counsel, (703) 518–6540, gbose@
ncua.gov; Damon P. Frank, Senior Trial
Attorney, Office of General Counsel,
(703) 518–6540, dfrank@ncua.gov.
SUPPLEMENTARY INFORMATION:
I. Scope
The proposed rule would amend the
Agencies’ regulations that prescribe
AML/CFT program requirements 1 for
banks 2 supervised by each of the
Agencies in a way that aligns with the
rule concurrently proposed by FinCEN 3
under the BSA.4 While FinCEN has
delegated its authority to examine banks
for compliance with the BSA to the
Agencies, the Agencies also have
independent authority to prescribe
regulations requiring banks to establish
and maintain procedures reasonably
designed to assure and monitor their
compliance with the requirements of
subchapter II of chapter 53 of title 31,
under 12 U.S.C. 1818(s) and 12 U.S.C.
1786(q) (Sections 8(s) of the Federal
Deposit Insurance Act and 206(q) of the
Federal Credit Union Act, respectively).
The Agencies are proposing to amend
their rules concurrently with FinCEN so
that their program requirements for
banks remain consistent with those
imposed by FinCEN
ce with the requirements of
subchapter II of chapter 53 of title 31,
under 12 U.S.C. 1818(s) and 12 U.S.C.
1786(q) (Sections 8(s) of the Federal
Deposit Insurance Act and 206(q) of the
Federal Credit Union Act, respectively).
The Agencies are proposing to amend
their rules concurrently with FinCEN so
that their program requirements for
banks remain consistent with those
imposed by FinCEN. Further, with
consistent regulatory text, banks will
not be subject to any additional burden
or confusion from needing to comply
with differing standards between
FinCEN and the Agencies. The proposed
changes are discussed in more detail
below in the section-by-section analysis.
II. Background
A. Anti-Money Laundering Programs
Under the Bank Secrecy Act and History
of the BSA Compliance Program Rules
for the Agencies
Enacted in 1970 and amended several
times since, the BSA is designed to
combat money laundering, the financing
of terrorism, and other illicit finance
activity risks (collectively, ML/TF
risks).5 Congress has authorized the
Secretary of the Treasury (Secretary) to
administer the BSA. The Secretary has
in turn delegated the authority to
implement, administer, and enforce
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00002
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18306
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
6 Treasury Order 180–01 (Jan. 14, 2020),
paragraph 3; see also 31 U.S.C. 310(b)(2)(I)
(providing that the Director of FinCEN shall
‘‘[a]dminister the requirements of subchapter II of
chapter 53 of this title, chapter 2 of title I of Public
Law 91–508, and section 21 of the Federal Deposit
Insurance Act, to the extent delegated such
authority by the Secretary of the Treasury.’’).
7 Public Law 99–570, section 5318, 100 Stat.
3207, 3207–29 (1986).
8 52 FR 2858 (Jan. 27, 1987).
9 Most recently, Congress enacted the Guiding
and Establishing National Innovation for U.S
I of
chapter 53 of this title, chapter 2 of title I of Public
Law 91–508, and section 21 of the Federal Deposit
Insurance Act, to the extent delegated such
authority by the Secretary of the Treasury.’’).
7 Public Law 99–570, section 5318, 100 Stat.
3207, 3207–29 (1986).
8 52 FR 2858 (Jan. 27, 1987).
9 Most recently, Congress enacted the Guiding
and Establishing National Innovation for U.S.
Stablecoins (GENIUS) Act on July 18, 2025. Public
Law 119–27, codified at 12 U.S.C. 5901 et seq. The
GENIUS Act requires that permitted payment
stablecoin issuers (PPSIs) be treated as financial
institutions under the BSA, including being
required to maintain ‘‘an effective anti-money
laundering program.’’ See 12 U.S.C. 5903(a)(5)(i).
The GENIUS Act also requires the primary Federal
payment stablecoin regulators, which are the
Agencies and the Federal Reserve Board to issue
regulations relating to PPSIs, including Bank
Secrecy Act and sanctions compliance standards.
These AML/CFT standards for PPSIs will be
addressed separately from this rulemaking.
10 Section 1517 of the Annunzio-Wylie Anti-
Money Laundering Act, Public Law 102–550, 106
Stat. 3672 (Oct. 28, 1992) (Annunzio-Wylie).
11 31 U.S.C. 5318(h)(1), as added by section
1517(b) of Annunzio-Wylie. The Agencies note the
proposed rule modifies the current sequencing of
AML/CFT program components; however, the
Agencies do not intend the change in sequencing
to modify or signify changes in any substantive
requirements.
12 31 U.S.C. 5312(a)(2)(E) and 31 U.S.C. 5312(c),
as added by section 321 of the USA PATRIOT Act,
Public Law 107–56, 115 Stat. 272 (Oct. 26, 2001)
(USA PATRIOT Act).
13 31 U.S.C. 5318(h), as added by section 352 of
the USA PATRIOT Act.
14 31 U.S.C. 5318(a)(2), (h)(1), and (h)(2).
15 See FinCEN, Customer Due Diligence
Requirements for Financial Institutions, 81 FR
29398 (May 11, 2016).
16 68 FR 25090 (May 9, 2003).
17 31 U.S.C. 5318(l), as added by section 326 of
the USA PATRIOT Act.
18 81 FR 29398 (May 11, 2016)
72 (Oct. 26, 2001)
(USA PATRIOT Act).
13 31 U.S.C. 5318(h), as added by section 352 of
the USA PATRIOT Act.
14 31 U.S.C. 5318(a)(2), (h)(1), and (h)(2).
15 See FinCEN, Customer Due Diligence
Requirements for Financial Institutions, 81 FR
29398 (May 11, 2016).
16 68 FR 25090 (May 9, 2003).
17 31 U.S.C. 5318(l), as added by section 326 of
the USA PATRIOT Act.
18 81 FR 29398 (May 11, 2016).
19 Press Release, Joint Statement on Enforcement
of Bank Secrecy Act/Anti-Money Laundering
Requirements (Aug. 13, 2020), https://www.occ.gov/
news-issuances/bulletins/2020/bulletin-2020-
75.html and https://www.fdic.gov/news/press-
releases/2020/pr20091a.pdf.
20 William M. (Mac) Thornberry National Defense
Authorization Act for Fiscal Year 2021, Public Law
116–283, 134 Stat. 3388 (Jan. 1, 2021).
21 Congress noted in its Joint Explanatory
Statement (JES) of the Committee of Conference
accompanying the FY21 NDAA that: ‘‘the current
[AML/CFT] regulatory framework is an
amalgamation of statutes and regulations that are
grounded in the [BSA], which the Congress enacted
in 1970. This decades-old regime, which has not
seen comprehensive reform and modernization
since its inception, is generally built on individual
reporting mechanisms (i.e., currency transaction
reports (CTRs) and suspicious activity reports
(SARs)) and contemplates aging, decades-old
compliance with the BSA and its
associated regulations to the Director of
FinCEN (FinCEN Director).6
The Money Laundering Control Act of
1986 (MLCA) 7 amended 12 U.S.C.
1818(s) and 12 U.S.C. 1786(q) (sections
8(s) of the Federal Deposit Insurance
Act and 206(q) of the Federal Credit
Union Act, respectively) to require the
Agencies and the Board of Governors of
the Federal Reserve System (Federal
Reserve Board) to issue regulations
requiring their supervised banks to
‘‘establish and maintain procedures
reasonably designed to assure and
monitor their compliance’’ with the
requirements of the BSA
(s) of the Federal Deposit Insurance
Act and 206(q) of the Federal Credit
Union Act, respectively) to require the
Agencies and the Board of Governors of
the Federal Reserve System (Federal
Reserve Board) to issue regulations
requiring their supervised banks to
‘‘establish and maintain procedures
reasonably designed to assure and
monitor their compliance’’ with the
requirements of the BSA. Consistent
with the MLCA, on January 27, 1987, all
the then-Federal bank regulatory
agencies issued substantially similar
regulations requiring their supervised
banks to develop procedures for BSA
compliance.8
Since its original enactment, Congress
has continued to address various
aspects of AML/CFT compliance,
including through expansion of the
BSA.9 In 1992, the Annunzio-Wylie
Anti-Money Laundering Act 10 gave the
Secretary authority to prescribe
minimum standards for AML programs,
including: ‘‘(A) the development of
internal policies, procedures, and
controls, (B) the designation of a
compliance officer, (C) an ongoing
employee training program, and (D) an
independent audit function to test
programs’’—what are often called the
‘‘four pillars’’ of AML/CFT programs.11
Later, the Uniting and Strengthening
America by Providing Appropriate
Tools Required to Intercept and
Obstruct Terrorism Act of 2001 (USA
PATRIOT Act) further amended the
BSA to include, among other things,
customer identification program (CIP)
requirements and the expansion of AML
program rules to cover certain other
financial industry participants (e.g.,
credit unions and futures commission
merchants).12 The USA PATRIOT Act
also made it mandatory for financial
institutions to maintain AML programs
that meet minimum prescribed
standards.13 Through the exercise of its
delegated authority, FinCEN is
authorized to require each financial
institution to establish an AML/CFT
program to ensure compliance with the
BSA and guard against ML/TF risks.14
Over time, FinCEN, the Agencies, and
the Federal Reserve Board inco
lso made it mandatory for financial
institutions to maintain AML programs
that meet minimum prescribed
standards.13 Through the exercise of its
delegated authority, FinCEN is
authorized to require each financial
institution to establish an AML/CFT
program to ensure compliance with the
BSA and guard against ML/TF risks.14
Over time, FinCEN, the Agencies, and
the Federal Reserve Board incorporated
many of these standards into their
respective program rules, and FinCEN
implemented additional requirements
for certain covered financial institutions
into their respective program rules.15
Although in practice the FinCEN
AML program rule and the Agencies’
compliance program rules for banks
they supervise operate together, since
the USA PATRIOT Act, banks under the
Agencies’ supervision have been
required to maintain compliance
programs under separate legal
authorities administered by (i) FinCEN
under Title 31 and (ii) the Agencies
under sections 8(s) and 206(q). Because
the authority for each Agency’s BSA
compliance program rule derives from
and is required by sections 8(s) and
206(q), each Agency prescribes
regulations requiring the banks they
supervise to establish and maintain
procedures reasonably designed to
assure and monitor the compliance of
such banks with the requirements of the
BSA.
In 2003, FinCEN, the Agencies, the
Federal Reserve Board, the Securities
and Exchange Commission, and the
Commodity Futures Trading
Commission jointly issued final rules on
CIP requirements,16 which were
mandated by amendments to the BSA
under the USA PATRIOT Act requiring
financial institutions to implement a
CIP as part of their BSA compliance
program.17 The CIP requirements
became part of the separate AML
program rules for banks administered by
FinCEN and each of the Agencies as
well as the Federal Reserve Board,
although the rules continued to function
together by allowing banks to satisfy
FinCEN’s rule by complying with their
Agency’s rule or, as appropriate, the
Federal
to implement a
CIP as part of their BSA compliance
program.17 The CIP requirements
became part of the separate AML
program rules for banks administered by
FinCEN and each of the Agencies as
well as the Federal Reserve Board,
although the rules continued to function
together by allowing banks to satisfy
FinCEN’s rule by complying with their
Agency’s rule or, as appropriate, the
Federal Reserve Board’s rule.
In 2016, FinCEN amended its AML
compliance program rules to
incorporate customer due diligence
(CDD) requirements, including
beneficial ownership information
collection requirements for certain
covered financial institutions, including
banks.18 Although the Agencies did not
promulgate CDD requirements at that
time, the Agencies examined supervised
banks for compliance with those
requirements under the authority of
sections 8(s) and 206(q).19 With the
exception of the CDD requirement,
FinCEN’s rule was substantially similar
to the rules of the Agencies and the
Federal Reserve Board’s rules, and
banks must currently comply with both
FinCEN’s AML bank program rule and
the BSA compliance rules of the
Agencies and, as appropriate, the
Federal Reserve Board.
B. The Anti-Money Laundering Act of
2020
On January 1, 2021, Congress enacted
the William M. (Mac) Thornberry
National Defense Authorization Act for
Fiscal Year 2021, of which the AML Act
was a component.20 With the passage of
the AML Act, Congress stated that it was
seeking to modernize and strengthen the
AML/CFT regulatory framework, which
‘‘had not seen comprehensive reform or
modernization’’ since the BSA was
enacted in the 1970s.21 Among other
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00003
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1
passage of
the AML Act, Congress stated that it was
seeking to modernize and strengthen the
AML/CFT regulatory framework, which
‘‘had not seen comprehensive reform or
modernization’’ since the BSA was
enacted in the 1970s.21 Among other
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00003
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18307
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
technology, rather than the current, sophisticated
AML compliance systems now managed by most
financial institutions.’’ Congress further stated that
the AML Act ‘‘comprehensively update[s] the BSA
for the first time in decades and provide[s] for the
establishment of a coherent set of risk-based
priorities.’’ Among other objectives, Congress
intended for the AML Act to require ‘‘more routine
and systemic coordination, communication, and
feedback among financial institutions, regulators,
and law enforcement to identify suspicious
financial activities, better focusing bank resources
to the AML task, which will increase the likelihood
for better law enforcement outcomes.’’ H.R. Rep.
No. 6395 (2020) at pp. 731–732 (Joint Explanatory
Statement of the Committee of Conference).
22 H.R. Rep. No. 6395 (2020) at 732 (Joint
Explanatory Statement of the Committee of
Conference), https://docs.house.gov/billsthisweek/
20201207/116hrpt617-
JointExplanatoryStatement.pdf.
23 See AML/CFT Priorities (June 30, 2021). As
required by 31 U.S.C. 5318(h)(4)(C), the AML/CFT
Priorities are consistent with Treasury’s National
Strategy for Combating Terrorist and Other Illicit
Financing (May 16, 2024). The AML/CFT Priorities
are supported by Treasury’s National Risk
Assessments on Money Laundering, Terrorist
Financing, and Proliferation Financing (Mar. 2026).
Additionally, Treasury is required to consult with
the Agencies on the National Illicit Finance
Strategy, which must include a risk assessment
y’s National
Strategy for Combating Terrorist and Other Illicit
Financing (May 16, 2024). The AML/CFT Priorities
are supported by Treasury’s National Risk
Assessments on Money Laundering, Terrorist
Financing, and Proliferation Financing (Mar. 2026).
Additionally, Treasury is required to consult with
the Agencies on the National Illicit Finance
Strategy, which must include a risk assessment. See
Combating Terrorism and Illicit Financing, Public
Law 115–44, 131 Stat. 934 (2017). As also required
by 31 U.S.C. 5318(h)(4)(B), the Secretary, in
consultation with the Attorney General, Federal
functional regulators, relevant State financial
regulators, and relevant national security agencies,
must update the AML/CFT Priorities not less
frequently than once every four years.
24 See OCC Bulletin 23019–33, Bank Secrecy Act/
Anti-Money Laundering: Joint Statement on the
Risk-Focused Approach to BSA/AML Supervision
(July 22, 2019).
25 See, e.g., Joint Statement on the Risk-Based
Approach to Assessing Customer Relationships and
Conducting Customer Due Diligence (July 6, 2022)
(‘‘Customer relationships present varying levels of
money laundering, terrorist financing, and other
illicit financial activity risks. The potential risk to
a bank depends on the presence or absence of
numerous factors, including facts and
circumstances specific to the customer relationship.
The Agencies continue to encourage banks to
manage customer relationships and mitigate risks
based on customer relationships, rather than
decline to provide banking services to entire
categories of customers.’’)
26 OCC, FDIC, NCUA, FinCEN, Agencies Issue
Exemption Order to Customer Identification
Program Requirements, (Jun. 27, 2025), https://
www.occ.gov/news-issuances/news-releases/2025/
nr-ia-2025-60.html.
27 FinCEN et. al, Answers to Frequently Asked
Questions Regarding Suspicious Activity Reporting
and Other Anti-Money Laundering Considerations
(Jan
ices to entire
categories of customers.’’)
26 OCC, FDIC, NCUA, FinCEN, Agencies Issue
Exemption Order to Customer Identification
Program Requirements, (Jun. 27, 2025), https://
www.occ.gov/news-issuances/news-releases/2025/
nr-ia-2025-60.html.
27 FinCEN et. al, Answers to Frequently Asked
Questions Regarding Suspicious Activity Reporting
and Other Anti-Money Laundering Considerations
(Jan. 19, 2021) (clarifying, among other things, that
there is no BSA regulatory requirement to terminate
a customer relationship after the filing of a SAR or
any specific number of SARs). See also FinCEN et.
al, Frequently Asked Questions Regarding
Suspicious Activity Reporting Requirements (Oct.
9, 2025), https://www.fincen.gov/system/files/2025-
10/SAR-FAQs-October-2025.pdf (clarifying filing
requirements related to potential structuring-related
activity, documentation requirements related to not
filing a SAR on potentially suspicious activity, and
certain aspects of continuing activity reporting).
28 FinCEN, Anti-Money Laundering Program
Effectiveness, 85 FR 58023 (Sept. 17, 2020).
objectives, Congress intended for the
AML Act to require ‘‘more routine and
systemic coordination, communication,
and feedback among financial
institutions, regulators, and law
enforcement to identify suspicious
financial activities, better focusing bank
resources to the AML task, which will
increase the likelihood for better law
enforcement outcomes.’’ 22
Section 6101(b) of the AML Act made
several changes to the BSA’s AML/CFT
program requirements.
First, section 6101(b) amended the
BSA at 31 U.S.C. 5318(h)(2)(B) to state
that, ‘‘[i]n prescribing the minimum
standards for [AML/CFT programs], and
in supervising and examining
compliance with those standards, the
Secretary of the Treasury, and the
appropriate Federal functional regulator
(as defined in section 509 of the Gramm-
Leach-Bliley Act (15 U.S.C. 6809)) shall
take into account’’ certain factors
(b) amended the
BSA at 31 U.S.C. 5318(h)(2)(B) to state
that, ‘‘[i]n prescribing the minimum
standards for [AML/CFT programs], and
in supervising and examining
compliance with those standards, the
Secretary of the Treasury, and the
appropriate Federal functional regulator
(as defined in section 509 of the Gramm-
Leach-Bliley Act (15 U.S.C. 6809)) shall
take into account’’ certain factors.
Second, section 6101(b) requires the
Secretary, in consultation with the
Attorney General, appropriate Federal
functional regulators, relevant State
financial regulators, and relevant
national security agencies, to establish
and make public government-wide
AML/CFT priorities (AML/CFT
Priorities). After consultation with the
Federal functional regulators and
relevant State financial regulators, the
Secretary must promulgate regulations,
as appropriate, to incorporate those
priorities into revised program rules,
and incorporation of the priorities must
be included as a measure on which
financial institutions are supervised and
examined. FinCEN issued the first
AML/CFT Priorities on June 30, 2021.23
Third, section 6101(b) expands the
BSA’s program rule requirement to
formally include an express reference to
CFT in addition to AML.
Fourth, section 6101(b) provides that
the duty to establish, maintain, and
enforce an AML/CFT program shall
remain the responsibility of, and be
performed by, persons in the United
States who are accessible to, and subject
to oversight and supervision by, the
Secretary and the appropriate Federal
functional regulator.
C. Prior BSA Modernization Efforts
The proposed rule also builds upon
other recent efforts by FinCEN, the
Agencies, and the Federal Reserve
Board to modernize AML/CFT
compliance program requirements for
banks, both before and after the passage
of the AML Act
ho are accessible to, and subject
to oversight and supervision by, the
Secretary and the appropriate Federal
functional regulator.
C. Prior BSA Modernization Efforts
The proposed rule also builds upon
other recent efforts by FinCEN, the
Agencies, and the Federal Reserve
Board to modernize AML/CFT
compliance program requirements for
banks, both before and after the passage
of the AML Act. These efforts include
actions taken to revise the BSA
regulatory regime through rulemakings,
providing exemptive relief from
regulatory requirements consistent with
the purposes of the BSA, and clarifying
regulatory requirements and supervisory
standards through policy documents.
For example, on July 22, 2019,
FinCEN, the Agencies, and the Federal
Reserve Board issued a joint statement
to clarify and explain their existing risk-
focused approach to examinations of
banks’ BSA/AML compliance program.
This statement was intended to increase
transparency into the risk-focused
approach used by the Agencies and the
Federal Reserve Board for planning and
performing BSA/AML examinations,
which included clarifying that the
Agencies and the Federal Reserve Board
‘‘generally allocate more resources to
higher-risk areas, and fewer resources to
lower-risk areas’’ based on the bank’s
unique risk profile.24 FinCEN, the
Agencies, and the Federal Reserve
Board have also taken steps to highlight
that customer relationships present
varying levels of ML/TF risk and, in
turn, to encourage banks to manage
customer relationships and mitigate
risks based on customer relationships,
rather than decline to provide banking
services to entire categories of
customers.25 More recently, the
Agencies and the Federal Reserve Board
have, with FinCEN’s concurrence,
issued an order permitting banks, as
part of their CIP obligations, to collect
Taxpayer Identification Number
information from a third party rather
than directly from the bank’s customer,
subject to certain conditions.26 FinCEN,
the Agencies, and the
services to entire categories of
customers.25 More recently, the
Agencies and the Federal Reserve Board
have, with FinCEN’s concurrence,
issued an order permitting banks, as
part of their CIP obligations, to collect
Taxpayer Identification Number
information from a third party rather
than directly from the bank’s customer,
subject to certain conditions.26 FinCEN,
the Agencies, and the Federal Reserve
Board have also issued Frequently
Asked Questions to clarify certain
obligations related to filing a suspicious
activity report (SAR) to help ensure
banks are not needlessly expending
resources on efforts that do not provide
law enforcement and national security
agencies with the critical information
they need to detect, combat, and deter
criminal activity, as well as to combat
misconceptions that banks are required
to terminate customer relationships
based on the filing of a SAR.27
With respect to prior rulemaking
efforts, prior to the enactment of the
AML Act, FinCEN published an
ANPRM seeking public comment on
potential regulatory amendments
intended to increase the effectiveness of
program rule requirements
(Effectiveness ANPRM), which was
informed by recommendations of the
AML Effectiveness Bank Secrecy Act
Advisory Group working group.28 While
the Effectiveness ANPRM was issued by
FinCEN on a standalone basis, the
Agencies and Federal Reserve Board
were consultative partners with FinCEN
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00004
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1
mendations of the
AML Effectiveness Bank Secrecy Act
Advisory Group working group.28 While
the Effectiveness ANPRM was issued by
FinCEN on a standalone basis, the
Agencies and Federal Reserve Board
were consultative partners with FinCEN
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00004
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18308
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
29 FinCEN, Anti-Money Laundering and
Countering the Financing of Terrorism
Requirements, 89 FR 55428 (Jul. 3, 2024).
30 OCC, Federal Reserve Board, FDIC and the
NCUA, Anti-Money Laundering and Countering the
Financing of Terrorism Requirements, 89 FR 65242
(Aug. 9, 2024).
31 For an overview of the content of the
Effectiveness ANPRM and the 2024 Program NPRM,
and for an overview of comments received on both,
refer to FinCEN’s proposed revisions to its AML/
CFT program requirements, issued concurrently
with this NPRM.
32 31 U.S.C. 5311.
33 31 U.S.C. 5318(h)(2).
34 Federal Reserve Board, FDIC, NCUA, OCC,
Joint Statement on Enforcement of Bank Secrecy
Act/Anti-Money Laundering Requirements, (Aug.
13, 2020), https://www.federalreserve.gov/frrs/
regulations/statement-on-bank-secrecy-act-anti-
money-laundering-enforcement.htm.
when developing the proposal. More
recently, on July 3, 2024, FinCEN
published an NPRM proposing revisions
to its AML/CFT program requirements
for all financial institutions, including
those applicable to banks,29 and on
August 9, 2024, the Agencies, along
with the Federal Reserve Board, issued
an NPRM proposing substantially
similar amendments to their respective
AML program rules applicable to banks
they supervise (the 2024 Program
NPRM).30
In proposing this rule in coordination
with FinCEN, the Agencies considered
applicable statutory requirements and
prior feedback on these recent BSA
modernization efforts, including
comments provided on FinCEN’s
Effectiveness ANPRM and those
PRM proposing substantially
similar amendments to their respective
AML program rules applicable to banks
they supervise (the 2024 Program
NPRM).30
In proposing this rule in coordination
with FinCEN, the Agencies considered
applicable statutory requirements and
prior feedback on these recent BSA
modernization efforts, including
comments provided on FinCEN’s
Effectiveness ANPRM and those
received on the 2024 Program NPRMs.
While building upon these prior
modernization efforts, the proposed rule
is distinct and separate from prior BSA
modernization rulemaking efforts.31
III. Overview of the Proposed Rule
A central objective of the Agencies’
BSA modernization efforts is to create
an AML/CFT supervisory and regulatory
regime that is more effective in
achieving the purposes of the BSA and
culminating in the development of
highly useful information related to
illicit financial transactions for law
enforcement and national security
agencies.32 The proposed rule would
further that objective by explicitly
defining the requirements for a bank to
establish and maintain an effective
AML/CFT program. It would also adopt
into regulations the AML Act’s
expectation that AML/CFT programs
should be risk-based, including
ensuring that banks direct more
attention and resources toward higher-
risk customers and activities, consistent
with the risk profile of the bank, rather
than toward lower-risk customers and
activities.33
The proposed rule would also revise
the AML/CFT supervisory and
examination process for banks by
enhancing FinCEN’s role in the
Agencies’ AML/CFT-related supervision
and enforcement process. In support of
this objective, the proposed rule would
establish a mechanism in which
FinCEN—as the statutory administrator
of the BSA—has an opportunity to
review and provide feedback to the
Agencies prior to certain AML/CFT-
related enforcement and supervisory
actions
tion process for banks by
enhancing FinCEN’s role in the
Agencies’ AML/CFT-related supervision
and enforcement process. In support of
this objective, the proposed rule would
establish a mechanism in which
FinCEN—as the statutory administrator
of the BSA—has an opportunity to
review and provide feedback to the
Agencies prior to certain AML/CFT-
related enforcement and supervisory
actions. This change will promote
consistent approaches to AML/CFT
supervision, culminating in the
development of highly useful
information related to illicit financial
transactions for both banks and the law
enforcement and national security
agencies that depend upon those banks’
critical BSA reporting. The enforcement
requirements only apply to actions by
the Agencies.
Proposed Rule
As noted above, the proposed rule
would require banks to establish and
maintain effective AML/CFT programs
and define the requirements for doing
so. In order for an AML/CFT program to
be effective, the proposed rule would
require a bank to establish an AML/CFT
program and then maintain the AML/
CFT program by implementing, in all
material respects, the established AML/
CFT program.
As described in more detail in section
IV.D a bank would be required to
establish a risk-based set of internal
policies, procedures, and controls that is
reasonably designed to ensure
compliance with the BSA and its
implementing regulations, 31 CFR
chapter X
L/CFT
program and then maintain the AML/
CFT program by implementing, in all
material respects, the established AML/
CFT program.
As described in more detail in section
IV.D a bank would be required to
establish a risk-based set of internal
policies, procedures, and controls that is
reasonably designed to ensure
compliance with the BSA and its
implementing regulations, 31 CFR
chapter X. The risk-based set of internal
policies, procedures, and controls must
also be reasonably designed to (1)
identify, assess, and document the
bank’s ML/TF risks through risk
assessment processes that evaluate the
risks of the bank’s business activities,
review and, as appropriate, incorporate
the AML/CFT Priorities, and are
updated promptly upon any change that
the bank knows or has reason to know
significantly changes the bank’s ML/TF
risks; (2) mitigate the bank’s ML/TF
risks consistent with the bank’s risk
assessment processes including by
directing more attention and resources
toward higher-risk customers and
activities, rather than toward lower-risk
customers and activities; and (3)
conduct ongoing customer due
diligence.
The proposed rule would also require
a bank to establish an ongoing employee
training program and independent
AML/CFT program testing as part of its
AML/CFT program. Finally, the
proposed rule would require a bank to
designate an individual responsible for
establishing and implementing the
AML/CFT program and coordinating
and monitoring day-to-day compliance;
that individual would be required to be
located in the United States and
accessible to, and subject to oversight
and supervision by, FinCEN or its
designee and the appropriate Agency.
Under the proposed rule, in addition
to establishing an AML/CFT program,
the bank would be required to maintain
that program by implementing, in all
material respects, its established AML/
CFT program
nce;
that individual would be required to be
located in the United States and
accessible to, and subject to oversight
and supervision by, FinCEN or its
designee and the appropriate Agency.
Under the proposed rule, in addition
to establishing an AML/CFT program,
the bank would be required to maintain
that program by implementing, in all
material respects, its established AML/
CFT program. By structuring the
requirement to have an effective AML/
CFT program as distinct obligations to
establish and maintain (via
implementation) an AML/CFT program,
the proposed rule is intended to clarify
and reinforce the distinction between
failures to establish an AML/CFT
program and failures to implement a
properly established program.
The distinction between establishing
a program and maintaining a program
by implementing it in all material
respects is particularly important under
the proposed rule for potential
supervisory and enforcement actions.
The proposed rule would not limit
enforcement or supervisory actions for
failures to establish an AML/CFT
program. However, once a bank has
properly established an AML/CFT
program, the proposed rule would raise
the threshold for significant supervisory
or enforcement actions based solely on
implementation deficiencies. Only
significant or systemic failures by a
bank to implement in all material
respects an established program would
warrant an ‘‘AML/CFT enforcement
action’’ or a ‘‘significant AML/CFT
supervisory action,’’ as these terms are
defined in the proposed rule
proposed rule would raise
the threshold for significant supervisory
or enforcement actions based solely on
implementation deficiencies. Only
significant or systemic failures by a
bank to implement in all material
respects an established program would
warrant an ‘‘AML/CFT enforcement
action’’ or a ‘‘significant AML/CFT
supervisory action,’’ as these terms are
defined in the proposed rule. In this
way, the proposed rule is intended to
clarify and reinforce a supervisory and
enforcement focus on addressing
significant or systemic failures to
implement a properly established AML/
CFT program, rather than on isolated,
technical, or immaterial implementation
issues.34
Importantly, under the proposed
regulations, having an effective AML/
CFT program would be more than a one-
time adoption of a risk-based set of
internal policies, procedures, and
controls. Rather, a bank would be
required to keep its risk-based set of
internal policies, procedures, and
controls—and the risk assessment
processes that inform them—current as
the bank’s risk profile changes. For
example, while a bank’s risk-based set
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00005
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18309
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
35 Countering the financing of terrorism (CFT)
includes laws, rules, regulations, or other measures
intended to detect and disrupt the solicitation,
collection, or provision of funds to support terrorist
acts or terrorist organizations, or other violent
extremist groups.
of internal policies, procedures, and
controls may, at one time, have been
reasonably designed, they may no
longer be reasonably designed given
changes to the bank’s risk profile
s, rules, regulations, or other measures
intended to detect and disrupt the solicitation,
collection, or provision of funds to support terrorist
acts or terrorist organizations, or other violent
extremist groups.
of internal policies, procedures, and
controls may, at one time, have been
reasonably designed, they may no
longer be reasonably designed given
changes to the bank’s risk profile.
Similarly, an AML/CFT program would
be more than a one-time creation of an
employee training program or initiation
of an independent testing mechanism:
the bank would be required to keep
such aspects of the AML/CFT program
current as the bank’s risk profile
changes. Thus, even where a bank has
previously established an AML/CFT
program in accordance with the
proposed rule, a failure to update the
program to reflect significant changes in
the bank’s risk profile may result in the
program no longer meeting the program
establishment requirements, and the
bank may accordingly be subject to
supervisory or enforcement action for a
failure to establish an effective AML/
CFT program.
The proposed rule would also provide
FinCEN with a greater role in the
Agencies’ supervisory process. To better
ensure that the Agencies are performing
‘‘risk-focused’’ BSA supervision, the
proposed rule would require that the
Agencies consult with FinCEN prior to
taking an AML/CFT enforcement action
or a significant AML/CFT supervisory
action. The Agencies would be required
to give FinCEN written notice at least 30
days prior to taking such an action.
FinCEN would have an opportunity to
review the action and the relevant
underlying information giving rise to it,
and the Agencies would be required to
consider any input offered by FinCEN
concerning the effectiveness of the
bank’s AML/CFT program
icant AML/CFT supervisory
action. The Agencies would be required
to give FinCEN written notice at least 30
days prior to taking such an action.
FinCEN would have an opportunity to
review the action and the relevant
underlying information giving rise to it,
and the Agencies would be required to
consider any input offered by FinCEN
concerning the effectiveness of the
bank’s AML/CFT program.
By explicitly defining the
requirements for a bank to establish and
maintain an effective AML/CFT
program, and by standardizing the
AML/CFT supervision and enforcement
process for banks and across the
Agencies, the proposed rule is expected
to better achieve the purposes of the
BSA, culminating in the development of
highly useful information related to
illicit financial transactions for banks
and law enforcement and national
security agencies. However, the
Agencies do not intend for the proposed
rule to provide banks permission to
establish an AML/CFT program that
might be interpreted as meeting the
proposed rule’s technical requirements
on their face, but do not effectively
detect and prevent ML/TF activity. To
establish a compliant AML/CFT
program under the proposed rule, a
bank must, among other things,
establish a risk-based set of internal
policies, procedures, and controls that is
reasonably designed to ensure
compliance with the BSA and 31 CFR
chapter X, including through the
adoption of risk assessment processes. A
critical element of this requirement is
that the bank’s s risk-based set of
internal policies, procedures, and
controls be ‘‘reasonably designed.’’ For
example, if a bank’s program testing
reveals that a new customer type or new
activity is high risk, but the bank does
not take any action to revise the design
of its risk-based set of internal policies,
procedures, and controls and therefore
treats the customer or activity as
presenting low risk, then its program
should not be considered reasonably
designed
e ‘‘reasonably designed.’’ For
example, if a bank’s program testing
reveals that a new customer type or new
activity is high risk, but the bank does
not take any action to revise the design
of its risk-based set of internal policies,
procedures, and controls and therefore
treats the customer or activity as
presenting low risk, then its program
should not be considered reasonably
designed. The Agencies believe that
banks have a better understanding of
their customer bases and businesses and
are best positioned to identify and
evaluate their ML/TF risks. Therefore,
under this proposed rule banks will
continue to have significant flexibility
and discretion in their decisions and
determinations related to risk
identification and resource allocation.
The Agencies will assess whether: (1) a
bank’s resource allocation decisions are
consistent with a reasonably designed
risk assessment processes; and (2) with
respect to implementation, specifically,
whether the bank knows or should
know of resource-related issues
involving its risk-based set of internal
policies, procedures, and controls that
may result in the bank failing to
implement its AML/CFT program in all
material respects and has failed to
address such issues.
Similarly, the Agencies expect a bank
to be examined for its implementation
of the established AML/CFT program in
all material respects. Merely designating
an individual responsible for
establishing and implementing the
AML/CFT program and having that
individual establish risk-based internal
policies, procedures, and controls, an
ongoing employee training program, and
an independent AML/CFT program
testing program, are not sufficient to
satisfy the proposed rule’s obligations
for a bank to have an effective AML/CFT
program
rely designating
an individual responsible for
establishing and implementing the
AML/CFT program and having that
individual establish risk-based internal
policies, procedures, and controls, an
ongoing employee training program, and
an independent AML/CFT program
testing program, are not sufficient to
satisfy the proposed rule’s obligations
for a bank to have an effective AML/CFT
program. Rather, a bank would be
examined for the implementation, in all
material aspects, of its established AML/
CFT program, including the
determination that the bank is, in fact,
allocating resources commensurate with
its established AML/CFT program,
which the proposed rule would require
to be consistent with and its reasonably
designed risk assessment processes.
IV. Section-by-Section Analysis
This section-by-section analysis
describes the specific proposed changes
to the Agencies’ BSA compliance
program rules. Section IV.A addresses
the proposed incorporation of CFT into
the program rules. Section IV.B
discusses the requirements for an
‘‘effective’’ AML/CFT program to
comply with the requirements of the
proposed rule. Section IV.C explains
what it means to ‘‘establish’’ and
‘‘maintain’’ an effective AML/CFT
program. Section IV.D describes the
components of program establishment,
including (1) a risk-based set of internal
policies, procedures, and controls
(including risk assessment processes);
the requirements for an
‘‘effective’’ AML/CFT program to
comply with the requirements of the
proposed rule. Section IV.C explains
what it means to ‘‘establish’’ and
‘‘maintain’’ an effective AML/CFT
program. Section IV.D describes the
components of program establishment,
including (1) a risk-based set of internal
policies, procedures, and controls
(including risk assessment processes);
(2) independent program testing; (3) an
individual, located in the United States
and accessible to FinCEN and the
Agencies, responsible for establishing
and maintaining the program, and
coordinating and monitoring day-to-day
compliance; and (4) ongoing employee
training. Section IV.E discusses the
requirements that the AML/CFT
program be written, accessible, and
approved by a bank’s Board of Directors,
an equivalent governing body within the
bank, or appropriate senior
management. Section IV.F addresses the
Customer Identification Program,
Section IV.G addresses the supervision
and enforcement section of the
proposed rule, and Section IV.H
discusses technical changes that the
proposal makes to the existing rules to
improve clarity and consistency across
the program rules. Lastly, Section IV.I
discusses disclosure of supervisory
information.
A. Inserting the Term ‘‘CFT’’ Into the
Program Rules
Section 6101(b)(2)(A) of the AML Act
amends 31 U.S.C. 5318(h)(1) to
reference ‘‘countering the financing of
terrorism’’ 35 in addition to ‘‘anti-money
laundering’’ when describing the
requirement to establish an AML/CFT
program. The Agencies propose to
update the AML/CFT program rules to
reflect this new statutory language. For
example, the proposed rule would
change the title of the Agencies’
program rules from ‘‘Bank Secrecy Act
compliance’’ to ‘‘Anti-Money
Laundering/Countering the Financing of
Terrorism Compliance, Supervision,
and Enforcement.’’ Similar changes
would apply to the titles of relevant
parts and subparts
s propose to
update the AML/CFT program rules to
reflect this new statutory language. For
example, the proposed rule would
change the title of the Agencies’
program rules from ‘‘Bank Secrecy Act
compliance’’ to ‘‘Anti-Money
Laundering/Countering the Financing of
Terrorism Compliance, Supervision,
and Enforcement.’’ Similar changes
would apply to the titles of relevant
parts and subparts.
The inclusion of ‘‘CFT’’ in the BSA
compliance program rule would not
create new obligations for banks, insofar
as the USA PATRIOT Act already
requires them to account for risks
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00006
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18310
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
36 See 31 U.S.C. 5318(h)(2)(B)(iii).
37 Federal Financial Institution Examination
Council, BSA/AML Assessing Compliance with
BSA Regulatory Requirements — Suspicious
Activity Reporting, https://bsaaml.ffiec.gov/
manual/AssessingComplianceWithBSARegulatory
Requirements/04.
38 William M. (Mac) Thornberry National Defense
Authorization Act for Fiscal Year 2021, Public Law
116–283, 134 Stat. 4547 at section 6002(3) (Jan. 1,
2021).
39 Federal Reserve Board, FDIC, FinCEN, NCUA,
OCC, Joint Statement on Innovative Efforts to
Combat Money Laundering and Terrorist Financing,
(Dec. 3, 2018), https://www.fincen.gov/system/files/
2018-12/Joint%20Statement%20
on%20Innovation%20Statement%20
%28Final%2011-30-18%29_508.pdf.
40 For instance, the provision of the BSA which
requires financial institutions to have AML/CFT
program rules states that ‘‘each financial institution
shall establish’’ (emphasis added) such programs,
including certain requirements as specified. See 31
U.S.C. 5318(h)(1)
//www.fincen.gov/system/files/
2018-12/Joint%20Statement%20
on%20Innovation%20Statement%20
%28Final%2011-30-18%29_508.pdf.
40 For instance, the provision of the BSA which
requires financial institutions to have AML/CFT
program rules states that ‘‘each financial institution
shall establish’’ (emphasis added) such programs,
including certain requirements as specified. See 31
U.S.C. 5318(h)(1). The corresponding Federal
statute requiring each appropriate Federal banking
agency to prescribe regulations requiring their
supervised institutions to have BSA compliance
programs states that these banks must ‘‘establish
and maintain procedures reasonably designed to
assure and monitor the compliance’’ with the
requirements of the BSA. 12 U.S.C. 1818(s)(1).
related to terrorist financing.
Accordingly, the Agencies expect any
changes to existing AML/CFT programs
from the amendments described in this
subsection to be technical and therefore
not have any substantive impact on
banks’ compliance obligations.
B. An ‘‘Effective’’ AML/CFT Program
In prescribing the minimum standards
for an AML/CFT program and in
supervising and examining compliance
with those standards, the AML Act
requires the Secretary and the
appropriate Federal functional regulator
to take into account that effective AML/
CFT programs safeguard national
security and help law enforcement
prevent the flow of illicit funds in the
financial system.36 Further, the AML
Act contemplates AML/CFT
requirements focusing on achieving
effective outcomes rather than dictating
the processes used to reach those
outcomes, an orientation the Agencies
intend to reflect in the proposed rule
e into account that effective AML/
CFT programs safeguard national
security and help law enforcement
prevent the flow of illicit funds in the
financial system.36 Further, the AML
Act contemplates AML/CFT
requirements focusing on achieving
effective outcomes rather than dictating
the processes used to reach those
outcomes, an orientation the Agencies
intend to reflect in the proposed rule.
Consistent with the Agencies’ long-
standing expectations regarding what
effective outcomes entail, the Agencies
believe that, as a practical matter, it is
not possible for a bank’s AML/CFT
program to detect and report all
potentially illicit transactions that flow
through the institution.37 Similarly, a
bank’s AML/CFT program can be
effective without preventing every
minor instance of a bank falling prey to
illicit finance misuse. Accordingly, the
proposed rule would set out that, from
a supervisory and enforcement
perspective, an AML/CFT program is
‘‘effective’’ and complies with the
Agencies’ regulatory requirements
promulgated under 12 U.S.C. 1818(s) or
12 U.S.C. 1786(q), as applicable, so long
as it is established and maintained in
accordance with applicable
requirements.
The proposed rule would provide that
a bank has an ‘‘effective’’ program if it
(1) is established in accordance with the
proposed rule’s establishment
requirements; and (2) is maintained,
meaning that a properly established
AML/CFT program is implemented in
all material respects.
One of the AML Act’s key purposes is
to ‘‘encourage technological innovation
and the adoption of new technology by
financial institutions to more effectively
counter money laundering and
financing of terrorism.’’ 38 Consistent
with this purpose, the Agencies
encourage banks to evaluate whether
new technology or innovative
approaches in other resources might
help to combat financial crime more
effectively
’s key purposes is
to ‘‘encourage technological innovation
and the adoption of new technology by
financial institutions to more effectively
counter money laundering and
financing of terrorism.’’ 38 Consistent
with this purpose, the Agencies
encourage banks to evaluate whether
new technology or innovative
approaches in other resources might
help to combat financial crime more
effectively. Innovative approaches could
involve machine learning, generative
artificial intelligence (GenAI), digital
identity, blockchain monitoring and
analytics, or application programming
interfaces (APIs).
The Agencies recognize that adopting
new technologies for BSA compliance
may not be suitable for all banks,
particularly smaller ones, and the
proposed rule therefore does not
reference or require the use of any
particular technology. A bank may find
it beneficial to consider whether its
AML/CFT program appropriately uses
the bank’s existing resources, including
technology and data. However,
consistent with longstanding guidance,
the Agencies encourage banks to engage
in responsible AML/CFT innovation.39
Banks that responsibly incorporate
innovative technologies into their AML/
CFT programs will not incur on that
basis any additional risk of being subject
to a significant supervisory action or
enforcement action solely based on the
use of innovative technologies.
C. Establishing and Maintaining an
AML/CFT Program
The requirement that a bank establish
and maintain an AML/CFT program is
not new, although over time various
formulations of this requirement have
developed in statutes and regulations.40
The proposed rule would harmonize
and delineate the regulatory
requirements that must be met for banks
to have an effective AML/CFT program.
That is, the proposed rule would create
a two-pronged framework under which
a bank’s AML/CFT program would be
deemed to be effective if the bank
establishes and maintains its program
of this requirement have
developed in statutes and regulations.40
The proposed rule would harmonize
and delineate the regulatory
requirements that must be met for banks
to have an effective AML/CFT program.
That is, the proposed rule would create
a two-pronged framework under which
a bank’s AML/CFT program would be
deemed to be effective if the bank
establishes and maintains its program.
Under the proposed rule, a bank
maintains its properly established AML/
CFT program by implementing it in all
material respects.
1. Establishing Versus Maintaining an
AML/CFT Program
For a bank to have an effective AML/
CFT program, the proposed rule would
require a bank to establish an AML/CFT
program and then maintain the AML/
CFT program by implementing, in all
material respects, the established AML/
CFT program. The proposed rule
describes the requirements for an
effective AML/CFT program to be
established and maintained. The AML/
CFT program minimum components
constituting program establishment, and
described in further detail in Section
V.D below, are: (1) a risk-based set of
internal policies, procedures, and
controls (including risk assessment
processes); (2) independent program
testing; (3) an individual, located in the
United States and accessible to FinCEN
and the appropriate Agency, responsible
for establishing and maintaining the
program, and coordinating and
monitoring day-to-day compliance; and
tail in Section
V.D below, are: (1) a risk-based set of
internal policies, procedures, and
controls (including risk assessment
processes); (2) independent program
testing; (3) an individual, located in the
United States and accessible to FinCEN
and the appropriate Agency, responsible
for establishing and maintaining the
program, and coordinating and
monitoring day-to-day compliance; and
(4) ongoing employee training.
‘‘Establishing’’ an AML/CFT program
involves designing an AML/CFT
program that incorporates all of the
required components. ‘‘Maintaining,’’
by contrast, addresses whether the bank
is implementing that program in
practice. The regulation uses the term
‘‘implement’’ to describe this second
prong. The distinction between
establishing a program and maintaining
a program by implementation matters
because the proposed rule ties the
availability of AML/CFT enforcement
and significant supervisory actions
based on the program rule for an
established bank program to a
significant or systemic failure to
‘‘implement’’ the properly established
AML/CFT program. The distinction
between establishing and ‘‘maintaining’’
an AML/CFT program is intended to
make transparent how the individual
elements of the proposed rule work
together.
Separating program establishment
from program maintenance therefore
provides needed clarity regarding
whether a supervisory concern relates to
deficiencies stemming from the
program’s design, on the one hand, or
failures in the program’s operation, on
the other. This two-prong framework
would help promote consistent
articulation of supervisory expectations
and prevent conflating criticisms of
program design—the remediation of
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00007
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1
n the one hand, or
failures in the program’s operation, on
the other. This two-prong framework
would help promote consistent
articulation of supervisory expectations
and prevent conflating criticisms of
program design—the remediation of
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00007
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18311
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
41 See, 12 CFR 21.21(d)(1) (OCC); 12 CFR
326.8(c)(1) (FDIC); and 12 CFR 748.2(c)(1) (NCUA).
which would likely be different in
kind—with criticisms of day-to-day
implementation. The proposed
distinction does not change the
substantive obligations for the bank.
As noted previously, the Agencies
intend for the requirements of this
proposed rule to not be limited to a one-
time adoption of the elements required
for program establishment, such as a
risk-based set of internal policies,
procedures, and controls. Rather, the
Agencies intend a bank’s establishment
of its AML/CFT program to require the
bank’s risk-based set of internal policies,
procedures, and controls—and the risk
assessment processes that inform
them—to remain current as the bank’s
risk profile changes. For example, if a
bank begins providing a new product or
service—or changes how it provides an
existing product or service, such as
operating in a new geographic
location—under this proposed rule, a
bank would need to incorporate its new
product or service as part of its risk
assessment processes. The proposed
rule would require a bank to make a risk
determination and, as appropriate,
redesign its risk-based set of internal
policies, procedures, and controls to
account for the risks that it did not
previously encounter prior to offering
the new product or service, or operating
in the new geographic location
orate its new
product or service as part of its risk
assessment processes. The proposed
rule would require a bank to make a risk
determination and, as appropriate,
redesign its risk-based set of internal
policies, procedures, and controls to
account for the risks that it did not
previously encounter prior to offering
the new product or service, or operating
in the new geographic location. Thus,
under the proposed rule, even where a
bank has previously established an
AML/CFT program in accordance with
the proposed rule, a failure to update
the program to reflect significant
changes in the bank’s risk profile may
result in the program no longer
satisfying the proposed rule’s
requirements regarding establishment.
2. Implementation of an AML/CFT
Program
Once a bank has properly
‘‘established’’ an AML/CFT program,
the bank must ‘‘maintain’’ the program
by implementing it, in all material
respects. Minor deficiencies of an AML/
CFT program would not necessarily
mean that a bank has failed to
implement the program.
Although there are a variety of ways
that a bank may not be implementing its
program ‘‘in all material respects,’’ in
the Agencies’ experience, commonly
observed examples may include, but
would not be limited to: (1) internal
policies, procedures, and controls are
not being performed or not being
performed on a consistent, regular, and
timely basis (e.g., consistently ignored
warnings or red flags that a program was
seriously deficient) due to the nature or
extent of required resources becoming
inadequate; (2) gaps in the risk
assessment processes that result in the
bank’s program internal policies,
procedures, and controls missing or
inadequately covering higher ML/TF
risks (e.g., systems used to monitor for
potentially suspicious activity failing to
capture material volumes or types of
transactions); or (3) deficiencies or
weaknesses in the risk assessment
processes that have a material impact on
the bank’s mitigation of ML/TF risks
through its risk-bas
program internal policies,
procedures, and controls missing or
inadequately covering higher ML/TF
risks (e.g., systems used to monitor for
potentially suspicious activity failing to
capture material volumes or types of
transactions); or (3) deficiencies or
weaknesses in the risk assessment
processes that have a material impact on
the bank’s mitigation of ML/TF risks
through its risk-based set of internal
policies, procedures, and controls,
including due to data-related issues
involving relevant processes and
systems.
Similarly, the Agencies expect that a
bank could become aware of such
implementation-related concerns
through a variety of mechanisms,
including but not limited to: (1)
independent testing of the AML/CFT
program; (2) examiner observations,
suggestions, or other informal comments
about the AML/CFT program;, (3)
management information systems and
related reports or other outputs (e.g., key
performance indicators or key risk
indicators, such as monitoring for
potentially material backlogs in relevant
AML/CFT processes), and (4) issues
identified by personnel involved in the
operation of the bank’s AML/CFT
program.
D. Program Establishment
As noted earlier, pursuant to 31
U.S.C. 5318(h), the Agencies’ AML/CFT
program requirements for banks
currently require certain minimum
elements, including: (1) a risk-based set
of internal policies, procedures, and
controls; (2) an independent audit
function to test programs; (3) a
designated compliance officer; and (4)
an ongoing employee training program.
The majority of the proposed rule’s
AML/CFT program components are
substantially similar to the existing
regulatory requirements for banks.
However, the Agencies are proposing
certain additions and modifications to
modernize and strengthen banks’ AML/
CFT programs to allow banks to better
mitigate illicit finance risks.
1
compliance officer; and (4)
an ongoing employee training program.
The majority of the proposed rule’s
AML/CFT program components are
substantially similar to the existing
regulatory requirements for banks.
However, the Agencies are proposing
certain additions and modifications to
modernize and strengthen banks’ AML/
CFT programs to allow banks to better
mitigate illicit finance risks.
1. Internal Policies, Procedures, and
Controls
The Agencies’ rules currently require
banks to develop ‘‘a system of internal
controls to assure ongoing compliance’’
with the requirements of the BSA as
part of their AML/CFT programs.41 The
Agencies’ existing program rules,
however, do not clearly articulate what
it means to establish such a system of
internal policies, procedures, and
controls to ensure compliance.
Under the proposal, the Agencies are
amending and clarifying the current
internal control pillar requirements.
Specifically, the proposal provides that
banks must establish a risk-based set of
internal policies, procedures, and
controls that is reasonably designed to:
(1) identify, assess, and document ML/
TF risks through risk assessment
processes; (2) mitigate ML/TF risks
consistent with the risk assessment
processes, including by directing more
attention and resources toward higher-
risk customers and activities rather than
toward lower-risk customers and
activities; and, (3) conduct ongoing
CDD. The preamble addresses each of
these features below.
Under this proposal, a bank’s risk-
based set of internal policies,
procedures, and controls should be
based upon, informed by, and consistent
with a bank’s risk assessment processes.
The internal policies, procedures, and
controls should be commensurate with
the size, structure, risk profile, and
complexity of the bank
t ongoing
CDD. The preamble addresses each of
these features below.
Under this proposal, a bank’s risk-
based set of internal policies,
procedures, and controls should be
based upon, informed by, and consistent
with a bank’s risk assessment processes.
The internal policies, procedures, and
controls should be commensurate with
the size, structure, risk profile, and
complexity of the bank. The
requirement that a bank’s risk-based set
of internal policies, procedures, and
controls be ‘‘reasonably designed’’ gives
banks flexibility in how they achieve
compliance with the BSA and the
proposed rule’s other requirements. As
part of having a risk-based set of
internal policies, procedures, and
controls, reasonably designed to ensure
compliance, banks may choose to
responsibly adopt new technologies or
innovative approaches to comply with
BSA requirements. Consistent with this
purpose, the Agencies encourage banks
to evaluate whether new technology or
innovative approaches in other
resources might help to more effectively
combat financial crime. Innovative
approaches could involve machine
learning, GenAI, digital identity,
blockchain monitoring and analytics, or
APIs.
i. Risk Assessment Processes
The Agencies are proposing that, as
part of a bank’s risk-based set of internal
policies, procedures, and controls, the
bank identify, assess, and document the
bank’s ML/TF risk through risk
assessment processes that: (1) evaluate
the ML/TF risks of the bank’s business
activities, including products, services,
distribution channels, customers, and
geographic locations; (2) review and, as
appropriate, incorporate the AML/CFT
Priorities; and (3) update promptly upon
any change that the bank knows or has
reason to know significantly changes the
bank’s ML/TF risks.
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00008
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1
ls, customers, and
geographic locations; (2) review and, as
appropriate, incorporate the AML/CFT
Priorities; and (3) update promptly upon
any change that the bank knows or has
reason to know significantly changes the
bank’s ML/TF risks.
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00008
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18312
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
42 Joint Statement on Risk-Focused Bank Secrecy
Act/Anti-Money Laundering Supervision (July 22,
2019), https://www.fdic.gov/sites/default/files/2024-
03/pr19065a.pdf. The Joint Statement on Risk
Focused BSA/AML Supervision, July 22, 2019,
clarifies the Agencies’ and the Federal Reserve
Board’s long-standing supervisory approach to
examining for compliance with the BSA considers
a financial institution’s risk profile and notes that
‘‘[a] risk-based [AML] compliance program enables
a bank to allocate compliance resources
commensurate with its risk.’’ It further clarifies that
a well-developed risk assessment process assists
examiners in understanding a bank’s risk profile
and evaluating the adequacy of its AML program.
The statement also explains that, as part of their
risk-focused approach, examiners review a bank’s
risk management practices to evaluate whether a
bank has developed and implemented a reasonable
and effective process to identify, measure, monitor,
and control risks.
43 See FinCEN, Section 314(b) Fact Sheet, (Dec.
2020), www.fincen.gov/system/files/shared/
314bfactsheet.pdf.
44 See U.S. Dep’t of Treasury, 2026 Nat. Money
Laundering Risk Assess. (Mar. 2026), https://
home.treasury.gov/system/files/246/2026-
NMLRA.pdf; U.S. Dep’t of Treasury, 2026 Nat.
Terrorist Financing Risk Assess. (Mar. 2026),
https://home.treasury.gov/system/files/246/2026-
NTFRA.pdf; U.S. Dep’t of Treasury, 2026 Nat.
Proliferation Financing Risk Assess. (Mar
iles/shared/
314bfactsheet.pdf.
44 See U.S. Dep’t of Treasury, 2026 Nat. Money
Laundering Risk Assess. (Mar. 2026), https://
home.treasury.gov/system/files/246/2026-
NMLRA.pdf; U.S. Dep’t of Treasury, 2026 Nat.
Terrorist Financing Risk Assess. (Mar. 2026),
https://home.treasury.gov/system/files/246/2026-
NTFRA.pdf; U.S. Dep’t of Treasury, 2026 Nat.
Proliferation Financing Risk Assess. (Mar. 2026),
https://home.treasury.gov/system/files/246/2026-
NPFRA.pdf.
The Agencies have traditionally
viewed risk assessment processes as a
critical tool of a reasonably designed
BSA compliance program; a bank
cannot implement a reasonably
designed program to achieve
compliance with the BSA unless it
understands its risk profile.42 Most
banks already use risk assessments or
risk assessment processes to structure
their risk-based compliance programs.
Despite being viewed as a critical tool,
the Agencies’ regulations do not
currently explicitly require such risk
assessment processes nor outline
mandatory considerations for such
processes. Thus, the proposed rule
would codify into regulations the
requirement for banks to establish risk
assessment processes, thereby clarifying
existing expectations and practices, as
well as require specific factors for
consideration that are responsive to the
AML Act.
Importantly, the proposed rule
requires, as a part of a bank’s risk-based
set of internal policies, procedures and
controls, that it identify, assess, and
document its ML/TF risks using risk
assessment processes. A bank would
retain flexibility in how it would
document the results of its risk
assessment processes. As proposed,
banks would not be required to establish
a single, consolidated risk assessment
document solely to comply with the
proposed rule
based
set of internal policies, procedures and
controls, that it identify, assess, and
document its ML/TF risks using risk
assessment processes. A bank would
retain flexibility in how it would
document the results of its risk
assessment processes. As proposed,
banks would not be required to establish
a single, consolidated risk assessment
document solely to comply with the
proposed rule. While such a document
may be appropriate under the proposal,
the use of the term ‘‘risk assessment
processes’’ is intended to reflect that a
financial institution may rely on
multiple processes—applied as
appropriate within its AML/CFT
program—to identify, assess, and
document its ML/TF risks and will be
examined based on the totality of these
processes rather than the sufficiency of
a single, standalone risk assessment
document.
The Agencies believe banks are best
positioned to identify and evaluate their
ML/TF risk and are therefore not
prescribing any particular risk
assessment processes or methodologies
other than the critical elements
described in this proposed rule. Under
the proposed rule, banks would be
examined for whether they have
established and maintained, in all
material respects, reasonably designed
risk assessment processes—which need
not be in the form of a singular risk
assessment process. Furthermore, the
Agencies are not prescribing any
particular time frame for banks to
update their risk assessment processes.
The Agencies recognize that banks
vary significantly in size, structure,
complexity, and risk profile. Under the
proposed rule, bank’s risk-based set of
internal policies, procedures, and
controls—including its risk assessment
processes—should be commensurate
with the bank’s size, structure, risk
profile, and complexity
ular time frame for banks to
update their risk assessment processes.
The Agencies recognize that banks
vary significantly in size, structure,
complexity, and risk profile. Under the
proposed rule, bank’s risk-based set of
internal policies, procedures, and
controls—including its risk assessment
processes—should be commensurate
with the bank’s size, structure, risk
profile, and complexity. Accordingly,
banks with broader product offerings,
more complex corporate structures, or
greater exposure to higher-risk
customers, products, services, or
geographic locations would be expected
to establish correspondingly more
formalized or analytically complex
internal policies, procedures, and
controls—including risk assessment
processes. By contrast, many
community banks operate with more
limited business activities, traditional
lending and deposit services, a narrower
geographic footprint, and customer
bases concentrated within defined local
communities. For such banks, risk
assessment processes may appropriately
be more streamlined or qualitative in
nature, and a risk-based set of internal
policies, procedures, and controls that is
reasonably designed for a large, complex
financial organization would not
necessarily be required or appropriate
for a community bank with a more
limited risk profile.
As noted previously, most banks
already design their BSA compliance
programs based on their assessment of
ML/TF risks under existing risk
assessment processes. The Agencies
expect that most banks will be able to
leverage their existing risk assessment
processes to satisfy the proposed
requirement without making significant
changes.
a. ML/TF Risks
The proposed rule would require
banks’ risk assessment processes to
evaluate the ML/TF risks of the bank’s
business activities, including products,
services, distribution channels,
customers, and geographic locations.
These factors are generally well known
and often incorporated into current risk
assessment processes of banks
equirement without making significant
changes.
a. ML/TF Risks
The proposed rule would require
banks’ risk assessment processes to
evaluate the ML/TF risks of the bank’s
business activities, including products,
services, distribution channels,
customers, and geographic locations.
These factors are generally well known
and often incorporated into current risk
assessment processes of banks. While
most banks are generally familiar with
these concepts, ‘‘distribution channels’’
may be a newer term for some banks.
For purposes of this rule, the Agencies
consider ‘‘distribution channels’’ to
refer to the methods and tools through
which a bank opens accounts and
provides products or services,
including, for example, through remote
or other non-face-to-face means.
Banks may use a variety of sources to
inform their risk assessment processes.
Such sources may include information
obtained from other financial
institutions, such as emerging risks and
typologies identified through section
314(b) information sharing or payment
transactions that other financial
institutions returned or flagged due to
ML/TF risks.43 Information a bank
generates or maintains could be another
source. Internal information may
include, for example, customer internet
protocol addresses or device logins and
related geolocation information.
Feedback from FinCEN, law
enforcement, and financial regulators
may also inform risk assessment
processes. For example, if a bank
receives feedback from law enforcement
about a report it has filed or potential
risks at the bank, the bank may
incorporate that information into its risk
assessment processes. Similarly, banks
may consider information identified
from responding to section 314(a)
requests.
In addition to feedback, reports and
analyses published by Treasury and
FinCEN may be particularly relevant to
a bank’s business activities, thereby
warranting consideration when
evaluating ML/TF risks
at the bank, the bank may
incorporate that information into its risk
assessment processes. Similarly, banks
may consider information identified
from responding to section 314(a)
requests.
In addition to feedback, reports and
analyses published by Treasury and
FinCEN may be particularly relevant to
a bank’s business activities, thereby
warranting consideration when
evaluating ML/TF risks. For example,
Treasury describes changes in the illicit
finance risk environment in its biennial
National Money Laundering Risk
Assessment, National Terrorist
Financing Risk Assessment, and
National Proliferation Financing Risk
Assessment, which highlight significant
illicit finance threats, vulnerabilities,
and risks.44 Regardless of the source,
banks should take measures in their risk
assessment processes to ensure this
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00009
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18313
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
45 31 U.S.C. 5318(h)(4)(E).
46 FinCEN’s concurrently issued proposal
provides additional clarity on how FinCEN
anticipates addressing the AML/CFT Priorities.
47 31 U.S.C. 5318(h)(2)(B)(iv)(II).
information is reasonably current,
complete, and accurate.
b. AML/CFT Priorities
The AML/CFT Priorities set out the
priorities for the U.S. government’s
AML/CFT policy as required by the
AML Act and are designed to ensure
that banks’ AML/CFT programs are
aligned with those priorities.
Recognizing the diverse nature of ML/
TF threats facing the U.S. financial
system and national security, and that
bank AML/CFT programs benefit U.S.
national security by safeguarding the
financial system from ML/TF risk, the
AML/CFT Priorities are intended to
ensure that banks are focusing on the
greatest threats to U.S. national security,
as defined by Treasury
ed with those priorities.
Recognizing the diverse nature of ML/
TF threats facing the U.S. financial
system and national security, and that
bank AML/CFT programs benefit U.S.
national security by safeguarding the
financial system from ML/TF risk, the
AML/CFT Priorities are intended to
ensure that banks are focusing on the
greatest threats to U.S. national security,
as defined by Treasury.
Section 6101 of the AML Act requires
that a financial institution’s review and
appropriate incorporation of the AML/
CFT Priorities into its AML/CFT
program be subject to supervision and
examination for compliance with the
BSA and other AML/CFT laws and
regulations.45 The Agencies are
implementing this statutory requirement
by proposing that, as part of their risk
assessment processes, banks must
review and, as appropriate, incorporate
the AML/CFT Priorities. The inclusion
of the AML/CFT Priorities in risk
assessment processes is meant to help
ensure that banks understand their
exposure to risks in areas that are of
particular importance nationally, which
may help banks develop risk-based and
reasonably designed AML/CFT
programs.
The Agencies understand that the
AML/CFT Priorities may not always be
applicable to a bank’s risk profile and
activities. Therefore, the Agencies
require the incorporation of the AML/
CFT Priorities in a bank’s risk
assessment processes, as appropriate.
This means that, having reviewed the
AML/CFT Priorities, a bank may
determine the extent to which a
particular Priority is applicable and
whether and how a particular AML/CFT
Priority should be appropriately
incorporated into its risk assessment
processes.
Further, a bank may use its judgment
and apply a reasonable, risk-based
determination on whether to focus on a
specific aspect of an AML/CFT Priority,
rather than addressing all aspects of a
Priority that may either not be
applicable or pose lower risks to the
bank
and
whether and how a particular AML/CFT
Priority should be appropriately
incorporated into its risk assessment
processes.
Further, a bank may use its judgment
and apply a reasonable, risk-based
determination on whether to focus on a
specific aspect of an AML/CFT Priority,
rather than addressing all aspects of a
Priority that may either not be
applicable or pose lower risks to the
bank. However, the Agencies caution
that a surface-level, perfunctory review
of an AML/CFT Priority by a bank and
of the foreseeable ways in which it may
manifest itself within the bank’s
customers, products and services,
geographies, and distribution channels
would not satisfy this requirement. For
example, patterns of transactions that
may be consistent with potential
structuring should not automatically be
dismissed as lower value to law
enforcement and untethered to an AML/
CFT Priority without determining
whether there is a potential connection
to various types of other illicit finance
activity (e.g., structuring or similar
patterns involving transactions in
narcotics trafficking proceeds).
Whenever the AML/CFT Priorities are
updated, banks would no longer be
required to incorporate prior versions of
the AML/CFT Priorities. Banks would
only be required, as appropriate, to
incorporate the most recent AML/CFT
Priorities into their risk-based AML/CFT
programs.
The Agencies anticipate that some
banks, such as community banks, may
ultimately determine that their business
models and risk profiles have limited
exposure to some of the threats
addressed in the AML/CFT Priorities
but instead have greater exposure to
other ML/TF risks. Additionally, some
banks’ risk assessment processes may
determine that their AML/CFT programs
already sufficiently incorporate to some
extent, the AML/CFT Priorities
community banks, may
ultimately determine that their business
models and risk profiles have limited
exposure to some of the threats
addressed in the AML/CFT Priorities
but instead have greater exposure to
other ML/TF risks. Additionally, some
banks’ risk assessment processes may
determine that their AML/CFT programs
already sufficiently incorporate to some
extent, the AML/CFT Priorities. In
either case, any changes to banks’ AML/
CFT program, such as internal policies,
procedures, or controls would be based
on the results of risk assessment
processes and their impact on the AML/
CFT program, including how to review
and, as appropriate, incorporate the
AML/CFT Priorities before making these
determinations.46 The Agencies request
comment from the public on whether
additional guidance related to the
consideration of the AML/CFT Priorities
as part of an institution’s risk
assessment processes would be
warranted.
c. Updates to Risk Assessment Processes
The proposed rule would require
banks to update their risk assessment
processes promptly upon any change
that the bank would know or have
reason to know would significantly
change their ML/TF risk profile. For
example, a bank may need to update its
risk assessment when new products,
services, and customer types are
introduced; existing products, services,
and customer types undergo significant
changes; when the bank adopts new risk
mitigation technology; or the bank as a
whole expands or contracts through
mergers, acquisitions, and divestitures.
Banks may also need to update their risk
assessment processes based on factors
external to their operations that they
know or have reason to know
significantly change their ML/TF risk
profiles. The Agencies welcome
comments on whether it should further
clarify when banks must review or
update their risk assessment processes.
ii
contracts through
mergers, acquisitions, and divestitures.
Banks may also need to update their risk
assessment processes based on factors
external to their operations that they
know or have reason to know
significantly change their ML/TF risk
profiles. The Agencies welcome
comments on whether it should further
clarify when banks must review or
update their risk assessment processes.
ii. Mitigate ML/TF Risks Through Risk-
Based Allocation of Attention and
Resources
Section 6101(b) of the AML Act states
that the AML/CFT programs of financial
institutions should be ‘‘risk-based,
including ensuring that more attention
and resources of financial institutions
should be directed toward higher-risk
customers and activities, consistent
with the risk profile of a financial
institution, rather than toward lower-
risk customers and activities.’’ 47 The
proposed rule would adopt this
formulation as part of a bank’s
obligation to establish a risk-based set of
internal policies, procedures, and
controls. Under the proposed rule, a
bank’s efforts to mitigate its ML/TF risks
would involve ‘‘directing more attention
and resources toward higher-risk
customers and activities, consistent
with the risk profile of [a bank], rather
than toward lower-risk customers and
activities.’’
The Agencies view risk-based
allocation of resources as a critical step
in realizing the AML Act’s BSA
modernization and reform ambitions,
and consistent with the Agencies’
ongoing efforts to modernize AML/CFT
compliance and supervision. The
proposed rule envisions banks
exercising more flexibility in deploying
attention and resources in accordance
with the proposed rule without fear of
supervisory criticism or action from
examiners for directing more attention
and resources on higher risk customers
and activities, rather than toward lower
risk customers and activities
rts to modernize AML/CFT
compliance and supervision. The
proposed rule envisions banks
exercising more flexibility in deploying
attention and resources in accordance
with the proposed rule without fear of
supervisory criticism or action from
examiners for directing more attention
and resources on higher risk customers
and activities, rather than toward lower
risk customers and activities.
The goal of risk-based resource
allocation is for banks to spend less
time, energy, and resources on lower
priority activities that may result in less
resources devoted to and potentially
distract from more serious threats. The
proposed rule would enable banks to
focus more on higher risk customers and
activities, which the Agencies have
determined should result in banks being
more effective at detecting, reporting,
and preventing the flow of illicit funds
and providing law enforcement with
more valuable BSA reporting.
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00010
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18314
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
48 See 31 CFR 1020.210(a)(2)(v) and (b)(2)(v).
49 31 U.S.C. 5318(h)(1)(D).
50 See Federal Reserve Board, FDIC, NCUA, OCC,
and FinCEN, Interagency Statement on Sharing
Bank Secrecy Act Resources (Oct. 3, 2018), https://
www.fincen.gov/news/news-releases/interagency-
statement-sharing-bank-secrecy-act-resources.
As noted above, the Agencies believe
that banks are best positioned to
identify and evaluate their ML/TF risk
and to make decisions related to risk
identification and resource allocation in
accordance with risk identification. The
proposed rule, therefore, does not
contemplate second-guessing of a bank’s
reasonable determinations regarding
appropriate resource allocation or
conclusions regarding specific risks
ncies believe
that banks are best positioned to
identify and evaluate their ML/TF risk
and to make decisions related to risk
identification and resource allocation in
accordance with risk identification. The
proposed rule, therefore, does not
contemplate second-guessing of a bank’s
reasonable determinations regarding
appropriate resource allocation or
conclusions regarding specific risks.
However, while the Agencies do not
believe that an examiner should
substitute his or her own subjective
judgment in place of the bank’s,
examiners will be expected to assess
whether (1) a bank’s resource allocation
decisions are informed by, and
consistent with, reasonably designed
risk assessment processes; and (2) with
respect to implementation, specifically,
whether the bank knows or should
know of resource-related issues
involving its internal policies,
procedures, and controls and other
mandatory elements that may result in
the bank failing to implement its AML/
CFT program in all material respects
and has failed to address such issues.
iii. Conduct Ongoing Customer Due
Diligence
The proposed rule would add CDD as
a required component of the Agencies’
AML/CFT program rule. Appropriate
risk-based procedures for conducting
ongoing CDD—in the form of
understanding the nature and purpose
of customer relationships and
conducting ongoing monitoring—is
currently a required component in
FinCEN’s AML program rule,48 and,
therefore, banks are already required to
comply with these ongoing CDD
requirements under FinCEN’s rule. The
inclusion of risk-based procedures for
conducting ongoing CDD in the
Agencies’ proposed rules would mirror
FinCEN’s existing rule and reflect the
Agencies’ long-standing supervisory
expectations
ing monitoring—is
currently a required component in
FinCEN’s AML program rule,48 and,
therefore, banks are already required to
comply with these ongoing CDD
requirements under FinCEN’s rule. The
inclusion of risk-based procedures for
conducting ongoing CDD in the
Agencies’ proposed rules would mirror
FinCEN’s existing rule and reflect the
Agencies’ long-standing supervisory
expectations. Long before FinCEN
amended its AML program rule to
expressly include the CDD component
requirement, the Agencies had
considered CDD an integral component
of a risk-based program, enabling the
bank to understand its customers and its
customers’ activity to better identify
suspicious activity. Adding the CDD
component to the Agencies’ AML/CFT
program rule will eliminate confusion
for banks concerning the current
differences with FinCEN’s rule. Because
banks must already comply with
FinCEN’s CDD component requirement,
the proposed change should not alter
current compliance practices.
The proposed rule would incorporate
CDD requirements not as a standalone
pillar, but instead by making them part
of the requirement that banks establish
a risk-based and reasonably designed set
of internal policies, procedures, and
controls. As noted previously, the
activities required to conduct ongoing
CDD, such as monitoring customer
relationships, maintaining and updating
customer information on a risk basis,
and identifying and reporting
suspicious transactions are, in practice,
subsumed by the obligation for a bank
to have a risk-based and reasonably
designed set of internal policies,
procedures, and controls and have long
been viewed by the Agencies as integral
to component of a bank’s internal
controls. Accordingly, establishing these
requirements within this pillar more
accurately reflects how banks
operationalize ongoing customer due
diligence as part of their overall AML
programs.
2
r a bank
to have a risk-based and reasonably
designed set of internal policies,
procedures, and controls and have long
been viewed by the Agencies as integral
to component of a bank’s internal
controls. Accordingly, establishing these
requirements within this pillar more
accurately reflects how banks
operationalize ongoing customer due
diligence as part of their overall AML
programs.
2. Independent Testing
The Agencies have required banks to
perform independent testing since the
original adoption of their BSA
compliance program rules. The AML
Act did not change the BSA’s separate
requirement that each bank must
independently test its AML/CFT
program.49 The proposed rule therefore
retains the existing requirement for
banks to establish independent AML/
CFT program testing to be conducted by
bank personnel or an outside party with
minor, non-substantive clarifications
that are not intended to change
regulatory requirements.
The purpose of independent testing is
to assess the bank’s compliance with
AML/CFT statutory and regulatory
requirements, relative to its risk profile.
The independent AML/CFT program
testing should be focused on whether
the AML/CFT program is effective, and
it should identify issues and areas for
remediation accordingly.
To support the effective
implementations of an AML/CFT
program, independent testing should be
based on objective criteria designed to
assess whether a bank has established
and implemented an effective AML/CFT
program and allocated resources
consistent with its risk assessment
processes. These criteria should also
assess whether related project
governance is sufficient to manage risks
and apply compensating controls where
necessary, particularly in areas where
remediation is underway. This
evaluation helps to inform the bank’s
board of directors and senior
management of weaknesses or areas in
need of enhancement or stronger
controls
t with its risk assessment
processes. These criteria should also
assess whether related project
governance is sufficient to manage risks
and apply compensating controls where
necessary, particularly in areas where
remediation is underway. This
evaluation helps to inform the bank’s
board of directors and senior
management of weaknesses or areas in
need of enhancement or stronger
controls. Typically, this evaluation
includes a conclusion about the bank’s
overall compliance with AML/CFT
statutory and regulatory requirements
and sufficient information for the
reviewer (e.g., board of directors, senior
management, AML/CFT officer, outside
auditor, or an examiner) to reach a
conclusion about whether the set of
internal policies, procedures, and
controls is reasonably-designed, and
resources are well-allocated consistent
with the bank’s risk assessment
processes.
Additionally, while banks retain some
flexibility regarding who conducts the
audit or testing, the proposed rule
would continue to require that testing
be independent. Banks that do not
employ outside auditors or consultants
or that do not have internal audit
departments may comply with this
requirement by using internal staff who
are not involved in the function being
tested. For these banks and banks with
other types of arrangements for
independent testing, the AML/CFT
officer or any party who directly, and in
some cases indirectly, reports to the
AML/CFT officer, or an equivalent role,
would generally not be considered
sufficiently independent. Any
individual conducting the testing,
whether internal or external, would be
required to be independent of other
parts of the bank’s AML/CFT program,
including its oversight
r
independent testing, the AML/CFT
officer or any party who directly, and in
some cases indirectly, reports to the
AML/CFT officer, or an equivalent role,
would generally not be considered
sufficiently independent. Any
individual conducting the testing,
whether internal or external, would be
required to be independent of other
parts of the bank’s AML/CFT program,
including its oversight. For banks that
engage outside auditors or consultants,
the bank would be required to ensure
that the outside parties conducting the
independent testing are not involved in
functions related to the AML/CFT
program at the bank that may present a
conflict of interest or lack of
independence, such as AML/CFT
training or the development or
enhancement of internal policies,
procedures, and controls. Additionally,
for the purposes of the independent
testing component, outside parties
would not include government agencies,
entities, or instrumentalities, such as a
bank’s Federal or state functional
regulators. Banks with less complex
operations and lower risk profiles may
consider utilizing a shared resource as
part of a collaborative arrangement to
conduct testing, as long as the testing is
independent.50
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00011
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18315
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
51 31 U.S.C. 5318(h)(5).
52 See, e.g., FinCEN, Financial Crimes
Enforcement Network; Confidentiality of
Suspicious Activity Reports, 75 FR 75593 (Dec. 3,
2010); see also FinCEN, Interagency Guidance on
Sharing Suspicious Activity Reports with Head
Offices and Controlling Companies (Jan. 20, 2006),
https://www.fincen.gov/system/files/guidance/
sarsharingguidance01122006.pdf.
53 31 U.S.C. 5318(h)(1)(C).
54 12 CFR 21.21(d) (OCC); 12 CFR 326.8 (FDIC);
and 12 CFR 748.2 (NCUA)
Confidentiality of
Suspicious Activity Reports, 75 FR 75593 (Dec. 3,
2010); see also FinCEN, Interagency Guidance on
Sharing Suspicious Activity Reports with Head
Offices and Controlling Companies (Jan. 20, 2006),
https://www.fincen.gov/system/files/guidance/
sarsharingguidance01122006.pdf.
53 31 U.S.C. 5318(h)(1)(C).
54 12 CFR 21.21(d) (OCC); 12 CFR 326.8 (FDIC);
and 12 CFR 748.2 (NCUA).
55 Other financial regulators with stakeholders
subject to the BSA currently utilize their own
versions of this requirement. See 31 CFR
1020.210(a)(2)(iv), (b)(2)(iv) (banks);
1021.210(b)(2)(iii) (casinos); 1022.210(d)(3) (MSBs);
1023.210(b)(4) (broker-dealers); 1024.210(b)(4)
(mutual funds); 1025.210(b)(3) (insurance
companies); 1026.210(b)(4) (FCMs and IBCs);
1027.210(b)(3) (DPMSJs); 1028.210(b)(3) (operators
of credit card systems); 1029.210(b)(3) (loan or
finance companies); 1030.210(b)(3) (housing GSEs).
3. Designate an AML/CFT Officer
Located in the United States
i. Duties of the AML/CFT Officer
The Agencies have required banks to
‘‘designate an individual or individuals
responsible for coordinating and
monitoring day-to-day compliance’’
since the inception of their program
requirements. The BSA separately
requires that banks with AML/CFT
program obligations must have a
designated compliance officer, which
was not altered by the AML Act. As in
the Agencies’ current BSA compliance
program rules, the proposed rule would
provide that an AML/CFT program must
designate an individual(s) (referred to as
an AML/CFT officer) responsible for
establishing and implementing the
AML/CFT program and coordinating
and monitoring day-to-day compliance
with the requirements and prohibitions
of the BSA and FinCEN’s implementing
regulations. The Agencies’ view is that
the individual serving as the AML/CFT
officer must be qualified for that role
and not overburdened with other
responsibilities at the institution
officer) responsible for
establishing and implementing the
AML/CFT program and coordinating
and monitoring day-to-day compliance
with the requirements and prohibitions
of the BSA and FinCEN’s implementing
regulations. The Agencies’ view is that
the individual serving as the AML/CFT
officer must be qualified for that role
and not overburdened with other
responsibilities at the institution. The
Agencies are proposing clarifying and
technical changes to the AML/CFT
officer requirement, as well as changes
to incorporate to FinCEN’s
interpretation of 31 U.S.C. 5318(h)(5), as
discussed below. These changes are
generally not expected to impose new
obligations on banks.
Consistent with current requirements,
the proposed rule is not intended to be
primarily concerned about the formal
title of the individual(s) responsible for
establishing and implementing the
AML/CFT program and coordinating
and monitoring day-to-day compliance;
instead, the proposed rule focuses on
the AML/CFT officer’s position in the
bank’s organizational structure that
enables the AML/CFT officer to
effectively establish and implement the
bank’s AML/CFT program. The AML/
CFT officer’s authority, independence,
and access to resources within the bank
are critical. An AML/CFT officer should
have decision-making capability
regarding the AML/CFT program and
sufficient functional stature within the
organization to ensure that the program
meets BSA requirements.
The AML/CFT officer’s access to
resources may include: adequate
compliance funds and staffing with the
skills and expertise appropriate to the
bank’s risk profile, size, and complexity;
an organizational structure that supports
compliance and effectiveness; and
sufficient technology and systems to
support the timely identification,
measurement, monitoring, reporting,
and management of the bank’s ML/TF
risks
access to
resources may include: adequate
compliance funds and staffing with the
skills and expertise appropriate to the
bank’s risk profile, size, and complexity;
an organizational structure that supports
compliance and effectiveness; and
sufficient technology and systems to
support the timely identification,
measurement, monitoring, reporting,
and management of the bank’s ML/TF
risks. An AML/CFT officer with
conflicting responsibilities that
adversely impact the officer’s ability to
effectively coordinate and monitor day-
to-day AML/CFT compliance generally
would not fulfill this requirement. The
addition of the explicit requirement that
the AML/CFT officer be responsible for
‘‘establishing and implementing the
AML/CFT program’’ in the proposed
rule would make explicit a long-
standing supervisory expectation, rather
than changing current supervisory
expectations.
ii. The AML/CFT Officer Must Be
Located in the United States and
Accessible to Regulators
The AML Act provides that the duty
to establish, maintain, and enforce a
bank’s AML/CFT program shall remain
the responsibility of, and be performed
by, persons in the United States who are
accessible to, and subject to oversight
and supervision by, the Secretary and
the appropriate Federal functional
regulator.51 Because this is a new
requirement under the AML Act, it is
not currently reflected in the Agencies’
program rule requirements. FinCEN’s
concurrently proposed revisions to its
AML/CFT program rules interpret this
requirement as applying to the AML/
CFT officer, so the Agencies’ proposed
rule would amend the existing
compliance officer requirements to align
with FinCEN’s proposal.
The Agencies recognize banks may
currently have AML/CFT staff and
operations outside of the United States,
or they may contract out or delegate
parts of their AML/CFT operations to
third-party providers located outside of
the United States
ing to the AML/
CFT officer, so the Agencies’ proposed
rule would amend the existing
compliance officer requirements to align
with FinCEN’s proposal.
The Agencies recognize banks may
currently have AML/CFT staff and
operations outside of the United States,
or they may contract out or delegate
parts of their AML/CFT operations to
third-party providers located outside of
the United States. These arrangements
may serve to improve cost efficiencies;
to enhance coordination, particularly
with respect to cross-border operations;
or serve other purposes not in conflict
with goals underlying the BSA.
Consequently, under the proposed rule,
while the AML/CFT officer must be
located in the United States, personnel
located outside of the United States
would still be permitted to perform
certain AML/CFT functions. This
language does not alter existing
regulations and guidance that generally
prohibit the sharing of SARs with
personnel located outside of the United
States, other than in limited
circumstances such as a bank’s foreign
head office or controlling company.52
The Agencies request comment on
whether any further clarifications on
this point would be useful.
4. Ongoing Employee Training Program
The BSA requires AML/CFT programs
to include an ‘‘ongoing employee
training program.’’ 53 This statutory
requirement is reflected in all current
Agency program rules employing
different wording.54 The proposed rule
would harmonize the Agencies’ program
rules with that of other financial
regulators by adopting the BSA’s
‘‘ongoing employee training program’’
language uniformly.55 This change is
clarifying, not substantive.
The Agencies would generally expect
training to cover a bank’s internal
policies, procedures, and controls,
which should in turn reflect the results
of the bank’s risk assessment processes,
the latest AML/CFT regulatory
requirements, and other relevant
information
y adopting the BSA’s
‘‘ongoing employee training program’’
language uniformly.55 This change is
clarifying, not substantive.
The Agencies would generally expect
training to cover a bank’s internal
policies, procedures, and controls,
which should in turn reflect the results
of the bank’s risk assessment processes,
the latest AML/CFT regulatory
requirements, and other relevant
information. The frequency with which
the training would occur, and the
content of the training, would depend
on the bank’s ML/TF risk profile and the
roles and responsibilities of the persons
receiving the training. The Agencies
welcome comment on whether any
further clarifications of the proposed
training requirement are needed and
recognize that banks may have
employees and non-employees who may
have a variety of roles and
responsibilities in relation to the AML/
CFT program. The risk-based nature of
an AML/CFT program provides
flexibility for financial institutions to
identify both employees and non-
employees who must be trained on an
ongoing basis.
E. Access to and Approval of a Written
AML/CFT Program
1. Written AML/CFT Programs Must Be
Made Available Upon Request
The Agencies’ current BSA
compliance program rule generally
requires a bank to have a written AML/
CFT program that is approved by the
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00012
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1
pproval of a Written
AML/CFT Program
1. Written AML/CFT Programs Must Be
Made Available Upon Request
The Agencies’ current BSA
compliance program rule generally
requires a bank to have a written AML/
CFT program that is approved by the
VerDate Sep<11>2014
16:45 Apr 09, 2026
Jkt 268001
PO 00000
Frm 00012
Fmt 4702
Sfmt 4702
E:\FR\FM\10APP1.SGM
10APP1
lotter on DSK8BHNXB4PROD with PROPOSALS1

18316
Federal Register / Vol. 91, No. 69 / Friday, April 10, 2026 / Proposed Rules
56 See 12 CFR 21.21(c)(1) (OCC), 326.8(b)(1)
(FDIC), and 748.2(b)(1) (NCUA).
57 See 12 CFR 1020.210(b)(3).
58 The proposal would not be intended to affect
or restrict criminal enforcement under the BSA or
the authority of the Department of Justice to pursue
such actions.
bank’s board of directors.56 The
proposed rule would modify these
requirements and move them to a
separate subsection and add clarifying
text to harmonize the language with
FinCEN’s proposed rule. The Agencies
request comment on whether further
clarification on this point would be
useful.
2. Bank Approval of a Written AML/
CFT Program
Banks subject to Agency supervision
currently must have board approval for
their AML/CFT programs under the
Agencies’ rules. The proposed rule
would continue to require that a bank’s
written AML/CFT program be approved,
though the proposal will expand the
options available for a bank to obtain
such approval. Specifically, the
proposed rule will require that the
AML/CFT program be approved by the
bank’s board of directors or an
equivalent governing body within the
bank, or appropriate senior
management. The proposed rule
specifies that approval encompasses
each of the components of the AML/
CFT program
though the proposal will expand the
options available for a bank to obtain
such approval. Specifically, the
proposed rule will require that the
AML/CFT program be approved by the
bank’s board of directors or an
equivalent governing body within the
bank, or appropriate senior
management. The proposed rule
specifies that approval encompasses
each of the components of the AML/
CFT program.
With respect to the new ‘‘equivalent
governing body’’ language, FinCEN’s
current rule requires a bank lacking a
Federal functional regulator to obtain
approval of the bank’s written AML
program from either the bank’s board or
an equivalent governing body.57 The
Agencies’ proposed rule would also add
a reference to an ‘‘equivalent governing
body’’ to clarify that a bank can satisfy
the requirement by having an equivalent
governing body approve the program.
The equivalent governing body can take
different forms. For example, for the
U.S. branch of a foreign bank, the

[Text truncated at 120,000 characters. The full text is on the page linked above.]

## Nearby sections

- [FDIC FIL-1-2002 FOREIGN ASSETS CONTROL ACT](https://www.frixlaw.com/law-library/statutes/FDIC_FIL02001.md)
- [FDIC FIL-1-2010 Employee Compensation Advance Notice of Proposed Rulemaking](https://www.frixlaw.com/law-library/statutes/FDIC_FIL10001.md)
- [FDIC FIL-1-2024 Consolidated Reports of Condition and Income for Fourth Quarter 2023](https://www.frixlaw.com/law-library/statutes/FDIC_FIL24001.md)
- [FDIC FIL-2-2004 Foreign Assets Control Act](https://www.frixlaw.com/law-library/statutes/FDIC_FIL04002.md)
- [FDIC FIL-2-2020 Consolidated Reports of Condition and Income for Fourth Quarter 2019](https://www.frixlaw.com/law-library/statutes/FDIC_FIL20002.md)
- [FDIC FIL-3-2003 FILING PROCEDURES](https://www.frixlaw.com/law-library/statutes/FDIC_FIL03003.md)
- [FDIC FIL-4-2006 Commercial Real Estate Lending Proposed Interagency Guidance](https://www.frixlaw.com/law-library/statutes/FDIC_FIL06004.md)
- [FDIC FIL-4-2021 Revised Guidelines for Appeals of Material Supervisory Determinations](https://www.frixlaw.com/law-library/statutes/FDIC_FIL21004.md)
- [FDIC FIL-4-2023 Guidance to Help Financial Institutions and Facilitate Recovery in Areas of California Affected by Severe Winter Storms, Flooding, Landslides and Mudslides](https://www.frixlaw.com/law-library/statutes/FDIC_FIL23004.md)
- [FDIC FIL-4-2025 FDIC Statement of Policy on Bank Merger Transactions](https://www.frixlaw.com/law-library/statutes/FDIC_FIL25004.md)
- [FDIC FIL-5-2000 Consumer Credit Reporting Practices](https://www.frixlaw.com/law-library/statutes/FDIC_FIL00005.md)
- [FDIC FIL-5-2003 LETTER TO STAKEHOLDERS](https://www.frixlaw.com/law-library/statutes/FDIC_FIL03005.md)
- [FDIC FIL-5-2021 Frequently Asked Questions Regarding Suspicious Activity Reporting and Other Anti-Money Laundering (AML) Considerations](https://www.frixlaw.com/law-library/statutes/FDIC_FIL21005.md)
- [FDIC FIL-6-2000 Special Alert](https://www.frixlaw.com/law-library/statutes/FDIC_FIL00006.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/FDIC_FIL26012. Check the current official text before relying on it. Not legal advice.
