Skip to main content

FinCEN's 2026 AML Overhaul: What the Shift to Risk-Based Compliance Means for MSBs and Fintechs

Published 14 min readMike ThriftMike Thrift
FinCEN's 2026 AML Overhaul: What the Shift to Risk-Based Compliance Means for MSBs and Fintechs

If you run a money transmitter, check casher, neobank, payment app, or any fintech that touches customer funds, the way regulators judge your anti-money laundering program is about to change — and it could actually get more sensible.

On April 7, 2026, the Financial Crimes Enforcement Network proposed a rule that it calls a fundamental reform of financial institutions' anti-money laundering and countering the financing of terrorism (AML/CFT) programs under the Bank Secrecy Act. The message from Treasury was blunt: for too long, success was measured by paperwork volume, not by whether bad actors were kept out. The new direction would measure you on effectiveness, let you aim resources where risk is highest, and stop examiners from second-guessing every reasonable judgment you made in good faith.

For money services businesses and fintechs — where BSA obligations hit hard relative to headcount and where a single large customer type can define your entire risk profile — that shift matters. Here is what the proposal would do, why it supersedes the July 2024 draft, and how to get your program and your books ready before it becomes final.

Why This Is Happening Now

The Bank Secrecy Act dates to 1970. It requires every "financial institution," including banks, broker-dealers, casinos, insurers, and money services businesses, to maintain an AML program reasonably designed to prevent and detect money laundering and terrorist financing, file Currency Transaction Reports and Suspicious Activity Reports, and keep records examiners can test.

For years, examiners and institutions have disagreed about what "reasonably designed" means in practice. Many institutions responded by building check-the-box programs — thick manuals, universal monitoring thresholds, and exhaustive low-risk customer reviews — to avoid criticism. FinCEN says that approach generated low-value filings and spread resources thin.

Congress tried to reset the balance with the Anti-Money Laundering Act of 2020 (AMLA), enacted as part of the National Defense Authorization Act. AMLA told FinCEN to streamline, modernize, and update the AML/CFT regime, encourage innovation and technology adoption, and make supervision more risk-based and outcomes-focused. It also required that national AML/CFT priorities be published and that programs be "effective and reasonably designed" — not just technically complete.

FinCEN's July 3, 2024 proposal started that implementation. The April 2026 proposal withdraws the 2024 draft entirely and replaces it with a cleaner framework that aligns with AMLA, codifies the effectiveness standard, and adds guardrails on how supervisors can critique your program. The comment period closed June 9, 2026, and the three federal banking agencies issued a parallel banking-agency proposal on the same day. A final rule is expected after comments are digested, and the Federal Reserve followed with its own largely conforming draft in the summer.

In other words: this is not a tweak. It is the biggest rewrite of AML program rules since the USA PATRIOT Act amendments.

The Core Idea: Effective and Reasonably Designed, Not Perfect

The proposal replaces "check every box" with two linked standards.

1. Your program must be reasonably designed. That means it is tailored to your actual illicit-finance risks — your customers, products and services, delivery channels, and geographies — and built to achieve the purposes of the BSA. A small MSB doing domestic remittances to one corridor, a crypto on-ramp, and an employer-of-record fintech with scattered contractor payouts should not have identical programs, even if they are all "financial institutions."

2. Your program must be effective in operation. Design is not enough. You have to implement what you designed, monitor whether it works, and fix gaps.

Why split the concepts? Today, an examiner's finding might blur the two: a single missed alert or a formatting error in a manual could be cited as a program deficiency. Under the new two-prong structure, FinCEN wants supervisors to distinguish a design shortfall (your risk assessment missed an entire product line, you have no controls for a known risk) from an implementation shortfall (you designed the right control but staff did not follow it consistently). The distinction matters because only significant or systemic failures to implement an otherwise properly established program would warrant a formal AML/CFT enforcement or significant supervisory action. An isolated operational slip would be treated as an implementation matter to be remediated, not automatically as a violation that threatens your charter or MSB registration.

That is a consequential change for smaller firms. It gives you room to make good-faith, risk-based calls without living in fear that an examiner will retroactively redesign your program in the exit meeting.

The Five Reforms That Matter Most

The proposal makes five interconnected changes.

1. You own the risk assessment — and you must document it

The rule reinforces that you are best positioned to identify and evaluate your illicit-finance risks. It requires a risk assessment process as part of your internal policies, procedures, and controls. That assessment must consider the AML/CFT priorities FinCEN publishes, along with your specific customers, products, geographies, and distribution channels.

For MSBs and fintechs, document at least:

  • Customer types (consumers vs. businesses, domestic vs. non-resident, PEPs, cash-intensive businesses)
  • Products (money transmission, currency exchange, virtual currency, bill pay, agent locations)
  • Delivery channels (in-person, mobile, API, agent network, white-label partners)
  • Geographies (border corridors, high-risk jurisdictions, sanctions-exposed regions)
  • Transaction characteristics (cash funding, rapid movement, structuring patterns)

Update the assessment when you add a corridor, launch a token, sign a large agent, or enter a new state. A stale annual memo that says "low risk" will not survive an effectiveness review.

2. You can — and should — prioritize higher risks

The proposal explicitly empowers you to devote more attention and resources to higher risks and proportionately less to lower risks. That is permission to tier customers, set risk-based monitoring thresholds, and concentrate enhanced due diligence where it matters.

Example: a check casher whose primary customers are local payroll checks might spend far more time monitoring walk-in cash exchange and cross-border cash shipments than reviewing repetitive, verified business payroll deposits from the same employer every two weeks. A fintech sponsoring a partner bank program might focus transaction monitoring on high-velocity crypto off-ramps rather than on low-value, recurring subscription charges.

Prioritization is not a license to ignore low-risk areas. It means your intensity varies with risk, and your documentation explains why.

3. Examiners cannot substitute their judgment for yours

This is the paragraph most compliance officers underlined.

The proposal clarifies expectations for independent testing and audit functions: examiners and auditors should not substitute their subjective judgment in place of your risk-based, reasonably designed program. If your program is reasonable and you followed it, a supervisor should not cite you because they would have weighed a risk differently.

Independent testing still matters — in fact, it becomes more important as proof that your reasonable design is working. But the test is whether the program is reasonable, not whether it matches an examiner's personal playbook.

4. Design vs. implementation gets its own framework

As noted above, the rule would codify the two-prong evaluation and promote consistent articulation of findings. Supervisors would need to state whether a criticism is about design or about day-to-day implementation. That discipline is meant to stop the common conflation where every file error becomes a "program violation" and to make remediation more targeted.

For your records, mirror that structure internally. Tag findings, audit issues, and QA reviews as "Design" or "Implementation" and track remediation separately. It will make your exam responses and your board minutes much clearer.

5. FinCEN takes a stronger coordination role

The proposal affirms FinCEN's central role in AML/CFT supervision and introduces a notice-and-consultation framework between FinCEN and the federal banking supervisors for significant AML/CFT supervisory actions. For bank-fintech partnerships, that could mean fewer surprises where a prudential regulator and FinCEN apply different lenses to the same BaaS program.

The 2026 MSB context makes this timely. In January 2026, FinCEN announced a multi-tier operation targeting more than 100 MSBs along the southwest border for potential BSA/AML noncompliance, reminding MSBs that effective risk-based programs, customer identification, transaction monitoring, timely reporting, and agent oversight are not optional even for small storefront operators. A clearer consultation framework may reduce inconsistent signals while that enforcement focus continues.

What "Risk-Based" Actually Looks Like in Practice

A risk-based program is not a thinner program. It is a better-documented, better-aligned program. Under the proposal, every covered financial institution — banks, MSBs, broker-dealers, casinos, and others — would need a framework that includes these core pillars:

  • Internal policies, procedures, and controls incorporating a risk assessment and risk management that tie directly to the risks identified.
  • A designated BSA/AML officer with authority, resources, and access to leadership.
  • Ongoing training tailored to the people executing the controls, not generic annual slides.
  • Independent testing with a credible scope, frequency, and reporting line. Independence does not require outsourcing if you can demonstrate objectivity, but for many fintechs, an external review every 12–18 months remains the cleanest evidence.

Build those pillars around your risks, and evidence each with records an examiner can follow without you in the room:

  • Risk assessment with methodology, data sources, and approval dates
  • Customer risk rating criteria and periodic re-rating logic
  • Product approval checklist that includes BSA/AML review
  • Transaction monitoring rules with thresholds, tuning history, and disposition rationale
  • Alert aging, escalation, and SAR decision documentation
  • Agent or partner oversight files (for MSB principals): onboarding due diligence, site visits or remote monitoring, volume and exception reporting, termination history

A Preparation Checklist for MSBs, Money Transmitters, and Fintechs

You do not need to wait for a final rule to tighten the program. The direction is clear, and examiners are already asking risk-based questions.

1. Re-run your risk assessment this quarter

Pull 12 months of transactions, segment by product, corridor, customer type, and channel, and compare to what your last assessment says. If you added a product since the last assessment, you found your first update.

2. Write a one-page risk appetite statement

Get board or owner sign-off on what you will and will not do. Examples: maximum cash funding per day, prohibited customer categories, required enhanced due diligence triggers. This makes every downstream decision auditable.

3. Tier your customers and your controls

Define at least three risk tiers with distinct onboarding, monitoring, and review requirements. Document why a customer sits in a tier and when they move.

4. Re-tune monitoring around higher risks

Review alert-to-SAR conversion rates. If 90% of alerts are from low-risk recurring activity, your thresholds are misaligned. Shift tuning time to the typologies FinCEN highlights in its priorities and advisories — fraud, cybercrime, and illicit-finance patterns tied to your services.

5. Fix agent and partner oversight files

MSB principals are responsible for agents. FinCEN guidance has long said principals must monitor agents to understand associated risks. For each agent or API partner, keep due diligence, training records, volume reports, and evidence of periodic review. One MSB examination trend is to trace a suspicious corridor back to a single agent with no file — do not be that case.

6. Harden independent testing

Scope testing around your documented risks, not a template. Ensure testers have independence and can opine on both design and implementation. Track findings to closure with owner, due date, and evidence.

7. Separate design issues from implementation slips in your QA

When QA samples alerts, tag errors. A missing narrative field is implementation; a rule that never fires on a known typology is design. Plotting them separately will tell you whether to retrain staff or rewrite a control.

8. Build examiner-ready documentation

For every major control, keep: purpose, risk link, procedure, owner, system relied on, and evidence of operation. If you cannot explain a control's risk link in two sentences, rewrite it.

9. Align financial reporting with compliance reporting

Reconcile MSB agent commissions, fee income, and 1099 or other tax documents to gross transaction reports. FinCEN expects that currency transaction and suspicious activity reporting ties back to what accounting shows happened.

10. Comment and plan for the final rule

If a requirement is unworkable for your model, the time to say so was the comment period that ended June 9, 2026. Now, build an implementation timeline that assumes a 6- to 12-month window after publication of the final rule and prioritize items that improve effectiveness regardless of the exact regulatory text.

Bookkeeping and Operational Details That Examiners Actually Check

AML is often treated as a compliance-only topic, but your ledger and back-office processes either support the program or undermine it.

  • Cash and settlement reconciliation. Reconcile daily cash, bank settlement, and agent or partner net-settlement reports to the transaction system. Out-of-balance cash is often the first sign of a control failure.
  • SAR and CTR timeliness. Track filing deadlines in your close calendar. A SAR is generally due within 30 days, with a 30-day extension if no suspect is identified; CTRs are due within 15 days. Late filings are easy implementation findings.
  • Fee and reserve accounting. For money transmitters using rolling reserves or prefunding, book reserves as restricted cash, not revenue, and reconcile them independently. Examiners will ask who controls reserve releases.
  • Agent ledger discipline. If you are a principal, maintain a subledger per agent with volumes, commissions, chargebacks, and exceptions. If you are an agent, reconcile principal statements to bank deposits weekly.
  • Audit trail retention. Keep risk assessments, board minutes, training attendance, testing reports, and alert dispositions for at least five years, stored where access is logged and versions are preserved.

This is where plain-text accounting helps small teams. When every transaction, adjustment, and correction lives in a version-controlled ledger you can diff, search, and reproduce without a proprietary database, answering "what happened to this customer’s transactions last March and who approved the rule change?" becomes a ten-second query instead of a two-week scramble.

Common Mistakes to Avoid

  • Treating the 2026 proposal as optional. Even before a final rule, supervisors are applying the effectiveness lens. The southwest border MSB operation is a reminder that FinCEN is actively testing whether smaller firms have effective programs, not just manuals.
  • Copying a bank's program. A community bank's risk assessment will not fit a cross-border remittance MSB or a stablecoin-adjacent fintech. Examiners notice templates.
  • Equating low transaction volume with low risk. A low-volume corridor to a high-risk jurisdiction can be higher risk than high-volume domestic payroll.
  • Under-documenting reasonable judgments. If you rated a customer as low risk despite a higher-risk geography because of verified employer payroll and controls, write that rationale at the time of decision.
  • Letting independent testing be a formality. A clean testing report that never touches your highest-risk product will not protect you.

What Stays the Same

Even under a more flexible regime, the fundamentals do not change:

  • You still must have a written AML/CFT program.
  • You still must file SARs and CTRs, maintain records, and respond to law-enforcement requests.
  • You still must designate a BSA officer, train staff, and test independently.
  • You still must apply customer identification and, where applicable, customer due diligence and beneficial-ownership expectations.
  • Civil and criminal penalties for willful violations remain severe.

The reform changes how your program is judged and clarifies where you have discretion; it does not remove the obligation to have a serious program.

Timeline and What to Watch Next

  • April 7, 2026: FinCEN NPRM issued; banking-agency NPRM issued the same day; FinCEN withdrew the July 3, 2024 proposal.
  • June 9, 2026: Comment deadline for the FinCEN NPRM.
  • Summer 2026: Federal Reserve issued its own largely conforming proposal; comment period for that draft closed later in the summer.
  • Next: FinCEN will review comments and publish a final rule. Watch for the notice-and-consultation details, the final wording on "significant or systemic" implementation failures, and any adjustment to the pillar descriptions for non-bank financial institutions.

Budget one workstream for "design" fixes (risk assessment, policies, tiering) and one for "implementation" fixes (training, monitoring tuning, QA). That mapping lets you show an examiner progress on both prongs even before the final rule lands.

Simplify Your Financial Management

Rebuilding your AML/CFT program around real risk — not just volume — is easier when your financial data is transparent, reconciled, and fully auditable. Beancount.io provides plain-text accounting that is version-controlled, human-readable, and AI-ready, so you can trace every fee, settlement, and reserve adjustment without black-box software. Get started for free and give your next exam a ledger you can explain line by line.

Share this article