Skip to main content

FinCEN Delayed the Investment Adviser AML Rule to 2028. The Clock Is Still Running.

Published 10 min readMike ThriftMike Thrift
FinCEN Delayed the Investment Adviser AML Rule to 2028. The Clock Is Still Running.

If you run an SEC-registered investment advisory firm, the last day of 2025 brought a quiet reprieve: FinCEN formally pushed the effective date of its anti-money laundering rule for investment advisers from January 1, 2026 to January 1, 2028. Two extra years, just as the original deadline arrived.

Here's the catch: a program that takes most firms 12 to 18 months to build now has a 24-month fuse. Advisers who treat the delay as a vacation will spend 2027 scrambling. Advisers who treat it as a runway will arrive at the deadline with a tested program, trained staff, and clean records — and will have spent the interim years actually reducing their exposure to the fraud and illicit-finance risks the rule was written to catch.

This guide covers what was delayed, who it covers, what the rule will demand when it lands, and a practical month-by-month way to use the time.

What Actually Happened

In August 2024, FinCEN finalized a rule that added certain investment advisers to the definition of "financial institution" under the Bank Secrecy Act (BSA). That single definitional change pulled advisers into the same anti-money laundering and countering-the-financing-of-terrorism (AML/CFT) regime that banks and broker-dealers have operated under for decades — a first for the advisory industry, after earlier FinCEN proposals in 2002, 2003, and 2015 were each shelved without being finalized.

The 2024 rule carried a January 1, 2026 compliance date. Then the timeline slipped in stages:

  • July 2025 — Treasury announced it intended to postpone and review the rule.
  • August 2025 — FinCEN issued exemptive relief so no adviser would be examined against the rule while the review proceeded.
  • September 2025 — FinCEN formally proposed the two-year delay.
  • December 31, 2025 — the final rule landed: the new effective date is January 1, 2028.

Two things in the delay notice matter more than the date itself. First, FinCEN said it will use the time to review and re-tailor the rule to the diverse business models and risk profiles across the adviser sector — meaning some requirements may still change, probably around the edges rather than at the core. Second, FinCEN plans to coordinate timing with the long-pending Customer Identification Program (CIP) rule for advisers, a joint rulemaking with the SEC that will add formal customer-ID verification duties on top. The agency estimated the delay defers more than $1 billion in near-term compliance costs across the industry — real money, and a hint at the size of the build ahead for each firm.

Who's Covered — and Who Isn't

The rule reaches two categories:

  • SEC-registered investment advisers (RIAs) — roughly 14,000 firms, most of them small businesses with a handful of employees.
  • Exempt reporting advisers (ERAs) — advisers that report to the SEC but are exempt from full registration, principally venture capital fund advisers (Section 203(l)) and private fund advisers with under $150 million in U.S. assets under management (Section 203(m)). Roughly 6,000 more firms.

Together that's on the order of 20,000 firms overseeing well over $100 trillion in client assets.

Just as important is who's out: state-registered advisers, foreign private advisers, family offices, mid-sized advisers registered with states, pension consultants, and RIAs that report zero AUM on Form ADV are all excluded as the rule is currently written. If you're not sure where you land, your Form ADV filing status answers the question.

One caveat for the excluded: "not covered" doesn't mean "untouched." Banks, broker-dealers, and fund administrators that are BSA-covered increasingly push AML expectations onto their counterparties. If your custodian or administrator asks for your AML policy as part of onboarding or annual review, a written program is fast becoming table stakes regardless of your registration status.

What the Rule Will Require When It Lands

The delay changed the date, not the substance. Assuming the core survives FinCEN's re-tailoring review, covered advisers will need:

A written, risk-based AML/CFT program

The classic five pillars, sized to your firm:

  1. Internal policies, procedures, and controls designed around your actual risk profile — your client types, the strategies and products you advise on, your geographies, and how money moves in and out of the accounts you touch.
  2. Independent testing of the program, by your own personnel not involved in running it or by a qualified outside party.
  3. A designated AML/CFT compliance officer (or committee) with real authority and organizational stature. At a five-person RIA this will be a hat someone wears — the rule allows that — but the designation must be explicit.
  4. Ongoing employee training, extended to any third parties administering parts of the program.
  5. Risk-based customer due diligence (CDD) — understanding the nature and purpose of each client relationship, building a risk profile, and monitoring against it. Collecting beneficial-ownership information is a risk-based judgment under this rule, pending the separate CIP rulemaking.

The program needs formal approval from your board or its equivalent. You may delegate administration to a fund administrator or compliance vendor — but legal liability stays with you, so "the administrator handles it" is not a defense.

Suspicious Activity Reports at $5,000

The biggest operational change. Advisers will file SARs with FinCEN on transactions conducted or attempted that involve or aggregate at least $5,000 when the adviser knows, suspects, or has reason to suspect the funds come from illegal activity, are structured to evade BSA requirements, have no business or apparent lawful purpose, or use the adviser to facilitate crime. The filing deadline is 30 days from initial detection, the existence of a SAR is strictly confidential, and supporting documentation must be retained for five years.

Currency Transaction Reports above $10,000

Cash transactions over $10,000 will require a CTR — replacing the Form 8300 obligation advisers already have — and structuring client deposits to duck under that line is exactly the kind of conduct SARs exist to catch.

Recordkeeping and the Travel Rule at $3,000

Transmittals of funds of $3,000 or more trigger BSA recordkeeping, and required information must "travel" with the transmittal to the next institution in the payment chain. Retail advisers whose assets sit at qualified custodians will feel this less directly than advisers who move money themselves — but you'll need to map which flows are yours.

Information sharing and examinations

Section 314(a) information requests from law enforcement and voluntary 314(b) sharing between institutions will both apply to advisers. And examination authority is delegated to the SEC — meaning AML compliance becomes part of your ordinary SEC exam cycle, not a separate federal process. Once the rule is live, BSA civil penalties for program failures can run into the tens of thousands of dollars per day per violation, with far steeper exposure for willful failures.

Why FinCEN Hit Pause — and Why the Rule Isn't Going Away

Read the delay for what it is: a timing adjustment, not a policy reversal. FinCEN's stated reasons were practical — re-tailor the rule to an industry that ranges from solo RIAs to hundred-billion-dollar fund complexes, and line the effective date up with the CIP rule so firms build once instead of twice.

Meanwhile the rationale for the rule hasn't moved. Treasury's February 2024 risk assessment concluded the adviser sector presents material illicit-finance risk: advisers manage enormous pools of wealth with historically no obligation to know whose money it really is. Anti-corruption researchers estimate that foreign individuals with unknown identities control on the order of $1.7 trillion in U.S. private investment fund assets. Sanctions evasion, fraud proceeds, and corruption money looking for a respectable home are the exact problems a risk-based AML program is designed to surface.

Every signal from the agency — including the text of the delay rule itself — says the requirements take effect in 2028. Plan on it.

A 24-Month Runway Plan

Here's how to spread the work so 2027 isn't a fire drill.

Months 1–6: Assess your risk

  • Write your illicit-finance risk assessment. Inventory your client base (domestic vs. foreign, individuals vs. entities vs. funds), your strategies, the jurisdictions you touch, and how subscriptions, redemptions, and disbursements actually flow. This document drives everything else — and it's the first thing an examiner will ask for.
  • Gap-check against the five pillars. Most advisers already have pieces: a compliance manual, a code of ethics, maybe identity checks at onboarding. Map what exists against what the rule demands.
  • Decide build vs. buy. If you use a fund administrator or compliance platform, find out now what AML support they offer and at what price. Remember the liability rule: outsourcing the work never outsources the responsibility.

Months 7–12: Build the program

  • Draft the written program around your risk assessment, and get it formally approved at the top of the firm.
  • Designate your AML officer and write the escalation path: who reviews alerts, who decides to file a SAR, who signs.
  • Set up the mechanics — FinCEN BSA e-filing access, SAR and CTR workflows, and the recordkeeping system for five-year retention.
  • Watch the CIP rulemaking. Whatever customer-ID requirements emerge will bolt onto this program; leave room in your design.

Months 13–18: Train and test

  • Train everyone who touches client onboarding or money movement — portfolio managers, client service, operations — and document who was trained, on what, and when.
  • Run an independent test while you still have time to fix what it finds. A mock exam or consultant review in mid-2027 beats a deficiency letter in 2028.

Months 19–24: Run it in shadow mode

  • Operate the program as if the rule were live: monitor, document, dry-run your SAR decision process. By January 2028 the program should be boring — a routine, not a project.
  • Track what compliance costs you as its own expense category. Software subscriptions, consultant fees, training time, and testing are all real line items now, and knowing your number makes vendor renewals and budget cycles much less painful.

The Recordkeeping Burden Is a Bookkeeping Problem

Strip away the acronyms and this rule is, at its core, a recordkeeping regime: five-year retention on SARs and their supporting files, records on every covered funds transmittal, documented risk assessments, training logs, testing reports. When the SEC examines your AML program, it will read those records next to your financials — and inconsistencies between the two are how exams go sideways.

That makes disciplined books a compliance asset, not just an accounting chore. If your firm's ledgers already track every dollar with dates, counterparties, and audit trails, producing the documentation an examiner wants is an export, not an archaeology project. If they don't, the runway to 2028 is also the right window to fix the foundation — starting with a dedicated expense category for compliance costs and a chart of accounts that separates client funds activity from the firm's own operations.

Simplify Your Financial Management

Getting your own books in order is the cheapest first step toward AML readiness — and the payoff shows up long before 2028, at every exam, audit, and tax season in between. Beancount.io gives you plain-text accounting that is transparent, version-controlled, and auditable by design, so every transaction in your firm's ledger carries the paper trail regulators expect. Get started for free and see why finance-minded founders are moving their books to plain text.

Share this article