Fed proposal would recast bank AML rules around risk evidence
The Federal Reserve proposal would require supervised banks to show AML/CFT programmes are tied to current illicit finance risks.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
The Federal Reserve Board has proposed changes to Bank Secrecy Act compliance rules that would require supervised banks to maintain anti-money laundering and counter-terrorist financing programmes built around current illicit finance risks. The July 9, 2026 Notice of Proposed Rulemaking carries a September 8, 2026 comment deadline, giving banks a near-term window to assess how their controls, risk assessments and governance records would stand up under the proposed framework.
The proposal, issued in cooperation with the Financial Crimes Enforcement Network and pursuant to the Anti-Money Laundering Act of 2020, would amend 12 CFR Part 208. According to the notice, the rule would apply to institutions supervised by the Federal Reserve Board, including state member banks, Edge and agreement corporations, and certain US operations of foreign banking organisations.
Treasury Secretary Scott Bessent has described the policy direction as a move away from measuring compliance by the volume of paperwork and toward stopping illicit finance threats. Rohini Gupta, chief executive of FinregE, wrote in a Finextra opinion that the proposal would shift banks from static compliance records toward evidence that their AML/CFT operating models respond to business and risk changes.
What the proposal would require
Under the proposed amendment, a covered bank would need to establish, implement and maintain an AML/CFT programme that is reasonably designed to identify, assess and mitigate money laundering and terrorist financing risks. The mechanism is risk-based: a bank’s controls would be expected to reflect its products, customers, delivery channels, geographies and business activities rather than a uniform checklist.
The programme would include internal policies, procedures and controls designed to ensure BSA compliance, document relevant risks, mitigate those risks and support ongoing customer due diligence. The proposed risk assessment process would have to take account of the bank’s business profile and incorporate FinCEN’s AML/CFT Priorities where appropriate.
The proposal would also require risk assessments to be updated promptly when a bank knows, or has reason to know, that its risk profile has changed materially. Gupta cited examples such as launching a product, entering a new market, changing onboarding channels, adopting a payment mechanism or serving a different customer type as events that may require changes to monitoring, training, controls and escalation processes.
Testing, accountability and technology
Independent testing would remain part of the AML/CFT programme. The proposal is also intended to limit the risk that examiners or auditors replace a bank’s reasonably designed risk-based programme with their own subjective judgement, according to Gupta’s analysis.
Banks would need to designate an AML/CFT individual in the United States. That person would have to be subject to supervision and oversight by FinCEN or its designee and the Federal Reserve, and be available to those authorities. Employee training would also remain a core requirement, but the proposal would tie training to the bank’s risk profile rather than treat it as a fixed annual exercise.
The proposal does not mandate artificial intelligence or any specific technology. Gupta wrote that it leaves room for banks to assess whether tools such as machine learning, graph analytics, digital identity, blockchain monitoring and application programming interfaces can improve detection, triage, explainability and auditability.
The proposed framework also signals a more materiality-based approach to supervision. According to Gupta, once a bank has properly designed an AML/CFT programme, major supervisory or enforcement attention would focus on significant or systemic failures rather than minor technical issues. That approach would still leave banks accountable for gaps that impair implementation of the programme in practice.
This story draws on original reporting from Finextra Research.