A Proposal to Refocus the BSA Program
In April 2026, the Financial Crimes Enforcement Network (FinCEN) published a proposed rule intended to modernize how financial institutions design and supervise their anti-money laundering and countering the financing of terrorism (AML/CFT) programs. The proposal is framed around a practical question: are institutions directing their finite compliance resources toward the activity that presents the greatest illicit-finance risk?
FinCEN’s summary of the proposed changes says the rule would give institutions more flexibility to focus on higher-risk areas, elevate FinCEN’s role in bank AML/CFT supervision, and clarify that programs should be judged by their effectiveness rather than by technical compliance alone.
The proposal is not a final rule. Its public-comment deadline was June 9, 2026, so institutions should check FinCEN for subsequent rulemaking before treating any provision as an enforceable requirement.
What Would Change
1. Risk focus would become more explicit
The proposal would allow financial institutions to direct more resources toward higher-risk activity instead of treating every control, customer segment, product, and transaction pattern as if it presented the same exposure. That does not eliminate the need for a complete risk assessment. It raises the standard for explaining why the program’s resources, thresholds, investigations, and escalation paths are proportionate to the risks the institution has identified.
For compliance teams, the operational implication is clear: a risk-based program needs an evidence trail. Teams should be able to connect their enterprise risk assessment to monitoring coverage, customer due diligence, sanctions and fraud controls, staffing, quality assurance, and management reporting.
2. Program effectiveness would matter more than checklist completion
FinCEN’s summary says the proposed rule would clarify that an effective AML/CFT program must include risk-based internal policies, procedures, and controls reasonably designed to ensure compliance with the Bank Secrecy Act and FinCEN’s regulations. The emphasis is on whether the program is designed and operating to combat and prevent illicit finance—not merely whether a policy, committee, or procedure exists on paper.
That distinction changes how teams should test controls. A policy review alone is not enough. Teams should test whether alerts identify the risks the institution actually faces, whether investigators receive useful context, whether escalation decisions are reproducible, and whether suspicious activity reporting produces information that is useful to law enforcement.
3. Bank supervision could become more coordinated
The proposal would require federal banking regulators to consult with FinCEN before taking certain supervisory or enforcement actions related to bank AML/CFT programs. It would also align the supervisory framework more closely with Treasury’s focus on program effectiveness, with certain actions reserved for the most serious deficiencies in implementation once a bank has established an AML/CFT program.
This is not a reason to reduce governance discipline. It is a reason to make the program’s design choices, limitations, remediation decisions, and effectiveness evidence easier to review across the three lines of defense.
How Teams Can Prepare Now
- Map risk to control coverage. Document how material threats translate into detection scenarios, customer-risk rules, transaction monitoring, sanctions controls, investigation queues, and reporting.
- Measure outcomes, not just activity. Track alert quality, investigation turnaround, escalation consistency, filing usefulness, repeat issues, and post-remediation performance.
- Document proportionality decisions. If a control is calibrated differently by product, customer type, geography, or channel, record the risk rationale and the evidence supporting that choice.
- Test for blind spots. Use typology reviews, independent testing, scenario validation, and retrospective analysis to identify activity the program is not seeing.
- Separate proposal monitoring from implementation. Maintain a regulatory watchlist for the rule and prepare impact notes, but do not represent proposed language as a current obligation.
The Practical Takeaway
FinCEN’s proposal points toward a more outcome-oriented AML/CFT conversation. The question is not simply whether a financial institution has a large control inventory. It is whether the program can demonstrate that its resources, controls, and decisions are aimed at the most serious threats—and that the institution can show what it learned when those controls failed.
For compliance leaders, the best preparation is disciplined evidence: a clear risk assessment, traceable control design, measurable outcomes, and a documented explanation for where the program places its attention. Read the FinCEN summary of the proposed rule before making any implementation decision.
