— Dixie Hieb, Partner, Davenport Evans Law Firm
It is not often that bankers react warmly to yet another rules revision, but FinCEN’s latest proposed Bank Secrecy Act changes should make bankers, and especially BSA Officers, smile. On April 7, 2026, FinCEN published proposed revisions to the Bank Secrecy Act rules that may change little on the day-to-day compliance front but that could change dramatically the resulting compliance examinations and enforcement actions.
Why issue a revised rule regarding anti-money laundering and countering the financing of terrorism (AML/CFT)? In part, to send a message to the federal banking regulators. The focus of the proposed rule is aimed squarely at the regulatory agencies, with an emphasis on reducing the AML/CFT compliance burden while permitting banks to determine how best to assess and monitor AML/CFT risk. Per the summary introduction accompanying the proposed rule, FinCEN issued the rule to ensure that financial institutions establish and maintain effective AML/CFT programs in order to better achieve the purposes of the Bank Secrecy Act and lead to more effective outcomes for financial institutions, law enforcement, and national security agencies. FinCEN’s “Key Changes” publication states that the proposed rule will reduce unnecessary regulatory burden by allowing financial institutions to focus resources on higher risk areas in their AML/CFT programs, elevate FinCEN’s role in the AML/CFT process to promote consistent, risk-based supervision by examiners, and refocus banks’ AML/CFT programs on effectiveness in preventing illicit finance activity, rather than mere technical compliance. In the words of Secretary of the Treasury Scott Bessent, the proposed rule “restores common sense with a focus on keeping bad actors out of the financial system, not burying America’s banks in more red tape.”
Bankers should not, however, be fooled into thinking the proposed FinCEN rule is “BSA lite.” The proposed rule sets forth two separate requirements for a bank’s AML/CFT program: establishment and maintenance. The basic requirements regarding “establishment” of an AML/CFT program are much the same as the current BSA/AML requirements. As to maintenance, the proposed rule states (in a circular fashion) that a bank must implement an AML/CFT program that meets the “establishment” requirements.
From a policies and procedures perspective, the proposed rule does little more than update terminology and reframe existing requirements, primarily under the AML/CFT program “establishment” prong. Throughout the regulations, references to BSA and AML are being updated to AML and CFT, and references to “other criminal activity” are being replaced by “other illicit finance activity.” The five pillars of BSA compliance (internal policies, procedures, and controls; an appointed BSA officer; employee training; independent testing; and customer due diligence) will now be referred to as four pillars, with customer due diligence being considered a component of internal policies, procedures, and controls rather than a separate pillar. The proposed rule also incorporates AML/CFT risk assessment and consideration of the AML/CFT Priorities into the internal policies, procedures, and controls pillar. As described in FinCEN’s Fact Sheet, risk assessment processes would have to: (1) evaluate the AML/CFT risks of the bank’s business activities, (2) incorporate the AML/CFT Priorities, as appropriate; and (3) be updated promptly upon any change that the bank knows or has reason to know significantly changes its risk profile. On a substantive note, the proposed rule adds the requirement that a bank’s AML/CFT officer be located in the United States. The proposed rule also maintains the current expectation that a financial institution approve its AML/CFT program, but the proposed rule permits approval not only by a bank’s board but also by an equivalent governing body or senior management.
From an examination perspective, the changes are significant. The mode of viewing AML/CFT compliance must now be based on whether a bank has established a program that meets the requirements and whether the bank has, in all material respects, implemented that program. Per the supplementary information accompanying the proposed rule, examiners are not supposed to “second guess” a bank’s reasonable determination regarding specific risks or resource allocation, and an examiner should not substitute his or her own subjective judgment in place of the bank’s. Instead, with regard to program implementation, the examiner should focus on the bank’s resource allocation in light of the bank’s AML/CFT risk assessment. FinCEN outlines indicators that a bank may not be implementing its AML/CFT program “in all material respects,” including the failure to perform required procedures in a consistent and timely manner due to inadequate resources, and gaps in the risk assessment process that result in missing higher money laundering or terrorist financing risks.
From an enforcement perspective, the changes could be even more significant. The proposed rule does not limit supervisory or enforcement actions based on a failure to establish an AML/CFT program, but the proposed rule provides that an enforcement action would be taken with respect to AML/CFT program implementation only if there was a significant or systematic failure to implement the program. Further, the proposed rule requires any federal banking regulator to provide FinCEN with 30 days’ advance notice of any proposed AML/CFT enforcement action.
This new approach to AML/CFT enforcement
was not adopted by FinCEN alone; on the same day that FinCEN issued its proposed rule, the
OCC, the FDIC, and the NCUA issued corresponding rules revisions that included the 30-day advance notice requirement.
The proposed AML/CFT changes are more than welcome. If FinCEN and the federal banking regulators hold true to the mandates and restrictions set forth in the proposed rule, Bank Secrecy Act compliance should result in far
less busywork and a far greater emphasis on high-risk activities.

