The Federal Reserve’s Notice of Proposed Rulemaking, published in the Federal Register on July 9, closes a gap that had left Board-supervised banks as the last major category of U.S. financial institution operating under AML program requirements not yet aligned with the administration’s broader deregulatory rewrite of the Bank Secrecy Act framework. The Fed had been conspicuously absent from an earlier joint proposal issued in April by FinCEN alongside the OCC, the FDIC, and the National Credit Union Administration, and its arrival in July effectively completes the regulatory quartet whose supervised institutions will now operate under a substantially revised customer due diligence and program-design standard, once finalized.
The substance of the proposal reorients AML compliance around a formal, documented risk assessment process rather than a checklist of required program elements. Institutions would be required to build internal controls, staffing decisions, and monitoring intensity directly around FinCEN’s published national AML/CFT priorities, with the expectation that resources flow disproportionately toward higher-risk customers and activities rather than being spread evenly across a customer base regardless of risk profile. The proposal also formally incorporates FinCEN’s existing ongoing customer due diligence obligation into the Federal Reserve’s own program requirements, and requires that a bank’s designated compliance officer be located in the United States and directly accessible to examiners, closing a structural gap that had allowed some institutions to house compliance leadership offshore.
Perhaps the most consequential change for enforcement exposure is a proposed redefinition of what triggers a formal supervisory or enforcement action. Under the revised standard, once an institution has properly established an AML/CFT program, only significant or systemic failures to implement that program in practice would justify an enforcement action or a formal supervisory finding — a meaningfully higher bar than the current standard, under which isolated or technical lapses can sometimes support a finding of inadequacy. The proposal simultaneously introduces a new interagency consultation framework, requiring the Federal Reserve to coordinate with FinCEN before certain enforcement or supervisory actions proceed, a structural change intended to produce more consistent outcomes across the multiple regulators that oversee different categories of BSA-covered institution.
The comment period runs sixty days, closing September 7, layering onto a comment period for the April interagency proposal that closed June 9. Compliance functions at Fed-supervised institutions now face the practical challenge of responding to two overlapping rulemakings whose final texts, and the degree of interpretive alignment between them, remain unresolved. Institutions that operate under multiple federal banking regulators — a common structure for larger bank holding companies with both a national bank subsidiary and Fed-supervised entities — face a nearer-term risk: divergence between how the Fed’s final rule and the OCC/FDIC/NCUA joint rule define “significant or systemic” could leave multi-charter organizations managing materially different enforcement thresholds across affiliates performing similar functions.
The rulemaking sits downstream of two deregulatory moves earlier in 2026 that compliance teams have already had to absorb. In February, FinCEN issued an exceptive relief order eliminating the requirement that covered financial institutions re-verify beneficial ownership information for legal entity customers at every new account opening, shifting instead to a first-account, ongoing-monitoring model. And running in parallel, a May 19 executive order titled Restoring Integrity to America’s Financial System pushed in the opposite direction on one narrow front, directing Treasury to issue red-flag guidance — delivered in June — on suspicious activity tied to non-work-authorized individuals and their employers, with proposed changes to risk-based customer identification requirements still due by mid-November. Taken together, the pattern is not a uniform loosening of AML obligations but a targeted recalibration: broad compliance burden reduction around routine, low-risk customer relationships, paired with sharpened, narrowly targeted expectations around specific typologies the administration has flagged as national priorities, including immigration-linked financial exploitation and cartel-adjacent trade finance.
For compliance officers, the near-term task is less about redesigning programs today and more about positioning to respond quickly once the rule texts finalize, likely in the first half of 2027 given the current comment timelines. The clearest actionable step available now is documentation: institutions that can demonstrate a formally adopted, risk-based assessment process — showing how staffing, monitoring thresholds, and due diligence intensity map to FinCEN’s stated priorities — will be far better positioned under the proposed “significant or systemic” enforcement standard than institutions relying on informal or undocumented risk judgments, even if those judgments happen to be sound in substance.
By FCCT Editorial Team

