Skip to main content

The Fed’s AML/CFT Overhaul: What Supervised Banks Need to Know

The Federal Reserve Board has issued a Notice of Proposed Rulemaking that would overhaul the Anti-Money Laundering/Countering the Financing of Terrorism (AML/CFT) program requirements for Board-supervised banks. The proposal parallels reforms issued by FinCEN, and separately by the OCC, the FDIC, an

man with papers

Two Filings, One Reform

On July 7, 2026, the Federal Reserve Board published a Notice of Proposed Rulemaking (12 CFR Part 208, Docket No. R-1835, RIN 7100-AG78) to modernize AML/CFT program requirements for Board-supervised institutions. 

The Fed's proposal parallels reforms proposed separately by FinCEN, as well as those put forward by the OCC, the FDIC, and the NCUA, on April 10, 2026 (Federal Register, 91 FR 2026-06948). The proposals are designed to move in lockstep, so banks supervised by more than one agency should expect a single, consistent standard rather than divergent requirements. 

A New Two-Pronged Standard: Establish and Maintain

Under the proposal, a bank must not only design an AML/CFT program but also keep it current as the institution's risk profile evolves. Supervisory action for implementation failures would apply only where those failures are significant or systemic, not for isolated, immaterial, or technical issues. This is a deliberate move away from a check-the-box compliance posture toward a more effective, risk-based supervisory model. 

What Changes for Supervised Banks

  • Standardized risk assessment, required and formalized
    • Banks must evaluate money laundering and terrorist financing risk across products, services, distribution channels, customers, and geography, and incorporate FinCEN's AML/CFT Priorities. Risk assessments must be updated promptly once the bank knows, or has reason to know, that its risk profile has meaningfully shifted. 
  • Risk-based resource allocation, made explicit
    •  Banks are directed to allocate more attention and resources to higher-risk customers and activities than to lower-risk ones, with flexibility to do so without added supervisory scrutiny. 
  • Ongoing customer due diligence
    •  Added formally as a program component, aligning the Board's rule with FinCEN's existing requirement. 
  • A US-based AML/CFT officer requirement 
    • With clear expectations on authority, independence, and access to resources. 
  • Broader program approval authority
    • The board, an equivalent governing body, or senior management may approve the written program, expanding beyond board-only sign-off. 

Why It Matters

The practical effect is a shift in what examiners will look for. Historically, supervisory findings have often centered on whether a program was designed and documented. Under the proposed standard, examiners will also assess whether the program is being implemented in a way that keeps pace with the bank's changing risk profile, and whether resources are genuinely weighted toward higher-risk areas. Banks that treat this as a documentation update, rather than an operating model change, are likely to be caught out. 

The rule is still a proposal and open for public comment. But the direction of travel is clear, and banks that get ahead of it now will be better positioned once the rule is finalized. 

How Sia Can Help

Sia helps banks translate proposals like this into action: 

  • Program diagnostic. Benchmark the current AML/CFT program against the proposed establish/maintain framework and pinpoint where documentation falls short. 
  • Risk assessment redesign. Rebuild risk assessment methodology to meaningfully incorporate FinCEN's AML/CFT Priorities and trigger timely updates as the risk profile changes. 
  • Resource allocation modeling. Build a defensible, risk-based resource allocation model that examiners can follow and that holds up under scrutiny. 
  • Governance and documentation. Update program approval workflows and written documentation to reflect the rule's expanded approval options and the establish/maintain distinction. 
  • AML/CFT officer structuring. Assess, and if needed restructure, the compliance officer function to meet the new US-location and independence requirements. 

If your team is starting to plan for this, we would welcome the conversation. 

Contact us for more information

Allowed formats: pdf, doc, docx, jpg, png. Max size: 2 MB

Sia integrates this data in its client database to send you marketing communications (invitations to events, newsletters and new commercial offers).
This data will be kept for 3 years before being deleted and you can withdraw your consent to the processing of your data at any time.
To learn more about the management of your personal data and to exercise your rights, please consult our Data Protection Policy.

CAPTCHA

Your data are used by Sia to process your contact request. Please note that you have rights regarding your personal data. For more information, we invite you to read our data protection policy