Blog Login
Fintech Compliance

What FinCEN's New AML Program Rule Means for MSBs

A

Anzar Dewani

10 hours ago

In April 2026, FinCEN proposed the most significant reform of AML/CFT program requirements in a decade. Here's what changed, what it means specifically for money services businesses, and what to do before the final rule arrives.

What FinCEN's New AML Program Rule Means for MSBs

On April 7, 2026, FinCEN issued a proposed rule that would fundamentally reform how financial institutions — including money services businesses — design and operate their AML/CFT compliance programs under the Bank Secrecy Act.

This is not a routine update. FinCEN describes the proposal as a structural reset of the BSA framework — the most significant rethinking of AML/CFT program requirements since the original BSA regulations were issued decades ago. For MSBs, several of the proposed changes have direct operational implications.

The comment period closed June 9, 2026. A final rule is the next beat. FinCEN has proposed a 12-month implementation period following issuance of the final rule.

The Core Shift: From Checklist to Risk-Based

The fundamental change in the proposed rule is a shift in how BSA compliance programs are evaluated. Under the current framework, financial institutions demonstrate compliance by meeting a defined set of program elements — policies, procedures, training, an independent audit function, and a designated compliance officer. The proposed rule changes the standard to: programs must be "effective, risk-based, and reasonably designed."

This is a meaningful doctrinal shift. It moves the compliance standard away from element-by-element checklist satisfaction toward a judgment about whether the program is actually working. Examiners will evaluate not just whether you have a compliance program, but whether your program is calibrated to your actual risk profile and producing effective outcomes.

For MSBs that have been operating with technically compliant but minimally resourced programs, this shift increases examination risk.

What Changes for MSBs Specifically

Formal Risk Assessment Now Explicit

The proposed rule explicitly requires all covered financial institutions — including MSBs — to conduct and maintain a formal, documented risk assessment. Under the current framework, risk assessment is best practice and embedded implicitly in program requirements, but it is not explicitly mandated as a standalone obligation.

Under the proposed rule, MSBs would be required to:

  • Conduct a formal assessment of their money laundering, terrorist financing, and other illicit finance risks
  • Document the methodology and findings of the risk assessment
  • Use the risk assessment to calibrate and update their AML/CFT program
  • Refresh the risk assessment when material changes occur in their business or risk environment

If you do not currently have a documented risk assessment, this is the most immediate compliance gap to address. For a practical framework, see our guide on AML compliance program requirements for fintechs.

Program Effectiveness Standard

The proposed rule introduces an "effectiveness" standard that does not currently exist explicitly in BSA regulations. This means FinCEN and state examiners will be able to cite an MSB not just for missing a program element, but for having a program element that does not function effectively in practice.

Examples of what this could mean in practice:

  • Transaction monitoring rules that are not regularly tuned and are generating overwhelming false positive rates could be cited as ineffective
  • SAR filing rates that are statistical outliers (too low relative to peer institutions) could be scrutinized
  • Training programs that are box-checking exercises rather than substantive could be questioned

Alignment with AMLA's Risk-Based Approach

The proposed rule implements the risk-based approach mandated by the Anti-Money Laundering Act of 2020 (AMLA), which directed FinCEN to update BSA regulations to incorporate risk-based principles. For MSBs, this means regulators will increasingly evaluate your compliance program against your specific business model and customer risk profile, not against a one-size-fits-all standard.

What Does Not Change

The core pillars of an MSB's BSA compliance program remain required:

  • A designated BSA compliance officer
  • Written internal policies, procedures, and controls
  • Ongoing training for relevant personnel
  • Independent testing and audit of the program
  • A customer due diligence / KYC program
  • SAR and CTR filing obligations
  • Recordkeeping requirements

The proposed rule adds rigor to how these elements must be calibrated and evaluated — it does not replace them.

Who the Rule Applies To

The proposed rule covers a broad range of financial institutions under FinCEN's jurisdiction, including:

  • Banks and credit unions
  • Money services businesses (all categories)
  • Broker-dealers
  • Mutual funds
  • Insurance companies
  • Futures commission merchants
  • Dealers in precious metals

MSBs are fully within scope. This includes money transmitters, currency exchangers, check cashers, and issuers or sellers of stored value and money orders. If you are registered with FinCEN as an MSB, the proposed rule applies to you.

The Implementation Timeline

The proposed rule is not yet final. Here's where things stand:

  • April 7, 2026 — FinCEN issued the Notice of Proposed Rulemaking (NPRM)
  • June 9, 2026 — Comment period closed
  • Next step — FinCEN reviews comments and issues a final rule (timing unconfirmed)
  • Implementation period — FinCEN has proposed 12 months from final rule issuance for covered institutions to come into compliance

The 12-month implementation window sounds long, but for MSBs that need to redesign their risk assessment methodology, update their compliance policies, and potentially upgrade their transaction monitoring systems, 12 months is not a long runway.

What MSBs Should Do Now

The proposed rule has not been finalized, but the direction of travel is clear. There is no reason to wait for the final rule to start preparing.

Conduct a Gap Assessment

Review your current AML/BSA compliance program against the proposed rule's requirements. Specifically:

  1. Do you have a documented, formal risk assessment?
  2. Is your risk assessment the foundation of your program design, or does your program run independently of a defined risk view?
  3. Can you demonstrate that your transaction monitoring rules are calibrated to your actual risk exposure?
  4. Is your training program substantive and documented?
  5. When was your last independent audit and what did it find?

Document Your Risk Assessment

If you do not have a formal, written risk assessment, creating one is the single highest-priority action. The risk assessment should identify your customer types, product lines, geographies, and delivery channels; assess the ML/TF risk associated with each; and document how your program controls address those risks.

Review Your Transaction Monitoring

Under an effectiveness standard, a transaction monitoring program that is not tuned to your actual risk profile — or that is generating unmanageable alert volumes — is a liability, not just an operational problem. Begin reviewing your alert logic, tuning parameters, and false positive rates now.

Strengthen Your Sanctions Screening

The proposed rule's effectiveness standard will extend to sanctions compliance as well. Ensure your OFAC screening program is current, well-documented, and that your escalation procedures for hits are clearly defined.

Why This Is a Direct Product Hook

The FinCEN proposed rule makes one thing very clear: documenting your compliance program — policies, risk assessments, controls, audit trails — is no longer optional or aspirational. It is the standard by which regulators will evaluate you.

For MSBs that have been running informal programs, this rule is a forcing function. The question is not whether to upgrade — it is how to do it efficiently, affordably, and in a way that holds up under examination.

 

This article is for informational purposes only and does not constitute legal or compliance advice. The FinCEN AML/CFT program rule discussed here is a proposed rule as of the date of this publication and has not been finalized. Requirements are subject to change. Consult qualified legal counsel regarding your specific compliance obligations.

 

Talk to the ComplyOne team to get started.

Share this article:

Related Articles