Field Guide

FinCEN's Proposed AML/CFT Program Rule, Explained

The short version

FinCEN has proposed a new rule, RIN 1506-AB72, that would change how a BSA/AML program is judged. FinCEN issued it on April 7, 2026; it published in the Federal Register on April 10, 2026; the comment period closed June 9, 2026. It is a proposal, not law. It would set an explicit requirement that a program be effective: established with the required components, then maintained by implementing the established program in all material respects. The internal policies, procedures, and controls would have to be risk-based and reasonably designed, documented risk assessment processes would become an explicit requirement inside that component, those processes would review and, as appropriate, incorporate FinCEN's national AML/CFT priorities, and the rule separates the failure of building a program wrong from the failure of running a sound one badly. Nothing is required today; a final rule would carry roughly a twelve-month runway.

The Anti-Money Laundering and Countering the Financing of Terrorism Programs rule, RIN 1506-AB72, is a FinCEN notice of proposed rulemaking, issued April 7, 2026, and published in the Federal Register on April 10, 2026 (91 FR 18704), that would revise the standard by which a BSA/AML compliance program is built and judged. It withdraws and supersedes the program rule FinCEN proposed in July 2024, which the agency does not intend to finalize. It responds to a congressional direction: the Anti-Money Laundering Act of 2020 amended the statute at 31 U.S.C. 5318(h) and directed the agency to write the details. The comment period closed June 9, 2026.

A notice of proposed rulemaking is not law. FinCEN now reviews the comments it received and decides what a final rule looks like, and the final rule can differ from the proposal in ways that matter. Nothing below is required today. What follows is what the proposal would change, and how each change reads from an examiner's position.

What the proposal would change

The proposal replaces the long-standing instruction to maintain an AML program with an explicit performance standard. A program would have to be effective, and the proposal defines the term: a program is effective when the institution establishes it with the required components and then maintains it by implementing, in all material respects, the program it established. The familiar risk-based and reasonably designed language survives, but it attaches to the set of internal policies, procedures, and controls rather than standing as a label on the program as a whole. For years the program rule described the parts a program must contain without stating that the parts have to function. The proposed structure states that requirement directly and gives examiners language to hold a program to it.

Three pieces sit underneath the standard:

The proposal also keeps the familiar program components and pairs them with a stated implementation period: roughly twelve months after any final rule before compliance is expected. For the foundation those components rest on, the BSA/AML program pillars guide walks the five-pillar structure this rule sits on top of.

The risk assessment moves inside the rule

Most programs already run a risk assessment. The change is where the obligation lives. Under the proposal, risk assessment processes sit inside the program's internal policies, procedures, and controls, with the institution required to identify, assess, and document its risks and to update the processes promptly when it knows or has reason to know its risk has significantly changed.

Two practical consequences follow. First, the risk assessment processes have to review the national priorities and incorporate the ones that apply, so a write-up that never engages the threats FinCEN named would read as incomplete — though the proposal lets an institution conclude, on the record, that a given priority does not reach its business. Second, because the process is documented, an examiner can ask to see not only the assessment but the method that produced it. A conclusion recorded without a method behind it is a gap the documentation requirement is written to surface.

Establishment versus maintenance

The proposal separates two failures that supervision has long collapsed into one. A program that was designed wrong is distinct from a program that was designed adequately and then operated poorly, and the two differ in the remediation they require, the timeline that remediation runs on, and where accountability sits.

By distinguishing the establishment of a program from its maintenance, the rule gives examiners a way to name which failure happened. An institution's evidence should therefore speak to both questions. Design records show the program was built to the institution's risk. Operating records, the alert dispositions and the calibration history and the testing results, show it was actually run. A defensible program answers both with documents rather than assertions.

Innovative approaches and the demonstration standard

The proposal encourages institutions to evaluate whether new technology or innovative approaches can help combat financial crime more effectively, and names machine learning, generative artificial intelligence, digital identity, blockchain monitoring and analytics, and APIs. It pairs the encouragement with a commitment: an institution that responsibly experiments with innovative technologies will not incur additional risk of a significant supervisory or enforcement action solely for using them. The rule text itself references no particular technology and requires none.

A tool demonstrates effectiveness only if it can be measured against the same objective criteria as the rest of the program: detection coverage against known typologies, the quality of the alerts it produces, and whether it surfaced weaknesses that were then found and fixed. A tool that cannot be measured against those criteria is asserting effectiveness rather than showing it. The commitment covers the choice to innovate, not the output: the program the tool sits inside is still examined for whether its internal policies, procedures, and controls are reasonably designed and implemented in all material respects. The conservative reading for a compliance officer is unchanged: the institution should be able to show how any AI tool is measured, not merely that it was deployed. The preamble separately airs industry concern that bank model-risk guidance fits AML models poorly — a signal that how far frameworks like SR 11-7 reach into the compliance stack is itself in play, which the AI model governance guide covers.

Timing and effective date

The proposal carries no fixed effective date. The sequence is: the comment period closed June 9, 2026; FinCEN reviews comments and issues a final rule on its own timeline; the proposal sets a proposed effective date of 12 months from issuance of the final rule. A proposal can change before it is finalized, and the comment record exists to shape it. Any specific obligation described here remains proposed until a final rule prints it.

Assessing a program against the proposal

No change to a program is required to comply with a proposal. The proposal instead functions as a reference point for where an existing program stands against the direction supervision is moving.

None of the proposal is law yet. The standard it describes tracks the expectation examiners already apply, independent of whether the final rule prints it.

This guide explains a proposed federal rule for general information and is not legal advice. Any obligation is verified against the final rule and the institution's own regulator's guidance. Primary sources: FinCEN NPRM, Anti-Money Laundering and Countering the Financing of Terrorism Programs, RIN 1506-AB72, Docket No. FINCEN-2026-0034, 91 FR 18704 (April 10, 2026); Anti-Money Laundering Act of 2020 (amending 31 U.S.C. 5318(h)); FinCEN National AML/CFT Priorities (June 30, 2021).

Common questions

What is FinCEN's AML/CFT Program rule (RIN 1506-AB72)?
It is a notice of proposed rulemaking that FinCEN issued on April 7, 2026, published April 10, 2026, to modernize the rule governing BSA/AML programs, as directed by the Anti-Money Laundering Act of 2020. It would set an explicit requirement that a program be effective — established with the required components and implemented in all material respects — make documented risk assessment processes an explicit requirement within the internal policies, procedures, and controls, and require those processes to review and, as appropriate, incorporate FinCEN's national AML/CFT priorities. The comment period closed June 9, 2026.
Is the AML/CFT Program rule final?
No. It is a proposed rule. FinCEN reviews the comments it received and then decides what a final rule looks like, and the final rule can differ from the proposal. Nothing in the proposal is required today.
What would change for an existing AML program?
The program would have to meet an explicit effectiveness standard — established with the required components and implemented in all material respects rather than only contain the required components. Documented risk assessment processes would become an explicit requirement within the internal policies, procedures, and controls, reviewing and, as appropriate, incorporating FinCEN's national priorities, and the rule separates the obligation to establish a program from the obligation to maintain one.
When would the new AML program rule take effect?
Not on a fixed date. The comment period closed June 9, 2026; FinCEN issues a final rule on its own timeline; the proposal sets a proposed effective date of 12 months from issuance of the final rule. Any specific obligation remains proposed until a final rule prints it.
What does the proposal say about AI in compliance?
It encourages institutions to evaluate whether new technology, including machine learning and generative AI, can help combat financial crime more effectively, and commits that responsibly experimenting with innovative technologies will not by itself create additional risk of a significant supervisory or enforcement action. The program the tool sits inside is still examined for reasonably designed, materially implemented controls, so the safe reading is to be ready to show how any AI tool is measured against objective criteria, not just that it was deployed.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.