FinCEN Advisory Raises Screening, Fair Banking Concerns

The White House recently issued an Executive Order titled “Restoring Integrity to America’s Financial System,” and the fear was that it would push banks toward a role they were never designed to play – immigration-adjacent screeners, asked to translate lawful-presence questions into BSA, fraud, credit, and customer-risk decisions.

On June 5th, FinCEN, joined by the FDIC, OCC, NCUA, and coordinated with the IRS, issued a new advisory on “non-work authorized populations and their employers” and the risks they allegedly pose to the integrity of the U.S. financial system. The advisory is expressly issued in response to the Executive Order, and it asks financial institutions to use the SAR keyword “FINANCIALINTEGRITY-2026-A002” when reporting activity connected to the typologies it describes.

That’s the thing about executive orders, which we’ve written about time and time again. They may begin as political documents – ones without the force or effect of law. But in many cases, someone eventually turns them into operational guidance – the kind that banks are suddenly “expected” to follow.

Just like the EO that gave it life, much of the advisory describes real financial-crime risk. It discusses identity theft, fraudulent use of Social Security numbers, off-the-books payroll, payroll tax evasion, workers’ compensation fraud, shell companies, complicit labor brokers, unregistered money services businesses, structured cash withdrawals, check cashing, P2P payments, and cash courier activity. But, as has been argued in the past, banks have been advised of – and are aware of – these patterns already. In fact, the “strongest” parts of the advisory read less like a new immigration warning and more like familiar payroll-fraud and labor-broker typologies – just wearing a new jacket.

The advisory is particularly detailed on labor broker schemes. It describes shell companies in industries like construction, agriculture, hospitality, domestic service, and staffing; checks written for supposed subcontracting services; repeated cash withdrawals or check-cashing activity; and workers paid outside ordinary payroll systems. FinCEN says financial institutions reported more than $2.5 billion in suspicious activity associated with this kind of scheme in 2025.

Then comes the even harder part.

The advisory tells banks to consider the use of an ITIN, in lieu of an SSN or valid employment authorization document, as a possible risk factor when opening accounts or extending credit. It notes that ITINs don’t establish legal status, authorize employment, or serve as identification outside the federal tax system. Now, that’s true enough, as far as it goes. But it is also true that ITINs exist so people who are not eligible for Social Security numbers can comply with federal tax obligations – a point the advisory acknowledges in almost ‘blink-and-you’ll-miss-it’ fashion.

Treating ITIN use as inherently suspicious risks doing exactly what the advisory says it is not doing – turning a lawful identifier used by many foreign nationals and immigrants into a reason for heightened scrutiny. And once that happens, the concern is not just BSA overreporting; it is fair banking and fair lending risk. A bank that treats ITIN users, immigrant-owned businesses, or customers with nontraditional documentation as categorically more suspicious may not be managing risk so much as converting immigration-adjacent assumptions into account access, credit availability, and customer-service decisions.

This may explain why the advisory includes the usual (and increasingly important) caveats: no single red flag is determinative, no red flag should be taken in isolation, institutions should consider the surrounding facts and circumstances, and no customer type presents a uniform money laundering or terrorist financing risk. Perhaps most importantly of all – the advisory explicitly states that its red flag indicators “do not convey or alter any independent regulatory obligations or supervisory expectations.”

Make sure to highlight that sentence. Because without it, this advisory could be read much too broadly. A customer using an ITIN is not automatically suspicious. A foreign passport is not a SAR. A remittance is not, by itself, a typology. And an immigrant-owned business in a cash-heavy industry is not presumptively a front for payroll fraud. Not to mention, Regulation B’s prohibited bases still exist – including race and national origin – as do the broader concepts tied to UDAP/UDAAP that arise when a “risk-based” process becomes unfair, inconsistent, or needlessly (and unjustifiably) exclusionary.

If banks use this advisory to sharpen monitoring for payroll fraud, identity theft, shell companies, structuring, unregistered MSB activity, and labor exploitation – fair enough; that’s at least the part rooted in actual financial-crime risk. But if banks internalize the broader message as “ITIN customers equal higher risk,” the advisory becomes something else entirely – a door to categorical financial exclusion, opened with a SAR keyword.

The FinCEN Advisory can be found here: [FIN-2026-A002]

Its genesis, Executive Order 14406, can be found here: [91 FR 30479]

 

Brett Goodnack, JD, CAMS

Compliance Advisor