Well, we can’t exactly say they didn’t warn us. When FinCEN issued its exceptive relief order earlier this year, it described the move as advancing a “more efficient, risk-based approach” while reducing “unnecessary regulatory burden,” and it expressly noted that it “anticipated pursuing further changes […] through the rulemaking process.” That language now looks even less like just a narrowly-applied exemption, and a whole lot more like table-setting for a broader rewrite of how AML / CFT programs are designed, implemented, and supervised.
And, indeed, with FinCEN’s newly released 202-page AML / CFT program proposal (now in the Federal Register at 91 FR 19704), the agency may be trying to escape “check-the-box” compliance – but it may also be slipping into something softer, vaguer, and harder to pin down.
A minor caveat: the following is a “first-impressions” (non-exhaustive) take on the proposal, only because the document itself is sprawling and the changes it proposes are significant; its central ambitions (and ambiguities) arrive well before page 200.
On initial read, and taken in its best light, FinCEN’s new AML / CFT program NPRM looks like a serious attempt to solve a problem that has been collectively shared by banks everywhere: too much AML supervision has drifted into process policing, mountains of documentation, and examiner second-guessing that often seem only loosely connected to actually stopping crime. On that much, the proposal talks the talk, and says a lot of the right things. That is, it talks about effectiveness, risk-based allocation of resources, useful information for law enforcement, innovation, and moving attention away from low-risk busywork and toward higher-risk activity. All of that, you could argue, is sensible. All of that, you could also argue, is long overdue.
And there’s the rub – because in doing so, this proposal may very well have corrected one problem by creating another.
If the 2024 version was vulnerable to criticism for being too prescriptive, too formalized, and too likely to become another compliance “ritual,” this new version may be vulnerable for almost the exact opposite reason. To be sure, it is full of standards that sound modern and flexible, but they aren’t especially precise. “Effective.” “Reasonably designed.” “In all material respects.” “Significant or systemic failure.” “Promptly.” “As appropriate.” Of course, those are not meaningless phrases, but neither are they self-explanatory, or rooted in statutory definition. And FinCEN concedes as much, because the NPRM repeatedly asks whether commenters think these concepts need more clarification. But when a proposal has to ask the public to help define some of its most important terms, that is at least an early sign that the rule may not yet be as clear as its authors think.
And, when paired with the proposal’s arguably most consequential shift for banks, the trouble doubles – for once a bank has “properly established” an AML / CFT program, major supervisory or enforcement action based on the program rule would generally be reserved for “significant or systemic” failures to implement the program, rather than isolated, technical, or immaterial deficiencies. Now, on one level, that sounds appealing enough, especially as a response to no doubt countless complaints about nitpicking and process for process’s sake. On another, it raises an obvious question: what counts as merely technical, and what counts as the beginning of something systemic? AML programs rarely collapse in one dramatic, catastrophic moment. More often, like so many other regulatory violations, they erode by accumulation – weak escalation here, thin staffing there, poor controls, unresolved issues – essentially, known gaps that enough people see, but don’t do anything about. Indeed, that is exactly the sort of “slow-burn” failure FinCEN itself has repeatedly described in its most significant recent enforcement actions. A framework designed to reduce “pointless” process criticism almost will inevitably make it harder to intervene before those weaknesses become undeniable. Rarely is a process “just for process’s sake.” More often, the process is the point.
You can see a similar “tension” in the proposal’s treatment of risk assessments. The 2024 NPRM would have centered a more formalized risk assessment process and expressly required consideration of business risks, AML / CFT Priorities, and BSA reports. This new version backs away from that structure. It speaks instead of “risk assessment processes,” allows institutions to rely on one or more processes, and drops the explicit requirement that BSA reports be a required input. Sure, you could argue that that may be more realistic for how most banks actually operate. But there’s almost no denying that it likely also means fewer objective anchors. The proposal still requires institutions to evaluate products, services, distribution channels, customers, and geographies, and to review and, as appropriate, incorporate the AML / CFT Priorities. But the overall direction is unmistakable, less formal architecture, more discretion – and discretion without clear, objective standards can quickly become a source of inconsistency and supervisory risk.
That same kind of “looseness” shows up in the proposal’s repeated invocation of “outcomes.” The NPRM speaks in terms of “better outcomes,” “highly useful information,” “demonstrable outputs,” and “advancing the AML / CFT priorities.” Again, those are all attractive ideas, and sound like they came from the lips of Dudley Do-Right himself. But they are not self-defining, and perhaps more importantly, these are not all just interchangeable ways of saying “outcomes.” That is to say – a bank can control the quality of its monitoring, escalation, due diligence, staffing, and reporting. What it cannot control is whether law enforcement uses a SAR effectively, whether prosecutors pursue a case, or whether a filing turns out to be tactically or strategically valuable months later. So, if the proposal wants to move toward an “outcomes” model, it still has not fully drawn the line between what a private institution can actually influence and what it cannot. Things can get very muddy, very quickly – because a standard that blurs outputs, outcomes, and aspirations risks becoming more subjective, not less.
Next, in handling the AML / CFT Priorities (oh, those pesky Priorities…), the proposal outlines that institutions would be required to review and, as appropriate, incorporate them into their risk assessment processes. The NPRM also acknowledges that some priorities are broad, high-level, and tied to a particular moment in time, and that institutions may lack enough context to know what threats or timeframes to emphasize. That admission likely shouldn’t be ignored. The priorities may be important as policy signals, but they aren’t really a full operating blueprint yet. Requiring institutions to incorporate them while also conceding that they may be too broad or too stale to operationalize cleanly isn’t quite the same thing as solving the priorities problem altogether.
There are also “smaller” signals in the proposal (with perhaps just as big of an impact) that point in the same direction. For example, the AML / CFT officer language now refers to “an individual,” not “an individual or individuals,” and makes that person responsible for “establishing and implementing” the program and coordinating day-to-day compliance (this individual must also live in the U.S., for what it’s worth). FinCEN describes that as making a longstanding expectation explicit. That may be so, but it also compresses institution-wide responsibility into language that sounds cleaner than reality could possibly allow. No “one person” “implements” an AML program alone. The board may still ultimately bear responsibility if something goes wrong, but one could argue that wording like this could risk creating a convenient “straw man” – a single officer made to carry the appearance of responsibility for failures that are, in truth, institutional.
This is obviously a major proposal, one that plainly takes a different path than the 2024 NPRM. But different is not the same thing as resolved (or even “better”). If the argument was that the earlier draft risked turning AML modernization into more process, then the clear retort is that this one risks turning it into more discretion. That may be the more attractive approach, but it is not necessarily the safer one. Because discretion without sufficiently objective boundaries can become just as problematic as formalism without judgment.
I’ll caveat again: these are only first takes, of course – but this proposal looks likely to give us quite a bit more to write about in the weeks and months ahead.
Comments on the NPRM are due by June 9, 2026. The NPRM can be found here: [91 FR 19704], and for posterity’s sake, you can find the 2024 NPRM here: [89 FR 55428].

Brett Goodnack, JD, CAMS
Compliance Advisor