
Three months ago, FinCEN told banks they’d have more room to breathe. Fewer boxes. Less paperwork on low-risk activity. More discretion to point resources at what actually matters.
Now the Federal Reserve has shown up to say: us too.
On July 7, the Fed issued its own proposal to overhaul AML program requirements for the banks it supervises, joining FinCEN’s April rule and the parallel OCC/FDIC/NCUA proposal that dropped the same day. The Fed had sat out that first round. It isn’t sitting out this one. This is part of a broader wave of 2026 AML program requirement changes, and comments are open through September 7.
And in the background, FinCEN is reportedly preparing to go further still, floating changes that would ease customer due diligence requirements on top of everything else already in motion.
Read that as one story, not three, and the story is simple: every regulator with a hand on the AML dial is turning it the same direction. Less mandated process. Less checking boxes. More emphasis on explaining why your risk-based AML program works the way it does, and whether it is effective.
That should concern anyone whose program was built to satisfy an examiner rather than to catch bad actors.
Here’s the part nobody’s saying out loud.
A lighter compliance burden doesn’t mean lowering the bar. It means moving the goal post from following the process to identifying the threat. When the checklist gets shorter, check-the-box AML stops being what protects you. What protects you is whatever you built to replace it.
For twenty years, that gap has been ignored. The rules rewarded documented process, so documented process is what the industry built: an entire compliance economy optimized for passing exams, not for finding the small fraction of illicit activity that transaction monitoring was ever designed to catch. Take the paperwork away and what’s left is whatever intelligence capability sits underneath it. For most institutions, that’s not much.
This is the trade the regulators are betting on, whether they’d frame it this way or not. Reduce the burden on the low-risk majority of activity, and now require financial institutions to redirect that freed-up capacity toward the high-risk activity that matters. That only works if the institution actually knows which activity is high-risk — not by transaction size or geography, but by who’s behind it and what they’re doing. That’s a threat-actor question. It has never been a checklist question.
What “AML/CFT program effectiveness” actually requires
So what do you do with three converging rulemakings and a BSA compliance comment period that closes in September? You don’t wait for the final rule to figure out what “effective” means. You get ahead of it. Ask your program a harder question than any examiner currently asks: if the paperwork went away tomorrow, what would still tell you a real threat actor is operating inside your institution? If the honest answer is “not much,” that’s the actual finding here — not the rule text, the gap underneath it.
The difference between AML compliance and AML effectiveness is exactly this: compliance asks whether you followed the process; effectiveness asks whether you found anything real. Regulators are now measuring the second thing, not the first.
The regulators are betting that financial institutions will use this moment to get sharper. The ones who do will be sitting on a real advantage when the rest of the industry is still rewriting policy manuals to match a rule that’s already changed twice this year.
We built Hybrid Threat Finance™ for exactly this moment, because when the compliance dragnet gets smaller, the intelligence underneath it has to get better. Let’s talk about what that looks like for your program.
(See our earlier breakdown of FinCEN’s April rule for the first piece of this story.)