On July 7 the Federal Reserve Board proposed amending the AML/CFT program requirements for the banks it supervises (published July 9 at 91 FR 42363, with comments due September 8). The Board voted 6–1 to issue the proposal, with Governor Michael Barr dissenting. It is the Fed’s entry into a rewrite already proposed separately by four other agencies, implementing the Anti-Money Laundering Act of 2020.
The direction of travel is consistent across the proposals. Programs would be judged by effectiveness rather than procedural completeness. Banks would “focus their anti-money laundering resources based on risk, with more attention given to higher-risk customers and activities,” and would “incorporate the Financial Crimes Enforcement Network’s anti-money laundering priorities into their risk assessment processes.” Once a program is established, the Fed says it would concentrate “supervision and enforcement activities on significant failures to implement the program.”
The pivot from process to risk
| Today | Proposed |
|---|---|
| Pillar-based program checklist | Risk-based program judged on effectiveness |
| Risk assessment as best practice | Documented risk assessment as an anchor requirement |
| National priorities referenced loosely | FinCEN priorities wired into the risk assessment |
| Findings on any program gap | Supervision focused on significant implementation failures |
The risk assessment stops being the binder nobody opens and becomes the load-bearing wall of the program. Everything else must trace back to it.
What to do with the comment window
For community institutions, the promise of this framework is proportionality. Resources go to your actual risk instead of a uniform checklist. The risk is ambiguity, because “effectiveness” and “significant failure” are standards examiners will interpret in the field. The comment window (through September 8) is the moment to ask for the definitions and examples that will constrain that discretion, and to say concretely what a proportionate program looks like at a $500 million bank.
- Start the gap analysis now. Put your current risk assessment next to FinCEN’s priorities and note what it does not address.
- Comment by September 8. Ask for concrete effectiveness criteria and community-bank examples, citing your own scale.
- Track the five proposals as one program rewrite. Your BSA policy will need a single coherent update instead of five patches.
Zovos drafts the documented risk assessment the proposed rules anchor on. It builds the assessment from your activity data and maps it line by line to FinCEN’s priorities.
This is for information only and is not legal advice. Confirm your obligations against the proposal text and counsel before acting.