On June 5, 2026, FinCEN — jointly with the FDIC, OCC, and NCUA and in coordination with the IRS — issued Advisory FIN-2026-A002, targeting illicit finance tied to unlawful employment and payroll fraud. On the surface, this looks like an employment and tax enforcement issue. Read it closely, and it is one of the most consequential AML developments of the year: financial institutions reported more than $2.5 billion in suspicious activity linked to payroll tax fraud schemes in 2025 alone, and FinCEN has named unregistered money services businesses as a primary laundering vehicle for these proceeds. If you operate a payroll processing firm, an MSB, or a fintech that moves wage-like payments, this advisory is speaking directly to you.
The Typology: Labor Brokers, Shell Companies, and Unregistered MSBs
The advisory describes a recurring scheme. A complicit labor broker sets up a generically named shell company — often functioning as an unregistered MSB — and opens a bank account using a foreign identity document or an Individual Taxpayer Identification Number (ITIN). Employers in construction, agriculture, hospitality, and domestic services pay that shell for purported services. The broker then distributes wages to unauthorized workers through cash couriers, checks, or peer-to-peer platforms, deliberately structured below BSA reporting thresholds, with no payroll tax withholding. Some brokers layer in workers’ compensation fraud by “renting” minimal policies across hundreds of workers, and some launder funds for drug trafficking and transnational criminal organizations through the same shells.
The damage is broader than tax loss. Identity theft underpins these schemes — stolen Social Security numbers of U.S. citizens and lawful residents are used to pass employment verification — and legitimate businesses are undercut by competitors evading payroll taxes and insurance costs. The IRS puts the employment tax gap at $127 billion.
The Headline Change: Enhanced Due Diligence on ITINs
The most significant regulatory shift in the advisory is its treatment of ITINs. Under the CIP rule, banks may accept an ITIN as a valid taxpayer identification number for non-U.S. persons. FIN-2026-A002 now encourages institutions to treat presentation of an ITIN in lieu of an SSN as a risk factor warranting enhanced due diligence — language historically reserved for correspondent banking, private banking for senior foreign political figures, and Section 311 jurisdictions. That is a deliberate signal: ITIN-based accounts are being moved toward the most scrutinized tier of the BSA regime, with deeper source-of-funds review, intensified monitoring, and escalation expectations. Under the CDD rule’s event-driven updating requirement, institutions may also need to reassess risk profiles of existing ITIN-holding customers — not just new ones.
Eighteen Red Flags and a New SAR Key Term
The advisory sets out 18 red flag indicators, organized by individual customers, large companies, and small companies — building on FinCEN’s 2023 Payroll Tax Fraud Notice but going further. Institutions are asked to:
- Incorporate the 18 indicators into transaction monitoring scenarios and alert logic
- Use the SAR key term FINANCIALINTEGRITY-2026-A002 in relevant filings
- Verify questionable Social Security numbers against SSA records
- Train frontline and compliance staff on the labor-broker and shell-company typologies
- Review existing customer relationships where risk indicators are present
The advisory also aligns itself with five of FinCEN’s AML/CFT national priorities — fraud, TCOs, DTOs, human trafficking, and terrorist financing. With the proposed AML/CFT program rule requiring priorities to be embedded in risk assessments, these typologies are effectively previewing tomorrow’s examination expectations.
Why MSBs and Payroll Processors Should Pay Particular Attention
For MSBs, the message is blunt: FinCEN has identified unregistered MSB activity as the connective tissue of payroll fraud laundering. Registered MSBs should be reviewing agent and counterparty relationships and asking whether their customer base shows patterns consistent with distributing unlawfully obtained wages. For payroll processing firms, the advisory effectively raises the bar on client onboarding: who is the employer, is the workforce real, do headcounts reconcile with tax filings, and do disbursement patterns make sense? And for fintechs and P2P platforms, structured wage distribution through your rails is now a named typology — your monitoring scenarios need to see it.
FinCheck’s Perspective & Way Forward
Our view: this advisory is less about immigration policy and more about a structural expansion of what AML programs are expected to detect. Three practical takeaways stand out.
First, calibrate — don’t de-risk. The temptation will be to exit ITIN customers or file defensive SARs wholesale. That is neither risk-based nor defensible, and it invites financial-inclusion and discrimination concerns. Build ITIN risk-scoring into CDD with clear escalation criteria instead of blanket exits.
Second, treat the 18 red flags as a gap assessment. Map each indicator against your current monitoring rules, CIP/CDD procedures, and training content. Most programs we review can absorb 70% of these expectations with tuning — the gaps cluster around shell-company detection, structuring below thresholds, and workforce-to-cash-flow reconciliation.
Third, get ahead of the program rule. With compliance dates expected 12 months after the AML/CFT final rule, institutions that embed these priorities into their risk assessment now will face examiners with evidence, not intentions. Document the decision trail.
FinCheck LLC supports MSBs, payroll processing firms, fintechs, and money transmitters with exactly this work — independent AML audits, BSA/AML risk assessments, MSB registration and licensing, policy and procedure development, transaction monitoring tuning, and fractional compliance officer services. We have helped payroll processors turn state examiner findings into clean examinations, and we can help you operationalize FIN-2026-A002 before it shows up in your next exam scope.
Ready to stress-test your program against the new advisory? Reach out to FinCheck LLC for a focused review of your CIP/CDD framework, monitoring coverage, and SAR procedures against FIN-2026-A002. Visit fincheckllc.com or connect with Syed Khalid on LinkedIn.