By Syed Khalid, CEO & Fractional Chief Compliance Officer, FinCheck LLC · July 13, 2026
The most consequential rewrite of U.S. AML program rules in a generation is now moving toward the finish line. FinCEN’s proposed rule to reform anti-money laundering and countering the financing of terrorism (AML/CFT) program requirements — published in April 2026 — closed its comment period on June 9, and Treasury’s summer regulatory agenda makes the direction unmistakable: “effectively tailored,” risk-based programs judged on outcomes, not paperwork volume. For MSBs, crypto firms, fintechs, and gaming operators, the question is no longer whether the framework changes, but whether your program is ready when it does.
What FinCEN Actually Proposed
The April 2026 Notice of Proposed Rulemaking — which fully supersedes and withdraws the 2024 proposal — implements the AML Act of 2020 and rebuilds program expectations around five pillars of reform:
Effectiveness over volume: compliance obligations refocus on whether a program actually mitigates illicit finance risk, distinguishing deficiencies in program design from deficiencies in implementation.
Institutions own their risk: FinCEN affirms that financial institutions — not examiners — are best positioned to identify and evaluate their own illicit finance risks.
Resources follow risk: firms are explicitly empowered to shift attention and budget toward higher-risk products, customers, and geographies, and away from demonstrably lower risks.
Guardrails on examiners and auditors: clarified expectations for independent testing so that reviewers do not substitute subjective judgment for an institution’s reasonably designed, risk-based decisions.
FinCEN at the center: a new notice-and-consultation framework between federal banking supervisors and FinCEN for significant AML/CFT supervisory actions.
FinCEN has proposed a 12-month implementation period once the rule is finalized — a runway that will feel shorter than it sounds.
The Sleeper Provision: A Formal Risk Assessment Mandate for MSBs and Casinos
Buried in the flexibility narrative is a new hard requirement. Today, there is no explicit regulatory obligation for MSBs, casinos, broker-dealers, or mutual funds to maintain a documented risk assessment process — it has been supervisory expectation and best practice, not rule text. The NPRM changes that: every covered financial institution would be expressly required to run a risk assessment process, one that considers the government’s national AML/CFT priorities and feeds directly into program design.
For money service businesses, crypto exchangers registered as MSBs, and card clubs or casinos — including sweepstakes and social gaming models operating near the regulatory perimeter — this converts the risk assessment from a “nice to have” exam artifact into the legal backbone of the entire program. A stale, template-driven assessment will no longer be a documentation weakness; it will be a program design deficiency.
What “Risk-Based” Will Not Mean
It is tempting to read this reform — alongside FinCEN’s July agenda signaling relief on customer due diligence and the delay of the investment adviser rule to 2028 — as deregulation. That is the wrong read. Enforcement attention is shifting toward material and systemic failures rather than isolated technical violations, which cuts both ways: fewer citations for footfaults, but far less tolerance for programs that cannot demonstrate a defensible link between their risk profile and their controls.
Under the new architecture, “we follow the same checklist as everyone else” stops being a defense. Examiners will ask why you scoped your monitoring, staffing, and testing the way you did — and the answer must live in your risk assessment, refreshed and evidenced.
The 12-Month Runway: Where to Focus Now
Firms that wait for the final rule will spend their entire implementation window catching up. Practical priorities for the second half of 2026:
Rebuild the risk assessment as a process, not a document — with defined triggers, data inputs, national priorities mapping, and board-level visibility.
Trace every control to a risk: transaction monitoring rules, KYC tiers, and training plans should each cite the risk they mitigate — and low-risk areas should show deliberate, documented de-prioritization.
Recalibrate independent testing: audits should evaluate design and implementation separately, mirroring how deficiencies will be classified under the new rule.
Document governance: who approved the program, on what risk rationale, and when it was last challenged.
FinCheck’s Perspective & Way Forward
At FinCheck, we see this reform as the strongest opportunity in years for lean compliance teams. The old regime punished non-banks with bank-style checklist expectations they were never resourced to meet. A genuinely risk-based standard rewards firms that know their business deeply — exactly where MSBs, crypto platforms, fintechs, and gaming operators can outperform. But the entry ticket is a living, defensible risk assessment and a program that visibly flows from it. Our advice: treat H2 2026 as your implementation year. Refresh the risk assessment now, pressure-test it with an independent review, and walk into the final rule ahead of your examiners rather than behind them.
FinCheck LLC supports FinTechs, MSBs, crypto, e-commerce, and gaming businesses with BSA/AML risk assessments, policy and procedure development, independent AML audits, and fractional compliance officer leadership — 25+ years of experience, 100+ satisfied clients worldwide.
Ready to get ahead of the final rule? Let’s talk — fincheckllc.com