By Syed Khalid, CEO & Fractional Chief Compliance Officer, FinCheck LLC · July 1, 2026
Every few years, the U.S. Department of the Treasury pulls back the curtain and tells the private sector where the money is actually moving. Its 2026 National Money Laundering Risk Assessment (NMLRA), released alongside companion assessments on terrorist financing and proliferation financing, is exactly that kind of document — a consolidated, government-wide view of how illicit funds enter and move through the American financial system. For compliance leaders at fintechs, crypto platforms, money services businesses, and gaming operators, it is not bedtime reading. It is a benchmark against which your own enterprise risk assessment will, eventually, be measured.
Released in March, the NMLRA has now had a quarter to settle. That makes mid-2026 the right moment to stop treating it as headline news and start treating it as an input — a source document your next risk-assessment refresh should visibly reflect. Examiners increasingly ask a simple question: does your institution’s risk assessment account for the threats the government has publicly identified? If the answer is no, that gap is difficult to defend.
What the 2026 Assessment Actually Says
The headline threats are familiar, and their persistence is the point. Treasury again identifies fraud, drug trafficking, cybercrime, human trafficking, human smuggling, and corruption as the largest generators of illicit proceeds in the United States. Fraud in particular — much of it now powered by scam networks and elder-targeting schemes — remains the dominant predicate, and the median loss in sentenced money laundering cases has risen sharply in recent years.
Several themes stand out for regulated non-bank institutions:
- Professional launderers are scaling. Third-party money laundering networks — including Chinese money laundering organizations — continue to offer laundering-as-a-service, compressing timelines and increasing the profitability of the underlying crime.
- Technology is the accelerant. Digital assets, encrypted messaging, social media, and artificial intelligence are increasingly exploited to perpetrate fraud, coordinate securely, and obscure the origin of funds. AI’s ability to lower the barrier to sophisticated fraud is called out as a top-tier concern.
- Beneficial ownership remains the soft spot. Shell companies, complex corporate structures, and professional intermediaries are still the preferred tools for hiding who ultimately controls the money — and for pushing proceeds into real estate and legitimate businesses.
- Trade and cash still matter. Trade-based money laundering, broker networks, and the Black Market Peso Exchange endure as durable channels, a reminder that old typologies do not retire simply because new ones arrive.
Crucially, Treasury frames these findings as the evidentiary base for the forthcoming 2026 National Illicit Finance Strategy — the policy roadmap that will shape supervisory priorities and, ultimately, examination focus. In other words, what the NMLRA flags today tends to become what examiners probe tomorrow.
Where These Risks Land Hardest
The assessment reads differently depending on where you sit. For FinCheck’s client base, the exposure is concrete:
- Money services businesses sit at the intersection of cash intensity, cross-border flows, and agent networks — precisely the channels professional launderers target. Expect scrutiny of agent oversight, structuring detection, and funnel-account activity.
- Crypto and digital-asset firms are named repeatedly as a laundering vector. The pairing of pseudonymous rails with AI-enabled fraud raises the bar for blockchain analytics, Travel Rule execution, and sanctions screening.
- Gaming and sweepstakes operators face layered risk: fraud, account takeover, and the use of play as a placement or layering mechanism. Player due diligence, geolocation integrity, and payout monitoring are all in scope.
- Fintechs and BaaS participants inherit the beneficial-ownership problem wholesale, onboarding entities at speed while bank partners expect bank-grade CDD. The NMLRA’s emphasis on opaque structures is a direct message to this segment.
Why a Point-in-Time Risk Assessment No Longer Holds
The uncomfortable implication of the NMLRA is that threat velocity now outpaces the annual risk-assessment cycle many institutions still run. AI-enabled fraud, synthetic identities, and laundering-as-a-service do not wait for your calendar. A risk assessment written eighteen months ago, however polished, may already misstate the institution’s real exposure.
This does not mean rewriting the document every quarter. It means building a living methodology: a defined process for ingesting new national and sector guidance, mapping it to your products and channels, and documenting why a given threat is or is not material to you. Regulators are far more forgiving of a well-reasoned “not applicable” than of silence.
FinCheck’s Perspective & the Way Forward
Our view is direct: the 2026 NMLRA is the most useful free risk-assessment input your program will receive this year — but only if you operationalize it. Three steps make the difference between a document that sits on a shelf and one that strengthens your defense.
- Map the threats to your risk assessment now. Take each NMLRA threat and vulnerability and record, in writing, whether and how it applies to your customer base, products, geographies, and channels. Close any gap where a named national threat is absent from your own assessment.
- Pressure-test your detection scenarios. Confirm your transaction monitoring, sanctions screening, and fraud controls actually cover professional-launderer typologies, AI-assisted fraud, and beneficial-ownership evasion — not just textbook structuring.
- Prepare for the strategy and the advisory. With the National Illicit Finance Strategy and a Treasury red-flag typology advisory expected to follow, ensure your governance can absorb new guidance quickly, update procedures, and evidence board-level awareness.
The institutions that treat the NMLRA as a compliance obligation will file it. The ones that treat it as intelligence will use it — to sharpen their risk assessment, defend their program in the next examination, and stay ahead of typologies that are evolving faster than the rulebook. That is the posture we build with our clients: risk-based, evidence-led, and genuinely current.
Is your risk assessment current?
FinCheck LLC helps fintechs, crypto platforms, MSBs, and gaming operators refresh BSA/AML risk assessments, run independent AML audits, and deploy fractional compliance leadership — mapping national threat guidance directly to your program. Let’s make sure your next examination finds a risk assessment that reflects the world regulators are actually watching.
Learn more at fincheckllc.com · Global Compliance Consulting for FinTech, Crypto, MacSB & Gaming.