search

FinCEN Updates 2026: New Beneficial Ownership and AML Rules

5/8/2026

The last several years have been the most active period of AML rulemaking since the USA PATRIOT Act, and unusually for compliance topics, much of it has not settled. Rules have been finalized, challenged in court, narrowed by interim rules, and had compliance dates moved.

This post covers the developments a bank compliance function needs to be tracking, what each one means operationally, and — importantly — which of them are still in motion.

The Legislative Backdrop

Three instruments shape everything below.

The Anti-Money Laundering Act of 2020, enacted as part of the National Defense Authorization Act for fiscal year 2021, is the largest overhaul of the BSA regime in two decades. It directed Treasury to modernize the framework, expanded whistleblower protections and awards, strengthened penalties, and required the establishment of national AML/CFT priorities that institutions must incorporate into their programs.

The Corporate Transparency Act, enacted within the same legislation, created a beneficial ownership reporting regime aimed at shell companies — requiring companies themselves to report their beneficial owners to FinCEN, rather than requiring banks to collect the information.

The national AML/CFT priorities, first issued in 2021, name the threat areas Treasury considers most significant. Institutions are expected to consider them in their risk assessments and programs.

Beneficial Ownership: Two Regimes, Frequently Confused

This is the area where staff most often go wrong, so it is worth stating plainly.

The CDD rule obligates banks. Since May 2018, covered financial institutions must identify and verify beneficial owners of legal entity customers at account opening — the 25 percent ownership prong and the control prong. This is a bank obligation, performed at onboarding, and it is unaffected by anything that happens to the Corporate Transparency Act.

The Corporate Transparency Act obligates companies. Reporting companies file beneficial ownership information directly with FinCEN, into a registry that authorized recipients — including financial institutions with customer consent, for CDD purposes — may access under defined conditions.

The CTA's implementation has been genuinely turbulent. Reporting began in January 2024, was subject to litigation through 2024 and into 2025, and FinCEN issued an interim final rule in March 2025 that substantially narrowed the scope of who must report, exempting domestic reporting companies and focusing the obligation on foreign reporting companies.

NOTE TO EDITOR: Confirm the current CTA scope and whether the interim final rule was finalized, amended, or superseded before publishing. This paragraph is the highest-risk statement in the article.

What this means for a bank: your CDD obligations did not change. Continue collecting beneficial ownership from legal entity customers exactly as before. What changed is the availability and coverage of the FinCEN registry as a corroborating source — not your duty to collect.

AML Program Modernization

FinCEN proposed rules to implement the AML Act's modernization mandate, restructuring the program requirement around programs that are "effective, risk-based, and reasonably designed," with explicit incorporation of the national AML/CFT priorities and a formalized role for the risk assessment.

The direction of travel matters even where the final text is still pending. The emphasis is shifting from process compliance — did you file, did you train, did you test — toward effectiveness: whether the program actually produces useful output for law enforcement and allocates resources to the institution's real risks.

Practically, this rewards institutions that can demonstrate:

  • A risk assessment grounded in their own data, not a template
  • Monitoring tuned to identified risks rather than to vendor defaults
  • Resource allocation proportional to risk, with low-value activity deliberately reduced
  • Consideration of the national priorities documented in the assessment

NOTE TO EDITOR: Confirm whether the AML program effectiveness rule has been finalized and its compliance date before publishing.

Expansion to New Sectors

Two expansions matter to banks even though neither regulates banks directly.

Investment advisers. FinCEN finalized a rule extending AML/CFT program and SAR requirements to certain registered investment advisers and exempt reporting advisers, closing a long-identified gap. Compliance dates for this rule have been subject to adjustment.

Residential real estate. A rule requiring reports on certain non-financed transfers of residential real property to legal entities and trusts addresses a channel long used to place illicit funds.

NOTE TO EDITOR: Verify the current compliance dates for both rules; the investment adviser rule's date in particular has been revised.

Why a bank should care. First, these are your customers — advisers and title companies banking with you now carry their own obligations, which changes their risk profile and your due diligence conversations. Second, the direction is consistent: gaps in the perimeter are being closed, and institutions that serve gatekeeper professions should expect more scrutiny of those relationships.

Sanctions and OFAC

Sanctions activity has been intense and shows no sign of slowing. The operational lessons are stable even as the lists change:

  • Screening frequency matters. Lists change without notice; batch screening on a monthly cycle leaves an unacceptable window.
  • Fuzzy matching needs tuning. Too tight and you miss; too loose and analysts drown in false positives and start clearing them mechanically.
  • Sanctions are strict liability. There is no suspicion standard and no threshold. This distinguishes OFAC from the BSA and should be trained separately.
  • 50 percent rule exposure. Entities owned 50 percent or more by blocked persons are themselves blocked even when not listed, which requires ownership analysis rather than name matching.

What to Do in the Next 90 Days

A practical sequence for a compliance function absorbing all of this:

  1. Confirm your CDD procedures were not changed in response to CTA news. Several institutions relaxed collection on the mistaken belief that the CTA narrowing affected their obligations. It did not.
  2. Refresh the risk assessment with explicit reference to the national AML/CFT priorities, documenting which apply and which do not, and why.
  3. Review monitoring tuning against the risks the assessment identifies, and document the rationale for current thresholds. Under an effectiveness standard, "these are the vendor defaults" is not an answer.
  4. Identify customers in newly covered sectors — investment advisers, title and escrow companies — and revisit their risk ratings and due diligence.
  5. Update training to reflect the two-regime beneficial ownership distinction, because this is where front-line confusion is concentrated.
  6. Set a monitoring routine for FinCEN announcements with a named owner, rather than learning about changes from an examiner.

How to Keep Current

Subscribe to FinCEN's own announcements and to your primary regulator's issuances rather than relying on secondary coverage, which lags and sometimes misstates. Read the FFIEC BSA/AML Examination Manual updates, because that is what examiners work from. And build regulatory change management into the compliance calendar as a standing activity with an owner — the institutions that struggled most in this period were not the ones that disagreed with the rules, but the ones that found out late.

Structured coverage of the framework these changes sit inside is available through our Certificate in BSA and AML Compliance and our broader BSA and AML training.

Building a Regulatory Change Process That Works

The institutions that struggled most through this period were rarely the ones that disagreed with a rule. They were the ones that found out about it late, or found out on time and had no process for turning an announcement into a change in operations. A functioning regulatory change process has five components, and it is worth building before the next wave rather than during it.

Intake with a named owner. One person is accountable for monitoring FinCEN, the primary federal regulator, the FFIEC, and OFAC, on a defined cadence rather than opportunistically. Distributing this across a team without naming an owner reliably produces gaps, because everyone assumes someone else read it.

Applicability assessment. For each development, a recorded determination of whether it applies to the institution and why. "Not applicable" is a legitimate and common conclusion — but it must be documented, because the alternative is indistinguishable from never having considered it.

Impact analysis. Which policies, procedures, systems, training modules, and reports are affected. This is where the work actually gets scoped, and it usually reveals that a single rule touches four departments that do not routinely coordinate.

Implementation with dates and owners. Tasks assigned, deadlines set against the compliance date rather than against convenience, and progress tracked somewhere visible to management.

Validation. Confirmation after the compliance date that the change actually took effect — the procedure was updated, the system configuration changed, the training was delivered. This step is skipped constantly, and it is the reason institutions discover at examination that a change was planned, assigned, and never completed.

The log this process produces is itself an examination asset. When an examiner asks how the institution stays current, a dated register showing each development, the applicability decision, the actions taken, and the validation date answers the question in a way that no verbal description can. Institutions without one end up arguing that they are diligent; institutions with one demonstrate it.

A closing caution on sourcing. During periods of rapid change, secondary coverage — including vendor newsletters and industry press — frequently reports proposed rules as final, final rules as effective, and court decisions as broader than they were. Several institutions changed procedures during this period on the basis of headlines that misstated the scope of a ruling. Before acting on any development described here or elsewhere, read the primary source: the FinCEN announcement, the Federal Register text, or the court's own order.

It is also worth setting expectations internally about the pace. Compliance teams that treated this period as an anomaly to be endured spent it in a permanent state of catch-up. The teams that handled it well treated frequent change as the normal operating condition and built for it — a standing agenda item, a named owner, a register, and a quarterly review with the business lines most affected. That posture costs a few hours a month and converts each new announcement from a disruption into a routine intake.

Frequently Asked Questions

Did the Corporate Transparency Act changes affect a bank's CDD obligations?

No. The CDD rule requiring banks to identify and verify beneficial owners of legal entity customers at account opening is a separate regulation and remains in force. Changes to the scope of the Corporate Transparency Act affect which companies must report to FinCEN's registry — not what banks must collect from customers.

What are the national AML/CFT priorities?

Threat areas identified by Treasury under the Anti-Money Laundering Act of 2020 that institutions are expected to consider in their risk assessments and programs. The practical expectation is that an institution can show it evaluated each priority and documented whether and how it applies to its own risk profile.

Are investment advisers now subject to AML requirements?

FinCEN finalized a rule extending AML/CFT program and suspicious activity reporting obligations to certain registered investment advisers and exempt reporting advisers. Compliance dates have been adjusted since finalization, so confirm the current date before relying on it — and note that this changes the risk profile of adviser customers your bank serves.

What does "effective, risk-based, and reasonably designed" mean?

It signals a shift in supervisory emphasis from whether required processes were performed to whether the program produces useful results and directs resources at the institution's actual risks. In practice it raises the importance of the risk assessment, of documented tuning decisions, and of being able to explain why the program looks the way it does.

How should a bank track FinCEN rule changes?

Assign a named owner for regulatory change management, subscribe directly to FinCEN and to the institution's primary regulator, review FFIEC manual updates, and maintain a log that records each development, the assessment of whether it applies, and the actions taken. Relying on secondary reporting or on annual training to surface changes is what produces late discovery.

Is OFAC compliance part of BSA?

They are separate regimes that are commonly trained together. OFAC administers sanctions and imposes strict liability with no suspicion standard and no dollar threshold, while the BSA imposes recordkeeping and reporting duties based on defined thresholds and suspicion. Policies and procedures should treat them distinctly even where training combines them.

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026