Banking regulators are rewriting the trigger for anti-money-laundering enforcement, moving it away from technical paperwork gaps and toward failures serious enough to threaten a bank’s actual ability to catch illicit finance. The Federal Reserve’s July 7 proposal, released alongside a coordinated push from four other federal agencies, is the clearest signal yet that Washington’s AML compliance regime is shifting from volume-based citations to risk-based judgment.
What the Fed Actually Proposed
The Federal Reserve Board voted to request public comment on amendments to the anti-money-laundering program requirements that banks under its supervision must maintain. The core change is a mandate that banks allocate compliance resources according to risk: institutions must concentrate AML staffing, monitoring, and investigative capacity on the customers and activities that present the highest money-laundering exposure, rather than spreading effort evenly across a portfolio regardless of risk profile.
Banks would also be required to fold the Financial Crimes Enforcement Network’s national AML priorities directly into their own risk assessments, so that a bank’s internal compliance calendar tracks what FinCEN has flagged as the highest-priority threats, from fentanyl trafficking finance to corruption-linked flows, rather than a static, historical view of risk.
The most consequential change is where the Fed sets the bar for citing a bank at all. Under the proposal, supervisors would reserve formal findings, known as matters requiring attention, and enforcement action for failures that are “significant or systemic,” rather than isolated or purely technical shortcomings in an otherwise functioning program. The Federal Reserve Board opened a 60-day public comment period once the proposal is published in the Federal Register.
Coordinated, Not Unilateral
The Fed’s move did not happen in isolation, and it was not first. The Treasury Department’s Financial Crimes Enforcement Network proposed the underlying risk-based reform back on April 7, 2026, and the FDIC, the Office of the Comptroller of the Currency, and the National Credit Union Administration issued a joint proposed rule the same day to align their own supervisory requirements with FinCEN’s approach. That joint rule also clarifies how banks may share information with FinCEN tied to AML supervisory and enforcement actions, and builds in a consultation framework that gives FinCEN a more direct role in how examiners handle enforcement decisions.
The Federal Reserve’s July 7 vote effectively brings the last major banking regulator into a framework the other four had already committed to three months earlier. For multi-charter banking groups, that sequencing matters as much as the substance: a single risk-based standard, consistently applied by FinCEN, the FDIC, the OCC, the NCUA, and now the Fed, is easier to build one compliance program around than five overlapping ones that drift apart over time.
The Dissent That Frames the Debate
Federal Reserve Governor Michael Barr cast the sole dissenting vote against the proposal. His objection centers on the vagueness of the new bar itself: Barr warned that the “significant or systemic” standard is undefined, and that its unknown effects could weaken the Board’s ability to substantiate, and act on, cases where a bank has failed to establish or maintain an adequate anti-money-laundering program.
That dissent captures the real tension in the proposal. Raising the threshold for a citation should, in theory, free examiners to focus on the failures that actually let dirty money move, rather than on documentation gaps that produce paperwork without reducing risk. But an undefined “significant or systemic” test also hands banks and supervisors alike a genuinely new, untested standard to interpret, with no case history to draw on until it has been enforced, or challenged, in practice.
What Happens Next
The proposal is not final. It enters a 60-day comment window once published in the Federal Register, the same window FinCEN, the FDIC, the OCC, and the NCUA already gave the industry on their April proposals, during which banks, compliance vendors, and consumer and law-enforcement advocates can weigh in before the agencies finalize the combined rule. Nothing in the current program changes until that process concludes, and the Fed’s late entry means the five agencies are not yet on identical clocks, a detail compliance teams tracking effective dates will need to watch closely.
What It Means for the Finance Leader
For chief compliance officers, the practical work starts now, not after the rule is final. Two elements of the proposal are unlikely to change much between draft and final text: the requirement to actively incorporate FinCEN’s national priorities into risk assessments, and the general direction toward risk-weighted resource allocation. Compliance teams that start mapping their current risk assessment methodology against FinCEN’s published priorities now will be better positioned than those who wait for a final rule to force the exercise.
The proposal also echoes a wager regulators elsewhere are making about supervision itself: that existing frameworks, applied with more judgment and less rigidity, can govern new and evolving risks better than new rules layered on top. The UK’s Financial Conduct Authority made a similar bet on existing supervisory frameworks in its recent review of how agentic AI should be governed in retail financial services, opting to test current rules against new technology before writing bespoke ones. The Fed’s proposal is the AML compliance version of the same instinct: trust risk-based judgment over uniform, prescriptive process.
For banks operating across multiple charters or regulators, the near-term move is to submit comments during the window and pressure-test internal AML programs against the “significant or systemic” language now, well before an examiner has to decide what that phrase means in practice.
Source: Federal Reserve Board