A Program that Passes isn’t the same as one that Works
July 2026 Webinar Recap
SESSION INSIGHTS
“Effectiveness” Is the New Exam Standard
Most AML risk assessments have the same life cycle – they get completed once a year, they go in a drawer, and they come out of the drawer when the examiner or the auditor asks for them. They earn a compliment or a criticism, a few recommendations get noted for next year, and the cycle repeats.
That is a document that passes. It is not the same as one that works.
The distinction used to be academic. Under FinCEN’s proposed AML/CFT Program Rule, it is the whole exam.
What the Proposed Rule Actually Changes
In April 2026, FinCEN issued a Notice of Proposed Rulemaking to reform financial institution AML and CFT programs, replacing an earlier July 2024 NPRM that was never finalized. The comment period closed June 9, 2026. The final rule is expected within roughly six months — late 2026 into early 2027 — and the direction is unlikely to shift much from the proposal.
Five changes matter to anyone who owns a program:
The standard is effectiveness, not completeness. The rule moves supervision away from check-the-box compliance toward risk-based programs that actually help fight financial crime while cutting unnecessary burden.
The risk assessment becomes mandatory and defined. It stops being an informal exercise and becomes a required, explicitly specified component of the program.
It is a living document. The expectation is that it gets maintained as the institution changes — not refreshed annually and shelved.
Resource allocation has to be real. People and controls are expected to sit where the risk actually is.
Supervision shifts with it. Examiners move from testing whether the required elements exist to evaluating whether the program works.
The bottom line for practitioners: the risk assessment is now the foundation everything else is judged against. Every question an examiner asks ties back to it.
The Word Nobody Defined
Here is the problem. The rule mandates effectiveness. It does not define it.
What counts as effective at a $40 billion institution with correspondent relationships across three continents is not what counts as effective at a community bank with a single branch footprint. That variability is the point of a risk-based regime — and it is also what makes the standard so uncomfortable to operationalize.
Most of what the rule describes is not new. Institutions working in private banking, international banking, NRA relationships, and correspondent banking have applied a risk-based approach since the early 2000s. What changed is that it is now coded into law — and paired with a standard the institution itself has to make demonstrable.
There is precedent for how this plays out. Global AML supervision already made this move: from technical assessment, which asks whether the required elements exist, to effectiveness assessment, which asks whether the regime actually works. Evaluators stopped counting statutes and started asking who supervises which sector, where SARs are being filed, and whether the quality of those filings is any good.
Bring that lens down to your own institution. When the examiner arrives, they are asking a version of the same thing: what are you designed to detect, how do you detect it, and does the cycle end in a quality output?
Traceability Is How You Prove It
Because “effective” is undefined, the burden shifts. The institution has to make effectiveness demonstrable rather than argue it.
The mechanism is traceability.
This is a real break from how effectiveness has been measured in practice. The old proxies were volume-based: how many SARs were filed, how large the compliance department is, how many hours of training were delivered. Those numbers describe activity. They say nothing about whether the program works. The new question is whether every decision can be traced and examined.
Consider the exchange every BSA officer should be able to survive. The examiner points at an alert and says: you did not file a SAR on this — walk me through the process that determined it wasn’t suspicious. If the path from detection to disposition to decision is documented, the institution is defensible. If it isn’t, no volume of activity compensates.
The national priorities are where this gap shows up most often. The eight priorities have not changed since they were issued. Most institutions have incorporated priority language into their AML manual — and stopped there. Policy language without a traceable path is precisely the deficiency examiners are finding.
For each priority, the chain has to hold end to end: from the priority, to a written procedure for detecting that specific illicit activity, to the monitoring rules or thresholds mapped against it, to alert generation and disposition, to the final filing decision with its reasoning documented.
It is the same standard that has always applied to training. You show the program, the procedure, the attendance records, and the content. Nobody accepts “we train our staff” as evidence. The rule now applies that logic to the entire program.
Regulators are already reading SAR filings — and the alerts institutions chose not to file on — specifically to see whether they tie back to the risk assessment and the national priorities. Many institutions producing genuinely high-quality SARs still cannot connect those dots. That connection is the work to do now.
Where Manual Risk Assessments Quietly Break Down
The proposed rule raises the floor on what a defensible risk assessment requires, and it exposes the shortcuts.
The most common shortcut is the FFIEC manual chart from 2014 — the cheat sheet asking whether the institution has “a significant number” or “a large amount” of something. It is over a decade old, and it was never designed to substitute for institution-specific analysis. Institutions that leaned on it are the most exposed.
Define “significant” for your own book. These terms are relative to complexity: total transaction flow, customer count, and the products, services, channels, and geographies offered. Five hundred NRAs inside a 50,000-customer base looks immaterial by headcount. If those 500 customers move 60 to 80 percent of total dollar volume, they are the most material thing in the portfolio. Quantify it rather than defaulting to a label.
Calculate inherent risk as probability times impact. Probability means the likelihood that a specific risk event occurs — and the FFIEC chart never told anyone what those events are. They have to be defined, driven by the vulnerabilities of each product, service, customer, and channel: a jurisdiction with weak AML controls, FATF grey-list exposure, a foreign customer whose stated address and net worth cannot be verified in person, an overnight drop box. Probability should then be weighted by transaction count and value, not by customer headcount.
Impact is what happens if the event materializes: a fine, a consent order, loss of license, franchise damage. The proposed rule folds technology risk into that analysis alongside the traditional operational, legal, and compliance risks — a reasonable move given how completely most institutions now depend on their systems. Bad or obstructed data is its own exposure. What the system cannot see, it cannot monitor, and suspicious activity goes undetected on a timeline nobody can defend.
Separate the subjective from the objective. “The regulator considers all NRAs high risk” is a default. Whether your own transaction data supports that rating for your book is an analysis. Both have a place — but only the second one traces.
Reputational risk deserves a note. It was removed from the enterprise-wide risk assessment, but it still carries weight from an AML perspective. An institution known as the banker for shady actors in shady jurisdictions eventually loses its good customers, and that erosion reaches safety and soundness. Weigh it deliberately even where the enterprise-wide view no longer requires it.
The Question That Decides Your Rating
Residual risk — what remains after controls — is where effectiveness actually lives. For every control claimed, the institution has to trace it end to end and show it was designed to mitigate a specific, identified risk. For a high-risk segment, is customer due diligence the only control, or are there others? Those are the controls that get analyzed for whether they work.
Roll customers, products, services, channels, and geographies into a single consolidated risk profile, and the implied test is blunt: can this institution reasonably identify suspicious activity?
Then comes the question that separates two institutions with identical ratings:
Are you moderate-high because your controls are weak, or because your inherent risk is genuinely high and you hold it there with strong controls?
Same rating. Opposite verdicts. High inherent risk, robust controls, and a board that has knowingly accepted that risk appetite is a defensible position. High residual risk for lack of trying is a finding.
This is also where de-risking originates. When controls are already maxed out, the only remaining lever is reducing inherent risk — exiting a product or a customer segment, whether correspondent banking or money services businesses, that the institution has decided it cannot support at the required rigor. That should be a documented, deliberate decision. Too often it is a reflex.
What to Do in the Next Six to Twelve Months
Waiting for the final rule is the wrong posture. The work is available now, and it runs in both directions.
Make the risk assessment drive the program. Correlate the assessment with the program manual — examiners will now request both and read them side by side, and a manual full of policy but thin on procedure sitting next to a moderate-high rating does not correlate. Update the manual from the assessment report. Make sure the methodology and report explain why the institution is inherently high or low, which controls reduced that risk, and what is missing in between. Those gaps become recommendations to strengthen controls. They are recommendations, not findings — a risk assessment is not an audit, and it is worth saying so to clients who flinch at the word.
Make the program drive the risk assessment. Most assessments count alerts and SARs filed versus not filed, then stop. Add the substance: how suspicious activity is detected, whether the system is validated and working, how alerts are disposed, when detection was last calibrated, and whether any rules or thresholds are tied to the national priorities.
Push the auditors for substance. “We tested SARs and the bank complies” is a technical result, not an effectiveness test. Require the auditor to write what they tested, which components of the SAR process they covered, and what they found. Otherwise there is nothing concrete to hand a regulator later.
Validate the models and the data. Confirm the system detects what it is believed to detect. Poor data means poor visibility into real exposure, and examiners will ask for model validation alongside the risk assessment and the audit.
Two questions are worth keeping on the wall through all of it. How does your risk assessment drive your program? And how does your program drive your risk assessment? Answer both with traceable evidence and the effectiveness standard stops being a threat.
Every one of these demands the same underlying capability: a risk assessment calculated from real data, tied to the controls it justifies, kept current, and traceable end to end. That is exactly where manual processes break down — the connections don’t hold, the data can’t be trusted, and the trail an examiner asks for was never built.
At RiskRator, we built the platform around that problem: calculating inherent and residual risk from an institution’s own transaction data, mapping controls to the risks they mitigate, and producing the documented, traceable methodology the effectiveness standard rewards.
This article draws on insights shared during RiskRator’s webinar series. It is provided for general information and is not legal or compliance advice; institutions should evaluate the FinCEN proposed rule and any final rule against their own circumstances.
Interested in the Free Practitioner’s Guide on this?


