October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How to Create an Effective BSA/AML Compliance Program: 2026 Update

Learn how U.S. financial institutions can build a risk-based BSA/AML program, connect CDD to monitoring, assign ownership, test controls, and account for 2026 updates.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An effective Bank Secrecy Act/anti-money laundering (BSA/AML) compliance program starts with the rules that apply to your institution and the risks its actual customers, products, services, locations, and delivery channels create. For covered financial institutions, FinCEN identifies internal controls, independent testing, a designated compliance officer, appropriate personnel training, and risk-based ongoing customer due diligence as core program elements.

Updated October 8, 2026: This article focuses on U.S. financial institutions, particularly institutions covered by FinCEN’s Customer Due Diligence (CDD) Rule and banking organizations subject to FFIEC examination guidance. Requirements vary by institution type and regulator. FinCEN issued beneficial-owner relief in February 2026, and its April 2026 AML/CFT program changes remain a proposal unless finalized.

Start by identifying which requirements apply

There is no single BSA/AML checklist that applies identically to every financial institution. Before drafting a program, identify the institution’s legal and regulatory obligations, its regulator, and the products and activities within scope. FinCEN’s regulations and other applicable laws establish binding obligations; examination materials and supervisory statements can help explain how regulators assess risk and controls but should not be described as statutes or regulations.

The FFIEC BSA/AML Examination Manual is examination guidance. The 2022 interagency Joint Statement on the Risk-Based Approach to Assessing Customer Relationships and Conducting CDD explains that the manual guides examiners and does not establish requirements for banks. Use such materials to understand supervisory expectations, while confirming the actual obligation in the applicable law or regulation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build the program in a sequence that connects risk to controls

A written program is useful only if its requirements translate into responsibilities, repeatable procedures, and evidence that controls operate. A practical build sequence is:

  1. Define scope and governance. Document the institution type, applicable regulator and requirements, products, services, customer groups, geographies, and delivery channels. Designate a compliance officer or responsible individual with clear authority, access to senior management, adequate resources, and a documented escalation route. FinCEN lists designation of a compliance officer as a core element for covered financial institutions.
  2. Assess the institution’s risks. Evaluate exposure across customers, products and services, geographies, transaction patterns, and delivery channels. Record the facts behind the assessment and explain how they affect controls. Revisit the assessment when the business, customer base, products, or risk environment changes.
  3. Translate risk into written controls. Set out operational procedures staff can follow for onboarding, identity verification, escalation, transaction review, suspicious-activity handling, recordkeeping, and quality assurance, as applicable to the institution. Assign each control an owner and retain evidence of its operation. FinCEN identifies internal controls as a core program element.
  4. Implement customer due diligence and monitoring. For covered institutions, connect customer and beneficial-owner information, relationship purpose, risk profiles, ongoing monitoring, and risk-based updates. Monitoring should take account of the expected purpose and activity of a relationship and provide a way to investigate meaningful deviations.
  5. Train people for their roles. Provide role-appropriate training that explains relevant risks, each person’s responsibilities, and escalation routes. Keep evidence of training and revisit its content when roles or program requirements change. A purchased course may support training, but it does not by itself establish that the institution’s program is sufficient.
  6. Test independently and remediate findings. Arrange independent testing proportionate to the institution and its risk. Document the test’s scope and findings, assign owners and deadlines for corrective action, and validate whether remediation worked. FinCEN identifies independent testing as a core program element.
  7. Give leadership useful oversight. Report meaningful information on risk, control performance, exceptions, testing, suspicious-activity trends, and remediation. Keep records of material decisions and update the program when applicable requirements or institutional risks change.

Make the risk assessment specific enough to guide decisions

A risk assessment should describe the institution’s exposure, not simply label broad categories of customers or activities. Avoid treating every customer in a category as automatically prohibited or high risk. Instead, document the institution-specific facts that affect the likelihood or impact of money laundering or terrorist financing and explain the controls those facts call for.

Customer due diligence should be commensurate with BSA/AML risk. Higher-risk relationships may call for enhanced due diligence, but the decision should follow the institution’s assessment and applicable requirements rather than a blanket rule. FinCEN’s beneficial-ownership guidance discusses risks that can arise when nominal account holders or entity structures obscure the natural persons who own or control assets, and describes risk-proportionate CDD and enhanced diligence for relationships assessed as presenting heightened risk.

Connect CDD, customer risk profiles, and ongoing monitoring

FinCEN’s CDD Rule summary identifies four requirements for covered institutions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Identify and verify customers.
  • Identify and verify beneficial owners of legal-entity customers.
  • Understand the nature and purpose of customer relationships to develop risk profiles.
  • Conduct ongoing monitoring to identify and report suspicious transactions, while maintaining and updating customer information on a risk basis.

These elements should work together. Information gathered at onboarding helps establish what a relationship is for and what activity is expected. Monitoring can then identify meaningful departures for investigation, while risk-based updates keep relevant customer information current. FinCEN’s CDD Rule FAQs state that CDD procedures must be included in the covered institution’s AML compliance program.

Account for the February 2026 beneficial-owner relief

On February 13, 2026, FinCEN issued an order granting covered financial institutions exceptive relief from identifying and verifying legal-entity beneficial owners each time a customer opens a new account. The relief is not a general elimination of beneficial-owner obligations. Before changing onboarding procedures, review the order and current FinCEN materials for its exact scope and any subsequent changes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Separate current obligations from proposed changes

FinCEN’s April 2026 AML/CFT program requirements notice of proposed rulemaking (NPRM) proposed changes to program requirements, including a structural reorganization of certain CDD elements. A proposal is not an effective final rule. Do not treat the NPRM’s proposed changes as current obligations unless a final rule has since been issued and applies to the institution.

Keep a process for checking whether applicable rules, guidance, or relief have changed, and record how the institution assessed the effect on its procedures. A static checklist labeled “2024” cannot establish that a program meets current requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
J. J. Keller DOT Handbook: Compliance Guide for Truck Drivers
  • Handy reference covers critical elements of truck driver training including key FMCSA regulatory compliance topics, general info about orientation & company policies, trip preparation, on-the-road information, and incident/accident handling procedures.
  • Filled with truck driver essentials, this handbook helps meet DOT entry-level driver training requirements (49 CFR 380, Subpart E).
  • Easy-to-understand, concise DOT compliance resource works great for truck driver education "finishing training," new hire orientation training, and drivers new to the field. Ideal for Driving Training Instructors for use in aiding their curriculum.
  • Features quizzes at the end of every chapter.
  • 7" x 5" English spiral bound handbook with 192 pages.

How to judge whether the program is effective

Effectiveness is not established by having policies on file. Leadership should be able to see how the institution’s risks map to controls, who owns each control, how staff escalate concerns, and whether testing shows that controls work in practice. Useful review questions include:

  • Does the assessment reflect the institution’s current customers, products, geographies, channels, and activity?
  • Can staff follow the procedures and identify when to escalate an issue?
  • Do customer risk profiles inform monitoring and risk-based information updates?
  • Does independent testing examine control operation, and are corrective actions tracked through validation?
  • Are current final requirements and applicable relief distinguished from examination guidance and pending proposals?

These questions support program oversight; the specific duties remain those applicable to the institution under its governing laws and regulations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.