Video
September 9, 2026

Replay: Driving Effective BSA/AML/CFT Risk Management

Table of Contents

Share with network

Related Insights

Replay: Driving Effective BSA/AML/CFT Risk Management

Replay: Driving Effective BSA/AML/CFT Risk Management

Lorem ipsum dolor set

SEC semiannual reporting proposal: What financial institution leaders need to knowSEC semiannual reporting proposal: What financial institution leaders need to know

SEC semiannual reporting proposal: What financial institution leaders need to know

Lorem ipsum dolor set

Should community banks reconsider the Community Bank Leverage Ratio?Should community banks reconsider the Community Bank Leverage Ratio?

Should community banks reconsider the Community Bank Leverage Ratio?

Lorem ipsum dolor set

Your next CFO probably isn't looking for a jobYour next CFO probably isn't looking for a job

Your next CFO probably isn't looking for a job

Lorem ipsum dolor set

Replay: Responsible AI Starts Here: Governance & Controls in ActionReplay: Responsible AI Starts Here: Governance & Controls in Action

Replay: Responsible AI Starts Here: Governance & Controls in Action

Lorem ipsum dolor set

In this replay of our recent webinar, our team explores the regulatory, operational, and technology developments shaping BSA/AML compliance programs today. The discussion highlights the importance of strengthening risk assessments, validating models, improving data quality, integrating fraud and AML functions, and maintaining documentation that can withstand examiner scrutiny.

Watch the webinar replay.

1. FinCEN's proposed rule shifts BSA/AML/CFT from a checklist-driven risk assessment to an effectiveness-driven program

The pending proposal moves the program away from procedural compliance toward demonstrating you're actually helping law enforcement combat illicit finance. The four pillars remain, but with greater emphasis on how they feed into your risk assessment. National AML priorities (including fraud) must now be embedded in your risk assessment with assigned risk grades and mapped controls. With a proposed 12-month implementation window, executives should direct BSA teams to analyze their risk assessment and controls, close gaps, and evaluate tech and AI resources now.

2. Corporate Transparency Act relief is real, but CDD obligations remain

As of the August 11 final rule, U.S. entity customers no longer report beneficial ownership information to FinCEN (only foreign entities/persons do), and previously submitted data will be deleted. However, this does not eliminate your 2016 Customer Due Diligence (CDD) Rule obligations. Institutions must still collect beneficial ownership at the initial account opening of a new customer. Verbal collection is permitted only for existing customers when your internal procedures require it, not for new customers.

3. BSA model validations are non-negotiable, even after guidance was rescinded

OCC, Federal Reserve Board, and FDIC rescinded prior Model Risk Management (MRM) guidance, but a footnote confirms supervisory action still applies if poor model management leads to violations. Best practice: validate at least every 3 years, and prioritize immediately if you've never validated, are switching models, or are deploying AI. With two-plus systems always in play, undetected data gaps (e.g., a transaction type not flowing into your monitoring model) can let suspicious activity slip through.

4. There’s no way to optimize bad data

Bad data in, bad data out. Before optimizing models, confirm transactions are coded correctly and customer data maps properly from the core. Signs that optimization and validation are overdue: high alert volumes that never escalate, rapid growth in customers or products, or new fintech or digital account delivery channels.

5. The dividing line between fraud and AML is disappearing

With fraud now a national priority and typologies evolving fast (e.g., check washing, synthetic identity theft, elder exploitation, account takeover, peer-to-peer scams), the separation between fraud and BSA/AML is dwindling. Executives should push for cohesive, cross-trained teams.

6. Documentation remains your strongest defense during examinations

Examiners want to see how your risk assessment, controls, Enhanced Due Diligence (EDD), investigations, and Suspicious Activity Reports (SARs) connect into a coherent program. Strong documentation demonstrates that risks were identified, assessed, monitored, and addressed appropriately.

authors

contact our team

contact our team

contact our team.