Infographic

A breakdown of the April 2026 AML/CFT Program NPRM and the June 2026 Section 314(b) fraud-sharing guidance — and how compliance teams should respond.

In 2026, the Financial Crimes Enforcement Network (FinCEN) advanced two related but distinct regulatory changes that together redefine what an effective Bank Secrecy Act (BSA) compliance program looks like.

On April 7, 2026, FinCEN and the federal banking regulators published a Notice of Proposed Rulemaking (NPRM) that would replace the decades-old, process-driven approach to AML/CFT programs with an outcomes-based, risk-tiered framework. Two months later, on June 12, 2026, FinCEN issued an updated Section 314(b) fact sheet that explicitly extends the information-sharing safe harbor to fraud — including real-time sharing between financial institutions.

Taken together, these two actions form what we call FinCEN's dual mandate: modernize how AML/CFT programs are built and measured, while simultaneously expanding the tools institutions can use to detect and stop illicit activity collaboratively. This guide explains both rulemakings in plain terms, what they require, and what compliance, risk, and fraud teams should be doing now to prepare.

Key takeaways

  • FinCEN's April 2026 NPRM would require banks and other covered institutions to run AML/CFT programs that demonstrate effectiveness, not just documented process — a fundamental shift in how examiners will evaluate compliance.
  • The rule codifies four core program pillars: risk-based internal controls, independent testing, a U.S.-based AML/CFT officer, and ongoing employee training.
  • A final rule is expected in 2027, with a 12-month implementation window once it's issued. The comment period on the proposal closed June 9, 2026.
  • FinCEN's updated Section 314(b) fact sheet (June 12, 2026) makes explicit that fraud — including romance scams, pig-butchering schemes, and mule account activity — is covered by the information-sharing safe harbor, and permits real-time sharing.
  • SARs and the existence of a SAR remain strictly confidential under the update — that protection is unchanged.
  • Institutions that invest in explainable AI, dynamic risk assessment, and network-level intelligence sharing are positioned to meet both rules' expectations rather than simply react to them.
Download the infographic today

What Is FinCEN's AML/CFT Program NPRM?

On April 7, 2026, FinCEN — together with the FDIC, OCC, and NCUA — published a joint Notice of Proposed Rulemaking that would overhaul the AML/CFT program requirements financial institutions have operated under for decades. Notably, the Federal Reserve is not among the issuing agencies. The proposal supersedes a July 2024 draft and, according to FinCEN's official fact sheet, covers 11 categories of financial institutions.

From check-the-box to outcomes

The plain-English shift is this: FinCEN is moving away from a process-driven, "check-the-box" compliance model and toward an outcomes-based, risk-tiered framework. Under the proposed rule, a program's success is no longer measured by the volume of paperwork it generates — it's measured by whether the program actually detects and disrupts illicit finance. That reframing runs through every part of the NPRM, from how risk assessments are built to how examiners will approach enforcement.

The four pillars of an "effective" AML/CFT program

The NPRM codifies four core pillars that every covered institution's program must address:

  1. Risk-based internal controls. Policies must be reasonably designed to identify, assess, and document money laundering and terrorist financing (ML/TF) risks. Risk assessments are now embedded directly into internal controls rather than treated as a standalone requirement, and they must incorporate FinCEN's national AML/CFT priorities — updating promptly whenever an institution's risk profile materially changes.
  2. Independent testing. Testing must evaluate whether a program is actually effective, not simply whether it exists on paper. Frequency and scope should be tailored to the institution's real risk profile rather than applied uniformly.
  3. A U.S.-based AML/CFT officer. The designated AML/CFT officer must be physically located in the United States and accessible to FinCEN and federal regulators. Support staff may still be based offshore, but SAR sharing with foreign personnel remains tightly restricted.
  4. Ongoing employee training. Training requirements are standardized across institution types, but the frequency and content should be tailored by role and risk exposure — not applied identically across an entire workforce.

Two structural changes reshaping enforcement

Beyond the four pillars, the NPRM introduces structural changes that will reshape how compliance programs are supervised and resourced:

  • A two-tier enforcement framework. Regulators will separate the establishment of a program from its day-to-day implementation. Enforcement actions will be reserved for significant or systemic failures rather than technical or de minimis gaps — meaning that once a program is properly established, institutions gain meaningful protection from minor supervisory actions.
  • Effectiveness over volume. Programs will be evaluated on whether they produce outcomes that are useful to law enforcement, not on Suspicious Activity Report (SAR) filing counts. Institutions may — and are expected to — direct fewer resources toward lower-risk customer segments. Risk-proportionate resource allocation becomes a regulatory expectation rather than simply a best practice.

AI and RegTech: from optional to strategically protective

One of the more notable signals in the NPRM is that it explicitly lists the use of innovative tools, including AI, as a factor FinCEN may weigh before taking enforcement action. That elevates technology adoption from a discretionary investment to a strategically protective one — a meaningful signal for any institution weighing RegTech investment against competing budget priorities.

Key dates and the implementation timeline

  • October 2025 - FinCEN FAQs reduce SAR filing burden
  • February 2026 - CDD Rule exceptive relief granted
  • April 7, 2026 - AML/CFT Program NPRM published; comment period closed June 9, 2026
  • June 12, 2026 - Updated Section 314(b) fact sheet issued, clarifying fraud sharing
  • ~2027 (expected) - Final rule issued, triggering a 12-month implementation window

What financial institutions should do now

  • Gap-assess your current risk assessment methodology and documentation before the final rule is issued.
  • Build evidential frameworks that demonstrate program effectiveness, not just existence.
  • Review governance: the NPRM requires board or senior-management approval of the written program.
  • Re-evaluate resource allocation, and be prepared to justify reduced spend on low-risk segments in writing.
  • Confirm your AML/CFT officer is U.S.-based and accessible to regulators.
  • Formalize how your internal controls align with FinCEN's national AML/CFT priorities.
  • Treat AI and technology adoption as a strategic compliance asset rather than a back-office cost — see how SymphonyAI's AML software supports this shift.

What Does FinCEN's Updated Section 314(b) Guidance Change?

Section 314(b) of the USA PATRIOT Act has long allowed financial institutions to voluntarily share information about suspected money laundering or terrorist financing with each other, under a legal safe harbor. On June 12, 2026, FinCEN issued an updated Section 314(b) fact sheet that replaces the December 2020 version in its entirety and removes years of institutional hesitation about one specific question: does 314(b) cover fraud?

The core clarification is that Section 314(b) was always meant to be a fraud tool — FinCEN has now made that explicit. The update is part of the Treasury's participation in the White House Task Force to Eliminate Fraud.

Fraud is now explicitly in scope

Fraud offenses are Specified Unlawful Activities (SUAs) under 18 U.S.C. § 1956. That means mail fraud, wire fraud, bank fraud, securities fraud, computer fraud, romance scams, pig-butchering schemes, and mule account activity are all explicitly covered. Institutions need only suspect fraud — they don't need to identify specific laundered proceeds — to invoke the safe harbor.

Real-time information sharing is permitted

There is no restriction on the method or timing of sharing under the updated guidance. Institutions may share information verbally, in writing, or via electronic platforms as activity is occurring. Sharing is also no longer limited to situations involving a shared customer or transaction with the receiving institution — context-free intelligence sharing is now permissible.

What can and can't be shared

Financial institutions can share transaction records, entity relationship data, monitoring alerts, adverse media, device fingerprints, IP addresses, video surveillance footage, and fraud indicators such as new payees followed by large outbound transfers.

One protection remains unchanged: SARs and the existence of a SAR remain strictly confidential. Nothing in the update alters that requirement.

Who can participate, including non-bank associations

A non-financial institution may form and operate a 314(b) association, which opens the door for RegTech vendors to serve as network orchestrators for member institutions. Foreign sharing carries limits — it doesn't benefit from the 314(b) safe harbor unless the foreign entity qualifies as a FinCEN-regulated financial institution. Joint SARs also remain available to institutions that identify suspicious activity through 314(b) collaboration.

Operational requirements for compliance teams

  • Register (and renew annually) through FinCEN's Financial Institution Portal — an expired registration means no safe harbor.
  • Verify that the receiving institution is a registered 314(b) participant before sharing anything.
  • Maintain procedures to safeguard shared data, and use it only for AML/CFT purposes, account decisions, or BSA compliance.
  • Confirm eligibility: banks, money services businesses, broker-dealers, mutual funds, insurance companies, loan and finance companies, and 314(b) associations all qualify.

Why These Two Rules Are Connected

It's tempting to treat the AML/CFT Program NPRM and the Section 314(b) update as separate news items, but they share a common thread: both reward institutions that invest in intelligence, automation, and network-level insight over institutions that simply generate paperwork.

The NPRM tells examiners to evaluate programs on outcomes and effectiveness rather than SAR volume. The 314(b) update gives institutions a broader, faster, real-time channel to generate exactly the kind of high-quality, actionable outcomes the NPRM will reward — particularly for fraud typologies like romance scams and mule networks that rarely respect institutional boundaries. Read together, FinCEN's 2026 dual mandate is a clear signal: the institutions best positioned for the next phase of BSA/AML supervision will be the ones that can demonstrate detection effectiveness and collaborate across the network to stop fraud before it settles.

How SymphonyAI Helps Financial Institutions Respond

Both rulemakings reward institutions that invest in intelligence, automation, and network-level insight. SymphonyAI's Symphony Risk Intelligence platform is purpose-built for exactly that operating model.

Responding to the AML Program NPRM:

  • Explainable, risk-proportionate detection. SRI's AML models surface the highest-risk alerts first, with audit-ready rationale, helping institutions demonstrate resource concentration on high-risk segments as the new framework requires.
  • Adversarial testing and model validation. Built-in model performance analytics and independent testing support help satisfy the NPRM's strengthened independent testing pillar with documented evidence of detection effectiveness, not just process completion.
  • A dynamic risk assessment engine. Automated risk scoring across products, customers, geographies, and channels updates in near-real time as profiles change, aligning directly with the NPRM's requirement to refresh risk assessments when material changes occur.

Responding to the Section 314(b) update:

  • Network-level entity resolution and link analysis. SRI's graph analytics connect behavioral signals across accounts, institutions, and typologies, transforming incoming 314(b) intelligence from peer institutions into actionable detection context without requiring a pre-existing customer relationship.
  • Real-time alert enrichment and case management. Shared 314(b) signals, such as IP addresses, device data, and transaction patterns, can be ingested directly into SRI's case management and investigation tools for immediate analyst review.
  • Fraud typology detection and mule network identification. Pre-built fraud scenario libraries cover pig-butchering schemes, romance scam fund flows, first-party fraud rings, and mule account patterns — all now expressly in scope under the updated guidance.
  • Joint SAR workflow support. Coordinated investigation workflows let multiple institutions collaborating via 314(b) build a consolidated evidence picture and file joint SARs, maximizing the law enforcement utility FinCEN now treats as a direct measure of program effectiveness.

Talk to SymphonyAI about your AML/CFT program

Related resources

Learn more about Symphony Risk Intelligence

Find out more about Symphony Risk Intelligence and Always-on Compliance, and how it can improve your approach to transaction monitoring, KYC/CDD, fraud, and screening.

FinCen's 2026 AML/CFT Program Reform and Section 314(b) Update - FAQs
When does FinCEN's AML/CFT Program NPRM take effect?

The proposal was published April 7, 2026, with a public comment period that closed June 9, 2026. A final rule is expected in 2027, which would trigger a 12-month implementation window once issued.

What is Section 314(b) of the USA PATRIOT Act?

It's a provision that gives financial institutions a legal safe harbor to voluntarily share information about suspected unlawful activity with one another, in order to identify and report money laundering and terrorist financing.

Does FinCEN's updated Section 314(b) guidance cover fraud?

Yes. FinCEN's June 12, 2026 fact sheet update makes explicit that fraud, including romance scams, pig-butchering schemes, and mule account activity, is a Specified Unlawful Activity covered by the 314(b) safe harbor.

Can financial institutions share information in real time under Section 314(b)?

Yes. The updated guidance removes restrictions on the method or timing of sharing, permitting institutions to share information as suspicious activity is occurring.

Are Suspicious Activity Reports (SARs) shareable under Section 314(b)?

No. SARs and the existence of a SAR remain strictly confidential. That protection was not changed by the 2026 update.

about the author
Elizabeth Callan
AML | FinCrime | Sanctions Compliance & Risk Management SME

Elizabeth has spent more than 20 years tackling money laundering (ML) and financial crime. At SymphonyAI she drives the strategy and innovation that delivers transformational compliance solutions. Prior to SymphonyAI she worked within the U.S. intelligence and law enforcement communities. As a Senior Intelligence Analyst with the U.S. Department of the Treasury, she drove U.S. policy and enforcement actions and supported U.S. officials and policymakers, including at OFAC and FinCEN, on ML threats and sanctions initiatives. She also served as Treasury’s first Intelligence Liaison and Senior Advisor to DEA’s Special Operations Division, spearheading large-scale ML investigations and intelligence collection initiatives, training law enforcement agents and analysts, and promoting collaboration between Treasury and U.S. and foreign law enforcement. In the private sector, Elizabeth also worked within financial institutions and consulting managing investigations teams, developing risk management strategies for complex products and services, and designing institutional AML programs and controls. Elizabeth also teaches AML and sanctions courses at the university level.

Learn more about the author >