.png)
In 2026, the Financial Crimes Enforcement Network (FinCEN) advanced two related but distinct regulatory changes that together redefine what an effective Bank Secrecy Act (BSA) compliance program looks like.
On April 7, 2026, FinCEN and the federal banking regulators published a Notice of Proposed Rulemaking (NPRM) that would replace the decades-old, process-driven approach to AML/CFT programs with an outcomes-based, risk-tiered framework. Two months later, on June 12, 2026, FinCEN issued an updated Section 314(b) fact sheet that explicitly extends the information-sharing safe harbor to fraud — including real-time sharing between financial institutions.
Taken together, these two actions form what we call FinCEN's dual mandate: modernize how AML/CFT programs are built and measured, while simultaneously expanding the tools institutions can use to detect and stop illicit activity collaboratively. This guide explains both rulemakings in plain terms, what they require, and what compliance, risk, and fraud teams should be doing now to prepare.

On April 7, 2026, FinCEN — together with the FDIC, OCC, and NCUA — published a joint Notice of Proposed Rulemaking that would overhaul the AML/CFT program requirements financial institutions have operated under for decades. Notably, the Federal Reserve is not among the issuing agencies. The proposal supersedes a July 2024 draft and, according to FinCEN's official fact sheet, covers 11 categories of financial institutions.
The plain-English shift is this: FinCEN is moving away from a process-driven, "check-the-box" compliance model and toward an outcomes-based, risk-tiered framework. Under the proposed rule, a program's success is no longer measured by the volume of paperwork it generates — it's measured by whether the program actually detects and disrupts illicit finance. That reframing runs through every part of the NPRM, from how risk assessments are built to how examiners will approach enforcement.
The NPRM codifies four core pillars that every covered institution's program must address:
Beyond the four pillars, the NPRM introduces structural changes that will reshape how compliance programs are supervised and resourced:
One of the more notable signals in the NPRM is that it explicitly lists the use of innovative tools, including AI, as a factor FinCEN may weigh before taking enforcement action. That elevates technology adoption from a discretionary investment to a strategically protective one — a meaningful signal for any institution weighing RegTech investment against competing budget priorities.
Section 314(b) of the USA PATRIOT Act has long allowed financial institutions to voluntarily share information about suspected money laundering or terrorist financing with each other, under a legal safe harbor. On June 12, 2026, FinCEN issued an updated Section 314(b) fact sheet that replaces the December 2020 version in its entirety and removes years of institutional hesitation about one specific question: does 314(b) cover fraud?
The core clarification is that Section 314(b) was always meant to be a fraud tool — FinCEN has now made that explicit. The update is part of the Treasury's participation in the White House Task Force to Eliminate Fraud.
Fraud offenses are Specified Unlawful Activities (SUAs) under 18 U.S.C. § 1956. That means mail fraud, wire fraud, bank fraud, securities fraud, computer fraud, romance scams, pig-butchering schemes, and mule account activity are all explicitly covered. Institutions need only suspect fraud — they don't need to identify specific laundered proceeds — to invoke the safe harbor.
There is no restriction on the method or timing of sharing under the updated guidance. Institutions may share information verbally, in writing, or via electronic platforms as activity is occurring. Sharing is also no longer limited to situations involving a shared customer or transaction with the receiving institution — context-free intelligence sharing is now permissible.
Financial institutions can share transaction records, entity relationship data, monitoring alerts, adverse media, device fingerprints, IP addresses, video surveillance footage, and fraud indicators such as new payees followed by large outbound transfers.
One protection remains unchanged: SARs and the existence of a SAR remain strictly confidential. Nothing in the update alters that requirement.
A non-financial institution may form and operate a 314(b) association, which opens the door for RegTech vendors to serve as network orchestrators for member institutions. Foreign sharing carries limits — it doesn't benefit from the 314(b) safe harbor unless the foreign entity qualifies as a FinCEN-regulated financial institution. Joint SARs also remain available to institutions that identify suspicious activity through 314(b) collaboration.
It's tempting to treat the AML/CFT Program NPRM and the Section 314(b) update as separate news items, but they share a common thread: both reward institutions that invest in intelligence, automation, and network-level insight over institutions that simply generate paperwork.
The NPRM tells examiners to evaluate programs on outcomes and effectiveness rather than SAR volume. The 314(b) update gives institutions a broader, faster, real-time channel to generate exactly the kind of high-quality, actionable outcomes the NPRM will reward — particularly for fraud typologies like romance scams and mule networks that rarely respect institutional boundaries. Read together, FinCEN's 2026 dual mandate is a clear signal: the institutions best positioned for the next phase of BSA/AML supervision will be the ones that can demonstrate detection effectiveness and collaborate across the network to stop fraud before it settles.
Both rulemakings reward institutions that invest in intelligence, automation, and network-level insight. SymphonyAI's Symphony Risk Intelligence platform is purpose-built for exactly that operating model.
Responding to the AML Program NPRM:
Responding to the Section 314(b) update:
Talk to SymphonyAI about your AML/CFT program
Find out more about Symphony Risk Intelligence and Always-on Compliance, and how it can improve your approach to transaction monitoring, KYC/CDD, fraud, and screening.
The proposal was published April 7, 2026, with a public comment period that closed June 9, 2026. A final rule is expected in 2027, which would trigger a 12-month implementation window once issued.
It's a provision that gives financial institutions a legal safe harbor to voluntarily share information about suspected unlawful activity with one another, in order to identify and report money laundering and terrorist financing.
Yes. FinCEN's June 12, 2026 fact sheet update makes explicit that fraud, including romance scams, pig-butchering schemes, and mule account activity, is a Specified Unlawful Activity covered by the 314(b) safe harbor.
Yes. The updated guidance removes restrictions on the method or timing of sharing, permitting institutions to share information as suspicious activity is occurring.
No. SARs and the existence of a SAR remain strictly confidential. That protection was not changed by the 2026 update.