FinCEN Is Changing the AML Playbook: What Internal Auditors Should Be Watching in 2026
- John Blackshire
- Aug 23
- 8 min read
The U.S. anti-money laundering environment is changing rapidly.
For Internal Auditors, compliance officers, fraud professionals, financial institutions, broker-dealers, insurance organizations and other regulated entities, the Financial Crimes Enforcement Network—FinCEN—is becoming increasingly important.
FinCEN's recent activity points to a clear direction:
AML compliance is moving away from simply proving that procedures exist and toward demonstrating that the AML/CFT program actually identifies and responds to significant illicit-finance risks.
Recent enforcement actions, regulatory proposals, information-sharing guidance and threat advisories provide Internal Audit with a useful roadmap for determining where AML programs are most likely to fail.
What Does FinCEN Actually Do?
Financial Crimes Enforcement Network, commonly known as FinCEN, is a bureau of the U.S. Department of the Treasury.
Among its major responsibilities is administering and enforcing the Bank Secrecy Act (BSA) and its implementing regulations.
FinCEN can pursue enforcement for violations involving reporting, recordkeeping and other BSA requirements, including failures involving Suspicious Activity Reports (SARs), Currency Transaction Reports (CTRs), certain recordkeeping requirements and registration obligations applicable to money services businesses.
For auditors, that means AML should be viewed as a system of internal controls, not simply a regulatory filing function.
A Major Development: FinCEN Wants to Reform AML/CFT Programs
On April 7, 2026, FinCEN proposed significant changes to the framework governing financial institutions' AML/CFT programs.
FinCEN describes the proposal as intended to promote risk-based, reasonably designed programs while improving consistency in how banks are evaluated for effectiveness. Treasury also characterized the initiative as an effort to focus compliance resources more directly on stopping illicit finance rather than measuring success primarily through paperwork volume.
That distinction should get Internal Audit's attention.
The future question may increasingly become less:
“Did the institution complete all the required compliance activities?”
and more:
“Does the institution have a reasonably designed AML/CFT system that effectively addresses its actual risks?”
Those are very different audit questions.
The $125 Million UBS Action Should Get Auditors' Attention
One of the clearest recent signals came on August 3, 2026.
FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc. for willful BSA violations. FinCEN described UBSFS as a repeat offender and said this was the largest BSA penalty it had imposed against a broker-dealer to date.
That enforcement action sends an important message beyond the securities industry:
Remediation has to work.
When a regulator has already identified weaknesses, management cannot simply produce a corrective-action plan, close the issue and move on.
Internal Audit should independently determine:
Was the root cause identified?
Was corrective action actually implemented?
Did the corrective action solve the problem?
Was the remediation tested?
Has the same deficiency reappeared elsewhere?
Repeat findings can transform a compliance problem into a much more serious governance problem.
Broker-Dealers Are Clearly in FinCEN's Sights
The UBS action wasn't isolated.
On March 6, 2026, FinCEN assessed an $80 million penalty against Canaccord Genuity LLC for willful BSA violations. At the time, FinCEN described it as the largest BSA penalty ever imposed against a broker-dealer; the later UBS action surpassed it.
The Canaccord case is particularly useful for auditors because FinCEN identified weaknesses involving:
AML program requirements
Risk-based customer due diligence
Internal controls
Suspicious-activity monitoring
SAR reporting
FinCEN said Canaccord failed to file at least 160 SARs associated with dozens of over-the-counter securities and thousands of underlying suspicious transactions.
For an Internal Auditor, that suggests a straightforward test:
Follow the suspicious activity from initial transaction through detection, investigation, escalation and SAR decision.
Don't merely determine that the organization has transaction-monitoring software.
Determine whether the system works.
The TD Bank Case Remains a Warning About What Catastrophic AML Failure Looks Like
The $1.3 billion FinCEN penalty against TD Bank in October 2024 remains one of the most important AML case studies for auditors.
FinCEN said TD Bank's AML program was not appropriately designed or adequately resourced for its risks. The agency identified transaction-monitoring deficiencies, SAR backlogs, high-risk activity, employee involvement in suspicious transactions and other major control weaknesses. FinCEN's settlement included a four-year independent monitorship.
The case illustrates an important principle:
An AML program can fail even though the organization has an AML department, policies, employees and technology.
Existence is not effectiveness.
That distinction should be familiar to every Internal Auditor.
FinCEN Is Also Looking Beyond Traditional Banks
Another important development is the breadth of FinCEN's enforcement activity.
In December 2025, FinCEN assessed a $3.5 million penalty against Paxful, a peer-to-peer convertible virtual currency platform. FinCEN said the companies facilitated more than $500 million in suspicious activity involving illicit actors and high-risk jurisdictions.
FinCEN also launched a data-driven operation targeting more than 100 money services businesses operating along the Southwest border. The operation generated notices of investigation, examination referrals and more than 50 compliance outreach letters.
Earlier in 2025, FinCEN assessed a $37 million penalty against Brink's Global Services USA, its first enforcement action against an armored car company.
The lesson is straightforward: AML risk is not just a commercial-bank problem.
Information Sharing Is Becoming More Important
In June 2026, FinCEN issued updated guidance concerning Section 314(b) of the USA PATRIOT Act.
The guidance clarified how participating financial institutions can share information with one another concerning suspected fraud.
This matters because criminals do not respect organizational boundaries.
A fraud scheme may involve:
Bank A
→ Money Services Business
→ Bank B
→ Cryptocurrency Platform
→ Shell Company
→ Foreign Account
One institution may see only one piece of the transaction chain.
Information sharing can provide additional context.
Internal Audit should therefore understand whether its organization's AML and fraud functions are appropriately using available information-sharing mechanisms.
FinCEN Is Increasingly Connecting Fraud and AML
This may be one of the most important developments for Internal Audit.
Organizations traditionally create separate organizational boxes:
Fraud
AML
Cybersecurity
Sanctions
Compliance
Internal Audit
Criminals do not care about those organizational boundaries.
Fraud generates proceeds.
Those proceeds have to go somewhere.
Money laundering helps disguise their origin.
Cybercrime can produce the proceeds.
Shell companies can obscure ownership.
Money mules can move the funds.
Cryptocurrency can provide another transfer mechanism.
FinCEN's June 2026 Section 314(b) guidance explicitly addressed information sharing concerning suspected fraud.
That reinforces a useful audit question:
Does our organization connect fraud intelligence with AML monitoring, or are the two functions operating in separate silos?
Chinese Money Laundering Networks Illustrate the Complexity
FinCEN has also highlighted the growing threat posed by Chinese money laundering networks.
In August 2025, FinCEN issued both an advisory and a Financial Trend Analysis addressing these networks and their use by Mexico-based drug cartels.
This is a good example of why AML monitoring cannot remain static.
The risk environment changes.
Criminal organizations change methodologies.
New payment technologies appear.
Geographic risks change.
Customer behavior changes.
A transaction-monitoring system designed around the organization's risk profile from five years ago may not adequately address today's threats.
Geographic Risk Still Matters
FinCEN continues to communicate changes arising from the Financial Action Task Force's identification of jurisdictions with strategic AML/CFT and counter-proliferation-financing deficiencies.
For example, FinCEN's March 2026 notice reminded U.S. financial institutions to consider FATF's positions when evaluating their risk-based policies, procedures and practices.
This creates another audit question:
How quickly does the organization's AML risk assessment respond to changing geographic risk?
A policy that says the risk assessment will be updated “periodically” may not be sufficient if significant risk information changes between formal assessments.
FinCEN Is Expanding Its Whistleblower Infrastructure
Another development deserves Internal Audit's attention.
In February 2026, FinCEN launched a dedicated mechanism for confidential whistleblower tips involving fraud, money laundering and sanctions violations.
FinCEN says individuals providing qualifying information may be eligible for awards when their information contributes to successful enforcement actions.
That raises the stakes for corporate governance.
If an employee believes management is ignoring a serious BSA issue, the organization should assume that person may have a channel for reporting the matter externally.
The correct response isn't to fear whistleblowers.
It is to create an internal environment in which legitimate concerns are:
Reported
→ Investigated
→ Escalated
→ Corrected
→ Monitored
Internal Audit should independently evaluate whether that process works.
What Should Internal Auditors Be Testing?
The emerging FinCEN enforcement environment suggests several areas deserve particular attention:
AML Risk Assessment — Does it reflect the organization's actual customers, products, geography, delivery channels and emerging threats?
Customer Due Diligence — Are higher-risk customers identified and appropriately investigated?
Transaction Monitoring — Does the technology actually identify the activity it was designed to detect?
SAR Processes — Are alerts investigated and SAR decisions made and filed on a timely basis?
Backlogs — Are large alert queues masking serious control failures?
Data Quality — Is the information feeding transaction-monitoring systems complete and accurate?
High-Risk Customers — Does enhanced due diligence continue after onboarding?
Employee Misconduct — Could insiders facilitate suspicious transactions?
Information Sharing — Are fraud and AML intelligence appropriately connected?
Remediation — Are previously identified deficiencies actually corrected?
Governance — Does the board receive enough information to understand the real condition of the AML program?
Follow One Alert From Beginning to End
One of the best ways for Internal Audit to understand an AML system is deceptively simple.
Select a transaction-monitoring alert and follow it.
Transaction
→ Monitoring Rule
→ Alert
→ Analyst Review
→ Investigation
→ Escalation
→ SAR Decision
→ SAR Filing, if required
→ Continuing Customer Monitoring
Then inspect the evidence at every step.
This often tells the auditor considerably more than reading the AML policy.
Don't Forget Data Lineage
Modern AML programs depend heavily on technology.
That creates an IT audit problem hiding inside the AML program.
Suppose a bank has excellent transaction-monitoring rules.
But 15% of transactions from one payment platform never reach the monitoring system.
The rules can work perfectly and the AML program can still fail.
Auditors therefore need to understand:
Source System
→ Interface
→ AML Platform
→ Monitoring Rules
→ Alerts
→ Case Management
→ SAR Reporting
Ask:
How do we know the data are complete?
That question belongs in virtually every technology-dependent AML audit.
Internal Audit Should Look Beyond Compliance
The emerging regulatory philosophy makes a distinction Internal Auditors should embrace:
Compliance activity is not necessarily compliance effectiveness.
An institution may have:
A BSA Officer.
An AML policy.
Training.
Customer due diligence.
Transaction-monitoring software.
SAR procedures.
Independent testing.
All of these are necessary.
But the ultimate question remains:
Does the system identify, escalate and report suspicious activity consistent with the institution's risk?
That is an effectiveness question.
A Better AML Audit Model
Internal Audit can structure its work around a simple methodology:
Understand the Business
→ Identify Inherent AML Risks
→ Understand the AML Risk Assessment
→ Identify Key Controls
→ Evaluate Design Effectiveness
→ Test Operating Effectiveness
→ Evaluate Technology and Data
→ Examine Exceptions and Backlogs
→ Evaluate SAR Decision-Making
→ Review Regulatory Findings
→ Test Remediation
→ Determine Residual Risk
→ Report to Governance
That turns an AML audit from a regulatory checklist into an evaluation of the AML control system.
What the FinCEN Activity Means for Audit Committees
Audit Committees of regulated financial organizations should not receive an annual presentation saying simply:
“Our AML program is compliant.”
They should ask harder questions:
What are our five largest AML risks?
Which risks are increasing?
How many monitoring alerts are outstanding?
How old is the oldest significant alert?
What percentage of alerts ultimately produce SARs?
What regulatory findings remain open?
Have repeat deficiencies occurred?
What does Internal Audit believe about the program?
Are AML technology and staffing adequate for the risk?
How do we know our transaction-monitoring data are complete?
The TD Bank, Canaccord and UBS cases demonstrate why these are governance questions—not merely compliance-department questions.
The Bottom Line: FinCEN Is Telling Auditors Where to Look
Recent FinCEN activity provides Internal Auditors with a remarkably useful collection of case studies.
The recurring themes include:
Weak risk assessment
Inadequate customer due diligence
Transaction-monitoring failures
SAR failures
High-risk customers
Technology and data weaknesses
Inadequate resources
Poor remediation
Repeat violations
Governance failures
The most important lesson may be this:
A technically compliant AML program can still be an ineffective AML program.
Internal Audit's responsibility is to look beyond the existence of policies, procedures and systems and determine whether the control environment actually works.
FinCEN's April 2026 proposal reinforces the direction of travel: more emphasis on risk-based, reasonably designed and effective AML/CFT programs.
That should change how Internal Auditors approach AML.
Don't merely ask:
“Do we comply?”
Ask:
“Where could money laundering get through our controls—and how would we know?”
That is the question that can turn an AML compliance audit into meaningful assurance.
Comments