Risk-Based AML in the AI Era: Making Sense of FinCEN's Proposed Reform
The April 2026 proposal is not in force yet. What it actually asks of compliance officers, where AI helps, and what a defensible file has to leave behind.
Rodolfo Santos
Real Estate Compliance Attorney & Co-Founder, VeriKYC

A Proposal, Not a New Obligation
On April 7, 2026, the U.S. Financial Crimes Enforcement Network (FinCEN) announced a proposed rule to reform anti-money laundering and countering the financing of terrorism (AML/CFT) programs under the Bank Secrecy Act. It would affect covered financial institutions, including banks, money services businesses, broker-dealers, mutual funds, insurers and certain lenders.
The announcement introduces a proposal. It does not itself put these changes into effect. The text was published in the Federal Register on April 10, 2026, and it fully supersedes FinCEN's July 2024 AML program proposal.
For compliance officers, the proposed changes concern how AML programs are designed and implemented, how resources are allocated to higher-risk activity, and how program effectiveness is assessed, particularly through bank supervision. The direction is already operationally useful: the ability to explain why controls address an institution's risks, and to demonstrate that those controls work, becomes the centre of the discussion.
For a compliance officer managing onboarding queues, screening alerts, internal reviews and commercial pressure, that raises a familiar question: how can a limited team dedicate enough attention to the cases that require professional judgment?
AI can help, provided its role is clearly defined and its performance can be evaluated.
What FinCEN Is Actually Asking For
The proposal emphasizes risk-based, reasonably designed programs. It distinguishes deficiencies in program design from failures in implementation. It also seeks clearer expectations for independent testing and more consistent supervision.
That distinction matters. A program that was never designed around the institution's actual risk is a different finding from a program that was designed correctly and then executed poorly. FinCEN's accompanying discussion also encourages institutions to consider machine learning, generative AI, digital identity and other innovative approaches. It states that no particular technology is required.
Our reading is practical. Institutions should assess where AI can improve their AML work and produce evidence of that improvement. Technology is optional. Being able to show that the program is risk-based, and that it operates as written, is not.
For the five BSA program pillars this reform sits on top of, see building a BSA/AML program that holds up under U.S. examination. For what examiners actually request, see SEC AML exam readiness.
Giving Compliance Officers More Time to Investigate
A substantial part of customer due diligence is preparing information for a decision. Teams request documents, reconcile names and addresses, review ownership records, examine screening results and assemble the supporting file.
AI can assist with those tasks by extracting information, identifying inconsistencies and preparing summaries linked to the underlying evidence. That gives a reviewer a clearer starting point, especially when information arrives across multiple documents or languages.
Consider a corporate customer whose onboarding form identifies one beneficial owner, while the supporting records indicate an additional ownership layer. A useful system would flag the discrepancy, identify the relevant documents and indicate what information remains missing. The compliance officer can then assess the structure, request clarification and decide whether further diligence is appropriate.
The operational benefit is a better-prepared case, with unresolved questions visible before a decision is made. Mapping the ownership chain, rather than accepting the named entity, is the same control described in beneficial ownership verification.
Making Screening Results Easier to Assess
A potential screening match requires context. Similar names may relate to different people, and a reviewer may need to compare dates of birth, nationalities, locations, business connections and the underlying source.
AI can help organize those details and highlight information that supports or weakens a possible match. Missing information should remain visibly unresolved. A system should not turn an incomplete comparison into a confident clearance.
For compliance officers, the useful output is a traceable assessment: what triggered the alert, which information was compared, what remains uncertain, and who made the final decision.
That is the same standard a screening programme needs regardless of whether AI is involved. See AML screening and watchlist checks for the difference between a sanctions hit, a PEP match and adverse media, and OFAC screening for U.S. private funds for why ownership data, not the signature, is the actual control.
Turning Risk Assessment Into Daily Decisions
A risk-based approach needs to influence how work is handled. Customer characteristics, ownership complexity, geographic exposure and inconsistencies in supporting information can all inform which cases deserve closer attention.
AI can help organize those indicators and route files according to the institution's policies. The compliance team should be able to understand the reasons for an escalation, adjust thresholds and challenge a recommendation.
For example, a file with incomplete ownership information and conflicting source-of-funds explanations may warrant priority review. The value of automation lies in making those issues visible early and ensuring that the file reaches someone with the authority and experience to investigate it.
If the model cannot explain why a file was escalated, it does not support a risk-based programme. It supports a queue. Explainable AI in KYC is the longer treatment of that requirement.
Building Evidence the Compliance Officer Can Defend
When a decision is questioned internally or during an examination, the compliance officer needs to reconstruct what happened.
A well-designed AI workflow should preserve the documents reviewed, the screening information available at the time, the issues identified and the reviewer's decision. Material statements in generated summaries should link back to supporting evidence. Corrections and overrides should also be recorded.
This makes the audit trail useful throughout the customer relationship. Another reviewer should be able to understand why the customer was accepted, which concerns were resolved and which conditions require follow-up.
An AI-generated report is useful only to the extent that its contents are accurate, complete enough for the task and open to verification. For the exam-file version of the same problem, see how to build a defensible AML audit trail.
Measuring Whether AI Improves the Program
For a compliance officer evaluating a new tool, processing speed is one part of the assessment. A practical pilot should also examine:
- Accuracy. Does the system extract and compare material information correctly?
- Missed concerns. Does it fail to identify discrepancies or risk indicators that reviewers would expect it to catch?
- Review quality. Are summaries supported by the source material, and how often do reviewers correct them?
- Escalation. Do uncertain or complex cases reach the appropriate person?
- Capacity. Does the tool create more time for investigation and follow-up?
- Traceability. Can the team reconstruct the evidence and reasoning behind a decision?
Testing should include incomplete documents, ambiguous matches and complex ownership structures. Those cases reveal how the system behaves when the information is difficult to interpret.
The results give compliance leaders a concrete basis for deciding where automation is appropriate and where additional controls are needed.
Keeping Accountability Clear
The institution should define who approves customers, resolves material alerts, authorizes exceptions and changes risk thresholds. Compliance officers also need a practical way to pause or restrict automation when performance falls below expectations.
Data handling belongs in the same assessment. Before deploying a tool, teams should understand who can access customer information, how it is retained and whether it is used to train models.
Clear responsibilities and access to supporting evidence allow compliance professionals to exercise meaningful oversight as technology takes on more of the preparatory work.
At VeriKYC, we support this approach by bringing document collection, identity verification and LSEG World-Check screening into a single workflow with an exportable audit trail. The aim is to give compliance officers an organized evidence base for customer due diligence, helping them identify unresolved issues and apply their judgment within the institution's broader AML program.
For compliance leaders considering AI, the strongest starting point is a specific operational problem: a document review bottleneck, repeated reconciliation work or poorly organized screening evidence. Define the expected improvement, test it against real cases and give reviewers the ability to challenge the output.
Frequently Asked Questions
Is FinCEN's April 2026 AML/CFT program reform already in force?
No. FinCEN issued a notice of proposed rulemaking on April 7, 2026. The text was published in the Federal Register on April 10. Until a final rule is adopted and an effective date is set, existing BSA program rules continue to apply. The proposal is still the document that tells you where supervision is heading.
Does the proposal require institutions to use AI?
No. FinCEN encourages institutions to consider machine learning, generative AI, digital identity and other innovative approaches, and it states that no particular technology is required. The obligation is a risk-based, reasonably designed program whose effectiveness can be demonstrated, not a mandate to buy a model.
What is the difference between a design deficiency and an implementation failure?
A design deficiency means the written program was never reasonably matched to the institution's risks. An implementation failure means the program was designed correctly and then not followed in material respects. The proposal treats those as different findings, which is why being able to show both the design rationale and the operating evidence matters.
What should an AI tool leave behind for an examiner?
The documents reviewed, the screening information available at the time, the issues identified, the reviewer's decision, and a way to trace material statements in any generated summary back to source evidence. Overrides and corrections should be recorded. A summary that cannot be verified is not an audit trail.
Where should a small compliance team start with AI?
With one operational bottleneck: document review, name-and-address reconciliation, or poorly organized screening evidence. Define the improvement you expect, test it on incomplete files and complex ownership, and keep a way to pause the tool if quality drops. Do not start with a model that clears alerts the reviewer cannot reconstruct.
The Bottom Line
FinCEN's proposal recenters AML programs on risk and on proof that the program works. AI is useful in that world only where it prepares a better file, surfaces unresolved questions, and leaves a trail a reviewer can defend.
Start with a specific problem. Test it. Keep the human accountable for the decision.
Rodolfo Santos
Rodolfo Santos is a real estate compliance attorney with 10+ years of experience in cross-border transactions and the co-founder of VeriKYC, an AI-powered compliance platform for real estate professionals. He has closed over 150 property transactions worth more than €50 million.