The Financial Crimes Enforcement Network ‘s (FinCEN) National AML/CFT Priorities are eight government wide priorities that identify the most serious threats to the U.S. financial system. The Priorities, issued in June 2021, under Section 6101 of the Anti Money Laundering Act of 2020, identify the following, in no particular order: Corruption; cybercrime, including cybersecurity and virtual currency considerations; Foreign and domestic terrorist financing; Fraud; Transnational criminal organization activity; Drug trafficking organization activity; Human trafficking and human smuggling; and proliferation financing. When they were first released, there was no immediate regulatory requirement. That changed in 2026.
In April 2026, FinCEN issued a Notice of Proposed Rulemaking (NPRM) that would dramatically overhaul AML/CFT program requirements under the Bank Secrecy Act and, critically for the subject of this article, would require financial institutions to formally incorporate the Priorities into their risk assessments and compliance programs. The NPRM replaces and withdraws an earlier 2024 proposal and, when finalized, will codify the integration of the Priorities into risk assessment methodology as a documented, examinable obligation, rather than an aspirational reference. (Full guide what the Priorities are)
For compliance leaders, this is not some far off regulatory possibility. Comments were due by June 9, 2026. Following publication of the final rule, financial institutions will have a proposed 12 month implementation period to show that their programs and their risk assessments, substantively and defensibly address the eight Priorities. Institutions already using the Priorities as an input to their risk assessment methodology will be those that will pass the first examination cycle under the new framework. The goalposts have moved for those institutions that viewed the 2021 release as informational.
The following sections explore the Priorities and the changes they bring as of 2026 in more detail:
- Why the 2026 NPRM is Important Today
- 8 Priorities Explained
- How to Integrate Priorities Into Your Risk Assessment
- What Regulators Expect from Priority Integration
- Common Mistakes and How to Avoid Them
- How Sanction Scanner Can Help
Why the 2026 NPRM is Important Today
The April 2026 NPRM is the most radical restructuring of the U.S. AML/CFT programme requirements in a generation, and its most consequential change for the topic of this article is that it elevates the National Priorities from a suggested reference to a required input for compliance program design.
The core mechanic is simple. Under the proposed rule, a financial institution's AML/CFT compliance program must be reasonably designed and risk based, and the risk assessment process supporting the program must consider FinCEN's National Priorities along with the institution's particular business activities, products, services, distribution channels, customers, intermediaries, geographic locations, and the reports it files under FinCEN regulations. Institutions will have to assess the relevance of each of the Priorities to their business and be able to articulate why certain Priorities are, or are not, material to their risk profile. The FinCEN has expressly warned that a shallow approach to the Priorities will not meet supervisory expectations.
The structural features of the proposal affect the way this obligation will be implemented in practice.
Two-pronged approach. The proposed rule distinguishes between the “establishment” of an AML/CFT program (its design) and “implementation” or “maintenance” (its day to day operation). This distinction is made to avoid confusion by examiners between design flaws and implementation flaws, and to reduce scrutiny for nonmaterial or de minimis operational lapses where the underlying program design is sound. From a risk assessment perspective this means that the design of the assessment methodology including how the Priorities are integrated, is a first order exam question assessed separately from whether each individual customer file reflects the methodology perfectly.
Explicit, risk based resource allocation. The proposed rule advances Treasury Secretary Scott Bessent's stated goal to 'make changes to the AML/CFT framework to truly focus on national security priorities and higher-risk areas and explicitly permit financial institutions to de-prioritize lower risks. The NPRM operationalizes that directive by requiring institutions to pay more attention and resources to higher risk customers and activities, and less to lower risk customers and activities, with the Priorities as one of the anchors for what “higher risk” means. Bessent has also spoken publicly about the burden of a system that measures success by “the volume of paperwork rather than the ability to stop illicit finance threats”. This framing is present throughout the NPRM.
The 2024 NPRM is formally withdrawn. The July 3, 2024 proposal for requiring Priority integration under an earlier framework has been formally replaced. Any steps taken by institutions in preparing for the 2024 rule will need to be re evaluated in light of the 2026 version, which keeps the core requirement to incorporate Priorities but modifies key surrounding provisions, including the two pronged framework, supervisory notice and consultation between FinCEN and federal banking regulators, and clarifications around independent testing.
The Fed sat this one out. On the same day FinCEN issued its NPRM, the FDIC, OCC and NCUA issued a joint NPRM in parallel to align their own AML/CFT program requirements with FinCEN’s framework. The Federal Reserve Board, which had participated in the corresponding 2024 rulemaking, did not participate in the 2026 joint NPRM. The lack of meaningful signal from Fed supervised institutions about supervisory alignment is something institutions should be on the lookout for.
Timeline. Public comment was due June 9, 2026. The FinCEN has recommended a 12 month period for implementation from the date of the final rule. The final rule does not prescribe a timing for which existing AML/CFT program requirements would remain in full force and effect until a final rule is issued and any prescribed effective date has passed. In practice, this means that institutions should begin to adjust risk assessment methodology now, with a view to substantive Priority integration before the final rule closes the transition window.

8 Priorities Explained
Each Priority corresponds to a particular threat category that FinCEN, in consultation with other Treasury components, federal and state regulators, law enforcement, and national security agencies, determined to be significant in 2021 and confirmed to be ongoing through subsequent National Risk Assessments and enforcement activity.
Corruption. Corruption, which President Biden’s June 2021 National Security Study Memorandum identified as a core U.S. national security interest, undermines democratic institutions and routes large amounts of illicit proceeds through the U.S. financial system. The FinCEN priorities highlight the link between corruption and kleptocracy, sanctions evasion, and the cross border movement of wealth. This Priority requires institutions to focus on politically exposed persons (PEPs), high net worth individuals with opaque source of wealth documentation, private banking relationships, real estate transactions, and shell company structures used to obscure ultimate beneficial ownership.
Cyber crime. FinCEN describes cybercrime as a “major illicit finance threat,” particularly ransomware attacks, cyber enabled financial crime, and the use of virtual assets and convertible virtual currencies to launder illicit proceeds. This Priority for institutions calls for the integration of cyber signals into transaction monitoring device intelligence, IP geolocation, behavioural anomalies and increased scrutiny of transactions involving convertible virtual currency, especially rapid conversions and transfers to high risk exchanges or mixing services. FinCEN encourages the sharing of information related to suspected cyber crime activity among institutions under the Section 314(b) safe harbor.
Financing of Foreign and Domestic Terrorism. The Priority serves to remind covered institutions of their existing obligations to identify and file SARs on potential terrorist financing transactions. FinCEN highlights the threats of international terrorism (with the National Terrorist Financing Risk Assessment for 2024 focusing on Hamas after the October 2023 attacks in Israel) and the increasing threat of domestic terrorism, including racially and ethnically motivated violent extremism. Recent FinCEN advisories on Hamas financing and crowdfunding based terrorism financing highlight specific red flags for donations to organizations that solicit funds but do not provide charitable services.
Fraud. FinCEN says fraud is responsible for the largest share of illicit proceeds in the United States. The Priority specifically highlights business email compromise (BEC), email account compromise, healthcare fraud, internet enabled fraud, and importantly, foreign intelligence entities using illicit financial practices to fund influence campaigns and espionage. For institutions this Priority is directly related to fraud detection and transaction monitoring configurations that capture the classic BEC signature (change of payee, urgency markers, out of pattern wires), synthetic identity fraud, and elder financial exploitation.
Transnational Criminal Organization (TCO) Activities. The TCOs are prioritized as threats because of their "crime terror nexus" and their participation in numerous illicit activities, including cybercrime, drug trafficking, human trafficking, weapons trafficking, and intellectual property theft. FinCEN specifically cites Chinese money laundering organizations offering laundering services to Mexican drug cartels, and the increasing role of TCOs in trade based money laundering. For institutions TCO monitoring examines complex counterparty webs, high risk geographies and trade finance patterns that are inconsistent with the underlying commercial rationale.
Drug Trafficking Organization (DTO) Activity. Coinciding with the TCO activity, but singled out separately because of the particular weight of the fentanyl crisis in U.S. national security concerns. The Priority calls out cash based money laundering, funnel accounts and the use of shell companies to move drug proceeds. The 2024 TD Bank enforcement action, discussed in more detail below, was based on precisely this Priority: TD Bank’s failures enabled drug trafficking networks to launder hundreds of millions of dollars in illicit proceeds through the U.S. financial system.
Human Trafficking & Human Smuggling. This Priority builds upon existing FinCEN advisories on human trafficking typologies. Red flags include third party control of financial transactions for trafficking victims, front companies with unusual cash intensity (hospitality, restaurants, spas and nail salons in particular geographies), and payment patterns consistent with human smuggling routes. Since 2014, FinCEN has issued a number of advisories on these typologies, most recently updated to reflect evolving smuggling trends at the southern border.
Financing of proliferation. The Priority focuses on weapons of mass destruction and other arms proliferation activities involving Iran, North Korea and Syria, with correspondent banking identified as “a principal vulnerability and driver of proliferation financing risk within the United States due to its central role in processing U.S. dollar transactions.” Correspondent banking exposure, specifically, requires that institutions build proliferation financing screening into their correspondent due diligence and transaction monitoring, with particular focus on jurisdictions and typologies discussed in FinCEN and OFAC advisories on North Korean sanctions evasion.
How to Integrate Priorities Into Your Risk Assessment
This is where compliance leads spend the bulk of their prep time, and where the 2026 NPRM will impose the toughest requirements. The Priorities are inputs to a risk assessment, not the risk assessment per se. How they are integrated will determine if the assessment can withstand scrutiny.
A defensible approach has five steps.
Step 1. Assign each Priority to your business
Ask a specific set of questions for each of the eight Priorities. Is this Priority for us? What about our products, services, customer segments or geographic exposures makes this Priority material? Which are largely insignificant? For institutions with a domestic retail customer base and little international exposure, proliferation financing may be truly low relevance; for a global correspondent bank it is central. Write it down. The mapping itself is one of the artifacts examiners will look for.
Step 2: Evaluate inherent and residual risk
For each applicable Priority, determine the institution’s inherent risk (the amount of this Priority in your customer base, product set, and geographic spread, before controls are applied) and residual risk (the amount that remains after your controls are in place). This is a difference that matters. A high inherent risk area with strong controls could become a low residual risk. A moderate inherent risk area with weak controls might stay high. Regulators want to see the numbers and the analysis that connects them.
Step 3: Align Document Control
For each Priority that has material residual risk, identify the specific controls in your AML/CFT program that address the Priority. Cybercrime maps to fraud detection use cases, device intelligence and virtual asset counterparty screening. Terrorist financing is connected to sanctions and PEP screening, adverse media, and specific transaction monitoring scenarios keyed to known typologies. Corruption means increased need for more due diligence on PEPs, source of wealth documentation, and beneficial ownership analysis. Mapping should also be one to many where appropriate a single control often addresses multiple Priorities.
Step 4: Spot the gaps
Where does the mapping show poor control coverage? Are there material residual risks within Priorities that are not fully addressed by a particular control? The most valuable output from the exercise is this gap analysis, which drives the remediation roadmap. That's also what examiners will focus on. A risk assessment that identifies gaps and articulates a plan to close them is materially stronger than one that either misses the gaps entirely or acknowledges the gaps without an action plan.
Step 5: Review and refresh on your own cadence
The 2026 NPRM proposes that the institution review and update its risk assessments when there are material changes to the institution’s illicit finance risks. Most mature programs review annually and refresh on trigger events in practice such as new products, new geographies, ownership changes, significant regulator advisories or SAR patterns indicating emerging typologies. FinCEN also performs priority reviews when it updates the Priorities, which the AML Act requires at least every four years. Institutions should be watching for a statutory update to the 2021 Priorities, which is long overdue.
This five-step process does not result in a page count target. This is a working document that connects all elements of your AML/CFT program back to those specific threats that FinCEN has identified as most critical, with residual risk and control coverage clearly articulated for each. Institutions that produce this document as a living artifact (updated as controls change and threats evolve) pass the “substantive integration” test the NPRM is signaling. Those that create it as a one off exercise for regulatory display don’t.

What Regulators Expect from Priority Integration
FinCEN releases, interagency statements, and enforcement actions articulate regulator expectations for Priority integration. There are five expectations that keep coming back.
Real integration, not just lip service. FinCEN has emphasized that a cursory approach to the Priorities will not satisfy supervisory expectations. A boilerplate paragraph in a risk assessment that references the Priorities without applying them to the institution’s specific business will not withstand examination scrutiny. Each Priority is expected to be assessed against the actual risk profile of the institution with the results documented.
Analysis documentation. The rationale for decisions (such as why a Priority was assigned or not assigned, how inherent risk was determined, why the controls selected are sufficient, where residual gaps are) must be documented contemporaneously. Reconstruction of analysis during the week prior to an examination is transparent to examiners and results in materially worse outcomes than documentation as the work is done. The audit trail is the mapping from Priority to residual risk to control.
Engagement of board and senior management. The 2026 NPRM would require that AML/CFT programs be approved by the board of directors or equivalent governing body or appropriate senior management. In practice this means that the risk assessment and Priority integration methodology should be presented to and approved by the relevant governance body, and the approval should be documented. Boards that consider AML/CFT reporting as a rubber stamp item produce program level findings; boards that engage substantively produce program level defensibility.
Consistency with SARs filings, and enforcement patterns. Regulators will match the institution’s Priority based risk assessment against the actual SAR filings and any advisories or enforcement actions that pertain to the institution’s business. If the institution is filing multiple TF related SARs a year, but the risk assessment indicates that terrorist financing is a low risk, then either the assessment is outdated or the institution’s exposure is not well understood. The consistency between these artifacts is a subject of inquiry in and of itself.
Implications of programmatic failures for enforcement. The reference case is the October 2024 TD Bank action, which resulted in a total penalty of about $3.09 billion, with $1.3 billion specifically assessed by FinCEN. FinCEN found TD Bank had “long term, pervasive and systemic deficiencies” in its AML program, didn’t substantively update its transaction monitoring from 2014 to 2022 and left 92% of its transaction volume (about $18.3 trillion between January 2018 and April 2024) unmonitored. The bank’s accounts processed three money laundering networks that funneled $670 million in narcotics proceeds directly tied to two of FinCEN’s Priorities (drug trafficking and transnational criminal organization activity). TD Bank pleaded guilty to conspiracy to commit money laundering, the first time in U.S. history a bank has done so. Each finding maps back to failures that Priority driven risk assessment would have uncovered: Failure to update monitoring scenarios, insufficient resource allocation, specific typologies missed. This case is not a fringe example. It’s what regulators cite when they address the significance of the Priorities.
Common Mistakes and How to Avoid Them
Most institutions preparing for Priority integration under the 2026 framework make a small set of avoidable mistakes. Knowing about them is the cheapest preparation you can have.
All Priorities are equally treated as material. The Priorities are a national threat map. Your risk assessment maps them to the specific footprint of your institution. A regional retail bank with no international correspondent business will not face the same proliferation financing risk as a global custody bank, and the assessment should say so and why. The language “in no particular order” used in the FinCEN release should not be read as “of equal weight to your institution.”
Language copied from FinCEN releases. It is tempting to take boilerplate language from the FinCEN Priorities document and simply transplant it into the risk assessment. This is precisely what FinCEN has warned against. Regulators understand boilerplate and it conveys the opposite of the substantive integration that the NPRM is trying to create.
Failure to adapt to changes in the threat environment. The operational meaning of certain Priorities has changed due to the 2023 Hamas attacks, the ongoing Russia-Ukraine conflict, the fentanyl crisis, and the changing environment of virtual asset laundering. Institutions that had an integration in 2022, and never went back to it, are describing, in 2026, a threat environment that doesn’t exist anymore. Trigger-based updates are just as important as calendar-based updates.
Underinvesting in the mapping step. The above five step methodology can work only if the first step of mapping each Priority to a specific business element is done rigorously. If you have a weak Step 1, then you have a weak risk assessment no matter how strong Steps 2 to 5 are.
Viewing the risk assessment as a document rather than as an operational tool. The best risk assessments drive real decisions: Which customer segments are subject to enhanced due diligence, which transaction monitoring scenarios to tune tighter, where the compliance team allocates review capacity. Even if the document looks polished, descriptions of risk that do not affect the operations generate examination findings.
How Sanction Scanner Can Help
Sanction Scanner’s platform is built to provide Priority integration as a configurable capability, not a documentation effort. Each Priority is directly linked to its underlying platform module.
PEP Screening and Adverse Media Screening are run during onboarding and on an ongoing basis against comprehensive global sources for corruption. Sanction Scanner screens customers and transactions real time against OFAC, UN, and EU lists embedded within the ruleset for terrorist financing, including specific advisories (about Hamas, Iran, North Korea). The platform has coverage for the whole typology map for fraud, including BEC, synthetic identity, elder financial exploitation, account takeover with configurable rules. Transaction monitoring rules for TCO and DTO activity include funnel accounts, unusual counterparty webs and high risk geography. The rule library can be configured to have FinCEN advisory based typologies for human trafficking and smuggling. Correspondent banking due diligence and sanctions screening target the primary means of proliferation financing.
The unifying capability sits in the FUSION platform: One enriched customer risk profile that reflects exposure across all eight Priorities, with the underlying evidence (screening results, alert history, adverse media hits, transaction patterns) retained as an audit trail that supports the risk assessment methodology directly. When examiners ask how the institution has integrated each Priority into its program, the platform produces the mapping as configuration, not as a separate document.
The architectural point is the same one that runs through every guide in this series: The 2026 NPRM is not asking institutions to add a new compliance layer. It wants them to demonstrate their existing layers are aligned with the threats FinCEN has said are most important. The institutions that have one integrated risk surface, one that reflects each Priority through configurable, evidenced controls, will be the ones that pass the first examination cycle under the new framework without a scramble.
Sources
[1] Financial Crimes Enforcement Network. Anti-Money Laundering and Countering the Financing of Terrorism National Priorities. 2021.
[2] Financial Crimes Enforcement Network. Fact Sheet: Proposed Rule to Fundamentally Reform Financial Institution AML/CFT Programs. 2026.
[3] Federal Register. Anti-Money Laundering and Countering the Financing of Terrorism Programs. 2026.
[4] U.S. Department of Justice. TD Bank Pleads Guilty to Bank Secrecy Act and Money Laundering Conspiracy Violations in $1.8B Resolution. 2024.
[5] Financial Crimes Enforcement Network. FinCEN Assesses Record $1.3 Billion Penalty against TD Bank. 2024.
FAQ's Blog Post
FinCEN Priorities anchor a risk-based AML program by defining the national threats institutions must weigh against their own footprint. A risk-based program directs more resources to higher-risk customers and activities and less to lower-risk ones, using the Priorities as one reference point for what higher-risk means in practice.
2026 NPRM fully supersedes and withdraws the July 2024 proposed rule. It keeps the core requirement to incorporate the Priorities but revises key provisions, including the two-pronged design-versus-implementation framework, the notice-and-consultation process between FinCEN and banking regulators, and clarifications on independent testing. Prior 2024 preparation should be re-evaluated.
AML program failures can trigger civil and criminal penalties reaching billions of dollars. The 2024 TD Bank case brought roughly $3.09 billion in total penalties, including a record $1.3 billion assessed by FinCEN, after the bank left about 92% of its transaction volume unmonitored and pleaded guilty to money laundering conspiracy.
Control mapping links each material AML/CFT Priority to the specific controls that address it, showing where coverage is strong and where gaps remain. For example, corruption maps to [PEP and adverse media screening], while terrorist financing maps to [sanctions screening] and typology-based [transaction monitoring]. One control often covers several Priorities.
Effectiveness-based AML programs shift the compliance standard from process and paperwork toward measurable outcomes: Detecting and reporting the illicit activity that matters most. The 2026 proposed rule advances this model by asking institutions to direct more attention and resources to higher-risk customers and activities, and less to lower-risk ones.
AML Act of 2020 is the landmark U.S. law that modernized the Bank Secrecy Act framework. Section 6101 directs the Treasury to establish and publish government-wide AML/CFT Priorities and incorporate them into program requirements, forming the legal basis for the 2026 proposed rule and today's Priority integration expectations.
BSA/AML risk assessments should be updated on a regular cadence, typically annually, and promptly after material changes such as new products, new geographies, ownership shifts, or significant advisories. The 2026 proposed rule expects updates whenever an institution's illicit finance risks change significantly, not only on a fixed calendar.
Inherent risk and residual risk measure exposure at two points: Inherent risk is the level of a threat in your customers, products, and geographies before controls apply, while residual risk is what remains after controls. Strong controls can turn high inherent risk into low residual risk.
FinCEN AML/CFT Priorities are not yet a standalone legal requirement, but the April 2026 proposed rule would change that. Once finalized, financial institutions must review and, where relevant, incorporate the Priorities into their risk assessments, with a proposed 12-month window to comply after the final rule.
FinCEN's National AML/CFT Priorities are eight government-wide threats FinCEN identified as most serious to the U.S. financial system. Issued in June 2021 under the AML Act of 2020, they cover corruption, cybercrime, terrorist financing, fraud, transnational crime, drug trafficking, human trafficking and smuggling, and proliferation financing.

