June 8, 2026 | Public Comment

Anti-Money Laundering and Countering the Financing of Terrorism Programs

June 8, 2026 | Public Comment

Anti-Money Laundering and Countering the Financing of Terrorism Programs

Download

Download
Full Public Comment

Full Written Public Comment

To the United States Department of the Treasury

I. Introduction and Interest of Commenter

The Foundation for Defense of Democracies (FDD) and its Center on Economic and Financial Power (CEFP) submit these comments on the Financial Crimes Enforcement Network’s Notice of Proposed Rulemaking on Anti-Money Laundering and Countering the Financing of Terrorism Programs. FDD is a nonpartisan policy institute focused on national security and foreign policy. CEFP’s research addresses economic statecraft, sanctions, illicit finance, and the intersection of financial regulation with U.S. national security interests.

We submit these comments not as critics of reform but as an organization that understands what is at stake if reform is poorly designed. The existing AML/CFT framework is imperfect. A shift toward effectiveness-based, risk-calibrated compliance is warranted. The question is whether this proposed rule is structured to strengthen national security outcomes or, inadvertently, to create the conditions under which America’s most consequential adversaries — Russia, Iran, China, and transnational criminal organizations, including drug cartels — are better able to exploit the U.S. financial system.

We have three principal concerns, developed below. We also offer recommendations for each.

II. FinCEN Centralization: A Legitimate and Potentially Valuable Reform

CEFP commends FinCEN for undertaking this rulemaking. The current AML/CFT framework imposes substantial compliance costs on financial institutions while generating, in too many cases, more paperwork than actionable financial intelligence. The shift toward an effectiveness-based standard — focusing institutions on genuine money laundering and terrorism financing risk rather than procedural box-checking — is the right direction.

We also commend FinCEN’s attention to financial inclusion. An overly burdensome compliance regime contributes to de-risking practices that deny banking services to low-income individuals, immigrant communities, and small businesses operating in higher-risk sectors. That outcome serves neither the public interest nor the purposes of the Bank Secrecy Act. A calibrated framework that directs scrutiny toward genuine threats and reduces friction for lower-risk customers is consistent with both financial integrity and access goals.

These objectives — compliance efficiency, financial inclusion, and national security — are not in tension in the abstract. They become so, however, when reform is designed without adequate attention to the adversaries who exploit regulatory gaps systematically.[1] Russia, Iran, China, and transnational drug cartels do not encounter AML/CFT programs randomly. They study them, test them, and probe for weaknesses with resources and patience that ordinary financial criminals do not possess. A framework that reduces compliance burden for the many must not, in doing so, reduce enforcement capacity against the few who represent the most serious threats.

The proposed rule’s most structurally significant change — centralizing AML/CFT supervisory authority in FinCEN through the notice-and-consultation framework — is not inherently objectionable. We note that several of the commenters on this proposed rule have framed this provision as a threat to prudential regulator independence. We do not share that framing wholesale.

The OCC, FDIC, and NCUA are banking regulators whose primary statutory mandates center on safety and soundness. AML/CFT is one function among many. FinCEN’s sole institutional mandate is financial crimes and national security — making it the natural locus for setting and enforcing AML/CFT standards consistently across the financial community. An arrangement that ensures FinCEN has visibility into and input on significant supervisory actions across all categories of supervised institutions is, in principle, a mechanism for greater coherence and a higher floor of AML/CFT expertise in enforcement.

To be successful in this new role, however, FinCEN needs to be properly resourced. FinCEN was already “outmatched” compared to the scale of terrorist financing and money laundering before it reportedly lost 11 percent of its workforce last year.[2] The Treasury Department should increase hiring in both OFAC and FinCEN. This hiring should likely precede the rule change, as FinCEN’s capacity issues are precisely the type of vulnerability that our most dangerous adversaries are seeking to exploit. Potential problems detailed in Sections III and IV of this comment compound that vulnerability.

III. Two Provisions That Undermine the National Security Case for Centralization

A. The ‘Significant or Systemic Failure’ Enforcement Threshold

In response to Questions 5 and 21, which ask whether clarification is needed to define a ‘significant or systemic failure’ to implement an effective AML/CFT program, we submit that clarification is not only warranted but essential to prevent the threshold from creating an enforcement gap in precisely the cases the AML/CFT framework exists to address.

The proposed rule conditions meaningful supervisory action on a showing of “significant or systemic failure” to maintain an established AML/CFT program. The standard is underdefined in the regulatory text, potentially resulting in needless litigation to clarify the standard. We submit that as currently drafted, it is calibrated to catch catastrophic institutional breakdowns — not the targeted, surgical evasion that national security cases present.

Sanctioned actors — Russian oligarchs and state-linked entities, Iranian front companies, North Korean procurement networks — do not need to collapse a bank’s AML/CFT program. They need to exploit one gap at one institution. The evasion strategies documented in OFAC enforcement actions and congressional investigations are characterized by precision and deliberateness.[3] A compliance program that is sound in design and generally adequate in operation can still fail in ways that matter most. For instance, a Chinese network allegedly set up fake companies between May 2022 and April 2024, funneling $92 million through branches of Chase, Wells Fargo, and Bank of America across North Carolina.[4] The laundering succeeded through branch-level structuring that slipped past routine controls at otherwise compliant institutions.

A similar concern applies to transnational criminal organizations, including the cartels this administration has designated as foreign terrorist organizations.[5] Fentanyl proceeds laundered through U.S. financial institutions are among the highest-priority illicit finance threats the U.S. government has identified.[6] Cartel money laundering does not require systemic program failure. It only requires a bank that fails in small ways.

Recommendation: FinCEN should clarify in the final rule that where an institution’s AML/CFT program fails to detect, flag, or report transactions involving OFAC-designated persons or entities, FTO-designated organizations, or activity consistent with typologies identified in the AML/CFT Priorities, examiners are authorized to assess whether that failure reflects a deficiency in program design. Specifically, examiners should be able to determine whether the institution’s risk assessment processes and internal controls were reasonably designed to identify the relevant typology or counterparty type — and a program that is structurally blind to a documented national security threat does not meet the ‘reasonably designed’ standard that the proposed rule itself requires. A finding to that effect should constitute sufficient basis for supervisory action, regardless of whether broader program deficiencies exist. This clarification preserves the rule’s deregulatory intent for routine compliance matters while ensuring that technical compliance with program requirements cannot shield institutions whose risk assessment processes fail to account for the specific threats the AML/CFT Priorities identify.

Proposed regulatory text: “A failure by a financial institution’s AML/CFT program to detect, flag, or report transactions involving OFAC-designated persons or entities, FTO-designated organizations, or activity consistent with typologies identified in the AML/CFT National Priorities or other FinCEN guidance shall constitute sufficient basis for a supervisory finding, regardless of whether the failure reflects a broader or systemic program deficiency.”

B. The Constraint on Examiner Judgment

Even where the threshold described above is met, a second and independent barrier to effective enforcement remains: The proposed rule’s constraint on examiner judgment limits the ability of examiners to identify and act on the precise patterns of activity most likely to cross that threshold in the first place.

In response to Question 2, which asks whether financial institutions or regulators are best positioned to identify risks and allocate resources, we submit that the preamble’s constraint on examiner judgment — while appropriate for ordinary commercial compliance — is structurally inadequate in the national security context and should be explicitly carved out for activity connected to FinCEN’s AML/CFT Priorities.

FinCEN’s accompanying Fact Sheet describes the rule as instructing that “examiners and auditors do not substitute their subjective judgment in place of financial institutions’ risk-based and reasonably designed AML/CFT programs.” The proposed rule states, “Treasury and FinCEN do not believe that an examiner should substitute his or her own subjective judgment in place of the financial institution.” Instead, examiners are instructed to “assess whether: (1) a financial institution’s resource allocation decisions are informed by, and consistent with, reasonably designed risk assessment processes; and (2) with respect to implementation, specifically, whether the financial institution knows or should know of resource-related issues involving its internal policies, procedures, and controls and other mandatory elements that may result in the financial institution failing to implement its AML/CFT program in all material respects and failing to address such issues.” We understand the intent: to prevent overreach by examiners who second-guess reasonable institutional decisions.

However, this rule fails in a national security context. The history of major sanctions evasion cases and AML failures involving adversarial actors is not a story of rogue examiners imposing idiosyncratic standards on compliant banks. It is a story of institutional blind spots — banks that designed programs adequate for ordinary commercial risk that were nonetheless exploited by actors who stayed deliberately ahead of documented typologies and risk profiles.[7]

Individual financial institutions do not always see systemic level threats — they see only what comes through their door. FinCEN, however, can have a much broader view of risk, across financial institutions. Examiner judgment is precisely the mechanism by which novel evasion methods are identified before they become documented typologies and national security threats. An examiner who observes a pattern that the institution has not yet encoded into its procedures and who is told that her judgment cannot override the institution’s own risk classification is structurally constrained from doing her job in the cases that matter most.

Recommendation: The final rule should establish that the examiner judgment constraint does not apply where a review involves activity with a connection to FinCEN’s AML/CFT Priorities — including drug trafficking organization proceeds, Russian and Chinese illicit finance, and terrorist financing. In those circumstances, examiners should retain explicit authority to: (1) require enhanced due diligence beyond what the institution’s own program specifies; (2) flag transactions as suspicious regardless of whether the institution’s risk classification would otherwise require a SAR filing; and (3) initiate supervisory action without first demonstrating that the institution’s program is deficient as a whole. This is not a license for routine second-guessing of reasonable institutional judgments. It is a targeted preservation of examiner authority in the cases where institutional self-assessment is least reliable and adversarial exploitation is most likely.

To make this authority meaningful, FinCEN should also require that examiners have access to SAR feedback reports for the examined institution — including law enforcement utilization data and indicators of defensive filing — prior to initiating any examination. Absent that evidence base, examiners assessing program effectiveness in Priority-nexus cases are limited to procedural review, which is precisely the check-the-box dynamic this rule aims to move beyond.

Proposed regulatory text: “The constraint on examiner judgment shall not apply where an examination involves activity with a nexus to one or more of FinCEN’s AML/CFT National Priorities or other official guidance. In such circumstances, examiners retain independent authority to require enhanced due diligence, designate activity as suspicious for SAR purposes, and initiate supervisory action without a predicate finding of program-wide deficiency.”

IV. A Compounding Vulnerability: The Beneficial Ownership Gap

In response to Questions 10 and 13, which ask whether risk assessment processes should account for additional criteria and what guidance on incorporating the AML/CFT Priorities would be useful, we submit that the effectiveness standard cannot be met with respect to the threats the AML/CFT Priorities identify so long as beneficial ownership data for U.S.-incorporated counterparties remains unavailable under FinCEN’s March 2025 interim final rule.[8]

The proposed rule’s effectiveness standard depends on financial institutions conducting meaningful risk assessments of their customers, counterparties, and transaction flows. Risk assessment requires knowing who you are doing business with. FinCEN’s March 2025 interim final rule exempting U.S. domestic companies from beneficial ownership reporting requirements under the Corporate Transparency Act has created a structural gap in the data inputs those assessments depend upon.

The Corporate Transparency Act should be fully enforced. An effectiveness standard without beneficial owner transparency for U.S.-incorporated counterparties is not an effectiveness standard for the threats that matter most. Russian-linked capital flows, Chinese state-adjacent investment vehicles, and cartel-owned businesses are disproportionately structured through domestic legal entities specifically to exploit this opacity.[9]

Recommendation: FinCEN should fully enforce the Corporate Transparency Act. In lieu of that, it should address in the final rule how financial institutions are expected to meet the effectiveness standard with respect to domestic counterparties for whom beneficial ownership data is unavailable under current regulations. Guidance on enhanced due diligence obligations in the absence of UBO data — particularly for customers in high-risk sectors or jurisdictions identified in the AML/CFT Priorities — would provide institutions with a workable framework and preserve the national security value of the effectiveness standard.

V. Conclusion

CEFP supports FinCEN’s role as the central expert authority on AML/CFT supervision. A well-designed centralization framework has the potential to raise standards and reduce the inconsistencies that sophisticated adversaries exploit. A more capable and involved FinCEN is good for U.S. national security.

The issues identified in Sections III and IV risk inverting that outcome — not in ordinary commercial banking cases, where the deregulatory logic applies, but in precisely the cases where the U.S. financial system is most vulnerable and where enforcement matters most. The fixes we recommend are targeted and would not disrupt the rule’s broader architecture. They would ensure that the final rule delivers on its promise to focus on genuine threats rather than paperwork.

We appreciate the opportunity to comment and welcome further engagement.

[1] U.S. Department of the Treasury, “2024 National Money Laundering Risk Assessment,” February 2024. (https://home.treasury.gov/system/files/136/2024-National-Money-Laundering-Risk-Assessment.pdf); U.S. Department of the Treasury, “2018 National Proliferation Financing Risk Assessment,” December 20, 2018. (https://home.treasury.gov/system/files/136/2018npfra_12_18.pdf)

[2] Spencer Woodman, “As US pledges renewed fight against dirty money, head of financial crime agency says funding shortfalls have caused delays,” International Consortium of Investigative Journalists, April 29, 2022. (https://www.icij.org/investigations/pandora-papers/as-us-pledges-renewed-fight-against-dirty-money-head-of-financial-crime-agency-says-funding-shortfalls-have-caused-delays/); Paul O’Donoghue, “Number of FinCEN staff cut by 11% over last year,” AMLIntelligence, January 15, 2026. (https://www.amlintelligence.com/2026/01/news-number-of-fincen-staff-cut-by-11-over-last-year/)

[3] U.S. Attorney’s Office, Southern District of New York, Press Release, “Turkish Bank Charged In Manhattan Federal Court For Its Participation In A Multibillion-Dollar Iranian Sanctions Evasion Scheme,” October 15, 2019. (https://www.justice.gov/usao-sdny/pr/turkish-bank-charged-manhattan-federal-court-its-participation-multibillion-dollar)

[4] Kalé Carey, “Cartels, cash and cover-ups: How drug money moves through US banks,” Straight Arrow News, May 15, 2025. (https://san.com/cc/cartels-cash-and-cover-ups-how-drug-money-moves-through-us-banks/)

[5] U.S. Executive Order 14157, “Designating Cartels and Other Organizations as Foreign Terrorist Organizations and Specially Designated Global Terrorists,” January 20, 2025. (https://www.whitehouse.gov/presidential-actions/2025/01/designating-cartels-and-other-organizations-as-foreign-terrorist-organizations-and-specially-designated-global-terrorists/)

[6] U.S. Department of the Treasury, Financial Crimes Enforcement Network, “Anti-Money Laundering and Countering the Financing of Terrorism National Priorities,” June 30, 2021. (https://www.fincen.gov/system/files/shared/AML_CFT%20Priorities%20(June%2030,%202021).pdf)

[7] U.S. Department of the Treasury, Office of Foreign Assets Control, Press Release, “Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups,” September 13, 2019. (https://home.treasury.gov/news/press-releases/sm774)

[8] Beneficial Ownership Information Reporting Requirement Revision and Deadline Extension, U.S. Department of the Treasury, Financial Crimes Enforcement Network, 90 Federal Register 13688, March 26, 2025. (https://www.federalregister.gov/documents/2025/03/26/2025-05199/beneficial-ownership-information-reporting-requirement-revision-and-deadline-extension)

[9] U.S. Department of the Treasury, Press Release, “Fact Sheet: Treasury Actions to Enhance Financial Transparency and Combat Illicit Finance,” February 14, 2024. (https://home.treasury.gov/news/press-releases/jy2097)