Five U.S. regulatory agencies—the Board of Governors of the Federal Reserve System (“FRB”), the Federal Deposit Insurance Corporation (“FDIC”), the National Credit Union Administration (“NCUA”), the Office of the Comptroller of the Currency (“OCC”), and the U.S. Department of Treasury’s Financial Crimes Enforcement Network (“FinCEN”)—released on October 3, 2018 an Interagency Statement on Sharing Bank Secrecy Act Resources (the “Statement”). This guidance addresses instances in which certain banks and credit unions can enter into “collaborative arrangements” to share resources to manage their Bank Secrecy Act (“BSA”) and anti-money laundering (“AML”) obligations more efficiently and more effectively.

The Statement contemplates banks sharing resources such as internal controls, independent testing, and AML/BSA training (it does not apply to collaborative arrangements formed for information sharing among financial institutions under Section 314(b) of the U.S. Patriot Act). Such resource sharing contemplates reducing costs and increasing efficiencies in the ways banks manage their BSA and AML obligations. The Statement clearly is addressed primarily to community banks, for which the costs of AML/BSA compliance can be significant, and which presumably engage in “less complex operations [and have] lower risk profiles for money laundering or terrorist financing.” The Statement potentially represents another step in an ongoing AML reform process, which increasingly acknowledges the costs of AML compliance to industry. Continue Reading Federal Banking Agencies Encourage BSA Resource Sharing

FinCEN recently announced the launching of the “FinCEN Exchange” to enhance information sharing with financial institutions.  We previously have blogged about the potential benefits of a public-private partnership between law enforcement and financial institutions for both parties as a way to enhance law enforcement’s efforts to disrupt and intercept money laundering and terrorist financing as well as a financial institution’s ability to identify and accurately report suspicious activity. Information sharing has become a key issue in global conversations about reform of Anti-Money Laundering (“AML”) regimes.

The FinCEN Exchange represents a direct response to financial industry requests for more guidance and information from government to help identify and report suspicious activity. Although it is a positive step towards improving the system for reporting suspicious activity, the FinCEN Exchange presumably will create expectations by the government that problems identified by the Exchange will be captured by suspicious activity reporting going forward.  Hopefully, the converse also will occur, and expectations regarding the reporting of activity identified as low priority will be lowered, so that industry truly may focus its current resources and not be compelled to expend even more resources on AML compliance. Continue Reading Information Sharing Exchange Launched by FinCEN to Improve Suspicious Activity Reporting

Second in a Three-Part Series of Blog Posts

As we recently blogged, the Royal United Services Institute (“RUSI”) for Defence and Security Studies — a U.K. think tank – has released a study:  The Role of Financial Information-Sharing Partnerships in the Disruption of Crime (the “Study”).  The Study focuses on international efforts — including efforts by the United States — regarding the reporting of suspicious transactions revealing criminal activity such as money laundering and terrorist financing.  The Study critiques current approaches to Anti-Money Laundering (“AML”) reporting, and suggests improvements, primarily in the form of enhanced information sharing among financial institutions and governments.

In our first blog post in this series, we described some of the criticisms set forth by the Study regarding the general effectiveness of suspicious activity reporting, which the Study described as often presenting little or no “operational value to active law enforcement investigations.” In this second blog post pertaining to the Study, we will discuss the current landscape of AML information sharing in the United States — which is governed by Section 314 of the Patriot Act, and which is an important component of many financial institutions’ ability to fulfill successfully their AML obligations. In the third and final blog post pertaining to the Study, we will circle back to the Study and examine its findings and proposals for an enhanced process of information sharing by financial institutions and governments in order to better fight money laundering and terrorism. Continue Reading AML Information Sharing in the U.S. – Section 314 of the Patriot Act

U.S. House Passes Corporate Transparency Act; FATF Issues Guidance on Identifying Entities’ Beneficial Owners

First Post in a Two-Post Series on Beneficial Ownership

As we often blog, the issue of the beneficial ownership of entities and the potentially pernicious role of shell companies in perpetuating money laundering is the primary anti-money laundering (“AML”) concern across the globe for both enforcement officials and the financial industry.

Consistent with this concern, and within a single week, both the U.S. House of Representatives and the Financial Action Task Force (“FATF”), an international and intergovernmental AML watchdog group, recently took notable steps in the fight against the misuse of shell companies. Specifically, on October 23 the House passed H.R. 2513, a two-part Act which sets forth in its initial section the Corporate Transparency Act, or CTA. If passed into legislation, the CTA would require certain, defined U.S. companies to report identifying information regarding their beneficial owners to the Treasury Department – so that such information would be available to both the government and financial institutions carrying out their own AML duties. Meanwhile, FATF has issued a detailed document entitled “Best Practices on Beneficial Ownership for Legal Persons,” (“Best Practices Guidance”) which urges countries to use multiple methods to identify accurately and timely the beneficial owners of legal entities, and sets forth some high-level recommendations.

Today, we will discuss the CTA. Tomorrow, we will discuss FATF’s Best Practices Guidance, which approaches the problem of beneficial ownership from a different angle – the Guidance and its recommendations represent an evaluation of historical efforts by the member countries’ approaches to the collection and maintenance of beneficial ownership information in countries that already create repositiories of such information for law enforcement, as envisioned by the CTA. Continue Reading Shell Company Update: Congress and FATF Target Beneficial Ownership

Bill Would Create BSA Whistleblower Program

First Post in a Three-Post Series

Last week, the House Financial Services Committee released three proposed bills to codify many of the reform ideas that have arisen in an ongoing conversation among financial agencies, law enforcement, financial institutions, and commentators regarding the Bank Secretary Act (“BSA”) and Anti-Money-Laundering (“AML”) and Combating the Financing of Terrorism (“CFT”) laws. These reform topics include information sharing, resource sharing, and technological innovation — all of which have been repeat topics for this blog.

One proposed bill — entitled as the “To make reforms to the Federal Bank Secrecy Act and anti-money laundering laws, and for other purposes” — seeks to reform the BSA and AML laws (the “BSA/AML Reform Bill”) and is divided into three main sections: Strengthening the Treasury; Improving AML/CFT Oversight; and Modernizing the AML System. Through the three sections, common themes emerge, including an emphasis on: BSA/AML regulation as a matter of national security; the need for cooperation among both the public/private sectors as well as the international community; and the need to encourage innovation as the technological conduits for financial crimes continue to evolve.  The BSA/AML Reform Bill is extremely detailed, with many various provisions, and we merely will summarize its major points here.

In the coming weeks, we will blog on the other two proposed bills, The Corporate Transparency Act of 2019, which seeks to ensure that persons who form legal entities in the U.S. disclose the beneficial owners of those entities, and the Kleptocracy Asset Recovery Rewards Act, which seeks to create an asset recovery rewards program to help identify and recover stolen assets linked to foreign government corruption. Continue Reading The House Financial Services Committee Releases Proposed Legislation to Codify BSA/AML Reform Initiatives

Director Blanco Emphasizes BSA Resource Sharing, Technological Innovation, and Collaboration Between Public and Private Sectors

The Financial Crimes Enforcement Network (FinCEN) released prepared remarks delivered by FinCEN director, Kenneth A. Blanco, at the Securities Industry and Financial Markets Association (SIFMA) Anti-Money Laundering (AML) & Financial Crimes Conference on February 4, 2019. Director Blanco’s speech highlights various regulatory reform efforts, including the approval of collaborative sharing of Bank Secrecy Act (BSA) resources and an interagency initiative to promote innovation in the technologies and methodologies used to combat money laundering and terrorist financing. The Director also emphasized the importance of collaboration among the public and private sectors.  These remarks do not occur in a vacuum; rather, they represent just part of what has been an ongoing conversation in the BSA/AML realm. Potential resource sharingtechnological innovation and information sharing have been repeated topics in this blog. Continue Reading FinCEN Director’s Remarks Highlight AML Regulatory Reform Efforts

On April 8, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) and Office of Foreign Assets Control (OFAC) issued a joint Notice of Proposed Rulemaking (NPRM) to implement the Guiding and Establishing National Innovation for U.S. Stablecoins Act (GENIUS Act). The proposal would create a comprehensive anti‑money‑laundering/countering‑the‑financing‑of‑terrorism (AML/CFT) and sanctions compliance framework for “permitted payment stablecoin issuers” (PPSIs), treating them as financial institutions under the Bank Secrecy Act (BSA). Treasury frames the rule as an effort to support responsible innovation in payment stablecoins while mitigating illicit‑finance risks (see also Treasury’s press release and Fact Sheet).

For our coverage of Treasury’s related Notice of Proposed Rulemaking on state oversight of stablecoin issuers, see our post here.

Statutory Background and Policy Context

The GENIUS Act directs that PPSIs be treated as financial institutions for BSA purposes and comply with federal laws relating to sanctions, money‑laundering prevention, customer identification, and due diligence. It also requires PPSIs to maintain an effective sanctions compliance program.

Treasury’s March 2026 Congressional Report highlights the rapid growth of digital assets, the increasing use of stablecoins in payments, and the ways illicit actors exploit them for fraud, ransomware, sanctions evasion, and money laundering. These findings inform the risk‑based approach reflected in the NPRM.

Primary and Secondary Market Activity

A central concept in the NPRM is the distinction between primary and secondary market activity. Primary market activity refers to direct interactions between a PPSI and a user, such as issuing, redeeming, converting, repurchasing, burning, reissuing, or providing custodial services. Secondary market activity involves transactions between third parties that rely on the PPSI’s smart contract but do not involve the PPSI as a counterparty. This distinction matters because several obligations—including suspicious activity reporting—apply only to primary‑market transactions. This distinction will shape how PPSIs design monitoring, SAR processes, and technical controls, because only primary‑market activity triggers most BSA obligations.

AML/CFT Program Requirements

The NPRM would require PPSIs to establish and maintain a written AML/CFT program that mirrors the core elements required of other financial institutions, with tailoring for stablecoin‑specific risks. PPSIs must implement internal policies, procedures, and controls to identify, assess, and mitigate illicit‑finance risks. Risk assessments must evaluate the PPSI’s business activities, incorporate the national AML/CFT priorities, and be updated promptly when risks change.

PPSIs would also be required to conduct ongoing customer due diligence, including understanding the nature and purpose of customer relationships, developing customer risk profiles, and monitoring for suspicious activity. On a risk basis, PPSIs must maintain and update customer information, including beneficial ownership information for legal‑entity customers.

Independent testing is required to assess whether the PPSI has implemented an effective AML/CFT program. PPSIs must designate a U.S.‑based AML/CFT compliance officer responsible for day‑to‑day compliance. The program must also include ongoing employee training tailored to employee roles and responsibilities and must be approved by the PPSI’s board or equivalent governing body.

The NPRM outlines a supervisory framework under which FinCEN would generally not take enforcement action if a PPSI has established an AML/CFT program and does not exhibit significant or systemic failures. It also describes a notice and consultation process between FinCEN and primary federal payment‑stablecoin regulators for significant supervisory actions. For many issuers, this will require adopting governance, documentation, and testing practices that resemble those of traditional financial institutions—a significant shift for engineering‑driven companies.

Suspicious Activity and Currency Transaction Reporting

PPSIs would be required to file suspicious activity reports (SARs) for any suspicious primary‑market transaction. The NPRM explicitly states that secondary‑market transfers are not, by themselves, considered transactions “by, at, or through” a PPSI for SAR purposes. PPSIs must retain SARs and supporting documentation for five years.

Currency‑transaction reporting (CTR) requirements would apply to transactions in currency exceeding $10,000, though Treasury notes that stablecoin issuers rarely engage in physical‑currency transactions.

Recordkeeping, Travel Rule, and Information Sharing

The NPRM would require PPSIs to comply with the BSA’s Recordkeeping Rule and Travel Rule for transfers of $3,000 or more and would amend the definition of “transmittal order” to expressly include payment stablecoins. PPSIs would also be integrated into the BSA’s information‑sharing framework, including Section 314(a) requests and voluntary Section 314(b) sharing.

Enhanced Due Diligence and Special Measures

The NPRM would apply the BSA’s enhanced due‑diligence requirements for correspondent accounts for foreign financial institutions and private‑banking accounts for non‑U.S. persons. PPSIs would also be subject to special measures under Section 311 of the USA PATRIOT Act, Section 9714(a) of the Combating Russian Money Laundering Act, and 21 U.S.C. 2313a.

Sanctions Compliance Program Requirements

The NPRM reflects a significant change in Treasury’s expectations for PPSIs. PPSIs would be required to maintain a formal sanctions compliance program—something other BSA‑regulated financial institutions are not explicitly required to do. OFAC sanctions remain a strict‑liability regime, but Treasury is elevating sanctions compliance to the same programmatic level as AML/CFT. Examiners would look not only at whether a PPSI violated sanctions, but at whether its program is designed, resourced, and operating in line with OFAC’s risk‑based expectations. A strong program would meaningfully mitigate enforcement exposure, while gaps or weak controls could carry greater consequences given the statutory mandate.

OFAC proposes requiring PPSIs to maintain an effective sanctions compliance program incorporating five core elements: senior‑management commitment; holistic risk assessments; risk‑based internal controls, including technical capabilities; independent testing and auditing; and risk‑based training. These elements align with OFAC’s existing guidance and reflect the GENIUS Act’s mandate that PPSIs comply with all federal sanctions laws applicable to financial institutions.

Technical Capabilities and Lawful Orders

The GENIUS Act requires PPSIs to maintain the technological capability to block, freeze, and reject impermissible transactions and to comply with lawful orders, including orders to seize, freeze, burn, or prevent the transfer of payment stablecoins. These expectations apply whenever a PPSI’s smart contract is involved, even in secondary‑market activity, and will require issuers to document how these controls function in practice. Because these controls must function whenever a PPSI’s smart contract is implicated, issuers will need to document how block, freeze, reject, and burn capabilities operate in practice and ensure they can withstand regulatory scrutiny.

Economic Impact

Treasury estimates that approximately 50 PPSIs may be subject to the rule, with first‑year compliance costs of about $1.8 million and ongoing annual costs of roughly $1 million. Government costs are estimated at $5.9 million in the first year, and customer costs at approximately $1.2 million annually. Treasury expects many PPSIs to be money‑services businesses or insured‑depository‑institution subsidiaries already subject to similar requirements, reducing incremental burden.

Key Takeaway

The proposal makes clear that Treasury now expects permitted stablecoin issuers to operate with the same level of AML, sanctions, governance, and technical rigor long required of mature financial institutions. The NPRM signals that PPSIs will need to build compliance into the core of their operating models—risk assessments, beneficial‑ownership collection, primary‑market SAR obligations, enhanced due diligence, and the ability to block, freeze, or burn tokens cannot be bolted on later. These expectations create a high regulatory bar, and not every current or aspiring issuer will be able to meet it. Firms with the capital, staffing, and engineering capacity to stand up a full BSA/OFAC program will be positioned to move forward, while smaller or less‑resourced issuers may struggle to qualify as PPSIs. The practical effect is a market that shifts toward a smaller number of issuers capable of operating under a full federal compliance regime. The framework ultimately favors well‑capitalized issuers and is likely to accelerate consolidation in the stablecoin market.

Next Steps

FinCEN and OFAC are accepting public comments for 60 days following publication in the Federal Register. Treasury seeks input on the clarity of definitions, the feasibility of technical requirements, the tailoring of obligations for PPSIs of different sizes and business models, and the interaction between federal and state regulatory frameworks.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On September 29, 2025, FinCEN issued a Notice and Request for Comment (the “Notice”) on a proposed information gathering exercise – A Survey of the Costs of Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) Compliance (the “Survey”).  Specifically, the Survey is intended to gather information on direct compliance costs incurred by non-bank financial institutions in AML/CFT compliance and, to the extent those costs overlap with other obligations, the amount directly attributable to AML/CFT compliance.

The Notice is directed to specific categories of non-bank financial institutions: Casinos and Card Clubs; Money Services Businesses; Insurance Companies; Dealers in Precious Metals and Stones; Operators of Credit Card Systems; and Loan or Finance Companies. 

In total, FinCEN estimates there will be 279,715 respondents falling into these categories, with the vast number – approximately 230,000 – being Money Services Businesses.  Given FinCEN’s assumption that the survey will take approximately 8 hours to complete, FinCEN estimates subject non-bank financial institutions to expend well north of 2 million hours providing the information sought.  While compliance with the survey will be voluntary, FinCEN notes that “information gathered will help assess the cumulative impact of AML/CFT regulations and may inform efforts to adjust regulatory obligations and advance deregulatory proposals consistent with the Executive Orders of the Trump administration.”  It also states that “the data may also support the development of deregulatory rulemakings or guidance to reduce compliance burden without compromising the effectiveness of current AML/CFT frameworks.”  And, FinCEN makes clear that no information submitted will be used for any supervisory or enforcement purposes.

Plainly, and expressly, FinCEN is setting the stage for efforts to scale back non-bank financial institutions’ compliance obligations, seeking comment on: the practical utility of compliance obligations, whether assumptions concerning compliance time-costs are accurate, ways to add efficiencies to the compliance process, ways information technology or other automated techniques can reduce manpower expended on compliance.

Comments will be accepted until December 1, 2025. 

For ease of reference, we reproduce the proposed survey here:

  1. What was the total estimated direct cost in calendar year 2024 for your institution for compliance with all programs mandated by the BSA and its implementing regulations?
  2. Please specify which of the following areas your institution uses technological resources, including software, to assist with, as applicable:
    • customer identification and verification procedures;
    • identifying suspicious activity;
    • currency transaction reporting or reports relating to currency in excess of $10,000 received by a trade or business;
    • 314(a) information sharing
    • Office of Foreign Assets Control (OFAC) compliance
  3. Approximately what percentage of the total direct cost of AML/CFT compliance is attributable to the production of Suspicious Activity Reports (SARs), if applicable.  These direct costs include costs associated with AML/CFT staff reviewing alerts, maintaining a transaction monitoring system, and investigating cases arising from alerts, whether or not they lead to the production of a SAR, among other things.
  4. (OPTIONAL) If your institution is able to provide the following information without significant burden, please provide approximately what percentage of the total cost of AML/CFT compliance is directly attributable to, as applicable:
    • Customer identification and verification procedures;
    • Reporting requirements for suspicious activity reporting;
    • Reporting requirements for currency transaction reporting and exemptions or reports relating to currency in excess of $10,000 received by a trade or business;
    • Internal controls related to AML/CFT compliance program;
    • Independent testing for compliance by internal personnel or an outside party;
    • Training and staffing employees;
    • 314(a) information sharing;
    • Funds transfer record keeping;
    • Monetary instrument recordkeeping;
    • Special measures;
    • Software;
    • Additional financial institution-specific BSA recordkeeping obligations (e.g., monetary instrument logs, also known as negotiable instrument logs, for casinos; extension of credit, for casinos; additional records that dealers in foreign exchange must retain);
    • MSB registration;
    • Other third-party activities
  5. What approximate percentage of the total cost of AML/CFT compliance is attributable to complying with OFAC regulations?
  6. Does your institution conduct anti-financial crime activities or maintain systems designed to combat financial crime that are not directly required by the BSA or its implementing regulations?  Examples include additional customer due diligence programs or the development and operation of a Financial Intelligence Unit.  If so, what is the direct cost (not included in question 1) of these additional activities across all business lines of your institution in calendar year 2024.  Separately, approximately what percentage of your institution’s total operating expenses did these direct costs represent in calendar year 2024?
  7. Please provide any available date or narrative comments for your institution regarding the extent to which the non-BSA driven expenditures (i.e., the costs referenced in question (6)) generate a substantial portion of either the overall suspicious activity, and/or of national AML/CFT priorities related threat activity, that is described in SARs, if applicable.
  8. Please provide any available data or narrative comments on whether there are particular types of products, services, customers or delivery channels where AML/CFT-required monitoring, reviews or investigations that have generated limited useful information from your institution’s perspective.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch.  Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

Second in a Two-Part Series on the Utility of BSA Filings

In this post, we will once again consider the issue of the utility of Bank Secrecy Act (BSA) filings to the global anti-money laundering/countering the financing of terrorism (AML/CFT) compliance regime. 

In our first blog post in this series, we invited Don Fort, a former Chief of the Internal Revenue Service’s Criminal Investigation (CI) Division, to answer questions on utility of BSA filings from the perspective of law enforcement.  Here, we will discuss two recent publications by industry groups:  one by the Bank Policy Institute, the Financial Technology Association, the Independent Community Bankers of America, the American Gaming Association, and the Securities Industry and Financial Markets Association (collectively, the Associations), and another by the Wolfsberg Group, which is an association of 12 global banks which aims to develop frameworks and guidance for the management of financial crime risks.

The Associations respond to an estimate by the Financial Crime Enforcement Network (FinCEN) concerning the time required to complete a Suspicious Activity Report (SAR).  The Associations’ observations on SAR filing compliance costs are targeted and precise and serve as a good segue into the broader critiques and recommendations made by the Wolfsberg Group regarding overall AML/CFT reporting and how it might be more effective.

Continue Reading BSA Filings and Their Utility to Law Enforcement:  An Industry Viewpoint

On July 3, the Financial Crimes Enforcement Network (FinCEN) published a notice of proposed rulemaking (NPRM) as part of a broader initiative to “strengthen, modernize, and improve” financial institutions’ anti-money laundering and countering the financing of terrorism (AML/CFT) programs. In addition, the NPRM seeks to promote effectiveness, efficiency, innovation, and flexibility with respect to AML/CFT programs; support the establishment, implementation, and maintenance of risk-based AML/CFT programs; and strengthen the cooperation between financial institutions (“FIs”) and the government.

This NPRM implements Section 6101 of the Anti-Money Laundering Act of 2020 (the “AML Act”).  It also follows up on FinCEN’s September 2020 advanced notice of proposed rulemaking soliciting public comment on what it described then as “a wide range of questions pertaining to potential regulatory amendments under the Bank Secrecy Act (‘BSA’) . . . . to re-examine the BSA regulatory framework and the broader AML regime[,]” to which FinCEN received 111 comments.

As we will discuss, the NPRM focuses on the need for all FIs to implement a risk assessment as part of an effective, risk-based, and reasonably designed AML/CFT program.  The NPRM also focuses on how consideration of FinCEN’s AML/CFT Priorities must be a part of any risk assessment.  However, in regards to addressing certain important issues, such providing comfort to FIs to pursue technological innovation, reducing the “de-risking” of certain FI customers and meaningful government feedback on BSA reporting, the NPRM provides nothing concrete.

FinCEN has published a five-page FAQ sheet which summarizes the NPRM.  We have created a 35-page PDF, here, which sets forth the proposed regulations themselves for all covered FIs.

The NPRM has a 60-day comment period, closing on September 3, 2024.  Particularly in light of the Supreme Court’s recent overruling of Chevron deference, giving the courts the power to interpret statutes without deferring to the agency’s interpretation, this rulemaking, once finalized, presumably will be the target of litigation challenging FinCEN’s interpretation of the AML Act. 

Continue Reading FinCEN Issues Proposed Rulemaking Aimed at Strengthening and Modernizing AML Programs Across Multiple Industries