FinCEN’s 2026 NPRM: The AML collaboration imperative?

by Rick Hamilton , AI Strategist and Risk Management specialist , Consilient
Key takeaways from this article:
FinCEN’s proposed AML rule sets one standard: demonstrate that your program is genuinely effective. Process-based compliance is no longer enough.
No bank encounters the full range of financial-crime typologies, can freely combine suspicious activity data with peers, or can objectively benchmark its own SAR experience. These are structural limitations of the single-institution view.
Banks that engage in proactive analytics and innovative activities producing demonstrable outputs will have that held in their favour when FinCEN considers supervisory or enforcement action.
Collaborative approaches allow institutions to benefit from shared typology knowledge and external benchmarks without exposing underlying customer data or displacing existing systems.
Responsible experimentation is explicitly encouraged. Banks that can show their programs learn from risks and experience beyond their own four walls will be better positioned when a final rule lands.

On April 7, 2026, FinCEN and the federal banking agencies issued a notice of proposed rulemaking (NPRM) to reform the Bank Secrecy Act’s AML/CFT program requirements. The proposal does not order banks to adopt any particular technology. It does something more interesting. It names specific categories of innovation and states plainly that experimenting with them will not expose an institution to enforcement risk.

Left unspoken, but not hard to infer, is this point: a program that never experiments with collaborative tools has correspondingly less to point to when an examiner asks what evidence it has of effectiveness beyond its own four walls.

That detail is easy to miss in a document mostly concerned with risk assessments, program governance, and the boundary between “establishing” and “maintaining” a compliance program. FinCEN is telling banks that experimenting with collaborative machine learning, alongside artificial intelligence and other advanced monitoring tools, is the kind of proactive analytics the agency wants to see and will weigh in a bank’s favour when considering supervisory or enforcement action. 

What’s more, The NPRM also draws on the AML Act of 2020’s stated purpose to “encourage technological innovation and the adoption of new technology by financial institutions to more effectively counter money laundering.” These documents set a clear expectation that banks will both innovate and collaborate, and do so in a way that aligns with their specific AML risks and risk appetites.

The proposed rule would require a federal banking regulator to give FinCEN’s Director at least thirty days’ advance written notice before taking a significant AML/CFT supervisory action against a bank, so that FinCEN can review and weigh in first. In deciding whether to bring an enforcement action, pursue a significant supervisory action, or push back on a banking regulator’s proposed action, FinCEN’s Director is directed to consider, among other things, whether the bank is employing innovative tools such as artificial intelligence, federated learning, or other advanced monitoring tools that produce demonstrable evidence of its program’s effectiveness. That is about as close to an explicit assurance as a regulator typically puts in writing: not merely that responsible experimentation will be tolerated, but that it is a named factor FinCEN will credit in a bank’s favor before deciding whether to consult, defer, or intervene.

Three areas of practice map onto this encouragement especially well, because each addresses a structural problem that no single bank can solve on its own since no institution:

  1. Sees enough of any one typology or has the industry-wide investigative expertise to train a fully representative model
  2. Can share raw suspicious activity data with peers
  3. Has an objective benchmark for how its own SAR filing experience compares to the broader system.

Federated learning answers the first problem. A model trained on one bank’s data reflects only the typologies that bank has actually encountered, and only the investigative expertise of its own team. Federated learning allows a model to train across many banks’ data without any institution’s records leaving its own environment, producing a multi-typology model informed by the collective investigative experience of the federation rather than any single participant. FinCEN’s proposed rule does not require this architecture, but it is difficult to construct a more literal answer to the agency’s interest in tools that let a bank demonstrate broader, evidence-based typology coverage. The approach is, in effect, a systematic and repeatable way of exchanging typology expertise and investigative know-how across institutions, in the same spirit as the information-sharing channels the NPRM already treats as legitimate inputs to a bank’s risk assessment.

Synthetic data addresses the second. Because federated models still need enough examples of rare or emerging typologies to generalize well, synthetic data generated from patterns observed in filed SARs can supplement thin real-world samples without exposing underlying customer records. Like the federated models themselves, this synthetic data improves as more institutions contribute to the training process, meaning its value compounds across the same collaborative structure the NPRM encourages banks to explore.

A comparative dashboard addresses the third. A bank can only judge whether its SAR filing patterns are unusual, thin, or well-calibrated if it has something to measure against. A dashboard that summarizes an institution’s own typology experience and sets it against both the average of a federation of peer banks and FinCEN’s own database of filings gives a compliance officer a concrete, evidence-based answer, exactly the kind of “demonstrable output” the NPRM references when it discusses proactive analytics and program effectiveness. It also gives examiners a more objective basis for evaluating a program than a purely narrative self-assessment.

None of this asks a bank to take collaborative machine learning on faith. Federated learning and synthetic data have a track record in other regulated, privacy-sensitive settings first. In medicine, the Federated Tumor Segmentation (FeTS) initiative trains diagnostic models across more than thirty hospitals worldwide, using synthetic imaging data to stabilize training where real cases of a given condition are scarce, all without any hospital’s patient records leaving its own systems.

In finance, the BIS Innovation Hub’s Project Aurora tested collaborative, privacy-preserving analysis across banks and borders and found it detected up to three times more complex money-laundering schemes and cut false positives by as much as 80% compared with siloed, rules-based monitoring. Consilient’s own bank trials have shown strong results inside a single federated model, reducing false positives while increasing true-positive detection. A bank experimenting with federated learning today is not the first institution to test the approach in a regulated, privacy-sensitive setting, which is part of what makes it a comparatively low-risk place to begin under the NPRM’s safe-harbor language, and a comparatively high-cost one to sit out.

Adoption also does not require a bank to displace what it already has. Because federated learning operates at the model layer rather than the data layer, it can be introduced in stages alongside existing systems rather than as a single, wholesale replacement. In Consilient’s implementation, that flexibility takes several forms:

  • Program foundation — Consilient serves as a bank’s primary detection system, for firms that want to replace their current rules-based model outright.
  • Program efficiency — Consilient runs as a post-processing layer alongside existing machine-learning or rules-based models, sharpening efficiency and risk prioritization.
  • Program benchmarking — Consilient is used to benchmark the effectiveness and efficiency of a bank’s existing system.
  • Collaboration link — Consilient operates as a feature within existing rules-based and machine-learning models, embedding cross-institution typology expertise while preserving each bank’s own customization.

A bank does not need to jump directly to full model replacement to benefit; each of these is a legitimate starting point on its own, and an institution can move between them as its risk assessment processes evolve, adding collaborative defense in depth gradually rather than all at once.

None of this requires a bank to choose between replacing its program wholesale and doing nothing differently. What the NPRM does is remove a specific source of hesitation, the fear that trying something collaborative or model-based will itself become the basis for a supervisory finding, at a moment when a growing body of evidence, in finance and beyond, suggests the approach works, and when FinCEN has told banks in writing that it will hold responsible experimentation in their favor.

Consilient’s platform was built around this same premise: that federated learning, SAR-trained synthetic data, and cross-institution benchmarking are more effective together than any bank’s isolated effort, and that they can be introduced gradually rather than adopted all at once. As FinCEN and the banking agencies finalize this rule, the institutions best positioned to show “demonstrable outputs evincing the effectiveness” of their programs, and the ones with the least explaining to do if they are not, may be the ones already experimenting with exactly the collaborative tools the NPRM calls out by name.

So, how do you plan to collaborate?

The comment period on the NPRM (Docket FINCEN-2026-0034, RIN 1506-AB72) closed June 9, 2026; FinCEN has proposed a twelve-month implementation period following any final rule.

Media Contact Email: enquiry@consilient.com

August 6, 2026 | Blog