This Week in AML

From FATF to FinCEN - Key AML, AI, and Regulatory Developments This Week

Written by AML RightSource | Oct 02, 2026

In this week's episode of This Week in AML, John Byrne and Elliot Berman examine Canada's newly released FATF mutual evaluation and what it may signal as the AML community awaits the upcoming U.S. assessment. They discuss FinCEN's plans to amend customer due diligence requirements related to immigration status verification, highlighting the operational and compliance challenges that institutions may face.

The conversation also explores escalating concerns surrounding artificial intelligence, including congressional calls for stronger oversight, emerging state-level initiatives, and recent reports of AI-enabled fraud targeting financial institutions. Additional topics include proposed stablecoin regulations under the GENIUS Act, new tools for measuring corruption, sanctions targeting criminal organizations, cybersecurity lessons from the reported FBI data breach, and outgoing SEC Commissioner Hester Peirce's critique of AML and KYC frameworks.

 

From FATF to FinCEN - Key AML, AI, and Regulatory Developments This Week - Transcript

Elliot Berman: Hi, John. How are you today?

John Byrne: I'm good, Elliot. Neither of us are at the ACAMS conference, but there's been, I won't say major news, but there's a couple things out of there we can mention. But I thought first it would make sense as we continue to await the FATF mutual evaluation of the US, that the FATF mutual evaluation of Canada was just released, and this is a mutual evaluation both of FATF and the Asia Pacific Group on Money Laundering, the APG.

This is a result of the onsite visits and follow-ups from November of twenty twenty-five. And so people should read the report themselves. The key findings are in various areas of risk, international cooperation, supervision, transparency, beneficial ownership, all sorts of things there, and there's a series of recommendations.

Some of the things that I noticed was again, overall a positive report, but Canada has been given some recommended actions that they have to complete within three years. So it's certainly not something that has to be done immediately. But some of the recommendations include strengthening the effectiveness of risk-based supervision, prosecution of complex professional and standalone money laundering cases, and expanding asset recovery.

So there's a whole series of things there. Read the report, but I thought I'd also highlight, the Minister of Finance issued a pretty detailed response and was pretty complimentary of the report's conclusions. And I'll just read a couple of quick quotes here, but you should look at that as well.

That's from the Department of Finance from Canada, again, issued the same day as the report's findings. And it said that they welcome the FATF mutual evaluation report. They said it's shows, quoting here, "Significant steps that Canada has taken in recent years to combat financial crime." It goes on to say that "Canada's strong legal framework, operational improvements and hawkish pursuit of bad actors have helped upgrade Canada's FATF evaluation to the best outcome category available and among countries whose AML/CFT systems are assessed to be broadly effective and aligned with international standards."

So again, that's from the Minister of Finance. Anything else in that report that jumps out at you?

Elliot Berman: No, I think you covered it, but I do want to put in a plug. November 19th we're going to do our November webinar, and it is on FATF evaluations and their impact, and I know you've got a couple of great speakers lined up and you're going to be talking about not just the reports, but the importance of mutual evaluations generally.

John Byrne: Since I mentioned the ACAMS conference, and you should go to the ACAMS website and moneylearn.com for further analysis. They have really good reporters on site there. But just the one thing I'll call out is that FinCEN announced during the conference that they're going to be taking additional steps to carry out an executive order calling for financial institutions to verify immigration status of their customers.

This was a May 19th executive order. The FinCEN representative was the acting associate director, and she told the audience that they are amending various regulations within 90 days to give the financial institutions what they're calling the authority to collect information on the immigration status.

So this is obviously going to be a change to the CDD rule. And again, just according to this is a report of the conversation, so we were not there in person. They said the executive order also gave the Treasury Department and the federal banking agencies until November 15th to revise the existing CIP requirements to quote, " account for the risks posed by foreign consular ID cards."

Something that we've reported on, but we should definitely watch. And in our end-of-the-year webinar that we'll do, obviously this will be something that I'm sure our panelists will mention, both operational and legal and other potential challenges to this, what could be a clear requirement as opposed to advisory direction.

Elliot Berman: And this will be one, depending on how FinCEN puts it into the regulation, I think this is a lot more complicated than it sounds on the surface. So we'll see. Unlike other elements of the CIP rule where there are clear ways to verify information, citizenship is a much more complicated thing, because there's no single US list of citizens.

John Byrne: Correct.

Elliot Berman: And status changes through time- ... in some cases. Not to get too deep in the weeds, but it'll be very interesting to read the rule and then to really think about how do you do this and keep it current and all that stuff. Where would you like to go from here?

John Byrne: Again, a bunch of other things just some quick hits here.

The House Committee on Financial Services the minority side issued a statement. And again, there's a lot of conversations going on about AI, which we will mention. But this particular press release came a couple of days ago. Congresswoman Maxine Waters, who's the ranking Democrat on Financial Services, issued the following statement when there were some reporting about OpenAI agents had targeted federal government websites, including activities from the SEC and other federal agencies.

Quoting here from the press release, "OpenAI's recent targeting of federal government websites marks a dangerous turning point in the unchecked artificial intelligence threat that members of Congress have warned about." And so that was highlighted by Maxine Waters. Obviously, since this has come out, there has been... an AI related meeting at the White House.

I also wanted to mention that my governor, I'm in the state of Virginia, Abigail Spanberger issued a statement a couple days ago as well. And this was a letter to Senate majority and minority leaders. And just quoting here from her description, "The impacts of AI are too great to leave to regulation solely in the hands of private companies." The conversation that we could have self-regulation, which Elliot and I can tell you from forty plus years of work never works, by the way.

"In the hands of private companies, especially when their CEOs," this again is from Spanberger, "are also sounding the alarm on the significant risks presented by their own technology." So she's asking congressional leadership in the House and Senate to take immediate action to confront the risks posed by the rapid development of AI.

And then we talked past couple of weeks about the executive order from Gavin Newsom. What Kathy Hochul, governor of New York, is doing in this space. So clearly, if there's perceived gaps from the federal government in terms of oversight, the states feel they either have to raise those concerns or act themselves.

So again, I know there's some other AI related issues that you want, you wanted to mention as well, Elliot.

Elliot Berman: I wanted to add that Governor Spanberger's letter also mentioned that she and others in Virginia are taking some action related to establishing AI safety programs.

Again, as you just said something that feels very strongly calls out loudly for federal action so that we have a consistent approach, the states are filling the gap until Congress and the administration decide to do something.

In terms of other things on the AI front, it was reported by AML Intelligence that two Italian banks were scammed by AI artificial voice creation where AI tools were used to mimic the voices of high-level authorized folks to access funds in two different banks and they were then transferred to offshore locations of the bad guys. These things are continuing to happen. This is not the only reported instance, but these were reported within the last week. That continues to happen.

The other thing I guess I would like to mention, and it's not about AI, but under the GENIUS Act, the four bank regulators which would be the OCC, FDIC, NCUA, and the Fed have an obligation to issue proposed rules related to stablecoins. The Fed issued their proposal either last Friday or this Monday. They're the last of the agencies to put their proposed rules out.

They're not identical, which is very interesting to me. If you're a state bank that's regulated by the Fed, then you're going to have a different rule than if you're a state bank that is regulated at the federal level by the FDIC. This seemed to me to call out for FFIEC action, but they each went their own way. Depending on who you're regulated by, you should look at the proposal. But in addition the thing to understand is that the effective date for the GENIUS Act is mid-January of next year.

And we're running, pretty close to the end of when you could get a final rule. Now, maybe they'll make those final rules effective beyond the effective date of the act. I don't know that was anybody's intent at the beginning, but it feels like that's where we're going to be. Take a look at the appropriate proposed rule for whoever regulates you if you're in a bank.

The other one that you pointed out that I think is worth talking about, but I'll let you take the lead on it, and that is that the UNODC has put out a statistical framework to measure corruption.

John Byrne: This was a report on how measurements can occur. There's like 145 indicators that cover criminal offenses, preventive measures, and broader enabling environments to report and address corruption offenses and risks. They talk about various things such as how do you translate the measurement into action, how to agree on priorities, and how to use the data to drive additional issues. So you can find this on the u4.no backslash publications, and it's Operationalizing the UNODC Statistical Framework to Measure Corruption.

It is from an organization we've talked about before, the U4 Anti-Corruption Resource Center. This was just posted late last week. And a couple of the main points from the framework include countries should begin with a small set of feasible policy relevant indicators, treating them as entry points to a broader measurement system. And then corruption statistics should inform the full policy cycle from identifying risks and bottlenecks to monitoring reforms and evaluating results.

Since we've talked about corruption and organizations that are involved in identifying those issues, I thought I would also mention that the Fact Coalition also posted on LinkedIn, Giulia Giancora, who's a environmental crime expert there, and somebody that we've had participated in, webinars for us in the past, she highlighted that The New York Times on Monday issued their investigation on the US importing gold that's linked to Tren de Aragua, which is a a foreign terrorist organization operating in southern Venezuela, and this is considered part of this administration's signature Venezuelan gold venture.

So Julia points out that in the story she told The New York Times, quote, "Around 90% of the gold produced in Venezuela is criminally produced. If international companies want to go in and try to find the 10% that's supposedly okay," she says, "that's like searching for a needle in a haystack."

So that, that was interesting, and it's related to another announcement by the US OFAC, and that is the sanctioning of a additional foreign terrorist organization, one that we've heard of before, Tren de Aragua. They designated 10 targets involved in their fraud scheme, that they say has been a key source of revenue for the organization. And so it's human trafficking, extortion, murder for hire. So that was just announced by the Treasury Department the same day that we are recording this which is Wednesday the 30th

Elliot Berman: Staying in corruption, I just wanna mention there's an organization the acronym is GRECO, the Group of States Against Corruption, and it's a part of the Council of Europe. It periodically publishes reports about efforts to stem corruption of member states, and it has recently published progress reports on Denmark, Hungary, Turkey, and Ukraine. The reason I mention it is if you are impacted in any way or by what business you do or where you do it by those countries it would be worthwhile to take a look at those reports.

And I wanna circle back to your conversation about the UNODC. . The focus of that report, which is excellent, is to give countries a framework to measure the corruption going on in their own countries. Every year, you and I talk about Transparency International's Corruption Perception Index, which has a very different purpose, and that is to create a framework to compare countries one to the other across the globe. A different purpose, but important. Both of them have real value.

John, I know you wanted to talk about the FBI data breach.

John Byrne: Go ahead. You have it in front of you.

Elliot Berman: It's been alleged that a group called ShinyHunters, they've claimed to have breached the FBI's jobs portal and stolen names, home addresses, and phone numbers of thousands of agents and their spouses. There's also some allegations floating around that if they really got in there, they may have stolen other personal information. Some commentators are calling this a serious counterintelligence disaster. There has been some information published on public sources, maybe as a proof that they really have the data. The only announcement I've seen from the FBI is they're investigating.

I guess the real message for the rest of us is let's be sure that our cybersecurity systems are working, because the bad guys are out there and they're trolling seriously.

John Byrne: Also after we recorded last week's This Week in AML, one of the commissioners from the SEC, Hester Peirce, who's been in role for, I believe nine years, or certainly since the first Trump administration, she's leaving. She's stepping down and gave a speech before SIFMA's Digital Assets Conference, and it was interesting on a number of levels, particularly because of our focus on AML related topics.

But I think you should take a look at the the speech. She's been a very strong supporter of crypto. That was pretty clear from her time in role here. But she spent some time in this particular speech talking about financial surveillance basically, and implying, if not directly stating, there should be a change to the version of the Bank Secrecy Act regarding how banks do know your customer.

So reading partially from the speech here, she said "The know your customer and AML frameworks operate on a simple theory." This is her suggestion of what the theory is. "If financial institutions under regulatory mandates collect enough information about enough people, law enforcement will be able to find the criminals hiding among the law-abiding majority.

We build ever bigger data haystacks on the theory that we'll find a needle or two inside. The bigger haystack, however, makes it harder to find the needles." I have a lot of questions about that whole paragraph. I'll leave it for others to decide whether they agree or not. She adds, "Consider the actual architecture of this haystack."

When you're calling the BSA a haystack, that kind of tells you where you're coming from. "Financial institutions following government mandates run CIP to collect and verify prospective customers' names, birthdays, addresses, and ID numbers. Ongoing surveillance obligations require FIs to understand the nature and purpose of a customer's relationship and activities on an ongoing basis.

When something looks unusual, or even when it does not, but a specific regulatory threshold has been crossed," huh, "financial institutions must file CTRs and SARs. Each one contains detailed personal and transactional information. Your firm knows the drill and knows just how costly monitoring and reporting on the customer is. The expense of running this system seems to dwarf its effectiveness on stopping bad actors."

Okay. Again, you should read that on your own. This is somebody who clearly is not a supporter of regulation. None of us are suggesting that the current BSA infrastructure is solid and doesn't need adjustment. We've talked about that for years, but I thought this was an interesting way to go out from Commissioner Hester Peirce.

Elliot Berman: Yes.

John Byrne: Hey, not everybody reads all these speeches, but I think, that's part of our job, right? Is to say, "Here's something you should pay attention to because- Yeah ... these people are policy leaders."

Elliot Berman: Yes. I wonder if she would've given that same speech if she weren't leaving.

John Byrne: Exactly ...

Elliot Berman: Don't know. So as we wrap up I know that you have a good panel put together for our October webinar, which is Best Practices in Managing Your High-Risk Customers, and given the fact that now everything is risk-based, I think my toaster is now risk-based, this is particularly timely.

That will stream on October 22nd at 1:00 PM Eastern Time, and there's still plenty of time to get a seat. And John, do you have other things in the pipeline you want to talk about?

John Byrne: I want to cross-promote something. Some of you are aware that I do a different podcast for Marquette University under the umbrella of the Center for Peacemaking. So it's about Marquette's focus on nonviolence and peace studies, those issues. But last week I had a very interesting conversation that I think is relevant to our community as well because it does touch on artificial intelligence. I interviewed a data scientist at Marquette, Michael Zimmer, about his work in AI and ethics.

That will be posted on Friday when you hear this conversation. So you can just go ahead on either LinkedIn or one of the social media platforms or YouTube. It's on YouTube as well. The Marquette University Center for Peacemaking. It's a half-hour conversation with Dr. Zimmer about that issue and as I was telling Elliot, I think it, there's a relevance to our space because AI is impacting in, surveillance, it's impacting money laundering prevention, human trafficking- all those issues, and I think the more we can learn from all stakeholders, the better off we will be.

Elliot Berman: Agreed. I'm looking forward to that posting. And one other thing that's posting is if you didn't get a chance to sit in on our September webinar on compliance best practices navigating the evolving global compliance landscape, that too should be posted to our website by the time you hear this episode.

So John you have a good rest of the week. I will be gone next week, so you and Joe McNamara will be handling next week's episode, but I will talk to you the following week.

John Byrne: Sounds good. Safe travels. Stay safe.

Elliot Berman: You too. Bye-bye.