Does Regulatory Flexibility Strengthen AML Compliance, Or Create New Governance Risks?
The U.S. Federal Reserve’s proposed overhaul of anti-money laundering supervision promises a more risk-based approach to compliance. Yet one controversial provision has reignited an old debate....
The U.S. Federal Reserve’s proposed overhaul of anti-money laundering supervision promises a more risk-based approach to compliance. Yet one controversial provision has reignited an old debate. Can regulators give institutions greater flexibility without weakening accountability? COMPLIANCETODAY asks…
For years, compliance professionals have complained that anti money laundering regulation often rewards documentation over effectiveness. Institutions have spent billions building controls, expanding compliance teams, and responding to examination findings, sometimes for procedural deficiencies that posed little genuine financial crime risk.
Now, the U.S. Federal Reserve appears ready to recalibrate that balance.
Its proposed amendments to AML and countering the financing of terrorism programme requirements would align supervisory expectations with a more risk-based philosophy already reflected in broader federal proposals. Rather than encouraging institutions to spread compliance resources evenly across all business activities, the proposal encourages banks to concentrate attention on customers, products, services, and transactions that present the greatest financial crime exposure. It would also require banks to integrate FinCEN’s national AML priorities into enterprise risk assessments.
On its face, the proposal reflects a modern understanding of financial crime. Criminal networks evolve faster than regulatory checklists. Effective compliance therefore depends less on mechanical adherence to process and more on an institution’s ability to understand, assess, and respond to changing risks.
Yet one element of the proposal has attracted particular attention within compliance circles.
The Federal Reserve suggests that supervisory action should generally focus on significant failures in implementing AML programmes rather than isolated or technical deficiencies. Supporters argue that this change would allow regulators to concentrate on weaknesses that genuinely increase money laundering risk instead of penalising every procedural imperfection.
Critics see something different.
Some fear that introducing a threshold centred on “significant” failures could create uncertainty about where regulators will draw the line between a technical weakness and a material compliance failure. Governor Michael Barr publicly expressed concern that the proposed standard may unintentionally weaken supervisory enforcement by introducing an undefined benchmark for regulatory intervention.
For compliance leaders, however, the debate should not revolve around whether regulators will become more forgiving.
The more important question is whether organisations will mistake regulatory flexibility for reduced accountability.
That would be a costly assumption.
Modern financial crime compliance has steadily moved away from checklist supervision towards demonstrable effectiveness. Regulators increasingly expect institutions to show that governance frameworks actually identify and mitigate financial crime risks rather than merely satisfy documentation requirements. Whether examinations become more principles based or remain rules driven, boards will continue to be expected to demonstrate effective oversight, credible challenge, and meaningful investment in financial crime controls.
This is where governance becomes inseparable from compliance.
A mature AML programme is no longer measured solely by the number of suspicious activity reports filed or policies updated. Increasingly, supervisors want evidence that institutions understand their own risk exposure, allocate resources proportionately, test the effectiveness of controls, and respond quickly when weaknesses emerge.
The proposed rule reinforces that expectation by placing enterprise wide risk assessment at the centre of AML governance. Institutions will be expected to align programmes with national financial crime priorities while ensuring that internal controls remain proportionate to evolving threats.
For boards, this raises important governance questions.
Does management receive meaningful financial crime intelligence or simply compliance metrics? Are risk assessments dynamic or largely annual exercises? Is internal audit evaluating the effectiveness of AML controls or merely confirming procedural compliance? Are technology investments improving detection capability or simply generating larger volumes of alerts?
These questions matter because financial crime increasingly exploits organisational blind spots rather than regulatory gaps.
Technology has transformed both sides of the compliance equation. Artificial intelligence, digital onboarding, instant payments, and cross border financial platforms have expanded opportunities for criminals while simultaneously providing institutions with more sophisticated monitoring capabilities. A risk based supervisory model recognises that institutions should have flexibility in designing controls, provided those controls demonstrably reduce exposure.
That flexibility, however, demands stronger governance rather than less oversight.
There is another lesson that extends well beyond the United States.
Regulators across multiple jurisdictions have gradually embraced outcomes-based supervision. Whether under FATF recommendations, European supervisory reforms, or emerging regulatory frameworks in Africa and Asia, the direction of travel is remarkably consistent. Institutions are increasingly assessed on the effectiveness of compliance programmes rather than their procedural completeness.
For compliance officers operating in emerging markets, including Nigeria, the Federal Reserve proposal offers an important reminder. Regulatory expectations are evolving globally. Organisations that continue treating AML as a documentation exercise may satisfy minimum regulatory requirements today while falling behind international supervisory expectations tomorrow.
Ultimately, the Federal Reserve’s proposal is not simply about changing examination procedures. It reflects a broader shift in regulatory philosophy, one that expects compliance functions to become more strategic, intelligence driven, and integrated into enterprise governance.
Whether the controversial supervisory provision survives the consultation process remains uncertain. What is already clear is that effective compliance will continue to depend less on avoiding examination findings and more on building institutions capable of identifying, understanding, and managing financial crime risk before regulators arrive.
For compliance professionals, that is the real message behind the proposal. Flexibility may change how regulators supervise, but it does not change the standard of governance expected from institutions. If anything, it raises the bar.



No Comment! Be the first one.