Regulators asked us to focus on risk. Here's the playbook.

October 9, 2026
Rick Shooman
Head of Managed Services at Bretton AI

This is the second post in Beyond the BPO, a series on how Bretton's AI-native Managed Services is changing what bank leaders should expect from their financial back-office.

FinCEN's proposed AML/CFT Program Rule, issued in April 2026, asks banks to do something most compliance leaders have wanted to do for years: move vital resources away from lower risks and toward higher ones. The direction is welcome. The challenge is that nobody is handing you a bigger budget to do it with. For most institutions, funding the shift means finding the money inside the program you already run.

That’s an operations problem, and after twenty-five years in financial crime operations I can tell you it is solvable. Here is how I would think it through.

The regulators have been consistent about this

The risk-based idea is not new. The FFIEC examination manual has long directed examiners to scope exams to each bank's risk profile, with more attention on higher-risk areas and less on lower-risk ones.

What counts as higher risk is not a mystery either. FinCEN published the national AML/CFT Priorities in June 2021: corruption, cybercrime, fraud, transnational criminal organization activity, drug trafficking, human trafficking and smuggling, terrorist financing, and proliferation financing.

The April 2026 proposed rule turns that direction into program requirements. Institutions would formally assess and document their risks, incorporate the national priorities, and direct resources accordingly. Programs would be judged on effectiveness rather than volume, examiners would be expected to defer to reasonable, documented risk-based decisions rather than substitute their own judgment, and enforcement would be reserved for significant or systemic failures.

And the tools question has been answered for years. Since the 2018 interagency statement, regulators have explicitly encouraged innovation in AML, including artificial intelligence, and the 2026 proposal goes further: responsible use of innovative tools that demonstrably improve effectiveness would count in an institution's favor in enforcement decisions.

So the mandate is clear and the regulatory permission is explicit. The question is how to ensure this reorientation doesn’t put your institution at risk.

Where the money goes today, and how to spend less of it

Most AML budgets put a large share toward low risk work. Level 1 alert review on predictable activity, the payroll deposits and the steady local businesses that alert every month and clear every month. KYC and EDD refreshes on customers whose risk has not changed since the last refresh. Repeat alerts on well-understood customers. Routine data gathering and CTR filing. None of this is optional, but very little of it needs to cost as much as it does today.

I would use four levers to bring that cost down without weakening the program. First, AI for the mechanical layers of the work: triage, data gathering, and narrative drafting, with analysts making the decisions. Second, lower-cost managed services for the high-volume, repeatable work, so your own people are not the most expensive way to clear the simplest alerts. One caution from someone who has sat on both sides of these contracts: this lever only funds the shift if the vendor's unit cost actually falls over time. A provider priced on headcount times rate cannot lower your unit cost, because its revenue is charged by the hour. As your volume grows, so does the invoice, and the savings you planned to reinvest never materialize. Ask any provider what happens to your price per alert at twice the volume. The answer tells you whether this lever is real or just relabeled. Third, tuning and segmentation to cut false positives at the source, so the queue shrinks before anyone touches it. Fourth, risk-based refresh cycles, so review effort tracks the customer's actual risk instead of the calendar.

The guardrails matter as much as the levers. Cost reduction on low-risk work is defensible only when it comes with QA sampling, documentation, and full auditability, so that every decision, human or machine-assisted, can be traced and explained. That bar gets harder to clear the further the work sits from the officer who must stand behind it. The proposed rule would require a US-based AML/CFT officer, and SAR information sharing with foreign personnel remains tightly restricted, so an offshore operation your officer cannot fully inspect is a cheaper line item with an audit problem attached. It’s okay to reduce the cost, but never okay to reduce the evidence.

Where the risk actually lies

In today’s world of financial crime, regulators want to see banks focus on the highest risk activities. These include the following examples:

Chinese money laundering networks and cartel cash. In August 2025, FinCEN issued an advisory and trend analysis on Chinese money laundering networks, built on roughly 137,000 BSA reports filed from 2020 through 2024 flagging about $312 billion in suspected CMLN-related activity. The networks ran mule accounts, trade-based laundering, and real estate placements, and in some cases recruited bank insiders.

Fentanyl and cartel finance. In February 2025, major cartels were designated foreign terrorist organizations. In June 2025, FinCEN used its new FEND Off Fentanyl authority for the first time, issuing orders against three Mexico-based institutions, CIBanco, Intercam, and Vector, for facilitating cartel-linked payments.

Pig-butchering scams and crypto laundering. In October 2025, FinCEN finalized a rule severing Cambodia-based Huione Group from the US financial system for laundering proceeds of virtual currency investment scams and North Korean cyber-heist funds.

Elder financial exploitation. In a single year spanning 2022 to 2023, institutions filed about 155,000 SARs reporting roughly $27 billion in suspicious activity tied to elder financial exploitation, and about 80 percent of those reports involved scams, many built on account takeovers.

What these have in common should be a wake-up call. Not one of them is caught by investing in more Level 1 review hours. Mule networks hide in patterns that span accounts and institutions. Trade-based laundering hides in data no alert queue really surfaces. Scam proceeds move fast and sideways. Catching this work takes analytics, network visibility, and experienced specialists, which is to say, it takes the budget currently consumed by payroll-deposit alerts. These threats are not missed due to under-resourced queues. They are revealed in patterns the queue model cannot detect, no matter who staffs it or where it sits.

Where the freed-up dollars should go

When the low-risk work costs less by incorporating AI-native operations, the savings can be injected into high-risk detection. Technology first: network and link analysis, typology-specific detection, and better data integration, because the threats above are network problems and most monitoring stacks are account-level tools. Analytics and metrics next: typology coverage, SAR quality, law enforcement feedback, and time to detection, the numbers that actually describe effectiveness. People: experienced investigators and typology specialists, the ones who can read a mule network, not just clear a queue. And partnerships: 314(b) information sharing and real engagement with law enforcement, because none of the cases above respects the walls of a single institution.

This is the program the guidance describes

This is the program the regulators have been describing, in public, for years. The SAR FAQs and the proposed rule's effectiveness standard are explicit permission to stop over-spending on the low-risk work in the first list. The national priorities, the CMLN advisory, the FEND Off Fentanyl orders, the Huione rule, and the elder exploitation analysis are the regulator telling you, typology by typology, where the second list should point. A bank that documents its risk assessment, shows where the savings came from, keeps oversight of its AI and its providers, and reports on effectiveness rather than volume is not taking a position an examiner might dislike. It is following the advisory record.

A simple playbook

Baseline your spend by process. Target the low-risk processes with the most room to save. Lower their cost with the controls in place, not after. Reinvest in one or two priority typologies, not seven at once. Then measure and report, in effectiveness terms, so the story is visible to your examiners and your board.

Regulators have told us where to focus. Lowering the cost of the routine work is how to pay for it. The best institutions are not cutting the cost of compliance. They are reallocating it, and for once the regulator is pushing in exactly that direction.

If you are working through this challenge at your institution, I would like to compare notes. Reach out anytime.

Bretton AI runs agentic operations for the financial back office, replacing traditional vendor contracts with one accountable team on one platform. Learn more at bretton.com.

Get the next one first
Sign up to receive blog posts directly to your email

AI agents for the financial back office

Bretton builds AI agents for the back office of banks and financial institutions — compliance review, investigations and the operational work that still scales with headcount. Payward, the parent company of Kraken, uses Bretton to clear high-risk cases with full quality control instead of hiring against the backlog.

Share this post
Copied!

Table of contents

The Compliance Leader's Guide to Agentic AI

Get a practical framework for evaluating agentic AI solutions purpose-built for regulated financial institutions

Related blogs

View All