Reinforcing risk-based compliance
One of the most important themes throughout the recent revisions is that financial institutions should avoid treating certain customer categories or products as inherently high risk. Instead, regulators continue to stress that risk should be assessed based on the specific characteristics of each customer relationship, product, service, and geographic exposure.
This principle was reinforced in the 2021 updates, which clarified examiner expectations surrounding charities and nonprofit organizations, politically exposed persons, and independent ATM owners and operators. The revisions emphasized that customer due diligence should be commensurate with each institution’s risk profile and that financial institutions should not engage in unnecessary de-risking solely because a customer belongs to a traditionally higher-risk category.
That same philosophy continues to guide more recent revisions to the examination manual. Rather than expanding lists of higher-risk customers, regulators have focused on evaluating whether institutions understand their own risks and have implemented controls that appropriately address them.
Transparency
One misconception surrounding updates to the FFIEC Examination Manual is that every revision creates new regulatory obligations. In reality, the recent updates have largely been intended to improve transparency by better distinguishing regulatory requirements from supervisory guidance and examination procedures.
The 2023 revisions reorganized several sections involving foreign correspondent banking, private banking, foreign shell banks, information sharing, and Iranian-linked financial institutions. These updates were designed to improve consistency in examinations while clarifying how existing requirements should be evaluated.
More recently, the 2026 revisions removed references to reputational risk from several examination sections, including Suspicious Activity Reporting and Electronic Banking. While this change generated industry discussion, it did not lessen expectations for AML/CFT compliance. Instead, it reinforced the view that examinations should remain focused on identifying and mitigating money laundering, terrorist financing, and other illicit finance risks, rather than evaluating institutions based on broader reputational considerations.