Skip to main content

FFIEC BSA/AML Examination Manual updates: What they mean for your AML/CFT program

Terri Luttrell, CAMS-Audit, CFCS
August 18, 2026
0 min read

What the FFIEC BSA/AML Examination Manual updates mean 

For many compliance professionals, the Federal Financial Institutions Examination Council (FFIEC) BSA/AML Examination Manual serves as the most reliable resource for understanding regulatory expectations. While it does not create new legal requirements, it provides valuable insight into how examiners evaluate anti-money laundering and countering the financing of terrorism (AML/CFT) compliance programs during examinations.

Recent Revisions

Since the FFIEC began updating the manual in 2020, it has issued several revisions, including significant updates in 2021, 2023, and most recently in 2026. Although each release has addressed different topics, the underlying message has remained remarkably consistent. Regulators continue to emphasize a risk-based approach, transparency in examinations, and the expectation that financial institutions demonstrate how their AM/CFT programs are designed to align with their unique risk profiles rather than relying on standardized checklists.

For compliance teams, these updates serve as an important reminder that maintaining an effective AML/CFT program is an ongoing process. Institutions that regularly review the examination manual alongside regulatory guidance are better positioned to identify emerging risks, strengthen internal controls, and prepare for examinations.

Staying on top of fraud is a full-time job. Let our Advisory Services team help when you need it.

Connect with an expert

 

Reinforcing risk-based compliance

One of the most important themes throughout the recent revisions is that financial institutions should avoid treating certain customer categories or products as inherently high risk. Instead, regulators continue to stress that risk should be assessed based on the specific characteristics of each customer relationship, product, service, and geographic exposure.

This principle was reinforced in the 2021 updates, which clarified examiner expectations surrounding charities and nonprofit organizations, politically exposed persons, and independent ATM owners and operators. The revisions emphasized that customer due diligence should be commensurate with each institution’s risk profile and that financial institutions should not engage in unnecessary de-risking solely because a customer belongs to a traditionally higher-risk category.

That same philosophy continues to guide more recent revisions to the examination manual. Rather than expanding lists of higher-risk customers, regulators have focused on evaluating whether institutions understand their own risks and have implemented controls that appropriately address them.

 

Transparency

One misconception surrounding updates to the FFIEC Examination Manual is that every revision creates new regulatory obligations. In reality, the recent updates have largely been intended to improve transparency by better distinguishing regulatory requirements from supervisory guidance and examination procedures.

The 2023 revisions reorganized several sections involving foreign correspondent banking, private banking, foreign shell banks, information sharing, and Iranian-linked financial institutions. These updates were designed to improve consistency in examinations while clarifying how existing requirements should be evaluated.

More recently, the 2026 revisions removed references to reputational risk from several examination sections, including Suspicious Activity Reporting and Electronic Banking. While this change generated industry discussion, it did not lessen expectations for AML/CFT compliance. Instead, it reinforced the view that examinations should remain focused on identifying and mitigating money laundering, terrorist financing, and other illicit finance risks, rather than evaluating institutions based on broader reputational considerations.

 

Risk assessment

Perhaps the greatest lesson from the past several years of updates to the examination manual is that the enterprise-wide AML/CFT risk assessment remains the foundation of an effective compliance program.

A current risk assessment should do far more than document products and services. It should demonstrate how the institution identifies its unique risks, evaluates those risks, and allocates resources to mitigate them. Just as importantly, it should show how those conclusions influence customer due diligence, transaction monitoring, staffing, training, independent testing, and board reporting.

Examiners increasingly expect to see clear connections between an institution’s documented risks and the controls designed to address them. When those connections are well supported, institutions are better prepared to explain why certain monitoring scenarios, customer risk ratings, or internal controls are appropriate for their business model.

This is particularly important as financial institutions expand digital banking services, introduce new payment technologies, and respond to increasingly sophisticated fraud schemes that often overlap with money laundering activity.

 

Continuous review

Historically, many institutions approached the risk assessment as an annual compliance exercise. Today’s regulatory environment demands much more.

Emerging fraud typologies, sanctions developments, beneficial ownership requirements, cyber-enabled financial crime, and evolving FinCEN priorities can change an institution’s risk profile throughout the year.

An effective AML/CFT program should include periodic reviews of the institution’s risk assessment, customer risk methodology, monitoring scenarios, policies and procedures, and governance processes to ensure they remain aligned with current risks.

This does not necessarily require a complete rewrite every time new guidance is issued. Instead, institutions should evaluate whether changes in their products, customers, services, delivery channels, or external threats warrant adjustments to existing controls.

Organizations that embrace this continuous risk management mindset are often better equipped to adapt quickly while demonstrating to examiners that compliance decisions are based on current risks rather than outdated assumptions.

 

A strategic resource

The FFIEC BSA/AML Examination Manual is far more than an examiner's handbook. It provides valuable insight into how regulators evaluate AML/CFT programs and offers financial institutions an opportunity to strengthen their compliance framework before an examination begins.

The recent updates do not introduce sweeping new requirements. Instead, they reinforce a consistent regulatory expectation that institutions understand their unique risks, document the rationale behind their compliance decisions, and maintain controls that evolve alongside an increasingly complex financial crime landscape.

Financial crime will continue to change, and regulatory guidance will continue to evolve. Institutions that regularly evaluate their AML/CFT programs against those expectations and use the Examination Manual as an ongoing governance resource, rather than an annual exam checklist, will be better positioned to manage risk, demonstrate compliance, and protect both their institution and the customers they serve.

Find out how to update your program to be FFIEC compliant.

Contact Advisory Services
About the Author

Terri Luttrell, CAMS-Audit, CFCS

Compliance and Engagement Director
Abrigo
Terri Luttrell is a seasoned AML professional and former director and AML/OFAC officer with over 20 years in the banking industry, working both in medium and large community and commercial banks ranging from $2 billion to $330 billion in asset size.

Full Bio

About Abrigo

Abrigo enables U.S. financial institutions to support their communities through technology that fights financial crime, grows loans and deposits, and optimizes risk. Abrigo's platform centralizes the institution's data, creates a digital user experience, ensures compliance, and delivers efficiency for scale and profitable growth.

Make Big Things Happen.