10 AML Realities a FinTech / EMI / MSB / VASP MLRO Lives With — June 2026¶
Date: 2026-06-04 · Audience: FinTech / EMI / MSB / VASP MLRO. Companion to 2026-06-aml-process-pain.md (Tier-1 bank lens). Previous edition: 2026-05-fintech-aml-reality.md.
What changed between May and June 2026¶
Four inflections since the May 25 edition sharpen the urgency:
-
GENIUS Act NPRM comment deadline is June 9 — 5 days away. The comment window opened in April with 62 days to go. It now closes in 5 days. Today (Thursday June 4) is the last full working day before the Friday–Saturday June 5–6 filing window that is the realistic last stop for most firms. Stablecoin issuers and banks sponsoring PPSIs that haven't completed a gap analysis against the proposed BSA-program + OFAC-compliance framework are at risk of starting implementation after the comment window has closed — and without a documented proactive engagement posture. FINTECH-9 shifts from "7 days to file or miss the window" to "file tomorrow or Friday."
-
AUSTRAC Tranche 2 enforcement begins July 1 — 27 days. Australian DNFBPs (lawyers, accountants, real-estate agents, DPMS) that do not have a board-approved AML/CTF program and AUSTRAC enrolment before July 1 face enforceable consequences. AUSTRAC's stated first-cycle posture favours enforceable undertakings over fines — but only for firms with documented good-faith programs. For fintechs with Australian operations, the window is 27 days. FINTECH-10 urgency has increased.
-
SR 26-2 is 48 days examination-active. FinTech MLROs who manage transaction monitoring scenarios or CDD scoring models are in scope. Q2 2026 examination cycles are running. Sponsor banks conducting third-party risk reviews of fintech AML programs are now applying the same SR 26-2 MRM lens — the "independent challenger" requirement extends to in-house ML-based AML models in fintech programs reviewed as part of BaaS third-party risk management. The new
aml model-inventoryCLI (v0.1.47) produces the SR 26-2 model-population inventory on demand — the artifact sponsor-bank MRM reviewers are now requesting. -
AMLA RTS final submission deadline is July 10 — 36 days. AMLA must submit final draft regulatory technical standards to the European Commission by July 10. After submission the Commission has three months to endorse before the RTS become binding law. For EU fintechs, the alignment window is closing — the standard will lock in July, and gaps against the final RTS become implementation backlogs. FINTECH-6 urgency has increased.
The 8 realities from May plus the 2 new ones (FINTECH-9 and FINTECH-10) remain valid. June sharpens the timing on FINTECH-9 (from 62 days to 5 days), FINTECH-10 (from 37 to 27 days), and adds a new urgency marker to FINTECH-6 (36 days to AMLA RTS lock-in).
How to use this doc¶
The MLRO at a fintech is exposed in ways a Tier-1 MLRO is not: personal regulator-named risk, sponsor-bank cure notices, and Series-B due-diligence questionnaires arrive at the same desk. Each reality below is anchored in a primary source — an enforcement order, a regulator press release, or court filings — so the copy is defensible the moment a buyer asks "where did you get that?"
Three things to remember about this audience:
- The MLRO at a fintech is exposed in ways a Tier-1 MLRO is not. Personal named risk, sponsor-bank cure notices, and investor diligence questionnaires arrive at the same desk. Lead with the named risk to the role, not the program.
- The sponsor bank is a regulator-by-proxy. After Synapse's April 2024 collapse and the cascade of Federal Reserve / OCC / FDIC consent orders, the sponsor bank's risk officer can move faster than any government regulator. With SR 26-2 48 days active, sponsor-bank third-party risk reviews now apply an MRM lens to fintech AML programs.
- Speed of evidence > sophistication of detection. What buys a fintech MLRO survival is the ability to produce — within the cure-notice window — a primary-source-cited record of every alert, decision, and exit.
The 10 realities¶
FINTECH-1 · "The sponsor bank's 90-day cure notice is now the operative regulator."¶
| Plain-English description | A Banking-as-a-Service sponsor bank receives a consent order from the Federal Reserve or FDIC. Within weeks, every fintech that rides on that sponsor's banking licence gets a remediation letter with a hard cure window — usually 30, 60, or 90 days — to evidence its AML program. Miss the window and the sponsor terminates. The fintech's MLRO has no appeal. |
| Vignette | Wednesday 9am, the sponsor bank's risk officer emails: "Per our Federal Reserve consent order, we need your full BSA/AML program file — risk assessment, transaction-monitoring scenarios, SAR log, training records — by the 60th day. Anything missing flips the relationship to wind-down." |
| Primary source | Federal Reserve cease-and-desist against Evolve Bancorp / Evolve Bank & Trust, 14 June 2024: failed to maintain "an effective risk management framework" for fintech partnerships; required a written plan within 90 days plus an independent third-party review. — Federal Reserve press release. The cascade of 2024 BaaS consent orders — Blue Ridge, Lineage, Piermont, Sutton, Mode Eleven, Thread Bank — established the pattern: sponsor banks are required to inventory, risk-assess, and exit fintech partners on regulator-set timelines. — Banking Dive running list. |
| Roles affected | MLRO, Head of Compliance, CEO, Engineering |
| Cost type | License risk |
| Framework capability | The Compliance Manifest is the program file the sponsor's risk officer is asking for. The audit ledger replays any historical run byte-for-byte; aml audit-pack produces the cure-notice evidence pack in hours, not weeks. SR 26-2's MRM requirements now apply to the sponsor bank's third-party risk review of the fintech's TM scenarios — the Manifest's per-rule MRM dossier answers that review directly. |
FINTECH-2 · "Fast growth is what the sponsor and the regulator both find first."¶
| Plain-English description | The fintech goes from 50,000 customers to 3 million in four years. The product team celebrates. Sanctions screening, transaction monitoring, and KYC onboarding controls do not scale at the same rate. |
| Primary source | FCA Final Notice against Starling Bank Limited, 27 September 2024: £28,959,426 fine. "Starling grew from approximately 43,000 customers in 2017 to 3.6 million in 2023, however, measures to tackle financial crime did not keep pace with its growth." The bank "repeatedly breached a requirement not to open accounts for high-risk customers, opening over 54,000 accounts for 49,000 high-risk customers." — FCA press release. |
| Roles affected | MLRO, Head of Onboarding, Sanctions team, Board |
| Cost type | Compliance + license risk |
| Framework capability | New product + new geography = new Manifest entries in days. Multi-Jurisdiction dashboard page surfaces coverage gaps the moment the firm onboards in a new corridor. |
FINTECH-3 · "The Annex 1 questionnaire is supervisory, not advisory."¶
| Plain-English description | The FCA's March 2024 Dear-CEO letter to Annex 1 firms — roughly 1,000 EMIs, payment institutions, money brokers, and lenders — demanded a six-month gap analysis. October 2025's follow-up questionnaire converted that demand into a supervisory tool with named-firm consequences. The March 2026 FCA statement on risks for firms dealing with unregulated lenders extended EDD requirements to Annex 1 counterparties. |
| Primary source | FCA Dear-CEO letter to Annex 1 firms, 5 March 2024: "absent, inadequate or disproportionate Business Wide Risk Assessments… discrepancies between activities reported to undertake versus the activities actually undertaken… inadequate resourcing and oversight." — FCA letter. FCA statement on financial crime risks for Annex 1 firms, 20 March 2026: MLROs at FCA-regulated banks must explicitly extend EDD frameworks to Annex 1 counterparties. — FCA statement March 2026. |
| Roles affected | MLRO, Head of Compliance, Board |
| Cost type | Audit-defensibility + license risk |
| Framework capability | The Compliance Manifest is the BWRA in machine-readable form. Framework Alignment and Program Maturity dashboard pages render the live BWRA from the Manifest; a stale binder becomes a live document the MLRO can hand to the FCA case officer the same day the email arrives. |
FINTECH-4 · "VASP enforcement is now bespoke, not boilerplate."¶
| Plain-English description | The 2024-26 enforcement wave hits the absence of a coherent program: KYC onboarding, alert clearance, SAR timeliness, and PEP screening cited as one connected failure pattern. The VASP MLRO is now expected to evidence the whole chain. |
| Primary source | NY DFS Consent Order against Coinbase, 4 January 2023, $100M: "failures to conduct adequate KYC due diligence at customer onboarding, timely clear alerts, timely file suspicious activity reports, conduct proper PEP and sanctions screening." — NY DFS press release. FinCEN $3.5M penalty against a peer-to-peer virtual-asset platform, December 2025. — FinCEN enforcement actions. EU 20th Russia sanctions package (April 23, 2026): sectoral ban on transactions with any Russian CASP — VASP MLROs must now block Russian-CASP counterparties and review historical VASP-to-VASP exposure. — EU Council press release April 23, 2026. |
| Roles affected | MLRO, Head of Compliance, KYC ops, SAR ops |
| Cost type | Audit-defensibility + license risk |
| Framework capability | Investigation aggregator stitches alert → KYC → sanctions → PEP → SAR into one INV-{sha256} bundle, deterministically. The SAR latency p95 metric and auto-bundled SAR ZIP close the gap NY DFS named in Coinbase. |
FINTECH-5 · "The Travel Rule is 99 jurisdictions, four protocols, one MLRO."¶
| Plain-English description | FATF's revised Recommendation 16 requires originator and beneficiary information on every qualifying cross-border transfer over USD/EUR 1,000. 99 jurisdictions are at varying stages of legislation. FATF's February 2026 plenary grey-listed Kuwait and Papua New Guinea — VASP MLROs with counterparty exposure in those jurisdictions must now apply enhanced due diligence to travel-rule counterparty records from those geographies. |
| Primary source | FATF Recommendation 16 update, June 2025: global implementation by end-2030. — FATF R.16 update. FATF February 2026 Plenary: Kuwait and Papua New Guinea added to the grey list (Jurisdictions under Increased Monitoring). — FATF February 2026 outcomes. EU AMLR 2024/1624 brings MiCA-authorised CASPs under direct AML obligations including travel-rule compliance. |
| Roles affected | MLRO, VASP compliance ops, Engineering integrations |
| Cost type | Compliance + license risk |
| Framework capability | ISO 20022 + Travel Rule field validator (Round 5) plus pacs.008 / pacs.009 ingestion ship as one binary. The Compliance Manifest declares the field-level requirements once; the audit ledger evidences each transmission per counterparty. |
FINTECH-6 · "AMLR's 10 July 2027 clock is the single largest unfunded mandate in EU fintech."¶
| Plain-English description | EU Anti-Money Laundering Regulation 2024/1624 applies directly across all 27 Member States from 10 July 2027. AMLA's RTS consultations closed May 8, 2026 — AMLA must submit final draft RTS to the European Commission by July 10, 2026 — 36 days away. After submission, the Commission has three months to endorse before the RTS become binding law. The window for EU fintechs to align before the standard locks is closing in 36 days. Gaps against the final RTS become implementation backlogs that compress the already-tight runway to July 2027. |
| Primary source | AMLR 2024/1624 and AMLA 2024/1620, Official Journal 19 June 2024. AMLA consultations on CDD RTS, business-relationships RTS, and pecuniary-sanctions RTS closed May 8, 2026; AMLA must submit final drafts to the Commission by 2026-07-10. — AMLA CDD RTS consultation. AMLA direct supervision of ~40 obliged entities begins 2028; data-collection exercise for selection methodology is now underway. — AMLA selection exercise. |
| Roles affected | MLRO, Compliance Director, CEO, Board |
| Cost type | Compliance + license risk |
| Framework capability | Multi-jurisdiction templating ships specs for US (FinCEN), CA (FINTRAC/OSFI), EU (EBA/AMLD6 + AMLR-ready), UK (FCA/POCA). The regulation-drift watcher (compliance/regwatch.py) hashes every regulation reference URL and alerts on text drift — so the AMLR July 10 RTS lock-in and the July 2027 application date do not become surprises. |
FINTECH-7 · "49 state regulators, one MSB, one Bank Secrecy Act program."¶
| Plain-English description | A US Money Service Business registers with FinCEN once but is licensed by up to 49 states under bespoke money-transmitter regimes. CSBS's MTMA is closing the gap — 31 states have adopted it — but the MLRO still answers to a multi-headed examiner, with each state running its own BSA/AML examination cadence. |
| Primary source | Coordinated multi-state enforcement against Block, Inc. / Cash App, 15 January 2025, $80M penalty by 48 state financial regulators: required Block to hire an independent consultant and correct deficiencies within 12 months. — CSBS press release. CSBS MTMA adoption: 31 states, covering 99% of reported activity. — CSBS MTMA page. |
| Roles affected | MLRO, State licensing team, Head of Compliance |
| Cost type | Compliance + license risk |
| Framework capability | One Compliance Manifest, multiple jurisdiction-tagged audit packs (aml audit-pack --jurisdiction US-FINCEN, --jurisdiction US-NY-DFS). Deterministic re-run means any state's lookback computes from the same evidence chain. |
FINTECH-8 · "Series-B+ AML diligence is the unfunded compliance mandate nobody warned us about."¶
| Plain-English description | A fintech raising a Series B (or filing an S-1) is asked for an AML program file, sanctions-screening evidence, BSA/AML training records, and per-rule effectiveness data — by an investor diligence firm or by SEC underwriters' counsel. The cost is real, the timeline is non-negotiable, and the questionnaire reads like an FCA Annex 1 letter. |
| Primary source | Chime's S-1 filing (2025) flagged AML compliance as a material risk factor, situating the fintech "in the gray area between tech and finance" with elevated regulatory exposure. — ICLG Fintech Laws USA 2025-2026. LexisNexis: "annual cost of financial crime compliance totals $61 billion in the United States and Canada." — LexisNexis press release. |
| Roles affected | MLRO, CEO, CFO, General Counsel |
| Cost type | Investor / capital risk |
| Framework capability | Apache 2.0, runs in the fintech's own perimeter — no vendor NDA blocking diligence disclosure. The audit ledger answers "every change to every rule, with rationale and timestamp" in one query. The backtester produces the false-positive trend the diligence partner is asking for. |
FINTECH-9 · "We're a stablecoin issuer and the Bank Secrecy Act just found us."¶
| Plain-English description | A permitted payment stablecoin issuer has operated in a regulatory grey area between fintech and bank. The GENIUS Act NPRM proposes that ends: full BSA-program equivalents plus a mandatory OFAC sanctions compliance program under new 31 CFR Part 502. The comment deadline is June 9, 2026 — 5 days away. The banks that provide correspondent services to PPSIs face the same scrutiny through third-party risk channels under SR 26-2. |
| Vignette | The PPSI's CEO forwards the April 8 Treasury press release with one line: "Do we have a BSA program?" The compliance lead has screening and some transaction monitoring. She does not have a board-approved risk assessment, an OFAC-specific compliance program, independent testing records, or a named US-located AML/CFT officer. She has 5 days to comment on the NPRM and, simultaneously, to build what it requires. |
| Primary source | FinCEN + OFAC joint NPRM: "Permitted Payment Stablecoin Issuers AML/CFT Programs and Sanctions Compliance Programs," Federal Register 2026-06963, published April 10, 2026. Proposes adding PPSIs as "financial institutions" under 31 U.S.C. § 5312(a)(2), requiring full BSA-program equivalents plus a mandatory OFAC sanctions compliance program under new 31 CFR Part 502. Banks sponsoring PPSIs must update their BSA/AML third-party risk assessments. Comments due 2026-06-09 — 5 days. — Federal Register 2026-06963; Treasury Press Release SB0435; FinCEN PPSI NPRM PDF. |
| Roles affected | MLRO / AML Officer (newly designated), CEO, Legal, any sponsoring bank's BSA Officer |
| Cost type | License risk + audit-defensibility |
| Framework capability | The Compliance Manifest is the board-approved risk assessment and program file the NPRM requires. Multi-jurisdiction templating lets a PPSI Manifest reference both BSA (FinCEN) and OFAC obligations in the same file. Apache 2.0 deployment means no per-seat licence appears in the PPSI's vendor-risk register — a material simplification of the sponsor-bank due-diligence process under SR 26-2. |
FINTECH-10 · "AUSTRAC just made us an obliged entity. We have 27 days."¶
| Plain-English description | Australian lawyers, accountants, real-estate agents, and dealers in precious metals and stones become enforceable under the AML/CTF Act on July 1, 2026 — 27 days from now. AUSTRAC's stated first-cycle posture is enforceable undertakings rather than fines — but only for firms with documented, board-approved programs in place before July 1. After July 1, AUSTRAC's examination posture treats them like any other reporting entity. |
| Vignette | The managing partner of a Melbourne property conveyancing firm returns from a compliance conference and asks the operations manager: "What's our AML/CTF program?" The operations manager has a PEP check and a file note. AUSTRAC wants an enrolment, a board-approved program, a risk assessment, and compliance reports — in 27 days. |
| Primary source | AUSTRAC Regulatory Expectations and Priorities 2025–26: Tranche 2 reform brings lawyers, accountants, real-estate agents, and DPMS under the AML/CTF Act with mandatory enrolment and board-approved programs enforceable from 2026-07-01. AUSTRAC's stated posture favours enforceable undertakings over fines in the first cycle — but only for firms with documented, good-faith compliance efforts. — AUSTRAC: Regulatory expectations 2025–26; AUSTRAC AML/CTF Reform hub. |
| Roles affected | Partner / Principal (personally liable under Australian law), newly-designated AML/CTF Compliance Officer, Board |
| Cost type | License risk + audit-defensibility |
| Framework capability | Multi-jurisdiction templating lets an AUSTRAC Tranche 2 firm generate a board-approved Manifest with a risk assessment anchored to the AML/CTF Act obligations in days, not weeks. aml audit-pack --jurisdiction AU-AUSTRAC produces the evidence pack AUSTRAC examinations require. Apache 2.0, deployable in the firm's own infrastructure — the board-approved program is owned by the firm, not a vendor cloud. |
Themes (≈100 words)¶
For a fintech MLRO in June 2026, the operative regulator is still whoever moves fastest — but two structural deadlines are now days away, not months. The GENIUS Act NPRM comment window closes June 9 (5 days): stablecoin issuers and their sponsor banks must decide today whether to engage or defer. AUSTRAC Tranche 2 enforcement begins July 1 (27 days): Australian DNFBPs without a board-approved program face enforceable consequences in under a month. The AMLA RTS standard locks in July 10 (36 days): EU fintechs that haven't completed an alignment gap assessment are building on a moving target. In all three cases, the operative question is unchanged: can you prove what you have, before the window closes?
Sources¶
US Federal / FinCEN / OFAC¶
- Federal Reserve Evolve Bancorp consent order, June 14, 2024
- Banking Dive — running list of BaaS banks hit with consent orders in 2024
- FinCEN enforcement actions index
- FinCEN + OFAC GENIUS Act NPRM — Federal Register 2026-06963
- Treasury Press Release SB0435 — GENIUS Act NPRM
- FinCEN PPSI NPRM PDF
- CSBS press release: $80M Block / Cash App multistate action, January 15, 2025
- CSBS Money Transmission Modernization Act page
NY DFS¶
FCA (UK)¶
- FCA Dear-CEO letter to Annex 1 firms, March 5, 2024
- FCA press release: £29M Starling Bank fine, September 27, 2024
- FCA statement: Risks for firms dealing with unregulated lenders, March 20, 2026
EU (AMLA / AMLR)¶
- EU Regulation 2024/1620 establishing AMLA
- EU Regulation 2024/1624 (AMLR)
- AMLA CDD RTS consultation (closed May 8, 2026)
- AMLA selection exercise press release
- EU Council 20th Russia sanctions package, April 23, 2026
FATF¶
- FATF Recommendation 16 update, June 2025
- FATF Plenary outcomes, February 11-13, 2026
- FATF Jurisdictions under Increased Monitoring, February 2026