Regulator Pulse: AML / Sanctions Events — June 2026 Forward Calendar¶
This is a CCO/MLRO-facing brief covering active regulatory obligations confirmed in the May 2026 window that generate compliance deadlines between 2026-06-01 and 2026-08-31. It is a living forward-calendar companion to the full chronological log in 2026-05-regulator-pulse.md, which covers the 120-day event window 2026-02-01 → 2026-05-31.
Last updated 2026-06-04. Full chronological log: 2026-05-regulator-pulse.md — 120 days, 33 events. Previous edition: 2026-04-regulator-pulse.md — 89 days, 30 events.
Active Forward Calendar — June / July / August 2026¶
✓ COMPLETED · 2026-06-01 · FinCEN — Whistleblower Incentives & Protections NPRM comment period closed¶
What it was: FinCEN's March 30 NPRM operationalising the BSA whistleblower program (10–30% of collected sanctions from the $300M Financial Integrity Fund, anti-retaliation protections) closed for public comment on 2026-06-01. Status: Comment period closed. Final rule expected late 2026 / early 2027. Compliance teams should now audit internal reporting channels — median triage time, escalation-to-board documentation, audit-ledger coverage of all internally-reported concerns — before the final rule triggers implementation timelines. Source: Federal Register 2026-06271
⚠️ 2026-06-09 · FinCEN / OCC / FDIC / NCUA + OFAC — Effectiveness NPRM AND GENIUS Act Stablecoin NPRM comment deadlines (same day)¶
What it is: Two major NPRMs share a single comment deadline. 5 days remain.
-
AML/CFT Program "Effectiveness" NPRM (Federal Register 2026-07033): FinCEN, OCC, FDIC, and NCUA jointly reframe the BSA program rule around an "effective, risk-based, reasonably designed" standard implementing the AMLA 2020 mandate. A documented enterprise-wide risk assessment becomes a pillar (not just expected practice), and FinCEN national priorities must be incorporated into the program. "Effectiveness" is split into (1) program established and (2) program maintained — distinguishing technical from systemic failure. Proposed implementation period: 12 months after a final rule. Expected final rule late 2026 / early 2027.
-
GENIUS Act PPSI NPRM (Federal Register 2026-06963): FinCEN and OFAC jointly propose treating permitted payment stablecoin issuers (PPSIs) as financial institutions under the Bank Secrecy Act, and — for the first time — imposing mandatory, legally-binding OFAC sanctions compliance programs under new 31 CFR Part 502.
What MLROs need to do by June 9 (5 days): - Complete gap analyses now. The last realistic working window for completing, reviewing, and filing a comment letter is Friday June 5, with Monday June 8 the final business day before the Tuesday June 9 deadline for most firms. Gap analyses started after today may not finish before the concurrent deadline compresses industry filing bandwidth. - Complete a gap analysis against the Effectiveness NPRM's risk-assessment and program-structure requirements. The 12-month implementation clock starts at the final rule — late 2026 gap analyses may not leave enough time. - Stablecoin issuers and banks sponsoring PPSIs: assess BSA-program equivalence and OFAC-sanctions-program gaps against the PPSI NPRM framework. - File comment letters if your firm has positions. The concurrent deadline compresses industry comment bandwidth.
Sources: - Federal Register 2026-07033 — Effectiveness NPRM - FinCEN Fact Sheet - Federal Register 2026-06963 — GENIUS Act PPSI NPRM - Treasury Press Release SB0435
⚠️ 2026-07-01 · AUSTRAC — Tranche 2 enforcement begins for Australian DNFBPs¶
What it is: AUSTRAC's Tranche 2 AML/CTF reform brings Australian lawyers, accountants, real-estate agents, and dealers in precious metals and stones (DPMS) under the AML/CTF Act with mandatory enrolment and board-approved AML/CTF programs, enforceable from 2026-07-01. 27 days remain.
What MLROs need to do:
- Australian DNFBPs must be enrolled with AUSTRAC and have a documented, board-approved AML/CTF program before July 1.
- AUSTRAC's stated first-cycle posture favours enforceable undertakings (EUs) over fines — but only for firms with documented good-faith compliance efforts. A board-approved program, even a lean one, is the difference between an EU and an immediate penalty.
- The AML Open Framework's multi-jurisdiction example pattern (examples/) can serve as the Compliance Manifest template for a Tranche 2-scoped program with a single PR.
Sources: - AUSTRAC: Regulatory expectations and priorities 2025–26 - AUSTRAC AML/CTF Reform hub
⚠️ 2026-07-10 · AMLA — Statutory deadline to submit all final RTS to European Commission¶
What it is: AMLA must submit final draft regulatory technical standards — including the CDD RTS (AMLR Article 28(1)), the business-relationships and occasional/linked-transactions RTS (Article 19(9)), and the pecuniary-sanctions RTS (AMLD6 Article 53(10)) — to the European Commission by July 10. After submission, the Commission has three months to endorse before the RTS become binding law. 36 days remain.
What MLROs need to do: - EU-supervised obliged entities should treat July 10 as the "locked-in" date for the RTS framework. Post-July amendments require a full new legislative cycle. - Institutions operating cross-border EU programs should complete their alignment-gap assessment before the Commission adoption clock starts — the window to influence the standard has closed (all consultations closed by 2026-05-08). - Cross-border groups operating in 6+ member states should complete data submissions for the AMLA 2027 direct-supervision selection exercise, which uses the same data period.
Sources: - AMLA CDD RTS consultation - AMLA business-relationships RTS consultation - AMLA pecuniary-sanctions RTS consultation - AMLA selection exercise press release
What the Framework Shipped in June 2026 (to date)¶
Four ML/AI roadmap features delivered 2026-06-04 across v0.1.46 + v0.1.47:
| Feature | Version | SR 26-2 / Effectiveness NPRM relevance |
|---|---|---|
| M1 — Triage Queue dashboard page | v0.1.46 | Advisory priority_score with per-alert explanation panel; deterministic, explainable, off-by-default — satisfies MRM advisory-only requirement for ML-assisted alert ranking |
M2 — aml model-inventory CLI |
v0.1.47 | SR 26-2 model-population inventory covering every rule + every python_ref external model + the N1 prioritization scorer; --markdown table ready for model-risk committee reports |
M3 — champion-challenger priority_outcome.json |
v0.1.47 | Precision@k / recall comparison between champion and challenger weights; temporal-leakage guard enforced at runtime — satisfies SR 26-2's independent-challenger validation requirement |
| M4 — point-in-time effective-dated joins | v0.1.47 | DataContract.effective_dated + aggregation_window.enrich emit as-of SQL JOINs so rules resolve reference state contemporaneous with each transaction; closes Pillar 3 (PARTIAL → COVERED) |
These directly address the SR 26-2 and Effectiveness NPRM controls that are now examination-active (48 days from April 17): demonstrable test coverage of ML scoring logic, deterministic replay of flagged alerts, and a model inventory that can be produced on demand.
What the Framework Shipped in May 2026 (Operational Context)¶
The May 31, 2026 security hardening sprint (PRs H0–H6) directly addresses compliance-critical controls that regulators now examine under SR 26-2 and the Effectiveness NPRM:
| PR | Area | What it fixed | SR 26-2 / Effectiveness NPRM relevance |
|---|---|---|---|
| H0 | CI coverage gate | Enforced the 98% floor for real — the gate was non-enforcing (pytest-cov exits 0 on Linux below threshold) | Outcome-analysis discipline: model-risk MRM requires demonstrated test coverage of scoring logic |
| H2 | SQL injection in data sources | _assert_safe_sql_identifier() + _sql_str_literal() validate/escape all table identifiers and file paths interpolated into SQL |
Data-integrity requirement: the audit ledger's hash chain is only meaningful if the underlying data cannot be tampered |
| H4 | Zip-slip in audit packs | _safe_zip_segment() + _assert_safe_zip_path() sanitise all case-id-derived ZIP entry paths against directory traversal |
Regulator-evidence integrity: the ZIP the examiner receives must contain only the intended evidence |
| H5/H6 | Engine correctness | Freshness tz-by-instant (aware datetimes now converted to UTC before comparison, not wall-clock stripped); matched-row observability (lineage-lookup failures now logged with rule_id, not silently swallowed) | Conceptual soundness: SR 26-2 requires demonstrated correctness of staleness logic and lineage chain |
| Audit det. | Audit pack determinism | _audit_trail_verification no longer embeds datetime.now() — same inputs → identical output bytes |
Deterministic-rerun guarantee: the central SR 26-2 challenger-model requirement |
These are not operational niceties — they are the controls regulators will inspect when applying SR 26-2's MRM framework to the framework itself as a challenger model.
Looking Ahead: Q3 2026¶
FinCEN Effectiveness NPRM final rule (expected late 2026 / early 2027). Once finalised, the 12-month implementation clock starts. Firms that completed gap analyses during the comment window (pre-June 9) have a head start; firms that deferred will find themselves in implementation under time pressure.
AMLA direct-supervision selection (2027-07-01 → 2027-12-31). AMLA will select its first 40 directly-supervised obliged entities from July 2027. The data-collection exercise now underway feeds the selection methodology. Groups operating in 6+ EU member states with significant AML risk profiles are the highest-exposure segment.
AUSTRAC Tranche 2 first enforcement cycle (2026-07-01 onward). AUSTRAC's first-cycle posture will be clarified in H2 2026 through its inspection and EU program. First-mover documented programs will be the benchmark.
FinCEN Whistleblower final rule. Expected late 2026 / early 2027. Once finalised, the 10–30% award structure becomes operational. Firms with unresolved SAR-backlog or screening-gap issues face heightened exposure from insider tips.
Last updated: 2026-06-04 · Full chronological log: 2026-05-regulator-pulse.md — 2026-02-01 → 2026-05-31, 120 days, 33 events.