Three inflections move the enforcement perimeter forward into the July window:
SR 26-2 has been examination-active for 112 days. The joint Fed/OCC/FDIC model risk management guidance went live April 17. Q2 2026 examination cycles have run and Q3 cycles are forming — second-line MRM teams have presented gap analyses to boards. First examination correspondence citing SR 26-2 specifically for TM scenarios and customer risk-rating models was issued in the first active cycle. PAIN-6 remains in "active examination cycle" territory, now deeper into it.
FinCEN Whistleblower NPRM comment period closed June 1. The proposed award structure (10–30% of collected sanctions from the $300M Financial Integrity Fund; anti-retaliation protections for current and former employees) is in outline — FinCEN will consolidate comments and publish a final rule expected late 2026 / early 2027. The terms are proposed, not final. The incentive signal is real and targeted squarely at SAR-backlog and screening-gap failures. PAIN-2 and PAIN-7 carry external-report risk.
The Effectiveness NPRM + GENIUS Act NPRM dual comment window closed June 9. Both NPRMs shared the same cutoff, which has now passed. There is no published final-rule outcome — both rulemakings are pending (final rule expected late 2026 / early 2027, with a 12-month implementation clock from the final rule). Firms that completed gap analyses or filed comments during the window now hold that work as documented proactive-posture evidence usable in SR 26-2 model governance. Firms that deferred will implement under time pressure when the final rule lands. PAIN-4 and PAIN-10 are now measured by readiness for the pending final rule, not by the (closed) comment window.
The 10 pains below are unchanged in number and kind. What changed is the clock: the comment windows that defined the June edition's urgency have closed, and the three "final rule imminent" pains now turn on pending-rule readiness.
This is the style guide for every leader-facing word in this repository — README headlines, dashboard page descriptions, deck slides, exec emails. Before you write copy aimed at a CCO, MLRO, Head of Financial Crime, or CRO, find the closest pain point below and borrow its plain-English phrasing. Each pain is anchored in a primary source (regulator letter, enforcement order, or cited industry survey) so the copy is defensible the moment a buyer asks "where did you get that?"
Three rules behind everything in the table:
Audit-defensibility, not detection, is the dominant pain in 2026. Across recent enforcement orders surveyed (TD, RBC, Wells, NatWest, Citibank), regulators rarely allege the bank missed a typology — they allege the bank cannot evidence what it did, when, or why. Process and governance gaps outnumber data and model gaps roughly 2:1 in the consent orders. Lead with proof, not detection.
CCOs publicly say "alert volume," but the underlying ailment is "alert quality." The 95% false-positive figure is industry-canonical; cite it sparingly and never as our number — it's the baseline the framework helps escape. Frame in terms of analyst attention, not alerts.
Write the way they speak. "We couldn't prove what ran." "The backlog has been red on the board for years." "My monitoring system is a model and I cannot validate it." These are real CCO sentences from public sources — not vendor copy. Copy paste before paraphrasing.
Decisions get made every day — alerts triaged, customers exited, scenarios re-tuned — but when the regulator asks "show us the working," the audit trail is a Word doc, three people's memory, and a SharePoint folder no one can search.
Primary source
FCA Dear CEO Letter to Annex 1 firms, March 2024 (still operative in 2026): "Decisions made in relation to financial crime were not supported by evidence or an audit trail of debate and challenge." — FCA letter. FinCEN's April 2026 Effectiveness NPRM (Federal Register 2026-07033) proposes that independent testing must specifically verify whether "the AML/CFT program is maintained and implemented effectively" — the audit trail is the evidence base for both words. The comment window closed 9 June 2026; the rulemaking is pending. — Federal Register 2026-07033.
Roles affected
CCO, MLRO, Internal Audit
Cost type
Audit-defensibility
Framework capability
Hash-chained audit ledger + deterministic replay → any historical run reproducible byte-for-byte. Audit & Evidence dashboard page; PR #97 (rule-effectiveness backtester) extends this to "show me the rule's track record." The May 31 zip-slip fix (H4) and SQL injection guard (H2) protect the integrity of the evidence bundle itself — the controls SR 26-2 examiners will inspect for data-integrity chain assurance.
PAIN-2 · "The backlog is red — and the board has known for years."¶
Plain-English description
Alerts pile up faster than analysts can clear them. The dashboards show it. The board approves the program anyway. Then a regulator notices, and what was a slide becomes a consent order. As of July 2026, the FinCEN Whistleblower NPRM comment period has closed — the proposed 10–30% award structure is in outline, with a final rule expected late 2026 / early 2027. The incentive to report a chronic backlog existed yesterday; the formal mechanism is being finalized.
Primary source
TD Bank Consent Order (FinCEN, October 2024): TD allowed "trillions of dollars in transactions annually to go unmonitored"; the AIU detection queue was in "red status" in board reporting for years, attributable to chronic understaffing. — FinCEN release. FinCEN Whistleblower NPRM (Federal Register 2026-06271, comment period closed June 1, 2026): proposed 10–30% of collected sanctions from the $300M Financial Integrity Fund; anti-retaliation protections for current and former employees. Final rule expected late 2026 / early 2027. The institutional-reporting trail that protects the bank is the same trail the Whistleblower program will examine first. — Federal Register 2026-06271.
Roles affected
CCO, MLRO, 1LoD analyst, CRO
Cost type
Audit-defensibility + morale
Framework capability
SLA timer + escalation engine → red queues become loud, not slide-decoration. Investigations dashboard page; per-queue breach-rate badges. The append-only audit ledger documents every internal escalation — the record regulators expect internal-report programs to produce and that the Whistleblower program will inspect first.
Analysts spend their week clearing legitimate transactions. The real bad actor is somewhere in the queue they didn't get to. By Friday, the queue has grown — not shrunk.
Primary source
"With industry false positive rates averaging 95%, financial institutions waste millions investigating legitimate transactions." — Flagright industry analysis; reinforced by Celent / NICE Actimize 2026 framing of "moving from volume-driven processing to signal-driven decision making" — eClerx.
Roles affected
1LoD analyst, MLRO
Cost type
Cost + morale
Framework capability
Tuning Lab + threshold sweeps with precision/recall scoring → analyst attention buys signal, not noise. PR #97 backtester answers "is this rule still earning its keep?" without commissioning a vendor study.
PAIN-4 · "Our risk assessment is a PDF nobody trusts."¶
Plain-English description
The Business Risk Assessment is supposed to drive everything — scenarios, thresholds, training, board reporting. In practice it lives in a binder, was last refreshed 18 months ago, and the regulator notices first. As of July 2026, the comment window to influence the Effectiveness NPRM's proposed BRA requirement has closed (June 9); the rulemaking is pending. Firms that completed a gap analysis during the window hold documented proactive posture; firms that have not are racing a 12-month implementation clock that starts at the final rule.
Primary source
FCA Dear CEO: "Many Annex 1 firms did not have a BRA in place… the quality of the BRA was poor in terms of detail and methodology." — FCA via Waystone. FINTRAC has reclassified missing/stale risk assessments as "very serious" violations under its 2025 AMP regime. FinCEN Effectiveness NPRM (Federal Register 2026-07033): proposed rule makes a documented enterprise-wide AML/CFT risk assessment — incorporating FinCEN national priorities, approved by the board — a standalone program pillar. "Effectiveness" splits into (1) program established and (2) program maintained; a stale BRA fails criterion (2). Comment window closed 9 June 2026; rulemaking pending. — Federal Register 2026-07033.
Roles affected
CCO, 2LoD, Internal Audit
Cost type
Audit-defensibility
Framework capability
The Compliance Manifest is the risk assessment in machine-readable form — every rule cites the regulation it answers. Framework Alignment and Program Maturity dashboard pages render the live BRA from the Manifest.
New product, new geography, new payment rail. The financial-crime team finds out when alerts start firing or when the OCC asks. Growth got an executive sponsor; controls got a Jira ticket.
Primary source
FCA: firms showed "business growth without evolving financial crime systems and controls… inadequately resourcing financial crime teams alongside business growth." — FCA letter. OCC Wells Fargo enforcement (Sep 2024, still active in 2026): bank now barred from "expanding into medium-to-high risk products and geographies without prior approval." — Banking Dive.
Roles affected
CCO, MLRO, CRO
Cost type
Audit-defensibility
Framework capability
New product = new Manifest entries in days, not quarters. Multi-jurisdiction page shows coverage gaps the moment a new geography is added.
PAIN-6 · "My monitoring system is a model — and I cannot validate it."¶
Plain-English description
SR 26-2 went live on 17 April 2026 and has been examination-active for 112 days. Q2 2026 examination cycles have run and Q3 cycles are forming. BSA/AML transaction monitoring, sanctions screening, customer risk-rating, and CDD scoring are in the model-risk inventory with documentation requirements — not as a future obligation, but in current examination cycles. Second-line MRM teams have presented gap analyses to boards. Independent challenger validation is one of three explicitly acceptable validation methods, and the window to get ahead of the next examination letter is still open.
Primary source
SR 26-2 (effective 17 April 2026, 112 days active as of August 7): Joint Fed/OCC/FDIC guidance supersedes both SR 11-7 and SR 21-8. TM, sanctions screening, name-matching, customer risk-rating, and CDD scoring are "expressly included" in the model inventory. Examiner Q&A identifies independent re-implementation as one of three acceptable challenger-model validation methods. — SR 26-2; SR 26-2 Attachment; OCC Bulletin 2026-13. Language note: in leader-facing copy use "we can show our model still works" — not "MRM."
Roles affected
CCO, 2LoD model validation, MRM Director
Cost type
Cost + audit-defensibility
Framework capability
Per-rule MRM dossier (generators/mrm.py) + PR #97 backtester → "rule X precision/recall trend over the last 4 quarters" answered before lunch. The May 31 security hardening sprint (H0–H6) closed the remaining SR 26-2 gap: the coverage gate is now enforced platform-independently (scripts/check_coverage_floor.py), and the audit pack produces byte-identical output across runs. The framework now satisfies all three SR 26-2 independent-challenger requirements: deterministic rerun, hash-chained audit ledger, and demonstrated test coverage of scoring and audit logic. The M2 aml model-inventory CLI (v0.1.47) emits the SR 26-2 model-population inventory on demand.
PAIN-7 · "We file SARs we don't believe in, and we miss the ones we should file."¶
Plain-English description
The bank files thousands of defensive SARs the analyst doesn't believe in, while the genuinely-suspicious case sits in the queue past its filing deadline. The defect is data quality and case completeness, not analyst effort. As of July 2026, the FinCEN Whistleblower NPRM comment period has closed — the proposed incentive structure targets precisely these failure patterns.
Primary source
FINTRAC on RBC (2024, $7.5M penalty): bank "failed to flag suspicious activity, neglected to keep its written AML policies and procedures up to date and did not disclose relevant information in suspicious transaction reports… failed to submit 16 suspicious transactions reports across 130 customer files." — ACAMS; Global Relay. FinCEN Effectiveness NPRM (2026-07033): frames program effectiveness around the unbroken chain — suspicious activity identified, escalated, and reported — not alert volume. FinCEN Whistleblower NPRM (comment period closed June 1, 2026): proposed 10–30% award on collected sanctions, anti-retaliation protections. Final rule expected late 2026 / early 2027. — Federal Register 2026-06271.
Roles affected
MLRO, 1LoD analyst
Cost type
Audit-defensibility
Framework capability
Case-to-STR auto-bundling (PR #64) + STR filing latency p95 metric + auto-drafted narratives drawing from the alert evidence chain → analyst writes the narrative, not the bundle.
PAIN-8 · "$61 billion a year — and I still can't tell the CEO what we got for it."¶
Plain-English description
The bill is real and visible. The return is not. Vendor licences, consulting fees, audit-prep contractors, FTE growth — all line items. ROI is uncostable line-by-line, so the CFO ends every annual review with the same question: "is the juice worth the squeeze?"
Primary source
LexisNexis Risk Solutions, True Cost of Financial Crime Compliance, US & Canada (Feb 2024): "annual cost of financial crime compliance totals $61 billion in the United States and Canada." — press release. FinCEN's Sep 2025 RFI on AML compliance costs explicitly framed the question "Is the juice worth the squeeze?" — Mayer Brown summary.
Roles affected
CCO, CRO, CFO
Cost type
Cost
Framework capability
Apache 2.0, runs in your perimeter, no per-seat licence; effectiveness pack quantifies what the spend bought. Deck slide Cost of Status Quo maps 6 cost pools to specific framework deltas.
PAIN-9 · "1LoD and 2LoD don't know whose risk it is."¶
Plain-English description
The business books the customer. Compliance owns the alert. Neither owns the outcome. The auditor finds the gap. Three people answer "who decided?" with the other two people's names.
Primary source
FCA (2021 retail-bank Dear CEO letter, still cited in 2025-26 supervisory framing): firms "blurred responsibilities between first line business roles and second line compliance roles, such that first line employees often do not own or fully understand the financial crime risk faced by the firm." — Lexology; Mayer Brown.
Roles affected
1LoD, 2LoD, CCO
Cost type
Audit-defensibility + morale
Framework capability
One Compliance Manifest — same artifact 1LoD ships, 2LoD reviews, 3LoD attests. PR #98 (fraud-AML case linkage) makes overlapping work visible across operational lines. Deck slide Three Lines of Defence shows the handoff explicitly.
PAIN-10 · "The Officer's name is on the line, personally."¶
Plain-English description
OSFI's January 2026 AMP Guide and FINTRAC's 2025 reclassification mean the MLRO is no longer shielded by "the program." FinCEN's April 2026 Effectiveness NPRM proposes board approval and a US-located designated officer as regulatory requirements, not preferences — the comment window closed June 9 and the rulemaking is pending. The Whistleblower NPRM comment period closed June 1: the proposed external reporting pathway (10–30% of collected sanctions, anti-retaliation protections) becomes more concrete with each step toward a final rule. The gap in the audit trail is not only a regulator risk — it is, increasingly, an internal-report risk backed by proposed financial incentives for reporters.
Primary source
OSFI Letter to Industry (11 September 2025): OSFI announced "a lower tolerance for contraventions… penalties may be issued for lower levels of potential negligence and harm, and more frequently in 2026," with new AMP Guide published 29 Jan 2026. — Fasken summary. FinCEN Effectiveness NPRM (Apr 2026): AML/CFT programs "must be approved by a board of directors… designated AML/CFT officer must be located in the United States." The proposed rule bifurcates violation types into "program established" and "program maintained" — individual officers are named in both categories. Comment window closed 9 June 2026; rulemaking pending. — Federal Register 2026-07033. FinCEN Whistleblower NPRM (Federal Register 2026-06271, comment period closed June 1, 2026): proposed 10–30% award of collected sanctions, anti-retaliation protections for current and former employees. Final rule expected late 2026 / early 2027. — Federal Register 2026-06271.
Roles affected
CCO, MLRO personally
Cost type
Morale + audit-defensibility
Framework capability
Hash-chained ledger + deterministic replay = the Officer can sign a control attestation she actually believes. The Manifest version she signs is unambiguous — by hash — about what the program covered, when. The May 31 audit-pack determinism fix means "same spec + same data = identical output bytes" — the central SR 26-2 challenger-model requirement, and the evidence base for an Officer's attestation under the Effectiveness NPRM's proposed "program maintained" standard.
The dominant pain in July 2026 primary sources remains audit-defensibility, not detection — regulators rarely allege the bank missed a typology; they allege the bank cannot evidence what it did, when, or why (FCA, TD, RBC). The inflection as of August 7 is that the comment windows that defined June's urgency have closed: SR 26-2 (112 days examination-active), the Effectiveness NPRM (comment window closed June 9, rulemaking pending), and the Whistleblower NPRM (comment period closed June 1, final rule late 2026). The FinCEN Effectiveness NPRM proposes converting "supervisory expectation" to regulation for the audit trail (PAIN-1), the documented risk assessment (PAIN-4), and the Officer's personal accountability (PAIN-10). With the comment windows closed, the discriminator is now documented proactive-posture and readiness for the pending final rule — not a filing deadline.