On 10 October 2024, TD Bank agreed to pay roughly $3.09 billion and pleaded guilty to conspiracy to commit money laundering, the largest penalty ever imposed under the Bank Secrecy Act. The Justice Department found that 92 percent of the bank’s transaction volume went unmonitored between January 2018 and April 2024.

The financial crime risk consequences did not stop at the fine. The OCC imposed a $434 billion asset cap on the bank’s US retail operations, and the Federal Reserve added its own enforcement action, so growth itself became the penalty for a monitoring failure.

Financial Crime Risk Management Lifecycle: Key Takeaways
TD Bank paid roughly $3.09 billion on 10 October 2024, the largest penalty ever imposed under the Bank Secrecy Act, and became the first US bank to plead guilty to conspiracy to commit money laundering.
The failure was coverage, not documentation. The Justice Department found that 92 percent of TD’s transaction volume went unmonitored between 1 January 2018 and 12 April 2024, while the written program looked complete.
FinCEN proposed on 7 April 2026 to fundamentally reform AML/CFT program requirements, shifting supervision from process compliance toward demonstrated effectiveness, with comments closing 9 June 2026.
The financial crime risk lifecycle runs six stages: identify, assess, onboard, monitor, investigate and govern. Stage six feeds findings back into stages one through four, or the cycle is not a cycle.
Investment advisers gained time rather than relief. FinCEN pushed their AML program and SAR obligations from 1 January 2026 to 1 January 2028, so build now and use the runway.
Under an effectiveness standard, alert volume stops being evidence of a working program. Regulators will ask what your financial crime risk controls actually caught, and what law enforcement did with it.

TD had policies, procedures and a fully documented program sitting in a binder. What it did not have was coverage, and that single distinction is the whole subject of financial crime risk management in 2026, for banks and non-banks alike.

Regulators have now drawn exactly the same conclusion from that case. FinCEN’s proposed rule of 7 April 2026 would move the supervisory standard from process completeness toward demonstrated effectiveness, which changes what every stage of the financial crime risk lifecycle has to produce.

The Financial Crime Risk Management Lifecycle: Six Stages That Have to Work in 2026

Figure 1. Four agencies, one coordinated resolution, and a $434 billion asset cap on top.

What the Financial Crime Risk Management Lifecycle Actually Is

Strip away the vendor diagrams and the lifecycle is a loop with six stages and one rule. Each stage hands verified output to the next, and the last stage feeds what it learns back to the first, which is what separates a program from a policy binder.

The Financial Crime Risk Management Lifecycle: Six Stages That Have to Work in 2026

Figure 2. Six stages, one loop; break the return path and the program stops adapting.

The Six Stages of the Financial Crime Risk Lifecycle

Every stage below has a deliverable that a regulator can inspect and a failure mode that shows up in enforcement actions. Treating them as a sequence of documents rather than a chain of evidence is the most common structural mistake we see.

Stage What it produces Owner Failure mode
1. Identify Inventory of threats by product, channel, geography and customer type Financial crime risk team with business input Threat list copied from a peer bank, never localised
2. Assess Enterprise-wide risk assessment with inherent, control and residual ratings Second line, approved by the board Ratings that never change year to year
3. Onboard Verified identity, beneficial ownership, risk rating and EDD where triggered First line, with compliance oversight Rating set once at onboarding and never refreshed
4. Monitor Transaction and sanctions alerts tuned to the assessed risks Operations and technology Coverage gaps, exactly what cost TD Bank $3.09 billion
5. Investigate Documented case decisions and SAR filings within statutory deadlines Investigations unit Backlogs that push filings past the deadline
6. Govern Independent testing, model tuning, board reporting and remediation Internal audit and the board Findings recorded but never fed back into stages one to four

Notice that ownership moves between the lines of defence as the loop turns. Our walkthrough of the three lines model explains why stage four sitting in the first line while stage six sits in internal audit is a feature rather than an inconsistency.

Financial Crime Risk Management Versus AML Compliance

The terms get used interchangeably and they should not be. AML compliance is the obligation to meet specific legal requirements, while financial crime risk management is the discipline of reducing actual exposure to laundering, fraud, sanctions breaches and terrorist financing.

A firm can be compliant and still be exposed, which is precisely the gap FinCEN is now targeting. That is also why we treat the programme as one domain inside an integrated risk management program rather than as a standalone compliance silo.

Why FinCEN Is Rewriting the Financial Crime Risk Rulebook

Bridging from structure to supervision, the standard those six stages are judged against is changing while most programs are still mid-cycle. That is the single most important fact for anyone planning financial crime risk work over the next eighteen months, and it has a date attached. The specialization sits on top of the generic risk management lifecycle, which covers the base loop before the six-stage variant here refines it.

FinCEN issued a notice of proposed rulemaking on 7 April 2026 under the Anti-Money Laundering Act of 2020. The proposal would require programs to be effective, risk-based and reasonably designed, with comments closing 9 June 2026 and a twelve-month implementation period after any final rule.

The Financial Crime Risk Management Lifecycle: Six Stages That Have to Work in 2026

Figure 3. The compliance clock is already running on a rule that is not yet final.

Read the shift plainly, because it inverts a decade of habit. Under a process standard the winning answer was a thicker manual, and under an effectiveness standard the winning answer is evidence that controls caught something and that the output was useful to law enforcement.

The Financial Crime Risk Management Lifecycle: Six Stages That Have to Work in 2026

Figure 4. Four practical changes hiding inside one proposed rule.

Investment advisers received extra time rather than a genuine reprieve from any of these obligations. FinCEN moved their AML program and SAR obligations to 1 January 2028, which is runway to build the programme properly rather than permission to simply wait it out.

Stages One and Two: Identifying and Assessing Financial Crime Risk

The loop starts where most programs are weakest, because a financial crime risk inventory borrowed from a peer institution produces an assessment that describes somebody else’s business. Identification has to be specific to your own products, channels, geographies and customer types.

Anchor the whole exercise in published threat work rather than in practitioner intuition alone. The Treasury national risk assessments and FinCEN’s national AML/CFT priorities tell you what the government expects to see reflected in your own financial crime risk assessment.

Scoring then converts that inventory into decisions about where the money and the headcount go. A defensible enterprise-wide assessment rates inherent risk, control effectiveness and residual risk separately, using the same discipline as any structured risk assessment and a consistent scoring scale. The FATF risk-based approach guidance for banking and ISO 31000 both describe the same underlying method.

Our position is that a financial crime risk assessment is worthless unless it actually moves resources. If this year’s ratings look identical to last year’s and the monitoring budget did not change at all, the assessment is documentation rather than a control.

Stage Three: Customer Due Diligence and Financial Crime Risk at Onboarding

Onboarding is where the assessment meets a real customer, and where most residual exposure is created or avoided. Know your customer, customer due diligence and enhanced due diligence are three depths of the same control, applied according to assessed risk.

Control What it establishes When it applies
Customer identification Verified identity of the account holder Every customer, at account opening
Beneficial ownership The natural persons who own or control a legal entity customer Legal entity customers, refreshed on trigger events
Customer due diligence Expected activity, purpose of the relationship and a risk rating Every customer, proportionate to assessed risk
Enhanced due diligence Source of funds, source of wealth and senior sign-off High-risk customers, PEPs, high-risk jurisdictions
Sanctions screening No match against OFAC and other applicable lists At onboarding and continuously thereafter
Periodic review Confirmation that the rating still matches observed behaviour On a risk-based cycle, and on trigger events

Sanctions is the financial crime risk control with the least tolerance for error, because strict liability applies regardless of intent or knowledge. OFAC’s compliance commitments framework sets the expected components, and our note on sanctions screening in third-party relationships covers the vendor dimension of the same financial crime risk control, alongside OFAC’s own programme resources.

The failure mode here is quiet and almost universal. A customer rated medium risk at onboarding in 2021 who now moves ten times the expected volume is a high-risk customer wearing an old label, which is why periodic review belongs in the lifecycle rather than in a backlog.

Stage Four: Transaction Monitoring and Financial Crime Risk Detection

If the lifecycle has a single point of catastrophic failure, this is it. TD Bank’s monitoring program looked complete on paper while 92 percent of transaction volume simply never reached a detection scenario, and no amount of policy quality compensates for that.

Coverage is therefore the first question to ask, well ahead of tuning or technology selection. Ask which transaction types, channels and products actually flow into monitoring, then ask who verified that answer independently and exactly when they last did it.

Monitoring question What a weak answer looks like What a defensible answer looks like
What percentage of volume is monitored? Nobody has calculated it recently A reconciled figure by product and channel, tested by audit
Are scenarios tuned to the risk assessment? Scenarios inherited from the vendor defaults Each scenario traced to a named risk in the assessment
How are thresholds set? Set at implementation and never revisited Above-the-line and below-the-line testing on a defined cycle
What happens to alerts? Volume reported, outcomes not tracked Conversion rates to case and to SAR, trended over time
Who validates the models? The team that built them Independent validation consistent with model risk guidance

Model validation deserves specific attention during this particular year above others. The OCC, Federal Reserve and FDIC replaced their model risk guidance on 17 April 2026, and any monitoring systems that qualify as models inherit those new supervisory expectations directly.

Machine learning is now common in tuning and alert triage, which introduces a second control problem. Firms deploying it should map those systems against the NIST AI Risk Management Framework and their own AI governance framework before an examiner asks how the model decides.

Stages Five and Six: Investigation, Reporting and Financial Crime Risk Governance

Detection without disposition is just noise, so stage five converts alerts into documented decisions and, where warranted, filings. The statutory clock is unforgiving, and investigator backlogs are the mechanism by which good financial crime risk programs quietly become late ones.

Stage six is where the loop closes and where most programs quietly break. Independent testing, model tuning and board reporting only earn their cost if their findings change the threat inventory, the assessment ratings, the onboarding rules or the monitoring scenarios.

The FFIEC BSA/AML examination manual remains by far the clearest statement of what examiners look for across all of these stages, and the Wolfsberg Group principles set the private-sector benchmark that large institutions find themselves measured against informally by peers and examiners alike.

Board reporting is the visible output of stage six and usually the weakest artefact. A pack that reports alert counts without conversion rates or coverage figures tells the board nothing about exposure, which our board-ready dashboard examples are designed to fix. Governance expectations here echo COSO’s enterprise risk management guidance and, for listed firms, SEC disclosure obligations.

Measuring Financial Crime Risk Management Effectiveness

Under the proposed standard, financial crime risk metrics stop being a reporting convenience and become the evidence base itself. These are the measures we would put in front of a regulator, and each one answers a question that raw alert volume simply cannot.

Metric What it proves Why it matters under an effectiveness standard
Monitored volume percentage That detection actually sees the business The single figure that decided the TD Bank outcome
Alert to case conversion That thresholds are tuned rather than merely noisy High volume with low conversion signals wasted effort
Case to SAR conversion That investigations are finding real activity Demonstrates useful output to law enforcement
SAR timeliness That statutory deadlines are met consistently Late filings are an enforcement finding on their own
Periodic review currency That risk ratings reflect current behaviour Stale ratings undermine every downstream control
Remediation closure rate That stage six findings change the program Proves the lifecycle loop is closed rather than open

Wire these into the indicator set the risk committee already reads rather than inventing a parallel report. Our library of key risk indicator examples and the risk and control self-assessment method both translate directly, and banks can start from an RCSA template built for banks.

Where Financial Crime Risk Programs Fail

A regional bank we reviewed had 14 monitoring scenarios, a 40-page programme document and a clean internal audit opinion. Nobody could tell us what share of card and ACH volume actually reached those scenarios, which is the same question TD Bank could not answer.

Failure Root cause Correction
Unmonitored transaction types Coverage assumed rather than reconciled Reconcile monitored volume to total volume by product, then test it
Static risk ratings No trigger-based review, only calendar review Add behavioural triggers that force re-rating between reviews
Assessment that never moves money Ratings produced for the file, not for budgeting Tie the monitoring and staffing budget to assessment outputs
SAR backlogs Investigator capacity set to average, not peak Model capacity against alert peaks and escalate before deadlines slip
Findings that never close the loop Remediation owned by audit rather than the business Assign each finding to a stage owner with a re-test date
Sanctions treated as a subset of AML One team, one budget, very different legal standards Separate ownership and testing; strict liability changes the calculus
Vendor defaults left untuned Implementation deadline beat calibration work Trace every live scenario to a named risk or retire it

The pattern across all seven failures is the same one FinCEN is now legislating against. Each represents a program that could describe itself accurately on paper while failing to reduce actual financial crime risk exposure by very much at all.

Financial Crime Risk Management: Your Questions Answered

What is the financial crime risk management lifecycle?

It is the continuous six-stage loop that runs from identifying threats, through enterprise-wide assessment, customer onboarding, transaction monitoring and investigation, to governance and independent testing. Stage six feeds its findings back into the earlier stages, which is what makes it a lifecycle.

How does financial crime risk differ from general operational risk?

Financial crime risk concerns the deliberate abuse of an institution by third parties, which means the adversary actively adapts to your controls. General operational risk management mostly addresses process failure, error and disruption, where the causes do not actively evade detection.

What is changing in financial crime risk regulation in 2026?

FinCEN proposed on 7 April 2026 to reform AML/CFT program requirements so that financial crime risk programs must be effective, risk-based and reasonably designed. Comments closed on 9 June 2026, and any final rule carries a twelve-month implementation period after issuance.

Who owns financial crime risk inside a bank?

The board owns oversight and approves risk appetite, a designated BSA officer owns the program, and the business lines own the controls they operate. Independent testing sits with internal audit, keeping the three lines distinct in practice as well as on the chart.

How often should the financial crime risk assessment be refreshed?

Annually at minimum, and immediately on material change such as a new product, a new market, an acquisition or a significant enforcement development. A financial crime risk assessment whose ratings never move between refreshes is not being used to make real decisions.

What financial crime risk metrics do regulators want to see?

Coverage of monitoring against total volume, alert to case and case to SAR conversion rates, SAR timeliness, currency of customer risk ratings, and closure of remediation findings. Alert volume on its own demonstrates activity rather than financial crime risk effectiveness.

Do non-bank firms need a financial crime risk lifecycle?

Yes, and the financial crime risk perimeter keeps widening to include payment providers, money services businesses and, from 1 January 2028, investment advisers. The six stages apply regardless of charter, though the intensity of each one scales with assessed risk.

Three Shifts That Will Rewrite the Financial Crime Risk Playbook

The first shift is the effectiveness standard itself, and it arrives with a hard deadline attached. Financial crime risk programs that cannot evidence coverage and outcomes within twelve months of a final rule will be defending a documentation-era design against an outcomes-era examiner.

The second shift is the steadily widening perimeter of who has to do this at all. Advisers come into scope during 2028, and the FATF recommendations continue pushing member states toward covering sectors that never considered themselves financial institutions at all.

The third is artificial intelligence on both sides of the line. Criminals are industrialising synthetic identities and deepfake onboarding while institutions deploy models to detect them, which turns model governance into a frontline financial crime risk control rather than a technical formality.

Our advice is to start with the one number that decided the largest BSA case in history. Establish what share of your transaction volume actually reaches a detection scenario, have it independently verified, and report it to the board this quarter.

Test Your Financial Crime Risk Lifecycle Before an Examiner Does

Ask your BSA officer for the monitored-volume percentage by product and channel, with the workings. If the answer takes more than a week to produce, that delay is itself the finding, and it is fixable well before any final rule lands.

We help banks, payment providers and advisers rebuild financial crime risk assessments, close monitoring coverage gaps and produce board reporting that survives an actual examination. Review our advisory services or get in touch about whichever stage of the lifecycle you currently trust least.

Teams working alone should start at stage two and build outward. Anchor the assessment with the risk management process, record the output in a proper risk register, and set appetite using worked appetite statements before touching any tooling.

Then connect the programme outward, because financial crime exposure never stays in one function. Operational risk in banking, third-party risk management and reputational risk all carry pieces of the same exposure, and GRC fundamentals supply the governance vocabulary that ties them together.