Resources · Regulatory Guide
The 2026 RIA AML Compliance Guide
FinCEN's final rule brings SEC-registered investment advisers and ERAs into the Bank Secrecy Act on January 1, 2026. Here's what a compliant program looks like, what independent testing requires, and how to build it without over-engineering.
Who this is for: CCOs, COOs, and general counsel at SEC-registered RIAs, ERAs, and private-fund advisers preparing their first AML/CFT program.
Timeline at a glance
The five pillars of an RIA AML program
FinCEN imported the same structure banks and broker-dealers already follow, adapted for the adviser model.
1. Written program
Board- or senior-management-approved policies covering CDD, monitoring, SAR/CTR, sanctions screening, recordkeeping, and information-sharing (Section 314(a) and 314(b)).
2. AML Compliance Officer
A named, senior-enough individual with authority to enforce the program. Fractional/outsourced AML Officers are permitted if properly documented.
3. Training
Role-based training at onboarding and at least annually thereafter. Retain sign-off logs and content versions for exam.
4. Independent testing
Annual (or more frequent) review by qualified personnel not involved in day-to-day operation of the program. Written report retained for five years.
5. Risk-based CDD
Client-risk rating, beneficial-ownership collection for legal-entity clients, ongoing monitoring, and enhanced due diligence for higher-risk relationships (PEPs, high-risk jurisdictions, cash-intensive).
Risk assessment: what to score
The written risk assessment is the foundation exam staff will read first. Score each client relationship (and the firm overall) across these five vectors, then calibrate the program's monitoring intensity to the result.
Client type. PEPs, non-U.S. persons, shell entities, trusts with hidden beneficial owners, cash-intensive businesses.
Product/service. Private funds, alternatives, cross-border SMAs, digital-asset exposure, unregistered offerings.
Geography. FATF-listed jurisdictions, OFAC-sanctioned countries, high-corruption regions.
Distribution. Third-party solicitors, unaffiliated introducing brokers, sub-advisory chains, family-office feeders.
Delivery channel. Non-face-to-face onboarding, remote e-signature, custodian-referred flows without direct KYC.
BSA/AML independent testing — scope checklist
Independent testing is the pillar most RIAs underestimate. It must be performed by someone outside the day-to-day program, and it must be documented in a written report retained for five years.
Build vs. outsource: which pieces to keep in-house
Keep in-house
- • Escalation and SAR filing decisions (senior management sign-off)
- • Board / management reporting
- • Onboarding KYC intake and beneficial ownership collection
- • Employee training attendance
Reasonable to outsource
- • Written program drafting and annual refresh
- • Fractional AML Compliance Officer coverage
- • OFAC / sanctions screening technology
- • Independent testing (must be independent from program operation)
- • Training curriculum and delivery
Frequently asked questions
When do the 2026 RIA AML requirements take effect?
FinCEN's final rule (31 CFR Chapter X) applies to SEC-registered investment advisers and exempt reporting advisers (ERAs) beginning January 1, 2026. Advisers must have a written AML/CFT program, designate a compliance officer, and file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) starting on that date.
Which advisers are covered — and who is exempt?
The rule covers SEC-registered investment advisers (RIAs) and ERAs. State-registered advisers, family offices excluded under Rule 202(a)(11)(G)-1, foreign private advisers, and RIAs that limit their activities to registered investment companies or business development companies are not covered. Sub-advisers relying on a primary adviser's program should still document reasonable reliance.
What five pillars does an RIA AML program need?
The FinCEN rule imports the same five-pillar structure banks use: (1) written internal policies, procedures, and controls; (2) a designated AML Compliance Officer; (3) an ongoing employee training program; (4) independent testing at least annually; and (5) risk-based customer due diligence (CDD), including beneficial-ownership identification. Larger and higher-risk firms should test more often than yearly.
What does BSA/AML independent testing look like for an RIA?
Independent testing must be performed by qualified personnel who did not build or operate the program — internal audit, a co-sourced consultant, or a third party. Scope typically includes: risk assessment review, policy walkthrough, transaction and client-file sampling, OFAC/sanctions screening testing, SAR/CTR readiness, training records, and prior-period issue remediation. The written report goes to the AML Officer and senior management.
How does this interact with the SEC's Customer Identification Program (CIP) rule?
FinCEN and the SEC jointly proposed a companion CIP rule that would require covered advisers to verify the identity of each client at account opening (name, DOB, address, TIN) and keep the records for five years. When finalized, CIP obligations layer on top of the AML program and share documentation with your existing KYC/onboarding workflow.
What are the penalties for non-compliance?
The Bank Secrecy Act authorizes civil penalties up to $25,000 per day for program failures and criminal penalties up to $500,000 and 10 years for willful violations. SEC exam findings that reference the AML rule can also drive deficiency letters, enforcement referrals, and rescission of registration in extreme cases.
How much does an outsourced RIA AML program cost?
Building the written program, risk assessment, and CDD workflow typically runs $6,500–$18,000 depending on firm complexity. Ongoing fractional AML Officer coverage is usually $1,500–$4,500/month. Annual independent testing for a small RIA starts around $4,500 and scales with headcount, product mix, and transaction volume.
Build a 2026-ready AML program with FIN Group
We draft the written program, staff the fractional AML Compliance Officer role, and run the annual independent test — all coordinated inside RegReview so exam requests are one export away.
Educational content only — not legal advice. Confirm current requirements with counsel.