Skip to main content

    Resources · Regulatory Guide

    The 2026 RIA AML Compliance Guide

    FinCEN's final rule brings SEC-registered investment advisers and ERAs into the Bank Secrecy Act on January 1, 2026. Here's what a compliant program looks like, what independent testing requires, and how to build it without over-engineering.

    Who this is for: CCOs, COOs, and general counsel at SEC-registered RIAs, ERAs, and private-fund advisers preparing their first AML/CFT program.

    Timeline at a glance

    Aug 28, 2024
    FinCEN publishes final AML/CFT rule for RIAs and ERAs
    2025 (Ongoing)
    Firms build risk assessments, draft written programs, appoint AML officers, and negotiate independent-testing arrangements
    Jan 1, 2026
    Compliance date — program must be operational; SAR/CTR filing obligation begins
    Q4 2026
    First annual independent test cycle typically due (or sooner if higher-risk)

    The five pillars of an RIA AML program

    FinCEN imported the same structure banks and broker-dealers already follow, adapted for the adviser model.

    1. Written program

    Board- or senior-management-approved policies covering CDD, monitoring, SAR/CTR, sanctions screening, recordkeeping, and information-sharing (Section 314(a) and 314(b)).

    2. AML Compliance Officer

    A named, senior-enough individual with authority to enforce the program. Fractional/outsourced AML Officers are permitted if properly documented.

    3. Training

    Role-based training at onboarding and at least annually thereafter. Retain sign-off logs and content versions for exam.

    4. Independent testing

    Annual (or more frequent) review by qualified personnel not involved in day-to-day operation of the program. Written report retained for five years.

    5. Risk-based CDD

    Client-risk rating, beneficial-ownership collection for legal-entity clients, ongoing monitoring, and enhanced due diligence for higher-risk relationships (PEPs, high-risk jurisdictions, cash-intensive).

    Risk assessment: what to score

    The written risk assessment is the foundation exam staff will read first. Score each client relationship (and the firm overall) across these five vectors, then calibrate the program's monitoring intensity to the result.

    Client type. PEPs, non-U.S. persons, shell entities, trusts with hidden beneficial owners, cash-intensive businesses.

    Product/service. Private funds, alternatives, cross-border SMAs, digital-asset exposure, unregistered offerings.

    Geography. FATF-listed jurisdictions, OFAC-sanctioned countries, high-corruption regions.

    Distribution. Third-party solicitors, unaffiliated introducing brokers, sub-advisory chains, family-office feeders.

    Delivery channel. Non-face-to-face onboarding, remote e-signature, custodian-referred flows without direct KYC.

    BSA/AML independent testing — scope checklist

    Independent testing is the pillar most RIAs underestimate. It must be performed by someone outside the day-to-day program, and it must be documented in a written report retained for five years.

    Risk assessment currency and methodology
    Written program vs. actual practice walkthrough
    Client-file sampling (CDD, beneficial ownership, EDD)
    OFAC / sanctions screening testing
    SAR decisioning workflow and 30-day filing timeliness
    CTR filing (if any cash equivalents)
    Training completion and content review
    Section 314(a) request handling and 314(b) log
    Recordkeeping and 5-year retention
    Prior-period findings remediation
    AML Officer authority and reporting line
    Board / senior management approval documentation

    Build vs. outsource: which pieces to keep in-house

    Keep in-house

    • • Escalation and SAR filing decisions (senior management sign-off)
    • • Board / management reporting
    • • Onboarding KYC intake and beneficial ownership collection
    • • Employee training attendance

    Reasonable to outsource

    • • Written program drafting and annual refresh
    • • Fractional AML Compliance Officer coverage
    • • OFAC / sanctions screening technology
    • • Independent testing (must be independent from program operation)
    • • Training curriculum and delivery

    Frequently asked questions

    When do the 2026 RIA AML requirements take effect?

    FinCEN's final rule (31 CFR Chapter X) applies to SEC-registered investment advisers and exempt reporting advisers (ERAs) beginning January 1, 2026. Advisers must have a written AML/CFT program, designate a compliance officer, and file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) starting on that date.

    Which advisers are covered — and who is exempt?

    The rule covers SEC-registered investment advisers (RIAs) and ERAs. State-registered advisers, family offices excluded under Rule 202(a)(11)(G)-1, foreign private advisers, and RIAs that limit their activities to registered investment companies or business development companies are not covered. Sub-advisers relying on a primary adviser's program should still document reasonable reliance.

    What five pillars does an RIA AML program need?

    The FinCEN rule imports the same five-pillar structure banks use: (1) written internal policies, procedures, and controls; (2) a designated AML Compliance Officer; (3) an ongoing employee training program; (4) independent testing at least annually; and (5) risk-based customer due diligence (CDD), including beneficial-ownership identification. Larger and higher-risk firms should test more often than yearly.

    What does BSA/AML independent testing look like for an RIA?

    Independent testing must be performed by qualified personnel who did not build or operate the program — internal audit, a co-sourced consultant, or a third party. Scope typically includes: risk assessment review, policy walkthrough, transaction and client-file sampling, OFAC/sanctions screening testing, SAR/CTR readiness, training records, and prior-period issue remediation. The written report goes to the AML Officer and senior management.

    How does this interact with the SEC's Customer Identification Program (CIP) rule?

    FinCEN and the SEC jointly proposed a companion CIP rule that would require covered advisers to verify the identity of each client at account opening (name, DOB, address, TIN) and keep the records for five years. When finalized, CIP obligations layer on top of the AML program and share documentation with your existing KYC/onboarding workflow.

    What are the penalties for non-compliance?

    The Bank Secrecy Act authorizes civil penalties up to $25,000 per day for program failures and criminal penalties up to $500,000 and 10 years for willful violations. SEC exam findings that reference the AML rule can also drive deficiency letters, enforcement referrals, and rescission of registration in extreme cases.

    How much does an outsourced RIA AML program cost?

    Building the written program, risk assessment, and CDD workflow typically runs $6,500–$18,000 depending on firm complexity. Ongoing fractional AML Officer coverage is usually $1,500–$4,500/month. Annual independent testing for a small RIA starts around $4,500 and scales with headcount, product mix, and transaction volume.

    Build a 2026-ready AML program with FIN Group

    We draft the written program, staff the fractional AML Compliance Officer role, and run the annual independent test — all coordinated inside RegReview so exam requests are one export away.

    Educational content only — not legal advice. Confirm current requirements with counsel.