CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

US Compliance Priorities for Q3 2026: AML, Stablecoins, and Fraud

CryptaCount Editorial · · 11 min read
AML / KYC / LICENSING US Compliance Priorities for Q3 2026:AML, Stablecoins, and Fraud

The third quarter of 2026 has handed US compliance teams a dense workload. A quarterly briefing by Forvis Mazars and ProBank Education Services, published 25 August 2026, catalogues an unusually heavy volume of active proposals, shifting suspicious activity report typologies, evolving FinCEN priorities, and a new generation of fraud schemes that are already reaching bank customers. For accounting firms, auditors, and CFOs with any exposure to digital assets, one item on that list demands particular attention: a proposed rule that would impose Bank Secrecy Act, anti-money laundering, and customer identification program obligations directly on permitted payment stablecoin issuers.

US Compliance Priorities for Q3 2026: AML, Stablecoins, and Fraud

A Regulatory Agenda That Will Not Wait

Agencies have been unusually prolific this quarter. Several rules have already crossed the finish line; others are still open for comment. The briefing is explicit that passive monitoring is not sufficient: compliance functions need to be engaging with the pipeline, not just logging it.

Rules Already in Effect

Two final rules took effect during the quarter. The first revised the Equal Credit Opportunity Act's treatment of disparate impact liability, issuing a clarification that ECOA does not recognise that theory and narrowing enforcement focus to overt discouragement of minority applicants. The rule was issued 22 April and took effect 21 July. The second final rule adjusted the Community Reinvestment Act small business data collection framework: the covered institution threshold moved from 100 to 1,000 originations, the small business revenue threshold was lowered to $1 million or less, and several discretionary data points were removed. That rule became effective 30 June.

The Consumer Financial Protection Bureau separately issued guidance on weighing immigration status in the ability-to-repay analysis and opened a request for information on reducing compliance burdens under the TILA/RESPA Integrated Disclosures regime.

Proposals Still Open for Comment

Several items are in the proposal stage and carry deadlines that teams should already have calendared. Key proposals include:

  • An FDIC proposal to lift the small-versus-large institution asset threshold from $10 billion to $30 billion, and to allow insured depository institutions to share confidential supervisory information with affiliates without seeking prior authorisation.
  • A Financial Stability Board consultation on sound practices for responsible adoption of artificial intelligence in financial services.
  • An FFIEC proposal to strengthen the CAMEL/UFIRS rating system used in bank safety-and-soundness examinations.
  • A joint proposal from four prudential agencies and FinCEN establishing compliance requirements for permitted payment stablecoin issuers.

The briefing's recommended approach is direct: track every open item, submit comments before deadlines close, and route any proposal with a material cost dimension (the FDIC assessment charge proposal is cited specifically) to the chief financial officer so that financial planning can begin now rather than after a rule is finalised.

The Stablecoin AML Proposal and What It Means for Digital Asset Accounting

The joint stablecoin proposal is the item most directly relevant to firms using crypto accounting software and digital asset accounting software. Under the proposed framework, permitted payment stablecoin issuers would be required to maintain full Bank Secrecy Act compliance programmes, implement AML controls, and operate a customer identification programme. They would also be subject to confidential reporting obligations.

Accounting and CFO Implications

For a firm that issues, holds, or transacts in payment stablecoins, this proposal signals a compliance infrastructure build-out that has accounting and finance consequences, not just legal ones. BSA programmes require documented policies, designated compliance officers, independent testing, and ongoing training, all of which carry costs that belong in a budget. Customer identification programme obligations create onboarding data that may need to be retained, audited, and reconciled against transaction records in the firm's crypto bookkeeping software.

Auditors reviewing stablecoin-exposed clients should begin assessing whether those clients have mapped their obligations under the proposed rule and whether their current accounting systems can produce the audit trail that a BSA examination would require. The proposal is not yet final, but comment periods close before any firm can complete a readiness assessment from scratch. Starting now is the only reasonable posture.

Confidential Reporting and Financial Statement Disclosure

The confidential reporting component of the proposal raises a subtler accounting question. If a stablecoin issuer receives a supervisory finding or is subject to a confidential directive, that fact may constitute a contingent liability or require disclosure assessment under US GAAP. CFOs and their auditors should agree in advance on the disclosure threshold and the process for surfacing such findings to the financial reporting team. That conversation is easier to have before a rule is final than after an examination has already begun.

SAR Typologies: What the Data Is Telling Compliance Teams

The briefing provides Q1 2026 suspicious activity report filing data across banks, savings institutions, and credit unions. The headline figure is 565,135 filings for that group alone, part of a total exceeding one million across all eight filing categories tracked by FinCEN. The composition of those filings has shifted in ways that should prompt firms to revisit their detection logic.

The Hierarchy Has Changed

Inconsistent transactions, meaning transactions with no apparent economic, business, or lawful purpose, now rank first among SAR typologies. When combined with inconsistent source of funds reports, this category accounts for 15% of total filings. Traditional structuring, the longstanding dominant typology, has fallen to fourth place. Suspicious wire transfers climbed above 9% of filings, while check fraud dropped to sixth.

For compliance teams calibrating their transaction monitoring systems, this is a meaningful signal. Detection rules built primarily around structuring thresholds may be systematically under-capturing the inconsistent transaction patterns that are now generating the most regulatory attention. Any firm using digital asset accounting software or crypto bookkeeping software to manage client transaction data should review whether its monitoring parameters reflect the current typology hierarchy, not the one from three or four years ago.

For a closer look at how continuous monitoring capabilities address exactly this kind of evolving pattern, the analysis of continuous monitoring and post-screening risk in crypto AML is worth revisiting alongside the Q3 data.

FinCEN Priority Areas: Beyond Traditional Financial Crime

FinCEN's stated priorities for the current period reflect a law enforcement environment that has moved well beyond conventional money laundering. The briefing identifies three areas that compliance officers should treat as active, not emerging.

Fiscal Fuel Theft and Smuggling

Fuel theft and fuel smuggling have become the largest non-drug illicit revenue source for cartel organisations operating across the US border. This is a reminder that AML typologies in sectors with physical commodity exposure, including energy companies with treasury digital asset holdings, can be more complex than standard financial crime patterns suggest. Transaction monitoring that focuses only on wire transfer anomalies may miss the layering stage of schemes that originate in commodity theft.

Identity Fraud and Payroll Tax Concerns

FinCEN has flagged concerns around identity theft and payroll tax fraud connected to non-work-authorised populations. The briefing notes that proceeds from these schemes can fund both criminal organisations and terrorist activity. For accounting firms with payroll clients, this is a prompt to ensure that payroll audit procedures include identity verification checks and that any anomalies in employee identification documents are escalated through the appropriate SAR pathway rather than treated as a routine HR matter.

Human Trafficking and Event-Based Red Flags

FinCEN issued a notice on 11 May 2026 detailing red flags associated with human trafficking activity expected to follow the FIFA World Cup 2026. Event-based typology notices of this kind are time-limited but operationally important: compliance staff who are not aware of the notice cannot apply the red flags it describes. The briefing's implicit recommendation is that FinCEN notices should be part of every compliance training cycle, not just annual BSA refreshers.

US Compliance Priorities for Q3 2026: AML, Stablecoins, and Fraud

Fraud Schemes Reaching Bank Customers Now

The Q3 briefing gives particular attention to fraud typologies that are already generating losses and reaching customers of banks and credit unions. Two categories stand out for their sophistication.

AI-Enhanced Pet and Imposter Scams

Pet scams have evolved to incorporate AI-generated images of distressed animals, combined with callers who pose as law enforcement officers or veterinary hospital staff. The emotional urgency is engineered, and the social proof of a convincing photograph or official-sounding caller makes detection harder for both customers and first-line staff. Government imposter scams have similarly escalated: fraudsters now send fake government photo identification via text message to establish apparent legitimacy before requesting funds. The briefing notes that losses to imposter scams in 2025 were substantial, and that social media was the single largest contact method by loss volume across all scam categories last year.

Defensive Measures Firms Should Implement

The recommended defences centre on three areas. Customer education remains the first line: customers who understand how government agencies actually communicate are harder to deceive. First-party fraud detection needs to be strengthened, particularly for account openings and payment initiations that follow an unusual sequence of contacts. And Nacha's updated monitoring rules for ACH transactions provide a compliance framework that firms should already be applying to their ACH payment processes. For firms whose clients hold or transact in digital assets, these same principles apply to on-chain payment flows, where the irreversibility of transactions makes early detection even more critical.

This quarter's fraud picture also connects to the broader policy environment covered in the review of global crypto policy shifts from Q2 2026, where cross-border enforcement coordination and typology sharing were identified as growing priorities for regulators in multiple jurisdictions.

Practical Steps for Accounting Firms and CFOs

The Forvis Mazars briefing is structured around three immediate actions that compliance teams should take in response to the Q3 regulatory environment. Each has a direct accounting dimension.

Build a Proposal Tracking Register

With multiple open proposals and staggered comment deadlines, a simple tracking register with responsible owners and deadline dates is a minimum requirement. For proposals with cost implications, the FDIC assessment change being the clearest example, the register should flag the CFO as a required reviewer before comments are submitted. Digital asset teams should ensure the stablecoin AML proposal is on the register with a readiness assessment workstream attached.

Recalibrate Transaction Monitoring Parameters

The shift in SAR typology rankings from structuring to inconsistent transactions is a direct prompt to review detection rules. Firms relying on crypto accounting software or digital asset accounting software to produce transaction data for AML review should audit whether the parameters feeding that review reflect current FinCEN typologies. A rule set calibrated for 2022 filing patterns will not catch the patterns generating 15% of 2026 filings.

Integrate FinCEN Notices Into Training Cycles

Time-sensitive notices, like the May 2026 human trafficking red flags issued ahead of the World Cup, have a short operational window. Compliance training cycles that run annually will miss them entirely. A quarterly review of FinCEN notices and typology updates, tied to the firm's SAR reporting calendar, ensures that front-line staff are applying current red flags rather than outdated ones.

Source: Forvis Mazars

Frequently Asked Questions

What does the proposed stablecoin AML rule require from issuers?

Under the joint proposal from four prudential agencies and FinCEN, permitted payment stablecoin issuers would need to implement a full Bank Secrecy Act compliance programme, maintain an AML framework, and operate a customer identification programme. They would also be subject to confidential reporting obligations. The rule is proposed, not yet final, but comment periods are open now.

Why has structuring fallen as the top SAR typology?

FinCEN Q1 2026 data shows that inconsistent transactions (those with no apparent economic or lawful purpose) have overtaken structuring as the leading SAR category, accounting for 15% of filings when combined with inconsistent source of funds reports. This likely reflects both changes in criminal methodology and improvements in detection systems that have made structuring harder to execute undetected.

How should accounting firms respond to the stablecoin proposal before it is final?

Firms should begin a readiness gap assessment now: map which clients issue or hold payment stablecoins, assess whether current onboarding and transaction recording systems can support BSA examination requirements, and engage in the comment process if the proposal's scope or cost structure warrants input. Waiting for a final rule leaves too little time for a compliant infrastructure build.

What are the accounting implications of a confidential supervisory finding under the proposed stablecoin rules?

A confidential directive or supervisory finding received by a stablecoin issuer may constitute a contingent liability under US GAAP, requiring a disclosure assessment. CFOs and auditors should agree on a disclosure protocol before any examination takes place, so that findings are surfaced to the financial reporting team promptly and the appropriate accounting treatment can be assessed without time pressure.

How do the updated SAR typologies affect firms using digital asset accounting software?

If the transaction data produced by a firm's digital asset accounting software feeds into an AML monitoring system, the detection parameters in that system should reflect current typology rankings. Rules optimised for structuring detection may systematically under-capture inconsistent transaction patterns, which now generate more SARs than any other category. A parameter review against the Q1 2026 FinCEN data is a practical starting point.

US#stablecoinsProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
GENIUS Act: Does the Synthetic Stablecoin Exemption Open a Back Door?
AML/KYC & Licensing
US Treasury Opens GENIUS Act Comment Period as January 2027 Deadline Looms
AML/KYC & Licensing
Treasury Proposes GENIUS Act Rules: Who Can Issue and Sell Stablecoins in the US
AML/KYC & Licensing
OFAC Sanctions 134 ISKP Crypto Addresses Tied to $2M in Terrorist Financing