Skip to main content
Category: Risk Assessment

AML/CFT National Priorities

Also known as: AML/CFT Priorities, National AML/CFT Priorities, AML/CFT Priorities, National Priorities for Anti-Money Laundering and Countering the Financing of Terrorism
Simply put

The AML/CFT National Priorities are a list published by FinCEN that identifies the most significant money laundering and terrorist financing threats currently facing the United States. First issued on June 30, 2021, they are intended to help financial institutions and other covered businesses focus their attention on the areas of greatest concern to U.S. national security and the financial system. The threats identified include areas such as corruption, cybercrime, terrorist financing, fraud, and transnational criminal activity.

Formal definition

The AML/CFT Priorities are government-established national priorities issued by FinCEN pursuant to the Anti-Money Laundering Act, which requires FinCEN to identify and periodically update the most significant AML/CFT threats to the U.S. financial system and national security. FinCEN published the first set of Priorities on June 30, 2021, describing threats related to predicate crimes associated with money laundering and terrorist financing; the Priorities were presented in no particular order and included categories such as corruption, cybercrime, terrorist financing, fraud, and transnational criminal organization activity. The Priorities are a policy instrument specific to the U.S. regime and do not by themselves impose freestanding obligations on obliged entities; the manner in which covered financial institutions are expected to incorporate the Priorities into their risk-based AML/CFT programs has been the subject of subsequent proposed rulemaking (for example, interagency and FinCEN proposals published in 2024). The evidence provided does not confirm the final effective requirements, and practitioners should confirm the current status, content, and any implementing rules against the applicable FinCEN and prudential regulator issuances. Note that under the AML Act terminology, FinCEN and the prudential agencies now generally use "AML/CFT" in place of the earlier "BSA/AML" phrasing.

Why it matters

The AML/CFT National Priorities represent an effort by FinCEN to give financial institutions a clearer signal about which money laundering and terrorist financing threats the U.S. government considers most significant to national security and the financial system. Rather than leaving institutions to interpret the landscape entirely on their own, the Priorities, first issued on June 30, 2021, articulate specific threat areas such as corruption, cybercrime, terrorist financing, fraud, and transnational criminal organization activity. For compliance officers and program owners, they function as a reference point for calibrating where risk-based attention may be warranted.

It is important to understand what the Priorities do and do not do. As published, they are a policy instrument specific to the U.S. regime and do not by themselves impose freestanding obligations on covered institutions. The precise manner in which institutions are expected to incorporate the Priorities into their risk-based AML/CFT programs has been the subject of subsequent proposed rulemaking, including interagency and FinCEN proposals published in 2024. Because the evidence available here does not confirm the final effective requirements, practitioners should treat the Priorities as a stated set of national threat concerns rather than as a definitive compliance mandate, and should confirm the current status against applicable FinCEN and prudential regulator issuances.

The Priorities also reflect a broader terminological shift. Consistent with the Anti-Money Laundering Act, FinCEN and the prudential agencies now generally use "AML/CFT" in place of the earlier "BSA/AML" phrasing, a change reflected in guidance from agencies such as the FDIC. Institutions monitoring their regulatory obligations should be attentive to how the Priorities are ultimately operationalized through implementing rules, as the eventual expectations will shape program design, documentation, and examination focus.

Who it's relevant to

BSA/AML and AML/CFT Compliance Officers
Compliance officers at U.S. covered financial institutions use the Priorities as a reference point when assessing which money laundering and terrorist financing threats may warrant attention in their risk-based programs. They should note that the Priorities did not, as published, impose freestanding obligations, and that the operational expectations depend on implementing rulemaking that should be confirmed against current FinCEN and prudential regulator issuances.
Financial Institution Risk and Program Managers
Those responsible for designing and maintaining risk-based AML/CFT programs may consider the listed threat areas, corruption, cybercrime, terrorist financing, fraud, and transnational criminal organization activity, when calibrating risk assessments and control priorities. The Priorities are presented in no particular order, so they should not be read as a ranked hierarchy of risk.
Regulatory and Examination Teams
Professionals tracking supervisory expectations should monitor how the Priorities are operationalized through implementing rules, including the interagency and FinCEN proposals published in 2024. They should also be aware of the terminology shift under the Anti-Money Laundering Act, where agencies such as the FDIC now generally use "AML/CFT" in place of "BSA/AML."
Legal and Policy Advisors
Attorneys and policy specialists advising covered institutions should distinguish between the Priorities as a stated policy instrument and any binding program requirements arising from implementing rulemaking. Because the evidence here does not confirm the final effective requirements, advisors should verify the current status, content, and implementing rules directly against applicable FinCEN and prudential regulator sources.

Inside AML/CFT Priorities

National-level priority statement
AML/CFT National Priorities generally refers to a formal set of priorities issued at the national level to focus obliged entities on the money laundering and terrorist financing threats considered most significant. In the US context, FinCEN issued National AML/CFT Priorities pursuant to the Anti-Money Laundering Act; other jurisdictions may publish comparable national risk-based priorities or national risk assessments under their own frameworks. Terminology and legal effect vary, and exact scope should be confirmed against the applicable regime.
Threat categories addressed
Such priorities typically identify categories of illicit finance concern (for example, corruption, fraud, cybercrime and cyber-enabled crime, terrorist financing, proliferation financing, drug trafficking, human trafficking, and transnational criminal activity). The specific list and its labeling depend on the issuing authority, and any enumeration should be treated as reflecting stated national concerns rather than an exhaustive or legally exhaustive typology.
Relationship to the risk-based approach
Priorities are intended to inform, not replace, an obliged entity's own risk-based approach. They are generally meant to be incorporated into risk assessments and program design in a manner proportionate to the entity's products, customers, geographies, and channels, rather than applied uniformly to all institutions.
Link to obliged-entity obligations
How and when priorities become operative obligations depends on implementing rules. In the US, for instance, the review-and-incorporation expectation was tied to future regulations rather than taking immediate binding effect upon publication of the Priorities themselves. Practitioners should confirm the current status of implementing rules in their jurisdiction before assuming a specific compliance requirement applies.
Distinction from a national risk assessment
National priorities and a national risk assessment are related but not identical. A national risk assessment is generally an analytical exercise identifying and evaluating ML/TF risks, while priorities are a directive focus statement derived from such analysis. The two may be published separately or together depending on the jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about AML/CFT Priorities.

Does the publication of AML/CFT National Priorities create an immediate, standalone compliance obligation that institutions must act on right away?
Not in the way many assume. In the US context, FinCEN's national AML/CFT priorities are intended to inform risk-based programs, but the operative obligation to incorporate them generally takes effect through subsequent implementing regulations rather than from publication alone. Until those rules are finalized and effective, examiners typically do not expect institutions to have formally overhauled their programs solely because the priorities were issued. Institutions may nonetheless choose to consider the priorities as part of their existing risk assessment. Exact obligations and timing should be confirmed against the applicable regulation and supervisory guidance.
Do National Priorities require every obliged institution to treat all listed priority areas equally within its program?
No. The priorities are not a mandate to devote equal attention to each listed area. They are intended to be applied on a risk-based basis, meaning an institution generally considers which priorities are relevant to its own products, customers, geographies, and delivery channels. A priority that does not correspond to an institution's actual risk exposure may warrant limited or no additional measures, provided that reasoning is documented. The priorities inform risk assessment; they do not override an institution's own risk-based judgment.
How should an institution incorporate National Priorities into its existing risk assessment?
A common approach is to map each published priority against the institution's current risk assessment to identify where the priority intersects with actual exposure, where existing controls already address it, and where gaps may exist. Institutions typically document this analysis, including reasoned conclusions about priorities deemed low or not applicable. This treats the priorities as an input to the risk-based process rather than a checklist. Specific expectations may vary by regulator, so institutions should confirm supervisory expectations for their sector and jurisdiction.
Who within the institution should own the process of reviewing and responding to National Priorities?
Responsibility commonly sits with the AML/CFT compliance function, often coordinated by the designated compliance officer, with input from risk, legal, and relevant business lines. Because incorporating priorities may involve updates to the enterprise risk assessment, policies, and potentially systems, governance frameworks generally involve senior management or board-level oversight for approval. Precise allocation of responsibility depends on the institution's governance structure and applicable regulatory expectations.
What documentation should an institution maintain to demonstrate it has considered the National Priorities?
Institutions generally maintain records showing how the priorities were assessed against their risk profile, including which priorities were determined relevant, the rationale for those deemed not applicable, and any resulting changes to policies, procedures, or controls. Keeping a clear audit trail supports examiner reviews and demonstrates a risk-based, reasoned approach. The specific form and retention of such documentation should be aligned with applicable recordkeeping requirements, which should be confirmed against the relevant regulation.
How should an institution handle updates or changes to the National Priorities over time?
Because priorities may be reissued or revised periodically, institutions typically build a mechanism to monitor for updates and to reassess their risk assessment and controls when changes occur. This often forms part of the periodic review cycle for the enterprise-wide risk assessment. Where new implementing regulations follow a priority update, institutions may need to revisit program elements to reflect any new binding requirements. The cadence and triggers for such reviews should reflect the institution's risk profile and applicable supervisory expectations.

Common misconceptions

The National Priorities create an immediate, standalone legal obligation that every institution must comply with the moment they are published.
Publication of priorities does not necessarily impose immediate binding requirements. In some regimes the operative obligation to incorporate priorities depends on subsequent implementing regulations, and the timing and scope of that obligation should be confirmed against the applicable rules.
Every obliged entity must address all listed priorities to the same degree.
Priorities are intended to be applied through a risk-based approach. An entity generally incorporates them proportionately to its own risk profile, products, customers, and geographies; those not relevant to a given institution's activities may warrant less emphasis, and this should be documented.
National AML/CFT Priorities are a single global standard applicable everywhere.
There is no single universal instrument. National priorities are issued by individual jurisdictions under their own frameworks, and terminology, legal effect, and content diverge across regimes. FATF standards may inform national approaches but are standards rather than binding law.

Best practices

Confirm the current legal status of the priorities in your jurisdiction, including whether implementing regulations have made incorporation a binding obligation and what the applicable effective dates are, rather than assuming immediate applicability.
Map each published priority against your institution's products, customers, geographies, and delivery channels, and document which priorities are relevant, which are less relevant, and the rationale for that assessment.
Integrate relevant priorities into your enterprise-wide risk assessment and update controls proportionately, treating them as inputs to the risk-based approach rather than as a checklist applied uniformly.
Maintain a clear record of how priorities informed program decisions, so that risk-based judgments can be evidenced to regulators and internal governance.
Distinguish priorities from the underlying national risk assessment and from FATF standards in policy documents, so staff understand the source, legal weight, and scope of each.
Review priorities periodically and upon any republication or issuance of new implementing rules, and align monitoring, screening, and training with the concerns they emphasize while avoiding treating any typology as exhaustive or as proof of wrongdoing.