Read this if you are a chief compliance officer or an AML/CFT officer at a community bank, credit union, or broker-dealer firm.
The US Department of the Treasury’s 2026 National Money Laundering Risk Assessment (NMLRA), which was issued in March 2026, provides a comprehensive look at the most significant illicit finance threats facing the US financial system. While the report spans the entire economy, several themes are particularly relevant for community banks, credit unions, and broker-dealers—all of which remain critical entry points and transit nodes for illicit funds.
Why this matters for banks and broker-dealers
The Treasury report confirms that the core money laundering threats—fraud, drug trafficking, cybercrime, human trafficking, corruption, and professional money laundering networks—have not changed. What has changed is scale and velocity.
Criminals are generating larger proceeds more quickly by:
- Leveraging digital channels, social media, and encrypted communications
- Using artificial intelligence (AI) to create synthetic identities, deepfakes, and believable scam communications
- Moving funds rapidly across banks, broker‑dealers, money services businesses (MSBs), and digital asset platforms
For smaller institutions and broker‑dealers with limited compliance resources, this evolution increases both operational risk and regulatory exposure.
Fraud risks facing banks and broker-dealers
The NMLRA identifies fraud—not drug trafficking—as the largest source of illicit proceeds entering the US financial system. The most common suspicious activity includes:
- Investment fraud
- Business email compromise
- Confidence scams
- Elder financial exploitation
- Digital asset‑related scams
Key implications:
- Community banks and credit unions are frequently used as deposit and transit accounts for fraud proceeds, often involving unwitting account holders or money mules (people who collect or receive illicit proceeds and then transport, transfer, or convert the funds on behalf of another person or organization).
- Broker‑dealers face rising exposure to:
- Ramp‑and‑dump (a market-manipulation scheme where bad actors artificially “ramp” up a stock’s price/volume—often via deceptive promotion—then sell into the spike, leaving other investors with losses) and pump‑and‑dump (similar manipulation: promoters “pump” a stock with misleading hype, then “dump” their shares at inflated prices) securities schemes
- Foreign‑based investment clubs operating via social media
- Omnibus and correspondent-style accounts masking beneficial ownership
Regulators are increasingly focused not just on transaction monitoring failures, but on whether firms understand how modern scams operate and have controls aligned to current typologies.
Digital assets and stablecoins: No longer peripheral
Although the report notes that most laundering still occurs through fiat channels, digital assets—especially stablecoins—play a growing role across fraud, ransomware, sanctions evasion, and drug trafficking.
For community banks and broker‑dealers, the takeaway is not limited to crypto custody or trading:
- Fraud proceeds are often converted into stablecoins after passing through traditional deposit accounts.
- Digital asset kiosks, over-the-counter (OTC) brokers, and foreign exchanges are frequently downstream of US institutions.
- Even firms that do not directly offer digital asset products may still be the first regulated touchpoint in the laundering chain.
Institutions are expected to recognize digital asset exposure through customer behavior, not just through product offerings.
Regulatory expectations are increasingly risk‑based—and personal
The assessment highlights that most anti-money laundering (AML) enforcement actions in recent years stem from:
- Weak internal controls
- Inadequate customer due diligence
- Insufficient authority, independence, or resourcing of the BSA (Bank Secrecy Act)/AML officer
- Failure to reassess risk as products, technologies, or customer behavior change
Notably, enforcement actions and SEC/FINRA cases against broker‑dealers emphasize individual accountability, including AML and compliance officers.
What regulators are signaling:
- “Check‑the‑box” AML programs are no longer sufficient
- Firms must demonstrate active understanding of emerging risks
- Boards and senior management are expected to own AML risk, not delegate it entirely
Community institutions face unique pressure points
The Treasury report recognizes that most US banks and credit unions are small institutions, often operating with lean compliance teams while facing the same threat environment as large, global firms.
Common vulnerabilities include:
- Rapid customer onboarding driven by competition and fintech pressures
- Mergers or core conversions that disrupt customer risk profiles
- Third‑party and fintech relationships that blur AML accountability
- Overreliance on vendors without sufficient internal challenge or oversight
At the same time, Treasury explicitly acknowledges the need to avoid excessive compliance burden, reinforcing that risk‑based tailoring—not volume of suspicious activity reports (SARs)—is the benchmark.
How community banks, credit unions, and broker-dealers can stay ahead
The 2026 National Money Laundering Risk Assessment reinforces a central message: Illicit finance risk is no longer confined to niche products or large institutions.
Community banks, credit unions, and broker‑dealers sit at critical points in the financial ecosystem. Institutions that proactively align their AML programs to modern fraud typologies, digital behaviors, and evolving regulatory expectations will be best positioned to manage risk without incurring unnecessary burden.
Practical takeaways for financial institutions and broker-dealers
- Refresh fraud risk assessments: This is especially important for elder customers, peer-to-peer (P2P) payments, wire activity, and investment‑related referrals.
- Revisit customer due diligence: Focus on beneficial ownership, nominee activity, and unexplained changes in behavior.
- Assess stress‑test controls around money mule activity: Funnel accounts, rapid movement of funds, and pass‑through behavior remain top red flags.
- Evaluate digital asset exposure—even indirectly: Consider how customers interact with exchanges, kiosks, or stablecoins outside the institution.
- Ensure BSA/AML governance is board‑engaged: Regulators increasingly expect documented oversight and challenge from senior leadership.
BerryDunn can help
Our risk management team helps clients develop and implement effective risk management programs tailored to each organization’s size, risk level, and resources. If you have questions, please reach out to your BerryDunn financial institutions and broker-dealers teams.