From Policy to Action: AML/CFT Implications of Executive Order 14406: “Restoring Integrity to America’s Financial System”
What Financial Institutions Can Do in Response to AML/CFT-Related Provisions of Executive Order 14406: “Restoring Integrity to America’s Financial System”
On May 19, 2026, President Trump issued an Executive Order titled “Restoring Integrity to America's Financial System” (the “Executive Order”) that, in part, directs the U.S. Department of the Treasury (the “Treasury”) and certain Federal Functional Regulators (the “FFRs”) to review and strengthen aspects of Anti-Money Laundering/Countering the Financing of Terrorism (“AML/CFT”) requirements in the context of the “risks associated with […] non-work authorized populations and their employers” to the US financial system.
The AML/CFT provisions of the Executive Order include:
- The issuance of a formal Advisory (the “Advisory”), completed on June 5, to identify red flags and typologies of suspicious activity tied to “non-work authorized populations and their employers” (e.g., payroll tax evasion, structuring, and labor trafficking);
- Proposal of amendments (by August 17, 2026) to strengthen risk-based customer due diligence (“CDD”) requirements (the “CDD Rulemaking”), including enhancing collection and verification of customer identity and beneficial ownership information; and,
- Consideration of changes (by November 15, 2026) to strengthen customer identification program (“CIP”) requirements (the “CIP Rulemaking”), including addressing risks associated with foreign consular identification cards.
This article focuses on these AML/CFT-related provisions of the Executive Order, laying out requirements placed on Treasury and the FFRs, considerations for covered Financial Institutions, and how they can act now in response to, or to prepare for, in-scope regulatory actions.
Additionally, this article considers the revised 314(b) Fact Sheet issued by FinCEN on June 12, 2026 (the “314(b) Fact Sheet”) that clarifies the permissibility of information sharing related to fraud between Financial Institutions.
Act Now: FinCEN Advisory related to the unlawful employment of non-work-authorized individuals and employers
On June 5, FinCEN and certain FFRs issued an Advisory to provide guidance on identifying and reporting suspicious activities related to the unlawful employment of non-work-authorized individuals and associated financial schemes used by their employers.
The Advisory emphasizes that while Individual Taxpayer Identification Numbers (“ITINs”) are issued for federal tax purposes to individuals not eligible for a Social Security Number (“SSN”), they do not authorize employment, confer legal status, or serve as identification outside of the tax system. According to the Advisory, the use of an ITIN instead of an SSN or other valid employment authorization to open an account or obtain credit “may be identified as a risk factor requiring enhanced due diligence” as part of existing AML/CFT obligations for risk-based customer due diligence.
The Advisory provides 18 red flags to help Financial Institutions detect potential fraud schemes involving the “unlawful employment of unlawful aliens.” Financial Institutions are reminded that no single red flag is determinative of illicit or suspicious activity, and to consider the surrounding facts and circumstances before determining if a behavior or transaction is suspicious. Notably, most of the red flags focus on either individuals interacting with (i.e., transacting with or working for), or companies operating in the agriculture, construction, domestic service, hospitality, or staffing industries (the “Relevant Industries”).
What Financial Institutions Should Do Now
- Update Program Documentation – Identify relevant policy or procedural documents and update to incorporate new red flags and typologies, as applicable; ensure desktop manuals reflect key term “FINANCIALINTEGRITY-2026-A002”.
- Assess Detections Coverage – Perform targeted coverage assessment to determine whether existing scenarios sufficiently detect activity tied to transactional red flags identified within the Advisory and formally document conclusions and enhancement decisions.
- Distribute Advisory and Execute Targeted Training – Circulate the Advisory across relevant first and second line teams and deliver role-specific training focused on red flags, the Relevant Industries, and technical filing expectations.
- Assess Customer Risk Rating (“CRR”) Methodology – Review CRR attributes to consider customer or transaction-based signals identified within the Advisory, including usage of ITINs and customers operating in the Relevant Industries. Update relevant documentation to ensure CRR attribute ratings align with policy.
- Validate Current Identity Verification Framework – Review identity verification waterfalls to confirm risk-based approach to SSN validation, reflecting red flag related to SSN mismatch/inconsistencies and other available signals.
- Update Information Sharing Procedures – Review and enhance information sharing procedures to reflect the updated 314(b) Fact Sheet and leverage this authority to share fraud-related information identified within the Advisory with other Financial Institutions.
Prepare: Future CDD and CIP Rulemaking
Second, the Executive Order directs the Treasury and appropriate FFRs to propose changes to Bank Secrecy Act (“BSA”) implementing regulations within 90 days to strengthen risk-based CDD, including to:
- Ensure that Financial Institutions collect and verify sufficient customer identity information to reasonably identify nominal and beneficial ownership and assess risks related to illicit finance, sanctions evasions fraud, or other unlawful activity; and
- Ensure that Financial Institutions, as part of a risk-based customer due diligence program, are able to obtain additional information to resolve material compliance concerns, including information relevant to whether account holders possess lawful immigration status and employment authorization in the United States when such information is relevant to assessing risks associated with fraud, identity misrepresentation, sanctions evasion, or other illicit financial activity.
Finally, the Executive Order directs the Treasury and appropriate FFRs to consider changes within 180 days to existing BSA regulations to strengthen risk-based customer identification program (“CIP”) requirements for Financial Institutions, including to account for the risks foreign consular identification cards pose to the integrity of the US financial system.
What Financial Institutions Should Do to Prepare
The exact contours of these forthcoming rulemakings remain undefined; however, Financial Institutions should consider the following actions as prudent steps to prepare based on the Executive Order and subsequent Advisory indicators.
- Socialize and Engage Cross-Functional Stakeholders – Brief senior management and establish a cross-functional working group of financial crimes executives, data and analytics, and legal representatives. Leverage existing governance forms or establish a dedicated routine to monitor updates, including inputs from regulatory change management function.
- Leverage Risk Assessment Processes to Identify Areas of Risk – Recognizing the synergy between the April 7 NPRM (which places the Risk Assessment as the dynamic engine of a Financial Crimes Compliance Program) and potential forthcoming rulemakings, enhance the Risk Assessment (or leverage other risk assessment processes) to consider the risks stated in the Executive Order and Advisory and identify pockets of increased risk across lines of business, products, or customer segments.
- Play it Out – Perform tabletop exercises to identify potential CIP and CDD changes that may require additional customer and/or beneficial ownership information to be collected and verified, and program implications. This exercise should consider those risks referenced in the Executive Order (e.g., “lawful immigration status” or “employment authorization”) but also creatively expand based on demonstrated Trump Administration priorities. Run through end-to-end scenario implications for the collection and verification of lawful immigration status or employment authorization, such as data and tooling needs; operational and procedural challenges to effectively and appropriately integrate sourced data into existing functions and systems; and downstream effects on customer risk rating, policy/risk-appetite, or ongoing monitoring mechanisms.
- Foreign Consular Identification Card Targeted Review – Given the explicit Executive Order verbiage, review existing CIP practices for foreign consular identifications cards, and whether acceptance, verification, and limitation practices are risk-based and aligned with the institution’s risk profile.
- Proactively Define “Material Compliance Concerns” – Clearly define objective, risk-based criteria for when a client would be required to provide “lawful immigration status” or “employment authorization” to resolve “Material Compliance Concerns”. Consult counsel and devise action plans to resolve such concerns in the context of other regulatory obligations, including, for example, state and federal debanking rules which, in general, prohibit denying, cancelling, suspending, or terminating services based on prohibited non-quantitative factors.
Pulling the Thread: Considerations for Covered Financial Institutions
The new Executive Order, FinCEN Advisory, forthcoming rulemakings, and broader AML/CFT modernization efforts represent a complex set of priorities that Financial Institutions must carefully navigate. By incorporating the recent FinCEN Advisory typologies into existing enterprise risk assessment processes, institutions can ensure their current monitoring frameworks remain aligned with evolving regulatory expectations. Financial Institutions should take a proactive approach to prepare for potential CDD and CIP rulemakings. Ultimately, initiating early discussions across compliance, legal, and technology teams will help institutions prepare for potential data and operational challenges down the road, ensuring a smooth path forward as more details emerge.
How KPMG Can Help
KPMG LLP brings deep financial crimes and data capabilities to help institutions strengthen AML/CFT programs, enhance governance, and operationalize risk-based controls in an evolving regulatory environment.
- Assess and enhance financial crimes frameworks – Evaluate and strengthen AML/CFT programs, including customer identification, due diligence, and risk assessment processes to support scalable, risk-based compliance
- Design and implement governance and control frameworks – Establish clear operating models, escalation pathways, and decisioning criteria that align compliance activities with enterprise risk management objectives
- Integrate artificial intelligence into KYC workflows – Deploy AI-enabled solutions to streamline customer onboarding, identity verification, and due diligence processes, improving efficiency while maintaining control effectiveness
- Enable secure, compliant data architecture and governance – Design data governance frameworks supporting collection, classification, validation, lineage, immutable storage, and controlled use of sensitive information, ensuring auditability and regulatory alignment
- Establish a data governance framework – classify and protect highly sensitive customer data with zero-trust access and masking, enforce data sovereignty requirements, maintain immutable lineage and chain of custody logs, and ring-fence usage strictly to AML/CFT compliance for full auditability and regulatory alignment
Meet our team