To safeguard the global financial system, the Bank Secrecy Act holds financial institutions to certain recordkeeping and reporting requirements in order to assist government agencies in detecting and preventing financial crime, such as anti-money laundering and counter-terrorist financing.
Under this framework, AML/CFT regulations require every bank to maintain a formal compliance program designed to stop the processing of illicit funds. This program is built around five core pillars: internal controls, a designated compliance officer, ongoing staff training, independent audits and customer due diligence.
Making AML Work Better: From Paperwork to Outcomes
Because the national security stakes are high, compliance resources need to be deployed strategically. But the current system is highly inefficient.
Banks are supervised by a split regime: FinCEN sets national financial intelligence priorities, while front-line exams are run by the prudential banking regulators: the Office of the Comptroller of the Currency, the Federal Reserve and the Federal Deposit Insurance Corporation. In practice, examiners often focus on documentation perfection, such as penalizing minor administrative errors, rather than evaluating whether banks are actually catching criminals. The result is that compliance teams spend finite resources on defensive paperwork instead of hunting down and safeguarding against complex criminal networks.
As BPI’s General Counsel, John Court testified before Congress, real modernization means shifting from checklist compliance to a risk-based system that rewards high-value investigative outcomes.
Extending AML to the Full Financial System
While banks employ tens of thousands of people to monitor transactions, file Suspicious Activity Reports and verify customer identities, large parts of the crypto ecosystem operate without those obligations.
For AML to work, it must cover the entire financial system. Unhosted wallets, privacy mixers and cross-chain bridges have become preferred tools for transnational criminal networks and hostile state actors, including Iran and North Korea, precisely because they currently operate outside the regulatory perimeter that covers banks and other financial institutions. Read more about crypto and AML here.

The Path Forward: Outcomes-Based Modernization
AML regulation exists to deny hostile actors access to capital — not to generate flawless paperwork. Getting there requires two things: reorienting bank examinations around outcomes and effectiveness rather than documentation, and extending meaningful AML obligations to digital asset service providers operating in U.S. markets.
Same risks = same rules = same regulation.
Watch John Court’s opening statement below to hear the case made directly to the House Financial Services Committee.

