Use Your Tools
What are the priorities that will drive your risk decisions?
I wrote last May that the priorities of the second Trump administration are different, from Biden’s term in office—that the new administration pivoted from massive sanctions against Russia, even as Moscow continued targeting civilians in Ukraine, to Iran, its terrorist proxies, and drug cartels. If you look at Treasury’s Press Release page, you mainly will see new terrorism, Iran, and cartel/counternarcotics designations. There have been almost no designations pursuant to Executive Order (EO) 14024—the Russia Harmful Foreign Activities Sanctions—since President Trump took office on January 20, 2025. The only exception was the SDN designation of Rosneft and Lukoil—Russia’s two largest oil producers and their named subsidiaries (36 designations altogether)—last October.
However, since the second Trump term began, we have seen multiple guidances dealing with Latin American cartels and individuals in the United States illegally, numerous designations related to Iran (counterterrorism and counterproliferation), and the designation of several drug cartels as foreign terrorist organizations (FTOs), meaning that US entities that transact with businesses that are owned by these cartels risk being charged with providing material support to terrorist groups.
So the shift in priorities is clear and visible, and smart firms and financial institutions must not only monitor new designations, but also engage in some forecasting based on current news reports, policymaker speeches, new designations, and regulator guidance.
Risk-based approach
Regulators and standard-setters are increasingly focused on banks and financial institutions taking a risk-based approach to financial crimes.
FinCEN in April proposed to fundamentally reform AML/CFT programs for banks and financial institutions.
The Financial Action Task Force (FATF) in its recent ministerial also pledged to strengthen a risk-based approach to implementing FATF standards.
The US Office of the Comptroller of the Currency (OCC) this year updated its Bank Secrecy Act and Anti-Money Laundering (BSA/AML) examination procedures for community banks streamlining supervisory reviews and reflecting a more proportionate approach to assessments of smaller financial institutions.
The Federal Reserve has proposed changes, setting a higher threshold (failures must be “significant or systemic” to trigger enforcement action) for bank BSA/AML deficiencies.
Every bank and every financial institution has a different risk appetite, so every approach will differ. That said, monitoring regulatory developments, understanding administration priorities, and delving into evolving illicit finance methodologies will help banks and financial institutions craft an appropriate risk assessment and inform risk decisions.
Keeping track of everything
As I wrote previously, published regulator guidance, designations, and National Priorities can provide a good roadmap to a robust AML compliance program. FinCEN’s list of national priorities was last published in 2021 and has not been updated since then. The list of eight includes: (1) corruption, (2) cybercrime, (3) foreign and domestic terrorist financing, (4) fraud, (5) transnational organized crime, (6) drug trafficking, (7) proliferation financing, and (8) human trafficking and smuggling.
But when everything is a priority, nothing is a priority, so tracking regulatory developments and administration statements is also critical to determining risk.
Track leadership speeches, such as a statement by Treasury Secretary Scott Bessent, who outright confirmed that although sanctions on Russia had been a major focus for the Biden administration, the Trump Administration refrained from sanctioning new Russian entities while working to end Russia’s full-scale invasion of Ukraine.
What world events will impact compliance? In March, OFAC offered significant sanctions relief to the Russian energy sector to mitigate the increase in oil prices following the US military action in Iran. Did financial institutions involved in the energy trade take advantage of the temporary waiver? These transactions were still risky, given that they involve Russia and EO 14114 imposes secondary sanctions risk on foreign financial institutions that transact with Russia’s military-industrial sector. And since everyone and everything sanctioned under EO 14024 is considered part of Russia’s military-industrial sector because Moscow pivoted to a full wartime economy, would financial institutions take that risk?
Syria also saw some sanctions relief, but it’s a country that is located in close proximity to terrorist hubs and continues to pose a high risk of terrorist financing. Should banks and financial institutions start slowly incorporating transactions with Syria? Maybe, but enhanced due diligence is needed.
Examine OFAC sanctions patterns. These designations are a real-time signal of national security/AML priorities. Currently we’re seeing a heavy emphasis on cartels, counternarcotics, Southeast Asia scam networks, and Iran's shadow banking networks.
Read national risk assessments published by the US Treasury. Read developments in illicit finance methodologies. Recent reporting from Bloomberg highlighted a Russian disinformation project that is more advanced and sophisticated than we’ve seen in a while. Project 2026 seeks to build an entire “alternative ecosystem” to thwart research efforts and spread Russia’s malign influence.
Internal planning documents detail Russian efforts to build websites controlled by the Kremlin, clone real websites and think tanks a la Operation Doppelgänger, and then capture search traffic and influence and train AI chatbots to cite these fake websites to spread disinformation and thwart research efforts.
Tracking these innovative and sophisticated disinformation and evasion methods is critical to mitigating risk, especially when AI is increasingly used to build complex ownership and control webs with numerous layers that would have been incredibly difficult to create manually.

Use your tools
Google searches are no longer enough. They can be clunky and insufficient. Search strings focused on your organization’s risk can be unwieldy and lengthy and produce so much data, that your analysts will spend hours, if not days, examining the search results. A professional organization will use OSINT platforms that can pull tax records, identify risky jurisdictions, provide tax ID numbers of beneficial owners, generate link analysis that will help determine how close your entity is to an illicit actor, and generate adverse media reports. These tools can wrap up all the needed information into a nice package with a bow on top and help you determine whether transactions with any given person or entity is within your organization’s risk appetite based on the data they scrape.
These tools can also flag regulatory developments, help you identify patterns in sanctions designations, and help you determine what’s on the horizon, informing the decision about whether to transact with a specific individual or entity.
The information can help you identify regulatory priorities and determine whether a specific transaction is within your risk appetite.
Tools support the decisionmaking process. Use them.


