Key Takeaways
- The post-2008 regulatory response built a banking regulatory training floor rooted in documentation and completion tracking, a model that was adequate for its era but was never designed for the pace of change that followed.
- The Anti-Money Laundering (AML) Act of 2020 shifted the legal standard from technical compliance to program effectiveness, a distinction that federal banking enforcement actions in 2024 and 2025 are actively applying against institutions whose training programs cannot demonstrate it.
- The Federal Financial Institutions Examination Council (FFIEC) Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Examination Manual requires documented training for all appropriate personnel, including board members and senior management, with training materials, testing records, and session dates available for examiner and auditor review.
- The Financial Crimes Enforcement Network’s (FinCEN) April 2026 notice of proposed rulemaking (NPRM) proposes codifying ongoing employee training as a mandatory, risk-calibrated pillar of every anti-money laundering and countering the financing of terrorism (AML/CFT) program, signaling that the informal expectation is becoming a formal standard with an implementation period to follow finalization.
- The institutions positioned best for 2027 are already treating training content, delivery infrastructure, and documentation records as one integrated compliance function, not 3 separate administrative tasks managed in disconnected systems.
The 2024 enforcement actions against Bank of America and multiple community banks cited the same deficiency in different words: training components were inadequate, documentation was incomplete, or the program existed without evidence that it was working. What those actions reveal is not a failure of basic training delivery. Annual programs ran at each institution, required courses were assigned by role, and completion records were produced. What those actions document is the absence of a demonstrable connection between training activity and the specific risk exposures those institutions carried, a connection examiners are now treating as a compliance baseline rather than an aspirational standard.
Over the past decade, banking regulatory training has moved through 3 distinct phases. The post-2008 environment built a compliance training floor rooted in documentation and role coverage. The years that followed added specificity as regulators began distinguishing between training that covered a topic and training that addressed the institution’s own risk profile. The AML Act of 2020 then changed the baseline entirely, shifting the legal standard from technical compliance to program effectiveness. That progression has not stopped, and the next phase of it is already visible in the regulatory record.
FinCEN’s April 2026 NPRM proposes to codify ongoing employee training as a formal, risk-calibrated pillar of every bank’s AML/CFT program, with the comment period having closed in June 2026. What emerges from that rulemaking will shape what examiners expect when they arrive in 2027 and beyond. Understanding the arc of change over the past decade is the prerequisite for positioning ahead of what is coming.
Why Banking Regulatory Training Has Always Been More Than a Checkbox
Banking has never had a light compliance burden. The Bank Secrecy Act and its implementing regulations have embedded training as a core component of BSA compliance programs, and every generation of regulatory expansion since then has added layers to that expectation. Dodd-Frank introduced unfair, deceptive, or abusive acts or practices (UDAAP) obligations in 2010, creating a new training requirement flowing through the Consumer Financial Protection Bureau’s (CFPB) examination authority. The Office of the Comptroller of the Currency’s (OCC) Compliance Management Systems handbook set the examination standard that all bank staff receive timely, periodic, and documented compliance training appropriate to their roles, with more advanced training required for compliance officers, auditors, management, and board members.
What makes banking unusual among regulated industries is that the training obligation is not bounded by a single statute or a single regulator. A community bank simultaneously manages BSA/AML training requirements under FinCEN, fair lending training under the Equal Credit Opportunity Act (ECOA) and the Home Mortgage Disclosure Act (HMDA), consumer protection training for UDAAP, and institution-specific training for its own policies and procedures. Each of those obligations comes with its own examination standard and its own consequence when it falls short. The training function in a bank has never been purely administrative; it has always been the most visible evidence of whether the compliance program functions as designed or simply exists on paper.
What the Post-2008 Era Produced for Banking Compliance Training
The Compliance Training Infrastructure That Emerged From Crisis
The 2008 financial crisis triggered the most concentrated burst of banking regulatory rulemaking in modern history. Dodd-Frank alone runs to 848 pages of statute, and the implementing regulations that followed built out across several years. The compliance training infrastructure that emerged from that period reflected the priorities of the moment: coverage and documentation. Banks built programs designed to demonstrate that every employee in a regulated role had received training on every relevant topic, with completion records to prove it.
That was the right response to the environment. Regulators in the early 2010s were primarily asking whether training programs existed, whether they covered the required subjects, and whether banks could produce evidence of who had completed what. The OCC’s examination framework set the bar at timely, periodic, and documented training, with all 3 criteria pointing toward a completion-tracking model. Learning management system (LMS) platforms proliferated across banking compliance as a direct operational response to that expectation. Annual training cycles became the norm because annual cycles produced clean completion reports that satisfied examiner requests efficiently.
What the Completion Model Achieved and Where It Left a Gap
The completion model succeeded at what it set out to do. Banks developed formal training programs, hired compliance training coordinators, and built the documentation infrastructure examiners expected to see during that era. What the model did not address was the connection between training activity and outcomes: whether the training changed what employees did, whether it reached the right people at the right time relative to the institution’s evolving risk profile, and whether corrective training assigned after an internal finding could be traced back to the incident that generated it. For the first decade post-crisis, that gap was tolerable because the primary examination question was whether banks had programs at all. That is no longer the question regulators are asking.
How the Post-2020 Regulatory Period Rewrote the Expectations
The AML Act of 2020 and the Shift to Program Effectiveness
The Anti-Money Laundering Act of 2020, enacted as Division F of the National Defense Authorization Act for FY2021, changed the legal foundation of what a BSA compliance program must be. The statute amended the Bank Secrecy Act to require that AML programs be effective rather than merely technically compliant. That single word carried significant implications for training. A training completion report demonstrates technical compliance. An effective program demonstrates that training produced the behavioral change it was designed to produce, reached the personnel whose job functions create the institution’s specific risk exposure, and was updated when the risk profile changed. The 2020 statute did not define how banks must prove effectiveness; it placed the burden of demonstrating that standard on the institution itself.
The FFIEC BSA/AML Examination Manual formalizes what examiners evaluate when they assess a bank’s training program. Banks must provide training for all personnel whose duties require BSA/AML knowledge. The manual requires documentation of training materials, testing materials where applicable, and the dates of training sessions, all available for examiner and auditor review on request. The board of directors and senior management must receive training and be kept informed of changes and new developments in BSA requirements. That board-level requirement is where many institutions underinvest, and where examiners found consistent gaps in the enforcement actions of 2024 and 2025.
How Remote Delivery and Hybrid Work Changed the Execution Challenge
The shift to remote and hybrid work environments beginning in 2020 created a delivery challenge that most banking compliance training programs were not designed for. Annual in-person sessions, still standard at many community banks as recently as 2019, became operationally unavailable almost overnight. Banks that had built their compliance training model around scheduled group sessions had to transition rapidly to asynchronous digital delivery, frequently without the LMS infrastructure or the training library to support it at the required depth.
That transition exposed a gap that the completion-tracking model had obscured. Having a training library and having training content calibrated to the institution’s specific risk profile are not the same thing. Generic BSA/AML courses available off the shelf cover regulatory requirements. They do not cover the institution’s own policies, the specific transaction patterns the bank has identified as elevated risk, or the customer populations the bank serves. The FFIEC examination manual requires training to cover the bank’s own policies, procedures, and processes alongside the regulation. Institutions that relied exclusively on off-the-shelf content during the transition to remote delivery found that requirement considerably harder to satisfy when examiners reviewed the curriculum in detail.
What Examiners Are Looking For in Banking Regulatory Training Programs
The 3 Questions Behind Every Training Review
The OCC’s December 2024 enforcement action against Bank of America, along with other federal banking enforcement actions against community banks through 2024 and 2025, cited training deficiencies as contributing factors in BSA/AML program failures. Each institution had a training program. What those actions document is the absence of a demonstrable connection between the training delivered and the risk profile the institution carried: documented evidence that training reached the right personnel in the right timeframes, and a record that allowed examiners to trace completion back to the specific compliance obligations it was meant to address.
The 3 questions that frame every examiner training review are whether the right people received training, whether the training content matched the institution’s actual risk profile, and whether the institution can demonstrate both of those things at the moment of examination. The third question is where training documentation becomes an active compliance asset rather than a passive record-keeping obligation. An institution that can answer all 3 questions within hours of an examiner’s request is positioned very differently from one that begins assembling records after the examination team walks in the door.
What OCC Bulletin 2025-37 Changed for Community Bank Examinations
OCC Bulletin 2025-37, effective February 1, 2026, established specialized BSA/AML examination procedures for community banks with up to $30 billion in assets. Training is a named pillar of the community bank examination framework. For institutions with a satisfactory prior examination conclusion on the training pillar and no significant change in risk profile, examiners may carry forward that conclusion rather than conducting a full re-examination of the training program. That carryover provision rewards institutions that maintain consistent, well-documented training programs, converting a strong training record into reduced examination burden in subsequent cycles. Institutions that have allowed documentation gaps to accumulate between examination cycles forfeit that benefit.
What 2027 Will Demand From Banking Training Programs
The FinCEN NPRM and the Coming Codification of Training Standards
FinCEN’s April 2026 NPRM proposes to codify ongoing employee training as a formal pillar of AML/CFT program requirements. The proposed rule would require training content and frequency to be calibrated to the institution’s risk profile and to the specific roles of the personnel being trained. That represents a substantial upgrade from the current framework, which requires training to exist and be documented but does not specify how it must be designed in relation to actual risk exposure. With the comment period closed in June 2026 and an implementation period to follow finalization, institutions should not expect the standard to arrive before 2027, and should not expect it to arrive with time to spare either.
What the NPRM signals is more consequential than its timeline. FinCEN is moving toward a standard in which a training program must demonstrate risk calibration, meaning that the content delivered to a teller, a lending officer, a compliance coordinator, and a board member differs in complexity and in its direct connection to the specific risk exposures each role creates. Generic annual training delivered uniformly to all staff will not satisfy a risk-calibrated standard. Institutions waiting for a final rule before redesigning their training programs will begin 2027 already behind the implementation curve.
The institutions that perform best in 2027 examinations will be the ones treating training as a risk management function today, not as a completion metric they will recalibrate once the rule is final.
The Section 1071 Timeline and Cross-Functional Training Demands
The CFPB’s Section 1071 small business lending rule introduces a separate banking regulatory training obligation on a parallel track. A May 1, 2026 CFPB final rule replaced the previous tiered compliance structure with a single unified compliance date of January 1, 2028 for all covered institutions. The rule requires institutions to collect and report specific data on small business loan applications, which means personnel involved in small business lending decisions must be trained on the new data collection requirements, a new subject area requiring new course content in most institutions’ existing programs. Chief Learning Officers (CLOs) managing compliance training at mid-size banking organizations will be managing simultaneous demands from the BSA/AML training redesign and the Section 1071 data collection rollout, alongside standing UDAAP, fair lending, and institution-specific training obligations that have not receded.
How Content, Delivery, and Records Work as One System
The Integration Gap That Enforcement Actions Make Visible
The pattern running through 2024 enforcement actions is an integration gap. Training content exists in one system, training completion records in another, and the institution’s risk assessment in a third. When an examiner requests evidence that training addressed a specific risk exposure for a specific employee population within a defined timeframe, an institution with disconnected systems must reconstruct that evidence manually from records never designed to talk to each other. Manual reconstruction under examination pressure is where gaps surface and where examiner characterizations of program adequacy begin to take shape. An institution that responds to a documentation request by assembling records it should have been maintaining in organized, accessible form is communicating a structural gap that examiners will note alongside any substantive finding.
The institutions that have resolved this gap share a common operational architecture. Training content is connected to the institution’s risk assessment process, ensuring that shifts in the risk profile trigger curriculum updates systematically rather than through a manual coordination cycle. Delivery infrastructure assigns training by role, tracks completion at the individual level, and generates the documentation the FFIEC examination manual requires. Records are accessible at the moment of an examination request, not assembled in the days that follow.
- Risk-linked content assignment that updates training curricula when the institution’s BSA/AML risk assessment identifies new or elevated risk areas, connecting the risk management cycle directly to the training calendar without requiring manual coordination between the compliance and training functions
- Role-based delivery that distinguishes training content by function, with separate curricula for tellers, lending officers, compliance officers, senior management, and board members, each tied to the specific regulatory obligations and risk exposures of that role rather than to a single institution-wide course catalog
- Documentation architecture that maintains training materials, completion records, and session dates in a format accessible to examiners and auditors on demand, satisfying the FFIEC requirement without requiring manual record assembly at the time of examination
Building the Records Layer Examiners Will Evaluate
The FFIEC BSA/AML Examination Manual names 3 documentation elements examiners review: training materials, testing materials where applicable, and dates of training sessions. What the manual describes is an audit trail encompassing what was taught, how comprehension was assessed, and the dates of each session for each employee in the relevant population. An institution that maintains those 3 elements in a searchable, role-organized format can respond to examination requests within hours. An institution assembling those records after the fact is demonstrating a documentation architecture that was not built to support the examination it is now facing, and examiners draw conclusions from that gap.
The role-based scope of that records layer varies by position, since what the FFIEC manual requires the board to retain differs from what it requires for customer-facing staff:
| Role Group | Training Scope Required | Documentation Standard |
|---|---|---|
| Board of Directors | BSA requirements, supervisory guidance, new regulatory developments | Session dates, materials provided, attendance records |
| Senior Management | BSA requirements, institution risk profile, program changes | Session dates, materials, evidence of review |
| BSA / Compliance Officers | Full regulatory curriculum, internal policies, risk assessment process | Completion records, testing materials, dates |
| Customer-Facing Staff (Tellers, Lenders, Customer Service Representatives) | Transaction monitoring indicators, suspicious activity report (SAR) filing awareness, customer due diligence (CDD) requirements | Completion records, role-specific curriculum, dates |
| Operations and Back-Office Staff | BSA policies relevant to job function, internal procedures | Completion records, applicable policy versions, dates |
The Signals Banking Compliance Leaders Should Watch
The Regulatory Horizon Between Now and 2027
3 signals beyond the FinCEN AML/CFT program rule and Section 1071 merit attention for banking compliance leaders building training programs with a 2027 time horizon. The first is the FFIEC’s February 2026 update to the BSA/AML Examination Manual, which revised several sections to remove references to reputational risk, consistent with Executive Order 14331 of August 7, 2025. That revision reflects a live policy direction; the examination framework is actively being updated, and training content calibrated to examiner expectations must stay current with each revision. An institution whose training materials reference examination criteria that have since been revised is presenting outdated content as current compliance guidance.
The second signal is the OCC and Federal Deposit Insurance Corporation’s (FDIC) proposed restriction on when matters requiring attention (MRAs) may be issued, limiting formal findings to practices that materially harm financial condition or constitute actual violations of law or regulation. That change, if finalized, reduces examination pressure for minor documentation issues while leaving the substantive standard unchanged. Effective, risk-calibrated, documented training remains the baseline. The institutions that built their programs to meet the stricter standard before the restriction takes effect will not need to recalibrate when it does.
Why the 2024 Enforcement Cycle Points Toward 2027
The accumulation of training-related enforcement actions in 2024 and 2025 is the third signal. Bank of America and the community banks cited in those findings each had training deficiencies named in enforcement actions against BSA/AML programs that were otherwise operational. Each institution had a program in place. Examiners applied a closer evaluation of whether training connected to the institution’s actual risk profile and found that it did not hold up under that standard. That examiner posture is a leading indicator of what a risk-calibrated training rule will formalize. Compliance leaders who read the 2024 enforcement cycle as a signal are positioning their programs differently from those who read it as an outlier.
How Banking Regulatory Training Programs Will Define the Next Decade
The decade between 2008 and today produced a compliance training infrastructure that did what it was designed to do. It documented coverage, demonstrated role-appropriate training delivery, and gave examiners what they were asking for at each examination cycle. The next decade will ask for something harder: evidence that training is a functioning risk management mechanism, calibrated to the institution’s actual exposure, delivered in a way that reaches the right people, and documented in a format that survives examination scrutiny without manual reconstruction in the days before an examiner’s findings are issued.
The gap between those two standards has grown from architectural causes rather than any shortage of training content. Banking compliance teams have more course content available today than at any point in the past decade. Institutions whose training content, delivery infrastructure, and documentation records operate as independent administrative processes will find themselves manually bridging those disconnects at each examination cycle, assembling connections that a unified architecture would produce automatically. Institutions that have already integrated those 3 functions are building the compliance training program the next decade of examination will require.
FinCEN’s 2026 NPRM, the Section 1071 compliance timeline, OCC Bulletin 2025-37, and the enforcement actions of 2024 are pointing in the same direction. The banking regulatory training programs that will perform best in 2028 and beyond are already being built today by compliance leaders who recognize that the examination standard has already moved ahead of the formal regulation and have chosen to meet it before a final rule arrives.
Frequently Asked Questions
1. What does the FFIEC BSA/AML Examination Manual require for bank training programs?
The FFIEC BSA/AML Examination Manual requires banks to provide training for personnel whose duties require BSA/AML knowledge. Training must cover BSA regulatory requirements, applicable supervisory guidance, and the bank’s own internal policies, procedures, and processes. Banks must maintain documentation of training materials, testing materials where applicable, and the dates of training sessions, all available for examiner and auditor review. Board members and senior management must also receive training and be kept informed of changes and new developments in BSA requirements. The manual was most recently updated in February 2026.
2. What did the AML Act of 2020 change about banking compliance training requirements?
The AML Act of 2020 amended the Bank Secrecy Act to require that AML/CFT programs be effective rather than merely technically compliant. This shifted the evaluation standard from documenting that training occurred to demonstrating that training produced meaningful outcomes and reached personnel based on their actual risk exposure. The effectiveness standard has become the primary reference point in federal banking enforcement actions citing training deficiencies, most prominently in the OCC’s December 2024 action against Bank of America and in BSA/AML examination findings against multiple community banks.
3. What is FinCEN’s April 2026 NPRM proposing for banking training programs?
FinCEN’s April 2026 NPRM proposes to codify ongoing employee training as a formal pillar of AML/CFT program requirements across covered financial institutions. The proposed rule would require training content and frequency to be calibrated to the institution’s risk profile and to the specific roles of the personnel being trained, so that a teller’s training curriculum differs from a compliance officer’s based on their respective risk exposures. The comment period closed in June 2026, and an implementation period will follow finalization. Institutions that begin redesigning training programs before the rule is final will be better positioned to implement within the compliance window.
4. How does OCC Bulletin 2025-37 affect community bank compliance training examinations?
OCC Bulletin 2025-37, effective February 1, 2026, established specialized BSA/AML examination procedures for community banks with up to $30 billion in assets. Training is a named examination pillar. For institutions with a satisfactory prior examination conclusion on the training pillar and no significant change in risk profile, examiners may carry that conclusion forward rather than conducting a full re-examination of the training program. This provision reduces examination burden for institutions with consistently strong training documentation and converts a well-maintained training record into a measurable operational benefit in subsequent examination cycles.
5. What training obligations does the CFPB Section 1071 rule create for banking compliance programs?
The CFPB Section 1071 small business lending rule requires institutions to collect and report specific data on small business loan applications, and personnel involved in small business lending must be trained on the new data collection requirements. A May 1, 2026 CFPB final rule replaced the previous tiered compliance structure with a single unified compliance date of January 1, 2028 for all covered institutions. For CLOs at mid-size banking institutions, the Section 1071 training requirement arrives during the same period as the anticipated FinCEN AML/CFT program rule redesign, requiring simultaneous management of two major curriculum changes alongside standing compliance training obligations.
6. How does KnowledgeCity support banking regulatory training programs?
KC Library carries compliance and finance training content, including regulatory compliance, fraud prevention, and retail banking course categories, in multiple languages. KC LMS delivers that content through a rule-based compliance and assignment engine that assigns training by role, tracks completion at the individual level, and maintains an audit-ready trail of materials, completions, and dates, the documentation elements the FFIEC examination manual names. Because content, delivery, and records run on one platform with a single reporting layer, a compliance officer can respond to an examiner’s training documentation request from one system rather than reconstructing evidence across three.
References
- Federal Financial Institutions Examination Council. BSA/AML Examination Manual, updated February 2026.
- Financial Crimes Enforcement Network. Anti-Money Laundering and Countering the Financing of Terrorism Programs, NPRM, Federal Register 2026-07033, April 10, 2026.
- Office of the Comptroller of the Currency. Compliance Management Systems, Comptroller’s Handbook, June 2018.
- Office of the Comptroller of the Currency. OCC Bulletin 2025-37: Community Bank Minimum BSA/AML Examination Procedures.
- Consumer Financial Protection Bureau. Small Business Lending Under the Equal Credit Opportunity Act (Regulation B), final rule, May 1, 2026.
- Office of the Comptroller of the Currency. NR-OCC-2024-140: OCC Issues Cease and Desist Order Against Bank of America for BSA Deficiencies, December 23, 2024.
- Office of the Comptroller of the Currency. OCC Bulletin 2025-29: Defining “Unsafe or Unsound Practice” and Revising the Framework for Issuing Matters Requiring Attention, interagency NPRM.
- Financial Crimes Enforcement Network. Anti-Money Laundering Act of 2020 Overview.



