For those of us who experienced September 11 firsthand, that day brought profound and lasting changes to our daily lives—most painfully for those who lost a loved one, friend, or colleague. In its aftermath, Congress acted with extraordinary speed, passing the USA PATRIOT Act just 45 days later. Among its many consequences, the Act fundamentally expanded the role of financial institutions in protecting the United States.
The Bank Secrecy Act (BSA) of 1970 already required financial institutions to maintain records and report certain transactions, while subsequent regulations introduced suspicious activity reporting. The PATRIOT Act went further: It explicitly linked the fight against money laundering and terrorist financing to national security, formalized customer identification requirements, and made financial institutions a more direct part of the country’s detection and information-sharing network.
In doing so, it helped establish the foundation for the modern Know Your Customer (KYC) process and today’s broader financial crime compliance framework.
Key takeaways
- The PATRIOT Act turned customer identification into a national-security function, converting varied bank practices into defined obligations under Title III.
- Its greatest achievement was visibility: Financial data became durable intelligence used well beyond terrorism cases.
- Identity is necessary but not sufficient: Intent shows up in behavior and networks, not identity documents.
- A final rule in August 2026 permanently exempts U.S. companies and U.S. persons from federal beneficial-ownership reporting, leaving financial institutions as the primary source of ownership data.
- Five pending FinCEN rulemakings point two ways at once — simplification for banks, expansion to investment advisers and stablecoin issuers.
- The supervisory question is shifting from “Was every step completed?” to “Was the program reasonably designed and effective?”
How the PATRIOT Act changed KYC and AML
Before 9/11, customer identification practices varied across institutions. Title III of the PATRIOT Act turned many of those practices into defined obligations.
Section 326 required financial institutions to establish Customer Identification Programs, including procedures to obtain and verify identifying information when an account is opened. Section 352 required firms to establish anti-money laundering (AML) programs built around internal controls, a designated compliance officer, training and independent testing. These requirements became an important foundation for modern Anti-Money Laundering compliance programs.
Other provisions addressed cross-border risk. Sections 311 and 312 introduced special measures and enhanced due diligence for higher-risk foreign relationships. Section 313 prohibited U.S. correspondent accounts for foreign shell banks. Section 314 created mechanisms for law enforcement and financial institutions to share information about suspected money laundering and terrorist activity.
The result was a new operating model. Financial institutions needed repeatable processes to identify customers, understand ownership and control, assess risk, monitor activity, investigate anomalies and demonstrate that their controls were working. Over time, KYC grew from an account-opening check into a lifecycle covering onboarding, KYC risk assessment, ongoing monitoring, review, investigation and reporting.
What did the framework accomplish?
Its greatest achievement was visibility. Financial information became far more usable as intelligence.
The 9/11 Commission’s terrorist-financing study found that agencies had not systematically assembled and analyzed the information they held, while investigators struggled to obtain records across organizational and national boundaries. After 9/11, financial intelligence became a sustained counterterrorism capability.
For example, under Section 314(a), the Financial Crimes Enforcement Network (FinCEN) can ask financial institutions nationwide to identify accounts or recent transactions connected to investigative subjects.
The wider BSA reporting system has also supported cases far beyond terrorism. The Government Accountability Office (GAO) found that, among federal law-enforcement personnel who used BSA reports from 2015 through 2018, 93% had used relevant reports at least occasionally to confirm information about a subject and 78% had found them relevant to identifying assets for possible forfeiture or restitution.
But the system accumulated complexity and cost. Institutions built large teams, fragmented technology estates and extensive control frameworks. False positives, duplicative reviews, manual document handling and limited feedback from law enforcement continue to consume investigative capacity. In 2024, the GAO found that fragmented federal data made it difficult to measure government-wide outcomes from illicit-finance investigations.
The attacks themselves offer a deeper lesson. The 9/11 plot reportedly cost approximately $400,000 to $500,000—modest compared with many money-laundering schemes. Identity verification is essential, but identity alone does not reveal intent. Effective detection requires customer, ownership, behavioral, network and external intelligence to be connected over time.
Modernization—and five more potential changes
FinCEN’s 2016 Customer Due Diligence (CDD) Rule expanded the framework to include beneficial ownership, customer risk profiles and ongoing monitoring. The Anti-Money Laundering Act of 2020 then emphasized national priorities, information sharing, technology and effectiveness. Its Corporate Transparency Act sought to reduce shell-company anonymity, but an August 2026 final rule permanently exempted U.S.-created companies and U.S. persons from federal beneficial-ownership reporting.
For financial institutions, these changes impacted how beneficial ownership reporting fits into the KYC process. Institutions still need reliable ownership information to understand who ultimately owns or controls a customer, and they cannot assume that a government database will provide every answer.
The next stage is taking shape through five FinCEN rulemakings. Importantly, these are not five completed final rules. As of September 2026, some remain proposed and others are scheduled for new proposals, so their requirements may change. If finalized substantially as contemplated, however, they could alter both the reach and philosophy of U.S. KYC and AML:
- CDD revisions (RIN 1506-AB60) could move beneficial-ownership collection away from repetitive, account-by-account exercises toward customer-level, risk- and event-based updates. FinCEN regulations have already relieved institutions from reverifying owners whenever an existing legal-entity customer opens another account. But because domestic companies are now outside federal beneficial ownership information reporting, financial institutions will likely remain a primary source of ownership information rather than relying on a comprehensive government database.
- Investment-adviser customer identification program (CIP) requirements (RIN 1506-AB66) would extend formal identity-verification duties to registered investment advisers and exempt reporting advisers. Combined with the investment-adviser AML rule—now postponed until January 1, 2028—the change could bring customer identification, AML programs and suspicious-activity reporting into a more coherent framework for private funds and advisory relationships.
- The Anti-Money Laundering/Countering the Financing of Terrorism (AML/CFT) Program Rule (RIN 1506-AB72) may have the broadest impact. FinCEN’s proposal would require documented risk assessments, consideration of national AML/CFT priorities and greater allocation of resources to higher-risk activity. It would distinguish weaknesses in program design from failures in execution and focus significant supervisory action on serious or systemic failures. If retained, the regulatory question could begin shifting from “Was every prescribed step completed?” to “Was the program reasonably designed, implemented and effective?”
- Stablecoin AML/CFT and sanctions requirements (RIN 1506-AB73) would treat permitted payment stablecoin issuers as financial institutions under the BSA. Proposed obligations include risk assessments, ongoing CDD, suspicious-activity reporting, recordkeeping, information sharing and the technical ability to block, freeze or reject impermissible transactions.
- A separate stablecoin CIP rule (RIN 1506-AB74) would require issuers to identify and verify customers, retain records, check designated government lists and address failed verification. Its central challenge will be applying meaningful identity controls to an ecosystem in which wallets, platforms, issuers and end users do not always have traditional account relationships.
Collectively, these rules point in two directions: simplification and expansion. Traditional institutions may receive more discretion to eliminate duplicative, low-value work and concentrate on genuine risk. At the same time, investment advisers and stablecoin issuers would be brought more fully within the KYC/AML perimeter.
From demonstrating compliance to demonstrating impact
The next generation of KYC will require reliable identities across products and systems, transparent ownership and control, event-driven risk updates and explainable analytics. AI in KYC and AML can reduce low-value manual work, but consequential decisions must remain accountable and subject to effective human oversight. Firms that build these systems now will be able to argue effectiveness; those that wait will be left defending checklists.
Twenty-five years ago, the PATRIOT Act made financial institutions active participants in national security. The framework created durable capabilities and valuable intelligence, but also complexity, duplication and cost.
The five pending rulemakings may determine whether the next era merely rearranges existing obligations or finally moves the system from demonstrating compliance to demonstrating impact. As we mark 25 years since 9/11, “Never Forget” must mean never losing sight of why this framework exists: to identify genuine threats, protect lives, and help prevent such a tragedy from happening again.
Frequently Asked Questions
What are the KYC requirements for financial institutions?
KYC requirements generally center on identifying and verifying customers, understanding ownership and control, assessing customer risk, monitoring activity, and maintaining appropriate records. Under the USA PATRIOT Act and KYC framework, Section 326 established Customer Identification Program requirements for financial institutions. Modern KYC process also connects customer due diligence, beneficial ownership, ongoing monitoring, and risk assessment as part of a broader AML compliance program.
What are the impacts of not implementing effective KYC standards?
Weak KYC standards can make it harder for financial institutions to identify suspicious activity, understand customer and ownership risk, and meet their regulatory obligations. They can also increase manual investigations, false positives, and operational costs. Effective KYC is therefore not just about completing identity checks; it is part of a broader financial crime compliance framework designed to identify and manage risk.
What are the changes proposed to the AML/CFT program?
FinCEN’s 2026 proposed AML/CFT program rule would place greater emphasis on risk-based, reasonably designed programs and effectiveness. It would require financial institutions to conduct documented risk assessments, consider national AML/CFT priorities, and direct more resources toward higher-risk activity. The proposal also seeks to distinguish program-design deficiencies from implementation failures. These changes remain proposed and could change before any final rule takes effect.
What role can AI play in modern KYC and AML compliance?
AI can help KYC and AML teams handle high-volume, repetitive work such as document processing, data analysis, transaction monitoring, and identifying patterns that may require further investigation. The goal is not to remove human judgment from compliance. Instead, AI can help investigators spend less time on low-value manual work and more time reviewing complex cases, with human oversight remaining important for consequential decisions.