What the 2026 U.S. National Money Laundering Risk Assessment Means for Compliance Professionals

2026 U.S. National Money Laundering Risk Assessment

7/30/20266 min read

The U.S. Department of the Treasury’s 2026 National Money Laundering Risk Assessment (NMLRA) delivers a clear message: the principal sources of illicit proceeds may be familiar, but the speed, scale, and technological sophistication of money laundering are changing rapidly.

This fifth national assessment identifies fraud, drug trafficking, cybercrime, human trafficking, human smuggling, and corruption as the leading money-laundering threats facing the United States. It also emphasizes illicit trade and the growing role of professional money launderers, including Chinese money-laundering networks and money mules that provide criminal organizations with specialized expertise, infrastructure, and economies of scale.

The report covers activity from January 2024 through December 2025 and draws on Bank Secrecy Act reporting, enforcement actions, public court records, law-enforcement analysis, regulatory information, and private-sector consultations. Its findings will help inform the forthcoming 2026 National Illicit Finance Strategy.

Fraud Has Become a Central AML Threat

One of the most important conclusions is that fraud can no longer be treated as a separate operational-loss issue managed only by fraud departments.

Fraud is now a major source of proceeds entering the money-laundering cycle.

In 2024, the FBI’s Internet Crime Complaint Center received 859,532 complaints involving more than $16 billion in reported losses, representing a 33% increase from 2023. The report also cites a Government Accountability Office estimate that fraud costs the federal government approximately $233 billion to $521 billion annually.

The assessment covers a broad spectrum of fraud:

  • investment fraud;

  • digital-asset investment scams;

  • healthcare fraud;

  • government-benefits fraud;

  • business email compromise;

  • impersonation scams;

  • romance scams;

  • advance-fee schemes;

  • check fraud;

  • identity theft; and

  • elder financial exploitation.

This has an immediate operational implication: AML, fraud, cybersecurity, sanctions, and investigations teams must work as an integrated financial-crime function. A fraudulent payment is not necessarily the end of a fraud event. It may be the beginning of a laundering chain involving mule accounts, shell companies, digital assets, payment applications, foreign exchanges, high-value goods, or real estate.

AI Is Increasing the Scale and Credibility of Fraud

The assessment gives particular attention to artificial intelligence.

Criminals are using generative AI to create convincing messages, fake websites, synthetic identities, fraudulent documents, cloned voices, manipulated images, and deepfake videos. These capabilities allow criminals to target more victims, operate across languages, impersonate trusted people or institutions, and attempt to defeat identity-verification controls.

The report notes that more than 9,000 AI-related complaints were submitted to the FBI’s IC3 during the first seven months of 2025.

For compliance teams, this means traditional document review and static identity verification are no longer sufficient. Institutions should strengthen:

  • liveness and biometric testing;

  • device and behavioral analytics;

  • duplicate-identity detection;

  • synthetic-identity controls;

  • document-authenticity testing;

  • voice and video verification protocols;

  • account-opening anomaly detection; and

  • escalation procedures for suspected deepfake activity.

At the same time, AI can support compliance by improving alert prioritization, transaction-pattern detection, adverse-media review, network analysis, and document assessment. Institutions must nevertheless manage model risk, explainability, privacy, bias, data quality, and human oversight.

Digital-Asset Investment Scams Are a Major Source of Losses

Digital-asset investment scams frequently called “pig-butchering” schemes—are among the report’s most serious fraud concerns.

Victims reported approximately $5.8 billion in losses from digital-asset investment scams in 2024, a 47% increase from the previous year. These schemes often begin through social media, dating applications, messaging services, or unsolicited text messages. Victims are directed to fake investment platforms and persuaded to send wire transfers or digital assets to accounts controlled by transnational criminal organizations.

The laundering process may involve:

  • domestic bank accounts;

  • money mules;

  • shell companies;

  • digital-asset exchanges;

  • stablecoins;

  • self-hosted wallets;

  • nested exchanges;

  • over-the-counter brokers; and

  • transfers to foreign-controlled wallets.

Compliance programs should therefore avoid treating digital-asset exposure as a narrowly defined crypto-sector issue. Banks, payment companies, MSBs, securities firms, and fintech businesses may all encounter the fiat entry and exit points of these schemes.

Professional Money Laundering Is Becoming More Organized

The report highlights the role of professional laundering networks that separate the predicate crime from the laundering activity.

These networks may collect cash from drug-trafficking organizations, move funds through shell-company accounts, use payment applications, purchase high-value electronics, convert value into digital assets, and transfer proceeds through international trade.

This specialization creates a detection challenge. The account holder may not appear directly connected to narcotics, fraud, or trafficking. Instead, the activity may resemble ordinary business payments, consumer transfers, import-export transactions, or purchases of goods.

Compliance teams should therefore look beyond individual transactions and analyze:

  • account networks;

  • shared devices and addresses;

  • rapid movement between unrelated parties;

  • multiple shell companies;

  • unusual cash-to-digital-asset conversion;

  • high-value electronics purchases;

  • repeated transfers to foreign counterparties;

  • unexplained trade activity; and

  • clusters of mule accounts.

The report’s analysis of shell companies explains how criminals use apparently legitimate entities to disguise illicit transfers as business activity and conceal the identities of underlying actors.

Traditional Channels Remain Important

Although technology receives substantial attention, the assessment does not suggest that traditional laundering methods are disappearing.

Cash, funnel accounts, cash-intensive businesses, banks, MSBs, casinos, prepaid products, money orders, insurance, real estate, legal entities, trusts, attorneys, accountants, third-party payment processors, precious metals, art, luxury goods, and electronics all remain relevant.

This is an important lesson for risk assessments: institutions should not replace traditional monitoring with technology-focused controls. They must manage both.

Criminals increasingly combine old and new methods, for example:

  1. fraud proceeds enter a mule bank account;

  2. funds move through a shell company;

  3. money is converted to stablecoins;

  4. part of the value purchases electronics or luxury goods;

  5. the assets are exported or resold; and

  6. proceeds are integrated through property or business activity.

The laundering chain is therefore multi-product, multi-channel, and often cross-border.

Real Estate Remains a Significant Vulnerability

The report continues to identify real estate as an attractive means of storing and integrating illicit wealth.

Most financed residential transactions involve regulated financial institutions, but non-financed purchases do not necessarily receive the same level of AML scrutiny. The report states that all-cash transactions account for approximately 20% to 30% of residential real-estate transfers.

Risks include:

  • purchases through companies or trusts;

  • nominees;

  • unexplained third-party funding;

  • rapid resale;

  • overvaluation or undervaluation;

  • payments through pooled professional accounts;

  • foreign corruption proceeds;

  • sanctions evasion; and

  • purchases inconsistent with the buyer’s known wealth.

Professionals involved in banking, lending, title services, legal services, wealth management, and real estate should incorporate ownership, funding, geography, sanctions, and source-of-wealth analysis into their controls.

Gatekeepers Remain a Structural Concern

The assessment identifies attorneys, accountants, and third-party payment processors as important gatekeepers.

These professionals frequently perform legitimate and essential functions, but criminals may seek their assistance to:

  • create legal entities;

  • administer trusts;

  • hold client money;

  • conduct property transactions;

  • structure investments;

  • move funds through pooled accounts; or

  • provide an appearance of legitimacy.

The vulnerability is not the profession itself. It is the opportunity created when complex transactions are carried out without sufficient transparency regarding the beneficial owner, commercial purpose, source of funds, and expected activity.

For regulated institutions, professional involvement should not automatically reduce risk. It may instead require verification of the professional’s role, authority, client relationship, and funding arrangements.

Elder Financial Exploitation Requires Greater Attention

The assessment also demonstrates the scale of elder financial exploitation.

Adults aged 60 and older reported nearly $4.9 billion in internet-enabled fraud losses in 2024, a 44% increase from the prior year. Financial institutions filed more than 155,000 suspicious activity reports involving over $27 billion in reported suspicious activity during the year following FinCEN’s elder-exploitation advisory.

Institutions should consider incorporating behavioral indicators such as:

  • sudden liquidation of savings;

  • unusual transfers to unfamiliar beneficiaries;

  • large purchases of gold or digital assets;

  • repeated payments following urgent telephone instructions;

  • a new person controlling the client’s communications;

  • unexpected account-access changes; and

  • transactions inconsistent with the client’s history.

Controls should combine fraud detection, customer protection, escalation, and SAR decision-making.

What Compliance Teams Should Do Now

The assessment should trigger a formal review of institutional risk assessments and controls.

Update the enterprise-wide risk assessment

Organizations should assess whether their current methodology adequately captures:

  • fraud as a predicate offence;

  • AI-enabled identity risk;

  • digital-asset exposure;

  • money mules;

  • professional laundering networks;

  • shell and front companies;

  • payment applications;

  • real estate;

  • gatekeepers;

  • high-value goods; and

  • cross-border criminal networks.

Recalibrate monitoring scenarios

Transaction-monitoring programs should test whether existing rules detect:

  • rapid pass-through activity;

  • funnel accounts;

  • unusual P2P transfers;

  • scam-related payments;

  • digital-asset kiosk activity;

  • stablecoin conversion;

  • mule-account patterns;

  • shell-company networks;

  • high-value electronics purchases;

  • unexplained all-cash property activity; and

  • transactions inconsistent with customer demographics or expected behavior.

Integrate fraud and AML investigations

Cases involving account takeover, impersonation, investment fraud, elder exploitation, synthetic identities, or government-benefit fraud should be evaluated for laundering indicators, related accounts, linked entities, and SAR obligations.

Strengthen customer and beneficial-owner verification

Institutions should improve verification for:

  • newly formed companies;

  • nominee ownership;

  • complex trusts;

  • nonresident entities;

  • third-party-funded accounts;

  • foreign PEPs;

  • higher-risk professional intermediaries; and

  • customers whose digital footprint is inconsistent with their stated identity or business.

Review emerging-technology controls

Organizations should establish governance for both criminal use of AI and institutional use of AI. Policies should address validation, explainability, human review, privacy, bias, information security, vendor oversight, and escalation.

Use the report as a training document

The NMLRA is particularly useful for scenario-based training. Staff should understand not only the listed threats but also how proceeds move across products, entities, payment methods, and jurisdictions.

The 2026 NMLRA shows that the United States combines very strong regulatory and enforcement capabilities with high inherent financial-crime exposure.

The risk is high not because the U.S. financial system is unsophisticated, but because it is vast, open, innovative, wealthy, and globally connected. Those characteristics attract legitimate commerce and investment—but they also attract fraudsters, traffickers, cybercriminals, corrupt actors, sanctions evaders, and professional money launderers.

The central lesson for compliance professionals is straightforward:

Financial crime risk must be reviewed continuously.

Fraud methodologies evolve. Technology changes. Criminal networks adapt. Products converge. Money moves faster. A risk assessment that was adequate two years ago may no longer reflect today’s threats.

The institutions best prepared for this environment will be those that connect fraud, AML, sanctions, cyber, customer due diligence, investigations, and technology governance into one coherent financial-crime framework.

Source: U.S. Department of the Treasury, 2026 National Money Laundering Risk Assessment, March 2026.

Contact us

amltraining@zoho.com

© 2026. All rights reserved.