This Week in Compliance: The AML/CFT Programme Rule — 10-16 July 2026
newsVerifyo Editorial TeamAugust 24, 2026

This Week in Compliance: The AML/CFT Programme Rule — 10-16 July 2026

In a single editorial week, three very different actors reached for the same thing. United States prudential regulators moved to recast how banks build an AML/CFT programme rule around risk. European penalty-setters put a turnover-percentage number on unevidenced crypto compliance. And a 6.9-million-record data breach at a US insurer showed, in the plainest terms, what it costs to keep the raw customer data those controls are built on. The through-line is demonstrable controls — proving the system works, not merely asserting that it does.

Compliance evidence is not a filing exercise. It is an architecture question. Almost every story this week turns on the same tension: what an institution keeps versus what it can prove. Hold that distinction in mind and the week reads as one argument told five ways.

The new AML/CFT programme rule: what "effective" now means

On 7 July 2026 the Federal Reserve issued its own notice of proposed rulemaking recasting the anti-money-laundering programmes banks must maintain. Federal Register publication followed on 9 July, and the comment window runs 60 days (1). In the Board's words, the proposal “would require banks to focus their anti-money laundering resources based on risk, with more attention given to higher-risk customers and activities” (1).

This is the companion move that completes the set. The OCC, FDIC and NCUA issued their joint AML/CFT programme proposal back in April 2026, aligning bank supervision with FinCEN's own April overhaul implementing the Anti-Money Laundering Act of 2020. The Federal Reserve was not part of that April action; its July proposal brings the last major prudential regulator into line. Four agencies, one direction — a risk-based approach for financial institutions, anchored in a mandatory risk assessment.

The shift matters because it changes the burden of proof. A bank no longer merely runs the four pillars — internal controls, independent testing, employee training and a US-based AML/CFT officer — as a checklist under the Bank Secrecy Act. It must now demonstrate to supervisors that resources are allocated by risk. That raises the evidentiary bar on customer due diligence specifically: onboarding controls have to be provable, not just present, and a supervisory action can turn on whether the institution can show its work. The same demonstrable-CDD demand is surfacing on the EU side, where AMLA's group-wide CDD harmonisation pushes obliged entities toward one evidenced standard across a group.

An AML/CFT programme is far broader than any onboarding vendor: it spans transaction-level surveillance, independent testing and governance that we do not perform. Where we fit is narrower and specific — the verification-evidence layer. A bank can hold a Zero-Knowledge KYC attestation that proves a customer cleared sanctions, PEP and adverse-media screening at verification time, and produce that proof to a supervisor without warehousing the raw customer data behind it.

A 6.9-million-record driver's licence data breach

AssuranceAmerica, an Atlanta non-standard auto insurer, disclosed on 9 July 2026 that a credential-phishing intrusion dating to March had exposed the personal data of 6,998,886 people. According to the notification filed with Maine's Attorney General, the stolen records “contained a combination of affected individuals' names, contact information ... and driver's license numbers” (2). It is one of the largest US driving-licence leaks of 2026.

Driving-licence numbers are breeder-document credentials — the very data collected at KYC onboarding to seed an identity. The breach surface here is not a bolt-on security failing. It is the retention model itself. An organisation that copies and stores breeder-document data becomes a standing target, and the scale of the loss is a direct function of how much it kept. The honeypot is the design, not the incident — which is the mirror image of the AML/CFT programme rule story. One side demands provable controls; the other shows the cost of proving them by hoarding.

There is an architecture that breaks this link. A verifier-private, Zero-Knowledge KYC attestation confirms that a credential is valid without the receiving platform retaining the credential itself. The document is checked once; what integrating platforms hold afterwards is proof of status, not a copy of the licence. Remove the stored breeder-document copy and you remove the honeypot the attacker walks off with. We verify the identity document and issue the attestation — we make no claim to secure an insurer's other systems — but the record that was never stored is the record that cannot leak.

How reusable digital identity works — and where it stops

On 3 July 2026, Sumsub joined the idOS Consortium and took a seat on its Governance Committee, with the stated aim of accelerating reusable digital identity across Web3 — verify once, reuse credentials across decentralised platforms (3). A leading incumbent endorsing verify-once, reuse-everywhere is a genuine market signal, and it validates the reusable-attestation thesis. This is a real step toward cutting redundant re-verification, and it is fair to name it as one.

But there is an architectural line worth drawing cleanly. Consortium-brokered credential reuse still routes verified attributes through a vendor-mediated capture-and-store model. Reuse reduces how often a platform re-collects a user's data; it does not, by itself, change whether the verified data is stored and transferable downstream. The wider field — verifiable credentials, digital wallets and trust frameworks built on zero-knowledge proofs — is converging on reusable compliance as the goal, but the goal splits in two. Reusable is not the same as private. It is entirely possible to reuse a verification and still expose the underlying data.

That distinction is where we build differently. A single Zero-Knowledge KYC attestation lets a user prove compliance status to any integrating platform through a status check, so the platform receives proof, not a copy of the documents. The verified attributes are not handed to each downstream party in turn. Reuse solves the frequency problem in identity verification; verifier-private proof solves the exposure problem underneath it.

Stablecoin regulation: the EBA puts a number on non-compliance

The European Banking Authority published, on 26 June 2026, a draft methodology for setting fines on issuers of significant asset-referenced tokens and e-money tokens under MiCA (consultation paper EBA/CP/2026/10). The consultation paper sets the ceilings — up to 12.5% of annual turnover for asset-referenced tokens and 10% for e-money tokens — while the EBA's stated objective is to keep fines “consistent, proportionate and transparent” (4). A virtual public hearing is scheduled for 16 July 2026, with registration by 13 July, and comments close on 28 September 2026 (4).

A transparent penalty framework prices the cost of unevidenced compliance. This is the enforcement flip side of the MiCA transitional cliff — not the deadline this time, the penalties. For significant token issuers, turnover-percentage fines convert “can you demonstrate MiCA-grade AML and KYC controls” from a supervisory nicety into a line on the balance sheet. The value of demonstrable controls just went up, and it is now measured in basis points of turnover. Stablecoin issuers reviewing their stablecoin KYC compliance posture should read the methodology as a pricing signal, not a distant consultation.

Market update: Ripple's full MiCA CASP authorisation

On 6 July 2026, days after the MiCA transitional window closed, Ripple announced it had received authorisation of its Crypto-Asset Service Provider licence from Luxembourg's Commission de Surveillance du Secteur Financier (5). The full CASP authorisation covers all 30 EEA states and stacks on Ripple's existing EU Electronic Money Institution licence, extending its regulated crypto-payments product across the bloc.

Authorisation is now the market-access gate for crypto-asset services in the EU — and, importantly, a continuing obligation rather than a one-time badge. An authorised CASP must keep evidencing MiCA-grade AML and KYC controls to its national competent authority, with EU passporting across the EEA resting on that standard holding in every market it reaches. The authorisation milestone is the start of an evidence obligation, not the end of one. A continuing obligation of that kind favours verifiable, verifier-private attestations a firm can produce to a national competent authority without warehousing raw customer data.

Timeline of the week's five compliance developments from 26 June to 9 July 2026 — EBA MiCA fines, Sumsub idOS, Ripple CASP, the Fed AML/CFT programme rule, and the AssuranceAmerica breach.

Prove it, don't hoard it

Pull the thread tight and the week points one way. A supervisory rule that demands demonstrable, risk-based customer due diligence. A breach that shows the cost of retention at scale. An incumbent validating reusable identity. A penalty framework putting a turnover-percentage price on the gap. Four moves, one conclusion: the assurance an institution can prove is worth more than the data it keeps.

The cheapest breach is the record you never stored. The strongest control is the one you can show a supervisor without opening a data room. That is the gap verifier-private, Zero-Knowledge KYC attestations are built for — and it is why we build the way we do.

Sources

(1) Federal Reserve. "Federal Reserve Board requests comment on a proposal to amend its requirements for banks to maintain anti-money laundering programs." 7 July 2026. https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260707a.htm

(2) BleepingComputer. "AssuranceAmerica data breach exposes records of 6.9 million drivers." 9 July 2026. https://www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/

(3) CoinTrust. "Sumsub Joins idOS Consortium to Advance Reusable Identity in Web3." 3 July 2026. https://www.cointrust.com/market-news/sumsub-joins-idos-consortium-to-advance-reusable-identity-in-web3

(4) European Banking Authority. "The European Banking Authority consults on a draft methodology for setting fines under the Markets in Crypto-Assets Regulation." 26 June 2026. Consultation paper EBA/CP/2026/10. https://www.eba.europa.eu/publications-and-media/press-releases/european-banking-authority-consults-draft-methodology-setting-fines-under-markets-crypto-assets

(5) Ripple. "Ripple Receives Full EU MiCA CASP License." 6 July 2026. https://ripple.com/ripple-press/ripple-receives-full-eu-mica-casp-license/

Tags:AML/CFT programme rulecomplianceweekly recapKYCreusable digital identityMiCA CASP authorisationdata breachZero-Knowledge KYC

Want to learn more?

Explore our other articles and stay up to date with the latest in zero-knowledge KYC and identity verification.

Browse all articles