How To Write A Board Report Executive Summary (With Examples)
Money Laundering in 2026: What Every US Board and Compliance Officer Needs to Know
Money laundering isn't a plot device from a crime drama — it's a structural drag on the global economy, and a governance risk that lands directly on the desks of corporate boards. According to the United Nations Office on Drugs and Crime (UNODC), between 2% and 5% of global GDP is laundered every year, an amount equal to roughly $800 billion to $2 trillion. Law enforcement agencies worldwide manage to seize or freeze less than 1% of that total.
For US companies, the compliance calculus has changed dramatically in the past two years. What used to be a technical, back-office function is now a board-level governance issue, driven by record-setting enforcement actions, a shifting regulatory landscape around beneficial ownership reporting, and expanding obligations for anyone touching cross-border payments or digital assets. This guide breaks down how money laundering actually works, what US regulators expect from corporate compliance programs in 2026, and why the board's oversight duties carry real personal and financial stakes.
Key Takeaways
-
Money laundering drains an estimated $800 billion to $2 trillion globally each year, or 2–5% of world GDP, per UNODC research.
-
The classic laundering process has three stages: placement, layering, and integration.
-
TD Bank's 2024 Bank Secrecy Act settlement — roughly $3.09 billion across the DOJ, FinCEN, the OCC, and the Federal Reserve — remains the largest AML penalty in US banking history and a cautionary governance case study.
-
The Corporate Transparency Act's domestic reporting requirement has been paused since March 2025; only foreign reporting companies currently must file beneficial ownership information with FinCEN, though the rule remains legally intact and could be reinstated.
-
As of the FATF's June 2026 plenary, 22 jurisdictions sit on the FATF "grey list" for AML/CFT deficiencies.
-
Under the Caremark doctrine, corporate directors can face personal liability for failing to build or maintain an adequate compliance-reporting system.
What Is Money Laundering?
Money laundering is the process of disguising the origin of funds obtained through criminal activity so they appear to come from a legitimate source — making "dirty" money look "clean" enough to spend, invest, or bank without raising red flags.
In the United States, the legal backbone for combating money laundering rests on the Bank Secrecy Act (BSA) of 1970 and the USA PATRIOT Act of 2001. Together, these statutes make it a federal crime to knowingly engage in financial transactions designed to conceal the nature, location, source, or true ownership of criminal proceeds.
AML, defined: Anti-Money Laundering (AML) refers to the full set of laws, regulations, and internal corporate procedures designed to detect, document, and prevent the concealment of illicit funds.
The Three Stages of Money Laundering
Regulators and law enforcement — including the international Financial Action Task Force (FATF) — generally describe laundering as unfolding across three sequential phases.
PLACEMENT ─────────▶ LAYERING ─────────▶ INTEGRATION Cash enters the Funds are moved Laundered money financial system through complex re-enters the (deposits, front transaction chains legitimate economy businesses, currency to obscure the (real estate, assets, exchange) audit trail business revenue)
-
Placement: Raw, illicit cash first enters the formal financial system — often through large bank deposits, cash-intensive front businesses, or retail currency exchanges.
-
Layering: Once inside the system, funds are shuffled through a maze of transactions, accounts, and jurisdictions. Wire transfers, asset purchases, and shell-company investments are stacked on top of each other to obscure the money's origin and confuse investigators.
-
Integration: In the final stage, laundered funds are folded back into the mainstream economy, resurfacing as real estate equity, luxury assets, or seemingly legitimate business revenue — ready to be used with minimal risk of detection.
Money Laundering Statistics US Businesses Should Know in 2026
-
$800 billion–$2 trillion: Estimated volume of capital laundered globally each year, or 2–5% of world GDP, according to UNODC.
-
Less than 1%: Share of global illicit financial flows that authorities actually intercept or freeze, per the same UNODC research.
-
22 jurisdictions: Countries on the FATF "grey list" for increased monitoring as of the June 19, 2026 FATF plenary, including Bosnia and Herzegovina and Iraq (added that session) alongside Bulgaria, Kenya, Syria, Venezuela, and Vietnam. Three jurisdictions — Iran, North Korea, and Myanmar — remain on the more severe FATF "blacklist."
-
$3.09 billion: TD Bank's combined 2024 settlement with the DOJ, FinCEN, the OCC, and the Federal Reserve — the largest Bank Secrecy Act penalty in US history.
-
$1.3 billion: The FinCEN-specific portion of that settlement, described by the agency as the largest penalty it has ever assessed against a depository institution.
-
$18.3 trillion: Volume of customer activity TD Bank failed to adequately monitor over roughly a six-year period, according to DOJ findings.
Real-World Methods of Deception
Illicit actors continually blend traditional laundering tactics with newer digital tools:
-
Smurfing (structuring): Breaking large sums into small deposits that fall just under the US $10,000 cash-reporting threshold, to avoid triggering automatic bank reporting.
-
Anonymous shell companies: Setting up entities with opaque ownership structures specifically to hide the identity of the true beneficial owner.
-
Trade-based laundering: Falsifying trade documents or over/under-invoicing imports and exports to move value across borders under the cover of ordinary commerce.
-
Crypto-asset exploitation: Using digital tokens, mixing services, and peer-to-peer crypto platforms to move value quickly across jurisdictions — a trend that has pushed FATF to extend its compliance expectations to Virtual Asset Service Providers (VASPs).
Case Study: TD Bank and the Cost of Governance Failure
TD Bank's 2024 settlement remains the clearest illustration of what happens when AML governance breaks down at the executive level. The bank pleaded guilty to Bank Secrecy Act violations and conspiracy to commit money laundering — the first US bank in history to admit to the latter charge — and agreed to pay approximately $3.09 billion combined across the DOJ ($1.8 billion in criminal fines and forfeiture), FinCEN ($1.3 billion), the OCC ($450 million), and the Federal Reserve ($123.5 million).
According to FinCEN's own announcement, the bank had allowed its AML program to deteriorate for over a decade, making it an easy target for illicit actors, including some of its own employees. Investigators found the bank failed to adequately monitor roughly $18.3 trillion in customer activity over about six years, during which several money-laundering networks — some tied to organized crime — moved hundreds of millions of dollars through TD Bank accounts largely undetected.
The consequences went well beyond the fines. The OCC imposed an asset cap restricting TD Bank's US retail growth, and the bank agreed to a multi-year independent monitorship. Reporting on the case has pointed to a specific structural failure: bank leadership enforced a "flat cost paradigm" that froze the AML budget even as the bank's commercial business expanded, and internal red flags were reportedly not acted on. The lesson for corporate boards is straightforward — a well-written compliance policy means little without funded, active executive oversight behind it.
Regulatory Frameworks US Businesses Must Track
1. The Bank Secrecy Act (BSA) and FinCEN
Administered by the Financial Crimes Enforcement Network (FinCEN), the BSA is the foundation of US domestic AML law. It requires financial institutions, broker-dealers, and certain cash-intensive businesses to keep detailed records, verify client identities, and file Suspicious Activity Reports (SARs) when transactions look anomalous.
2. The Corporate Transparency Act (CTA) — a moving target
The CTA was designed to be the biggest overhaul of US corporate ownership transparency in a generation, requiring millions of entities to report Beneficial Ownership Information (BOI) to FinCEN. Its status, however, has shifted substantially since original passage. In March 2025, FinCEN issued an interim final rule that exempted all US-formed entities and US persons from BOI reporting, narrowing the "reporting company" definition to cover only foreign entities registered to do business in the United States. Appellate courts, including the Eleventh Circuit in December 2025, have since upheld the CTA's underlying constitutionality, and FinCEN has signaled it expects to issue a final rule sometime in 2026 that could revise — or reinstate — domestic reporting obligations. Companies should treat the current exemption as provisional rather than permanent, and many law firms recommend keeping beneficial ownership records current in case reporting duties are reinstated with little notice.
Separately, New York's own LLC Transparency Act took effect January 1, 2026, requiring foreign-formed LLCs doing business in the state to disclose beneficial ownership information to the New York Department of State, independent of whatever the federal CTA ultimately requires.
3. FATF's 40 Recommendations
The Financial Action Task Force is an international standard-setting body rather than a domestic US regulator, but its 40 Recommendations heavily influence how US agencies structure cross-border reporting rules, evaluate foreign banking partners, and apply a risk-based approach to transaction monitoring. Jurisdictions on FATF's grey and black lists — 22 and 3 respectively as of the June 2026 plenary — face mandatory enhanced due diligence from banks and counterparties worldwide.
Building an Effective Corporate AML Program
A resilient AML defense generally rests on four operational pillars:
-
Know Your Customer (KYC): Verifying the identity of clients and business partners through official documentation, background checks, and corporate registries before onboarding, followed by periodic profile updates.
-
Continuous transaction monitoring: Using modern monitoring tools to track fund flows and flag irregular, repetitive patterns that serve no legitimate commercial purpose.
-
Regulatory alignment: Systematically updating internal procedures to reflect the evolving rules from FinCEN, the CTA, and state-level transparency laws, with every remediation leaving an auditable trail.
-
Targeted staff training: Building a transparent internal reporting channel so employees understand specific red flags and can escalate suspicious activity with confidence.
The Board's Duty: Oversight, Caremark, and Governance Technology
US corporate directors face real accountability for compliance failures. Under the Caremark doctrine, a body of Delaware corporate case law, directors can be held personally liable if it's shown they failed to implement any reasonable system for monitoring compliance risk, or that they consciously ignored red flags once a system existed. Combined with potential director and officer liability exposure, AML oversight functions as a core fiduciary duty, not an optional add-on.
This reality is why secure board management platforms like BoardCloud have become an operational necessity rather than a luxury for many organizations. Rather than tracking AML audits, risk assessments, and regulatory updates across scattered emails and spreadsheets, boards can centralize regulatory compliance documentation, log formal committee approvals, and maintain a clean, timestamped audit trail inside a single governance platform. If regulators ever ask a board to demonstrate active compliance oversight — as they did throughout the TD Bank investigation — having that record instantly on hand, rather than reconstructed after the fact, can materially change the outcome.
For boards building or refreshing their oversight structure, BoardCloud's governance functionality and broader guidance on board meeting governance outline practical ways to formalize this kind of documentation discipline.
Glossary of Key Terms
-
AML (Anti-Money Laundering): The laws, regulations, and internal procedures designed to detect and prevent the disguising of criminal proceeds as legitimate funds.
-
BSA (Bank Secrecy Act): The 1970 US law requiring financial institutions to assist government agencies in detecting and preventing money laundering.
-
BOI (Beneficial Ownership Information): Identifying details about the individuals who ultimately own or control a legal entity.
-
FinCEN: The Financial Crimes Enforcement Network, a bureau of the US Department of the Treasury that administers the BSA and collects BOI data.
-
FATF grey list: FATF's list of "Jurisdictions Under Increased Monitoring" — countries with AML/CFT deficiencies that have committed to a remediation action plan.
-
SAR (Suspicious Activity Report): A report financial institutions must file with FinCEN when they identify potentially suspicious transactions.
-
Caremark doctrine: A line of Delaware case law holding that corporate directors can be personally liable for failing to establish or monitor a reasonable compliance-oversight system.
-
VASP (Virtual Asset Service Provider): A business — such as a crypto exchange — subject to AML obligations under FATF standards.
Sources
-
United Nations Office on Drugs and Crime — Money-Laundering Overview
-
ABA Banking Journal — TD Bank Agrees to Pay $3.1 Billion to Resolve AML Allegations
-
FATF — Jurisdictions Under Increased Monitoring, June 19, 2026
This article is provided for general informational purposes and does not constitute legal advice. Companies should consult qualified legal counsel regarding their specific AML and beneficial ownership compliance obligations.