These questions are buzzing in compliance team meetings and CCO Slack channels. Enforcement numbers are down, the tone has shifted, and everyone’s trying to figure out what it means for their program. Here’s what you and your team need to know.
Context: Understanding the Shift
The SEC reported 456 total enforcement actions in FY2025, a 22% decrease from FY2024. FINRA filed 625 new disciplinary cases in 2025, down 14.4%. Whistleblower tips hit a record 53,753, up 19%, but payouts dropped from $255 million to $60 million. The new SEC Enforcement Director, David Woodcock, has stated the focus is on fraud, not technical violations.
Meanwhile, both the SEC and FINRA are highlighting AI governance as a key examination area. The GENIUS Act created the first federal framework for payment stablecoins. FinCEN proposed restructuring AML/CFT requirements to focus on outcomes rather than processes.
So, does this lighter enforcement posture mean you can ease up? Or is it time to tighten up before the next cycle? Let’s dive into what you need to know.
Q1: Does the Drop in Enforcement Actions Mean Less Risk?
Not exactly. The focus has shifted, not the scrutiny.
While the total number of SEC standalone actions dropped 30%, whistleblower tips are at an all-time high. The enforcement apparatus is more focused. You’re less likely to face action for a minor recordkeeping error, but if your program has significant gaps around fiduciary duty, custody, or conflicts of interest, you’re still exposed.
FINRA fines rose 31.7% to $99.6 million in 2025, largely due to a single $26 million penalty against Robinhood. Excluding that, fines fell 15%, but the point remains: when enforcement acts, it acts decisively. Fewer cases don’t mean smaller consequences.
The SEC Division of Examinations’ shift in tone is important. Chairman Atkins emphasized that the 2026 exam priorities are not a "gotcha exercise." But core obligations like fiduciary duty and compliance program effectiveness remain. The exam aims to be more constructive, but it’s not optional.
Q2: Can We Delay Building a Digital Asset Policy?
No. The regulatory framework is now in place.
The GENIUS Act established the first U.S. federal framework for payment stablecoins, declaring them outside the securities definition. The SEC released interpretive guidance on digital asset categories, providing the market with a clear taxonomy. If you’ve been waiting for clarity, it’s here.
If you’re exploring stablecoins, tokenized securities, or crypto custody, now’s the time to develop governance, due diligence, and recordkeeping frameworks. This isn’t about predicting market trends; it’s about having a documented decision framework to explain your evaluations, approvals, and controls.
Q3: What Does "AI Governance" Mean in Practice?
It means demonstrating oversight over tools that influence client outcomes.
Both the SEC and FINRA have identified AI governance as a distinct examination area for 2026. FINRA’s Annual Regulatory Oversight Report added a section on generative AI, warning about compliance challenges like data privacy, transparency, and potential misuse. The report states that firms cannot outsource their regulatory obligations.
Operationally, you need documentation showing:
- What AI tools you’re using and where
- Who approved their use and under what criteria
- What testing you did before deployment
- How you’re monitoring for errors, bias, or hallucinations
- What happens when the tool produces an inexplicable result
The risk isn’t bad advice from the tool; it’s the inability to demonstrate governance over a tool influencing client outcomes. If an examiner asks, "How do you know this recommendation was suitable?" and your answer is, "The AI said so," you have a problem.
Q4: Is Off-Channel Comms Enforcement Over?
The enforcement wave is over. The recordkeeping obligation is not.
The SEC’s FY2025 enforcement results clarified that the $2.3 billion in off-channel communications penalties from FY2022 through early FY2025 were seen as an inappropriate use of resources. That chapter is closed.
However, the requirement to maintain and preserve business communications hasn’t changed. If your firm built an electronic communications monitoring program under penalty threat, consider whether it’s genuine operational infrastructure or compliance theater.
Ask yourself: if you turned off monitoring tomorrow, would you lose visibility into important business conduct? If no, you built a penalty-avoidance system. If yes, you built a supervisory tool.
You don’t need to monitor every emoji, but you do need a defensible program that captures business communications, preserves records according to your Record Retention Policy, and allows you to respond to exam requests or investigations without scrambling.
Q5: What Should We Do About FinCEN's Proposed AML Rule?
Start focusing on outcomes, not just processes.
FinCEN’s April 2026 proposed rule restructures AML/CFT program requirements, moving towards a regime focused on demonstrable effectiveness. The fact sheet confirms that enforcement will target significant AML/CFT supervisory actions, with a new notice and consultation framework between federal banking supervisors and FinCEN.
Comments closed June 9, 2026, with a 12-month implementation window to follow. The RIA AML rule has been delayed to January 1, 2028, but it’s coming.
Practically, you need to show that your suspicious activity monitoring system works, detects real risks, investigates alerts, files SARs when appropriate, and adjusts the program when gaps are found. If your current AML program is a checklist exercise, now’s the time to test its effectiveness.
Q6: Should We Worry That Crypto Assets Disappeared from SEC Exam Priorities?
No. It means the framework is settled, not that the topic is gone.
Crypto assets were omitted from the SEC’s 2026 exam priorities for the first time since 2018. This doesn’t mean you should ignore digital assets. It signals that the SEC views the regulatory framework as established.
The exam priorities still emphasize fiduciary duty, compliance program effectiveness, and custody. If your firm holds digital assets for clients, those obligations apply. The absence of a standalone crypto bullet point doesn’t create a safe harbor.
Examiners are less likely to ask exploratory questions about crypto. They’re more likely to ask how your existing custody, conflicts, and valuation controls apply to the digital assets you hold.
Next Steps
The second half of 2026 is your window to stress-test your compliance infrastructure before the next exam cycle. The statutory framework hasn’t changed. Regulation Best Interest, the custody rule, AML program requirements, and the 2024 Regulation S-P amendments are all active.
If you’re assessing whether your program would hold up under the current examination lens, especially around AI governance, digital assets, or AML effectiveness, don’t wait for the exam notice to find out.



