The Financial Crimes Enforcement Network (FinCEN) is currently facing mounting pressure to rethink how financial institutions manage customer identity, as industry advocates argue that the traditional, data-heavy approach to Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) is inadvertently fueling the very crimes it seeks to prevent. In a recent formal filing, the nonprofit research and advocacy group Coin Center challenged the status quo, arguing that the standard practice of collecting and retaining sensitive personal information creates massive "honeypots" for hackers, facilitates widespread identity fraud, and offers diminishing returns in the fight against illicit finance.
The submission, directed at the U.S. Department of the Treasury and FinCEN, comes as regulators look to modernize the Bank Secrecy Act (BSA) to better account for the realities of the digital age. Coin Center’s position is that the current regulatory climate—which prioritizes the collection of driver’s licenses, passport scans, and exhaustive personal dossiers—is outdated. By forcing financial institutions to act as massive repositories for sensitive data, the current framework creates systemic vulnerabilities that sophisticated criminals are increasingly eager to exploit.
A Chronology of Regulatory Friction
The debate over the efficacy of the Bank Secrecy Act has intensified alongside the rise of digital assets. For decades, the primary method for verifying identity has been the "Know Your Customer" (KYC) protocol. However, the last decade has seen a paradigm shift in how illicit actors operate.
- 2001–2010: The post-9/11 era solidified the current BSA compliance structure, emphasizing the collection of static, paper-based identity documents to monitor financial flows.
- 2015–2020: As financial services migrated online, identity verification processes followed, leading to the "upload a selfie with a driver’s license" standard.
- 2021: FinCEN reported that approximately 1.6 million BSA filings involved identity-related suspicious activity, representing 42% of all reports that year.
- 2023: The scale of identity-related suspicious activity linked to financial crimes climbed to an estimated $394 billion, according to data cited by the National Institute of Standards and Technology (NIST).
- 2025: Current discussions regarding the modernization of the BSA have centered on how to reconcile the need for financial oversight with the increasing prevalence of data breaches and the weaponization of stolen credentials.
The Security Paradox: Overcollection as a Liability
The core of Coin Center’s argument is the existence of a "compliance paradox." Financial institutions are mandated to collect vast amounts of Personally Identifiable Information (PII) to satisfy regulatory examiners. Yet, this very data is the primary commodity sought by cybercriminals. Once a financial institution’s database is breached, the stolen credentials can be used to open fraudulent accounts, compromise existing ones, and launder money under the guise of an innocent person.
A 2024 study conducted by researchers at the University of Brasília, which examined over 500 data breaches at U.S. publicly traded companies, identified financial institutions as the most frequent targets for malicious actors. The researchers noted that these institutions are uniquely valuable because they hold the "gold standard" of identity verification documents—the exact tools needed to pass future AML checks elsewhere.
The Identity Theft Resource Center (ITRC) 2025 annual report further supports this, noting a significant transition in criminal methodology. Rather than focusing on transient data like credit card numbers, which can be easily canceled, criminals are now prioritizing "static identifiers." These include Social Security numbers and official government identification, which, once compromised, leave victims vulnerable to long-term identity fraud.
The Human Cost of Legacy Systems
While the financial industry bears the burden of compliance costs and cybersecurity insurance premiums, the true impact is felt by the American consumer. FBI and Federal Trade Commission (FTC) data show a clear, upward trajectory in identity theft and fraud-related complaints. The FTC’s Consumer Sentinel Network reported that total fraud and identity theft reports ballooned from roughly 860,000 in 2004 to over 6.4 million in 2024.
This data suggests that the current "ritual" of compliance—where everyday users submit intimate photos and personal documents to verify their identity—is not stopping the sophisticated criminal elements it was designed to target. Instead, it is forcing the average citizen to hand over a permanent record of their identity to a database that is statistically likely to be compromised at some point in the future.
Moving Toward Privacy-Preserving Alternatives
In its filing, Coin Center suggests that FinCEN should stop measuring success by the sheer volume of data collected and start measuring it by the outcomes achieved: the reduction in illicit finance and the protection of consumer data.
The proposal advocates for the adoption of privacy-preserving digital identity systems. These include:
- Portable Credentials: Identity verifications that can be moved and verified without sharing the underlying raw document.
- Attribute-Based Proofs: Systems where a user can prove they are over 21 or a resident of a specific country without revealing their full birth date, address, or legal name.
- Dynamic Risk-Scoring: Mechanisms that allow institutions to assess the risk of a transaction based on behavioral analysis rather than static, easily forged documents.
By encouraging the use of these technologies, FinCEN could allow regulated entities to verify that a customer is legitimate without becoming a "honeypot" for identity thieves. NIST has already begun laying the groundwork for this transition, noting in its recent digital identity guidelines that the emergence of new threats requires a shift toward more secure, usable, and privacy-preserving solutions.
Implications for the Financial Landscape
The policy implication of this shift is significant. If FinCEN moves to accept privacy-preserving proofs as a valid form of customer identification, it would represent a departure from the "examine the paperwork" mentality that has dominated the industry since the early 2000s.
Critics of this approach might point to the potential for regulatory arbitrage or the difficulty of tracing illicit funds if identity documentation is minimized. However, proponents argue that the current system is already failing to trace funds effectively, as criminals simply use stolen, authentic identities to mask their activity. By moving to a system that emphasizes verified attributes over stored, sensitive files, the financial sector could theoretically close the gap that criminals use to exploit the system.
Ultimately, Coin Center’s position is that "effectiveness" in the AML/CFT space should not be synonymous with "invasiveness." As the regulatory body continues its efforts to modernize the Bank Secrecy Act, the tension between the need for financial surveillance and the right to individual privacy—and digital security—will remain a focal point. Whether FinCEN adopts these recommendations will depend on whether it views the reduction of "honeypots" as a matter of national security and financial stability, or whether it continues to favor the traditional collection of physical identity documents as the primary, albeit flawed, tool of the trade.
