FIL-27-2021, dated April 9, 2021, transmitted an interagency statement explaining how the 2011 model risk management principles apply to the systems and models banks use for Bank Secrecy Act/anti-money-laundering and OFAC sanctions compliance — including machine-learning transaction monitoring. It created no new requirements, said no particular model risk framework was mandatory, and stressed that banks remain responsible for BSA/AML compliance even when they rely on third-party models. The FDIC rescinded it on April 17, 2026 in FIL-15-2026.
| Document | FDIC FIL-27-2021 — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC Compliance |
| Issued by | Federal Deposit Insurance Corporation |
| Type | Guidance |
| Status | Superseded |
| Published | Apr 9, 2021 |
| Effective | Apr 9, 2021 |
| Applies to | FDIC-supervised banks and savings associations (issued jointly with the Federal Reserve and OCC, in consultation with FinCEN and NCUA) |
| Also issued as | 2021 BSA/AML Model Risk Statement, OCC Bulletin 2021-19, 2021 BSA/AML Model Risk Management Statement |
| Superseded by | FDIC FIL-15-2026 |
| Official source | fdic.gov ↗ |
| Use cases | AML / KYC · Model risk management · Third-party & vendor AI |
What are the key points of FDIC FIL-27-2021?
- Joint FDIC, Federal Reserve, and OCC statement issued in consultation with FinCEN and the NCUA.
- Clarified that the 2011 model risk guidance can be a useful resource for BSA/AML systems, whether the bank's framework is formal or informal.
- Did not alter BSA/AML legal requirements or create new supervisory expectations.
- Banks must understand how third-party AML models work and confirm they fit the bank's risk profile; using a vendor does not shift responsibility.
- Issued alongside an RFI on model risk management principles for BSA/AML (FDIC docket 3064-ZA23).
- Rescinded April 17, 2026 with the revised interagency model risk management guidance.
What did FDIC FIL-27-2021 change for banks?
Between 2021 and 2026 this statement was the main answer to whether AI-driven transaction monitoring needed full model validation: it said model-risk principles apply, flexibly. Its rescission folds AML and sanctions models into the general 2026 framework, and the FDIC's pending BSA program rule proposal encourages AI for detecting illicit finance.
Is FIL-27-2021 still in effect?
No. The FDIC rescinded it on April 17, 2026 in FIL-15-2026. BSA/AML and OFAC models are now covered by the revised interagency model risk management guidance.
Did the 2021 statement require formal validation of AML models?
No. It said no specific model risk management framework was required and that the 2011 principles could guide a formal or informal framework scaled to the bank's complexity.
| Date | Document | Status |
|---|---|---|
| Apr 17, 2026 | FDIC FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance | In force |
| Jun 4, 2026 | Hill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators | Final |
| Mar 26, 2026 | FDIC House testimony on AI and innovation (Mar 2026) — Innovation at the Speed of Markets: How Regulators Keep Pace with Technology | Final |
| Jul 14, 2025 | FDIC 2025 Report on Cybersecurity and Resilience — 2025 Report on Cybersecurity and Resilience | Final |
| Jan 10, 2025 | Hill 'Charting a New Course' speech — Charting a New Course: Preliminary Thoughts on FDIC Policy Issues | Final |
| May 22, 2024 | FDIC 2024 Risk Review — 2024 Risk Review — Section 5: Operational and Cyber Risks | Final |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →