FinCEN's proposed Section 311 action involving Banque Misr UAE deserves to be examined beyond the immediate facts of the case.

On August 28, 2026, FinCEN proposed prohibiting U.S. financial institutions from maintaining correspondent accounts for Banque Misr UAE and proposed additional measures designed to prevent transactions involving the institution from accessing the U.S. financial system.

According to FinCEN, it identified approximately $1.8 billion in transactions involving 103 potential Iranian shadow-banking front companies through Banque Misr UAE between January 2024 and June 2026. FinCEN also concluded that additional conditions, reporting requirements, or other measures would not adequately address the risks it identified.

These are serious findings.

Familiarity Bias in Financial Crime Compliance

I think there’s a much bigger question here.

What if we’re looking at the problem through the lens of how financial risk and compliance have traditionally been managed?

There's a concept I've written about before: familiarity bias.

It’s not necessarily that people ignore new ideas. It’s that when we’ve spent decades solving a problem a certain way, we tend to frame the problem – and the available solutions – within the boundaries of what we already know.

This can, and does, happen in financial institutions.

It can, and does, happen with regulators.

Fact is, it happens across entire industries – not just banking.

When a correspondent banking relationship presents significant AML/CFT, sanctions, transaction or counterparty risk, the traditional response has generally been some combination of:

  • enhanced due diligence;

  • additional policies and procedures;

  • additional reporting;

  • additional screening;

  • additional monitoring;

  • additional controls; and ultimately

  • restricting or terminating the relationship.

Those tools and actions are important.

More people, more costs, slower payments. But humans fail. And eventually the costs and risks become too great – so correspondent banks exit. This is well documented.

Point is, these aren’t the only possible tools.

What FinCEN's Proposal Leaves Unexplored

There’s an important point in FinCEN's own proposal.

FinCEN's NPRM itself recognizes that financial institutions use commercially available software for screening and reporting activities.

That’s important.

Because the question isn't whether software is part of modern compliance. It clearly is.

The question is whether we've fully recognized what software can now do.

There’s a significant difference between using software to perform another screening function versus using new software as shared, cross-institution risk infrastructure – infrastructure that can help a financial institution establish not only what its counterparty says it does, but what its counterparty actually did.

I don't see this distinction meaningfully explored in the Banque Misr UAE analysis by anyone writing about this.

This deserves attention.

I've read FinCEN's proposed rule carefully.

FinCEN identifies significant deficiencies and explains why it believes the existing or additional traditional measures would not adequately address the risks it identified.

What I don't see is an analysis of whether new categories of technology and bank infrastructure could fundamentally change the way counterparty and transaction risk is managed between the foreign institution and its correspondent banks.

I'm not suggesting that FinCEN should have reached a different conclusion based on technology that may not have been available to it or to the institutions involved.

And I'm certainly not suggesting that software would somehow eliminate the conduct FinCEN identified.

I'm asking a different question: Did anyone consider whether a fundamentally different risk-management architecture could have changed the equation?

Imagining "See-Through" Risk Management

Consider what a correspondent relationship could look like with modern cross-border payment infrastructure – tools that have never existed before.

Imagine that a U.S. correspondent bank could look beyond simply trusting the controls of its foreign correspondent.

Imagine that it could have continuous, digitally verifiable visibility into:

  • the counterparty's risk assessment;

  • the parties involved in each transaction;

  • the underlying customers and counterparties;

  • beneficial ownership and party relationships;

  • sanctions and watchlist screening;

  • transaction-risk rules and decisions;

  • the data and documents supporting those decisions;

  • exceptions and overrides;

  • investigations and dispositions;

  • the controls that were required to be executed;

  • whether those controls were actually executed; and

  • the evidence supporting the conclusion.

And imagine that this information could be exchanged securely between institutions without requiring either institution to surrender control of its own data or systems.

Now imagine that the correspondent bank can choose whether to accept and trust this data.

What if it could independently execute its own AML/CFT functions, sanctions checks, watchlist screens, KYT, and more? During the payment process, not weeks or months after, and with all data residing naturally with complete payment details?

That is fundamentally different from simply asking a correspondent bank:

"Do you have adequate AML/CFT policies and procedures?"

It creates the possibility of moving from trusting that controls exist to digitally establishing how those controls were actually executed.

That is what I mean by "see-through" risk management.

And perpetual audits and actions.

It Works in Both Directions

If Banque Misr UAE – or any other foreign financial institution – is a legitimate institution that wants to operate responsibly but has deficiencies in its risk and compliance capabilities, modern infrastructure, whether acquired on its own or provided by its correspondent bank, could give that institution significantly better tools to execute its responsibilities with certainty.

At the same time, its correspondent bank could have much greater visibility into what was actually done.

The correspondent isn't simply relying on representations, periodic reviews, and reports.

It can have digitally accessible evidence.

Now consider the other possibility.

What if the originating institution itself is unwilling to operate with that degree of transparency and control?

That creates a different kind of signal.

A correspondent bank that requires its counterparties to operate within a transparent, digitally verifiable risk framework can make participation in the relationship conditional on demonstrable controls.

An institution that refuses or is unable to meet those requirements may choose another correspondent.

That doesn't necessarily eliminate the underlying risk from the global financial system.

But it can protect the correspondent institution that has chosen to manage its risk differently.

The Industry's Blind Spot

This is where I think the industry needs to challenge some conventional thinking.

The answer to every significant financial crime event can’t simply be: More rules. More reporting. More screening. More monitoring. Or ultimately, exit the relationship.

There's another possibility: Better infrastructure.

And this is where I believe the financial industry may have a significant blind spot.

We’ve spent enormous amounts of money building systems that process payments.

We’ve built systems that screen names.

We’ve built systems that monitor transactions.

We’ve built systems that perform KYC.

We’ve built systems that manage core banking accounts.

We’ve built systems that support correspondent banking.

Disparate systems and technology. Separate departments. Not simultaneously executed across departments and institutions.

But where's the infrastructure purpose-built to digitize every KYT, AML and other rule and continuously manage counterparty risk and transaction risk across the entire chain of a cross-border payment – and allow the relevant institutions to digitally establish how risk and compliance responsibilities were actually executed?

That’s a different problem.

And it requires a different architecture.

This Technology Now Exists

The capabilities I'm describing aren’t theoretical.

New cross-institution technologies now exist that connect functions typically siloed within each bank, enabling financial institutions to establish, execute, monitor, and share evidence of risk and compliance controls across institutional boundaries.

They are simply not yet widely known or understood by the banking and regulatory communities that could potentially benefit from them.

Payall is one company building this kind of infrastructure.

Our approach is not to add another screening application or another compliance report.

It’s to create infrastructure that allows originating institutions, correspondent banks and receive institutions to manage counterparty and transaction risk across the payment chain – and to establish digitally what controls were required, how they were executed, what information supported the decisions, and what happened when an exception occurred.

I believe that distinction is important enough that the industry should be discussing it.

Not because one piece of software can solve financial crime. It can't.

But because the architecture of risk management can be fundamentally improved.

The Bigger Lesson from Banque Misr UAE

Perhaps the biggest lesson from Banque Misr UAE is not about Banque Misr UAE.

FinCEN's proposed action is about a specific institution and specific conduct. It should be evaluated on those facts.

But the broader question is much bigger.

How many other correspondent relationships around the world are being managed with technology that was designed for a different era of financial risk?

And if we're being honest – they are based on "trust," validated by audits long after a transaction occurs.

And how many institutions, including regulators, banks, and financial infrastructure providers, are evaluating today's risks using yesterday's capabilities and mindset?

This is where familiarity bias becomes important.

The industry knows the tools it has used for decades.

It knows how to add another rule.

Another report. Another screening layer. Another periodic review. Another due-diligence questionnaire.

What if the next step isn't another layer?

What if it is a fundamentally different architecture?

The alternative to de-risking isn't less regulation.

It isn't less diligence.

It isn't less oversight.

It’s the possibility of managing risk better – through fundamentally better software and infrastructure to deal with data. In real time. Visible and shared across institutions.

By data, I mean the rules themselves, how they were executed, and the supporting data, documents and artifacts that justify each decision.

That is the opportunity I believe the industry has not yet fully recognized.

And it’s one of the reasons we built Payall.