The Federal Reserve is proposing new guidance that specifically identifies marijuana businesses as an example of higher-risk bank customers that may require more advanced anti-money-laundering monitoring tools.
The language is included in the Federal Reserve’s proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations, published in the Federal Register on September 15.
The proposal is designed for Federal Reserve-supervised banking organizations with less than $30 billion in assets that primarily serve their local communities.
In a section addressing Bank Secrecy Act and anti-money-laundering, or BSA/AML, platforms, the Federal Reserve says basic compliance tools will be sufficient for most traditional community banks.
However, the proposal states that more sophisticated systems may be appropriate when a bank serves customers considered higher risk.
“Where, however, a TCBO’s clients present higher risk (e.g., marijuana-related businesses), tools with more advanced capabilities may be appropriate,” the Federal Reserve says.
The explicit reference is notable as marijuana businesses continue to face substantially greater banking challenges than businesses in most other legal industries.
A Government Accountability Office report released earlier this month found that approximately 1,000 banks and credit unions filed marijuana-related suspicious activity reports in 2024, representing about 11% of the roughly 9,000 federally insured financial institutions nationwide.
Marijuana businesses participating in that federal review reported problems including sudden account closures, lengthy approval processes, high banking fees and limited access to affordable financing.
The Federal Reserve proposal does not create a new requirement for banks serving marijuana businesses, nor does it require them to purchase specific monitoring technology.
The agency emphasizes that the proposed guide would not establish enforceable standards or prescriptive requirements and that failure to follow its suggestions would not, by itself, result in supervisory criticism.
Instead, the guide offers examples of how community banks could tailor their third-party risk-management practices to their particular customers and business models.
For BSA/AML technology specifically, the Federal Reserve says banks may want to assess whether systems adequately account for their risk profile, including reviewing detection rules, thresholds and scenario coverage. Banks could also monitor for excessive false positives, unusual changes in alert volumes and whether providers promptly incorporate sanctions-list and regulatory updates.
The proposed community-bank guide is separate from broader third-party risk-management guidance proposed jointly by the Federal Reserve, Federal Deposit Insurance Corporation, Office of the Comptroller of the Currency and National Credit Union Administration.
Federal regulators said the broader proposal is intended to establish a principles-based approach allowing financial institutions to tailor oversight to the risks posed by individual third-party relationships.
Both proposals are nonbinding supervisory guidance rather than regulations carrying the force of law.
The Federal Reserve is accepting public comments on the community-bank proposal through November 16.








