Cartel Risk Is Becoming a Control Expectation, Not Just a Watchlist Check

03 September 2026 | Industry Intel

On September 2, 2026, the Financial Crimes Enforcement Network (FinCEN) reissued a Geographic Targeting Order aimed at money laundering and illicit financial activity connected to Mexico-based cartels along the U.S. southwest border.

For certain money services businesses (MSBs), the immediate requirement is clear. Covered businesses operating in specified ZIP codes within Bernalillo, Doña Ana, and San Juan counties in New Mexico, as well as Cameron, El Paso, Hidalgo, Maverick, and Webb counties in Texas, must file Currency Transaction Reports for cash transactions between $1,000 and $10,000. The reissued order will remain effective for 180 days following its publication in the Federal Register.

But the significance of the order extends beyond the businesses directly subject to it.

FinCEN explicitly connected the GTO to what it called the “significant risk to the U.S. financial system” posed by cartels, drug traffickers, and other criminal actors. It also said the additional reporting is intended to give law enforcement greater visibility into transactions that may help identify organizations and individuals connected to drug trafficking and money laundering.

For financial crime compliance teams, this is part of a much larger pattern.

Cartel risk is increasingly becoming a question of whether financial institutions can recognize risky behavior, geography, counterparties, ownership structures, and financial networks, not simply whether a customer’s name appears on a sanctions list.

What FinCEN’s Southwest Border GTO actually requires

Geographic Targeting Orders allow FinCEN to impose additional reporting or record keeping requirements on financial institutions and other businesses within specific geographic areas when the agency determines additional information is necessary to support the purposes of the Bank Secrecy Act.

The Southwest Border GTO has been evolving since FinCEN first introduced enhanced requirements in March 2025.

In March 2026, FinCEN expanded the order across portions of Arizona, California, New Mexico, and Texas. The September reissuance identifies specified areas in New Mexico and Texas, making it important for MSBs to confirm current ZIP-code applicability rather than assuming that the geographic scope of an earlier order remains unchanged.

The threshold itself is also notable.

FinCEN is seeking information about cash transactions well below the traditional $10,000 CTR threshold because activity at lower amounts can still provide valuable intelligence when examined alongside geography, transaction patterns, counterparties, and other information.

In its earlier guidance on the Southwest Border GTO, FinCEN explained why. MSBs in these areas operate in regions where drug cartels are actively involved in drug, human, and weapons trafficking and need mechanisms for moving illicit cash within the United States and across the border. FinCEN said information collected through the GTO can help identify cartel-related money laundering as well as suppliers and facilitators supporting these organizations.

That is what makes the order important beyond its immediate reporting requirements.

Financial network visualization showing cartel risk and cross-border financial activity between the United States and Mexico

The regulatory focus is moving beyond designated cartel members

Sanctions and watchlist screening remain foundational controls.

But recent Treasury actions demonstrate why identifying a designated cartel or sanctioned leader is only one piece of the problem.

In July 2026, OFAC sanctioned more than 50 individuals and entities connected to Cartel de Jalisco Nueva Generacion (CJNG). The action did not focus solely on cartel leadership. Treasury targeted drug trafficking cells, financiers, logistics operations, and other parts of CJNG’s financial network.

In May, Treasury targeted two separate networks associated with the Sinaloa Cartel, including individuals and entities allegedly involved in laundering narcotics proceeds.

In April, Treasury sanctioned cartel-linked casinos and associated individuals operating around the U.S.-Mexico border.

And in June, FinCEN issued a supplemental alert specifically asking financial institutions to identify and report suspicious activity connected to cartel-linked fuel smuggling and tax-evasion schemes. The alert included financial typologies and red flags intended to help institutions recognize that activity.

Taken together, these actions point toward a wider risk perimeter.

The challenge is no longer limited to recognizing a cartel name.

It is recognizing the financial ecosystem around it.

Cartel exposure can appear before a watchlist hit

A customer, company, or counterparty does not necessarily need to appear on the SDN List for cartel-related exposure to exist.

Risk can emerge through business relationships, beneficial ownership, geographic concentration, intermediaries, logistics providers, counterparties, unusual transaction behavior, or links to known facilitators.

That distinction matters because illicit networks are intentionally structured to obscure the connection between legitimate commerce and criminal organizations.

FinCEN has repeatedly highlighted this problem.

Its March 2025 alert described how Mexico-based transnational criminal organizations use bulk cash smuggling and repatriation schemes to move proceeds through the U.S. and Mexican financial systems.

FinCEN has also warned financial institutions about Chinese money laundering networks used by Mexico-based cartels. Its analysis found more than 137,000 BSA reports associated with suspected Chinese money laundering network activity between 2020 and 2024, representing approximately $312 billion in suspicious transactions.

More recently, FinCEN reported that financial institutions flagged nearly $5 billion in suspected human-smuggling activity from 2023 through 2025, identifying indicators such as excessive cash activity along the southwest border, transactions following common migration routes, and unverifiable relationships between originators and beneficiaries. FinCEN noted that many of these networks generate revenue for larger transnational criminal organizations, including Mexico-based cartels.

These are not traditional name-screening problems.

They are intelligence problems.

Four controls compliance teams should be assessing

1. Customer risk scoring needs to account for changing geographic risk

Geographic exposure has always been part of risk-based AML programs, but a simple country-risk flag may no longer provide enough precision.

FinCEN’s use of individual counties and ZIP codes demonstrates how granular geographic risk can become.

Institutions should be able to determine whether customers, counterparties, transaction corridors, business locations, or beneficial owners create exposure to areas associated with elevated cartel activity.

That does not mean treating every customer connected to Mexico or the Southwest as high risk.

It means ensuring geography can be evaluated alongside other indicators and can influence customer risk when the combination of signals warrants additional scrutiny.

2. Transaction monitoring should reflect current cartel typologies

A sanctions screening engine cannot identify suspicious transactional behavior on its own.

FinCEN’s recent alerts describe activity involving cash movement, cross-border payments, bulk cash repatriation, fuel and crude oil transactions, informal value-transfer mechanisms, front companies, and other laundering methodologies.

Compliance teams should determine whether monitoring scenarios and investigative workflows reflect current government intelligence rather than static typologies built years ago.

This includes assessing whether teams can connect unusual transaction activity to customer geography, business purpose, counterparties, ownership information, and external risk intelligence.

3. Screening needs to extend beyond a direct sanctions match

OFAC continues to designate cartel members and affiliated entities, so effective sanctions and watchlist screening remains critical.

But network-based exposure creates a harder problem.

A customer could transact with a company controlled by an intermediary connected to a cartel. A supplier could have relationships with a sanctioned network. A seemingly legitimate business could later appear in enforcement reporting, investigative journalism, or government intelligence.

That makes entity resolution, beneficial ownership intelligence, relationship mapping, and contextual screening increasingly important.

The central question changes from:

“Is this customer sanctioned?”

to:

“What material risk exists around this customer, its owners, counterparties, relationships, and activity?”

4. Ongoing monitoring matters because risk changes after onboarding

A customer cleared today can present a very different risk profile six months from now.

An owner can be sanctioned. A counterparty can appear in adverse media. A previously unknown relationship can be identified. A jurisdiction can become the focus of regulatory action. New government intelligence can reveal a typology that changes how historical activity should be evaluated.

That is why perpetual KYC and continuous monitoring become particularly important for cartel and transnational criminal organization risk.

FinCEN and Treasury are continually releasing new names, entities, typologies, geographic intelligence, and enforcement information.

Controls need to be capable of responding when that information changes.

The questions compliance leaders should be asking now

The Southwest Border GTO provides an opportunity for institutions to pressure-test whether their broader financial crime controls can recognize evolving cartel exposure.

Key questions include:

  1. Can customer risk models incorporate granular geographic risk alongside behavioral and relationship signals?
  2. Do transaction monitoring scenarios reflect FinCEN’s most recent cartel-related typologies and red flags?
  3. Can screening identify aliases, ownership relationships, and indirect connections around sanctioned entities?
  4. Can investigators see sanctions, adverse media, corporate ownership, geography, transaction activity, and related entities together?
  5. Are high-risk customers and counterparties continuously monitored after onboarding?
  6. Can emerging adverse media or government intelligence trigger a reassessment of an existing customer?
  7. Can the institution demonstrate why an alert was generated, investigated, escalated, or cleared when regulators ask?

That final question may be the most important.

A modern compliance program needs more than detection. It needs defensible evidence that controls are capable of identifying material risk and that analysts can explain how decisions were reached.

From list screening to cartel risk intelligence

The regulatory response to Mexico-based cartels increasingly spans FinCEN alerts, Geographic Targeting Orders, OFAC sanctions, financial intelligence analysis, and targeted actions against businesses and financial networks associated with illicit activity.

Financial institutions should not interpret the September GTO as creating new requirements for businesses outside its legal scope.

But they should pay attention to what it reveals.

Regulators and law enforcement agencies are looking at cartel exposure through a much wider lens. Geography matters. Transactions matter. Counterparties matter. Ownership matters. Network relationships matter. Emerging intelligence matters.

A watchlist match may ultimately confirm the risk.

Strong financial crime controls should be capable of finding the warning signals before that happens.

Building a broader view of cartel exposure

Sigma360 brings sanctions and watchlist data, adverse media, corporate and ownership intelligence, continuous monitoring, entity resolution, and network-based risk intelligence into a unified environment.

That approach is particularly relevant where a risk cannot be reduced to a single name on a list.

Compliance teams can evaluate direct and indirect exposure across customers, counterparties, beneficial owners, associated entities, adverse media, and emerging risk indicators, while applying configurable workflows and maintaining the audit trail necessary to support investigative decisions.

Chartis Research has separately highlighted Sigma360’s global risk data, continuous screening, configurable alerting, precision matching, contextual intelligence, and ability to consolidate sanctions, PEP, adverse media, and transaction risk signals within a unified platform.

As government scrutiny of cartel financial networks continues, that broader view becomes increasingly important.

The question for compliance leaders is no longer only whether the institution can identify a sanctioned cartel member. It is whether the institution can recognize the financial network forming around that risk before an enforcement action makes the connection obvious.

About Sigma360 | The Standard in KYC & Financial Crime Compliance

Sigma360 is an AI-powered, full-stack risk intelligence platform that consolidates operations into one enterprise-grade system, enabling point-in-time risk screening and perpetual client monitoring for financial crime prevention and compliance operations. Sigma360 unifies global risk data, proprietary intelligence, core screening technology and AI automation in a secure cloud environment to find direct and network-based risks at sub-second speed, reduce false positives and strengthen risk and compliance operations.

Sigma360.com / Schedule a Demo / Free Trial / Connect on LinkedIn

Engage with us

Our Risk Intelligence Specialists can get you the answers you need.