OCC Assesses $350 Million Civil Money Penalty Against American Express
AI Analysis
The OCC imposed a $350 million civil money penalty and issued a cease-and-desist order against American Express National Bank for systemic BSA/AML weaknesses, including inadequate resources and expertise, internal-control and independent-testing deficiencies, weak training, an improperly scoped risk assessment, and breakdowns in suspicious-activity monitoring and reporting. The OCC said the bank failed to timely identify, evaluate, and sufficiently report approximately $13 billion of suspected trade-based money-laundering activity from approximately June 2014 through May 2025, underscoring that card-focused banks must align AML controls with their dominant products rather than principally with deposit-account risks.
Key dates
- 2026-10-08
- The OCC announced the cease-and-desist order and $350 million civil money penalty against American Express National Bank; the Federal Reserve announced a coordinated action against American Express Company and American Express Travel Related Services Company.
Suggested considerations
- Compliance teams may wish to reassess whether the BSA/AML risk assessment accurately reflects the institution's largest and most complex products, customer segments, payment flows, geographies, channels, and transaction types, rather than relying primarily on deposit-account risk.
- Firms should consider testing whether customer identification, customer due diligence, beneficial-ownership information, and account-risk-rating processes provide sufficiently complete and reliable data for transaction monitoring and suspicious-activity reporting.
- Banks may wish to conduct a targeted lookback for trade-based money-laundering indicators in card, merchant, payment, cross-border, and related repayment activity, including activity involving insiders or connected accounts, and document escalation and reporting decisions.
- Compliance teams should consider validating that monitoring scenarios, alert thresholds, investigative workflows, case-management controls, quality assurance, and SAR filing processes can identify and report suspicious activity within applicable regulatory timeframes.
- Boards and senior management may wish to review whether BSA/AML staffing levels, expertise, reporting lines, technology, data governance, and independent-testing coverage are proportionate to the institution's size, complexity, and risk profile.
- Firms should consider strengthening role-based BSA/AML training for employees, directors, and senior management, with evidence of completion, competency, and periodic refreshers.
- Internal audit or another suitably independent function may wish to perform end-to-end testing of risk assessment, customer due diligence, monitoring, investigation, SAR decisioning, and governance controls, with tracked remediation and board-level reporting.
- U.S. banking organizations may wish to compare their programs against the OCC's findings and the market commentary emphasizing that the principal lesson is product-risk misalignment and the need for enterprise-wide controls, not merely remediation of isolated monitoring alerts.
What changed
This is an enforcement action and supervisory precedent, not a new generally applicable rule. The OCC required American Express National Bank to remediate a BSA/AML program that was not reasonably designed to assure and monitor compliance with the BSA and its implementing regulations. The findings specifically reinforce expectations that risk assessments cover the institution's actual product mix, including credit and charge cards; customer identification and customer due-diligence procedures support effective monitoring; transaction-monitoring and suspicious-activity reporting processes identify, investigate, evaluate, and report activity timely; staffing includes sufficient subject-matter expertise; internal controls and independent testing are effective; and BSA/AML training covers empl
Compliance impact
The action is highly severe because it combines a substantial penalty with a cease-and-desist order and concerns systemic program failures over approximately a decade, including missed suspicious activity of approximately $13 billion. The consequences include substantial financial exposure, heightened supervisory scrutiny, remediation and independent-testing costs, potential reputational damage, a
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original OCC source before acting. Full disclaimer.
What the OCC said
The Office of the Comptroller of the Currency (OCC) today announced a cease-and-desist order and a $350 million civil money penalty against American Express National Bank, Sandy, Utah (bank), for deficiencies in the bank's Bank Secrecy Act (BSA) and anti-money laundering (AML) compliance program.
Published by OCC . Read the full notice at the source for the authoritative text.