American Express – OCC Findings

Reported by OCC

(Obtained without editorial changes from: https://www.occ.gov/news-issuances/news-releases/2026/nr-occ-2026-87b.pdf)

The Comptroller finds, and the Bank neither admits nor denies, the following:

(1) The Bank is one of the largest credit and charge card issuers in the United States by transaction volume. However, the Bank has not established and maintained a reasonably designed BSA/AML compliance program. The Bank’s BSA/AML program has systemic internal control gaps and weak independent testing and BSA/AML training for employees and directors.

(2) The critical deficiencies of the Bank’s BSA/AML compliance program that resulted in a violation of 12 C.F.R. § 21.21, include the following:

(a) The Bank’s risk assessment was not appropriately tailored to its business activities because it focused on the risks in the Bank’s relatively narrow demand deposit account products and services and insufficiently on the risks in its more dominant credit and charge card products;

(b) The Bank failed to establish and maintain an effective framework to conduct ongoing CDD and understand the nature and purpose of customer relationships. This prevented the Bank from assigning appropriate risk ratings and conducting effective ongoing monitoring to identify and report suspicious activity;

(c) The Bank’s CIP procedures had substantial gaps and did not enable the Bank to form a reasonable belief that it knew the true identity of each customer. These gaps resulted in inconsistent collection and risk-based verification of customer identification information;

(d) The Bank had systemic breakdowns in its suspicious activity monitoring, investigation, and reporting processes, resulting in a pattern or practice of noncompliance with the SAR filing requirements. Weaknesses in the Bank’s controls surrounding SARs were significant and resulted in untimely, missed, or incomplete SARs, relating both to suspected trade-based money laundering (TBML) activity and other suspicious activity;

(e) The Bank’s internal audit group did not effectively monitor the Bank’s compliance with BSA/AML regulatory requirements. Independent testing was not appropriate in scope or effective relative to the Bank’s BSA/AML risk profile. This ineffective independent testing contributed to the failure to timely detect and remediate BSA/AML deficiencies, including the deficiencies that permitted suspected TBML and other suspicious activity to be processed by the Bank;

(f) The Bank has not historically supported the BSA/AML compliance program with appropriate resources, including staffing with commensurate skills, expertise, and training to appropriately administer the program; and

(g) The BSA/AML training program lacked appropriate risk-based BSA/AML training that effectively addressed employees’ job-specific responsibilities and duties. The lack of proper BSA/AML training impaired the Bank’s ability to appropriately identify, escalate, and report on BSA/AML compliance risks, red flags, and suspicious activity.

(3) A significant result of the deficiencies in the Bank’s BSA/AML compliance program was its failure to timely identify, evaluate, and sufficiently report suspicious activity related to its processing of suspected TBML activity. From approximately June 2014 to approximately May 2025, the Bank processed approximately $13 billion in suspected TBML activity, including a combination of suspicious card charges and associated repayments of those card charges, and including in certain instances through accounts associated with Bank insiders. Over this time period, the Bank periodically reported suspicious activity but lacked the internal controls and monitoring capabilities to timely identify and report the full scope of this activity.

(4) These deficiencies resulted in a BSA/AML program violation under 12 C.F.R. § 21.21 (see also 31 U.S.C. §§ 5318(h)(1), 31 C.F.R. § 1020.210(a)) and additional violations of regulations, including 12 C.F.R. § 21.11 (SAR violations), 31 C.F.R. § 1020.210(a)(2)(v) (CDD violation), and 31 C.F.R. § 1020.220(a)(2) (CIP violation).

(5) The Bank’s violations were part of a pattern of misconduct and caused more than a minimal loss to the Bank.

Leave a Reply