The OCC fined American Express National Bank $350 million on 8 October 2026 over $13 billion of suspected trade-based laundering. What the orders now require.
Table of contents
The American Express AML penalty is a $350 million civil money penalty the OCC imposed on American Express National Bank on 8 October 2026. The OCC found the bank failed to fully report roughly $13 billion of suspected trade-based money laundering from 2014 to 2025. A parallel Federal Reserve order targets the parent company's enterprise-wide controls.
- The OCC issued a cease-and-desist consent order and a separate $350 million penalty order against American Express National Bank, Sandy, Utah, both dated 8 October 2026.
- The OCC found about $13 billion of suspected trade-based money laundering processed from roughly June 2014 to May 2025, in some cases through accounts linked to bank insiders.
- The cited violations cover the BSA/AML program, suspicious activity reporting, customer due diligence and the customer identification program.
- The Federal Reserve issued its own cease-and-desist order against American Express Company and American Express Travel Related Services, including a separate OFAC compliance plan.
- The bank neither admits nor denies the findings. American Express says the orders impose no asset cap.
What did the OCC find at American Express?
The American Express AML penalty rests on one finding: the bank never built a BSA/AML program reasonably designed for its real business. The bank is a major card issuer, but its risk assessment focused on its small deposit book. That gap fed weak due diligence, weak identity checks and a pattern of missed or late suspicious activity reports.
The OCC news release of 8 October 2026 announced two orders. The first is a cease-and-desist consent order, docket AA-ENF-2026-46, which sets out the remediation. The second is a civil money penalty order, docket AA-ENF-2026-47, for $350 million payable on execution and directed to the US Treasury.
The findings name four violations: 12 CFR 21.21 (the BSA/AML program rule), 12 CFR 21.11 (suspicious activity reports), 31 CFR 1020.210(a)(2)(v) (ongoing customer due diligence) and 31 CFR 1020.220(a)(2) (customer identification program verification). The OCC lists seven program failures. These are an untailored risk assessment, no effective framework for ongoing due diligence, gaps in identity verification, systemic breakdowns in suspicious activity monitoring, ineffective independent testing, under-resourced staffing and generic training.
Comptroller of the Currency Jonathan Gould said the bank "failed to maintain a BSA/AML compliance program properly aligned with the money laundering risks" of its operations, according to the OCC release. On identity, the order finds the bank's procedures did not let it form "a reasonable belief that it knew the true identity of each customer", the exact standard the customer identification program rule sets.
The money at the centre of the case is trade-based money laundering (TBML). From approximately June 2014 to approximately May 2025, the order says, the bank processed about $13 billion of suspected trade-based activity, combining suspicious card charges with the repayments of those charges, "in certain instances through accounts associated with Bank insiders". The bank filed some reports over that period but lacked the controls to see the full scope.
| Item | Detail |
|---|---|
| Penalised entity | American Express National Bank, Sandy, Utah |
| Regulator and penalty | OCC, $350 million civil money penalty |
| Date of orders | 8 October 2026 |
| Suspected activity | About $13 billion of suspected trade-based laundering |
| Period | About June 2014 to May 2025 |
| Rules cited | 12 CFR 21.21, 12 CFR 21.11, 31 CFR 1020.210(a)(2)(v), 31 CFR 1020.220(a)(2) |
| Parallel action | Federal Reserve cease-and-desist order against the holding companies |
How do the OCC and Federal Reserve orders split the work?
The OCC order fixes the bank; the Federal Reserve order fixes the group around it. The OCC sets bank-level controls and a look-back of past suspicious activity. The Fed requires board oversight and an enterprise-wide AML plan, an OFAC plan from the travel services company, and bars re-engaging anyone who took part in the misconduct, was disciplined and left.
The OCC's remediation articles require a rebuilt risk assessment and a written due diligence program with enhanced due diligence for higher-risk customers. They also require a financial crimes risk program covering third parties and ACH limits, a suspicious activity review program, and a staffing and skills assessment. The compliance committee must have at least three members, a majority of them directors who are not bank employees or officers.
Two articles stand out. Article IX orders an independent SAR look-back consultant to decide whether past activity needs new reports and whether filed reports need amending, and the OCC can widen its scope or period. Article XIII requires a dedicated insider activity program, which follows directly from the finding that insiders' accounts were involved.
The Federal Reserve order, docket 26-052-B-HC, is addressed to American Express Company and American Express Travel Related Services. It cites supervisory findings of weak transaction monitoring, fraud referral processes, third-party risk assessment and financial crimes risk management. The Fed order itself carries no money penalty.
| Deadline | Requirement | Order |
|---|---|---|
| 15 days | Appoint a compliance committee | OCC, Article III |
| 30 days after each quarter | Committee progress report to the board | OCC, Article III |
| 90 days | Action plan covering Articles V to XIII | OCC, Article IV |
| 60 days after the look-back ends | Consultant's written SAR look-back report | OCC, Article IX |
| 90 days | Board oversight plan and enterprise-wide AML plan | Federal Reserve, paragraphs 1 and 2 |
| 90 days | OFAC compliance plan from the travel services company | Federal Reserve, paragraph 3 |
| 45 days after each quarter | Progress reports to the Reserve Bank | Federal Reserve, paragraph 7 |
How does this compare with recent AML penalties?
The American Express AML penalty follows a $15 million OCC penalty against the same bank in July 2023. It is smaller than TD Bank's $450 million OCC penalty of October 2024, which also carried a growth restriction.
That 2023 OCC penalty was partly because the bank failed to collect consumer information and keep records showing compliance with the customer identification program rules. Identity failings were flagged then and are cited again now, this time as a verification violation under 31 CFR 1020.220(a)(2).
| Action | Regulator | Amount | Core finding |
|---|---|---|---|
| American Express National Bank, 8 October 2026 | OCC | $350 million | Untailored program, about $13 billion of suspected TBML not fully reported |
| TD Bank, 10 October 2024 | OCC | $450 million plus growth restriction | Systemic monitoring and SAR breakdowns |
| UBS Financial Services, 3 August 2026 | FinCEN | $125 million | Repeat wilful BSA violations |
| American Express National Bank, 25 July 2023 | OCC | $15 million | Third-party affiliate oversight and CIP records |
The TD Bank figures come from the OCC's 2024 release, and the UBS figures from FinCEN's announcement, covered in our UBS AML penalty analysis. Unlike the TD Bank action, which carried an OCC growth restriction, this one comes without an asset cap, according to the company's filing.
What does the American Express AML penalty change for your obligations?
The American Express AML penalty shows how examiners are testing four duties: the risk assessment, identity verification, ongoing due diligence and suspicious activity reporting. The order shows each one being tested against where the money actually flows, not against the product the program was written for. Firms whose main revenue line is not their regulated account product are most exposed.
Risk assessment. Article V requires risk categories that include products "inclusive of accessories and extensions", naming supplemental cardholders, plus customer type, insiders, geographies and delivery channels. If your card, lending or payments product carries most of your volume, your Bank Secrecy Act risk assessment has to model it first. In this order, a deposit-centric assessment at a card-centric business was the first deficiency listed under the 12 CFR 21.21 violation.
Customer identification program. The cited rule, 31 CFR 1020.220(a)(2), requires risk-based procedures that let a bank form a reasonable belief it knows each customer's true identity. The OCC found "inconsistent collection and risk-based verification" of identifying information. For any issuer, that means documenting how each onboarding channel verifies identity and evidencing that the method fits the channel's risk. Our customer identification program entry sets out the minimum data points.
Ongoing due diligence. The 2016 CDD rule, 31 CFR 1020.210(a)(2)(v), requires understanding the nature and purpose of each relationship and monitoring it on a risk basis. The order ties the failure to an inability to assign proper risk ratings. A customer due diligence file that never updates a card customer's expected activity cannot flag charges paired with unusual repayments.
Suspicious activity reporting. The SAR rule for national banks, 12 CFR 21.11, was breached as "a pattern or practice". Article VIII now requires monitoring rules, thresholds and filters across every business unit, with periodic validation. If your transaction monitoring cannot connect a charge to how it was repaid, it can miss the core pattern of card-based trade laundering.
Sanctions and insiders. The Fed order requires a separate OFAC plan at the travel services company, with screening procedures and risk methodology. The OCC order requires an insider activity program. Both sit outside the classic customer file, so a program built around CDD can leave them uncovered.
What remains uncertain, and what are the risks?
The American Express AML penalty closes the OCC's money claim, not the matter. The OCC order does not resolve other agencies' actions, including the Department of Justice's. The look-back may produce new reports, the OCC reserves action against individuals, and the Fed requires cooperation with its investigations of individuals. Remediation cost and duration are not disclosed.
The first open question is the look-back. Its scope, methodology and timeline still need OCC sign-off, and the OCC may order a supplemental look-back covering more subjects or a longer period. Late SARs on a decade of activity could become leads for law enforcement, and nothing in the OCC orders limits that.
The second is individual accountability: the OCC can still act against institution-affiliated parties, but neither order names individuals.
The third is the policy backdrop. In July 2026 the Federal Reserve proposed to reserve AML enforcement for "significant or systemic" failures, which we covered in our risk-based AML program rule analysis. That rule is still a proposal. This case shows that failures the regulators call systemic still draw large penalties under the current framework.
The fourth is cost and slippage. American Express told investors in an 8-K filing that part of the penalty was already reserved and that remediation costs are not expected to affect 2027 guidance. Most OCC deadlines after the 90-day action plan are set by that plan, so the full remediation timeline is not public.
Why is card-based trade laundering hard to catch?
Card-based trade laundering is hard to catch because each charge can look like an ordinary purchase until it is matched with how it was paid back. The OCC describes the suspected activity as a combination of suspicious charges and the associated repayments. Monitoring that reviews charges and repayments separately, or by product line, can miss the pair.
The OCC order's own remedy points the same way. It asks for monitoring that evaluates previous suspicious activity "across all business units", and a risk assessment that counts supplemental cards and third-party relationships. The lesson for any issuer is structural: the customer profile, the merchant relationship and the repayment source need to sit in one view. Our glossary entry on the stages of money laundering explains where this fits in layering.
How should compliance teams respond?
The first lesson is to check that your risk assessment ranks products by real volume and risk, not by which product the AML program was first written for. Then test whether monitoring links charges to repayment sources, whether identity verification is documented per channel, and whether insider accounts get their own surveillance.
Concrete steps follow from the order's articles. Re-rate your products, including supplemental and secondary cards, against current volumes. Map each onboarding channel to the identity verification method it uses and record why that method fits the risk. Refresh customer risk ratings that have not changed since onboarding. Add a scenario that pairs card charges with unusual repayment sources. Give insider accounts a separate monitoring and referral route, and confirm your independent testing covers the dominant product, not just deposits.
Zyphe helps teams evidence the identity layer: chip-read document verification to ICAO 9303, two-step liveness and an exportable audit trail, with no central store of customer PII. See our KYC software and AML software, or book a demo.
The bottom line
The American Express AML penalty is a case about fit. A card issuer ran a program shaped around a minor deposit product, and the controls never caught up with where the money moved. The orders now require a risk assessment, identity checks, due diligence and monitoring built around the dominant product, with a look-back that may reopen a decade of activity. Any firm whose regulated account is not its main business line should test its own program against that same question of fit.
Cited sources
- OCC News Release 2026-87: $350 million civil money penalty against American Express
- OCC cease-and-desist consent order, American Express National Bank, AA-ENF-2026-46
- OCC civil money penalty consent order, AA-ENF-2026-47
- Federal Reserve Board press release, 8 October 2026
- Federal Reserve cease-and-desist order, American Express Company and TRS, docket 26-052-B-HC
- American Express Company Form 8-K, 8 October 2026
- OCC News Release 2024-116: TD Bank cease-and-desist order and $450 million penalty
- OCC News Release 2023-78: $15 million penalty against American Express National Bank
- 31 CFR 1020.220, customer identification program requirements for banks (eCFR)
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.