Skip to content
Free guide: How to use AI in compliance
← Back

The American Express AML penalty: $350 million for a card bank that assessed its deposits

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published October 9, 2026Reviewed by Charlene Wang
Editorial illustration for the article "The American Express AML penalty: $350 million for a card bank that assessed its deposits".

The OCC fined American Express National Bank $350 million on 8 October 2026 over $13 billion of suspected trade-based laundering. What the orders now require.

Table of contents

The American Express AML penalty is a $350 million civil money penalty the OCC imposed on American Express National Bank on 8 October 2026. The OCC found the bank failed to fully report roughly $13 billion of suspected trade-based money laundering from 2014 to 2025. A parallel Federal Reserve order targets the parent company's enterprise-wide controls.

  • The OCC issued a cease-and-desist consent order and a separate $350 million penalty order against American Express National Bank, Sandy, Utah, both dated 8 October 2026.
  • The OCC found about $13 billion of suspected trade-based money laundering processed from roughly June 2014 to May 2025, in some cases through accounts linked to bank insiders.
  • The cited violations cover the BSA/AML program, suspicious activity reporting, customer due diligence and the customer identification program.
  • The Federal Reserve issued its own cease-and-desist order against American Express Company and American Express Travel Related Services, including a separate OFAC compliance plan.
  • The bank neither admits nor denies the findings. American Express says the orders impose no asset cap.

What did the OCC find at American Express?

The American Express AML penalty rests on one finding: the bank never built a BSA/AML program reasonably designed for its real business. The bank is a major card issuer, but its risk assessment focused on its small deposit book. That gap fed weak due diligence, weak identity checks and a pattern of missed or late suspicious activity reports.

The OCC news release of 8 October 2026 announced two orders. The first is a cease-and-desist consent order, docket AA-ENF-2026-46, which sets out the remediation. The second is a civil money penalty order, docket AA-ENF-2026-47, for $350 million payable on execution and directed to the US Treasury.

The findings name four violations: 12 CFR 21.21 (the BSA/AML program rule), 12 CFR 21.11 (suspicious activity reports), 31 CFR 1020.210(a)(2)(v) (ongoing customer due diligence) and 31 CFR 1020.220(a)(2) (customer identification program verification). The OCC lists seven program failures. These are an untailored risk assessment, no effective framework for ongoing due diligence, gaps in identity verification, systemic breakdowns in suspicious activity monitoring, ineffective independent testing, under-resourced staffing and generic training.

Comptroller of the Currency Jonathan Gould said the bank "failed to maintain a BSA/AML compliance program properly aligned with the money laundering risks" of its operations, according to the OCC release. On identity, the order finds the bank's procedures did not let it form "a reasonable belief that it knew the true identity of each customer", the exact standard the customer identification program rule sets.

The money at the centre of the case is trade-based money laundering (TBML). From approximately June 2014 to approximately May 2025, the order says, the bank processed about $13 billion of suspected trade-based activity, combining suspicious card charges with the repayments of those charges, "in certain instances through accounts associated with Bank insiders". The bank filed some reports over that period but lacked the controls to see the full scope.

ItemDetail
Penalised entityAmerican Express National Bank, Sandy, Utah
Regulator and penaltyOCC, $350 million civil money penalty
Date of orders8 October 2026
Suspected activityAbout $13 billion of suspected trade-based laundering
PeriodAbout June 2014 to May 2025
Rules cited12 CFR 21.21, 12 CFR 21.11, 31 CFR 1020.210(a)(2)(v), 31 CFR 1020.220(a)(2)
Parallel actionFederal Reserve cease-and-desist order against the holding companies

How do the OCC and Federal Reserve orders split the work?

The OCC order fixes the bank; the Federal Reserve order fixes the group around it. The OCC sets bank-level controls and a look-back of past suspicious activity. The Fed requires board oversight and an enterprise-wide AML plan, an OFAC plan from the travel services company, and bars re-engaging anyone who took part in the misconduct, was disciplined and left.

The OCC's remediation articles require a rebuilt risk assessment and a written due diligence program with enhanced due diligence for higher-risk customers. They also require a financial crimes risk program covering third parties and ACH limits, a suspicious activity review program, and a staffing and skills assessment. The compliance committee must have at least three members, a majority of them directors who are not bank employees or officers.

Two articles stand out. Article IX orders an independent SAR look-back consultant to decide whether past activity needs new reports and whether filed reports need amending, and the OCC can widen its scope or period. Article XIII requires a dedicated insider activity program, which follows directly from the finding that insiders' accounts were involved.

The Federal Reserve order, docket 26-052-B-HC, is addressed to American Express Company and American Express Travel Related Services. It cites supervisory findings of weak transaction monitoring, fraud referral processes, third-party risk assessment and financial crimes risk management. The Fed order itself carries no money penalty.

DeadlineRequirementOrder
15 daysAppoint a compliance committeeOCC, Article III
30 days after each quarterCommittee progress report to the boardOCC, Article III
90 daysAction plan covering Articles V to XIIIOCC, Article IV
60 days after the look-back endsConsultant's written SAR look-back reportOCC, Article IX
90 daysBoard oversight plan and enterprise-wide AML planFederal Reserve, paragraphs 1 and 2
90 daysOFAC compliance plan from the travel services companyFederal Reserve, paragraph 3
45 days after each quarterProgress reports to the Reserve BankFederal Reserve, paragraph 7

How does this compare with recent AML penalties?

The American Express AML penalty follows a $15 million OCC penalty against the same bank in July 2023. It is smaller than TD Bank's $450 million OCC penalty of October 2024, which also carried a growth restriction.

That 2023 OCC penalty was partly because the bank failed to collect consumer information and keep records showing compliance with the customer identification program rules. Identity failings were flagged then and are cited again now, this time as a verification violation under 31 CFR 1020.220(a)(2).

ActionRegulatorAmountCore finding
American Express National Bank, 8 October 2026OCC$350 millionUntailored program, about $13 billion of suspected TBML not fully reported
TD Bank, 10 October 2024OCC$450 million plus growth restrictionSystemic monitoring and SAR breakdowns
UBS Financial Services, 3 August 2026FinCEN$125 millionRepeat wilful BSA violations
American Express National Bank, 25 July 2023OCC$15 millionThird-party affiliate oversight and CIP records

The TD Bank figures come from the OCC's 2024 release, and the UBS figures from FinCEN's announcement, covered in our UBS AML penalty analysis. Unlike the TD Bank action, which carried an OCC growth restriction, this one comes without an asset cap, according to the company's filing.

What does the American Express AML penalty change for your obligations?

The American Express AML penalty shows how examiners are testing four duties: the risk assessment, identity verification, ongoing due diligence and suspicious activity reporting. The order shows each one being tested against where the money actually flows, not against the product the program was written for. Firms whose main revenue line is not their regulated account product are most exposed.

Risk assessment. Article V requires risk categories that include products "inclusive of accessories and extensions", naming supplemental cardholders, plus customer type, insiders, geographies and delivery channels. If your card, lending or payments product carries most of your volume, your Bank Secrecy Act risk assessment has to model it first. In this order, a deposit-centric assessment at a card-centric business was the first deficiency listed under the 12 CFR 21.21 violation.

Customer identification program. The cited rule, 31 CFR 1020.220(a)(2), requires risk-based procedures that let a bank form a reasonable belief it knows each customer's true identity. The OCC found "inconsistent collection and risk-based verification" of identifying information. For any issuer, that means documenting how each onboarding channel verifies identity and evidencing that the method fits the channel's risk. Our customer identification program entry sets out the minimum data points.

Ongoing due diligence. The 2016 CDD rule, 31 CFR 1020.210(a)(2)(v), requires understanding the nature and purpose of each relationship and monitoring it on a risk basis. The order ties the failure to an inability to assign proper risk ratings. A customer due diligence file that never updates a card customer's expected activity cannot flag charges paired with unusual repayments.

Suspicious activity reporting. The SAR rule for national banks, 12 CFR 21.11, was breached as "a pattern or practice". Article VIII now requires monitoring rules, thresholds and filters across every business unit, with periodic validation. If your transaction monitoring cannot connect a charge to how it was repaid, it can miss the core pattern of card-based trade laundering.

Sanctions and insiders. The Fed order requires a separate OFAC plan at the travel services company, with screening procedures and risk methodology. The OCC order requires an insider activity program. Both sit outside the classic customer file, so a program built around CDD can leave them uncovered.

What remains uncertain, and what are the risks?

The American Express AML penalty closes the OCC's money claim, not the matter. The OCC order does not resolve other agencies' actions, including the Department of Justice's. The look-back may produce new reports, the OCC reserves action against individuals, and the Fed requires cooperation with its investigations of individuals. Remediation cost and duration are not disclosed.

The first open question is the look-back. Its scope, methodology and timeline still need OCC sign-off, and the OCC may order a supplemental look-back covering more subjects or a longer period. Late SARs on a decade of activity could become leads for law enforcement, and nothing in the OCC orders limits that.

The second is individual accountability: the OCC can still act against institution-affiliated parties, but neither order names individuals.

The third is the policy backdrop. In July 2026 the Federal Reserve proposed to reserve AML enforcement for "significant or systemic" failures, which we covered in our risk-based AML program rule analysis. That rule is still a proposal. This case shows that failures the regulators call systemic still draw large penalties under the current framework.

The fourth is cost and slippage. American Express told investors in an 8-K filing that part of the penalty was already reserved and that remediation costs are not expected to affect 2027 guidance. Most OCC deadlines after the 90-day action plan are set by that plan, so the full remediation timeline is not public.

Why is card-based trade laundering hard to catch?

Card-based trade laundering is hard to catch because each charge can look like an ordinary purchase until it is matched with how it was paid back. The OCC describes the suspected activity as a combination of suspicious charges and the associated repayments. Monitoring that reviews charges and repayments separately, or by product line, can miss the pair.

The OCC order's own remedy points the same way. It asks for monitoring that evaluates previous suspicious activity "across all business units", and a risk assessment that counts supplemental cards and third-party relationships. The lesson for any issuer is structural: the customer profile, the merchant relationship and the repayment source need to sit in one view. Our glossary entry on the stages of money laundering explains where this fits in layering.

How should compliance teams respond?

The first lesson is to check that your risk assessment ranks products by real volume and risk, not by which product the AML program was first written for. Then test whether monitoring links charges to repayment sources, whether identity verification is documented per channel, and whether insider accounts get their own surveillance.

Concrete steps follow from the order's articles. Re-rate your products, including supplemental and secondary cards, against current volumes. Map each onboarding channel to the identity verification method it uses and record why that method fits the risk. Refresh customer risk ratings that have not changed since onboarding. Add a scenario that pairs card charges with unusual repayment sources. Give insider accounts a separate monitoring and referral route, and confirm your independent testing covers the dominant product, not just deposits.

Zyphe helps teams evidence the identity layer: chip-read document verification to ICAO 9303, two-step liveness and an exportable audit trail, with no central store of customer PII. See our KYC software and AML software, or book a demo.

The bottom line

The American Express AML penalty is a case about fit. A card issuer ran a program shaped around a minor deposit product, and the controls never caught up with where the money moved. The orders now require a risk assessment, identity checks, due diligence and monitoring built around the dominant product, with a look-back that may reopen a decade of activity. Any firm whose regulated account is not its main business line should test its own program against that same question of fit.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

The OCC imposed a $350 million civil money penalty on American Express National Bank on 8 October 2026, payable on execution of the order and directed to the US Treasury. The Federal Reserve's parallel order against the holding companies imposes remediation duties but no separate money penalty.

The OCC found the bank's BSA/AML program was not tailored to its card business, with gaps in customer identification, ongoing due diligence, suspicious activity monitoring, independent testing, staffing and training. As a result, about $13 billion of suspected trade-based money laundering from 2014 to 2025 was not fully identified and reported. The bank neither admits nor denies the findings.

No. American Express stated in its 8-K filing that the consent orders do not impose an asset cap. That contrasts with the OCC's 2024 action against TD Bank, which included a restriction on the bank's growth alongside a $450 million penalty.

A SAR look-back is an independent review of past activity to decide whether suspicious activity reports should have been filed or need correcting. The OCC order requires American Express National Bank to hire a consultant approved by the OCC to run one, and the OCC can widen its scope or period.

No. That proposal, to focus AML enforcement on significant or systemic failures, is the Federal Reserve's and has not been adopted; this penalty is the OCC's. The OCC described the American Express failures as systemic breakdowns and a pattern or practice of SAR noncompliance, the kind of failure the proposal would still target.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo