SEC Fines Merrill Lynch $7.5 Million for SAR Reporting Failures
The U.S. Securities and Exchange Commission (SEC) has imposed a $7.5 million civil penalty on Merrill Lynch, Pierce, Fenner & Smith Incorporated for failing to file numerous Suspicious Activity...
The U.S. Securities and Exchange Commission (SEC) has imposed a $7.5 million civil penalty on Merrill Lynch, Pierce, Fenner & Smith Incorporated for failing to file numerous Suspicious Activity Reports (SARs), underscoring regulators’ growing scrutiny of transaction monitoring effectiveness and AML governance.
According to the SEC’s settled order, the reporting failures occurred between April 2020 and September 2024, during which Merrill relied on Bank of America’s enterprise-wide Bank Secrecy Act (BSA)/Anti-Money Laundering (AML) monitoring framework to meet its independent SAR filing obligations.
The regulator found that the firm’s transaction monitoring system grouped potentially suspicious transactions into “event groups” and assigned them risk scores. However, only event groups that exceeded a predefined threshold were escalated for investigation. Internal analyses dating back to April 2020 indicated that many lower-risk-scoring event groups would likely have resulted in SAR filings had they been reviewed, yet they remained uninvestigated for several years.
The SEC concluded that Merrill’s failure to investigate these alerts resulted in numerous missed SAR filings, violating Section 17(a) of the Securities Exchange Act of 1934 and Rule 17a-8, which require broker-dealers to maintain effective AML programmes and comply with SAR reporting obligations. Without admitting or denying the findings, Merrill agreed to a cease-and-desist order, a censure, and payment of the $7.5 million penalty.
Compliance Takeaways
The enforcement action reinforces that regulators are evaluating not only whether firms have transaction monitoring systems in place, but also whether those systems are appropriately calibrated, validated, and governed.
For compliance professionals, the case highlights several key expectations:
- Regular validation of transaction monitoring models and alert thresholds.
- Independent oversight of automated monitoring systems rather than sole reliance on enterprise-wide controls.
- Timely investigation of alerts supported by internal risk assessments.
- Continuous governance to ensure monitoring methodologies evolve with changing financial crime risks.
- The Merrill Lynch settlement serves as another reminder that ineffective alert thresholds can create blind spots in AML programmes, exposing firms to regulatory enforcement even where monitoring technology is in place. Regulators increasingly expect institutions to demonstrate that their systems identify, escalate, and report suspicious activity effectively—not merely that automated controls exist.



No Comment! Be the first one.