OCC Puts Bank of America Under the Microscope Over AML Failures
The US banking regulator has ordered Bank of America to overhaul parts of its anti-money laundering and sanctions compliance framework after identifying weaknesses in suspicious activity reporting,...
The US banking regulator has ordered Bank of America to overhaul parts of its anti-money laundering and sanctions compliance framework after identifying weaknesses in suspicious activity reporting, customer due diligence, internal controls, transaction monitoring, training and governance.
The Office of the Comptroller of the Currency, OCC, issued a cease-and-desist order against Bank of America, N.A., after identifying deficiencies in the bank’s Bank Secrecy Act and sanctions compliance programmes. The regulator’s findings cover several parts of the bank’s AML architecture, rather than a single isolated control failure.
According to AML Watcher, the deficiencies included weaknesses in risk assessments, customer due diligence, internal controls, employee training, transaction monitoring and models, independent testing, internal audit and the role of the bank’s BSA officer. The OCC also cited failures involving the timely filing of suspicious activity reports and a previously identified weakness in the bank’s customer due diligence processes.
The order requires Bank of America to take corrective action and bring its BSA and sanctions compliance programmes into compliance with OCC requirements. It also requires an independent consultant to review the programmes and conduct lookback work to determine whether suspicious activity was appropriately identified and reported.
The governance requirements are significant. Within 30 days of the order, the bank’s board was required to establish a compliance committee comprising three members, with a majority serving as independent directors. The committee is responsible for overseeing the remediation programme.
Bank of America said it had already been working with the OCC to strengthen its AML and sanctions programmes and that the work completed before the order put it in a position to implement the required measures.
Compliance Analysis
The important point here is the breadth of the deficiencies.
This was not simply a transaction monitoring problem. The OCC identified weaknesses stretching from customer onboarding and risk assessment to suspicious activity reporting, testing, training and board oversight.
That matters because AML programmes are interconnected. Poor customer due diligence can weaken transaction monitoring. Weak transaction monitoring can lead to missed suspicious activity. Poor governance can allow those weaknesses to persist.
The OCC’s requirement for an independent lookback is particularly important. It moves the question beyond whether the bank has fixed its systems today. The regulator wants to know whether suspicious activity may have been missed previously.
For other financial institutions, the warning is fairly direct. A compliance programme cannot be judged by how impressive its policies look. Regulators will ultimately test whether those policies work in practice.
AML Takeaway: The Bank of America action shows that regulators are increasingly examining the entire AML control environment, including governance, staffing, customer due diligence, monitoring, reporting and independent testing. Fixing one defective control will not be enough where weaknesses are systemic.



No Comment! Be the first one.