Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
$350M Penalty: Six AML Mistakes You're MakingAML and KYC
6 min readFor AML/KYC Compliance Officers

$350M Penalty: Six AML Mistakes You're Making

American Express must pay a $350 million penalty after regulators cited "significant deficiencies" in its anti-money laundering (AML) program. This isn't just a headline to skim. When the Federal Reserve and the OCC impose such a penalty, they're signaling that foundational elements of an AML framework have failed.

Here's why this enforcement action is instructive: the deficiencies weren't obscure. They were structural failures in a program that should have caught them. If you're running an AML program at a bank, fintech, or payment company, you need to ask whether your controls would hold up under the same scrutiny.

Why These Mistakes Keep Happening

AML programs fail for predictable reasons. Teams build compliance frameworks that look complete on paper but break down in practice. You might implement transaction monitoring rules that generate too many false positives, leading analysts to ignore alerts. You might document policies but fail to enforce them consistently. You might hire compliance staff but not give them access to the data they need to investigate effectively.

The result: a program that satisfies a checklist but doesn't actually detect suspicious activity. Regulators don't fine you for missing one transaction. They fine you when your program's design makes it inevitable that you'll miss hundreds.

Mistake 1: Treating Suspicious Activity Reports as a Quota

Why it happens: Teams measure Suspicious Activity Report (SAR) filing as an output metric. Filing X reports per quarter doesn't mean the program is working. SAR volume isn't a success metric; it's a trailing indicator that something in your monitoring caught a pattern worth escalating.

The consequence: You either over-file to show activity (wasting investigator time and diluting the quality of your reporting to FinCEN) or under-file because you've tuned your rules to reduce noise. Both patterns show up in examinations. Examiners review your SAR narratives and compare them to your transaction data. If your filings don't reflect the risk profile of your customer base, your monitoring isn't calibrated correctly.

The fix: Start with your risk assessment. Map your customer segments to specific money laundering typologies. Then build monitoring scenarios that detect those typologies. Your SAR volume should correlate with your risk exposure, not with arbitrary targets. If you serve cross-border remittance customers, you should be filing SARs on structuring patterns. If you don't file any structuring SARs, your monitoring isn't working.

Mistake 2: Running Watchlist Screening as a One-Time Event

Why it happens: You screen customers at onboarding and assume that satisfies your sanctions obligations. But Politically Exposed Person status changes. The Office of Foreign Assets Control (OFAC) updates its list weekly. A customer who wasn't a match last year might be a match today.

The consequence: You're holding accounts for individuals now on sanctions lists, and you don't know it. When regulators examine your screening logs, they'll compare your last screening date to the date a name was added to the Specially Designated Nationals (SDN) list. If there's a gap, you've been facilitating transactions for a sanctioned party.

The fix: Implement continuous screening. Every time OFAC publishes an update, re-run your entire customer base against the new list. This isn't optional under the Bank Secrecy Act. You're required to have controls that prevent you from maintaining accounts for sanctioned individuals. One-time screening at onboarding doesn't meet that standard.

Mistake 3: Siloing AML Data Across Business Units

Why it happens: Your retail banking division has one transaction monitoring system. Your commercial lending team has another. Your payment processing subsidiary has a third. Each system generates alerts independently, and no one is aggregating activity across entities.

The consequence: A customer structures deposits across three accounts in different divisions, staying under your single-account threshold in each system. Your monitoring never flags the pattern because no single system sees the full picture. This is exactly the kind of deficiency regulators describe as "significant."

The fix: Build a consolidated view of customer activity before you apply monitoring rules. If you can't replace legacy systems immediately, create a data layer that aggregates transactions across platforms. Your transaction monitoring scenarios should run against the customer's total activity, not against individual accounts. This is technically complex, but it's not optional. The FFIEC BSA/AML Examination Manual explicitly requires you to monitor relationships, not just accounts.

Mistake 4: Documenting Risk Assessments You Don't Actually Use

Why it happens: You conduct an annual enterprise risk assessment because your policy requires it. You document inherent risk, residual risk, and control effectiveness. Then you file the document and continue operating your AML program the way you always have.

The consequence: Examiners will compare your risk assessment to your monitoring scenarios, staffing levels, and investigation procedures. If your risk assessment identifies cross-border wire transfers as high-risk but you don't have enhanced monitoring for those transactions, that's evidence your risk assessment isn't driving your control design. Regulators view this as a paper compliance exercise, not a functioning risk management framework.

The fix: Your risk assessment should directly determine your resource allocation. If you identify a new risk, document the corresponding control enhancement in the same quarter. If you can't implement a control immediately, document the gap and the timeline for remediation. Examiners want to see that your risk assessment is a management tool, not a compliance artifact.

Mistake 5: Understaffing Investigations Relative to Alert Volume

Why it happens: You tune your transaction monitoring to generate 1,000 alerts per month, then assign three investigators to clear them. The math doesn't work, so investigators spend 15 minutes per alert instead of conducting thorough investigations.

The consequence: You're dispositioning alerts without gathering sufficient evidence. When examiners sample your closed alerts, they'll find cases where you marked "no suspicious activity" without reviewing account statements, without checking for related parties, and without documenting your analysis. That's not an investigation. That's a backlog management strategy.

The fix: Either reduce your alert volume by refining your scenarios or increase your investigation capacity. Calculate the time required to properly investigate each alert type. A structuring alert might require 30 minutes. A trade-based money laundering alert might require four hours. Staff your team based on realistic time requirements, not based on wishful thinking about how fast investigators can work.

Mistake 6: Failing to Test Your Controls Independently

Why it happens: The compliance team designs the AML program and also validates that it's working. There's no independent testing function reviewing whether your transaction monitoring scenarios actually detect the risks they're designed to catch.

The consequence: Your controls drift over time. You implement a scenario to detect structuring, but a system upgrade changes how transaction amounts are aggregated, and the scenario stops firing. No one notices because no one is testing whether the control still works as designed.

The fix: Establish an independent testing function separate from the compliance team. This can be internal audit, a dedicated AML testing team, or a third party. They should test your monitoring scenarios by running known suspicious patterns through your system and verifying that alerts fire correctly. They should review your investigation procedures by re-performing a sample of closed cases. Document the testing methodology and the results, and remediate any control gaps immediately.

Prevention Checklist

Before your next examination, verify:

  • Your SAR filings reflect the risk profile of your customer base, not a target volume
  • You're screening your entire customer base every time OFAC publishes a list update
  • Your transaction monitoring aggregates activity across all accounts and entities for each customer
  • Your risk assessment directly determines your monitoring scenarios, staffing levels, and investigation procedures
  • Your investigation team has sufficient capacity to conduct thorough reviews of all alerts
  • An independent function tests your AML controls at least annually and validates they detect the risks they're designed to catch
  • You document control gaps and remediation timelines when you identify deficiencies

The American Express penalty demonstrates that "significant deficiencies" aren't theoretical risks. They're structural failures that regulators will find and penalize. Your job isn't to file more SARs or document more policies. It's to build a program that actually detects money laundering, and to prove that it works.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like