Skip to main content
Capital One's $390M Fine: What 16 Billion in Unreported Transactions Reveal About AML Control FailuresAML and KYC
5 min readFor AML/KYC Compliance Officers

Capital One's $390M Fine: What 16 Billion in Unreported Transactions Reveal About AML Control Failures

What Happened

Capital One was fined $390 million for willful and negligent violations of the Bank Secrecy Act. The institution failed to report transactions worth $16 billion despite receiving warnings from regulators. This wasn't about missing a few alerts; it was a systemic control breakdown.

The failure occurred amid increasingly strict AML regulations. The EU introduced the Fourth Anti-Money Laundering Directive in 2017 and the Fifth in 2020, reflecting a global tightening of AML frameworks. Capital One's penalty shows what happens when your program doesn't keep pace.

Timeline and Control Breakdown

The phrase "despite warnings from regulators" indicates this wasn't a sudden failure. Regulatory warnings precede enforcement actions. You receive examination findings, you're given time to remediate, and if you don't, penalties follow.

The $16 billion figure indicates sustained, large-scale monitoring failure. This volume suggests either:

  • Transaction monitoring rules were misconfigured or too permissive
  • Alerts were generated but not investigated
  • Suspicious Activity Reports (SARs) were drafted but not filed
  • Escalation procedures broke down between detection and reporting

Any of these scenarios point to control failures across multiple program elements.

Which Controls Failed

Transaction Monitoring
Your transaction monitoring system exists to flag unusual patterns and volumes. When $16 billion in reportable transactions slip through, your rules are either missing key typologies or your thresholds are set so high they're meaningless.

The Bank Secrecy Act requires you to monitor for patterns consistent with money laundering. If your system isn't surfacing transactions that regulators later determine should have been reported, you're not meeting that requirement.

Suspicious Activity Reporting
Even if monitoring flagged some transactions, failing to file SARs indicates a breakdown in your investigation and escalation process. The FFIEC BSA/AML Examination Manual requires timely SAR filing when you identify suspicious activity. "Timely" means within 30 days of initial detection.

If your investigators are overwhelmed, lack training, or if your escalation chain has gaps, SARs don't get filed.

Management Oversight
Regulatory warnings should trigger immediate executive attention. The fact that warnings didn't result in remediation suggests either:

  • Senior management wasn't informed of the deficiencies
  • They were informed but didn't allocate resources to fix them
  • Remediation plans were inadequate

The Bank Secrecy Act places responsibility on senior management to ensure program effectiveness. You can't delegate that accountability.

Risk Assessment
A proper AML risk assessment should have identified the gaps in your monitoring coverage. If your assessment rated your transaction monitoring as effective while $16 billion in transactions went unreported, your assessment methodology is flawed.

Risk assessments should surface control gaps before regulators do.

What the Standard Requires

Bank Secrecy Act: Core Obligations
The BSA requires financial institutions to establish and maintain procedures to detect and report suspicious transactions. This includes:

  • Filing SARs within 30 days of initial detection
  • Maintaining records of transactions over $10,000
  • Implementing a written AML program approved by the board

Your program must be risk-based and commensurate with your institution's size and complexity.

FFIEC BSA/AML Examination Manual: Program Elements
The manual specifies that your AML program must include:

  • A system of internal controls
  • Independent testing of the program
  • Designation of a compliance officer
  • Ongoing employee training

"Internal controls" means your transaction monitoring system, your SAR decision-making process, and your escalation procedures. All of which failed in this case.

USA PATRIOT Act: Enhanced Due Diligence
The PATRIOT Act expanded BSA requirements, particularly around customer due diligence and beneficial ownership identification. While the Capital One case centers on transaction reporting, due diligence failures often contribute to monitoring gaps. If you don't understand your customer's expected activity, you can't identify what's unusual.

Lessons and Action Items for Your Team

Audit Your Monitoring Rules Against Known Typologies
Pull your transaction monitoring rule library. Map each rule to specific money laundering typologies: structuring, trade-based laundering, funnel accounts, rapid movement schemes. If you have typologies without corresponding rules, you have coverage gaps.

Test your thresholds. Run historical data through your system with thresholds lowered by 25%. How many additional alerts would you generate? If the answer is "thousands," your thresholds might be too high. If it's "zero," your rules might not be working at all.

Measure Your SAR Filing Rate Against Alert Volume
Calculate: (SARs filed / alerts generated) by quarter. A very low percentage might indicate over-alerting. A rate that never changes might indicate investigators aren't actually investigating, they're just clearing queues.

Compare your filing rate to peer institutions of similar size and customer base. Significant deviation in either direction warrants explanation.

Validate Your Escalation Chain
Document the path from alert generation to SAR filing. Who reviews? Who approves? What's the maximum time allowed at each step? Then test it. Generate a mock high-risk alert and track how long it takes to reach a filing decision.

If regulatory warnings didn't trigger remediation, your escalation to senior management is broken. Create a formal process: examination findings go to the board within 10 days, with a remediation plan within 30.

Stress-Test Your Risk Assessment
Your risk assessment should predict control failures before they happen. Review the Capital One scenario: could your assessment methodology have identified a $16 billion reporting gap? If not, your assessment is too high-level.

Make your assessment quantitative where possible. Don't just rate transaction monitoring risk as "medium." Measure: percentage of transaction volume covered by rules, average time from alert to SAR decision, percentage of SARs filed within the 30-day window.

Treat Regulatory Warnings as Incidents
When you receive examination findings, activate your incident response process. Assign an owner, set a remediation deadline, allocate budget and resources, and report progress to the board monthly until closure.

Capital One's penalty wasn't for the initial failure. It was for failing to remediate after being warned. Your response to findings matters as much as your initial controls.

The $390 million fine represents roughly $24 per unreported million. That's the cost of control failure at scale. Your transaction monitoring system isn't just a compliance checkbox. It's your first line of defense against becoming a case study.

You Might Also Like