Skip to main content
Three Banks Ignored $170M in Suspicious PaymentsAML and KYC
5 min readFor AML/KYC Compliance Officers

Three Banks Ignored $170M in Suspicious Payments

The Challenge

JPMorganChase, Deutsche Bank, and Bank of America failed to file timely Suspicious Activity Reports (SARs) for over $170 million in payments from billionaire Leon Black to Jeffrey Epstein. A Senate Finance Committee investigation led by Sen. Ron Wyden revealed that these banks processed thousands of transactions that should have triggered enhanced due diligence under the Bank Secrecy Act, but they weren't flagged until after Epstein's 2019 arrest on sex-trafficking charges.

These weren't procedural gaps. Internal compliance teams at JPMorganChase raised human-trafficking concerns before formally terminating Epstein as a client, yet senior leadership maintained informal relationships with him to access other ultra-wealthy clients. Deutsche Bank ignored large cash withdrawals without documented business purposes. Bank of America processed payments through Black's accounts without verifying the purpose.

This wasn't a case of sophisticated schemes evading detection. The red flags were visible and documented internally. The question your compliance program needs to answer: what happens when relationship managers override compliance escalations?

The Environment and Constraints

Each bank was obligated under the Bank Secrecy Act to file SARs when transactions lacked apparent lawful purpose or when customers appeared to structure activity to evade reporting thresholds. Large cash transactions over $10,000 require reporting. While wire transfers don't trigger automatic reporting, patterns of high-value transfers without documented business rationale require enhanced due diligence and potential SAR filing.

JPMorganChase served as Epstein's primary bank from 1998 to 2013. Deutsche Bank took over from 2013 until Epstein's death in 2019. Bank of America held accounts for Black used specifically to pay Epstein between 2012 and 2017.

These weren't small regional banks struggling with resource limitations. They had mature AML programs, dedicated compliance teams, and sophisticated transaction monitoring systems. JPMorganChase reported flagging suspicious transactions "as early as 2002" to government agencies, yet the Senate investigation found evidence of thousands of unreported transactions and delayed reporting years past the relationship's formal termination.

The competitive pressure was explicit. Senior bankers at all three institutions viewed Epstein as a conduit to other billionaire clients, creating an incentive structure where compliance concerns became obstacles to revenue.

The Approach Taken

The banks' responses followed a pattern: flag some activity, maintain the relationship, delay comprehensive reporting until external pressure forced action.

JPMorganChase's approach illustrates the problem. The bank's internal compliance personnel raised warnings about Epstein's activity. Senior leadership received information about "the pervasive presence of young women or underage girls at Epstein's homes," according to the Senate report. The bank eventually terminated Epstein as a formal client due to human-trafficking concerns but continued informal relationships with senior bankers working with him to preserve referral relationships.

Deutsche Bank maintained Epstein as "a major client" despite massive cash withdrawals lacking documented business purposes. The bank filed SARs after Epstein's death in 2019, retroactively flagging activity that should have triggered real-time escalation.

Bank of America processed payments from Black to Epstein without requesting business records to verify the stated purpose. When Black's accounts showed a pattern of large transfers to a single recipient over five years, that pattern alone should have triggered enhanced due diligence questioning.

None of the three banks cooperated with Sen. Wyden's investigation, declining to answer questions or provide documents beyond what regulators had already obtained.

Results and Metrics

The three banks, along with the estates of Black and Epstein, have paid more than $900 million in settlements to Epstein's victims and regulators in the Virgin Islands and New York. These settlements reflect the scale of the compliance failures.

JPMorganChase's spokesperson stated the bank "strongly disagrees with the report's conclusions" and emphasized that it flagged suspicious transactions throughout the relationship. Bank of America said it takes "legal and regulatory obligations seriously" and "did not facilitate wrongdoing." Deutsche Bank acknowledged it "regrets our historical connection with Jeffrey Epstein" and has invested in strengthening its control environment.

The Senate report identifies 13 senior bankers across the three institutions who allegedly protected Epstein to maintain access to ultra-wealthy clients. Several JPMorganChase bankers who handled Epstein's accounts remain in senior positions at the bank.

What didn't happen: timely SAR filing when the activity occurred, comprehensive enhanced due diligence on the business rationale for the payments, or escalation that resulted in relationship termination when compliance concerns were raised internally.

What Should Have Been Done Differently

The core failure was allowing relationship management priorities to override compliance escalations. When your compliance team flags human-trafficking concerns and senior leadership responds by maintaining informal contact to preserve referral relationships, you've inverted your control structure.

Enhanced due diligence isn't a checkbox exercise. When a client makes $170 million in payments to a single recipient over five years, your KYC process must document the business rationale for those payments. If the stated purpose is tax and estate planning advice, you request engagement letters, invoices, work product documentation. If the client can't or won't provide substantiation, that's your signal to file a SAR and consider relationship termination.

The Bank Secrecy Act requires timely reporting. "Timely" doesn't mean waiting until the client is arrested and then retroactively flagging thousands of transactions. It means filing within the regulatory window when the suspicious activity occurs.

Your transaction monitoring system should flag patterns automatically, but the human review layer is where these cases failed. If your compliance analysts escalate concerns and those escalations die in relationship manager review, you need to redesign your escalation workflow to route high-risk findings directly to your BSA officer or chief compliance officer.

Takeaways for Your Team

Sen. Wyden plans to introduce legislation requiring bankers to personally confirm they've reviewed and conducted legally required due diligence for large wire transfers involving ultra-wealthy clients. Bankers who fail to report suspicious transactions in a timely manner would face increased civil or criminal penalties. Banks would be required to notify Treasury when they drop a client due to human trafficking, money laundering, or other crime concerns.

Whether that legislation passes or not, your program needs these controls now:

Escalation independence. Compliance escalations on high-risk clients must bypass relationship managers and go directly to your BSA officer. If your current workflow allows relationship teams to downgrade or delay compliance findings, you're exposed.

Enhanced due diligence triggers. Large payments to individuals (not corporate entities) without clear business documentation should trigger automatic enhanced review. If your client is a billionaire paying millions to a personal advisor, you need engagement documentation, not just a stated purpose.

Timely SAR filing metrics. Track the time between initial suspicious activity detection and SAR filing. If you're seeing patterns of delayed filing until external events force action, that's a control failure.

Post-termination monitoring. If you terminate a client relationship due to AML concerns, your monitoring doesn't end. Continued informal contact between your bankers and that former client creates ongoing risk and potential obstruction of your own compliance program.

The Senate investigation found that a small team of investigators "connected the dots and found evidence of multiple crimes." Your compliance team should be connecting those dots before external investigators do. If relationship revenue is driving your risk decisions, you're not running a compliance program. You're running a risk acceptance program without calling it that.

You Might Also Like