Skip to main content
The state of ai impact assessment
BSA Officer With Full Authority Wasn't EnoughRegulatory Obligations Management
4 min readFor CISOs

BSA Officer With Full Authority Wasn't Enough

The OCC's June 2026 consent order against a newly converted national bank highlights a critical lesson in BSA/AML remediation: changing your charter won't fix structural deficiencies. The bank, which converted from a Texas state-chartered member bank to a national bank on June 12, 2026, faced a requirement to incorporate every corrective action from a 2024 Federal Reserve Bank of Dallas and Texas Department of Banking order. The message is clear: unresolved AML issues will follow you through corporate restructuring.

The Challenge

The bank's BSA/AML program had major deficiencies in foreign correspondent banking and virtual currency customer oversight. It needed better board oversight, customer due diligence, suspicious activity monitoring, and OFAC compliance. The bank mistakenly believed a charter conversion might reset the clock. It didn't.

The OCC required continued implementation of remediation plans that predated the conversion. These plans addressed key gaps: inadequate risk assessment, insufficient independent testing, and deficient customer due diligence (CDD) for existing customers. The consent order emphasized that the BSA compliance officer needed "full autonomy and adequate resources," indicating previous remediation efforts had faltered due to authority issues.

Environment and Constraints

Two customer segments increased the risk profile: foreign correspondent banking relationships and virtual currency businesses. Both require sophisticated transaction monitoring, enhanced due diligence, and continuous sanctions screening. These high-margin businesses often pressure boards to maintain relationships even when controls are lacking.

The bank operated under a prior 2024 order while pursuing charter conversion. This created a constraint: remediation work had to continue during the conversion process, and the OCC wouldn't approve the new charter without commitments to complete the Federal Reserve's ordered corrections.

The Approach Taken

The consent order outlined a comprehensive remediation program. The board must review program effectiveness annually and submit quarterly progress reports. The bank committed to a thorough BSA/AML risk assessment tailored to its correspondent banking and virtual currency exposures.

The institution agreed to enhanced independent testing by parties outside the business and compliance lines. It also committed to remediating deficient due diligence for existing customers, not just applying enhanced standards to new accounts. The BSA officer's authority, decision-making autonomy, and staffing levels were formalized.

The order required enhanced training, improved OFAC compliance, and stronger suspicious activity monitoring. These are essential for any institution serving high-risk customer segments. The regulatory insistence on completing these despite the charter change was noteworthy.

Results and Metrics

The bank processed about 1,680 official bank checks totaling over $92 million through a separate insider-facilitated money laundering scheme prosecuted by the DOJ in July 2026. While this involved a different bank, it illustrates the transaction volume BSA controls must handle. The OCC didn't publish specific deficiency counts or remediation timelines, but the requirement for quarterly board reporting indicates an expectation of multi-year oversight. The order's continuation from a 2024 state action means the bank has been under formal remediation for at least two years.

What They Would Do Differently

Charter conversion shouldn't be a remediation strategy. If the bank could go back, it would complete AML remediation before pursuing conversion, removing regulators' leverage to condition approval on corrective commitments.

The bank would also address the BSA officer's autonomy and resources earlier. The consent order's language about "full autonomy" suggests previous efforts gave the officer a title without the authority to override business-line objections. Many institutions appoint a compliance officer but don't empower them to halt onboarding or exit relationships.

Finally, the bank would calibrate its transaction monitoring and CDD programs to correspondent banking and virtual currency risk from the start, rather than retrofitting controls after gaps were identified. Enhanced due diligence isn't something you apply retroactively without significant cost and operational friction.

Takeaways for Your Team

Supervisory findings survive corporate restructuring. If you're considering a charter change, merger, or acquisition, expect regulators to require remediation of outstanding AML deficiencies as a condition of approval. Plan accordingly.

BSA officer autonomy is an examiner expectation. Your compliance officer needs genuine decision-making authority, sufficient staffing, and the organizational standing to override revenue-generating business lines. If your officer can't stop a customer onboarding without escalating to the CEO, you don't have autonomy.

Independent testing means outside the business and compliance lines. Don't assign BSA testing to the same team that built the monitoring scenarios. Use internal audit, a qualified third party, or a separate risk function with no reporting relationship to the BSA officer.

Retroactive CDD remediation is expensive. If you serve foreign correspondents or virtual currency businesses, calibrate your due diligence and ongoing monitoring to that risk from day one. Remediating deficient CDD for existing customers requires file-by-file review, enhanced information gathering, and potential relationship exits. It's far cheaper to get it right initially.

Correspondent banking and virtual currency customers require specialized controls. Generic transaction monitoring won't catch nested banking exposure, sanctions evasion through correspondent relationships, or structured virtual currency transactions. You need blockchain analytics, cross-border transaction tracking, and monitoring rules tuned to these specific risks.

The consent order's requirement for annual board effectiveness reviews signals a shift from compliance-as-checklist to compliance-as-governance. Your board shouldn't just receive BSA officer reports; it should evaluate whether the program actually detects and prevents money laundering given your customer base. That's a harder question, and it's the one examiners are asking.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like