Skip to main content
Promotional banner for the pentest readiness checklist
Five BSA/AML Mistakes That Cost American Express $350 MillionRegulatory Obligations Management
6 min readFor Compliance Officers

Five BSA/AML Mistakes That Cost American Express $350 Million

The OCC and Federal Reserve Board imposed a $350 million penalty on American Express National Bank for failing to maintain a compliance program "reasonably designed to assure and monitor compliance with the BSA and its implementing regulations." This wasn't a fine for a minor oversight; it was a penalty for a systemic breakdown.

Here's what matters for your compliance program: the deficiencies that trigger enforcement actions like this one aren't rare. They're predictable failures in how organizations structure, resource, and operate their BSA/AML programs. Let's examine the mistakes that keep appearing in consent orders and the specific fixes that prevent them.

Why These Mistakes Keep Happening

BSA/AML compliance requires coordination across multiple teams. Your compliance team needs deep regulatory knowledge. Your operations team handles transaction monitoring and reporting. Your technology team maintains systems that flag suspicious activity. When these groups don't share a common understanding of Impact Tolerance and control design, gaps emerge.

The mistakes below reflect a pattern: organizations treat BSA/AML compliance as a checklist exercise rather than a risk-based program. They implement controls without validating effectiveness, staff teams without ensuring expertise, and deploy technology without confirming it can detect the patterns regulators expect.

Mistake 1: Building a Compliance Program Around Tools Instead of Risk Assessment

Why it happens: Your organization buys transaction monitoring software, configures the vendor's default scenarios, and assumes you're covered. The tool generates alerts, someone reviews them, and the program looks functional on paper.

The consequence: Default scenarios reflect generic typologies, not your institution's specific risk profile. If you serve high-risk customer segments or operate in jurisdictions with elevated money laundering risk, those defaults won't catch what regulators expect. When examiners test your program, they'll find gaps between your stated risk assessment and your actual monitoring coverage.

The fix: Start with a documented risk assessment that identifies your specific BSA/AML risks based on products, services, customers, and geographic footprint. Then design your transaction monitoring scenarios to address those risks. Your scenario library should map directly to risks in your assessment. If your risk assessment identifies trade-based money laundering as a material risk, you need scenarios that detect it, not just the vendor's standard wire transfer rules.

Mistake 2: Treating Suspicious Activity Report Filing as a Compliance Milestone

Why it happens: Your team measures success by SAR filing volume and timeliness. You've built workflows that move alerts through investigation queues efficiently. Your metrics dashboard shows you're meeting the 30-day filing requirement.

The consequence: Filing SARs on time doesn't prove your program is effective. It proves you can complete paperwork. Regulators examine whether you're identifying the suspicious activity in the first place. If your alert generation is weak, you'll file SARs on the obvious cases while missing patterns that should have triggered investigation.

The fix: Measure detection effectiveness, not just filing compliance. Conduct lookback testing on closed investigations to validate that your scenarios would have caught known suspicious activity. When law enforcement or regulators identify money laundering that touched your institution, trace it backward through your controls. If your transaction monitoring didn't flag it, you have a scenario gap to close.

Mistake 3: Staffing Your BSA/AML Team With Generalists

Why it happens: You need to fill compliance positions quickly. The job descriptions emphasize regulatory knowledge and attention to detail. You hire smart people who can learn the BSA regulations and follow investigation procedures.

The consequence: Effective BSA/AML compliance requires understanding how money laundering actually works, the structuring patterns, the layering techniques, the trade finance schemes. Generalist compliance staff can follow investigation checklists, but they struggle to recognize suspicious patterns that don't match documented scenarios. When examiners review your SAR narratives and investigation files, they'll spot superficial analysis that misses the underlying scheme.

The fix: Require demonstrated BSA/AML subject matter expertise for investigation roles. That means CAMS certification or equivalent specialized training, not just general compliance experience. For senior roles, look for candidates who've worked financial crimes investigations at other institutions or regulatory agencies. Your team needs people who can explain why a pattern is suspicious, not just that it triggered an alert.

Mistake 4: Running Independent Testing as a Checklist Audit

Why it happens: You engage internal audit or a consultant to satisfy the BSA requirement for independent testing. They review policies, sample investigation files, and confirm you're filing SARs. The testing report documents that you have the required program elements.

The consequence: Checklist testing validates that controls exist, not that they work. Regulators expect independent testing to assess whether your program is "reasonably designed" to detect and report suspicious activity. That requires testing whether your scenarios would catch known money laundering typologies, whether your risk assessment reflects your actual risk exposure, and whether your investigation quality meets regulatory expectations.

The fix: Structure independent testing as effectiveness validation. Your testing scope should include scenario coverage analysis (do your rules detect the money laundering patterns relevant to your risk profile?), alert disposition quality review (are investigators reaching sound conclusions?), and risk assessment validation (does your documented risk profile match your actual customer base and transaction patterns?). The testing report should identify control gaps, not just confirm compliance with procedures.

Mistake 5: Treating Customer Due Diligence as an Onboarding Task

Why it happens: Your customer onboarding process collects beneficial ownership information, risk-rates the relationship, and sets transaction monitoring parameters. Once the account is open, that due diligence sits in the customer file unless something triggers a review.

The consequence: Customer risk profiles change. A low-risk customer starts conducting transactions inconsistent with their stated business purpose. A beneficial owner changes but your records don't reflect it. Your transaction monitoring scenarios are calibrated to outdated risk ratings, so you're not generating alerts on activity that should look suspicious.

The fix: Implement ongoing due diligence that refreshes customer risk ratings based on actual behavior. Your transaction monitoring system should flag accounts where activity deviates from expected patterns, not just transactions that exceed dollar thresholds. When you identify inconsistencies between stated business purpose and actual transaction patterns, that's a trigger for enhanced due diligence, not just an alert to clear. Build periodic reviews into your account maintenance workflow, with review frequency tied to customer risk rating.

Prevention Checklist

Before your next regulatory examination, validate these elements:

  • Your BSA/AML risk assessment identifies specific risks based on your institution's products, customers, and geographic footprint, not generic industry risks
  • Your transaction monitoring scenarios map to risks documented in your assessment, with clear rationale for scenario parameters
  • Investigation staff hold specialized BSA/AML credentials (CAMS or equivalent) and can articulate money laundering typologies relevant to your risk profile
  • Independent testing scope includes effectiveness validation, not just procedural compliance
  • You conduct lookback testing on known suspicious activity to confirm your scenarios would have detected it
  • Customer risk ratings refresh based on actual transaction behavior, not just at account opening
  • Your SAR narratives demonstrate analysis of underlying schemes, not just description of transactions
  • Senior management receives metrics on detection effectiveness, not just SAR filing volume

The $350 million penalty against American Express National Bank shows what happens when a BSA/AML compliance program exists on paper but fails in practice. Your program needs to detect money laundering, not just document that you have detection procedures.

Promotional banner for the Penetration Report Template Kit

You Might Also Like