OCC fines American Express Bank $350 million
The OCC fined American Express National Bank $350 million for BSA and AML failures after delays in reporting suspicious activity.
The Office of the Comptroller of the Currency fined American Express National Bank $350 million over deficiencies in its Bank Secrecy Act and anti-money laundering program. The agency said the bank was slow to identify, assess and report nearly $13 billion in suspicious activity linked to trade-based money laundering over the prior decade.
The Office of the Comptroller of the Currency fined American Express National Bank $350 million over deficiencies in its Bank Secrecy Act compliance and anti-money laundering program. The agency said the bank had systemic failures in monitoring and reporting suspicious transactions, with delays in identifying, assessing and reporting nearly $13 billion in suspicious activity tied to trade-based money laundering over the prior decade.
What did the OCC observe in the American Express National Bank case?
The OCC said there were systemic failures in the bank's monitoring and suspicious activity reporting processes. In its view, that led to a prolonged delay in processing activity that the agency said totaled about $13 billion and was linked to trade-based money laundering schemes.
The penalty was set at $350 million, according to the official notice cited by MLex and Banking Dive. The available materials do not detail any additional measures, but they do note that the deficiencies affected both BSA compliance and AML controls.
What else do the available sources show?
Beyond the fine, the research material also includes an interagency proposal on third-party risk management that would replace supplemental resources issued in 2024 and a 2002 OCC bulletin on foreign-based service providers. According to analysis by The Bonadio Group, the proposal takes a proportionality-based approach and would not impose enforceable standards or prescriptive requirements.
A legal analysis by Morrison Foerster adds that the agencies want to move away from overly broad, process-driven approaches, make clear there is no single path for third-party risk management, and support responsible innovation. That framework was not presented as a banking cybersecurity rule for Latin America, but as a broader review of third-party guidance and compliance in the U.S. financial system.
Sources
- Amex dinged by Fed, OCC; must pay $350M for AML failuresbankingdive.com· Banking Dive
- Understanding the New Interagency TPRM Proposalbonadio.com· The Bonadio Group
- Monthly Deposits – Issue #7mofo.com· Morrison Foerster
- Skadden Discusses Bank Agencies' Proposed Changes to Third-Party Risk Management Guidanceclsbluesky.law.columbia.edu· Columbia Law School Blue Sky Blog
- Amex Bank fined $350 million by US OCC for BSA, money laundering defectsmlex.com· MLex
- Weekly Enforcement Action Digestacrossoversight.com· Across Oversight
- OCC Assesses $350 Million Civil Money Penalty Against American Express National Bankocc.gov· Office of the Comptroller of the Currency



