Regulators Fine Amex $350 Million Over AML Failures
Approximately $13 billion in suspected trade-based money laundering moved through between June 2014 and May 2025. Systemic breakdowns in suspicious-activity monitoring left that volume delayed, missed, or incompletely reported across roughly a decade. Some of the transactions involved accounts associated with bank insiders. The enforcement order did not identify the individuals or specify their roles.
The Comptroller of the Currency imposed a $350 million civil money penalty on American Express National Bank. The sum landed as one half of a dual federal strike: the same day, the Federal Reserve brought its own separate enforcement action against the wider American Express group.
“The OCC expects banks of American Express’s size and complexity to devote sufficient resources to ensure compliance with laws and regulations designed to detect and prevent money laundering, which are critical to both economic and national security,” Gould said. The rules exist to keep illicit money from moving through the banking system undetected; the OCC held that an institution of this scale had not met that bar.
The concurrent Federal Reserve order reached beyond the bank itself to American Express Co. and American Express Travel Related Services Co. What supervisors at the Federal Reserve Bank of New York had already recorded about the enterprise surfaced in the findings. “Recent supervisory assessments of Amex conducted by the Federal Reserve Bank of New York identified significant deficiencies in Amex's enterprisewide financial crimes risk management program, including weaknesses in transaction monitoring, fraud referral processes, third-party risk assessment, and financial crimes risk management,” the Federal Reserve said.
The gaps ran enterprise-wide and weighed heaviest at the bank subsidiary. Transaction monitoring is the continuous scan of payment flows for patterns that may signal illicit activity. Fraud referral processes move suspected cases to the desks that can act. Third-party risk assessment tests the partners and vendors that touch the network. Financial crimes risk management is the full program that ties those controls together. New York supervisors had found each of those layers short. The cease-and-desist bound American Express Co. and American Express Travel Related Services Co. to correct them.

“American Express failed to maintain a BSA/AML compliance program properly aligned with the money laundering risks of its operations, which resulted in the bank's failures to timely identify and report significant missed suspicious activity and to provide important information to law enforcement,” Gould said. The Bank Secrecy Act requires financial institutions to keep records and report activity that may signify money laundering so government agencies can detect and prevent it. A program out of line with the risks the bank actually carried produced the missed and late reports.
The defects reached into how the bank had weighed its own operations from the start. The bank’s BSA/AML risk assessment overweighted comparatively narrow deposit-taking and underweighted far larger credit and charge-card operations. American Express specializes in payment cards and is one of the largest U.S. credit- and charge-card issuers by transaction volume. Nearly 87 million cards were in circulation and total charges approached $1.7 trillion in 2025. Deposits accepted that year stood at $153 billion. American Express National Bank is a direct bank owned by the company, yet its deposit products remained the comparatively narrow line against the card volume that defines the business. The OCC found the bank had focused too much on its relatively narrow demand-deposit products and services and not enough on the risks in its more dominant credit and charge card products. That skew sat beside insufficient staffing, inadequate training, limited expertise, weak internal audits, and ineffective internal controls. Customer-identification procedures fell short. The processes meant to produce suspicious activity reports did too.
American Express said internal and external reviews had identified weaknesses in its financial crimes compliance program. “We also investigated transactions that we identified being processed over our network by individuals misusing our products for the purchases of goods and services, reported that information to law enforcement, and took other appropriate action,” the company said in a statement.
Chairman and CEO Stephen J. Squeri said the company “takes its responsibility to combat financial crimes seriously.” He said it was “fully committed to addressing the concerns outlined by the FRB and OCC and continuing to strengthen our Financial Crimes Compliance program.” “Over the last few years, we have engaged closely with regulators as we have strengthened our controls and with law enforcement to provide information,” Squeri said. “We have made and continue to make substantial investments in our people, technology, training, governance, and oversight to fortify how we identify, assess, and respond to evolving financial crimes risk across our business and the industry.”
The OCC ordered an independent review of historical transactions to determine whether additional suspicious activity reports should have been submitted. Findings from that review must be provided to the bank’s examiner-in-charge. The bank must establish a board-level compliance committee and develop a comprehensive remediation plan. The Federal Reserve set parallel obligations at the holding-company level. American Express Co. and American Express Travel Related Services Co. must submit remediation plans addressing weaknesses in financial crime risk management, measures that extend beyond the OCC’s requirements for the bank itself. The parent companies must also cooperate with investigations involving employees and other individuals connected to the misconduct.
American Express said in a regulatory filing that a portion of the $350 million civil money penalty had already been reserved in prior periods and does not impact full-year 2026 guidance. The consent orders impose no asset cap. They are not expected to affect the company’s 2027 guidance. The independent review of the historical traffic still lies ahead.






