Article,

The American Express Order: Your AML Risk Assessment Must Follow the Product

The OCC's October 8, 2026 order against American Express National Bank found a risk assessment built around deposit products while roughly $13 billion of suspected trade-based money laundering ran through card charges and repayments.

On October 8, 2026, the Office of the Comptroller of the Currency announced a cease-and-desist order and a $350 million civil money penalty against American Express National Bank for deficiencies in its Bank Secrecy Act and anti-money laundering compliance program. The OCC acted in coordination with a concurrent cease-and-desist order from the Federal Reserve Board against American Express Company and American Express Travel Related Services Company, Inc. The bank consented to the OCC order and neither admitted nor denied the findings. The penalty will get the headlines. The finding that matters for fintech lenders, card programs and embedded-credit providers is narrower, and it sits in Article II of the consent order.

What the OCC found

The OCC found that the bank’s risk assessment “focused on the risks in its relatively narrow demand deposit account products and services, and insufficiently on the risks in its more dominant credit and charge card products.” According to the consent order, from approximately June 2014 to approximately May 2025 the bank processed approximately $13 billion in suspected trade-based money laundering activity. That activity included a combination of suspicious card charges and associated repayments of those charges, in certain instances through accounts associated with bank insiders. The OCC said the bank experienced systemic breakdowns in its suspicious activity monitoring and reporting processes.

The risk assessment gap did not stand alone. The OCC described deficiencies involving inadequate resources, including staff without sufficient expertise, systemic internal control gaps, weak independent testing, and weak BSA/AML training for employees and directors. It also said the bank’s customer due diligence processes and customer identification program procedures contributed to its monitoring and reporting failures. The consent order finds a BSA/AML program violation under 12 C.F.R. § 21.21 and suspicious activity report violations under 12 C.F.R. § 21.11, alongside customer due diligence and customer identification program violations.

“American Express failed to maintain a BSA/AML compliance program properly aligned with the money laundering risks of its operations,” Comptroller of the Currency Jonathan Gould said.

Why the risk assessment finding is the one to read

This is our reading, not the OCC’s. The pattern described in the order is a familiar one. A card issuer’s deposit accounts look like the classic AML surface, so the assessment is built around them. The card book is treated as a credit risk problem rather than a financial crime problem. Yet the card book is where the volume is, and in a card business the inbound flow of funds is the repayment. A charge and its repayment each look like ordinary activity. Taken together they can move value from one party to another through a regulated institution, with the institution’s own records making it look like commerce.

For a fintech lender or an embedded-credit program, the same structure exists. You advance credit against a purchase; someone repays. The repayment is where third-party money enters your books, and it is often the flow programs monitor least, because the credit decision already happened. If your risk assessment starts from the account type your bank partner asked about rather than from the product that generates most of your volume, you likely have the gap the OCC described.

A risk assessment that does not start from the product you actually sell is not a risk assessment.

The remediation template, as a self-test

The orders bind American Express and no one else. Most firms reading this are unlikely to be subject to an order of this kind. But the remediation articles are specific enough to use as a checklist, and we expect bank partners and examiners to point to them when they ask fintech programs about their own controls. The test is whether you could answer the same questions.

Governance first. Within fifteen days of the order, the bank’s board must appoint a compliance committee of at least three members, a majority of them directors who are not employees or officers of the bank. Within 90 days, the bank must submit a written action plan to the examiner-in-charge for a determination of no supervisory objection. Under the Federal Reserve order, the American Express board must submit a written plan for its oversight of the matters identified within 90 days. Ask: who on your board owns AML remediation, and when did they last see a progress report?

Risk assessment. The OCC order requires the assessment to be refreshed periodically, at intervals not exceeding twelve months, or whenever there is a significant change in risk. The required risk categories include products and services inclusive of accessories and extensions such as supplemental cardholders, and customer types including bank insiders. Ask: does your assessment cover every extension of the product, including authorized users and merchant-side arrangements, and does it name insiders as a customer category?

Customer due diligence. The CDD program must include clear definitions of customer risk categories and an effective methodology for assigning a customer’s risk profile to a defined category. Ask: can you show the methodology, and does it feed back into the risk assessment?

Monitoring. Any changes to monitoring thresholds must be approved at senior management level and reported to the board. The program must require periodic independent validation of the models and filtering thresholds used for monitoring. Ask: who changed your thresholds last, who approved it, and when were the models validated by someone independent of the team that built them?

Insiders and third parties. The bank must establish an insider activity program commensurate with its BSA/AML risk profile. The financial crimes risk management program must include a third-party BSA/AML compliance risk management framework. The Federal Reserve order asks for oversight of information from network partnerships, ATM partners and third parties engaged to support BSA/AML compliance. Ask: are employees’ and founders’ accounts subject to the same rules as everyone else, and do you see the data your processor, network and servicers hold?

People. The staffing level and skills assessment must include a succession plan for the BSA Officer. Ask: if your BSA officer resigned tomorrow, who would sign the next SAR?

Look-back. The OCC order requires an independent consultant to determine whether SARs should be filed for any previously unreported suspicious activity. Ask: if someone reran your alerts for the last several years with correct thresholds, what would they find?

What still applies

In our reading, nothing in these orders changes the rules. The program, suspicious activity reporting, customer due diligence and customer identification requirements the OCC cited stand as they did before the orders. The orders do not appear to create a new standard for card products; they apply the existing standard to a business whose assessment had not caught up with its own product mix. For non-bank lenders, obligations usually arrive through the bank partner’s program and the contract that governs it, and those have not changed either. What has likely changed is the question bank partners will ask next, and how much evidence they will want behind the answer.

What firms should do

First, re-base the risk assessment on volume. List your products by dollar flow, not by regulatory category, and make sure the assessment spends its pages where the money is. Include extensions of the core product: supplemental users, merchant arrangements, refund paths.

Second, treat repayments as a monitored flow. Write rules for repayment source, velocity, mismatch between payer and borrower, and repayments that arrive without a corresponding purchase pattern. Document why each threshold sits where it does.

Third, put threshold changes under governance. A log of who changed what, when, with senior sign-off, is the document an examiner or bank partner is likely to ask for first.

Fourth, test the testers. If internal audit has never scoped a review against your actual risk profile, and no one independent has validated your monitoring models, schedule both this quarter.

Fifth, count your people and plan for succession. A staffing and skills assessment against your product risk, and a named successor for the BSA officer, are cheap to produce and expensive to lack. Where the gap is capacity rather than knowledge, a fractional compliance team can carry the risk assessment rewrite and the monitoring tuning while permanent hires are made.

Sixth, add insiders and third parties to the program on paper and in the rules. Employee accounts, founder accounts and the data held by processors and networks all belong in scope.

Taft does this work in plain terms: it reviews AML programs against findings like these, rewrites risk assessments and supplies the people to run the program day to day. Taft is not a law firm, and where a self-test raises questions about past filings, you should involve counsel. For the underlying rules and how they reach non-bank programs, start with our guide to AML compliance for fintechs and funds.

Sources

  1. OCC Assesses $350 Million Civil Money Penalty Against American Express, OCC
  2. UNITED STATES OF AMERICA, OCC
  3. UNITED STATES OF AMERICA, OCC
  4. UNITED STATES OF AMERICA, Federal Reserve Board

Taft does not provide legal advice. Content is for informational purposes only and subject to regulatory guidance.

Talk it through with an expert.