The Federal Reserve and OCC recently fined American Express $350 million and demanded a complete overhaul of its AML controls. This enforcement action reveals a deeper issue: American Express processed about $13 billion in suspected trade-based money laundering from 2014 to 2025 due to fundamental control failures.
These aren't rare issues. They're the same problems that arise when your team treats AML compliance as a checkbox exercise instead of a risk management discipline. Here's what went wrong and how to prevent it in your program.
Why These Mistakes Keep Happening
AML control failures often don't result from missing technology or lack of funds. They occur because teams confuse activity with effectiveness. You can run thousands of alerts and file dozens of Suspicious Activity Reports, yet still miss billions in suspicious transactions if your controls aren't aligned with your actual risk exposures.
The pattern is clear: institutions expand their business faster than they enhance their financial crimes risk management. Transaction volumes grow, product lines expand, and third-party relationships multiply, while the AML framework that worked three years ago becomes inadequate. By the time regulators arrive, you're running a compliance program designed for a different institution.
Mistake 1: Transaction Monitoring Rules That Don't Match Your Risk Profile
The OCC found that American Express failed to maintain a BSA/AML compliance program "properly aligned with the money laundering risks of its operations." This means your transaction monitoring rules are generic, not risk-based.
Why it happens: Teams implement vendor-supplied scenarios without customizing them for their specific customer base, transaction patterns, or product risks. A rule set designed for retail banking won't catch trade-based money laundering typologies in a card payment environment.
Real consequence: You generate alerts on low-risk activity while high-risk patterns go undetected. For American Express, this meant missing trade-based money laundering involving repeated cycles of suspicious card charges and repayments.
The fix: Map your transaction monitoring rules directly to your institution's risk assessment. If your risk assessment identifies trade-based money laundering as a material risk, you need scenarios that detect circular payment patterns, mismatched goods descriptions, and rapid charge-repayment cycles. Review your rule effectiveness quarterly. Track your false positive rate alongside your detection rate. If 95% of your alerts close as false positives, your rules aren't risk-based; they're noise generators.
Mistake 2: Treating Suspicious Activity Reporting as a Filing Exercise
Regulators found "weaknesses in the Bank's controls surrounding SARs were significant and resulted in untimely, missed, or incomplete SARs." This wasn't about missing a few deadlines. It was a systemic failure in the SAR decision-making process.
Why it happens: Teams focus on whether they have "enough evidence" to file instead of whether the activity is suspicious enough to warrant reporting. The threshold gets inflated. Analysts wait for certainty that will never come.
Real consequence: Law enforcement loses visibility into criminal networks. Your institution processes illicit funds without flagging them. When regulators conduct a look-back, they find patterns you should have reported years earlier.
The fix: Reset your SAR threshold to match the regulatory standard: reasonable grounds to suspect. Not proof. Not certainty. Suspicion. Train your analysts to document what makes activity suspicious, not why they're certain it's criminal. Implement a SAR quality review process that examines whether the narrative provides actionable intelligence to law enforcement. The OCC ordered American Express to conduct an independent look-back to identify missed SARs. Don't wait for regulators to order one. Run your own look-back on closed alerts from the past 12 months and assess whether your SAR decisions would survive regulatory scrutiny.
Mistake 3: Inadequate Customer Due Diligence at Onboarding
The enforcement actions referenced deficiencies in American Express's know-your-customer processes. This matters because inadequate Customer Due Diligence at onboarding affects every downstream control.
Why it happens: Onboarding teams prioritize speed and customer experience over risk assessment. KYC becomes a data collection exercise, not a risk evaluation. You gather documents but don't analyze what they reveal about the customer's actual business model or expected transaction patterns.
Real consequence: You assign incorrect risk ratings, which means your ongoing due diligence intervals are wrong, your transaction monitoring thresholds are miscalibrated, and your periodic reviews miss red flags. When suspicious activity emerges, you lack the baseline understanding to recognize it as anomalous.
The fix: Separate KYC data collection from KYC analysis. Your onboarding system should not auto-approve accounts based on document submission. Require analysts to articulate the customer's business model, expected transaction types, anticipated volumes, and source of funds before account activation. For higher-risk customer segments, verify the business model through independent research, not just customer-provided information. Build expected activity profiles during onboarding and use them to calibrate your transaction monitoring rules for that customer.
Mistake 4: Weak Third-Party Risk Management
The Fed identified "third-party risk assessment" as a significant deficiency in American Express's financial crimes risk management program. Third-party relationships create control gaps that criminals exploit.
Why it happens: Institutions assess third-party credit risk and operational risk but treat AML risk as an afterthought. You onboard payment processors, correspondent banks, and service providers without understanding their AML controls or customer bases.
Real consequence: Your institution becomes the weak link in a chain that processes illicit funds. You inherit the AML failures of your third parties. When regulators examine your controls, they don't accept "our vendor handles that" as an answer.
The fix: Conduct AML-specific due diligence on every third party that touches customer transactions or data. Request their most recent regulatory examination results, Suspicious Activity Report volumes, and AML training completion rates. For high-risk third parties, require annual attestations from their MLRO confirming their AML/CFT Framework's effectiveness. Include AML performance metrics in your vendor contracts and exit clauses for material control failures. Review third-party relationships when you update your institutional risk assessment.
Mistake 5: Insufficient Fraud-to-AML Referral Processes
The Fed specifically called out "fraud referral processes" as a weakness. Fraud and AML teams often operate in silos, which means potential money laundering gets classified as fraud and never escalates to SAR consideration.
Why it happens: Organizational structure treats fraud and financial crimes as separate disciplines. Fraud teams close cases when they recover funds or block transactions. They don't assess whether the fraud pattern indicates money laundering. There's no formal handoff protocol.
Real consequence: You detect the symptom but miss the underlying financial crime. A fraud case involving compromised accounts might actually be a money mule network. Account takeover fraud might be cashing out proceeds of cybercrime. If fraud teams don't refer these patterns to AML, you never file the SAR.
The fix: Establish mandatory referral criteria from fraud to AML. Any fraud case involving multiple accounts, third-party beneficiaries, or cross-border transactions should trigger an AML review. Create a joint fraud-AML case review meeting where teams discuss patterns, not just individual incidents. Train fraud analysts to recognize money laundering typologies. They're often the first to see emerging schemes. Build a shared case management system where fraud and AML can track related activity across both disciplines.
Prevention Checklist
Use this checklist quarterly to assess whether your controls are calibrated to your current risk profile:
- Transaction monitoring rules map directly to risks identified in your institutional risk assessment
- Rule effectiveness review completed within the past 90 days, with documented tuning decisions
- SAR decision-making guidance emphasizes "reasonable grounds to suspect," not certainty
- Look-back completed on closed alerts from the past 12 months to validate SAR decisions
- Customer Due Diligence process requires documented business model analysis before account activation
- Expected activity profiles built during onboarding and used to calibrate monitoring thresholds
- Third-party AML due diligence completed for all entities that touch customer transactions or data
- Third-party AML performance metrics tracked and reviewed at least annually
- Formal referral criteria established from fraud to AML with documented handoff protocols
- Joint fraud-AML case review conducted monthly to identify cross-functional patterns
- Board-level compliance committee receives metrics on control effectiveness, not just activity counts
- Remediation plans developed for any control gaps identified in the past six months
The American Express enforcement actions demonstrate what regulators mean when they say your AML/CFT Framework must be "commensurate with your risk profile." It's not about the size of your compliance budget. It's about whether your controls actually address the money laundering risks your institution faces. If you're generating compliance activity without reducing financial crime risk, you're running a program that won't survive regulatory scrutiny.





