Skip to main content
Category: Enforcement and Penalties

Cease and Desist Order

Also known as: C&D, Cease-and-Desist Order, C&D Order
Simply put

A cease and desist order is a directive issued by a government agency or court requiring a person or organization to stop a specified activity. It typically serves as a formal warning that continuing the conduct may lead to further legal enforcement or penalties. Depending on the issuing body and jurisdiction, it may be an administrative order or a step toward judicial enforcement.

Formal definition

A cease and desist order is an order issued by an administrative agency (or, in some contexts, a court) directing a named party to halt specified practices, and is generally characterized as a warning of impending judicial enforcement should the conduct continue. Its legal basis, issuing authority, and available remedies vary by jurisdiction and by the underlying statutory framework; for example, the U.S. International Trade Commission is authorized to issue such orders as a remedy in investigations under section 337 of the Tariff Act of 1930, while other administrative agencies issue them under their respective enabling statutes across areas such as labor and employment law. The order typically communicates that the offending party is prohibited from continuing the specified activity and may face legal consequences for non-compliance. Practitioners should note that cease-and-desist authority is instrument- and agency-specific rather than uniform, and the precise issuing body, scope, and enforcement mechanism should be confirmed against the applicable statute and regulatory regime in the relevant jurisdiction.

Why it matters

A cease and desist order is one of the more visible signals that a regulator or court has moved from informal engagement to formal enforcement. For compliance, legal, and risk professionals, it marks a directive to halt a specified activity, coupled with a warning that continued conduct may lead to further judicial enforcement or penalties. Understanding whether an order is administrative or a step toward judicial action, and which authority issued it, is essential to gauging the seriousness and the potential downstream consequences for an organization.

Who it's relevant to

Compliance and Legal Officers
Compliance and legal teams at obliged entities need to understand which authority issued a cease and desist order and under what statute, as this determines the scope of the directive, the conduct that must stop, and the consequences of non-compliance. Because the issuing body and remedy vary by jurisdiction, teams should confirm the specific enabling statute before assessing exposure.
Risk and Enforcement Analysts
Analysts tracking regulatory actions treat a cease and desist order as a formal enforcement signal distinct from informal supervisory engagement. Distinguishing an administrative order from a step toward judicial enforcement helps in evaluating the seriousness of an action and its potential downstream implications.
Banking Supervision Practitioners
In the U.S., professionals dealing with BSA/AML supervision should note that cease-and-desist authority over banking institutions rests with the federal banking agencies under 12 U.S.C. 1818, not with FinCEN, whose instruments include civil money penalty assessments, geographic targeting orders, and special-measure orders. Attributing enforcement powers to the correct body is essential.

Inside C&D

Issuing Authority
In the US banking context, cease-and-desist orders in BSA/AML matters are typically issued by the federal banking agencies (such as the OCC, Federal Reserve, and FDIC) under their statutory enforcement powers, generally associated with 12 U.S.C. 1818, rather than by FinCEN. Analogous supervisory stop-action powers exist in many other jurisdictions but are vested in different regulators and grounded in different instruments; the specific authority should be confirmed against the applicable regime.
Statutory Basis
The order derives from a specific enabling provision that empowers a supervisor to direct a regulated institution or individual to stop conduct the authority views as unsafe, unsound, or in violation of applicable requirements. The precise legal basis, scope of covered conduct, and procedural protections vary by jurisdiction and instrument.
Named Respondent
The order identifies the party subject to it, which may be an institution, and in some regimes individuals such as officers or directors. The categories of parties reachable depend on the authority's jurisdiction over the relevant obliged entity or person.
Required and Prohibited Conduct
The operative directives instruct the respondent to cease specified conduct and, in many cases, to take affirmative corrective steps such as remediating deficiencies or enhancing controls. The mix of prohibitions and affirmative obligations depends on the issuing authority and the facts.
Procedural Posture
Depending on the regime, an order may be entered on consent (agreed by the respondent) or issued following, or subject to, an administrative process that generally affords notice and an opportunity to be heard. Interim or temporary orders may be available in urgent circumstances under some frameworks.
Compliance and Enforcement Consequences
The order typically carries a compliance timeline and describes consequences for non-compliance, which may include further supervisory or enforcement action. Exact consequences and any associated penalties vary by regime and should be confirmed against the applicable law.

Common questions

Answers to the questions practitioners most commonly ask about C&D.

Does a cease-and-desist order mean the institution has been convicted of money laundering or another crime?
No. A cease-and-desist order is a civil or administrative supervisory instrument, not a criminal conviction. It is typically issued by a banking or financial regulator to require an institution to stop specified conduct or to correct deficiencies, and it generally reflects supervisory findings rather than a judicial determination of criminal guilt. Criminal liability for money laundering or related offenses is established through separate criminal proceedings under the applicable law. Receiving such an order does not by itself establish that any individual or entity committed a crime.
Does FinCEN issue cease-and-desist orders for BSA/AML violations?
Cease-and-desist authority over insured depository institutions and certain other entities for BSA/AML matters generally rests with the federal banking agencies acting under their statutory enforcement powers (for example, 12 U.S.C. 1818), rather than with FinCEN. FinCEN's own enforcement toolkit is generally described as including civil money penalty assessments and other measures such as geographic targeting orders and special measures. Practitioners should confirm which agency holds the relevant authority for a given institution and matter, as jurisdiction depends on the entity type and its primary regulator.
Which authority issues a cease-and-desist order to a given financial institution?
This depends on the institution's charter, its primary supervisor, and the jurisdiction. In many regimes the relevant banking or financial regulator holds cease-and-desist authority over the entities it supervises. Because supervisory responsibility varies by entity type and jurisdiction, institutions should identify their applicable regulator and the specific statutory or regulatory basis for any order, and confirm the details against the applicable law and supervisory framework.
What steps might an institution take upon receiving a cease-and-desist order?
Institutions typically review the order carefully to understand the specific conduct it addresses and any required corrective actions and deadlines, engage legal counsel and relevant compliance leadership, and consider any rights to respond or contest that the applicable process provides. Many institutions then develop a remediation plan mapped to the order's requirements. Because procedures and available responses vary by regulator and jurisdiction, the exact process should be confirmed against the terms of the order and the governing framework.
How does a cease-and-desist order typically interact with an institution's existing AML program?
Such an order often directs an institution to remediate identified deficiencies, which may touch on elements of its AML program such as controls, monitoring, or governance. The order generally functions as a supervisory directive to correct or cease specified conduct rather than a redesign mandate. Institutions commonly align their remediation with the order's requirements while continuing to manage broader financial crime risk. The precise scope depends on the order's terms and should be read against the applicable supervisory expectations.
Is a cease-and-desist order generally made public, and how long does it typically remain in effect?
Whether an order is publicly disclosed and how long it remains in force vary by regulator and jurisdiction. Some regimes provide for public availability of enforcement actions, while others may treat certain supervisory measures differently. An order generally remains in effect until the institution satisfies its terms or the issuing authority terminates or modifies it. Institutions should confirm disclosure treatment and duration against the specific order and the applicable regulatory framework.

Common misconceptions

FinCEN issues cease-and-desist orders in BSA/AML matters.
FinCEN's enforcement instruments generally include civil money penalty assessments, geographic targeting orders, and special measures. Cease-and-desist authority in US BSA/AML matters rests with the federal banking agencies under their supervisory enforcement powers, typically associated with 12 U.S.C. 1818, not with FinCEN.
A cease-and-desist order is a criminal finding that establishes the respondent committed a crime.
Such an order is generally a supervisory or administrative enforcement measure directed at conduct and controls; it does not by itself establish criminal wrongdoing. Criminal liability is a separate matter determined through the criminal process under the applicable law.
Cease-and-desist orders work the same way in every country.
The label, issuing body, statutory basis, reachable parties, and procedures differ across jurisdictions. Equivalent stop-action powers exist in many regimes but are vested in different regulators under different instruments, so the specifics must be confirmed against the applicable framework.

Best practices

Confirm which authority holds cease-and-desist power over the relevant obliged entity in the applicable jurisdiction, recognizing that in US BSA/AML matters this generally rests with the federal banking agencies rather than FinCEN.
Identify the precise statutory or regulatory basis and procedural posture (consent versus contested, interim versus final) before assessing rights and obligations, and confirm details against the governing instrument.
Treat the order's affirmative obligations and prohibitions as distinct workstreams, mapping each directive to a concrete remediation plan with owners and timelines.
Distinguish the supervisory or administrative nature of the order from any separate criminal exposure, and avoid treating the order as proof of criminal conduct.
Track compliance deadlines closely and document remediation evidence, given that non-compliance may trigger further supervisory or enforcement action.
Engage legal counsel familiar with the specific regime early, since the scope of reachable parties, procedural protections, and consequences vary by jurisdiction and should not be assumed from another regime.