The Office of the Comptroller of the Currency issued a Cease and Desist Order against Bank of America, N.A. on 23 December 2024, citing violations and unsafe and unsound practices in the bank's Bank Secrecy Act, anti-money-laundering, and sanctions compliance programmes. The formal enforcement action requires the bank to take immediate and sustained corrective action across a range of identified compliance and governance deficiencies and represents one of the more significant regulatory interventions by the OCC against a major American lender in the period since the financial crisis.
The OCC identified two principal failings at the core of the enforcement action: the bank's failure to file suspicious activity reports in a timely manner as required under the BSA, and its failure to correct a customer due diligence deficiency that had been identified in a prior supervisory examination. The persistence of the CDD shortcoming after it had already been flagged by the regulator was a significant factor in the decision to escalate to a Cease and Desist Order, a formal enforcement tool that carries obligations enforceable in court if the bank fails to comply.
GOVERNANCE AND CONTROLS FOUND INADEQUATE
Beyond the specific SAR filing and CDD failings, the OCC's action documented broader deficiencies in Bank of America's internal controls, governance arrangements, independent testing processes, and the training provided to staff responsible for financial crime compliance. These structural findings indicate that the problems the regulator identified extended beyond individual process breakdowns into the design and oversight of the AML and sanctions compliance frameworks at an institutional level. A systemic assessment of this nature carries particular weight because it suggests that remediation will require organisational and cultural change rather than targeted fixes to isolated procedures.
As part of the order, the OCC required Bank of America to engage an independent consultant to conduct a comprehensive assessment of its BSA/AML and sanctions programmes. The independent consultant will also be required to carry out lookback reviews covering suspicious activity that may not have been identified and reported within the required timeframes during the period when the bank's controls were operating below the expected standard. The scope of the lookback requirement underscores the regulator's concern that historical activity may have gone undetected as a result of the identified control deficiencies.
RESTRICTIONS IMPOSED WITHOUT CIVIL PENALTY
The OCC did not impose a civil money penalty as part of the 23 December action, distinguishing the Cease and Desist Order from enforcement actions that combine formal requirements with an immediate financial sanction. In lieu of a monetary fine, the regulator imposed forward-looking restrictions requiring Bank of America to seek pre-approval before offering new products or services carrying elevated BSA-related risk, entering new high-risk markets, or taking on new categories of high-risk clients. These requirements effectively subject a segment of the bank's business development activity to ongoing regulatory sign-off until the OCC is satisfied that the underlying compliance infrastructure meets acceptable standards.
Bank of America, N.A. is one of the largest federally chartered banks in the United States by total assets, and the formal enforcement action underscores the OCC's willingness to apply its most direct supervisory tools to institutions of the highest systemic importance when it finds that compliance failures are persistent and that internal correction has not been forthcoming. The requirement for an independent consultant, a lookback review, and pre-approval for high-risk business activity together constitute a supervisory framework designed to ensure that the bank's AML and sanctions compliance programmes are rebuilt under external scrutiny and regulatory oversight.