OCC Issues Cease and Desist Order Against USAA Federal Savings Bank for Persistent Compliance Failures
Office of the Comptroller of Currency sign and logo in downtown,Andriy Blokhin / Shutterstock.com.

The Office of the Comptroller of the Currency issued a cease and desist order against USAA Federal Savings Bank, headquartered in Phoenix, Arizona, on 19 December 2024, requiring the institution to remediate a range of unsafe or unsound practices spanning management, earnings, information technology controls, consumer compliance programmes, and suspicious activity reporting. The action, assigned Docket No. AA-ENF-2024-56, replaced prior cease and desist orders that the OCC had issued against USAA FSB in January 2019, signalling that the bank's supervisory challenges have persisted across a five-year period.

The replacement of the 2019 orders with a new enforcement action is itself a significant supervisory signal. It indicates that USAA FSB has not resolved the concerns identified in the earlier enforcement cycle to the OCC's satisfaction, and that the regulator has concluded that continued formal supervisory pressure is necessary. Persistent supervisory concerns of this nature represent a serious regulatory challenge, implying that corrective actions taken since 2019 have been insufficient in scope, speed, or durability.

WIDE-RANGING DEFICIENCIES CITED BY THE OCC

The breadth of the 2024 order is particularly notable. The OCC cited deficiencies across six distinct areas: management practices, earnings adequacy, information technology controls, consumer compliance programmes, suspicious activity reporting obligations, and compliance with the OCC's heightened standards framework. The heightened standards framework — formally set out in the OCC Guidelines Establishing Heightened Standards — applies to large or complex banks and sets elevated expectations for governance, risk management infrastructure, and internal controls relative to what is required of smaller, simpler institutions.

The heightened standards framework requires qualifying institutions to maintain robust front-line risk management functions, strong and independent risk oversight, and effective board-level engagement with risk matters. USAA FSB's repeated failure to meet these standards is among the most significant elements of the enforcement action, as it suggests that the gaps identified are not confined to individual compliance programmes but extend to the bank's broader risk governance architecture and the culture of accountability that the regulator expects to see embedded at the senior leadership and board level.

USAA FSB serves exclusively the US military and veteran community, providing banking, insurance, and financial services to a customer base that the institution has long marketed itself as uniquely equipped to serve. The bank's compliance difficulties have been associated with the rapid growth in its asset base and member numbers — growth that outpaced the development of commensurate compliance infrastructure, systems, and talent. Scaling compliance capabilities proportionately with institutional growth is a challenge recognised across the banking industry, but the OCC has been clear that it expects institutions to manage this alignment proactively.

IMPLICATIONS OF A REPLACEMENT ENFORCEMENT ORDER

A replacement cease and desist order — as distinct from the termination of the 2019 orders following successful remediation — reflects the OCC's determination that persistent supervisory concern warrants continued formal engagement rather than a graduation to lighter-touch oversight. Cease and desist orders are among the most serious enforcement instruments available to the OCC, carrying binding legal obligations and the potential for additional penalties if the bank fails to comply with the corrective commitments they impose.

For USAA FSB's board and senior management, the December 2024 order represents an urgent mandate to demonstrate to the OCC that the institution possesses the governance capability, management commitment, and resource allocation required to address the identified deficiencies in a durable and sustainable way. The scope of the cited concerns — spanning management, technology, consumer compliance, and suspicious activity reporting simultaneously — indicates that targeted, programme-specific fixes are unlikely to satisfy the regulator, and that a systemic transformation of the bank's risk management framework and governance culture will be required.