OCC Issues Consent Order Against Community Federal Savings Bank Over BSA/AML Deficiencies
Office of the Comptroller of Currency sign and logo in downtown,Andriy Blokhin / Shutterstock.com.

The Office of the Comptroller of the Currency issued a cease-and-desist consent order against Community Federal Savings Bank on Thursday, citing significant deficiencies in the lender's Bank Secrecy Act and anti-money laundering compliance programme. The action was disclosed in OCC news release NR-OCC-2026-40 and filed under Docket AA-ENF-2025-21.

The order requires the bank to remediate breaches of core federal rules that govern how institutions detect and report suspicious activity, including obligations tied to information-sharing between banks and law enforcement under the USA PATRIOT Act. Community Federal, headquartered in New York, is a nationally chartered savings bank widely known for providing sponsor-bank services to a range of fintech partners.

COMPLIANCE PROGRAMME FAILURES

According to the OCC, the deficiencies encompassed violations of 12 CFR 21.21, which requires banks to maintain a written BSA compliance programme reasonably designed to assure and monitor adherence to anti-money laundering laws. Regulators also flagged failures under 12 CFR 163.180(d), the rule governing the timely filing of Suspicious Activity Reports on transactions that may indicate potential wrongdoing.

A third strand of the order concerns 31 CFR 1010.520(b)(3), a USA PATRIOT Act provision that establishes procedures for financial institutions to share information with federal law enforcement about suspected terrorist activity or money laundering. Taken together, the cited breaches touch each of the pillars that supervisors typically probe in a BSA/AML examination — programme design, suspicious-activity reporting and inter-agency information-sharing.

The OCC did not disclose a monetary penalty in the release. Consent orders of this type typically compel banks to overhaul governance, staffing, transaction-monitoring systems and customer due-diligence procedures within defined timelines, and to submit regular progress reports to the supervisor. For community banks that offer sponsor-bank services to fintechs, such orders can also trigger a reappraisal of onboarding standards and the pace at which new programmes are approved.

PROHIBITION AGAINST FORMER JPMORGAN EMPLOYEE

In the same release, the OCC announced an Order of Prohibition against Dyemond Williams, a former associate at JPMorgan Chase. The regulator said Williams was responsible for at least USD 38,500 in unauthorised withdrawals, conduct that renders her permanently barred from working in any federally insured depository institution without OCC approval.

The dual announcement is characteristic of the OCC's monthly enforcement bulletins, which combine institutional actions with individual bans and civil money penalties against former bank staff. The community-bank action, however, is the more consequential item for the industry, coming as US regulators continue to scrutinise the compliance frameworks underpinning bank-fintech partnerships and the resources smaller institutions dedicate to policing them.

Community Federal has not published a response to the order. The bank retains the right to remedy the identified deficiencies under the timeframes set out by the OCC. The order and accompanying materials are available on the regulator's website, alongside the wider list of May enforcement actions. Follow-on examinations will typically test whether the remediation programme has been implemented in practice, not merely committed to on paper. The OCC's public enforcement register is one of the most consulted resources for compliance officers and boards benchmarking the calibre of expectations placed on their own institutions, and community banks with fintech clients tend to review such actions closely for read-across implications.