OCC Enters Consent Order with FinTech Bank for BSA/AML Violations
The OCC entered into a consent order with a fintech partner bank over its Bank Secrecy Act and Anti-Money Laundering (BSA/AML) compliance program.
The OCC found that the bank, which has a single branch, had been growing its payment processing business significantly over the last few years, relative to its size. This included a large volume of wire and ACH transfers, as well as cross-border activity involving foreign financial institutions. Despite the growing volume of transactions, the bank failed to develop a BSA/AML program commensurate with its risk and growth. Problems included:
- Setting deficient criteria to govern the bank’s automated suspicious activity alerting system, such that the system automatically closed many alerts that should have been escalated for further review;
- Insufficient customer due diligence, including failures to understand the nature of certain customers’ businesses and the purposes of payment processing transactions;
- Failing to determine whether it had correspondent accounts with foreign financial institutions; and
- A weak internal auditing program which did not effectively test its BSA/AML program and failed to identify weaknesses.
The bank did not admit or deny the allegations. The consent order required, among other things, that the bank: create a compliance committee to monitor and oversee compliance with the consent order; develop a corrective action plan; obtain a comprehensive third-party review of its BSA/AML program; develop a new system of BSA/AML internal controls, including regular risk assessments and an updated customer due diligence program; implement a new risk-based program to identify, evaluate, and report suspicious activity; retain an independent third-party to conduct a look-back report for previously unreported suspicious activity; and create an independent BSA/AML testing and audit program. The consent order did not provide for a monetary penalty.
