American Express 350 Million Fine Reveals Cost of Compliance Failures
austin carrollA compliance program can look perfectly fine on paper and still leave a business exposed. American Express is facing a $350 million penalty after US banking regulators identified serious weaknesses in its anti-money laundering controls, offering a costly reminder that policies are only as effective as the systems and people responsible for enforcing them.
The enforcement action, announced on October 8, 2026, puts a spotlight on a familiar challenge for regulated businesses: keeping compliance controls aligned with the risks their operations actually create.
According to Reuters, the Office of the Comptroller of the Currency (OCC) imposed the penalty on American Express National Bank, while the Federal Reserve issued a separate cease-and-desist order against American Express and its travel-related services subsidiary.
American Express Overlooked 13 Billion Dollars in Suspicious Activity
The OCC found that American Express National Bank failed to identify, evaluate, and sufficiently report approximately $13 billion in suspicious activity over the past decade.
The regulator identified several weaknesses in the bank's anti-money laundering program, including inadequate staffing, insufficient employee expertise, gaps in training, and deficiencies in internal controls. Problems with customer identification and due diligence also contributed to the shortcomings.
One finding stands out: the bank's risk assessment did not adequately reflect the way its business operated. According to the OCC, American Express focused disproportionately on its relatively limited deposit products while paying insufficient attention to risks associated with its much larger credit and charge card businesses.
In other words, the bank's approach did not adequately account for the risks across its operations. That disconnect matters because a compliance program cannot provide meaningful protection if it overlooks important parts of the business it is designed to monitor.
American Express did not admit or deny the regulators' findings. CEO Stephen Squeri said the company was committed to addressing regulators' concerns and strengthening its compliance programs. He also said the penalty and associated compliance expenses were not expected to affect the company's financial guidance for 2026 and 2027.
The Real Compliance Risk Is Assuming Your Controls Still Work
The American Express case illustrates why compliance cannot be a set-and-forget exercise. Business models change, products expand, and customer activity evolves. Controls that once seemed sufficient may no longer reflect the risks an organization faces.
The same principle matters in marketing compliance, although the regulatory obligations are different. Financial institutions must meet anti-money laundering requirements, while marketing teams in regulated industries need to manage advertising claims, disclosures, brand standards, and applicable regulations.
A team might have detailed policies and an approval process, yet still struggle if employees cannot find the latest guidance, disclosures are inconsistent across campaigns, or content bypasses required reviews.
The issue is not necessarily an absence of rules. It can be the gap between what a policy requires and what happens during everyday work.
Three Lessons Regulated Businesses Should Take From the Fine
The enforcement action offers three practical lessons for organizations managing regulatory risk.
Assess the risks your business actually creates. Review individual products, services, departments, and communication channels. Avoid relying on broad risk assessments that overlook important activities or emerging vulnerabilities.
Make compliance guidance usable. Employees need clear policies, relevant training, and sufficient resources to follow requirements consistently. Guidance should be updated when business activities or regulatory expectations change.
Build monitoring and accountability into daily workflows. Establish clear review procedures, document decisions, escalate concerns, and verify that corrective actions are completed. Regular testing can help reveal weaknesses before they become more serious.
These steps cannot eliminate every risk, but they can help businesses spot gaps earlier and respond before problems escalate.
Why Marketing Teams Need More Than an Approval Checklist
For marketing teams in financial services and other regulated industries, compliance becomes more challenging as content moves across campaigns, channels, and employee advocacy programs.
Scattered policy documents, manual reviews, and disconnected approval processes can make it difficult to confirm that the right requirements were followed. They can also reduce visibility into who approved content, what changes were made, and whether required disclosures were included.
Technology can help bring policies, review workflows, and compliance checks into a more consistent process. Warrant supports regulated marketing teams with tools for managing content reviews, applying compliance requirements, and maintaining visibility throughout the content lifecycle. These tools complement, rather than replace, qualified oversight and sound governance.
The lesson from the American Express enforcement action extends beyond banking: compliance controls must reflect real-world risks, and organizations need to verify that those controls work in practice.