American Express has been fined $350 million by US banking regulators after they found serious weaknesses in its anti-money-laundering compliance programme. The Office of the Comptroller of the Currency (OCC) said the bank failed to identify, evaluate and sufficiently report roughly $13 billion in suspected trade-based money-laundering activity over about a decade. The enforcement action is a reminder that even large, established financial brands can face major regulatory consequences when transaction monitoring, staffing, training and customer checks do not match the risks of their business.

What happened: regulators impose a $350 million penalty

US regulators announced enforcement actions against American Express and related entities on October 8, 2026. The OCC imposed a $350 million civil money penalty on American Express National Bank and issued an order requiring corrective action. The Federal Reserve also announced a separate enforcement action concerning weaknesses in the company’s anti-money-laundering programme.

According to Reuters, the OCC said the bank did not maintain a compliance programme adequate for the risks associated with its operations. Regulators pointed to insufficient resources, inexperienced staff, weak training and gaps in internal controls. They also identified shortcomings in customer identification and due diligence practices.

American Express did not admit or deny the regulators’ findings as part of the action. Chief Executive Stephen Squeri said the company takes its responsibility to combat financial crime seriously and is committed to addressing the concerns. He also said the penalty and remediation costs were not expected to change the company’s financial guidance for 2026 and 2027.

The headline figure is substantial, but the regulatory action is about more than the payment itself. The company must address the underlying control weaknesses and satisfy regulators that its systems can identify and escalate suspicious activity appropriately.

What does the $13 billion figure actually mean?

The OCC said that systemic breakdowns in monitoring and reporting led American Express National Bank to fail to identify, evaluate and sufficiently report roughly $13 billion in suspected trade-based money-laundering activity over the past decade. This is a figure describing activity regulators considered suspicious and inadequately handled by the bank’s controls. It is not a finding that $13 billion was definitively proven to be criminal proceeds, nor does it mean the bank itself lost $13 billion.

Trade-based money laundering is a method in which trade transactions are used to disguise the origin or movement of illicit funds. It can involve misrepresenting the value, quantity or nature of goods, or using invoices and payments to make suspicious money flows look like ordinary commercial activity. Because trade and payment networks can span countries, investigators may need to compare transactions with customer profiles, invoices, counterparties and other information to assess whether activity makes sense.

Financial institutions are generally expected to monitor activity for warning signs, investigate alerts and file reports with the appropriate authorities when legal thresholds are met. A suspicious-activity report is not itself a conviction or proof that a customer committed a crime. It is a mechanism for sharing relevant concerns with law enforcement and regulators.

The distinction matters. The regulatory finding concerns the bank’s ability to detect, evaluate and report suspicious activity in a timely and sufficient way. The dollar figure signals the scale of transactions implicated by the monitoring failures, not a final criminal judgment about every transaction included in that amount.

The compliance gaps regulators identified

Anti-money-laundering controls typically combine technology, people, processes and oversight. Software may flag unusual patterns, but trained staff must investigate alerts, understand customer activity, escalate cases and document decisions. Governance teams must also test whether the controls work and ensure resources are allocated to the actual risk.

The OCC identified several weaknesses at American Express National Bank:

  • Insufficient resources: regulators said the programme lacked adequate resources to handle its responsibilities.
  • Staff expertise and training: inexperienced personnel and weak training were among the concerns identified.
  • Internal-control gaps: processes were not effective enough to ensure suspicious activity was properly identified and reported.
  • Customer checks: regulators cited shortcomings in customer identification and due diligence.
  • Risk assessment: the OCC said the bank’s approach did not sufficiently reflect the risks in its broader business activities.

These issues can reinforce one another. If a monitoring system generates alerts but the team is understaffed, investigations may be delayed. If customer information is incomplete, analysts may struggle to judge whether activity is unusual. If risk assessments overlook a major product line, the bank may fail to build controls around the transactions that need the most attention.

Regulators therefore look at the whole compliance framework, not only whether a bank has purchased monitoring software or written policies. Effective controls need to work in daily operations and be tested as products, customer behaviour and financial-crime methods change.

Why the credit-card business mattered

The OCC said American Express focused on risks in its relatively narrow deposit products and services without giving sufficient attention to the much larger credit-card business. That observation highlights a basic principle of risk management: controls must reflect where a company’s transactions and exposures actually occur.

American Express is widely known for its credit and charge cards, while its national bank also offers deposit products. Different products can create different risk patterns. A monitoring framework designed primarily around deposit accounts may not be enough for a business whose larger transaction flows run through card and payment services.

That does not mean credit-card transactions are inherently suspicious. It means a bank’s risk assessment must account for the size, structure and nature of the activities it processes. Monitoring rules, customer checks and investigative resources should be proportionate to those activities rather than built around only one part of the business.

For other financial companies, this is a practical lesson: as businesses add payment channels, commercial customers, international activity or new products, compliance teams must revisit their assumptions. Controls that were adequate for a smaller operation can become insufficient as transaction volumes and complexity grow.

What the fine means for American Express

The immediate cost is the $350 million penalty, alongside the expense of improving compliance systems, reviewing historic activity and reporting progress to regulators. The enforcement orders also create management and governance work that can continue after the fine is paid. The bank must demonstrate that its remediation is effective rather than merely promise to make changes.

American Express said the penalty and the costs of meeting regulatory requirements were not expected to affect its 2026 or 2027 financial guidance. That is the company’s stated outlook, not a guarantee that the issue will have no future business impact. Remediation expenses, management attention and the results of regulatory follow-up will depend on how the work proceeds.

For customers, the announcement does not by itself mean that ordinary card accounts are being shut down or that customer funds have been declared unsafe. The enforcement action concerns compliance with financial-crime controls. Customers should rely on official company communications for any account-specific changes and continue to protect their account credentials and review transactions as usual.

For investors, the issue is one of execution and oversight. A large penalty can raise questions about governance, internal controls and the cost of remediation. However, the company’s financial guidance statement should be distinguished from independent analysis of the longer-term reputational or operational consequences.

The wider lesson for banks and fintech companies

Anti-money-laundering compliance is not only a paperwork requirement. It is part of the infrastructure that helps financial institutions identify suspicious financial flows and provide useful information to law enforcement. Banks, card networks and fintech firms may process enormous volumes of legitimate transactions, making effective risk-based monitoring essential.

Three lessons stand out. First, compliance budgets and staffing need to match the institution’s scale and complexity. Second, customer due diligence and transaction monitoring must cover the products and channels where the business actually operates. Third, independent testing and governance need to identify failures early, before they become systemic.

Technology can support these goals by helping teams detect unusual patterns, prioritise alerts and connect information across systems. But automated tools are not a substitute for clear accountability, well-trained investigators and reliable escalation processes. Poor data, weak rules or inadequate staffing can undermine even sophisticated software.

Fintech companies should pay attention as they expand into cards, lending, transfers and cross-border payments. Rapid customer growth can create new risks faster than internal controls evolve. Building compliance capability early is generally less disruptive than repairing major gaps after regulators intervene.

Abhijeet Take

The most important detail in this case is not just the $350 million fine. It is the gap regulators identified between the risks in American Express’s business and the controls used to monitor them. A financial company can have a trusted brand and a large customer base, but that does not make its compliance systems effective by default.

The $13 billion figure also needs careful wording: regulators described suspected activity that was not adequately identified and reported; it should not be presented as $13 billion of proven money laundering or as money lost by Amex. That distinction is important for readers trying to understand what the enforcement action actually says.

For the wider industry, the message is straightforward: transaction monitoring, customer checks, staff training and independent oversight need to evolve with the business. The real test for Amex will be whether its corrective actions resolve the weaknesses and stand up to regulatory scrutiny over time.

Frequently asked questions

Why was American Express fined $350 million?

US regulators found major deficiencies in American Express National Bank’s anti-money-laundering compliance programme, including weaknesses in staffing, training, internal controls and monitoring.

Was $13 billion proven to be money laundering?

No. The OCC described roughly $13 billion in suspected trade-based money-laundering activity that was not adequately identified, evaluated or reported. That is not the same as a finding that every transaction was proven criminal.

Did American Express admit wrongdoing?

Reuters reported that American Express did not admit or deny the regulators’ findings as part of the enforcement action. The company said it was committed to addressing the concerns.

Will the fine affect Amex’s financial outlook?

CEO Stephen Squeri said the penalty and remediation costs were not expected to affect the company’s guidance for 2026 and 2027. This is the company’s stated outlook.

Does this mean Amex cardholders need to do anything?

The enforcement action does not itself announce a general change to cardholder accounts. Customers should follow official Amex communications and contact the company directly for account-specific questions.

Sources and reporting notes

Reuters — American Express fined $350 million for insufficient anti-money-laundering programme (October 8, 2026)

Banking Dive — Amex fined by Fed and OCC over AML failures

Reporting note: The article distinguishes regulator allegations and compliance findings from a criminal conviction. The $13 billion amount refers to suspected activity cited by regulators, not a proven total of criminal proceeds.