The United States’ 2022 anti-money laundering enforcement record was more complex than the headline suggested.
An industry analysis counted 19 AML-related actions by the Office of the Comptroller of the Currency, Financial Crimes Enforcement Network, Federal Deposit Insurance Corporation and Federal Reserve. That was an increase from 11 actions in 2021, although it remained below the 40 recorded in 2020.
Eight of the 2022 actions reportedly carried combined penalties of approximately US$384 million, compared with US$403 million across six monetary actions in 2021.
Those figures appeared to show moderately higher enforcement activity accompanied by a small decline in financial penalties. They did not, however, capture the complete US enforcement environment.
The Department of Justice, New York State Department of Financial Services, Office of Foreign Assets Control and other authorities pursued separate criminal, regulatory, sanctions and asset-recovery actions. Some resolutions overlapped, some included credit for payments made to another authority, and others addressed AML alongside cybersecurity, fraud or sanctions violations.
The result is not one national enforcement total, but a fragmented system in which different authorities use different powers against the same underlying financial-crime risks.
Key Takeaways
- US AML Enforcement Activity Increased in 2022
- Lower Aggregate Penalties Did Not Mean Lower Enforcement Risk
- Enforcement Statistics Can Be Misleading Without Methodological Context
- AML Failures Often Reflect Broader Governance Weaknesses
- Compliance Programmes Must Scale With Business Growth
- Repeat Supervisory Findings Signal Structural Control Failures
- Transaction Monitoring Remains a Major Enforcement Weakness
- Suspicious Activity Reporting Deficiencies Continue to Attract Scrutiny
- Digital Asset Firms Face the Same Core AML Expectations as Traditional Banks
- AML and Sanctions Failures Frequently Share Common Root Causes
- Foreign Banks Must Maintain Effective Controls Over US Operations
- Customer Expected Activity Must Be Continuously Reassessed
- Penalty Size Alone Is a Poor Measure of Enforcement Severity
- Non-Monetary Actions Can Create Significant Business Impact
- Later Enforcement Actions Confirmed That 2022 Was Not a Period of Reduced Risk
Listen the podcast
Watch the video
Why the 2022 enforcement record still matters
The year marked a transition in US financial-crime enforcement.
Traditional banks remained exposed to penalties for weak transaction monitoring, inadequate suspicious-activity reporting and failure to remediate repeat supervisory findings. At the same time, regulators increased their attention to cryptocurrency exchanges, digital-asset banks and technology-led financial businesses.
Treasury’s 2022 National Illicit Finance Strategy identified the abuse of legal entities, professional facilitation, virtual assets, corruption and technological change as significant vulnerabilities.
The enforcement cases concluded during the year reflected those concerns. Several institutions had expanded their customer bases, transaction volumes or product offerings without making corresponding investments in staffing, monitoring and governance.
This pattern later appeared in much larger resolutions involving Binance and TD Bank. The 2022 cases were therefore not evidence that enforcement pressure was disappearing. They were early indicators of the control failures that would produce record penalties over the following two years.
Why US enforcement totals are difficult to compare
The United States does not have one AML supervisor or one central enforcement authority.
FinCEN administers and enforces the Bank Secrecy Act. The OCC, Federal Reserve, FDIC and National Credit Union Administration supervise different categories of banking institution. State authorities, particularly New York DFS, impose additional requirements on institutions operating within their jurisdictions.
The Department of Justice can pursue criminal offences, including money laundering, Bank Secrecy Act violations, fraud and sanctions evasion. OFAC administers economic sanctions, while the Securities and Exchange Commission and Commodity Futures Trading Commission may address related misconduct within their markets.
A single institution can therefore face several simultaneous actions.
Adding every announced amount together can produce double counting. One authority may credit a payment made under another settlement. A criminal forfeiture may be presented alongside a civil penalty, while a monitor, activity restriction or cease-and-desist order creates consequences that have no simple monetary value.
Annual comparisons must therefore explain which authorities, offences and remedies are included.
USAA and the cost of compliance failing to scale
The largest federal banking AML penalty identified in the 2022 industry compilation involved USAA Federal Savings Bank.
FinCEN and the OCC imposed coordinated penalties totalling US$140 million. USAA paid US$80 million attributable to FinCEN’s action and US$60 million under the OCC resolution.
The bank admitted that it had willfully failed to maintain an AML programme satisfying minimum Bank Secrecy Act requirements between at least January 2016 and April 2021. It also admitted failures involving the accurate and timely reporting of thousands of suspicious transactions.
The enforcement action was not based on one isolated system defect. Regulators concluded that the institution’s customer base and revenue had grown while its compliance programme failed to keep pace.
The OCC also found that USAA had not corrected internal-control problems previously identified by supervisors.
This distinction is important. A newly discovered deficiency may indicate a control-design failure. A recurring deficiency indicates a governance failure because management knew about the exposure and did not resolve it effectively.
The resulting orders required improvements to internal controls, staffing, training and third-party risk management—not merely payment of a fine.
Repeat findings at the National Bank of Pakistan
The Federal Reserve and New York DFS took coordinated action against the National Bank of Pakistan and its New York branch.
The Federal Reserve imposed a US$20.4 million penalty, while DFS imposed a further US$35 million.
The findings concerned ineffective AML risk management, deficient transaction monitoring and inadequate managerial oversight. Supervisory concerns had been identified during earlier examinations, but significant weaknesses persisted across multiple review cycles.
DFS concluded that senior management had failed to promote an adequate compliance culture and had not provided sufficient resources to the New York branch.
The case illustrates why foreign banking organisations remain a priority within US enforcement.
A branch may form a small part of a global institution but still provide access to US dollar clearing and the wider American financial system. The parent organisation must ensure that global governance, customer information and monitoring systems support the risks created by that access.
Local compliance personnel cannot compensate indefinitely for weak data, limited authority or insufficient investment from the parent bank.
MoneyGram and the failure to investigate changing behaviour
New York DFS also imposed an US$8.25 million penalty on MoneyGram.
The action concerned transactions sent through several agents to recipients in China. Activity increased from approximately 7,500 transactions worth US$30 million in 2014 to more than 25,000 transactions exceeding US$100 million during a 17-month period in 2016 and 2017.
The issue was not simply that transaction volume increased.
The institution allegedly failed to investigate adequately whether the activity remained consistent with the purpose and expected behaviour of the agents and customers involved.
This is a recurring AML problem. Institutions often establish a baseline during onboarding but do not reassess the relationship when transaction volumes, destinations or customer behaviour change materially.
A risk-based programme must treat expected activity as a living hypothesis. Significant deviation should trigger investigation, customer engagement and, where appropriate, regulatory reporting or account restriction.
Digital assets moved towards the centre of enforcement
Several 2022 actions demonstrated that cryptocurrency businesses would be held to the same core financial-crime standards as traditional institutions.
FinCEN imposed a US$29.28 million penalty on Bittrex as part of a coordinated settlement with OFAC. The company’s US$24.28 million OFAC payment was credited against the FinCEN amount, preventing the two announced penalties from simply being added together.
FinCEN found that Bittrex had relied at times on as few as two employees to review more than 20,000 daily transactions manually. The company did not file any suspicious-activity reports between February 2014 and May 2017.
It also processed more than 116,000 transactions valued above US$260 million involving persons or entities in comprehensively sanctioned jurisdictions.
The case connected AML and sanctions risk directly. Weak customer identification and transaction monitoring limited the platform’s ability to detect suspicious activity, while inadequate location and counterparty controls allowed transactions involving sanctioned jurisdictions.
New York DFS separately fined Robinhood Crypto US$30 million for AML, cybersecurity and consumer-protection failures. Its AML programme was inadequately staffed, and its manual transaction-monitoring arrangements had not been upgraded sufficiently as the business expanded.
The OCC also issued a non-monetary consent order against Anchorage Digital Bank for failing to satisfy BSA/AML requirements attached to its operating agreement.
Together, the cases showed why enforcement intensity cannot be measured through fines alone. An activity restriction, monitor or supervisory order may materially affect a business even where no immediate penalty is imposed.
The Danske Bank resolution changed the financial picture
The largest financial-crime resolution announced in 2022 was not a conventional supervisory AML fine.
Danske Bank pleaded guilty to conspiracy to commit bank fraud and agreed to criminal forfeiture of approximately US$2.059 billion.
The bank admitted misleading US financial institutions about the customers and AML controls of its Estonian branch. Between 2008 and 2016, the branch processed approximately US$160 billion through US banks for high-risk non-resident customers.
The Department of Justice agreed to credit around US$850 million in payments associated with parallel resolutions involving Danish authorities and the SEC.
Danske’s case explains why some 2022 analyses produced totals exceeding US$2 billion while federal banking-regulator calculations produced hundreds of millions.
The resolution concerned access to the US financial system, deception of correspondent banks and the movement of suspicious funds. It was highly relevant to AML enforcement, but its principal criminal charge and financial remedy were not equivalent to a FinCEN civil money penalty.
Its wider lesson concerned the responsibility of global institutions for remote branches and acquired businesses. A group cannot rely on formal policies at headquarters while a high-risk subsidiary serves opaque customers through deficient controls.
Sanctions enforcement must be counted separately
OFAC concluded 16 civil enforcement matters in 2022 with combined penalties of approximately US$42.7 million.
Sanctions compliance and AML frequently overlap, but they are not identical.
AML controls seek to identify and report suspicious activity and prevent the financial system from being used to process criminal proceeds. Sanctions rules can prohibit transactions with designated persons, blocked entities or restricted jurisdictions regardless of whether the funds are criminal proceeds.
The Bittrex resolution illustrates the intersection. The same weaknesses in customer data, location controls and transaction monitoring created both Bank Secrecy Act and sanctions exposure.
Institutions should therefore share relevant information across AML and sanctions functions while preserving the distinct legal tests and escalation requirements.
A suspicious transaction may require investigation and reporting. A confirmed sanctions match may require immediate rejection or freezing.
Why penalty totals are a weak measure of deterrence
Annual fine values are heavily influenced by a small number of major cases.
One multibillion-dollar criminal resolution can make a year appear exceptionally aggressive even if the number of actions falls. A year containing many cease-and-desist orders or individual prohibitions may appear weak because those actions carry limited or no financial penalty.
Penalty size also does not show whether the institution experienced a monitor, business restriction, licensing consequence, historical transaction review or substantial remediation cost.
Nor does it show whether individuals were held accountable.
Enforcement effectiveness should instead be assessed through several dimensions: the seriousness of the misconduct, whether the action addressed the root cause, the speed of remediation, the removal of responsible individuals and whether the intervention prevented recurrence.
What happened after 2022
Later cases confirmed that the modest decline in aggregate penalties did not represent a sustained reduction in US enforcement risk.
In November 2023, Treasury imposed its largest settlements at that time against Binance. FinCEN assessed US$3.4 billion, OFAC imposed US$968 million, and the company became subject to a five-year monitorship and substantial compliance obligations.
In October 2024, TD Bank pleaded guilty to Bank Secrecy Act and money-laundering-conspiracy offences as part of coordinated resolutions exceeding US$3 billion.
The Department of Justice found that the bank’s transaction-monitoring programme had remained largely static despite increasing profits, changing products and repeated warnings. Approximately 92% of transaction volume went unmonitored during part of the relevant period.
The connection to 2022 is direct. USAA, Robinhood, Bittrex and other institutions had already demonstrated the consequences of allowing growth and transaction volume to exceed the capacity of the control environment.
What an evidence-led remediation programme looks like
Remediation should begin with the factual cause of the failure rather than the wording of the enforcement order.
Where suspicious transactions were not reported, the institution should determine whether the cause was missing data, inadequate scenarios, alert backlogs, poor investigations or management resistance.
Where regulators identified insufficient staffing, the institution should assess workload, expertise and decision authority—not simply increase headcount.
Historical reviews should establish which customers and transactions were affected and whether delayed reports, restrictions or exits are required.
Testing must demonstrate that the corrected control operates across real customer and transaction data. A new policy or system does not prove effectiveness until it produces appropriate outcomes.
Boards should receive evidence showing alert ageing, transaction coverage, overdue customer reviews, data failures, unresolved findings and the time taken to implement compliance decisions.
What a resilient control stack looks like
The first layer is a current enterprise-wide risk assessment connected to actual products, customers, geographies and transaction channels.
The second is scalable customer due diligence capable of keeping pace with growth and identifying material changes in ownership or expected activity.
The third is complete data coverage. Every relevant transaction type should enter monitoring and screening systems accurately and on time.
The fourth is risk-sensitive surveillance combining rules, behavioural analysis and documented threshold governance.
The fifth is effective case management. Alerts must lead to timely investigation, escalation and defensible decisions.
The sixth is integrated AML and sanctions intelligence, with clear distinctions between reporting obligations and immediate legal prohibitions.
The seventh is independent testing capable of identifying whether remediation has reduced exposure in practice.
Finally, boards and senior management must treat repeat findings, overdue action plans and control overrides as indicators of structural risk.

What this means for financial crime leaders
The US enforcement record in 2022 should not be interpreted as a simple increase in actions or decline in penalties.
It demonstrated that enforcement statistics depend on methodology and that financial consequences extend beyond civil fines.
More importantly, the cases exposed a consistent operating failure: institutions expanded customers, products and transaction volumes without building financial-crime controls capable of supporting that growth.
Financial crime leaders should therefore look beyond annual league tables and examine the control weaknesses described in each action.
The most significant question is not how much another institution paid. It is whether the same deficiency—insufficient staffing, incomplete monitoring, weak escalation or unresolved supervisory findings—exists within their own organisation.
Enforcement risk becomes material long before a penalty is announced. It develops when known weaknesses are allowed to persist while the business continues to grow.
What Financial Institutions Should Consider
- Ensure AML Controls Scale With Customer and Transaction Growth
- Strengthen Enterprise-Wide Financial Crime Risk Assessments
- Maintain Complete Transaction Monitoring Coverage
- Improve Suspicious Activity Reporting Quality and Timeliness
- Monitor Material Changes in Customer Behaviour
- Strengthen Governance Over Repeat Regulatory Findings
- Escalate Overdue Remediation Actions
- Ensure Compliance Functions Have Adequate Resources and Authority
- Strengthen AML Controls for Digital Asset Activity
- Integrate AML and Sanctions Intelligence
- Improve Customer and Counterparty Data Quality
- Review High-Risk Foreign Banking Relationships
- Conduct Historical Reviews After Material Control Failures
- Perform Root-Cause Analysis Rather Than Policy-Only Remediation
- Test Whether Remediation Works on Real Customer and Transaction Data
- Monitor Alert Backlogs and Overdue Customer Reviews
- Strengthen Board-Level Financial Crime Reporting
- Measure Control Effectiveness Beyond Regulatory Fine Values
- Treat Repeat Findings and Control Overrides as Structural Risk Indicators




The United States’ 2022 AML enforcement record cannot be understood through a simple comparison of case numbers and penalty totals. Different regulators, prosecutors and sanctions authorities applied different legal powers, while coordinated settlements, credited payments and criminal forfeitures complicated any attempt to calculate a single national figure.
The more important finding is the consistency of the underlying control failures. Institutions expanded their customer bases, products and transaction volumes without ensuring that staffing, data quality, transaction monitoring and escalation processes developed at the same pace.
The USAA, National Bank of Pakistan, MoneyGram, Bittrex and Robinhood Crypto actions showed that enforcement risk grows when known deficiencies remain unresolved. Repeat supervisory findings, inadequate monitoring coverage and delayed suspicious-activity reporting are not isolated operational problems; they indicate weaknesses in governance and senior-management accountability.
The cases also demonstrated the increasing convergence of AML, sanctions and digital-asset risk. Poor customer information, ineffective location controls and incomplete transaction monitoring can expose an institution simultaneously to money laundering, sanctions evasion, fraud and cyber-enabled crime.
For financial crime leaders, the practical lesson is to look beyond enforcement league tables. The relevant question is not whether another institution received a larger penalty, but whether the same control weakness exists internally and whether management can demonstrate that remediation has reduced the underlying risk.
Ultimately, enforcement exposure develops long before a regulator announces a settlement. It begins when business growth outpaces compliance capacity, known deficiencies remain open and commercial objectives are allowed to override risk-based decisions. Institutions that treat repeat findings as structural warnings—and connect customer due diligence, data governance, monitoring and board oversight—will be better positioned to prevent those weaknesses from becoming enforcement cases.