Biscuits & Jelly: Dangerously Delicious
top of page

EXPERTS INSIGHTS

Biscuits & Jelly: Dangerously Delicious

  • Writer: SEDA Experts
    SEDA Experts
  • 3 hours ago
  • 5 min read

“Bank Secrecy Act/Anti Money Laundering criticism continues to roll out of Supervisory Agencies like Jelly from a Jar” was the headline for this article dated 2019. Smucker’s Jelly is still served with a spoon; and Supervisory Agencies continue to issue enforcement actions on institutions for Anti-Money Laundering (AML) deficiencies.


Recognizing just the right amount of AML controls for your institution is difficult. Similar to enjoying a biscuit, often you realize there is a problem only after you have Jelly on your best dress shirt.


Since this article (originally published Nov. 2019), there have been an additional 79 institutions that issued formal orders for Bank Secrecy Act (BSA) failures. The story really hasn’t changed. Kids (and often Adults) need help with “jelly”. Institutions fail to realize their own need for HELP to navigate AML expectations.


June 2026 a $1B Texas bank was issued Consent Orders by the Office of the Comptroller of the Currency (OCC). This order addresses Ineffective Board Oversight, Internal Controls, Risk Assessment, Audit, efficacy of the AML Officer, and policy and procedure deficiencies. This order further focused on Customer Due Diligence, Suspicious Activity Monitoring and Reporting, and Office of Foreign Assets Control (OFAC).


March 2026 a $100M Mississippi Bank was issued Consent Orders by the Federal Deposit Insurance Corporation (FDIC). This order addressed Board Oversight, Risk Assessment, suspicious activity reporting, customer due diligence, currency transaction reporting, an ineffective AML Officer, training.


Midsize and large institutions are not excluded from these actions. Their issues have been documented and published across news feeds and other professional associations.


These SEVENTY-NINE Banks and their Consent order serve as an example to every institution when it comes to BSA/AML. The expectations and accountability are equal among both large and small institutions. No institution is too small, and there are no size/complexity thresholds.


While a variety of internal control deficiencies seem to be the root cause for these actions. The rest of the story may change your mind. The Agencies assert that the Banks “fail to develop and provide for the continued administration of an adequate system of internal controls”. The specific assertions are “quoted” below and accompanied by our own guidance.


a. Risk Assessment Scope


Finding:


“Failure of the Risk Assessment (RA) process to assess the particular BSA risks associated with all products, services, customers, entities, transactions, and geographic locations.”


Guidance: You RA must evaluate all customers. To only evaluate higher risk of customers and to overlook quantity and volumes of transactions associated with customers, products or services is ill-conceived. Risk assessment models are often seen as “cool” models. But often fail to document the Facts required to support the model.


b. Monitoring of Higher-Risk Products and Services


Finding:


“Failed to adequately monitor and manage the delivery of higher risk products and services; and failed to detail the mitigating controls used to offset the associated, inherent BSA risks.


Guidance: The risk is not the existence of Mobile Deposit and Remote Deposit Capture customers (for example). The risk lies in trends; and whether the usage (transaction volume) is reasonable. Which customers produce the highest volume?


c. Customer Risk-Rating Methodology


Finding:


“Failed to have an adequate BSA customer risk-rating system that is consistently applied and based on a well-documented methodology.”


Guidance: Do you have a high-risk customer list for both Commercial & Consumer relationships; or do you have a listing of customers in higher risk industries? There’s a big difference. Consumer risk and commercial customers have completely different risk profiles. An effective risk-rating system will differentiate between the two.


d. Enhanced Customer Due Diligence


Finding:


“Failed to adequately develop and implement "increased customer due diligence" procedures for its higher-risk customers.”


Guidance: You cannot monitor higher-risk customers if you do not know who they are? INCREASED is a key word here. Does Your AML system accurately identify higher-risk customers; or do you have your own “manual” list and ignore the system generated list of higher-risk customers?


e. Transaction Monitoring Systems


Finding:


“Failed to adequately implement account monitoring systems necessary to monitor customer transactions for suspicious activity.”


Guidance: Do you understand the risk scoring system and how system rules and alerts are functioning? Do you have duplicate overlapping alerts? If so, you may have gaps as well.


f. BSA Staffing and Resource Allocation


Finding:


“Failed to appropriately analyze the staffing and resource allocation needs for adequate performance of its BSA compliance program.”


Guidance: Have you been informed the BSA program is stressed or the “ONE” BSA officer is stretched too thin? Do you have adequate 2nd reviews of cases & Suspicious Activity Reports (SARs)? Are you operating in denial? The signs are there, but no one is asking for assistance?


g. Risk-Rating Governance and Consistency


Finding:


“Failed to have an adequate BSA customer risk-rating system that is consistently applied and based on a well-documented methodology.”


Guidance: Key words “well-documented” and “consistently applied”? Your institution may need assistance understanding how to meet these expectations.


h. Operational Knowledge of Higher-Risk Customers


Finding:


“Failed to adequately develop and implement "increased customer due diligence" procedures for its higher-risk customers.”


Guidance: Are your higher-risk customers acquainted with the BSA Team? Better yet, is your BSA Team acquainted with your high-risk customers? Retrieve your system’s list of Human Resources customers and simply call out the names of customers amongst your BSA team. If there’s silence in the room, you may have an issue.


i. Effectiveness of Transaction Monitoring Technology


Finding:


“Failed to adequately implement account monitoring systems necessary to monitor customer transactions for suspicious activity.”


Guidance: Do your systems work? Are you utilizing the functionality of the system for monitoring purposes? Changing to a more costly, more complex system may not solve your challenges. The issue is most often not the system; it’s how the system is used (it’s the user).


j. Weak independent testing


Finding:


“The Bank’s internal auditor also failed to scope in its audit work and effectively test high-risk areas of the Bank’s BSA/AML program.”


Guidance: Is audit operating in their own silo? Audit functions are independent, but they should be part of your team. Your AML Officer and Management should leverage audit to evaluate those areas causing the most frustration for your AML Program. Audits actually help us improve.


k. BSA Officer Authority and Program Oversight The final failure is truly the ultimate root cause


Finding:


“Failure to endow the BSA Officer with an appropriate level of delegated authority and resources for coordinating and monitoring day-to-day BSA compliance as evidenced by failure of the BSA Officer to administer a comprehensive and robust BSA compliance program”.


Guidance: Every institution is faced with expectations of growth and managing expenses. Many seek a program that is trim and just meets expectations. I have also assisted several larger institutions that over-staffed their risk functions. Over-staffing creates its own unique set of challenges as well. Engage an industry expert to mentor your AML Officer and boost your existing program to operate more effectively. This is a short-term investment for long-term profitability.



Conclusion


Once again, we leave you with these final thoughts:


  1. Has your bank engaged industry experts to guide your institution to success. Whether this includes employees, consulting, monitoring or auditing teams; external or internal… Are they equipped to keep Jelly off your shirt?

  2. Has your “expert” been guiding you for way too long; only to have continuing issues or a never-ending financial cost for their services? Maybe it’s time to consider obtaining someone who can actually get you across the finish line.


The opinions, views, and statements expressed in this article are solely those of the individual authors and do not represent, reflect, or constitute the views or opinions of SEDA Experts.

EXPERT INVOLVED

Kenneth Simmons - Managing Director


Kenneth Simmons is a renowned expert in regulatory compliance, fraud, anti-money laundering (AML), Sanctions, and the Bank Secrecy Act (BSA). His background spans hands‑on leadership roles within major financial institutions as well as influential positions across multiple regulatory bodies.





Contact Us

+1 646-626-4555

 
 
 
bottom of page