An OCC consent order maps the BaaS failure pattern

Payments volume at Community Federal Savings Bank grew faster than its controls. Every fintech-partner bank should read the detail about the alert-triage system that auto-closed what it should have escalated.

AA-ENF-2025-21
Consent order
Down: 2020→
Payments growth period
90 days
Action-plan deadline
$0
Civil money penalty

The OCC’s consent order against Community Federal Savings Bank of Woodhaven, New York (AA-ENF-2025-21, executed April 24 and released May 21) is a case study in a pattern examiners now look for on sight. It shows a small institution whose payment-processing business grew dramatically while its BSA/AML program stood still. The order cites violations of the BSA compliance-program rule (12 C.F.R. § 21.21), suspicious-activity reporting requirements, and Section 314(a) information-sharing obligations.

The findings read like a checklist of fintech-partner risk. Since 2020 the bank “significantly grew its payment processing line, relative to its size,” including cross-border activity with foreign financial institutions, but it “failed to develop and maintain controls and risk management processes commensurate with its risk and growth.” Customer due diligence was found ineffective, independent testing weak, BSA staffing thin, and internal audit missed all of it.

The detail that should stop you

The most instructive finding is about automation. The bank ran an automated alert-triage system, but “several deficiencies in its logic, data, and methodology resulted in the system auto-closing alerts that should have been escalated for further review. As a result, the system auto-closed a very high percentage of all ingested alerts.” A misconfigured automated control became an automated failure at scale.

A triage model that auto-closes what it should escalate has stopped monitoring. It has become a suppression program with good intentions.

The order’s clock

Key remediation deadlines in the order
DeadlineRequirement
15 daysBoard compliance committee of 3+ members, mostly non-employee directors
90 daysWritten action plan to the OCC for non-objection (Articles V–X)
Per planIndependent consultant engaged for a SAR look-back review
60 days after look-backConsultant’s report on the look-back due
OCC consent order AA-ENF-2025-21

Two things the order does not do are also worth noting. It imposes no civil money penalty, and it states expressly that its findings are “based on concerns largely unrelated to customers involved in digital assets activities.” This is a story about controls. It is not a story about crypto.

What this means for your bank
  • Validate your alert-triage and auto-close logic against escalation outcomes. Sample the closed queue as well as the worked one.
  • Tie BSA staffing and monitoring capacity to payments volume with a written trigger, so growth forces a program review automatically.
  • Refresh CDD on payment-processing and fintech-program customers until you can state each one’s business and expected activity in a sentence.
From Zovos AI

Zovos benchmarks your alert auto-close rate and escalation outcomes against your transaction growth, and flags the divergence examiners flagged here before your exam finds it.

Sources

This is for information only and is not legal advice. Confirm your obligations against the order text and counsel before acting.