The OCC’s consent order against Community Federal Savings Bank of Woodhaven, New York (AA-ENF-2025-21, executed April 24 and released May 21) is a case study in a pattern examiners now look for on sight. It shows a small institution whose payment-processing business grew dramatically while its BSA/AML program stood still. The order cites violations of the BSA compliance-program rule (12 C.F.R. § 21.21), suspicious-activity reporting requirements, and Section 314(a) information-sharing obligations.
The findings read like a checklist of fintech-partner risk. Since 2020 the bank “significantly grew its payment processing line, relative to its size,” including cross-border activity with foreign financial institutions, but it “failed to develop and maintain controls and risk management processes commensurate with its risk and growth.” Customer due diligence was found ineffective, independent testing weak, BSA staffing thin, and internal audit missed all of it.
The detail that should stop you
The most instructive finding is about automation. The bank ran an automated alert-triage system, but “several deficiencies in its logic, data, and methodology resulted in the system auto-closing alerts that should have been escalated for further review. As a result, the system auto-closed a very high percentage of all ingested alerts.” A misconfigured automated control became an automated failure at scale.
A triage model that auto-closes what it should escalate has stopped monitoring. It has become a suppression program with good intentions.
The order’s clock
| Deadline | Requirement |
|---|---|
| 15 days | Board compliance committee of 3+ members, mostly non-employee directors |
| 90 days | Written action plan to the OCC for non-objection (Articles V–X) |
| Per plan | Independent consultant engaged for a SAR look-back review |
| 60 days after look-back | Consultant’s report on the look-back due |
Two things the order does not do are also worth noting. It imposes no civil money penalty, and it states expressly that its findings are “based on concerns largely unrelated to customers involved in digital assets activities.” This is a story about controls. It is not a story about crypto.
- Validate your alert-triage and auto-close logic against escalation outcomes. Sample the closed queue as well as the worked one.
- Tie BSA staffing and monitoring capacity to payments volume with a written trigger, so growth forces a program review automatically.
- Refresh CDD on payment-processing and fintech-program customers until you can state each one’s business and expected activity in a sentence.
Zovos benchmarks your alert auto-close rate and escalation outcomes against your transaction growth, and flags the divergence examiners flagged here before your exam finds it.
This is for information only and is not legal advice. Confirm your obligations against the order text and counsel before acting.