Nsight Blog | Ncontracts

Enforcement Actions Roundup: July 2026

Written by Jenna Zacharewicz and Toni Fennell | Aug 11, 2026, 7:00:01 PM

Welcome to the latest Enforcement Actions Roundup. BSA and AML deficiencies and insider activities dominated this month's actions, from prison sentences for two bank insiders convicted of facilitating money laundering to a former chief lending officer permanently barred over altered appraisals. The OCC and FDIC rounded things out with consent orders touching correspondent banking gaps, a broken compliance management system, and repeat flood insurance force-placement failures. 

Each month, we break down what went wrong, why it matters, and what your financial institution (FI) can do to stay ahead — giving you two resources: the Enforcement Actions Tracker, a running tally of actions by agency, category, and topic, and the Enforcement Deep Dive below, a closer look at each action's details, takeaways, and controls to revisit. 

Related: Bookmark the Ncontracts Enforcement Action Tracker to search the latest enforcement actions by date, category, and regulator.     

2025/2026 Enforcement Action Tracker

 
  Year Fair Lending Advertising AML/CFT Underwriting UDAAP Electronic Funds Transfers Insider Activities Flood Insurance Financial Risk Concentration Military Lending Government Loan Programs
CFPB 2025 1 2     4 1         1  
  2026 YTD         1              
DOJ 2025                        
  2026 YTD     2               1
OCC 2025     3       1   8 3    
  2026 YTD   1 1                  
FRB 2025         1     3 1      
  2026 YTD       1     2   1      
FDIC 2025     5 3 1 1 1 10 6      
  2026 YTD 1   1 2     2 6 3      
NCUA 2025                        
  2026 YTD                        

 

Enforcement Actions Deep Dive: July 2026

CFPB Enforcement Actions

The CFPB issued no institutional enforcement actions in July 2026. 

DOJ Enforcement Actions

DOJ Secures Prison Sentences for Bank Insiders Who Facilitated Money Laundering, Fraud

The DOJ announced that two former national bank employees were sentenced for facilitating money laundering and fraud from inside the bank. A former assistant store manager was sentenced to 46 months in prison for leveraging his position to help a money laundering network move hundreds of millions of dollars through accounts between 2019 and February 2021, including processing roughly 1,680 official bank checks totaling more than $92 million for his co-conspirator. The former assistant manager repeatedly failed to identify the co-conspirator on required currency transaction reports (CTR) despite knowing of the cash deposits and prior account closures for suspicious activity and accepting over $11,000 in gift cards for his assistance.  

A second former employee was sentenced to 24 months for accepting at least $26,700 in bribes to obtain confidential customer information used to take over accounts, facilitating $484,572 in fraud at the institution. The individual later falsified records at another institution to open a shell company account used for additional fraud.  

Takeaways

This action highlights insider risk as a direct threat to BSA/AML integrity, showing how frontline and management personnel can defeat CTRs and suspicious activity report (SAR) controls when incentivized by bribery. Institutions should ensure that CTR conductor identification can’t be circumvented by a single employee, and that transaction monitoring independently detects structuring and third-party cash-funded official check activity. Strong controls over access to confidential customer information, dual-control and segregation of duties for high-risk transactions, and monitoring for unusual employee behavior or unexplained benefits are critical. The case also reinforces the value of connecting prior suspicious-activity account closures to ongoing monitoring so that flagged customers cannot simply resume activity through a complicit employee.

Controls to Evaluate

  1. Currency Transaction Report (CTR) Systems: Integrated systems are in place that automatically identify currency transactions exceeding $10,000, tracking transactions involving foreign currency exchanges, cash advances, and credit line transactions that involve currency. These systems capture required customer identification information, aggregate related transactions, and generate complete CTR forms. They also facilitate electronic filing with FinCEN within regulatory timeframes, maintain comprehensive documentation and records, and provide audit trails for all CTR activities — ensuring regulatory compliance and preventing Bank Secrecy Act violations.
  2. CTR Access Controls: The FI has integrated access control systems in place that manage CTR user permissions, including role-based access controls for supervisory and general users, automated user provisioning and deprovisioning, multi-factor authentication requirements, session management controls, privileged access monitoring, and comprehensive audit logging of all CTR system access activities to ensure appropriate user permissions and prevent unauthorized access.
  3. SAR Quality Assurance: Independent secondary review of all SARs by management or a designated reviewer is in place to ensure completeness, accuracy, and quality before filing, with regular testing of monitoring scenarios and alert thresholds to ensure effectiveness in detecting suspicious patterns. Management information reporting includes SAR filing metrics, false positive rates, and control effectiveness measures.
  4. Segregation of Duties: Roles and responsibilities across all departments are formally documented to ensure no single employee controls the initiation, approval, and reconciliation of any transaction; where staffing limitations prevent full segregation of duties, compensating controls are implemented through periodic reviews and audits conducted by the Board Audit Committee or an external audit firm.
  5. Fraud-to-SAR Escalation: Fraud investigation procedures are formally integrated with the FI's BSA/AML/CFT compliance program to ensure suspected fraud incidents are evaluated for SAR filing obligations within regulatory timeframes; escalation triggers, filing thresholds, and coordination protocols between the fraud function and BSA/AML/CFT compliance are documented, and SAR filing deadlines are tracked and monitored to prevent regulatory violations attributable to investigation delays.

Related Ncontracts Content in Your Platform

Ncomply Sample Policies

Nrisk Risk Assessments

Related: How to Create Dynamic BSA/AML/CFT Risk Assessments

OCC Enforcement Actions

OCC Orders National Bank to Strengthen BSA/AML and OFAC Controls Tied to Correspondent Banking and Virtual Currency Customers

The OCC issued a consent order against an institution for significant BSA/AML and OFAC deficiencies tied to its foreign correspondent banking and virtual currency customers. The bank had converted from a Texas state-chartered member bank to a national bank on June 12, 2026, and the OCC conditioned approval of that conversion on the bank entering an order incorporating corrective actions from a prior 2024 order issued by the Federal Reserve Bank of Dallas and the Texas Department of Banking. The order directs the bank to continue implementing plans to strengthen board oversight, its BSA/AML compliance program, customer due diligence (CDD), suspicious activity monitoring and reporting, and OFAC compliance. Required measures include a comprehensive risk assessment, enhanced independent testing, a qualified BSA compliance officer with full autonomy and adequate resources, remediation of deficient due diligence for existing customers, and enhanced training. The board must submit quarterly progress reports and review the effectiveness of each program at least annually.

Takeaways

This action illustrates that supervisory deficiencies follow an institution through charter conversion. Regulators will carry forward outstanding corrective obligations rather than allow for a fresh start. Banks serving higher-risk customer bases such as foreign correspondents and virtual currency businesses must ensure their BSA/AML risk assessment, transaction monitoring, and CDD programs are calibrated to that elevated inherent risk. A qualified BSA officer with genuine autonomy, decision-making authority, and sufficient staffing is a recurring examiner expectation, as is independent testing performed by parties outside the business and compliance lines. Institutions contemplating a charter change or acquisition should assume that unresolved AML findings will be a condition of approval and plan remediation accordingly. 

Controls to Evaluate

  1. Correspondent Banking Due Diligence: Continuous monitoring and testing of international correspondent banking relationships is in place to determine risk management effectiveness, including validation of due diligence completeness, assessment of ongoing monitoring quality, tracking of nested banking oversight, evaluation of foreign bank control assessment, and measurement of sanctions compliance to ensure adequate correspondent banking management and prevent severe reputational damage and restricted access to global payment systems. 
  2. SAR Quality Assurance: Independent secondary review of all SARs by management or a designated reviewer is in place to ensure completeness, accuracy, and quality before filing, with regular testing of monitoring scenarios and alert thresholds to ensure effectiveness in detecting suspicious patterns. Management information reporting includes SAR filing metrics, false positive rates, and control effectiveness measures. 
  3. Customer Risk Rating System: An automated system is utilized that analyzes customer/member data against predefined risk criteria and parameters to assist in identifying and flagging customers that warrant higher risk ratings based on established money laundering and terrorist financing risk factors. 
  4. CDD Program Automation: BSA/AML/CFT systems are in place that support CDD requirements including automated customer risk rating algorithms, beneficial ownership identification tools, high-risk customer flagging capabilities, enhanced due diligence workflow management, ongoing monitoring automation, and transaction monitoring systems that detect unusual patterns, structured transactions, rapid movement of funds, transactions inconsistent with customer profiles, geographic risk indicators, and suspicious relationship activities to ensure effective customer risk assessment and ongoing oversight. 
  5. Digital Asset and Cross-Border Monitoring: Transaction monitoring systems are configured to identify, monitor, and detect digital asset transactions and cross-border activities including blockchain analytics capabilities, virtual currency transaction investigation tools, cross-border transaction tracking, sanctions screening, money laundering detection, terrorist financing identification, correspondent banking monitoring, and comprehensive audit trails to ensure effective digital asset and cross-border oversight and prevent regulatory enforcement actions and criminal liability.

Related Ncontracts Content in Your Platform

Ncomply Sample Policies

Nrisk Risk Assessments

FRB Enforcement Actions

FRB Bars Former Chief Lending Officer for Approving Loans on Altered Appraisals

The FRB issued an Order of Prohibition against the former chief lending officer of an institution after the individual caused the bank to approve at least four loans supported by appraisals that had been altered to reflect higher property values than the appraisers originally transmitted. On at least 25 other occasions before the bank's December 2020 merger, the individual failed to ensure that loans and renewals were supported by appraisals from appraisers currently licensed in the relevant state and ignored inconsistencies that should have called the appraisals' accuracy into question. 

After the merger, the surviving bank re-appraised the collateral at significantly lower values, foreclosed on certain loans, and incurred losses when the collateral sold for substantially less than the original appraised amounts. The Board concluded the individual's conduct involved violations of law, breaches of fiduciary duty, or unsafe or unsound practices, together with personal dishonesty or willful disregard for the bank's safety and soundness. As a result, the Board permanently barred the individual from the banking industry.

Takeaways

This prohibition order reinforces that appraisal integrity is a core safety and soundness control, and that a single senior lender can expose an institution to significant credit losses when that control fails. FIs should ensure appraiser licensing is independently verified, that appraisals are received directly through controlled channels resistant to alteration, and that the lending function cannot unilaterally accept collateral valuations without independent review. Recurring inconsistencies or irregularities in appraisals should trigger escalation and re-ordering rather than being ignored. 

The case also demonstrates that supervisory consequences for individual misconduct can arrive years later and survive a merger, so acquiring institutions should scrutinize the loan portfolios and underwriting practices of targets during due diligence.

Controls to Evaluate

  1. Appraisal Management Program: An appraisal management program is in place, including policy and procedures for:
    1. Ordering appraisals or valuations, including staff and selection criteria used to select the appraiser and appraisal content, and criteria for use of evaluations and AVMs 
    2. Working with or through Appraisal Management Companies (AMCs) 
    3. Independence rules and disclosure requirements 
    4. Providing appraisals to customers 
    5. Appraisal review ordering, completion, and review, to ensure appraisals comply with appraisal regulations and supervisory guidance and that appraisals/evaluations contain sufficient information to support the credit decision 
    6. Validation of appraisals and evaluations to support subsequent transactions, as appropriate 
    7. Appraisal complaints or disputes received 
    8. Reconsideration of value (ROV) processes for non-HUD loans, consistent with Interagency Guidance 
    9. Submitting referrals to state agencies as directed by the appraisal committee for appraisers with material non-compliance with USPAP or ethical, discriminatory, or bias concerns 
    10. Monitoring ongoing performance of appraisers and evaluators, such as maintaining the approved appraiser list, verifying certifications, and monitoring for enforcement actions against approved appraisers
  2. Appraisal Review Process: Appraisal reviews are completed for appraisals and valuations (including automated valuation models/AVMs) performed for the FI or another institution (including participations), as required by policy. Appraisal reviews are conducted by independent staff or consultants with the requisite education, expertise, and competence to perform the review commensurate with the complexity of the transaction. Reviewers assess whether the appraisal or evaluation contains sufficient information and analysis to support the FI's decision to engage in the transaction and to ensure compliance with USPAP and also review for any discriminatory verbiage or indications of bias. Reviewers may refer any deficiencies for the Reconsideration of Value (ROV) process, as applicable, and ROV processes are followed for non-HUD loans in accordance with Interagency Guidance.

Related Ncontracts Content in Your Platform

Ncomply Sample Policies

Nrisk Risk Assessments

FDIC Enforcement Actions

FDIC Orders Bank to Correct HMDA, TILA, RESPA, ECOA, and Flood Insurance Violations

The FDIC issued a consent order and order to pay against a bank after determining, in its February 18, 2025, Consumer Compliance Report of Examination, that the bank violated the Home Mortgage Disclosure Act (HMDA), the Truth in Lending Act (TILA), the Real Estate Settlement Procedures Act (RESPA), the Equal Credit Opportunity Act (ECOA), and the Flood Disaster Protection Act (FDPA). The order requires the bank to fully correct all cited violations and implement processes to prevent recurrence, including root cause analysis, remediation of consumer harm, and validation testing. The bank must also conduct a file search to identify additional harmed parties affected by the TILA and RESPA violations since its November 28, 2022, examination and provide restitution where consumer harm occurred. Within 90 days, the board must develop and maintain a sound compliance management system integrated into the bank's overall risk management strategy. The bank was assessed a $44,800 civil money penalty for the HMDA violations.

Takeaways

This action shows how deficiencies spanning multiple consumer protection laws often trace back to a weak compliance management system rather than isolated errors. Institutions should ensure their CMS is proportionate to the complexity of their mortgage operations and is genuinely integrated with enterprise risk management, not maintained as a standalone function. HMDA data integrity remains an examiner's focus and can independently support civil money penalties. When violations are identified, examiners expect a disciplined remediation methodology: root cause analysis, look-back file reviews to find all affected consumers, restitution, and testing to confirm corrective actions work.

Controls to Evaluate

  1. Compliance Management System (CMS): The CMS is in place to ensure compliance with all applicable state and federal laws and regulations. The program is well-documented and reviewed periodically, and includes active tracking of emerging, new, and changed regulations. It consists of requirements for appropriate staffing within the Compliance Department and training for all employees, agents, management, and the Board, and assists in avoiding unfair, deceptive, or abusive practices. The CMS includes:
    1. Policies and procedures
    2. Monitoring, testing, and audit procedures
    3. Board and management oversight and reporting
    4. Change management, including for new products and services
    5. Identification and management of risks
    6. A consumer complaint management program
    7. Governance processes with defined escalation thresholds and accountability mechanisms requiring Senior Management action and Board challenge when material compliance issues, repeat findings, or delayed remediation are identified, including documented decisions, risk acceptance (if applicable), and follow-up reporting.

Related Ncontracts Content in Your Platform

Ncomply Sample Policies

Nrisk Risk Assessments

Nverify Audits

FDIC Penalizes Two Banks for Flood Insurance Force-Placement Failures

The FDIC issued FDPA enforcement actions against two institutions. The first institution failed to purchase flood insurance on a borrower's behalf, upon the borrower's failure to obtain it, in fifty-four separate instances. The second institution failed to timely force place flood insurance after determining insufficient coverage on designated loans and failed to timely notify borrowers that flood insurance must be obtained, or the bank would force place it.

Takeaways

Force-placement failures remain among the most frequently cited and penalized flood insurance violations. When a designated loan lacks adequate coverage, the institution must notify the borrower and, if the borrower does not obtain coverage within 45 days, force place insurance on the borrower's behalf; a breakdown in that workflow across multiple loans establishes the pattern or practice that supports civil money penalties. Institutions should maintain automated ticklers and monitoring systems that track coverage adequacy throughout the loan term and trigger timely notice and force-placement. Regular internal audits of the flood compliance process are essential to catch systemic gaps before they accumulate. Given how quickly individual loan-level lapses aggregate into a pattern or practice, ongoing portfolio monitoring and periodic independent testing of the flood compliance workflow are the most effective protections against penalties.

Controls to Evaluate

  1. Force-Placed Policy Tracking and Reconciliation: Force-placed flood insurance policies and their premium due dates are recorded in a loan servicing system, with premium payment reminders generated in advance of each due date and assigned to designated loan operations staff for action. A monthly reconciliation of force-placed flood insurance policies confirms that all premiums due during the period have been paid and documents payment confirmation, reviewed and signed by a supervisor. Upon receipt of a force-placed policy cancellation or lapse notice, an automated alert is generated in the servicing system, triggering an escalation workflow that requires immediate supervisor notification, assessment of the coverage gap, and initiation of replacement coverage within a defined timeframe.
  2. Cancellation Tracking and Refund Reconciliation: Upon receipt of a borrower's declarations page or equivalent coverage confirmation, an insurance or servicing system opens a 30-day cancellation tracking record, with staff required to submit the cancellation request to the force-placed insurer within the system prior to the deadline and system alerts generated at 15 and 5 days out. A standardized checklist confirms that the coverage confirmation document meets regulatory standards, including the existing policy number, insurer identity, and contact information for the insurer or agent, with deficient documentation triggering a borrower outreach record. All refunds of overlapping premiums and related fees are tracked in a dedicated log, including the date coverage confirmation was received, the force-placement cancellation date, the refund amount, and the refund date, and the log is reconciled and reviewed by a supervisor monthly.
  3. Second-Line Quality Control: A second-line quality control and compliance testing program is established to independently validate that first-line flood compliance controls, including LOS configurations, pre-closing checklists, servicing workflows, and tracking logs, are operating as intended. The program operates on a risk-based sampling methodology, with review frequency and sample size calibrated to transaction volume, risk level, and prior findings. QC reviews are performed by compliance or a designated QC function independent of the line of business being reviewed, with each review covering a specific flood compliance subject area so that, together, the reviews provide comprehensive coverage of the flood compliance program on a periodic basis.

Related Ncontracts Content in Your Platform

Ncomply Sample Policies

Nrisk Risk Assessments

Nverify Audits

NCUA Enforcement Actions

The NCUA issued no institutional enforcement actions in July 2026. 

Additional Enforcement Actions

FDIC

FDIC-26-0028b - For unsafe or unsound banking practices relating to capital management, concentration, allowance for credit loss, and interest rate risk. 

Struggling to make the case for compliance software? This month's actions all point to compliance programs that existed on paper but didn't catch the problem in practice — from monitoring and testing gaps to breakdowns in board reporting. How to Get Buy-In for Compliance Software can help you build the case to your CFO, CRO, CEO, and IT team.