Connect with us

NEWS

OCC Puts Community Federal Back on 2020 AML Homework

The OCC ordered Community Federal Savings Bank to rebuild its AML program, recycling BSA risk controls the 2020 strategic plan already required.

Published

on

The OCC on May 21, 2026, published a consent order that tells Community Federal Savings Bank to rebuild its anti-money-laundering program after payments growth outran its controls. The order was signed on April 24, 2026. The Woodhaven, Queens, thrift sponsors Wise’s U.S. dollar accounts and issues the prepaid card behind Crypto.com’s spend product.

The same growth problem sat inside a February 2020 strategic plan the OCC had already required, including written steps to limit Bank Secrecy Act risk on new business lines.

The 2020 Plan Already Named This Risk

In the February 20, 2020, formal agreement, docket AA-NE-2020-8, the OCC found unsafe or unsound practices in strategic planning and earnings and placed the bank in “troubled condition.” Within 90 days the board had to send a written plan covering at least three years. That plan had to set risk limits for new products and growth, and it had to include control BSA/AML risk where exposure is high.

action plans and time frames to control risks where exposure is high, particularly with regard compliance, strategic, and reputation risks, and BSA/AML risk

OCC Formal Agreement, Community Federal Savings Bank, February 20, 2020

The same article told the board to analyze and limit the risks of any new line of business or growth it took on. The 2026 consent order opens on that exact gap. Since 2020, the OCC found, the bank “has significantly grown its payment processing line, relative to its size,” producing heavy annual wire and ACH volume, including cross-border activity through foreign banks, without controls that matched the risk.

Five of the seven directors who signed the April 2026 order had also signed the 2020 agreement. The 2020 deal did not last until 2026. The OCC terminated it on January 20, 2022. The payments line kept growing after that date, and the April findings still clock the unmatched growth from 2020.

THE ENFORCEMENT FILE ON THIS CHARTER

  1. February 6, 2014: Enters a formal agreement on management and earnings that also requires a revised suspicious-activity reporting program.
  2. February 20, 2020: Replaces that deal with a new agreement, troubled-condition status, and a three-year strategic plan that includes BSA/AML risk; the 2014 agreement ends the same day.
  3. January 20, 2022: The OCC terminates the 2020 agreement.
  4. April 24, 2026: The bank consents to a cease-and-desist order, docket AA-ENF-2025-21, for BSA/AML program, suspicious-activity reporting, and USA PATRIOT Act information-sharing violations.
  5. May 21, 2026: News Release 2026-40 makes the consent order public.

The bank neither admits nor denies the 2026 findings. The cited rules are 12 CFR 21.21, 12 CFR 163.180(d), and 31 CFR 1010.520(b)(3).

Woodhaven’s One-Branch Bank Runs Global Payments

Community Federal is a federal savings association chartered in 2001. It reports a single domestic office at 8916 Jamaica Avenue in Woodhaven. Its partner list is the part of the story that does not fit a one-branch thrift.

The bank provides U.S. dollar account details for Wise and issues Crypto.com’s U.S. prepaid card. It also sponsors payments and card programs for a wider fintech roster. BaaS analyst Jason Mikula, writing when the order landed, named Airwallex, Nomad, Chipper Cash, TomoCredit, and Revolut among those programs.

THE BANK AT YEAR-END 2025

  • Assets: Roughly $866 million as of the December 31, 2025 FDIC filing.
  • Deposits: Roughly $753 million in the same filing.
  • Offices: One domestic office, in Woodhaven, Queens.
  • Charter: Opened in 2001 as an OCC-supervised federal savings association.

A one-branch lender booking global wires, ACH, and card spend for those partners is the mismatch the OCC wrote down. Domestic shops built for local deposits rarely staff the monitoring, language, and correspondent work that cross-border fintech volume requires, and the order says this one did not keep pace.

Why the Alert System Closed Files on Its Own?

The bank ran an automated suspicious-activity alerting system whose filters and thresholds, the OCC found, had not been tuned to the payment-processing book, the rise in higher-risk products, or the international exposure. An automated triage layer then closed alerts that should have gone to a human. The result, in the auto-closed a very high percentage of alerts finding, is the core of the SAR violation.

WHAT THE OCC SAID BROKE

  • Alert triage: Logic, data, and method gaps let the system close alerts that needed review, so a very high share of ingested alerts never reached an investigator.
  • Customer due diligence: The program was ineffective, and the bank did not understand some customers’ businesses or the purpose of payment-processing transactions, including foreign-bank risk and cross-border volume.
  • Correspondent status: In various cases the bank did not even determine whether it held correspondent accounts for foreign financial institutions, the trigger for enhanced due diligence under section 312 of the USA PATRIOT Act.
  • Independent testing: The internal auditor failed to identify BSA/AML program weaknesses and failed to scope and test high-risk areas.
  • Staffing: Weak BSA staffing sat beside the control and testing gaps, and together they produced a program the OCC said was not reasonably designed.

Those five points are the program failure under 12 CFR 21.21, not a single missed filing. The SAR rule and the 314(a) information-sharing rule sit on top of that program gap.

Customer Due Diligence Missed Foreign Banks

Payment-processing customers can look like a fintech on the surface and like a chain of foreign banks underneath. If the sponsor bank cannot say what the customer does, or whether the account is a correspondent account, it cannot set a monitoring rule that fits the flow. The OCC said Community Federal failed on both questions inside the same line of business.

Independent Testing Skipped High-Risk Work

The internal auditor, in the OCC’s telling, did not find the program holes and did not put the high-risk work in scope. Independent testing is one of the four BSA program pillars. When that pillar misses the book that is growing fastest, the other pillars do not get a second look either.

Zero Fine and No Freeze on New Partners

The order imposes no civil money penalty. It does not cap growth. It does not bar new fintech partners. It names no officer or director and bars no one from banking. A bank spokesperson said the order “does not impose restrictions on partner onboarding,” and that the bank continues to partner with new and existing fintech clients “in a safe and sound manner.”

That is a different remedy from the last widely watched OCC file on a fintech-sponsor bank. The January 24, 2024, Blue Ridge Bank consent order told that Virginia bank it shall not onboard new third-party fintech relationships, sign a new fintech contract, or add products through existing fintechs unless the board first gets a written OCC no-objection.

TWO SPONSOR-BANK ORDERS

Term Community Federal, April 2026 Blue Ridge Bank, January 2024
New fintech partners No onboarding freeze in the order Blocked without OCC written no-objection
Civil money penalty None Not used as the comparison here
BSA program rebuild End-to-end outside consultant plus an action plan Action plan plus a written third-party risk program
Suspicious-activity look-back Yes, including auto-closed alerts Yes, as part of the 2024 order

Blue Ridge later left banking-as-a-service. Chief executive Billy Beale said the bank “just threw BaaS out the door,” and that if it had kept three or four partnerships and run them well, the volume would not have outrun the shop. Community Federal is taking the other fork: rebuild the BSA program in place and keep the partner channel open.

The spokesperson said the bank takes the order seriously, began enhancing its compliance setup well before April, and has invested in systems and programs since mid-2024. Remediation, the bank said in May, was “well underway,” with the open items expected to be resolved “over the coming months.” The current BSA officer joined after the exam period behind the order and, the bank said, has been central to that work.

Does the Order Restrict Wise and Crypto.com?

No. The consent order never names Wise or Crypto.com, does not freeze partner onboarding, and does not tell those firms to move U.S. rails. A Wise spokesperson did not comment on the order. Crypto.com did not comment either. Customers can still see this bank on U.S. dollar account details and on the Crypto.com cardholder agreement, which names Community Federal as the prepaid-card issuer.

Wise’s own U.S. help pages already tell customers that a linked USD balance may show up as Community Federal Savings Bank or CFSB when they connect PayPal, a broker, or a bill. In November 2023, Wise ended its arrangement with Evolve Bank & Trust, which had issued USD account details from October 2020, and moved that service onto Community Federal.

The look-back and the retuned filters still sit on the payment-processing line those partners use. Large outbound transfers can land in manual review when a sponsor bank is rebuilding SAR rules, which is why a customer waiting on a big Wise send can feel a delay that the order never describes as a product change. That is an operational risk on the rails, not a clause that kicks Wise or Crypto.com off the bank.

The Look-Back That Can Reopen Old Wires

Within 15 days of April 24, 2026, the board had to appoint a compliance committee of at least three directors, a majority independent, and send the names to the assistant deputy comptroller. That clock ran to May 9, 2026. Within 90 days, by July 23, 2026, the bank had to file an action plan covering the rest of the order, with owners and dates, and wait for a written no-objection before carrying it out.

WHAT THE BANK MUST HIRE AND REBUILD

  • Program consultant: An outside firm must run an end-to-end review of the BSA/AML program against the bank’s size, complexity, and risk, and give the board and the OCC a written report on each pillar.
  • SAR look-back: A second consultant reviews historical monitoring, including alerts the automated system auto-closed, and can recommend new suspicious-activity reports or fixes to old filings.
  • Internal controls: A written BSA/AML risk assessment must weigh products, third-party relationships, customer types, volumes, and geographies, and a customer-due-diligence program has to be rebuilt from that assessment.
  • 314(a) screening: A separate program must screen transactions against FinCEN information-sharing requests under section 314(a) of the USA PATRIOT Act.
  • Testing and the BSA officer: Independent testing must be overhauled, and if the BSA officer job becomes vacant the OCC must pre-clear the next hire.

The look-back is the piece that reaches backward into the payment-processing book. Files the filters already closed can still produce a SAR. The OCC also reserved the right to bring further action on the same facts, including against institution-affiliated parties.

The findings in this Consent Order are based on examination of the Bank’s BSA/AML compliance program as a whole, and are based on concerns largely unrelated to customers involved in digital assets activities

OCC Consent Order, Community Federal Savings Bank, April 24, 2026

That sentence keeps Crypto.com’s card from becoming the face of the file, and it still leaves the prepaid-card issuer inside the same payment-processing line the look-back will sample. The 2020 plan asked this board to limit BSA/AML risk before it grew that line. The April order assigns two outside firms to inspect the growth that followed, including the alerts the software had already marked closed.

Disclaimer: This article is news reporting on a public OCC consent order and related bank filings. It is for information only and is not legal, banking, or investment advice, and it is not a recommendation to move funds, close a card, or change a money-transfer provider. Readers who need advice on an account, a prepaid card, or a BSA filing obligation should consult a qualified banking attorney or a licensed financial adviser who can review their own facts. Asset figures, partner names, and remediation status reflect the cited orders, filings, and statements as dated in 2026 and can change as the bank’s action plan and look-back proceed.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending