Back to Insights
  • Enforcement
  • Financial Crime
  • Governance & Accountability

Below the line: how a risk score of 20 cost Merrill Lynch $7.5 million

For more than four years, Merrill Lynch let a transaction-monitoring cutoff decide which suspicious activity got investigated. Its own testing showed the cutoff was wrong — and the reports that should have been filed never were.

Abstract blue illustration of a luminous threshold separating clustered signal nodes from ordered streams of signals

Enforcement dossier · Financial Crimes · Transaction Monitoring

SEC Administrative Proceeding 3-22652 • Exchange Act Rel. No. 105790 • Settled 29 June 2026

Case record

Case at a glance

Merrill agreed to a $7.5 million civil penalty, a censure, and a cease-and-desist order for conduct running from April 2020 through September 2024.

Penalty
$7.5M
Conduct period
Apr 2020–Sep 2024
Provisions
§17(a) & Rule 17a-8
Outcome
Cease & desist + censure

Source: SEC press release and settled order, Administrative Proceeding File No. 3-22652.

The crux of the case — the promotion threshold

Event groups scoring 20 or higher were promoted to a “Case” and investigated. Everything below the line was left unreviewed — including groups that internal testing flagged as likely to produce a filing.

  • Investigated (score ≥ 20)
  • Never investigated (score < 20)
  • Below threshold, high SAR yield — a filing was warranted

Source: SEC press release and settled order; diagram adapted from the Finished Draft.

01Overview

Overview

On 29 June 2026, the Securities and Exchange Commission settled charges against Merrill Lynch, Pierce, Fenner & Smith Incorporated, the registered broker-dealer subsidiary of Bank of America, for failing to file numerous Suspicious Activity Reports (SARs) with the Treasury Department’s Financial Crimes Enforcement Network. The failures ran from 8 April 2020 through 10 September 2024. Merrill agreed to a $7.5 million civil penalty, a censure, and a cease-and-desist order, and settled without admitting or denying the Commission’s findings.

The mechanics sit at the heart of the case. Merrill relied on Bank of America’s enterprise-wide anti-money-laundering program to help meet its own, non-delegable SAR obligations. That program ran a monitoring system called “Event Processor,” which bundled alerts of potentially suspicious activity into “event groups” and assigned each group a numeric risk score. Only groups scoring 20 points or more were promoted into investigable “Cases.” Anything below 20 was never reviewed for a possible filing, and under a separate aging rule those events “retired” from the system after 13 months.

What turns a design choice into an enforcement action is what Merrill already knew. Its own testing — a metric the firm called the “SAR Yield” — showed as early as April 2020 that certain below-threshold groups, if investigated, would generate SARs, in some cases at rates higher than groups sitting above the line. The threshold was not lowered until December 2023. This is Merrill’s third SEC settlement over SAR filing (after orders in 2017 and 2023), and it lands roughly 18 months after the Office of the Comptroller of the Currency issued its own BSA and sanctions consent order against Bank of America, N.A. in December 2024.

02The findings

Infringements

The Commission found a single, discrete violation: Merrill willfully violated Section 17(a) of the Securities Exchange Act of 1934 and Rule 17a-8 thereunder. Those provisions require registered broker-dealers to comply with FinCEN’s reporting rules under the Bank Secrecy Act — including the obligation at 31 C.F.R. § 1023.320(a)(2) to file a SAR on any transaction of at least $5,000 that the firm knows, suspects, or has reason to suspect involves illicit funds, is designed to evade the BSA, has no apparent lawful purpose, or is used to facilitate criminal activity.

The operative failure was one of omission at scale. Because below-threshold event groups were never investigated, Merrill did not file “numerous” SARs that the underlying activity warranted. The Commission described the unreported conduct in concrete terms: it touched hundreds of millions of dollars and carried the textbook markers of money laundering — transfers with no apparent economic or lawful purpose, large round-dollar movements, funds moving to and from high-risk jurisdictions, cash transactions that appeared structured to dodge reporting, activity linked to criminal conduct, and accounts belonging to subjects who had already been flagged in earlier SARs.

The word “willfully” carries a specific, and relatively low, meaning here: under the governing standard, it means only that Merrill knew what it was doing, not that it intended to break the law. Paired with the firm’s own SAR Yield analyses, that framing let the Commission conclude Merrill had reason to suspect the below-threshold activity was reportable. The remedy — cease-and-desist, censure, and a $7.5 million penalty — reflects that this was a controls-and-governance failure rather than a finding of intent to conceal.

03Root cause

Analysis

The first root cause is a hard numeric cutoff decoupled from measured risk. A promotion threshold of 20 is, functionally, a triage lever — it decides how much work the investigations team receives. When that lever is set without continuously testing whether it tracks actual suspiciousness, it stops being a risk control and becomes a capacity control. Everything below the line was invisible to investigators regardless of how suspicious it looked, and a score could only climb if new related events happened to attach to the group before it aged out.

The control that should have caught the problem did catch it. The failure was that nothing happened for roughly three and a half years.

That points to the second, and more damning, root cause: the organisation had the evidence and did not act on it. Below-threshold testing — the SAR Yield metric — is precisely the mechanism a mature program uses to validate its thresholds. Here it worked as designed, repeatedly showing that low-scored groups would have produced filings. The breakdown was in governance and escalation: a signal that first appeared in April 2020 did not translate into a threshold change until December 2023. The lag, not the metric, is where the program failed.

A third contributor was the 13-month “retirement” rule. Events that never reached a Case aged out of the system, with newer events re-forming into fresh groups. In practice, that meant a pattern of suspicious behaviour could churn more or less indefinitely without ever crossing the threshold, while the paper trail of the older activity quietly disappeared. Aging logic that clears untriaged items is a classic silent-failure mode: the queue looks clean because the backlog is being deleted, not resolved.

The fourth cause is structural: Merrill outsourced the plumbing but kept the liability. It leaned on Bank of America’s enterprise program to run monitoring across the group, yet the Commission was explicit that Merrill retained every bit of its own SAR-filing responsibility. Shared infrastructure is efficient, but it diffuses ownership — the registered entity on the hook for the filing is not always the team tuning the model. That gap between where the duty sits and where the decisions get made is a recurring theme in monitoring cases.

Tellingly, the fix was available the whole time. Merrill’s remediation — lowering the threshold in December 2023, running a retrospective look-back that produced numerous belated SARs, and commissioning an outside consultant to assess the enterprise program — is essentially the set of actions its own testing had been pointing to since 2020. The cost of waiting was not just the penalty; it was years of reportable activity that reached FinCEN late or not at all.

04What firms miss

Practical Insights

The Merrill order is a specific instance of a pattern regulators call alert capping — setting or tuning monitoring output around how much a team can handle rather than around risk. Across the RegLabs enforcement library, alert capping is rare as a distinctly labelled scheme, appearing in only a handful of tagged cases, but it is disproportionately expensive when it surfaces. The clearest precedent is U.S. Bank, which paid a $75 million OCC penalty in 2018 for capping suspicious-activity alerts to match staffing, with below-threshold testing again showing a high rate of missed filings; two years later, FinCEN separately penalised the bank’s former operational-risk officer $450,000 and imposed a multi-year ban. The fact pattern rhymes almost exactly with Merrill.

  1. Testing your own thresholds creates a duty to respond to the results. Below-threshold sampling is good practice, but once the metric exists it is discoverable, and a high yield you did not act on becomes evidence that you had “reason to suspect.” Firms overlook that the analysis is a liability if it sits in a deck rather than driving a change.

  2. The back end of monitoring fails as often as the front. Getting the alert is only half the job; disposition is the other half. In one enforcement matter, Commerzbank closed AML alerts without meaningful investigation and filed SARs years late. Alert-handling deficiencies co-occur across a large share of SAR cases — a well-tuned model does not save a firm that closes what it generates.

  3. Aging and auto-close rules can manufacture a clean queue. Any logic that retires, purges, or re-buckets untriaged items deserves the same scrutiny as the scoring model. If suspicious events expire before review, the program can look healthy while reportable activity slips through — exactly the effect of Merrill’s 13-month rule.

  4. Reliance on a group or affiliate program does not transfer the obligation. Registered entities are held to their own filing duties even when a parent runs the shared platform. Third-party, vendor, and governance failings cluster tightly around SAR cases; “the enterprise system did it” has never been a defence.

The connective tissue across these pitfalls is timing. Regulators rarely fault firms for having a threshold; they fault them for keeping a threshold they had already measured to be wrong. The distance between “we detected the gap” and “we closed it” is where penalties are made — and in Merrill’s case that distance was measured in years.

05The wider record

Thematic Review

Seen against the full enforcement record in RegLabs, SAR reporting is not a niche technicality — it is one of the most-litigated compliance obligations there is. Actions tagged to suspicious-activity reporting run to roughly 1,940 cases carrying close to $24 billion in penalties, and they travel in a tight cluster with anti-money-laundering programs, financial-crimes compliance, and transaction-monitoring surveillance. The theme is global and cross-regulator: FINRA leads on sheer case volume, while the Department of Justice, FinCEN, the OCC and the New York Department of Financial Services carry the heaviest dollar figures.

Chart A — Global, all regulators

Who brings suspicious-activity-reporting cases

Number of enforcement actions tagged to SAR-reporting procedures, by regulator. The SEC — Merrill’s regulator here — sits mid-table on volume but among the larger regulators by total penalties.

FINRA349
SEBI (India)147
OCC125
DOJ101
SEC97
FIC (S. Africa)96
FDIC92
FCA (UK)64
FinCEN63

Source: RegLabs enforcement database · policy tag “Suspicious Activity Reporting Procedures.”

Narrow the lens to the SEC, and the picture is a steady broker-dealer docket punctuated by occasional blockbuster years. The Commission has brought 97 SAR-tagged actions totalling about $456 million, with dollar spikes in 2016 and 2025 driven by a few very large settlements, and a 2026 that was already busy before summer — the Merrill order among them. Broker-dealers dominate the SEC’s SAR caseload, mirroring the global firm-type data, in which broker-dealers account for the single largest slice of SAR enforcement.

Chart B — This regulator (SEC)

The SEC’s SAR docket over time

Case count (bars) against total penalties (line, US$ millions), 2015–2026. 2026 is a partial year; the penalty spikes in 2016 and 2025 reflect a small number of outsized settlements.

20152$12.9M
20162$201.5M
20177$20.1M
201812$21.3M
20193$3.0M
20203$11.8M
20213$5.4M
20221$7.0M
20238$14.8M
20249$6.3M
20257$68.9M
2026*3$27.5M

Source: RegLabs · SEC · SAR-reporting procedures · 2026 year-to-date.

For this company, recidivism is the story. Merrill and Bank of America appear repeatedly across the anti-money-laundering record, with several SAR-specific settlements among a broader run of AML-tagged actions. The current order is Merrill’s third SEC resolution over SAR filing, and it follows the OCC’s 2024 BSA and sanctions consent order against Bank of America, N.A. — a reminder that monitoring weaknesses at a large group tend to surface across multiple regulators rather than in a single, isolated case.

The wider record

Four markers in the SAR enforcement record

The record combines recurring Merrill resolutions with a large global penalty total, broker-dealer concentration, and costly alert-capping precedents.

3rd
SEC SAR-filing settlement for Merrill (after 2017 & 2023)
~$24B
Global penalties tied to SAR-reporting failures
691
SAR cases involving broker-dealers — the largest firm type
$75M
Combined penalties in the two “alert-capping” precedents

Source: RegLabs enforcement database and the precedents identified in the Finished Draft.

Globally, the theme is persistent rather than cyclical. Annual SAR-related penalties bounce around a durable baseline of roughly 60 to 110 cases a year, with a dramatic 2023 outlier driven by multi-billion-dollar crypto resolutions. The underlying scheme mix is dominated by money laundering and terrorism financing — but the small cluster of “alert-capping” matters, though rare, consistently marks the most systemic monitoring breakdowns, the category into which the Merrill facts squarely fall.

Chart C — Global, all regulators

A persistent theme, with one outlier year

Total penalties tied to SAR-reporting failures, by year, US$ billions. 2023 is inflated by a handful of very large resolutions; the baseline in other years stays consistently high. 2026 is year-to-date.

$3.24B2018
$0.54B2019
$0.61B2020
$0.53B2021
$0.78B2022
$8.91B2023
$0.71B2024
$1.00B2025
$0.21B2026*

Source: RegLabs · all regulators · SAR-reporting procedures · 2018–2026 (2026 YTD).

06 — Put the record to work

The riskiest number in a monitoring program is the one nobody revisits

Merrill’s cutoff of 20 was measurable, testable, and wrong for years before anyone moved it. RegLabs is built so your team can find that number before an examiner does — by grounding every review in the actual enforcement record rather than intuition.

Automate the review

Run automated checks on SAR filing, transaction monitoring, alert disposition, and threshold tuning — benchmarked against thousands of real actions across the SEC, OCC, FINRA, FinCEN and beyond.

Systematise risk assessment

Map your controls to analogous precedent, quantify where your program sits against peers, and turn ad-hoc judgement calls into a repeatable, defensible risk model.

Simulate the exam

Generate a mock regulator examination on this exact topic — scored against how the SEC and other regulators have actually probed alert capping and below-threshold testing — and see the questions before they’re asked.

Explore this case in RegLabs Studio

This article summarises a settled administrative proceeding in which the respondent neither admitted nor denied the SEC’s findings. It is provided for information only and is not legal or compliance advice. Aggregate figures are drawn from the RegLabs database and reflect its coverage as of publication.

Sources & primary documents

  1. SEC press release & order. “SEC Institutes Settled Order Against Merrill Lynch for Failing to File Suspicious Activity Reports,” Administrative Proceeding File No. 3-22652, Exchange Act Rel. No. 105790 (29 June 2026). Available via sec.gov.
  2. Precedent — alert capping. OCC Consent Order, In re U.S. Bank N.A. (2018, $75M); FinCEN Assessment, In re Michael LaFontaine (2020, $450,000 and a multi-year compliance-function ban).
  3. Aggregate enforcement data & charts. RegLabs enforcement database, filtered on the “Suspicious Activity Reporting Procedures,” “AML,” and “Surveillance and Monitoring Procedures” policy tags and the “Alert Capping” scheme tag. Figures include actions across all covered regulators; 2026 totals are year-to-date.
Free trades, checked against only the five buyers who paid for themRegulatory RouletteAI on the Regulatory Radar