$7.5M Bank Fine
Testing found suspicious activity below Merrill’s threshold, showing how automated rules can miss cases without malfunctioning. AI-Generated Image/ChatGPT

A $7.5 million (£5.7 million) penalty against Merrill Lynch, Bank of America's wealth-management and brokerage business, has exposed a weakness in automated financial crime detection: software can successfully flag unusual activity while a human-set threshold still prevents some of it from reaching investigators.

The Securities and Exchange Commission found that Merrill's transaction-monitoring process grouped potentially suspicious events and assigned them risk scores. Only groups scoring 20 or higher were routinely investigated for possible Suspicious Activity Reports (SARs), even though internal testing found some below that cutoff would have resulted in reports if reviewed.

The case turns a regulatory penalty into a broader warning for financial institutions increasingly dependent on automated systems: the biggest blind spot may not be what software fails to detect, but what organisations decide is not important enough for a person to examine.

A Score of 20 Became the Gateway to Human Review

Merrill relied on Bank of America's transaction-monitoring system to help meet its obligations under the Bank Secrecy Act. The software aggregated potentially suspicious events into groups and assigned each a risk score. Merrill generally investigated groups scoring at least 20 to determine whether a SAR should be filed.

The system itself did not determine whether a customer had committed a crime, nor did it make the final decision on regulatory reporting. Instead, the score determined which activity entered the investigation process. That distinction is important. A number generated by software effectively controlled where limited human attention was directed.

Internal Testing Exposed the Blind Spot

The weakness was visible because Merrill and Bank of America tested samples of lower-scoring activity. Those analyses showed that some event groups below the 20-point threshold would have resulted in SAR filings had they received full investigations. The SEC found that Merrill nevertheless failed to investigate numerous such groups between April 2020 and September 2024.

That illustrates a particular risk with automated compliance: a system does not need to malfunction to produce a poor outcome. It can perform exactly as configured while the rules surrounding it exclude activity that warrants closer examination. Merrill later lowered the threshold for internal reviews and filed numerous additional SARs.

Suspicious Activity Reports Depend on Judgement

SARs are intended to alert US authorities to transactions that may indicate money laundering, fraud, tax evasion, or other potentially unlawful activity. Under the Bank Secrecy Act, financial institutions must assist authorities in detecting and preventing money laundering, including by reporting suspicious activity that could signal criminal conduct.

But a risk score is not the same as a conclusion that a transaction is illegal. Investigators still need to consider the circumstances surrounding the activity before determining whether regulatory reporting is warranted. That makes the design of an automated monitoring system a compliance decision as much as a technology decision.

Automation Does Not Transfer Accountability

Merrill accepted a censure, a cease-and-desist order, and the $7.5 million (£5.7 million) civil penalty without admitting or denying the SEC's findings. Bank of America said it maintains rigorous anti-money laundering practices and continually reviews its systems for detecting and reporting suspicious activity.

The wider lesson for banks is that automation can reduce the enormous workload involved in monitoring transactions, but it cannot transfer regulatory responsibility from the institution to the software. Thresholds, scoring models, sampling procedures, and escalation rules are ultimately designed or approved by people. If those settings systematically exclude potentially reportable activity, the fact that the underlying software operated as intended does not eliminate the compliance problem.

For financial institutions investing heavily in automated fraud and anti-money laundering tools, the Merrill case therefore exposes a deceptively simple risk: sometimes the most important alert is the one the system has been configured not to show an investigator.