SEC Fined Merrill Lynch $7.5 Million Over Oversight
The firm failed to review suspicious transaction groups that fell below its internal risk score threshold.
Updated on Sept. 30, 2026 in Financial Crime

Live Poll
Do you trust financial institutions to oversee automated monitoring systems that detect suspicious activity?
The Securities and Exchange Commission has fined Merrill Lynch $7.5 million for failing to investigate suspicious transaction groups. The firm had used an automated risk-scoring system to manage monitoring workloads.
Why it matters
The SEC action highlights regulatory requirements for financial firms to maintain rigorous oversight of automated compliance systems. Merrill Lynch accepted a censure and a cease-and-desist order to resolve the agency's findings.
The SEC imposed a $7.5 million penalty, a censure, and a cease-and-desist order against the firm. Merrill Lynch reached this resolution while neither admitting nor denying the findings presented by the commission.
The players
Securities and Exchange Commission
This is the federal agency responsible for protecting investors and maintaining fair, orderly, and efficient markets.
Merrill Lynch
This is a major American investing and wealth management division under Bank of America.
The details
Merrill Lynch relied on software that aggregated potential suspicious events into groups and assigned each a numerical risk score to determine which required human review. Testing revealed that the firm failed to investigate numerous transaction groups that scored below its set threshold of 20 during the multi-year period.
Timeline
April 2020: Period when the failure to investigate transaction groups began.
September 2024: Period when the failure to investigate transaction groups ended.
September 29, 2026: The Securities and Exchange Commission announced the fine.
Legal Context
Financial institutions are increasingly under scrutiny for the reliance on automated systems to satisfy strict regulatory reporting mandates. This case follows a pattern set by the Bank Secrecy Act's Suspicious Activity Report filing requirements by penalizing firms that bypass necessary human oversight in financial monitoring.
This enforcement action signals to the public that federal regulators are actively auditing the automated compliance protocols used by major financial institutions. Residents and account holders should remain aware that these systems exist to prevent illicit activity from flowing through the U.S. financial system.
The takeaway
Financial firms must ensure that automated risk-assessment tools do not create blind spots in their compliance procedures. Investors and clients should verify that their financial institutions maintain active human review processes for suspicious activity.
Further reading
For more information on regulatory oversight, visit Financial Crime.
Source note: This article includes information reported by International Business Times UK.
Live Poll
Do you trust financial institutions to oversee automated monitoring systems that detect suspicious activity?










