Initial source-linked research article with operating analysis and illustrative examples.
The primary record
On February 1, 2024, Sutton Bank entered a consent order with the FDIC and Ohio Division of Financial Institutions, FDIC-23-0110b / BA2023-01. The order states that the bank consented without admitting or denying the alleged unsafe or unsound practices and legal violations. It addressed Bank Secrecy Act and anti-money-laundering/countering-terrorist-financing controls, including work performed through third parties.
This is a historical case analysis of the public order. It does not establish the bank’s present remediation status, assert customer misconduct or identify any particular program manager as responsible for a deficiency. Those conclusions would require separate evidence.
The remediation architecture
The order required a revised written AML/CFT program within 180 days. Other provisions addressed board supervision, a designated BSA officer with sufficient authority and resources, an independent review of staffing and systems, third-party risk management, suspicious-activity monitoring and training. A directors’ committee was required to monitor compliance with the order, without reducing the full board’s responsibility.
For third parties, the order required an inventory showing responsibilities such as customer identification, transaction monitoring, independent testing and suspicious-activity reporting. It also called for ongoing monitoring, corrective action and quarterly reporting concerning third-party performance. Those requirements make responsibility traceable across organizational boundaries.
From a contract to a working control
Analysis: a contract can say that a program manager performs customer identification while leaving uncertainty about rejected records, unavailable documents or later changes. The bank needs evidence that required work happened for the actual customer population. A service-level report describing processing speed does not answer whether the underlying identification process was complete.
The same problem appears in monitoring. Receiving a list of alerts is different from knowing that all relevant transactions reached the monitoring system. A useful control chain reconciles the input population, identifies gaps, tracks investigation stages and tests the quality of dispositions. Responsibility should remain clear when a case moves between the bank and a partner.
Illustrative evidence chain
Consider a fictional prepaid program in which a partner processes 100,000 accounts, but the bank’s oversight file contains 99,600. The missing 400 are not automatically suspicious customers. They are an unexplained population difference that must be resolved before the bank can rely on a completion rate.
| Layer | Proposed check | Evidence to retain |
|---|---|---|
| Account population | Reconcile partner and bank counts | Identifiers and explanations for differences |
| Identification | Test required fields and verification outcomes | Original records and exception decisions |
| Monitoring | Reconcile transactions into scenarios | Input counts, exclusions and validation |
| Investigation | Sample alert closure and escalation | Analyst rationale and quality review |
| Governance | Track defects through closure | Owners, dates and independent confirmation |
Why staffing and authority interact
The order’s staffing provisions are more than a headcount exercise. Analysis: workload depends on customer and transaction volume, product complexity, alert quality and the amount of rework caused by incomplete data. Hiring more analysts may reduce a queue temporarily while leaving an upstream defect untouched.
A BSA officer also needs authority to obtain records and escalate unresolved weaknesses. A staffing model that assumes every partner file arrives clean and every alert can be closed quickly should be challenged. Board reporting becomes more useful when it connects volume, aging, quality defects and corrective actions rather than presenting a single “percent complete” figure.
Limits and follow-up questions
Not every control difference implies a BSA violation, and a consent order does not by itself demonstrate that prohibited transactions occurred. The public record supports the specified remedial duties and the historical allegations as characterized in the document. It does not reveal every supervisory examination finding or the subsequent effectiveness of remediation.
For current diligence, verify any later official modification or termination and ask for independent testing of the revised process. Evidence that would strengthen confidence includes reconciled populations, documented oversight, tested alert quality and durable correction of recurring defects. A future revision should separate new verified status information from these enduring operating lessons.