EagleBank’s $9.7 Million Lesson: When Executives Override Compliance, the Bank Pays the Price

What Happened
According to the non-prosecution agreement, EagleBank admits that between 2010 and 2021 it willfully failed to establish an anti-money laundering and countering the financing of terrorism program, in violation of the Bank Secrecy Act. At the center of the case: two customers, a father and son, who operated a check kiting scheme through EagleBank accounts for more than ten years. Check kiting works by writing checks against insufficient funds and depositing them at a different bank, exploiting the lag in check processing to create the appearance of available funds before either bank catches on. Run in a circular pattern across institutions, it can be sustained for years if nobody intervenes.
Here, somebody did try to intervene, repeatedly. The agreement states that EagleBank’s compliance personnel made multiple efforts to close the accounts and shut the scheme down, and that senior bank executives overrode them each time. The father at the center of the scheme was a friend and business partner of EagleBank’s former chairman and CEO, who resigned in 2019. The scheme ultimately caused a loss of nearly $6.3 million to another financial institution.
The Penalty

Under the agreement, EagleBank will pay a fine of $9,057,821.62 plus forfeiture of $736,515, representing the overdraft fees the bank collected on the very accounts used in the scheme. EagleBank also committed to further strengthening its AML/CFT program, cooperating with the Department’s investigation, and reporting any future violations of federal criminal law.
DOJ officials were blunt about the theory of the case. Assistant Attorney General A. Tysen Duva said EagleBank “knowingly allowed favored clients to operate a check kiting scheme, even as compliance personnel repeatedly tried to stop it,” and framed the case around a core compliance principle: financial institutions are supposed to be “gatekeepers, not gateways” for criminal activity.
Why This Case Is Different
Most AML enforcement actions describe a program that was deficient, understaffed, poorly calibrated, or simply never built out. This case describes something more troubling: a program that identified the risk correctly and was then deliberately dismantled by leadership to protect a personal relationship. That distinction matters enormously from an enforcement perspective. A negligent or under-resourced compliance function is a remediation problem. A compliance function whose findings are actively overridden by the C-suite is a governance and culture problem, and it is the kind of fact pattern that turns a civil regulatory matter into a criminal referral risk for the individuals involved, even when the institution itself resolves the matter through a non-prosecution agreement.
It is also worth noting who bore the loss. The scheme did not directly defraud EagleBank; it inflicted almost $6.3 million in losses on another financial institution, while EagleBank collected overdraft fees on the same accounts the whole time. The forfeiture of those fees signals that regulators will claw back even indirect financial benefits a bank realized from facilitating misconduct, not just direct proceeds of fraud.
Compliance Takeaways
A few points stand out for compliance officers and boards reviewing this case:

When compliance flags a risk and it gets overridden by executive leadership, that override needs to be escalated, documented, and revisited independently of the original decision-maker. A single override by a conflicted executive should never be the last word on an account relationship, particularly one tied to insider or personal relationships.
Personal and business relationships between senior executives and customers are a recognized red flag category, and they demand heightened, not diminished, scrutiny. The closer a customer relationship is to leadership, the more independent the review of that relationship needs to be.
Boards need a reporting channel for compliance concerns that bypasses the very executives whose decisions are being questioned. If the CEO or chairman is the one overriding compliance, compliance needs a path to the board or its audit committee that does not run through that same executive.
Financial benefit from facilitating misconduct, even indirect benefit like overdraft fees, will be treated as ill-gotten gains subject to forfeiture. Institutions should not assume that only direct proceeds of fraud are at risk in a resolution.
A decade-long failure to escalate is itself the violation. This was not one missed transaction. It was a sustained, multi-year pattern that DOJ characterized as willful, and that characterization is what elevated this from a supervisory criticism to a $9.7 million resolution.











