SEC’s $7.5 Million Merrill Lynch Settlement: When Your Threshold Becomes Your Blind Spot

The SEC’s latest enforcement action against Merrill Lynch is a reminder that a transaction monitoring system is only as good as the calibration behind it. On July 1, 2026, Merrill agreed to pay a $7.5 million civil penalty, accept a censure, and consent to a cease-and-desist order to settle SEC charges that it failed to file numerous Suspicious Activity Reports (SARs) between April 2020 and September 2024 — a failure the agency traced not to bad faith, but to a numerical scoring threshold that Merrill knew was letting suspicious activity slip through.
What Happened
Merrill relies on Bank of America’s enterprise-wide AML program to meet its own SAR filing obligations as a broker-dealer. Bank of America’s transaction monitoring system groups potentially suspicious transactions into “event groups” and assigns each a numerical risk score. Only event groups scoring 20 or higher triggered an automatic investigation for possible SAR filing.
According to the SEC’s order, Merrill’s own internal analysis — dating back to at least April 2020 — showed that event groups scoring below 20 still had a high likelihood of warranting a SAR if they had actually been reviewed. Despite that internal knowledge, Merrill kept the same threshold in place until December 2023. The result: hundreds of millions of dollars in transactions, including transfers with no apparent business purpose, large round-dollar transactions, activity tied to high-risk geographic locations, structured cash transactions, and activity involving customers who had previously been flagged in prior SARs, were never investigated and never reported to FinCEN.
Why This Matters
The SEC was careful to note what it did not allege: it did not claim Merrill knowingly facilitated money laundering or any underlying crime. This is a case about the integrity of the surveillance system itself, and it should reframe how compliance officers think about SAR risk. Regulators do not need to prove intent to reach a $7.5 million penalty. They only need to show that the firm knew its detection threshold was miscalibrated and chose not to fix it for years. That is the crux of the SEC’s theory here, and it is a fact pattern that should worry any compliance officer sitting on a similar internal analysis they haven’t yet acted on.

Once a firm has data showing its monitoring system is under-detecting, the clock starts running. Delay converts a tuning problem into a liability problem.
The Corrective Action Playbook
To its credit, Merrill did eventually respond. In December 2023, Bank of America and Merrill lowered the investigation threshold, conducted a retrospective look-back review of previously uninvestigated event groups, and filed the delayed SARs that resulted. Bank of America also retained an independent compliance consultant to review its firm-wide AML program. The SEC credited this cooperation and remediation in the settlement, which is consistent with how the agency has approached other AML cases: self-identification and thorough remediation reduce, but do not eliminate, the penalty.
Not a First Offense
This is Merrill’s third SAR-related enforcement matter, following settled administrative proceedings in 2017 and 2023. Separately, the OCC hit Bank of America with a cease-and-desist order in December 2024 over deficiencies in its Bank Secrecy Act and sanctions compliance programs. Regulators are clearly tracking a pattern here, not an isolated incident, and repeat violations tend to draw closer scrutiny and less patience in future cases.
Compliance Takeaways

A few lessons stand out for compliance and AML officers reviewing this case:
Monitoring thresholds are not “set and forget.” If your data analytics function ever identifies that a scoring threshold, alert rule, or filtering criterion is missing a material volume of true positives, that finding needs to be escalated and acted on promptly, not shelved as a future enhancement project.
Reliance on a parent company’s enterprise-wide compliance program does not relieve a regulated subsidiary of its own independent filing obligations. Broker-dealers that lean on shared infrastructure still own their own SAR responsibilities and their own exposure when that infrastructure underperforms.
Internal knowledge is discoverable and will be used against you. The SEC’s order leaned heavily on Merrill’s own internal analyses to establish that the firm knew about the gap well before it acted. Documentation that identifies a control weakness creates an obligation to remediate — and a record if you don’t.
Look-back reviews and independent consultants matter, but they are damage control, not prevention. The real value in this case for other firms is upstream: validate your monitoring thresholds against real outcomes on a recurring basis, and treat any evidence of under-detection as an urgent, not routine, priority.











