The SEC fined Bank of America’s (BAC) Merrill Lynch unit $7.5 million on Monday for systematically under-filing suspicious activity reports over more than four years, exposing a compliance blind spot at one of Wall Street’s largest broker-dealers.

For BAC shareholders, the fine itself is immaterial against the bank’s quarterly earnings, but the case signals renewed SEC scrutiny of anti-money laundering (AML) infrastructure at major broker-dealers – a regulatory risk that could drive higher compliance costs industry-wide.

Key Takeaways

  • SEC levies $7.5 million civil fine on Merrill Lynch for SAR failures.
  • Violations spanned April 2020 to September 2024 – over four years.
  • A software risk-score threshold of 20 was the root cause identified.

Market Reaction & Context

The $7.5 million penalty is a rounding error for Bank of America, which reported net income of roughly $7 billion in the first quarter of 2026 alone. However, compliance-related fines at large broker-dealers have been escalating, and the case joins a pattern of regulators scrutinising AML software calibration across the financial sector – a concern that peers including Morgan Stanley, Wells Fargo, and Charles Schwab will likely monitor closely.1

Merrill neither admitted nor denied wrongdoing in accepting the civil penalty, a standard settlement posture that leaves no formal legal liability on the record but still draws investor attention to internal control gaps.

Detailed Analysis: The Risk-Score Problem

The violation centred on Merrill’s reliance on Bank of America’s proprietary transaction monitoring software to satisfy its obligations under the federal Bank Secrecy Act, which requires broker-dealers to file suspicious activity reports (SARs) with the U.S. Treasury Department’s Financial Crimes Enforcement Network (FinCEN).2

According to the SEC, the software grouped potentially suspicious client transactions into “event groups” and assigned each a numerical “risk score.” Merrill’s compliance teams were instructed to investigate only event groups scoring 20 or above for potential SAR filings – yet the firm’s own internal analyses showed that some lower-scoring groups would have triggered filings had they been reviewed.1

The result was a systematic gap in AML reporting that persisted for roughly 54 months, from April 2020 through September 2024. The SEC did not disclose the total number of SARs that went unfiled, but described the failures as “numerous.”

The case is a textbook example of over-reliance on algorithmic compliance tools without adequate human oversight – an issue regulators have flagged at other institutions. A similar enforcement dynamic played out in Australia, where the ASX was fined A$20.5 million over misleading disclosures tied to its CHESS clearing system, illustrating that automated infrastructure failures can carry significant regulatory consequences.

Management Response & Outlook

Bank of America said it maintains rigorous anti-money laundering practices and continually reviews its AML systems to detect and report suspicious activity.2 The bank said Merrill cooperated with the SEC investigation and, after lowering the risk-score threshold for internal reviews, subsequently filed numerous SARs that had previously gone unsubmitted.

“[Bank of America] maintains rigorous anti-money laundering practices, and continually reviews its anti-money laundering systems to detect and report suspicious activity.”2

The regulator credited Merrill’s cooperation and remediation steps in reaching the settlement, factors that likely reduced what might otherwise have been a larger penalty.

Conclusion

The Merrill Lynch settlement reinforces a clear regulatory message: broker-dealers cannot delegate SAR compliance entirely to algorithmic systems without validating that calibration thresholds are sufficiently sensitive. For BAC investors, the direct financial hit is negligible, but the case may foreshadow increased compliance spending as firms audit their own monitoring software parameters ahead of potential industry-wide regulatory review.1

The SEC’s willingness to penalise a firm even when internal analyses flagged the deficiency – but remediation was delayed – sets a higher bar for how quickly institutions must act on self-identified AML gaps.

Not investment advice. For informational purposes only.

References

1Jonathan Stempel (June 29, 2026). “US SEC fines BofA’s Merrill Lynch $7.5 million for not flagging enough suspicious activity”. Reuters. Retrieved June 29, 2026.

2Jonathan Stempel (June 29, 2026). “US SEC fines BofA’s Merrill Lynch $7.5 million for not flagging enough suspicious activity”. KFGO / Thomson Reuters. Retrieved June 29, 2026.

3“US SEC fines BofA’s Merrill Lynch $7.5 million over suspicious activity reports” (June 29, 2026). MarketScreener. Retrieved June 29, 2026.