
Issue #21 | September 15, 2026 | 7 min read
The Brief
Rabobank's California subsidiary didn't get caught missing suspicious activity. Plenty of banks miss things and write a check to a regulator for it. Rabobank got caught telling its own regulator, in writing, that an assessment which had already found $233 million in unreported suspicious activity simply didn't exist, while the assessment sat in the bank's own files.
That distinction is what turned a compliance failure into a felony. This issue covers how Rabobank built an AML program that was structurally unlikely to catch anything, what happened when an outside consultant found the problem anyway, and what it eventually cost the one executive whose name ended up on the cover-up.
Main Feature
Rabobank Didn't Miss $233 Million in Suspicious Activity. It Buried the Report That Found It.
A "Verified List" made high-risk accounts officially non-suspicious. When a paid consultant said otherwise, executives told the OCC no such report existed.
On February 7, 2018, Rabobank, N.A., the Roseville, California-based U.S. subsidiary of the Dutch banking group, pleaded guilty to a single felony charge: conspiracy to defraud the United States and to corruptly obstruct the OCC's examination of its own bank secrecy program. It forfeited $368,701,259, one of the largest BSA-related penalties ever imposed on a bank its size, arising out of a rural branch network in California's Imperial County, on the US-Mexico border, where hundreds of millions of dollars in cash moved through the bank with minimal scrutiny for years.
The conduct that actually produced a criminal charge, rather than a civil settlement, happened after the fact. In 2012, the OCC examined Rabobank's AML program and got the impression, from bank executives, that everything was in order. In February 2013, the OCC sent a written request for a third-party consultant's assessment of that same program, an assessment the bank had already commissioned and already received. Executives, including then-General Counsel Daniel Weiss, held onto the full report, handed the OCC a sanitized summary instead, and told examiners for nearly a month that no further materials existed. The full report was in the bank's possession the entire time. It found more than $233 million in suspicious activity that Rabobank had never reported to FinCEN between 2010 and 2013.
$368,701,259 — forfeited to the DOJ; the $50 million Rabobank separately paid the OCC was credited against this total, not added on top
$233,000,000+ — in suspicious activity Rabobank's own hired consultant found unreported, 2010–2013
3 — analysts covering roughly 2,300 monthly alerts at the time
17 months — between Rabobank's own guilty plea and the OCC's personal penalty against the general counsel who helped conceal the report
The program the consultant was reviewing wasn't a mystery to anyone inside the bank. Rabobank ran a "Verified List" that formally designated certain high-risk accountholders as non-suspicious, overriding whatever the transaction monitoring system actually flagged on their accounts once they'd cleared it once. Accountholders moving cash in patterns just under the $10,000 currency transaction reporting threshold got a pass because they said it was to avoid extra paperwork crossing the border, the textbook structuring rationale, logged and accepted rather than tested. And the alert queue itself was a design choice: three analysts working roughly 2,300 alerts a month made a growing backlog structurally inevitable, not an unlucky staffing gap. When compliance staff tried to escalate what the consultant had found, the bank's response wasn't to fix the program. One compliance officer was placed on administrative leave and then terminated for allegedly failing to represent the bank properly to regulators. Another was demoted. Notably, one of the executives who'd later push back on the consultant's findings had previously examined Rabobank himself, as an OCC regulator, during the agency's 2006 and 2008 sanctions of the bank for similar deficiencies, a revolving door that didn't produce better oversight the second time around.
Red flags in this case
A "Verified List" policy that formally cleared high-risk accountholders as non-suspicious, overriding whatever the transaction monitoring system actually flagged going forward
Structuring patterns just under the $10,000 CTR threshold accepted at face value because accountholders said it was to avoid extra border paperwork
Three analysts covering roughly 2,300 monthly alerts — a caseload that made a growing review backlog inevitable, not incidental
Compliance staff who escalated the consultant's adverse findings were placed on leave, terminated, or demoted rather than heard
Executives withheld the full consultant report from the OCC for nearly a month and told examiners no further materials existed, when the report was in the bank's possession throughout
Any "verified" or "cleared" override list is itself a control, and it needs the same audit trail, expiration date, and periodic revalidation as any other risk decision, not a permanent exemption once an account clears review the first time. A customer's stated reason for a structuring pattern is a data point to test against actual account activity, not a reason to close the alert. And an escalation channel only exists in practice if the person who uses it keeps their job. Rabobank had a channel. It also had a documented track record of what happened to the people who used it.
Seventeen months after Rabobank's own guilty plea, the OCC came back for Daniel Weiss personally: a $50,000 civil penalty and a lifetime ban from the banking industry, specifically for the "continuous concealment" of the consultant's report. It's a small number next to $368.7 million, and it's also the only individual consequence anyone connected to this case has faced.
The felony charge here wasn't for running a bad AML program. Plenty of banks do that and settle civilly. It was for finding out, on paper, in a report the bank itself paid for, and telling the regulator otherwise.
Source: U.S. Department of Justice, "Rabobank NA Pleads Guilty, Agrees to Pay Over $360 Million," February 7, 2018 | U.S. Attorney's Office, Southern District of California, "Bank Pleads Guilty and Pays Historic Penalty for Concealing Anti-Money Laundering Failures" | Office of the Comptroller of the Currency, consent order and civil money penalty, In the Matter of Daniel Weiss, July 23, 2019
Controls & Testing
Risk & Control Matrix
Risk | Control |
|---|---|
A "cleared" or "verified" override list reclassifies flagged accountholders as non-suspicious without ongoing review of actual activity | Periodic independent revalidation of any override/exception list against current transaction activity, with a mandatory expiration date and no permanent status |
Below-threshold transaction patterns are accepted based on the customer's stated explanation rather than tested against it | An aggregation rule flagging repeated sub-$10,000 transactions from the same accountholder for SAR review regardless of the stated business reason |
Alert volume structurally exceeds analyst capacity, guaranteeing an unreviewed backlog | A documented alert-to-analyst capacity ratio with an escalation trigger, added staffing or threshold tuning, when volume crosses a defined limit |
Adverse findings from a commissioned third-party assessment get filtered or summarized before reaching the primary regulator or the board | A requirement that full third-party AML/BSA assessments go directly to the regulator and the board audit committee, not through the business line under review |
Compliance staff who escalate program deficiencies face termination, demotion, or involuntary leave rather than protection | A documented non-retaliation policy for AML escalations, tested by tracking employment actions against staff who raised findings |
Audit Test Steps
An audit program built around this typology could test for it by:
Pulling the population of accounts on any internal "verified," "cleared," or override list and comparing each account's transaction activity over the trailing 12 months against its assigned risk rating, flagging any account whose activity contradicts its override status.
Selecting a sample of accountholders with three or more transactions just under the $10,000 CTR threshold within a 30-day window and testing whether the stated business rationale was independently corroborated, rather than simply logged and accepted.
Calculating the monthly alert-to-analyst ratio for the transaction monitoring team over the trailing 12 months and comparing it to documented review capacity, flagging any period where volume exceeded capacity without a corresponding staffing or threshold change.
Requesting copies of every third-party AML/BSA assessment commissioned in the audit period and confirming each was provided to the primary regulator in full, not as a summary, within the timeframe required by any outstanding supervisory request.
Reviewing HR records for compliance staff who raised documented AML program concerns in the period and testing whether termination, demotion, or involuntary leave followed within 12 months of the concern being raised.
Intelligence Briefing
FinCEN — On September 2, FinCEN reissued its Geographic Targeting Order for money services businesses along the southwest border, requiring CTR filings on cash transactions between $1,000 and $10,000 in designated ZIP codes across Bernalillo, Doña Ana, and San Juan counties in New Mexico, and Cameron, El Paso, Hidalgo, Maverick, and Webb counties in Texas. The order runs through March 1, 2027. It's the same sub-$10,000 cash-transaction band this issue's main feature covers from the other side, a bank waving structuring through instead of an MSB required to report it. Source: FinCEN, "FinCEN Reissues Order Requiring Transparency from MSBs Along Southwest Border," September 2, 2026.
DOJ — On June 30, EagleBank agreed to pay $9.7 million to resolve a DOJ investigation into a decade-long BSA program failure (2010–2021) that let two customers run a check-kiting scheme costing another financial institution nearly $6.3 million. Per the DOJ's statement, bank executives repeatedly overrode compliance staff's attempts to stop it, the same executives-over-compliance pattern this issue's main feature runs on a larger scale. Source: U.S. Department of Justice, "EagleBank Agrees to Pay More than $9.7 Million to Resolve Bank Secrecy Act Investigation," June 30, 2026.
Career Intel
Financial examiners, the professionals who conduct exams like the one Rabobank obstructed, had a median annual wage of $94,160 in May 2025, with the top 10% clearing $174,200. BLS projects 9% employment growth through 2035, faster than average, and 44% of examiners work in private-industry credit intermediation rather than government roles. That's not a footnote: this issue's case features an OCC examiner from the bank's 2006–2008 sanctions who later became Rabobank's own compliance executive. The career path runs both directions, regulator to bank and back, and the revolving door doesn't automatically produce better oversight on the second pass.
Tip Line
Got any idea for something you'd want to see covered here? Doesn't have to fit neatly into a category. If you think it's interesting, we probably will too.
Send it to [email protected].
If someone forwarded this to you, welcome.
The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:
[BUTTON: Subscribe → theamlbrief.com]
Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.
The AML Brief | theamlbrief.com
Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.