Analysis: the wrinkle in US law behind the Merrill Lynch order and what the Wall Street Journal got wrong.
Outside the USA, there is little recognition that the USA operates a de minimis rule for suspicious activity reports: in short, even where there is suspicion, if the amount involved is less than USD5,000, no report is required. It would, of course, be prudent for the case to be documented by a financial institution.
Merrill Lynch used to apply that limit and so long as the amount involved was more than USD5,000, a SAR would be filed. But then it took over Bank of America and for reasons that are not at all clear, it started to apply a threshold of USD25,000.
Merrills identified the problem and self-reported and as a result it's paying USD6 million to each of the Securities and Exchange Commission and to the Financial Industry Regulatory Authority, FINRA. There were about 1,500 reports not made over a decade or so.
These are penalties, not fines as the Wall Street Journal termed them.
The Journal said "Anti-money-laundering rules require broker-dealers to report to regulators on transactions over $5,000." This is wrong. Under the Bank Secrecy Act, as amended, broker-dealers are required to submit both cash transaction reports and suspicious activity reports to FinCEN. FinCEN has regulatory functions but it is not an industry or company regulator in the sense that FINRA or the SEC are. Cash transaction reports (which relate to more than cash simpliciter) refer to transactions exceeding USD10,000. Suspicious activity reports are, as noted above, required unless the amount does not exceed USD5,000. So, the report should be prepared, even if it is not submitted because of the threshold.
The Journal's failure to refer to "suspicious transactions" creates a misleading impression.
Both FINRA and the SEC have been conducting long overdue inspections of the activities of broker-dealers.
Until the USA PATRIOT Act, broker-dealers were left to their own devices with regard to the identification of customers and, therefore, Know Your Customer processes which are the bedrock of any suspicious activity regime. Industry guidance, which had no enforcement teeth, did not even require the identification of existing customers even though it did say that it was good practice (and no more) for broker-dealers to undertake KYC for new customers. That guidance was introduced long after banks etc. were required to introduce such measures. The USA PATRIOT Act provided for FinCEN to produce a requirement for KYC (again with no express requirement for the evaluation of existing customers) to be introduced quickly. But although a "draft final rule" was produced long after it should have been in force, FinCEN withdrew it, saying that it "had eyes on the money through the bank," reflecting the USA's fixation on money not on the people who use it. There are some provisions in the USA PATRIOT Act that are outside the FinCEN Rule and those have been applied.
US Broker-Dealers habitually used to refuse to provide any information as to the customers they were trading on behalf of in overseas markets. Given the failure to properly regulate for counter-money laundering purposes, this should have resulted in a boycott of international business introduced by US Broker-Dealers but it never happened.
FINRA and the SEC were stung by criticisms that Broker-Dealers were an easy route into the financial markets by criminals and terrorists and since 2017 have been undertaking a review of policies and procedures at Broker-Dealers across the USA. It is therefore quite surprising that Merills did not identify and act on its failures sooner. It is also surprising that the regulators did not undertake an inspection of Merrill/BofA soon after they joined forces: it is an accepted fact that compliance is one of the most difficult - and last - parts of a merger to become fully integrated. An early inspection would have noticed a line in a manual saying "25,000" instead of "5000."
The case draws attention to the USA's isolation on the policy of de minimis exemptions. It is all the more ridiculous when in money services businesses the cash transaction reporting limit is as low as USD2,000 depending on the nature of the business. There is no room in a properly designed system for de minimis exceptions. If it's suspicious, it should be reported otherwise data is so full of holes, its value is diminished.
What it means is that tax evasion of less than USD5,000 per annum (there being no aggregation in this context) does not have to be reported by accountants and others even where they are suspicious or know for a fact that taxes are being dodged.
Further Reading:
https://www.sec.gov/news/press-release/2023-128
https://www.finra.org/sites/default/files/2023-07/Merrill_Lynch_Pierce_…
https://www.wsj.com/articles/merrill-lynch-to-pay-12-million-for-failin…


