In April 2026 the Office of the Comptroller of the Currency issued a consent order against Community Federal Savings Bank of Woodhaven, New York, docket AA ENF 2025 21. The order found that the bank's automated suspicious activity alert triage system, with filtering criteria and thresholds that had not been adequately tuned to a payment processing line that had grown sharply since 2020, closed a very high percentage of all ingested alerts, including alerts that should have been escalated for review. The OCC named the bank. It did not name the vendor or the model builder. This Working Paper reads the case as the financial instance of the structural gap The Accountability Gap™ (TAG™) names in clinical AI. It applies the two seats and the Handoff to the facts of the order, shows that the institutional seat failed to keep the system's authorization current and that the reviewing seat was left unfilled by the system's own configuration, and sets out what the case means for any financial institution running an automated system a person is expected to act on.
An automated alert triage system at a chartered United States bank closed a very high percentage of the suspicious activity alerts it ingested, including alerts that should have been escalated for human review. In April 2026 the Office of the Comptroller of the Currency issued a consent order against that bank, Community Federal Savings Bank of Woodhaven, New York. The order named the bank. It did not name the vendor that built the system or the model behind it. This is the financial instance of the same structural gap The Accountability Gap™ (TAG™) names in clinical AI. An AI system produced an output, a person was supposed to act on it, and between the two, no one was named as the reviewer of record.
The clinical version of that gap is treated in Working Paper №01. The framework that names it, in terms that do not depend on the room, is stated in Framework Brief №02, The Accountability Gap™. This paper does the same work Working Paper №01 does for the bedside. It gives the financial room its own citable record of where accountability broke and why.
The facts of the case
The consent order is docket AA ENF 2025 21, executed on April 24, 2026, and made public in the OCC’s May 2026 enforcement action release. Its findings are the Comptroller’s, which the bank neither admitted nor denied, and they describe a Bank Secrecy Act and anti money laundering compliance program that had not kept pace with the business it was supposed to govern.
The order records that since 2020 the bank had grown its payment processing line sharply relative to its size, producing significant annual wire and ACH activity, including cross border activity involving foreign financial institutions. The controls did not grow with it. The order states that the bank failed to develop and maintain controls and risk management processes commensurate with its risk and growth. That single sentence frames everything that follows. The business changed and the governance around it did not.
At the center of the findings is the monitoring system. The bank ran an automated suspicious activity alerting system whose filtering criteria and thresholds had not been adequately tuned to the risk profile of the payment processing line, the increases in higher risk products and services, or the international exposure the bank had taken on. On top of that alerting system the bank ran an automated alert triage system. The order finds that deficiencies in that triage system’s logic, data, and methodology caused it to close alerts that should have been escalated for further review. As a result, in the order’s own terms, the system closed a very high percentage of all ingested alerts.
Two dimensions make the finding more than a configuration error. The first is scale. This was not a handful of alerts closed in error. It was a very high percentage of everything the system ingested. The second is time. The thresholds were set for a smaller institution than the bank had become, and the bank kept growing, so the distance between the volume flowing through the system and the volume a person actually reviewed widened as the business expanded. A control that is not retuned to a growing business does not hold steady. It decays against a moving baseline.
The triage failure did not sit alone. The order also finds that the bank’s customer due diligence program was ineffective, to the point that the bank did not understand the nature of certain customers’ businesses or the purpose of their transactions in the payment processing line, including risks tied to foreign financial institutions and correspondent account obligations. It finds that independent testing was weak, that the internal auditor failed to identify the program’s weaknesses, and that the audit work did not scope in and test the high risk areas where the exposure actually lived. Taken together the order describes systemic internal controls breakdowns, weak independent testing, and weak staffing of the BSA function. The significance for this paper is direct. The automated triage system was closing alerts it should have escalated, and every other line of defense that might have caught that failure was itself deficient. Nothing behind the system was positioned to notice what the system was doing.
There is a further consequence in how the closures were recorded. When a triage system closes an alert automatically, the record shows a closed alert. It does not, on its own, distinguish an alert a qualified person reviewed and cleared from one the system suppressed before any person saw it. An examiner reconstructing the program after the fact inherits that ambiguity. The volume of closures that looked resolved was, in substance, a volume of decisions no one had made.
The order ties these findings to specific violations. The deficiencies amounted to a Bank Secrecy Act and anti money laundering program violation under 12 C.F.R. 21.21, alongside violations of the suspicious activity reporting requirement and of the information sharing requirement under section 314 of the USA PATRIOT Act. The register matters for a citable record. These are not observations that a bank could do better. They are findings of violation of law and regulation, consented to by the board, entered on the public supervisory record.
The outcome is a matter of public record. The OCC issued a consent order requiring a compliance committee with a majority of outside directors, an action plan naming the persons responsible for each corrective action, an end to end assessment of the BSA and AML program by an outside consultant, and a schedule of remediation the board is bound to oversee. The order is dated, docketed, and published. It is the durable evidence this paper rests on, and it requires no narration to carry its weight.
Who was named, and who was not
The consent order is captioned in the matter of the bank. The bank’s board consented to it. The bank answers for it. The vendor that supplied the triage system is not a respondent. The model builder is not a respondent. The fintech partners whose transaction volume flowed through the payment processing line, and whose growth created much of the exposure, are not respondents. The regulated, chartered institution is the party named, and the regulated, chartered institution is the party bound to remediate.
This is the structure of financial enforcement, not an accident of this case. Supervisory authority runs to the chartered entity. When an examination finds that a bank’s program failed, the order lands on the bank, whatever share of the system was built, operated, or fed by someone else. A bank can outsource the software. It cannot outsource the obligation. The accountability for what the system did inside the bank’s own compliance program stays with the bank.
The payment processing line is the detail that makes this pointed. Much of the volume, and much of the cross border risk, flowed through arrangements in which the bank extended its charter to activity that others originated. The exposure grew through those arrangements, and that growth is exactly what the thresholds failed to track. The order does not divide accountability in proportion to who generated the volume. The charter is indivisible. The institution that holds it holds the whole of the obligation that comes with it, including the obligation to govern the automated systems operating inside its own program.
The pattern is structural rather than particular to this bank. Supervisory authority attaches to the charter, so across comparable actions against institutions that sponsor payment and program relationships, the party named and bound is the chartered bank, not the partners whose activity moved through it. An institution cannot contract its way out of the obligation by pointing downstream to who built the system or upstream to who generated the volume. The name on the charter is the name on the order.
Working Paper №01 established the same principle for clinical AI. The institution that deploys the system is where liability lands, regardless of who built the model or trained it. A hospital does not escape accountability for a recommendation acted on at its bedside by pointing to the vendor, and a bank does not escape accountability for an alert closed inside its program by pointing to the triage vendor. The room changes. The party who answers does not. In both rooms the entity that put the system into use is the entity that has to stand behind what the system produced.
Applying TAG to this case
The Accountability Gap™ defines two named seats and a required handoff between them. The mechanics of the two seats, the six functions, and the Handoff are set out in Framework Brief №02 and are not repeated here. What follows applies them to the facts of the order.
The Governance Owner is the institutional seat that charters an automated system, commissions it into a specific use, and holds cover for it operating as chartered. Charter names what the system is authorized to do and, as importantly, keeps that authorization current with the business the system actually serves. The order describes a Charter failure in exactly those terms, without using the word. Thresholds set for a smaller institution were never retuned to the payment processing line the bank had grown into. The authorization the system was operating under had stopped matching reality, and no named owner was accountable for closing that distance. A charter that is written once and never revisited is not a live authorization. It is a snapshot of a bank that no longer exists.
Charter is the most visible of the three functions the institutional seat holds, and it is not the only one the order implicates. Commission, the approval of a system into a specific use, and Cover, the holding of institutional accountability for that system operating as authorized, were both nominally present and functionally absent. A system was in use, so something had been commissioned. An institution was on the hook, so cover existed on paper. What was missing was a named owner keeping all three live as the business changed. The order’s remedies read as the OCC compelling that seat into existence after the fact. A compliance committee of outside directors, an action plan that names the person responsible for each corrective action, and a board bound to review that plan are, in substance, the machinery of a Governance Owner the program had been operating without.
One caution follows from the framework. The order’s central governance remedy is a compliance committee, and a committee is oversight, not a seat. A committee cannot decide an individual escalated alert, and it cannot be the named owner who charters the system and keeps that charter current with the business. It can watch that those owners exist and do their work. An institution that treats the remedy as satisfied by standing up a committee, without naming the Governance Owner and the Decision Owner beneath it, will have added a layer of oversight above the same empty seats. The committee is the floor of the remedy. It is not the whole of it.
The Decision Owner is the seat that decides, documents, and defends the call on an individual escalated alert. In this case the seat was empty at the moment it was needed, and the reason is the heart of the matter. When an automated triage system closes an alert, the alert never reaches a person. The Decision Owner does not decline to review it. The Decision Owner never receives it. The seat goes unfilled for that decision by construction, not by neglect. The system’s own configuration removed the human review the seat exists to provide, and it did so silently, alert after alert, at a very high percentage of everything ingested. This is the mechanism of the gap in its purest form. The handoff did not fail under pressure. It was configured never to occur.
The point holds even for the alerts the system did escalate. The Decision Owner seat is not filled by receiving an alert. It is filled by deciding, by documenting the decision and its reasoning, and by being able to defend both when an examiner asks. A program with weak independent testing and systemic internal controls breakdowns, which the order found this one to have, is a program in which even the reviewed decisions may not have left a record that survives audit. The seat is only as real as the trail it produces, and the trail is what an examination reconstructs.
The Handoff is the documented junction where an alert clears the automated system and reaches a named person who then owns the call. In an accountable program that junction is defined. The system escalates, a person receives, the person’s decision and reasoning enter the record, and the transfer is legible to an examiner afterward. The order describes the opposite. Alerts that should have crossed that junction were closed before they reached it, and there was no named owner on the receiving side to notice that they had not arrived. The seam between where the system’s authority ended and where a person’s authority should have begun was never built. That unbuilt seam is what the OCC found, and it is what this paper is named for.
What this means for financial institutions now
The exposure is not confined to one bank. Any institution running an automated system that produces outputs a person is expected to act on carries the same structure, and the same question can be asked of it. Who charters the system and keeps that charter current with the business. Who receives the escalated output and owns the call. If the answer to either question is a system rather than a named person, the seat is unfilled, and the institution is exposed in the way Community Federal Savings Bank was exposed.
That exposure now sits alongside a narrowing insurance market. Position Paper №02 treats in full how the standard forms have begun to exclude losses arising from generative AI, and that treatment is not repeated here. The point for this paper is narrower. An institution that cannot show a named Governance Owner and a named Decision Owner for an automated system is holding a risk it may no longer be able to transfer, at the same moment a regulator has shown it will name the institution and no one else. The coverage question and the accountability question arrive together, and they are answered by the same act of naming.
Building the seam is specific work, and the order describes its absence precisely enough to describe its presence. Retuning the thresholds to the volume and the risk the business actually carries, on a schedule rather than once, is a Charter act with a named owner behind it. Placing a named reviewer on the receiving side of every escalation, with the authority to decide and the obligation to record, fills the Decision Owner seat. Defining the escalation path so that an alert cannot be closed without either a documented human decision or a documented rule a named reviewer stands behind, builds the Handoff. Re verifying all three as the business grows keeps them current. None of it requires a new model. It requires named people on both sides of the alert.
None of this is hypothetical. It has happened, it has been enforced, and the order is public. The instruction it carries for every institution running comparable systems is to build the seam before an examiner finds it missing. Name the seat that charters the system. Name the seat that receives what it escalates. Document the junction between them. The work is the same work the bank in this case did not do.
Close
The gap is not in the model. It is in the seam between where the system’s authority ends and where a named person’s authority should begin. The triage system did what its logic, data, and thresholds told it to do. What was missing was the named accountability on either side of the alert, the owner who should have kept the system’s authorization current and the owner who should have received what it escalated. FinVigilance™ names and audits that seam in the financial room the same way MedicoVigilance™ does at the bedside. Same framework. Different room.
Primary source
Office of the Comptroller of the Currency. Consent Order, In the Matter of Community Federal Savings Bank, Woodhaven, New York. Docket No. AA-ENF-2025-21. April 24, 2026. https://www.occ.gov/static/enforcement-actions/eaAA-ENF-2025-21.pdf
Funding
None declared.
Conflicts of interest
Mo Johnson, MD MBA is the founder of GPe Research. The Accountability Gap™ (TAG™), the Named Owner Principle, MedicoVigilance™, and FinVigilance™ are works and marks of GPe Research. The author has a commercial interest in the adoption of the frameworks described in this paper.
How to cite
@techreport{johnson2026seam,
author = {Johnson, Mo},
title = {The Seam: How a Bank's Automated Triage System Closed the Alerts Nobody Read},
institution = {GPe Research Publications},
type = {Working Paper},
number = {№02},
year = {2026},
month = {7},
url = {https://publications.gperesearch.com/papers/the-seam}
}