Epstein: the Complicity of Big Banks
Tone from the top fail
As someone who works in the financial crimes field, writing about the recent Epstein Wall Street Report published by the Senate Committee on Finance broke me. It broke my heart to see our financial system compromised by profit seekers. It destroyed me to see major banks that should have been at the forefront of defending financial integrity turn a blind eye to issues that erode it—all for the sake of profit (not that I oppose profit, but I oppose it when obvious crimes are involved in obtaining it). It enraged me to see the details of large banks’ willful ignorance of obvious suspicious transactions linked to a convicted sex trafficker and sex offender!
And seeing the lack of leadership and the obviously missing tone from the top that should have been emphasizing the importance of compliance and protecting the financial institution, its clients, and the financial system writ large, disillusioned and disenchanted me. This is the kind of stuff that makes me want to cash in my 401K, sell my home, and move to a cabin in the mountains, never again to read or be exposed to what I read in the 67-page report.
The Committee found that JPMorgan Chase (JPMC), Deutsche Bank, and Bank of America violated federal AML laws by failing to report Epstein’s suspicious transactions in a timely manner, and despite knowing how slimy their client was and eventually terminating their relationships with him, only notifying the US government years after the fact.
If you think these banks are the only ones that turn a willful blind eye to suspicious activity and maintain relationships with suspicious characters, refusing to file Suspicious Activity Reports until the activity becomes so egregious, it’s impossible to ignore, let me disabuse you of that notion. They’re just the ones that got most of the publicity.
It happens at other financial institutions that merely pay lip service to fighting illicit finance.
To be clear, I have never worked at JPMC, Deutsche, or Bank of America. But I’ve worked elsewhere, and I’ve seen it.
I’m basing my article strictly on what I have read in the Committee report and its source material.
What did the report find?
The report found massive “compliance failures” on the part of the three banks that are large, sophisticated financial institutions and should have known better.
Senator Ron Wyden’s (D-OR) staff reviewed records housed by the US Treasury, as well as internal bank records and the Epstein files published by the Justice Department, and determined that top executives at JPMC, Deutsche Bank, and Bank of America were not only aware of Epstein’s suspicious financial activity for years, but withheld that information from Treasury and other banks and protected Epstein from federal scrutiny.
Bank leaders coached Epstein on using shell companies to evade detection.
The banks worked to protect Epstein as a client and used him for business referrals.
They failed to send basic requests for information (RFIs), including for business records to substantiate the purpose of major suspicious transactions.
And these banks only reported the thousands of suspicious transactions retroactively, years later after Epstein’s crimes became clear.
These banks failed to conduct appropriate due diligence on more than $170 million in payments to Epstein from billionaire Leon Black. In fact, according to the report, “documents reviewed during this investigation demonstrate that JPMC’s senior leadership repeatedly protected Epstein as a client despite repeated warnings from internal compliance personnel.”
Let’s stop right there.
These are not “compliance failures”
Leadership was warned. Compliance personnel did their jobs, but leadership found that the piles of money they were making from keeping Epstein and Black as clients were worth moving the proceeds of sexual exploitation and abuse!
I will dispute the characterization of these activities as “compliance failures.” They were not. The phrase implies that suspicious activities were simply not found by compliance staff and that the processes had failed. It’s not the case here.
Compliance personnel were overruled. Period.
Unsealed internal JPMC emails indicate that JPMC’s former top compliance and AML executive William Langford tried for years to terminate Epstein over human trafficking concerns but was overruled by senior JPMC leadership, including General Counsel Steve Cutler. As the general counsel, Cutler was a member of JPMC’s operating committee and reported directly to CEO Jamie Dimon. Cutler was personally responsible for approving decisions to keep Epstein on as a client. In a 2023 deposition, CEO Jamie Dimon noted that the General Counsel, at the time Cutler, was the “ultimate decider” on decisions related to keeping Epstein on a as a client.
According to a released email, it appears that in 2011 JPMC’s AML team made a request to the private bank to exit the Epstein relationship over concerns of human trafficking. This email also noted that Epstein was a close “personal associate” of investment banking CEO Jes Staley and that decisions to keep Epstein in the bank were “all due to Jes’s personal relationship” with Epstein. The email also noted Epstein’s $212 million held at JPMC as a reason the private bank was hesitant to kick Epstein out as a client.
This is sickening.
There are also references in internal correspondence describing Epstein as “scum” and a “known child sleaze.”
Again, leadership knew and did nothing.
This is not a “compliance failure.” The compliance teams repeatedly did their jobs and flagged the activity, but leadership appeared more worried about their profits and about Staley’s personal relationship with Epstein.
Bank of America allowed nearly $170 million in wire transfers to just roll through from Black to Epstein with no apparent business purpose. Wyden’s team claims this is part of a larger pattern across Wall Street where financial institutions “do not sufficiently scrutinize ultra-wealthy clients like Leon Black, for fear that clients who don’t want to answer questions will simply take their business elsewhere.”
I don’t have sufficient experience to confirm or deny these allegations. But do banks, financial institutions, and other firms hesitate when performing enhanced due diligence and asking substantive questions about sources of funds and wealth of wealthy, high-risk clients? Yes. Because they will leave, and they will find a bank that glosses over their potentially harmful financial activities.
The report states that Bank of America does not appear to have ever asked Black or Epstein for additional information or business records to substantiate the purported tax and estate planning services Epstein claimed he was performing for $170 million. Except Epstein had no formal training, professional certifications, or licenses, and the transfers were much too large to pay for those types of services.
A typical tax advisor could cost tens of thousands of dollars, depending on the complexity of the client’s finances. But $170 million over the course of maybe six years to an individual who had zero formal training should raise red flags. And had Bank of America conducted thorough due diligence on these transactions, it likely would have filed SARs much sooner.
But instead, BoA waited until 2020 to file the reports with FinCEN - eight months after Epstein was arrested and seven years after the payments began.
As I noted in previous writing, a bank must file a SAR with FinCEN within 30 calendar days from the date of initial detection of the suspicious activity. If the bank cannot initially identify a suspect, it gets 60 calendar days. But not months, and certainly not years!
When BoA finally did file SARs retroactively, it flagged $156 million paid by Leon Black’s accounts to Epstein and stated that “the wire transfer activity does not have a verifiable business purpose” and that the transactions had “no apparent economic, business or lawful purpose.” In addition, the bank flagged “two potentially unusual wires” from the Black accounts to Epstein that the bank previously had failed to identify, one for $5.5 million in November 2012 and another $8 million in 2017.
“Potentially unusual?” Really?
Millions of dollars in wire activity to a convicted sex offender and trafficker that appear to have no lawful business purpose were merely “potentially unusual” years after the fact?
Come on, now.
Jane Heller at BoA was one of Black’s principal bankers, according to Justice Department records. The report cites a 2014 email by employees at Leon Black’s family office that indicate that confirm Heller was running point on coverage of Black’s accounts. Yet another internal BoA document noted that Heller “already has a relationship with Black that includes a $400MM art secured line.”
She knew Black. She knew he was transacting with a known sex offender. She knew and understood his business interests. I cannot imagine she and her colleagues were unaware of Epstein and his background!
Again, I cannot see how this can be characterized as a “compliance failure.”
This was willful. This was criminal. This was a conscious effort to protect a high-value client who likely generated millions of dollars in fees for “financial services, including private wealth management, brokerage, and large lines of credit against assets like stocks, art collections, yachts, and real estate.”
This is especially egregious given that Leon Black in 2023 reached a settlement agreement with the US Virgin Islands in which he agreed to pay more than $62 million in exchange for avoiding criminal prosecution for his funding of Epstein’s abuses. It’s not like it was unknown. Adverse media checks would have revealed Black’s relationship with Epstein.
JPMC top staff even coached Epstein how to use shell companies to withdraw cash! The use of shell companies is a massive indicator of money laundering and is consistently flagged as an illicit finance risk.
FinCEN flagged shell companies as a money-laundering risk 20 years ago.
The Federal Financial Institutions Examination Council (FFIEC) writes that shell companies can be used for money laundering and other crimes because they are easy and inexpensive to form and operate, and privately held shell companies can more easily conceal beneficial ownership, making them an ideal money-laundering vehicle.
Compliance firm Castellum.ai explains the compliance risks associated with shell (and shelf) companies, flagging that these entities are often registered in an offshore jurisdiction that does not require substantial disclosures on business ownership or may have advantageous tax regimes, like Cyprus, the UAE, Seychelles, the UK and dependencies like British Virgin Islands (BVI) or Cayman Islands, as well as some US states like Delaware, Wyoming or Nevada.
The global AML watchdog the Financial Action Task Force (FATF) has also written about anonymous shell companies flagging that they are one of the most widely used methods for laundering the proceeds of crime and corruption.
This is basic. Shell companies are a known risk and have been for years. Willful facilitation via the use of known financial vehicles that help bad actors move money is not and should not be characterized as “compliance failures.”
Cash withdrawals
Epstein’s suspicious transactions through JPMC did not only include suspicious wire transfers, but also the withdrawal of more than $7 million in physical cash and more than $3 million in direct payments to women or girls in high-risk jurisdictions for human trafficking.
Deutsche Bank also failed to flag in a timely manner withdrawals of more than $800,000 in cash to pay directly to women in Russia and throughout Eastern Europe for “hotel expenses, tuition, and rent,” as well as more than $7 million in private settlements with potential victims of Epstein’s sex trafficking scheme.
Deutsche should have known as well.
According to a 2020 consent order, an agreement with the New York Department of Financial Services resulted in a $150 million fine for the bank. The consent order details how Epstein’s attorney inquired into how often he could withdraw cash on Epstein’s behalf without triggering the need to file a Cash Transaction Report (CTR). Although whether the bank responded to the inquiry is unclear, the question itself should have been a red flag!
Deutsche’s AML team after a second inquiry advised the attorney, Darren Indyke, that his structuring of cash withdrawals to avoid filing reports with the Treasury Department was unacceptable and subsequently recommended exiting the relationship. But again, nothing was done, and the bank allowed Indyke to continue withdrawing cash on Epstein’s behalf.
They knew, and they did nothing. Worse yet, they tried to conceal it.
Other evidence indicates that senior Deutsche Bank executives were aware of the risks Epstein posed but deliberately limited written records of discussions related to risks arising from the Epstein relationship. For example, in 2015 members of Deutsche Banks’ America’s Reputational Risk Committee met to discuss the Epstein relationship in response to damaging new reports and litigation from victims of Epstein’s sex trafficking. Deutsche Bank’s policies and procedures required that minutes be kept of these meetings, but Deutsche Bank claimed to the NY DFS that no recorded minutes exist from this particular meeting.
Retroactive filing.
As I mentioned previously, banks and financial institutions must file SARs at MOST 60 days after the suspicious activity is detected. If there’s an actual suspect, the deadline is 30 days after the fact.
JPMC in 2019 retroactively flagged 4,725 wire transfers adding up to nearly $1.1 billion flowing in and out of Epstein’s accounts six years after terminating the relationship. It also flagged another 469 wire transfers totaling $201 million which included payments to women in in Russia, Belarus and Turkmenistan using foreign correspondent bank accounts at now-sanctioned Russian banks (Sberbank and Alfa Bank).
Deutsche Bank in 2019 retroactively flagged 1,140 wire transfers totaling $147 million in and out of Epstein’s accounts, and Bank of America in 2020 retroactively flagged $170 million in payments from Leon Black.
Epstein was convicted in 2008. He was brought into Deutsche as a client in 2013. Because of the amount of money involved, the move was a time to celebrate at Deutsche Bank. The fact that a convicted sex offender landed at Deusche was touted as a success story.
Epstein’s second relationship manager, Stewart Oldfield, was personally informed by compliance executives at the bank about the concerning cash withdrawals from Epstein’s accounts and the fact that Indyke was warned about structuring.
Deutsche didn’t terminate the relationship until 2018 and worked to protect Epstein instead, sending out a referral letter to another financial institution on bank letterhead, noting that they were “unaware of any problems relating to the operation or use of [the] accounts.”
Doing the right thing matters
Whenever I train firms and financial institutions on compliance matters, I stress the importance of setting the tone from the top.
This is a common phrase that might seem trite, but the concept is absolutely critical to building a culture of compliance that will protect the organization, its clients, its business partners, and the financial system. It protects an organization’s reputation and it informs all personnel that ethics are non-negotiable.
The culture of compliance begins at the Board and executive leadership levels, and actions speak louder than words.
Leaders should enforce ethical behavior, instead of covering for criminals.
I don’t know whether the leaders of these banks clearly communicated values and ethical expectations. If they did, their hypocrisy reflects badly on their integrity. Did they dedicate sufficient resources to empower compliance functions? I would think so, since these are some of the largest, most sophisticated banks in the world, and as I mentioned, compliance risks were clearly run up the flagpole but promptly ignored.
Were there whistleblowers? Were they protected? It sounds like those who flagged the possible illicit activity by a convicted sex trafficker and his associates were ignored, and therefore the leaders of these banks willfully failed. They chose to protect their millions of dollars over protecting the bank, its customers, and the financial system.
These banks’ relationships with Epstein and his associates weren’t a matter of flawed compliance systems or processes. Compliance officers did not make mistakes; they detected what almost certainly was illicit financial activity. They warned senior leaders about Epstein, his suspicious transactions, and recommended terminating the relationships. Compliance processes worked just fine, but senior leaders opted to ignore the warnings, choosing the avalanche of cash instead.
I have not worked at these banks, and there was a time I would have been excited to do so, believing that I’ve reached the pinnacle of the golden mountain in my career.
Not so much anymore. I’m heartbroken to see this report. It wrecked me on a very personal level, because compliance professionals are my people. They work to protect the bank. They got into this field because they want to fight illicit actors. Every one of my team members has told me this throughout the years.
They want to stop bad guys, and many of them have been hired under the pretense of doing just that.
The disenchantment and heartbreak are very real, and I feel sick about it.
Want to comment on this hot mess? Become a paid subscriber and start the conversation!



