Item 1. Business
ITEM 1. BUSINESS
Overview
American Express is a globally integrated payments company, providing customers with access to products, insights and experiences that enrich lives and build business success. We are a leader in providing credit and charge cards to consumers, small businesses, mid-sized companies and large corporations around the world. American Express ® cards issued by us, as well as by third-party banks and other institutions on the American Express network, can be used by Card Members to charge purchases at the millions of merchants around the world that accept cards bearing our logo.
Our various products and services are offered globally to diverse customer groups through various channels, including mobile and online applications, affiliate marketing, customer referral programs, third-party service providers and business partners, direct mail, telephone, in-house sales teams and direct response advertising.
We were founded in 1850 as a joint stock association and were incorporated in 1965 as a New York corporation. American Express Company and its principal operating subsidiary, American Express Travel Related Services Company, Inc. (TRS), are bank holding companies under the Bank Holding Company Act of 1956, as amended (the BHC Act), subject to supervision and examination by the Board of Governors of the Federal Reserve System (the Federal Reserve).
We principally engage in businesses comprising four reportable operating segments: U.S. Consumer Services (USCS), Commercial Services (CS), International Card Services (ICS) and Global Merchant and Network Services (GMNS). Corporate functions and certain other businesses are included in Corporate & Other. Our businesses function together to form our end-to-end integrated payments platform, which we believe is a differentiator that underpins our business model. For further information about our reportable operating segments, see “Business Segment Results of Operations” under “MD&A.”
Our Integrated Payments Platform and Technology
Through our general-purpose card-issuing, merchant-acquiring and card network businesses, we are able to connect participants and provide differentiated value across the commerce path. We maintain direct relationships with Card Members (as a card issuer) and merchants (as an acquirer), which provides us with direct access to information at both ends of the card transaction, distinguishing our integrated payments platform from the bankcard networks. Through contractual relationships, we also obtain information from third-party card issuers, merchant acquirers, aggregators and processors with whom we do business.
1
Table of Contents
Our integrated payments platform and the systems and infrastructure that underlie it allow us to analyze information on Card Member spending, build models and use analytical tools to help us underwrite risk, reduce fraud and provide targeted marketing and other information services for merchants and partners and special offers and services to Card Members, all while maintaining our commitment to respect Card Member preferences and protect Card Member and merchant data in compliance with applicable policies and legal requirements. We also leverage technology to allow for faster introduction and greater differentiation of products, as well as to develop and improve our service capabilities to continue to deliver a high-quality customer experience.
Card Issuing Businesses
Our global proprietary card-issuing businesses are conducted through our USCS, CS and ICS reportable operating segments. We offer a broad set of card products, rewards and services to a diverse consumer and commercial customer base, in the United States and internationally. We acquire and retain high-spending, engaged and creditworthy Card Members by:
• Designing innovative credit, charge and debit card products and payment and lending solutions that appeal to our target customer base and meet their spending and borrowing needs
• Using incentives to drive spending on our various card products and increase customer engagement, including our Membership Rewards ® and Amex ® Offers programs, cash-back reward features, interest rates offered on deposits and participation in loyalty programs sponsored by our cobrand and other partners
• Providing digital and mobile services and an array of benefits and experiences across card products, such as lounge access, dining experiences and other travel and lifestyle benefits
• Creating world-class service experiences by delivering exceptional customer care
• Developing a wide range of partner relationships, including with other corporations and institutions that sponsor certain of our cards under cobrand arrangements and provide benefits and services to our Card Members
Over the last several years, we have focused on broadening the appeal of our products to attract new customers, particularly Millennial and Gen Z customers, as well as expanding our position with small and mid-sized enterprise (SME) customers by providing more ways to help them manage and grow their businesses. We have a number of products that complement our card products, such as our business checking and consumer rewards checking account products, our business-to-business (B2B) payment products and other non-card payment and financing products, our Business Blueprint digital cash flow management hub, our Resy restaurant platform and other new digital capabilities. Additionally, we are focused on driving growth and efficiencies internationally, including a greater focus on local priorities in international jurisdictions. Jurisdictions that represent a significant portion of our billed business outside of the United States include the United Kingdom (UK), the European Union (EU), Australia, Japan, Canada and Mexico.
For the year ended December 31, 2023, worldwide billed business (spending on American Express cards issued by us) was $1,460 billion and at December 31, 2023, we had 80.2 million proprietary cards-in-force worldwide.
Merchant Acquiring Business
Our GMNS reportable operating segment builds and manages relationships with millions of merchants around the world that choose to accept American Express cards. This includes signing new merchants to accept our cards, agreeing on the discount rate (a fee charged to the merchant for accepting our cards) and handling servicing for merchants. We also build and maintain relationships with merchant acquirers, aggregators and processors to manage aspects of our merchant services business. For example, through our OptBlue ® merchant-acquiring program, third-party processors contract directly with small merchants for card acceptance on our network and determine merchant pricing. We continue to grow merchant acceptance of American Express cards around the world and work with merchant partners so that our Card Members are warmly welcomed and encouraged to spend in the millions of places where their American Express cards are accepted. We also seek to drive greater usage of the American Express network by deepening merchant engagement and increasing Card Member awareness through initiatives such as our Shop Small campaigns and expanding our payment options such as through debit and B2B capabilities.
GMNS also provides fraud-prevention tools, marketing solutions, data analytics and other programs and services to merchants and other partners that leverage the capabilities of our integrated payments platform.
2
Table of Contents
Card Network Business
We operate a payments network through which we establish and maintain relationships with third-party banks and other institutions in approximately 110 countries and territories, licensing the American Express brand and extending the reach of our global network. These network partners are licensed to issue local currency American Express-branded cards in their countries and/or serve as the merchant acquirer for local merchants on our network.
For the year ended December 31, 2023, worldwide network services processed volume (spending on American Express cards issued by third parties) was $220.5 billion and at December 31, 2023, we had 61.0 million cards-in-force issued by third parties worldwide.
Diverse Customer Base and Global Footprint
Our broad and diverse customer base spans consumers, small businesses, mid-sized companies and large corporations around the world. The following chart provides a summary of our diverse set of customers and broad geographic footprint based on worldwide network volumes:
3
Table of Contents
Partners and Relationships
Our integrated payments platform allows us to work with a range of business partners, and our partners in return help drive the scale and relevance of the platform.
There are many examples of how we work with partners, including: issuing cards under cobrand arrangements with other corporations and institutions (e.g., Delta Air Lines (Delta), Marriott International, Hilton Worldwide Holdings and British Airways); offering innovative ways for our Card Members to earn and use points with our merchants (e.g., Pay with Points at Amazon.com); providing greater value to our Card Members (e.g., Amex Offers and statement credits for purchases with partners); expanding merchant acceptance with third-party acquirers and processors (e.g., OptBlue partners); operating through joint ventures in certain jurisdictions (e.g., in China, the Middle East and Switzerland); developing new capabilities and features with our digital partners (e.g., PayPal and i2c); integrating into the supplier payment processes of our business customers (e.g., BILL and Extend); and enhancing our travel benefits and services (e.g., Fine Hotels and Resorts). We also have a significant ownership position in, and extensive commercial arrangements with, Global Business Travel Group, Inc. (GBTG), which provides business travel-related services.
Delta is our largest strategic partner. Our relationships with, and revenues and expenses related to, Delta are significant and represent an important source of value for our Card Members. We issue cards under cobrand arrangements with Delta and the Delta cobrand portfolio represented approximately 10 percent of worldwide network volumes and approximately 21 percent of worldwide Card Member loans as of December 31, 2023. The Delta cobrand portfolio generates fee revenue and interest income from Card Members and discount revenue from Delta and other merchants for spending on Delta cobrand cards. The current Delta cobrand agreement runs through the end of 2029 and we expect to continue to make significant investments in this partnership. Among other things, Delta is also a key participant in our Membership Rewards program, provides travel-related benefits and services, including airport lounge access for certain American Express Card Members, accepts American Express cards as a merchant and is a corporate payments customer.
Working with all of our partners, we seek to provide value, choice and unique experiences across our customer base.
Our Spend-Centric Model and Revenue Mix
Our “spend-centric” business model focuses on generating revenues primarily by driving spending on our cards and secondarily through finance charges and fees. Spending on our cards, which is higher on average on a per-card basis versus our network competitors, offers superior value to merchants in the form of loyal customers and larger transactions. Because of the revenues generated from having high-spending Card Members and the annual card fees we charge on many of our products, we are able to invest in attractive rewards and other benefits for Card Members, as well as targeted marketing and other programs and investments for merchants. This creates incentives for Card Members to spend more on their cards and positively differentiates American Express cards.
We believe our spend-centric model gives us the ability to provide differentiated value to Card Members, merchants and business partners.
The American Express Brand and Service Excellence
Our brand and its attributes—trust, security and service—are key assets. We invest heavily in managing, marketing, promoting and protecting our brand, including through the delivery of our products and services in a manner consistent with our brand promise. The American Express brand is ranked among the most valuable brands in the world. We place significant importance on trademarks, service marks and patents, and seek to secure our intellectual property rights around the world.
We aim to provide the world’s best customer experience every day and our reputation for world-class service has been recognized by numerous awards over the years. Our customer care professionals, travel consultants and partners treat servicing interactions as an opportunity to bring the brand to life for our customers, add meaningful value and deepen relationships.
4
Table of Contents
Our Business Strategies
We seek to grow our business by focusing on four strategic imperatives:
First, we aim to expand our leadership in the premium consumer space by continuing to deliver membership benefits that span our customers’ everyday spending, borrowing, travel and lifestyle needs, expanding our roster of business partners around the globe and developing a range of experiences that attract high-spending customers.
Second, we seek to build on our strong position in commercial payments by evolving our card value propositions, further differentiating our corporate card and accounts payable expense management solutions and designing innovative products and features, including financing, banking and payment solutions for our business customers.
Third, we are focused on strengthening our global, integrated network by continuing to increase merchant acceptance, providing merchants with fraud protection services, marketing insights and connections to higher-spending Card Members and working with our network partners to offer expanded products and services.
Finally, we want to continue to build on our unique global position, seeking ways to use our differentiated business model and global presence as we progress against our other strategic imperatives.
We also have an Environmental, Social and Governance (ESG) strategy that focuses on three pillars. The Building Financial Confidence pillar seeks to provide responsible, secure and transparent products and services to help people and businesses build financial resilience. The Advancing Climate Solutions pillar focuses on enhancing our operations and capabilities to meet customer and community needs in the transition to a low-carbon future. Finally, the Promoting Diversity, Equity and Inclusion (DE&I) pillar supports a diverse, equitable and inclusive workforce, marketplace and society.
5
Table of Contents
Our Colleagues
Our colleagues are integral to executing our business strategies and to our overall success. As of December 31, 2023, we employed approximately 74,600 people, whom we refer to as colleagues, with approximately 26,000 colleagues in the United States and approximately 48,600 colleagues outside the United States. In 2023, we continued to invest in our colleagues, building on a wide range of learning and development opportunities and enhancing our competitive benefits in key areas including holistic health and wellness, total compensation and flexibility.
We conduct an annual Colleague Experience Survey to better understand our colleagues’ needs and overall experience at American Express, and in 2023, 91 percent of colleagues who participated in the survey said they would recommend American Express as a great place to work.
To attract and retain the best talent, we strive to offer a compelling value proposition to our colleagues, which represents the ways in which we support our colleagues in four key areas: (1) our culture; (2) career growth and development; (3) rewards and holistic well-being; and (4) diversity, equity and inclusion.
Our Culture
Our culture is built on strong relationships, shared values and purpose and a commitment to back our customers, communities and each other. At the heart of our culture is what we call our Blue Box Values – a set of guiding principles that serve as the foundation for how we operate:
We Do What’s Right
We Embrace Diversity
We Back Our Customers We Stand for Equity and Inclusion
We Make It Great We Win as A Team
We Respect People We Support Communities
Career Growth and Development
We continuously invest in programs, benefits and resources to foster the personal and professional growth of our colleagues. We start with opportunities for colleagues to learn on the job, build cross-functional skills and grow in their careers through a defined, collaborative process for performance management. Colleagues have access to a wide variety of resources: career coaching, mentoring, professional networking, and rotation opportunities, as well as courses on-demand and with classroom-style instruction.
Rewards and Holistic Well-Being
We aim to provide our colleagues with competitive compensation and leading benefits and take a holistic approach to well-being, providing resources that address the physical, financial and mental health of our colleagues. Our financial well-being program, Smart Saving, provides tools and resources to help colleagues build their knowledge and skills for all life stages. We support our colleagues’ physical health and well-being through our corporate wellness program, Healthy Living. We also provide resources and support to increase awareness about mental health among our colleagues through our Healthy Minds Program.
Diversity, Equity and Inclusion
We continue to work to build an inclusive and diverse workplace that values our colleagues’ voices, rewards teamwork, celebrates different points of view and reflects the diversity of the communities in which we operate. As of December 31, 2023, women represented 53.2 percent of our global workforce and Asian, Black/African American and Hispanic/Latinx people represented 20.6 percent, 15.6 percent and 14.3 percent, respectively, of our U.S. workforce based on preliminary data for our 2023 U.S. EEO-1 submission. As of December 31, 2023, 50 percent of our Executive Committee were women or from diverse races and ethnic backgrounds (based on self-identified characteristics). We also regularly review our compensation practices to ensure colleagues in the same job, level and location are compensated fairly regardless of gender globally, and regardless of race and ethnicity in the United States. These reviews consider several factors known to affect compensation, including role, level, tenure, performance and geography. In the instances where a review has found inconsistencies, we have made adjustments. After making these adjustments, we believe we maintained 100 percent pay equity in 2023 for colleagues across genders globally and across races and ethnicities in the United States.
6
Table of Contents
Information About Our Executive Officers
Set forth below, in alphabetical order, is a list of our executive officers as of February 9, 2024, including each executive officer’s principal occupation and employment during the past five years. None of our executive officers has any family relationship with any other executive officer, and none of our executive officers became an officer pursuant to any arrangement or understanding with any other person. Each executive officer has been elected to serve until the next annual election of officers or until his or her successor is elected and qualified. Each officer’s age is indicated by the number in parentheses next to his or her name.
DOUGLAS E. BUCKMINSTER — Vice Chairman
Mr. Buckminster (63) has been Vice Chairman since April 2021. Prior thereto, he had been Group President, Global Consumer Services Group since February 2018.
JEFFREY C. CAMPBELL — Vice Chairman
Mr. Campbell (63) has been Vice Chairman since April 2021. He also served as Chief Financial Officer (CFO) from August 2013 to August 2023.
HOWARD GROSFIELD — President, U.S. Consumer Services
Mr. Grosfield (55) has been President, U.S. Consumer Services since May 2022. Prior thereto, he had been Executive Vice President and General Manager of U.S. Consumer Marketing and Global Premium Services since February 2021 and Executive Vice President and General Manager of U.S. Consumer Marketing Services from January 2016 to February 2021.
MONIQUE HERENA — Chief Colleague Experience Officer
Ms. Herena (52) has been Chief Colleague Experience Officer since April 2019. Ms. Herena joined American Express from BNY Mellon, where she served as the Chief Human Resources Officer and Senior Executive Vice President, Human Resources, Marketing and Communications since 2014.
RAYMOND JOABAR — Group President, Global Merchant and Network Services
Mr. Joabar (58) has been Group President, Global Merchant and Network Services since April 2021. Prior thereto, he had been President, Global Risk and Compliance and Chief Risk Officer since September 2019. He also served as President of International Consumer Services and Global Travel and Lifestyle Services from February 2018 to September 2019.
CHRISTOPHE Y. LE CAILLEC —
Chief Financial Officer
Mr. Le Caillec (58) has been CFO since August 2023. Prior thereto, he had been Deputy CFO since December 2021 and Head of Corporate Planning since February 2019. He also served as Business CFO for the Global Consumer Services Group from May 2016 to February 2019.
RAFAEL MARQUEZ —
President, International Card Services
Mr. Marquez (52) has been President, International Card Services since May 2022. Prior thereto, he had been President, International Consumer Services and Global Loyalty Coalition since September 2019 and Executive Vice President of International Consumer Services Europe, Joint Ventures EMEA and International Member Engagement from November 2015 to September 2019.
ANNA MARRS — Group President, Commercial Services and Credit & Fraud Risk
Ms. Marrs (50) has been Group President, Commercial Services and Credit & Fraud Risk since April 2021. Prior thereto, she had been President, Commercial Services since September 2018.
GLENDA MCNEAL —
Chief Partner Officer
Ms. McNeal (63) has been Chief Partner Officer since February 2024. Prior thereto, she had been President, Enterprise Strategic Partnerships since March 2017.
DAVID NIGRO — Chief Risk Officer
Mr. Nigro (62) has been Chief Risk Officer since April 2021. Prior thereto, he had been Executive Vice President and Chief Credit Officer, Global Consumer Services and Credit and Fraud Risk Capability since April 2018.
DENISE PICKETT — President, Global Services Group
Ms. Pickett (58) has been President, Global Services Group since September 2019. Prior thereto, she had been Chief Risk Officer and President, Global Risk, Banking & Compliance since February 2018.
7
Table of Contents
RAVI RADHAKRISHNAN — Chief Information Officer
Mr. Radhakrishnan (52) has been Chief Information Officer since January 2022. Mr. Radhakrishnan joined American Express from Wells Fargo & Company, where he served as Chief Information Officer for the Commercial Banking and Corporate & Investment Banking businesses since May 2020. Prior thereto, he had been Chief Information Officer, Wholesale, Wealth & Investment Management and Innovation from May 2019 to May 2020. He also served as Enterprise Chief Information Officer from March 2017 to May 2019.
ELIZABETH RUTLEDGE — Chief Marketing Officer
Ms. Rutledge (62) has been Chief Marketing Officer since February 2018.
LAUREEN E. SEEGER — Chief Legal Officer
Ms. Seeger (62) has been Chief Legal Officer since July 2014.
JENNIFER SKYLER — Chief Corporate Affairs Officer
Ms. Skyler (47) has been Chief Corporate Affairs Officer since October 2019. Ms. Skyler joined American Express from WeWork, where she served as Chief Communications Officer from January 2018 to September 2019.
STEPHEN J. SQUERI — Chairman and Chief Executive Officer
Mr. Squeri (64) has been Chairman and Chief Executive Officer since February 2018.
ANRÉ WILLIAMS — Group President, Enterprise Services
Mr. Williams (58) has been Group President, Enterprise Services since April 2021. Prior thereto, he had been Group President, Global Merchant and Network Services since February 2018. Mr. Williams also serves as the Chief Executive Officer of American Express National Bank.
8
Table of Contents
COMPETITION
We compete in the global payments industry with card networks, issuers and acquirers, paper-based transactions (e.g., cash and checks), bank transfer models (e.g., wire transfers and Automated Clearing House, or ACH), as well as evolving and growing alternative mechanisms, systems and products that leverage new technologies, business models and customer relationships to create payment, financing or banking solutions. The payments industry continues to undergo dynamic changes in response to evolving technologies, consumer habits and merchant needs, such as an increased shift to digital payments.
As a card issuer, we compete with financial institutions that issue general-purpose credit and debit cards, as well as businesses that issue private label cards, operate mobile wallets, provide payment services or extend credit. We face intense competition in the premium space and for cobrand relationships, as both card issuer and network competitors have targeted high-spending customers and key business partners with attractive value propositions. We also face competition for partners and other differentiated offerings, such as lounge space in U.S. and global hub airports, restaurant reservation capabilities and other experiential offerings to customers. Our banking products also face strong competition, such as with respect to the rates offered on deposits.
Our global card network competes in the global payments industry with other card networks, including, among others, China UnionPay, Visa, Mastercard, JCB, Discover and Diners Club International (which is owned by Discover). We are the fourth largest general-purpose card network globally based on purchase volume, behind China UnionPay, Visa and Mastercard. In addition to such networks, a range of companies globally, including merchant acquirers, processors and web- and mobile-based payment platforms (e.g., Alipay, PayPal and Venmo), as well as regional payment networks (such as the National Payments Corporation of India), carry out some activities similar to those performed by our GMNS business.
The principal competitive factors that affect the card-issuing, merchant and network businesses include:
• The features, value and quality of the products and services, including customer care, rewards programs, partnerships, travel and lifestyle-related benefits, and digital and mobile services, as well as the costs associated with providing such features and services
• Reputation and brand recognition
• The number, spending characteristics and credit performance of customers
• The quantity, diversity and quality of the establishments where the cards can be used
• The attractiveness of the value proposition to card issuers, merchant acquirers, cardholders, corporate clients and merchants (including the relative cost of using or accepting the products and services, and capabilities such as fraud prevention and data analytics)
• The number and quality of other cards and other forms of payment and financing available to customers
• The success of marketing and promotional campaigns
• The speed of innovation and investment in systems, technologies and product and service offerings
• The nature and quality of expense management tools, electronic payment methods and data capture and reporting capabilities, particularly for business customers
• The security of cardholder, merchant and network partner information
Another aspect of competition is the dynamic and rapid growth of alternative payment and financing mechanisms, systems and products, which include payment facilitators and aggregators, digital payment, open banking and electronic wallet platforms, point-of-sale lenders and buy now, pay later products, real-time settlement and processing systems, financial technology companies, digital currencies developed by both central banks and the private sector, blockchain and similar distributed ledger technologies, prepaid systems and gift cards, and systems linked to customer accounts or that provide payment solutions. Various competitors are integrating more financial services into their product offerings and competitors are seeking to attain the benefits of closed-loop, loyalty and rewards functionalities, such as ours.
9
Table of Contents
In addition to the discussion in this section, see “ Our operating results may materially suffer because of substantial and increasingly intense competition worldwide in the payments industry ” under “Risk Factors” for further discussion of the potential impact of competition on our business, and “ Our business is subject to evolving and comprehensive government regulation and supervision, which could materially adversely affect our results of operations and financial condition ” and “ Legal proceedings regarding provisions in our merchant contracts, including non-discrimination and honor-all-cards provisions, could have a material adverse effect on our business and result in additional litigation and/or arbitrations, changes to our merchant agreements and/or business practices, substantial monetary damages and damage to our reputation and brand ” under “Risk Factors” for a discussion of the potential impact on our ability to compete effectively due to government regulations or if ongoing legal proceedings limit our ability to prevent merchants from engaging in various actions to discriminate against our card products.
10
Table of Contents
SUPERVISION AND REGULATION
Overview
We are subject to evolving and extensive government regulation and supervision in jurisdictions around the world, and the costs of ongoing compliance are substantial. The financial services industry is subject to rigorous scrutiny, high regulatory expectations, a range of regulations and a stringent and unpredictable enforcement environment.
Governmental authorities have focused, and we believe will continue to focus, considerable attention on reviewing compliance by financial services firms and payment systems with laws and regulations, and as a result, we continually work to evolve and improve our risk management framework, governance structures, practices and procedures. Reviews by us and governmental authorities to assess compliance with laws and regulations, as well as our own internal reviews to assess compliance with internal policies, including errors or misconduct by colleagues or third parties or control failures, have resulted in, and are likely to continue to result in, changes to our products, practices and procedures, restitution to our customers and increased costs related to regulatory oversight, supervision and examination. We have also been subject to regulatory actions and may continue to be the subject of such actions, including governmental inquiries, investigations, enforcement proceedings and the imposition of fines or civil money penalties, in the event of noncompliance or alleged noncompliance with laws or regulations. For example, as previously disclosed, we are cooperating with governmental investigations related to certain of our historical sales practices, which are described in more detail in Note 12 to the “Consolidated Financial Statements.” External publicity concerning investigations can increase the scope and scale of those investigations and lead to further regulatory inquiries.
Policymakers around the world continue to propose and adopt new and increasingly complex laws and regulations governing a wide variety of issues that may impact our business or change our operating environment in substantial and unpredictable ways. For example, legislators and regulators in various countries in which we operate have focused on the offering of consumer financial products and the operation of payment networks, resulting in changes to certain practices or pricing of card issuers, merchant acquirers and payment networks, and, in some cases, the establishment of broad and ongoing regulatory oversight regimes.
The following discussion summarizes elements of the extensive regulatory environment in which we operate; it does not purport to be complete or to describe all of the laws or regulations to which we are subject or all possible or proposed changes in laws or regulations that may become applicable to us. See “Operational and Compliance/Legal Risks” under “Risk Factors” for a discussion of the potential impact that changes in applicable law or regulation, and in their interpretation and application by regulatory agencies and other governmental authorities, may have on our business, results of operations and financial condition.
Banking Regulation
American Express entities are subject to banking regulation in the United States and in certain jurisdictions internationally. U.S. federal and state banking laws, regulations and policies extensively regulate the Company, TRS and our U.S. bank subsidiary, American Express National Bank (AENB). For purposes of this Supervision and Regulation section, the “Company” refers only to American Express Company, a bank holding company, and does not include its subsidiaries. Both the Company and TRS are subject to comprehensive consolidated supervision, regulation and examination by the Federal Reserve and AENB is supervised, regulated and examined by the Office of the Comptroller of the Currency (OCC). The Company and its subsidiaries are also subject to the rulemaking, enforcement and examination authority of the Consumer Financial Protection Bureau (CFPB). Banking regulators have broad examination and enforcement power, including the power to impose substantial fines, limit dividends and other capital distributions, restrict operations and acquisitions and require divestitures, any of which could compromise our competitive position. Many aspects of our business also are subject to rigorous regulation by other U.S. federal and state regulatory agencies and by non-U.S. government agencies and regulatory bodies. For example, non-U.S. regulators supervising our international regulated financial institutions use many of the same principles of regulation and supervision that are used by U.S. federal bank regulators.
Activities
The BHC Act generally limits bank holding companies to activities that are considered to be banking activities and certain closely related activities. As noted above, each of the Company and TRS is a bank holding company and each has elected to become a financial holding company, which is authorized to engage in a broader range of financial and related activities. In order to remain eligible for financial holding company status, we must meet certain eligibility requirements. Those requirements include that each of the Company and AENB must be “well capitalized” and “well managed,” and AENB must have received at least a “satisfactory” rating on its most recent assessment under the Community Reinvestment Act of 1977 (the CRA). The Company and TRS engage in various activities permissible only for financial holding companies, including, in particular, providing travel agency
11
Table of Contents
services, acting as a finder and engaging in certain insurance underwriting and agency services. If the Company fails to meet eligibility requirements for financial holding company status, it and its subsidiaries are likely to be barred from engaging in new types of financial activities or making certain types of acquisitions or investments in reliance on its status as a financial holding company, and ultimately could be required to either discontinue the broader range of activities permitted to financial holding companies or divest AENB. In addition, the Company and its subsidiaries are prohibited by law from engaging in practices that regulatory authorities deem unsafe or unsound (which such authorities generally interpret broadly) and regulatory authorities have discretion in determining whether new or modified activities can be conducted in a safe and sound manner.
Acquisitions and Investments
Applicable federal and state laws place limitations on the ability of persons to invest in or acquire control of us without providing notice to or obtaining the approval of one or more of our regulators. In addition, we are subject to banking laws and regulations that limit our investments and acquisitions and, in some cases, subject them to the prior review and approval of our regulators, including the Federal Reserve and the OCC. Federal banking regulators have broad discretion in evaluating proposed acquisitions and investments that are subject to their prior review or approval.
Enhanced Prudential Standards
The Company is subject to the U.S. federal bank regulatory agencies’ rules that tailor the application of enhanced prudential standards to bank holding companies and depository institutions with $100 billion or more in total consolidated assets. Under these rules, each such bank holding company, as well as its bank subsidiaries, is assigned to one of four categories based on its status as a U.S. global systemically important banking organization and five other risk-based indicators: (i) total assets, (ii) cross-jurisdictional activity, (iii) non-bank assets, (iv) off-balance sheet exposure, and (v) weighted short-term wholesale funding, with the most stringent requirements applying to Category I firms and the least stringent requirements applying to Category IV firms. Under these rules, the Company (and its depository institution subsidiary, AENB) is currently subject to Category IV standards. However, changes in the levels of these risk-based indicators at the Company could result in changes to our regulatory tailoring category. Category III firms include those firms with greater than $250 billion but less than $700 billion in total consolidated assets, calculated based on a four-quarter trailing average. Our total consolidated assets were $251 billion and $261 billion as of September 30 and December 31, 2023, respectively, and, accordingly, we anticipate becoming a Category III firm in 2024. Category III firms are subject to heightened capital, liquidity and prudential requirements, single-counterparty credit limits and additional stress tests, which in some cases are subject to a transition period following a financial institution becoming a Category III firm. Moreover, further changes in the risk-based indicators described above, such as if we have $75 billion or more in cross-jurisdictional activity (calculated based on a four-quarter trailing average), could result in us becoming a Category II firm and subject to more stringent capital, liquidity and prudential requirements. Our cross-jurisdictional activity was $67 billion as of December 31, 2023, and the four-quarter trailing average was $60 billion.
Capital and Liquidity Regulation
Capital Rules
The Company and AENB are required to comply with the applicable capital adequacy rules established by federal banking regulators. These rules are intended to ensure that bank holding companies and depository institutions (collectively, banking organizations) have adequate capital given their level of assets and off-balance sheet obligations. The federal banking regulators’ current capital rules (the Capital Rules) implement the Basel Committee on Banking Supervision’s framework for strengthening international capital regulation, known as Basel III. For additional information regarding our capital ratios, see “Consolidated Capital Resources and Liquidity” under “MD&A.”
Under the Capital Rules, banking organizations are required to maintain minimum ratios for Common Equity Tier 1 (CET1 capital), Tier 1 capital (that is, CET1 capital plus additional Tier 1 capital) and Total capital (that is, Tier 1 capital plus Tier 2 capital) to risk-weighted assets. We report our capital adequacy ratios using risk-weighted assets calculated under the standardized approach. Category IV firms such as us and Category III firms are not subject to the advanced approaches capital requirements, whereas Category II firms are subject to the advanced approaches capital requirements under current capital rules, which introduce additional complexities in the methodologies used to calculate risk-weighted assets for purposes of determining capital adequacy ratios.
12
Table of Contents
On July 27, 2023, the U.S. federal bank regulatory agencies issued a notice of proposed rulemaking that would significantly revise U.S. regulatory capital requirements for large banking organizations, including the Company and AENB. The proposed rules would apply a new expanded risk-based approach to calculating risk-based capital ratios, and large banking organizations would be required to calculate their risk-based capital ratios under both (i) the standardized approach and (ii) the expanded risk-based approach and use the lower of the two ratio calculations to determine binding capital constraints under each risk-based capital ratio. The expanded risk-based approach to calculating risk-weighted assets would apply more granular risk-weighting methodologies for credit risk, include a new standardized methodology for operational risk, include new approaches for calculating market and credit valuation adjustment risk and revise the treatment of equity exposures not subject to market risk capital requirements. The new approach to calculating market risk also would apply to calculations under the standardized approach. The methodology for operational risk would include differential treatment of fee and other non-interest revenues as compared to interest income for purposes of determining operational risk-weighted assets. The proposed rules would also include additional credit risk capital requirements for certain “unconditionally cancellable commitments” such as unused portions of committed lines of credit (e.g., credit cards), and would create a proxy methodology to assign capital requirements to credit exposure on products that carry no pre-set spending limits such as charge cards.
Under the proposal, the revisions would become effective on July 1, 2025, subject to a three-year transition period for certain provisions, including phasing in the use of risk-weighted assets under the expanded risk-based approach. While the U.S. federal bank regulatory agencies have solicited comments on the proposal and the rule may not be adopted as proposed, based on a preliminary analysis, we estimate that the increase in our risk-weighted assets under the expanded risk-based approach as currently proposed could consume the capital buffer between our minimum regulatory requirements and our current CET1 risk-based capital ratio. See below for additional information on our minimum CET1 regulatory requirement and “Consolidated Capital Resources and Liquidity — Capital Strategy” under “MD&A” for additional information on our current CET1 risk-based capital ratio. This estimated impact reflects our current understanding of the proposal, the application to our businesses as currently conducted and the current composition of our balance sheet, and therefore does not reflect the impact of any changes we may make in the future as a result of the expanded risk-based approach or otherwise. The ultimate impact will depend on the final rulemaking, future minimum regulatory requirements as well as management decisions regarding our product constructs, capital distributions and target capital levels, and the actual impact of any final rule could materially differ from our current estimate.
In December 2018, federal banking regulators issued a final rule that provides an optional three-year phase-in period for the adverse regulatory capital effects of adopting the Current Expected Credit Loss (CECL) methodology pursuant to new accounting guidance for the recognition of credit losses on certain financial instruments, which became effective January 1, 2020. In August 2020, federal banking regulators issued a final rule that provides an option to delay the estimated impact of the adoption of the CECL methodology on regulatory capital for up to two years, followed by the three-year phase-in period at 25 percent once per year beginning in January 1, 2022. We elected to delay the recognition of $0.7 billion of reduction in regulatory capital from the adoption of the CECL methodology for two years, followed by the three-year phase-in period. As of January 1, 2024, the Company has phased in 75 percent of such amount. See “Critical Accounting Estimates” under “MD&A” for additional information on CECL.
The Company and AENB must each maintain CET1 capital, Tier 1 capital and Total capital ratios of at least 4.5 percent, 6.0 percent and 8.0 percent, respectively. On top of these minimum capital ratios, the Company is subject to a dynamic stress capital buffer (SCB) composed entirely of CET1 capital with a floor of 2.5 percent and AENB is subject to a static 2.5 percent capital conservation buffer (CCB). The SCB equals (i) the difference between a bank holding company’s starting and minimum projected CET1 capital ratios under the supervisory severely adverse scenario under the Federal Reserve’s stress tests described below, plus (ii) one year of planned common stock dividends as a percentage of risk-weighted assets.
On July 27, 2023, the Federal Reserve confirmed the SCB for the Company of 2.5 percent, which remained unchanged from the level announced in August 2022. As a result, the effective minimum ratios for the Company (taking into account the SCB requirement) and AENB (taking into account the CCB requirement) are 7.0 percent, 8.5 percent and 10.5 percent for the CET1 capital, Tier 1 capital and Total capital ratios, respectively. Banking organizations whose ratios of CET1 capital, Tier 1 capital or Total capital to risk-weighted assets are below these effective minimum ratios face constraints on discretionary distributions such as dividends, repurchases and redemptions of capital securities, and executive compensation. A bank holding company’s SCB requirement is effective on October 1 of each year and will remain in effect through September 30 of the following year unless it is reset in connection with resubmission of a capital plan, as discussed below.
Category III firms are also subject to (i) if enacted by the Federal Reserve, a CET1 countercyclical capital buffer requirement of up to an additional 2.5 percent and (ii) a minimum supplementary leverage ratio of 3.0 percent that takes into account both on‐balance sheet and certain off‐balance sheet exposures.
13
Table of Contents
We are also required to comply with minimum leverage ratio requirements. The leverage ratio is the ratio of a banking organization’s Tier 1 capital to its average total consolidated assets (as defined for regulatory purposes). All banking organizations are required to maintain a leverage ratio of at least 4.0 percent.
Liquidity Regulation
The Federal Reserve’s enhanced prudential standards rule includes heightened liquidity and overall risk management requirements. The rule requires the maintenance of a liquidity buffer, consisting of highly liquid assets, that is sufficient to meet projected net outflows for 30 days over a range of liquidity stress scenarios, and a minimum liquidity coverage ratio (LCR) that measures a firm’s high-quality liquid assets to its projected net outflows. A second standard provided for in the Basel III liquidity framework, referred to as the net stable funding ratio (NSFR), requires a minimum amount of longer-term funding based on the assets and activities of banking entities. As a Category IV firm with less than $50 billion in weighted short-term wholesale funding, we are not currently subject to a specific LCR or NSFR requirement; however, as described above, we anticipate becoming a Category III firm in 2024. Category III firms and their depository institution subsidiaries are subject to LCR and NSFR requirements but at a reduced level (that is, at 85 percent of the full requirements), unless they have $75 billion or more in weighted short-term wholesale funding, in which case the full requirements would apply. Category II firms and their depository institution subsidiaries are subject to the full requirements of the LCR and NSFR, as well as a requirement to submit a liquidity monitoring report on a daily (rather than monthly) basis.
Proposed Long-Term Debt Requirements
On August 29, 2023, the U.S. federal bank regulatory agencies issued a notice of proposed rulemaking that, if adopted as proposed, would require covered bank holding companies such as the Company to issue and maintain minimum amounts of eligible external long-term debt with specific terms for purposes of absorbing losses or recapitalizing the covered bank holding company and its operating subsidiaries. The notice of proposed rulemaking also proposed requiring certain insured depository institutions that have at least $100 billion in consolidated assets, such as AENB, to maintain minimum amounts of eligible internal long-term debt for purposes of absorbing losses or recapitalizing the insured depository institution.
Stress Testing and Capital Planning
Under the Federal Reserve’s regulations, the Company is subject to supervisory stress testing requirements that are designed to evaluate whether a bank holding company has sufficient capital on a total consolidated basis to absorb losses and support operations under adverse economic conditions. As part of the Comprehensive Capital Analysis and Review (CCAR), the Federal Reserve uses pro-forma capital positions and ratios under such stress scenarios to determine the size of the SCB for each CCAR participating firm.
Because the Company is currently a Category IV firm, it is required to participate in the supervisory stress tests every other year and is subject to the Federal Reserve’s supervisory stress tests in 2024. The Company is required to develop and submit to the Federal Reserve an annual capital plan on or before April 5 of each year.
For Category IV firms, the portion of the SCB based on the Federal Reserve’s supervisory stress tests is calculated every other year. During a year in which a Category IV firm does not undergo a supervisory stress test, the firm receives an updated SCB that reflects the firm’s updated planned common stock dividends. A Category IV firm can elect to participate in the supervisory stress test in an “off year” and consequently receive an updated SCB.
We may be required to revise and resubmit our capital plan following certain events or developments, such as a significant acquisition or an event that could result in a material change in our risk profile or financial condition. If we are required to resubmit our capital plan, we must receive prior approval from the Federal Reserve for any capital distributions (including common stock dividend payments and share repurchases), other than a capital distribution on a newly issued capital instrument.
Category III firms are subject to annual supervisory stress tests, with the SCB calculated each year, and must conduct company‐run stress tests every other year (commonly referred to as Dodd‐Frank Act Stress Tests or “DFASTs”). Category II firms must conduct company-run stress tests on an annual basis rather than every other year.
14
Table of Contents
Dividends and Other Capital Distributions
The Company and TRS, as well as AENB and the Company’s insurance and other regulated subsidiaries, are limited in their ability to pay dividends by statutes, regulations and supervisory policy.
Common stock dividend payments and share repurchases by the Company are subject to the oversight of the Federal Reserve, as described above. The Company will be subject to limitations and restrictions on capital distributions if, among other things, (i) the Company’s regulatory capital ratios do not satisfy applicable minimum requirements and buffers or (ii) the Company is required to resubmit its capital plan.
In general, federal laws and regulations prohibit, without first obtaining the OCC’s approval, AENB from making dividend distributions to TRS, if such distributions are not paid out of available recent earnings or would cause AENB to fail to meet capital adequacy standards. In addition to specific limitations on the dividends AENB can pay to TRS, federal banking regulators have authority to prohibit or limit the payment of a dividend if, in the banking regulator’s opinion, payment of a dividend would constitute an unsafe or unsound practice in light of the financial condition of the institution.
Prompt Corrective Action
The Federal Deposit Insurance Act (FDIA) requires, among other things, that federal banking regulators take prompt corrective action in respect of depository institutions insured by the FDIC (such as AENB) that do not meet minimum capital requirements. The FDIA establishes five capital categories for FDIC-insured banks: well capitalized, adequately capitalized, undercapitalized, significantly undercapitalized and critically undercapitalized. The FDIA imposes progressively more restrictive constraints on operations, management and capital distributions, depending on the capital category in which an institution is classified. In order to be considered “well capitalized,” AENB must maintain CET1 capital, Tier 1 capital, Total capital and Tier 1 leverage ratios of 6.5 percent, 8.0 percent, 10.0 percent and 5.0 percent, respectively.
Under the FDIA, AENB could be prohibited from accepting brokered deposits (i.e., deposits raised through third-party brokerage networks) or offering interest rates on any deposits significantly higher than the prevailing rate in its normal market area or nationally (depending upon where the deposits are solicited), unless (1) it is well capitalized or (2) it is adequately capitalized and receives a waiver from the FDIC. A portion of our outstanding U.S. retail deposits are considered brokered deposits for bank regulatory purposes. If a federal regulator determines that we are in an unsafe or unsound condition or that we are engaging in unsafe or unsound banking practices, the regulator may reclassify our capital category or otherwise place restrictions on our ability to accept or solicit brokered deposits.
Resolution Planning
Certain bank holding companies are required to submit resolution plans to the Federal Reserve and FDIC providing for the company’s strategy for rapid and orderly resolution in the event of its material financial distress or failure. However, Category IV firms are not required to submit a holding company resolution plan, while Category III firms are required to submit a holding company resolution plan every three years.
AENB continues to be required to prepare and provide a separate resolution plan to the FDIC that would enable the FDIC, as receiver, to effectively resolve AENB under the FDIA in the event of failure. Under the FDIC’s rule and its accompanying June 2021 statement on resolution plans for insured depository institutions, insured depository institutions with $100 billion or more in assets, such as AENB, are required to submit resolution plans on a three-year cycle. AENB submitted its most recent resolution plan in December 2022, as required.
On August 29, 2023, the FDIC issued a notice of proposed rulemaking that would require insured depository institutions with $100 billion or more in assets, including AENB, to submit full resolution plans every two years with interim supplements in non-submission years. Under the proposal, resolution plans would be subject to more stringent standards with respect to their assumptions and content, as well as enhanced credibility standards for the FDIC’s evaluation of resolution plans and expanded expectations regarding engagement and capabilities testing.
Orderly Liquidation Authority
The Company could become subject to the Orderly Liquidation Authority (OLA), a resolution regime under which the Treasury Secretary may appoint the FDIC as receiver to liquidate a systemically important financial institution, if the Company is in danger of default and is determined to present a systemic risk to U.S. financial stability. As under the FDIC resolution model, under the OLA, the FDIC has broad power as receiver. Substantial differences exist, however, between the OLA and the U.S. Bankruptcy Code, including the right of the FDIC under the OLA to disregard the strict priority of creditor claims in limited circumstances, the use of an administrative claims procedure to determine creditor claims (as opposed to the judicial procedure used in bankruptcy proceedings), and the right of the FDIC to transfer claims to a “bridge” entity.
15
Table of Contents
The FDIC has developed a strategy under OLA, referred to as the “single point of entry” or “SPOE” strategy, under which the FDIC would resolve a failed financial holding company by transferring its assets (including shares of its operating subsidiaries) and, potentially, very limited liabilities to a “bridge” holding company; utilize the resources of the failed financial holding company to recapitalize the operating subsidiaries; and satisfy the claims of unsecured creditors of the failed financial holding company and other claimants in the receivership by delivering securities of one or more new financial companies that would emerge from the bridge holding company. Under this strategy, management of the failed financial holding company would be replaced and its shareholders and creditors would bear the losses resulting from the failure.
FDIC Powers upon Insolvency of AENB
If the FDIC is appointed the conservator or receiver of AENB, the FDIC has the power to: (1) transfer any of AENB’s assets and liabilities to a new obligor without the approval of AENB’s creditors; (2) enforce the terms of AENB’s contracts pursuant to their terms; or (3) repudiate or disaffirm any contract or lease to which AENB is a party, the performance of which is determined by the FDIC to be burdensome and the disaffirmation or repudiation of which is determined by the FDIC to promote the orderly administration of AENB. In addition, the claims of holders of U.S. deposit liabilities and certain claims for administrative expenses of the FDIC against AENB would be afforded priority over other general unsecured claims against AENB, including claims of debt holders and depositors in non-U.S. offices, in the liquidation or other resolution of AENB. As a result, regardless of whether the FDIC ever sought to repudiate any debt obligations of AENB, the debt holders and depositors in non-U.S. offices would be treated differently from, and could receive substantially less, if anything, than the depositors in the U.S. offices of AENB.
Other Banking Regulations
Source of Strength
The Company is required to act as a source of financial and managerial strength to its U.S. bank subsidiary, AENB, and may be required to commit capital and financial resources to support AENB. Such support may be required at times when, absent this requirement, the Company otherwise might determine not to provide it. Capital loans by the Company to AENB are subordinate in right of payment to deposits and to certain other indebtedness of AENB. In the event of the Company’s bankruptcy, any commitment by the Company to a federal banking regulator to maintain the capital of AENB will be assumed by the bankruptcy trustee and entitled to a priority of payment.
Transactions Between AENB and its Affiliates
Certain transactions (including loans and credit extensions from AENB) between AENB and its affiliates (including the Company, TRS and their other subsidiaries) are subject to quantitative and qualitative limitations, collateral requirements and other restrictions imposed by statute and regulation. Transactions subject to these restrictions are generally required to be made on an arm’s-length basis.
FDIC Deposit Insurance and Insurance Assessments
AENB accepts deposits that are insured by the FDIC up to the applicable limits. Under the FDIA, the FDIC may terminate the insurance of an institution’s deposits upon a finding that the institution has engaged in unsafe or unsound practices; is in an unsafe or unsound condition to continue operations; or has violated any applicable law, regulation, rule, order or condition imposed by the FDIC. We do not know of any practice, condition or violation that would lead to termination of deposit insurance at AENB. The FDIC’s deposit insurance fund is funded by assessments on insured depository institutions, including AENB, which are subject to adjustment by the FDIC. On November 16, 2023, the FDIC adopted a final rule imposing a special assessment to recover the cost associated with protecting uninsured depositors in connection with the failures of two U.S. banks in March 2023. The special assessment will total approximately $53 million for us (which amount was recognized as an expense in the fourth quarter of 2023), and will be paid over eight quarterly assessment periods, with the first quarterly assessment period beginning on January 1, 2024.
Community Reinvestment Act
AENB is subject to the CRA, which imposes affirmative, ongoing obligations on depository institutions to meet the credit needs of their local communities, including low- and moderate-income neighborhoods, consistent with the safe and sound operation of the institution. AENB is currently designated a “limited purpose bank” under CRA regulations. In October 2023 , the U.S. federal bank
16
Table of Contents
regulatory agencies adopted a final rule that makes extensive revisions to the CRA regulatory framework, including to the definition of “limited purpose bank,” which could impact AENB and alter its CRA compliance obligations. Certain provisions of the final rule become effective on April 1, 2024, but the majority of the final rule’s operative provisions (including the revisions to the definition of “limited purpose bank”) become effective on January 1, 2026, with additional data collection and reporting requirements becoming effective on January 1, 2027. We are currently evaluating the impact of the final rule but expect that it will increase AENB’s obligations and compliance costs.
Climate Risk Management
The U.S. federal bank regulatory agencies have recently increased their focus on climate risk-related supervision. For example, on October 24, 2023, the U.S. federal bank regulatory agencies issued “Principles for Climate-Related Financial Risk Management for Large Financial Institutions.” The principles would apply to financial institutions with more than $100 billion in total consolidated assets, like the Company and AENB, and are broadly designed to provide a high-level framework for the safe and sound management of exposures to climate-related financial risks consistent with existing U.S. federal bank regulatory agencies’ rules and guidance. The principles outline six key aspects of climate-related financial risk management: governance; policies, procedures and limits; strategic planning; risk management; data, risk measurement and reporting; and scenario analysis. In addition, the principles offer risk assessment guidance for incorporating climate-related financial risks in various traditional risk categories. It is too early to determine what other regulations and policies may be adopted or apply to the Company and AENB and the effect of any such regulations or policies on the Company and AENB.
Consumer Financial Products Regulation
Our consumer-oriented activities are subject to regulation and supervision in the United States and internationally. In the United States, our marketing, sale and servicing of consumer financial products and our compliance with certain federal consumer financial laws are supervised and examined by the CFPB, which has broad rulemaking and enforcement authority over providers of credit, savings and payment services and products, and authority to prevent “unfair, deceptive or abusive” acts or practices. The CFPB has the authority to write regulations under federal consumer financial protection laws, to enforce those laws and to examine for compliance. It is also authorized to collect fines and require consumer restitution in the event of violations, engage in consumer financial education, track consumer complaints, request data and promote the availability of financial services to underserved consumers and communities. In addition, a number of U.S. states have significant consumer credit protection, disclosure and other laws (in certain cases more stringent than U.S. federal laws). U.S. federal law also regulates abusive debt collection practices, which, along with bankruptcy and debtor relief laws, can affect our ability to collect amounts owed to us or subject us to regulatory scrutiny.
On February 1, 2023, the CFPB issued a proposed rule to lower the safe harbor amount that would be considered, by regulation, to be “reasonable and proportional” to the costs incurred by credit card issuers for late payments. The proposed rule would also eliminate the annual inflation adjustment for such safe harbor amount and prohibit late fee amounts above 25 percent of the consumer’s required minimum payment.
On March 30, 2023, the CFPB adopted a final rule requiring covered financial institutions, such as us, to collect and report data to the CFPB regarding certain small business credit applications. Based on our small business credit transaction volume, we will be required to comply with this rule by October 1, 2024, subject to the outcome of litigation over the final rule.
On October 19, 2023, the CFPB issued a proposed rule on personal financial data rights that the CFPB stated would accelerate a shift toward open banking. The proposed rule would require data providers to provide consumers and consumer-authorized third parties with access to consumers’ financial data free of charge and would also impose requirements on authorized third parties, as well as data aggregators that facilitate access to consumers’ financial data. If the proposed rule is adopted as proposed, it (and other open banking initiatives) has the potential to change the competitive landscape, which would present new challenges and opportunities to our business model.
We are also regulated in the United States under the “money transmitter” or “sale of check” laws in effect in most states. In addition, we are required by the laws of many states to comply with unclaimed and abandoned property laws, under which we must pay to states the face amount of any Travelers Cheque or prepaid card that is uncashed or unredeemed after a period of time depending on the type of product. Additionally, we are regulated under insurance laws in the United States and other countries where we offer insurance services.
In countries outside the United States, regulators continue to focus on a number of key areas impacting our card-issuing businesses, particularly consumer protection (such as in the European Union (EU), the United Kingdom and Canada) and responsible lending (such as in Australia, Mexico, New Zealand and Singapore), with increasing importance on and attention to customers and outcomes rather than just ensuring compliance with local rules and regulations. Regulators’ expectations of firms in relation to their compliance, risk and control frameworks continue to increase and regulators are placing significant emphasis on a firm’s systems and controls relating to the identification and resolution of issues.
17
Table of Contents
Payments Regulation
Legislators and regulators in various countries in which we operate have focused on the operation of card networks, including through enforcement actions, legislation and regulations to change certain practices or pricing of card issuers, merchant acquirers and payment networks, and, in some cases, to establish broad regulatory regimes for payment systems.
The EU, Australia, Canada and other jurisdictions have focused on interchange fees (that is, the fee paid by the bankcard merchant acquirer to the card issuer in payment networks like Visa and Mastercard), as well as the rules, contract terms and practices governing merchant card acceptance. Regulation and other governmental actions relating to pricing or practices could affect all networks directly or indirectly, as well as adversely impact consumers and merchants. Among other things, regulation of bankcard fees has negatively impacted and may continue to negatively impact the discount revenue we earn, including as a result of downward pressure on our merchant discount rates from decreases in competitor pricing in connection with caps on interchange fees. In some cases, regulations also extend to certain aspects of our business, such as network and cobrand arrangements or the terms of card acceptance for merchants, and we have exited our network businesses in the EU and Australia as a result of regulation in those jurisdictions, for example. There is uncertainty as to when or how interchange fee caps and other provisions of the EU payments legislation might apply when we work with cobrand partners and agents in the EU. In a ruling issued on February 7, 2018, the EU Court of Justice confirmed the validity of fee capping and other provisions in circumstances where three-party networks issue cards with a cobrand partner or through an agent, although the ruling provided only limited guidance as to when or how the provisions might apply in such circumstances and remains subject to differing interpretations by regulators and participants in cobrand arrangements. On August 29, 2023, the Dutch Trade and Industry Appeals Tribunal referred questions to the EU Court of Justice on the interpretation of the application of the interchange fee caps in connection with an administrative proceeding by the Netherlands Authority for Consumers and Markets regarding our cobrand relationship with KLM Royal Dutch Airlines. Given differing interpretations by regulators and participants in cobrand arrangements, we are subject to regulatory action, penalties and the possibility we will not be able to maintain our existing cobrand and agent relationships in the EU. See “ Our business is subject to evolving and comprehensive government regulation and supervision, which could materially adversely affect our results of operations and financial condition ” under “Risk Factors.”
In various countries, such as certain Member States in the EU, Australia and Canada (other than in Quebec), merchants are permitted by law to surcharge card purchases. In addition, the laws of a number of states in the United States that prohibit surcharging have been overturned and certain states have passed or are considering laws to permit surcharging by merchants. Surcharging is an adverse customer experience and could have a material adverse effect on us, particularly where it only or disproportionately impacts credit card usage or card usage generally, our Card Members or our business. In addition, other steering or differential acceptance practices that are permitted by regulation in some jurisdictions could also have a material adverse effect on us. See “ Surcharging or steering by merchants could materially adversely affect our business and results of operations ” under “Risk Factors.”
In some countries, governments have established regulatory regimes that require international card networks to be locally licensed and/or to localize aspects of their operations. For example, the Reserve Bank of India, which has broad power under the Payment and Settlement Systems Act, 2007 to regulate the membership and operations of card networks, issued a mandate requiring payment systems operators in India to store certain payments data locally. In 2021, it imposed restrictions on American Express Banking Corp. from engaging in certain card issuing activities in India, which were lifted in 2022 following significant investment in technology, infrastructure and resources to comply with the regulation. The development and enforcement of these and other similar laws, regulations and policies may adversely affect our ability to compete effectively and maintain and extend our global network.
Privacy, Data Protection, Data Governance, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data governance and information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable privacy, data protection, data governance and information security and cybersecurity laws and requirements, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny.
Our regulators are increasingly focused on ensuring that our privacy, data protection, data governance and cybersecurity-related policies and practices are adequate to inform customers of our data collection, use, sharing and/or security practices, to provide them with choices, if required, about how we use and share their information, and to appropriately safeguard their personal information and account access. Regulators are also focused on data management, technology infrastructure and architecture, technology operations, resiliency and business continuity, and third-party risk management policies and practices.
18
Table of Contents
In the United States, certain of our businesses are subject to the privacy, disclosure and safeguarding provisions of the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations and guidance. Among other things, GLBA imposes certain limitations on our ability to share consumers’ nonpublic personal information with nonaffiliated third parties and requires us to develop, implement and maintain a written comprehensive information security program containing safeguards that are appropriate to the size and complexity of our business, the nature and scope of our activities and the sensitivity of customer information that we process. We also have expanded privacy-related obligations with respect to California residents who are not covered by GLBA, pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020. Various regulators and other U.S. states and territories are considering similar requirements or have adopted laws, rules and regulations pertaining to privacy and/or information security and cybersecurity that may be more stringent and/or expansive than federal requirements.
We are also subject to certain privacy, data protection, data governance and information security and cybersecurity laws in other countries in which we operate (including Member States in the EU, Australia, Canada, China, Japan, Hong Kong, India, Indonesia, Mexico, Singapore, Thailand and the United Kingdom), some of which are more stringent and/or expansive than those in the United States and some of which may conflict with each other. Some jurisdictions have instituted or are considering instituting requirements that make it onerous to transfer personal data to other jurisdictions, and certain countries require in-country data processing and/or in-country storage of data. Compliance with such laws results in higher technology, administrative and other costs for us, could limit our ability to optimize the use of our closed-loop data, and could require use of local technology services. Some of these laws also require us to provide foreign governments and other third parties broader access to our data and intellectual property. Data breach and operational outage notification laws or regulatory activities to encourage such notifications and regulatory activity and laws around resiliency, business continuity and third-party risk management are also becoming more prevalent in jurisdictions outside the United States in which we operate.
The EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR impose legal and compliance obligations on companies that process personal data of individuals in the EU and UK, irrespective of the geographical location of the company, with the potential for significant fines for non-compliance (up to 4 percent of total annual worldwide revenue). These laws include, among other things, a requirement for prompt notice of data breaches, in certain circumstances, to affected individuals and supervisory authorities and restrictions on the cross-border transfers of EU or UK personal data. We rely on a variety of compliant transfer mechanisms to transfer this personal data, including the use of binding corporate rules and standard contractual clauses. In 2023, the EU and UK regulators approved the EU-U.S. Data Privacy Framework and the UK Data Bridge, enabling easier transfers of EU and UK personal data to participating companies in the United States. We are also subject to certain data protection laws in Member States in the EU, which may be more stringent than the EU GDPR. Our data protection programs have become the subject of heightened scrutiny in certain Member States in the EU and we continue to make changes to our privacy practices and data governance to comply with these requirements.
Anti-Money Laundering, Countering the Financing of Terrorism, Economic Sanctions and Anti-Corruption Compliance
We are subject to significant supervision and regulation, and an increasingly stringent enforcement environment, with respect to compliance with anti-money laundering (AML), countering the financing of terrorism (CFT), sanctions and anti-corruption laws and regulations. Failure to maintain and implement adequate programs and policies and procedures for AML/CFT, sanctions and anti-corruption compliance could have material financial, legal and reputational consequences.
Anti-Money Laundering and Countering the Financing of Terrorism
We are subject to a significant number of AML/CFT laws and regulations globally.
In the United States, the majority of AML/CFT requirements are derived from the Currency and Foreign Transactions Reporting Act and the accompanying regulations issued by the U.S. Department of the Treasury (collectively referred to as the Bank Secrecy Act), as amended by the USA PATRIOT Act of 2001 (the Patriot Act). The Anti-Money Laundering Act of 2020 (the AMLA), enacted in January 2021, amended the Bank Secrecy Act and is intended to comprehensively reform and modernize U.S. AML/CFT laws. Many of the statutory provisions in the AMLA will require additional rulemakings, reports and other measures, and the impact of the AMLA will depend on, among other things, rulemaking and implementation guidance.
In Europe, AML/CFT requirements are largely the result of countries transposing the 5th and 6th EU Anti-Money Laundering Directives (and preceding EU Anti-Money Laundering Directives) into local laws and regulations. Numerous other countries have also enacted or proposed new or enhanced AML/CFT legislation and regulations applicable to American Express.
Among other things, these laws and regulations generally require us to establish AML/CFT programs that meet certain standards, including policies and procedures to collect information from and verify the identities of our customers, and to monitor for and report suspicious transactions, in addition to other information gathering and recordkeeping requirements. Our AML/CFT
19
Table of Contents
programs have become the subject of heightened scrutiny in some countries, including certain Member States in the EU. Any errors, failures or delays in complying with AML/CFT laws, perceived deficiencies in our AML/CFT programs or association of our business with money laundering, terrorist financing, tax fraud or other illicit activity can give rise to significant supervisory, criminal and civil proceedings and lawsuits, which could result in significant penalties and forfeiture of assets, loss of licenses or restrictions on business activities, or other enforcement actions.
Economic Sanctions
National governments and international bodies, such as the United Nations and the EU, have imposed economic sanctions against individuals, entities, vessels, governments and countries that endanger their interests or violate international norms of behavior. Sanctions have been used to advance a range of foreign policy goals, including conflict resolution, counterterrorism, counternarcotics and promotion of democracy and human rights, among other national and international interests. Failure to comply with such requirements could subject us to serious legal and reputational consequences, including criminal penalties.
The United States has imposed economic sanctions that affect transactions involving targeted jurisdictions, parties or activities. The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) administers most U.S. sanctions. OFAC regulations prohibit U.S. persons from engaging in financial transactions with or relating to, or other dealings involving, a targeted individual, entity, vessel, government or country without a license or other authorization and require U.S. persons to block property and property interests of parties on OFAC’s Specially Designated Nationals and Blocked Persons List and entities owned 50 percent or more by one or more Specially Designated Nationals. Blocked property (e.g., bank deposits or other financial assets) cannot be paid out, withdrawn, set off or transferred in any manner without a license from OFAC. Regulatory authorities in other international jurisdictions, such as the United Kingdom and Member States in the EU, administer similar programs to U.S. sanction programs.
We maintain a global sanctions compliance program designed to meet the requirements of applicable sanctions regimes.
Anti-Corruption
We are subject to complex anti-corruption laws and regulations, including the U.S. Foreign Corrupt Practices Act (the FCPA), the UK Bribery Act and other laws that prohibit the making or offering of improper payments. The FCPA makes it illegal to corruptly offer or provide anything of value to foreign government officials, political parties or political party officials for the purpose of obtaining or retaining business or an improper advantage. The FCPA also requires us to strictly comply with certain accounting and internal controls standards. The UK Bribery Act also prohibits commercial bribery and the receipt of a bribe, and makes it a corporate offense to fail to prevent bribery by an associated person, in addition to prohibiting improper payments to foreign government officials. Failure by us or our colleagues, contractors or agents to comply with the FCPA, the UK Bribery Act and other similar laws can expose us and/or individual colleagues to investigation, prosecution and potentially severe criminal and civil penalties.
Compensation Practices
Our compensation practices are subject to oversight by the Federal Reserve and the OCC. The federal banking regulators’ guidance on sound incentive compensation practices sets forth three key principles for incentive compensation arrangements that are designed to help ensure that incentive compensation plans do not encourage imprudent risk-taking and are consistent with the safety and soundness of banking organizations. The three principles provide that a banking organization’s incentive compensation arrangements should (1) provide incentives that appropriately balance risk and financial results in a manner that does not encourage employees to expose their organizations to imprudent risks, (2) be compatible with effective internal controls and risk management and (3) be supported by strong corporate governance, including active and effective oversight by the organization’s board of directors. Any deficiencies in our compensation practices that are identified by the banking regulators in connection with their review of our compensation practices may be incorporated into our supervisory ratings, which can affect our ability to make acquisitions or perform other actions. Enforcement actions may be taken against us if our incentive compensation arrangements or related risk-management control or governance processes are determined to pose a risk to our safety and soundness, and we have not taken prompt and effective measures to correct the deficiencies.
The Dodd-Frank Act requires U.S. financial regulators, including the Federal Reserve and the Securities and Exchange Commission (SEC), to adopt rules on incentive-based payment arrangements at specified regulated entities having at least $1 billion in total assets. In 2016, the federal banking regulators, the SEC, the Federal Housing Finance Agency and the National Credit Union Administration proposed revised rules on incentive-based compensation practices, which have not yet been finalized. If these or other regulations are adopted in a form similar to what has been proposed, they will impose limitations on the manner in which we may structure compensation for our colleagues, which could adversely affect our ability to hire, retain and motivate key colleagues.
20
Table of Contents
ADDITIONAL INFORMATION
We maintain an Investor Relations website at http://ir.americanexpress.com. We make available free of charge, on or through this website, our annual, quarterly and current reports and any amendments to those reports as soon as reasonably practicable following the time they are electronically filed with or furnished to the SEC.
In addition, we routinely post financial and other information, some of which could be material to investors, on our Investor Relations website. Information regarding our corporate sustainability initiatives, including our Environmental, Social and Governance reports, are available on the Corporate Sustainability section of our website at http://about.americanexpress.com/corporate-sustainability.
The content of any of our websites referred to in this report is not incorporated by reference into this report or any other report filed with or furnished to the SEC. We have included such website addresses only as inactive textual references and do not intend them to be active links.
You can find certain statistical disclosures required of bank holding companies starting on page A-1, which are incorporated herein by reference.
Our business as a whole has not experienced significant seasonal fluctuations, although network volumes tend to be moderately higher in the fourth quarter than in other quarters. As a result, the amount of Card Member loans and receivables outstanding tend to be moderately higher during that quarter. Additionally, we tend to have a higher proportion of retail-related billed business in the fourth quarter, which on average has a slightly lower merchant discount rate.
21
Table of Contents