The action and its completed supervisory phase
The OCC announced an $80 million civil money penalty against Capital One, N.A. and Capital One Bank (USA), N.A. on August 6, 2020. It cited ineffective risk assessment before a substantial move to public-cloud operations and delayed correction of deficiencies. The announcement also credited customer notification and remediation efforts. The money was payable to the Treasury, rather than described as a customer compensation fund. [1]
The related corrective was dated August 5, 2020. On August 31, 2022, the OCC terminated that order, stating that its continued existence was no longer required for the banks’ safety, soundness and legal compliance. An account written as of October 4, 2026 therefore cannot describe the 2020 corrective order as still outstanding. Termination did not rescind the separate monetary assessment or erase the historical findings. [2][4]
What the OCC actually found
The located the initial risk-assessment problem around 2015. It identified deficiencies in network security, data-loss prevention and handling alerts, alongside weaknesses in internal audit and board follow-through. The OCC found noncompliance with the information-security standards in 12 CFR Part 30, Appendix B, and unsafe or unsound practices. The banks neither admitted nor denied those findings. These were findings in an agreed supervisory order, not a criminal conviction. [2]
The companion penalty order imposed one total $80 million amount on the two named banks. It included waivers of administrative and judicial challenge and characterized the resolution as settlement of the contemplated penalty proceeding. Counting each named bank as separately owing $80 million would double the stated assessment. Nor does the penalty quantify total customer harm, all litigation exposure or the cost of the technology program. [3]
Why migration changes the risk boundary
Moving computing operations changes more than the physical location of servers. A bank can obtain infrastructure as a service while retaining responsibility for the applications, access choices, data classification and operating decisions that sit on it. The financial question is how the complete service works, rather than whether the underlying equipment is owned or rented.
This distinction helps explain the action’s focus. A system can be highly available and capable of processing customer transactions while still exposing information through inappropriate permissions or weak data controls. Availability, confidentiality and accuracy are separate dimensions of performance. A successful migration measured by uptime and processing speed does not alone establish that all three improved.
Cloud economics can make the distinction more consequential. Elastic capacity reduces the need to provision hardware for peak demand. It can also make it easier to create new data stores, grant new service permissions and replicate information across environments. Each additional configuration can be useful while changing the set of people or processes able to reach customer information. The benefit and the exposure can arise from the same flexibility.
These are analytical implications of the operating model, not findings that every such failure occurred at Capital One. The OCC’s record supports its specific conclusions. It does not establish a general prohibition on cloud computing, identify every third-party design choice as defective or prove that an on-premises alternative would have prevented the incident.
The cost of a control is different from the cost of a breach
Security spending is incurred before the size and timing of a loss are known. Remediation spending follows a discovered problem and may be accelerated because an operating system cannot simply be switched off. Customer support, investigation, legal work and rebuilding affected controls can therefore consume resources on different timetables.
A hypothetical migration that saves $20 million annually but requires $30 million in one-time control redesign is not necessarily uneconomic. Over three years the undiscounted operating savings would be $60 million before the redesign cost. But that comparison is incomplete if it excludes residual incident risk, transition expenses or the value of faster product delivery. These figures illustrate the accounting boundary; they are not Capital One’s cost estimates.
An enforcement penalty creates another category. The $80 million assessment is observable, but it is not an estimate of the expected loss the bank should have assigned before migration. A realized event is one outcome, while an ex-ante risk assessment concerns a distribution of possible outcomes. Confusing the two can make any eventual penalty appear either trivial beside a large balance sheet or enormous beside an isolated project budget.
The same distinction applies to customer experience. A person whose information is exposed can face monitoring costs and uncertainty even if no immediate unauthorized transaction occurs. Conversely, the number of records involved is not a count of proven identity-theft losses. Careful case analysis separates information exposure, fraud, reimbursement, penalties and private settlements instead of treating them as equivalent amounts.
Governance as a chain of evidence
The OCC’s findings implicate several stages of decision-making, not merely the employee who last changed a technical setting. The analytical sequence runs from identifying a new environment’s risks to testing controls, reporting weaknesses and securing resources to close them. Each stage produces evidence for a different decision. A completed audit inventory is not the same thing as a tested conclusion that the risks are controlled.
For that reason, a board can receive many reports without receiving a usable picture of unresolved exposure. A list of projects marked complete can coexist with exceptions that remain open. A technology team can close a ticket while the underlying business process still routes sensitive information in an unintended way. These possibilities explain the relevance of assurance and escalation without adding unsupported allegations to the bank’s record.
The public termination provides an observable endpoint for this particular supervisory intervention. It does not give outsiders access to all the remediation tests or supervisory judgments behind that decision. Its evidentiary value is specific: the OCC formally ended the identified order. It is not an agency guarantee that no future cyber incident could occur.
What remains useful in 2026
Capital One’s 2022 annual report separately disclosed the August 31 termination. That issuer disclosure corroborates the date but is not the authority that ended the order; the OCC’s signed termination is. The report also discussed cybersecurity risk as continuing business exposure, illustrating why a closed enforcement matter and continuing operational risk can coexist. [5]
The October 4, 2026 review located no later official reinstatement or reversal of this specific action. Other Capital One matters, merger conditions or data-breach litigation concern different obligations and cannot be silently attached to this order. The lasting contribution of the case is the separation of a technology choice from the risk assessment and accountability needed to operate it, together with an accurately dated conclusion to the corrective order.
Sources
- OCC — $80 million penalty announcement, August 6, 2020Official releaseBack to text: ↑
- OCC — corrective consent order 2020-037, August 5, 2020Official source · PDFBack to text: ↑1↑2
- OCC — civil money penalty order 2020-036, August 5, 2020Official source · PDFBack to text: ↑
- OCC — termination 2022-037, August 31, 2022Official source · PDFBack to text: ↑
- Capital One — 2022 annual report, filed 2023Filing / reportBack to text: ↑