Compliance frameworks, security audits, and quality certifications this company maintains.
American Express is a PCI DSS Level 1 certified payment brand and card network, maintaining the highest tier of Payment Card Industry Data Security Standard compliance across its global card processing, issuing, and merchant network operations to protect cardholder data at scale.
American Express's digital platforms, mobile applications, and data management systems maintain SOC 2 Type II certification, ensuring that cardholder account data, transaction records, and Membership Rewards points balances are managed to the highest operational security standards.
American Express holds ISO 27001 certification for its information security management system, governing how Amex protects cardholder data, employee information, and business-critical financial system assets across its global technology infrastructure.
American Express is fully compliant with the EU General Data Protection Regulation across its European card issuing and merchant acquiring operations, governing how Amex collects, processes, and stores personal data of European cardholders and merchant partners.
American Express complies with the California Consumer Privacy Act, providing Amex cardholders in California with rights to access, delete, and opt-out of sale of their personal financial and behavioral data collected through Amex card usage and digital platforms.
American Express Financial Advisors and its broker-dealer subsidiaries operate in compliance with FINRA rules governing the sale of financial products, requiring American Express advisors and registered representatives to meet suitability, disclosure, and supervision standards.
Regulatory
Bank Secrecy Act / AML
CompliantAmerican Express maintains a comprehensive Bank Secrecy Act and Anti-Money Laundering compliance program across its card, banking, and network operations, including customer due diligence, suspicious activity reporting, and OFAC sanctions screening for all card transactions.
Regulatory
TRUTH IN LENDING (Reg Z)
CompliantAmerican Express complies with Regulation Z (Truth in Lending Act) disclosure requirements for all Amex revolving credit card products, ensuring cardholders receive accurate APR, fee, and credit terms disclosures in card agreements and monthly statements.
American Express has adopted ISO 20022 financial messaging standards for its payment network and corporate payment operations, enabling richer payment data exchange with banking partners and improving reconciliation capabilities for Global Commercial Services enterprise customers.
American Express publishes Task Force on Climate-related Financial Disclosures (TCFD)-aligned climate risk reporting, disclosing how physical and transition climate risks affect Amex's business model, investment portfolio, and supply chain financing activities.