Compliance
This page summarises the frameworks we operate under. It is written to be readable rather than exhaustive — where a full policy document exists, it is linked from the relevant section. Last reviewed August 2026.
Regulatory status
Navy Federal is authorized and regulated by the Office of the Comptroller of the Currency under registration number 7693932939. We are permitted to accept deposits, provide payment services and offer regulated credit.
Eligible deposits are insured by the Federal Deposit Insurance Corporation (FDIC) up to $250,000 per depositor, per insured bank, for each account ownership category. Protection applies per depositor, per institution — not per account — so balances held across several Navy Federal accounts are aggregated for the purpose of the limit.
Our permissions, and any conditions attached to them, are recorded on the public register maintained by our regulator. Where our permissions change, we update this page and notify affected customers directly.
Financial crime and anti-money laundering
We operate a risk-based anti-money laundering and counter-terrorist financing program covering customer due diligence, ongoing monitoring, sanctions screening and suspicious activity reporting.
Every customer is identified and verified before an account is opened, and again when the risk profile of a relationship changes materially. We screen against applicable sanctions lists at onboarding and continuously thereafter.
Transaction monitoring runs continuously. Where activity is inconsistent with what we understand of a customer, we investigate and — where the threshold is met — report to the relevant authority. We are prohibited by law from telling a customer that such a report has been made.
We may decline, delay or reverse a transaction, or close a relationship, where we cannot satisfy ourselves as to its purpose or the source of funds involved.
Data protection
We process personal data as a controller under applicable data protection law. Our lawful bases are contract performance, legal obligation, legitimate interests and — where relied on — consent, which you may withdraw at any time.
We collect what we need to run your account, meet our regulatory duties and prevent fraud. We do not sell personal data, and we do not share it with third parties for their own marketing.
You have rights of access, rectification, erasure, restriction, portability and objection. Requests are answered within one month, and there is no charge unless a request is manifestly unfounded or excessive.
Complaints
If something has gone wrong, tell us and we will put it right. Complaints can be raised by phone, in writing, in a branch or through the app, and none of these routes is treated as less formal than another.
We acknowledge complaints promptly and aim to resolve them within three business days. Where that isn't possible we will write to you with an explanation and a realistic timeframe, and we will issue a final response within eight weeks.
If you are unhappy with our final response, or eight weeks pass without one, you may refer the complaint to the relevant independent ombudsman service free of charge. Doing so does not affect your legal rights.
Reporting and whistleblowing
We publish regulatory returns and disclosures as required, including capital and liquidity reporting, and we maintain records for the periods our obligations demand.
Staff and third parties can raise concerns about wrongdoing confidentially, and where they choose, anonymously. Reports are handled independently of line management, and we do not tolerate retaliation against anyone who raises a concern in good faith.
Concerns can also be raised directly with our regulator. Nothing in our policies restricts anyone from doing so.
Compliance enquiries
For regulatory correspondence, data protection requests or to raise a concern, contact our compliance team directly. Written correspondence should be sent to 1200 Market Street, Suite 400, Philadelphia, PA 19107.
Looking for our terms? Read the terms of service.