Enforcement digest · All monthly digests

Sanctions enforcement digest — July 2026

This issue departs from our usual designations roundup — a full statistical and narrative analysis of the 12 AML enforcement actions publicly disclosed in July 2026 across the FCA, MAS, FINTRAC, and DNB, totaling $13.73M in penalties dominated by two Dutch banking and payments fines.

Published 2026-08-03 · ProofAML editorial

Editor's note: this issue departs from our usual designations-and-enforcement roundup format. Rather than a skimmable table of the month's list changes, July's issue is a full statistical and narrative analysis of the month's publicly disclosed AML enforcement actions — 12 actions across four regulators, with penalties converted to USD at analysis-run exchange rates. For the standard roundup format, see the June 2026 issue.

Executive Summary

July 2026 produced twelve enforcement actions across four jurisdictions — the United Kingdom, Singapore, Canada, and the Netherlands — totaling $13,734,921.58 in monetary penalties on 32 discrete findings. That aggregate figure, however, masks an unusually sharp geographic split in enforcement philosophy. Dutch regulator DNB accounted for $13,560,218.75 of the period's penalties — 98.7% of the total — across just three actions against two firms, while the FCA (four actions), MAS (two actions), and MAS/SPF (one action) collectively imposed zero monetary penalties despite finding conduct ranging from systemic financial-crime-framework failure to outright fraud. Canada's FINTRAC was the only other regulator to fine, and modestly so: $174,702.82 across two administrative monetary penalties against Atlantic Lottery Corporation ($151,173.82) and VIP Realty/Royal LePage Integrity Realty ($23,529). No action in the period involved a voluntary self-disclosure — a null result across all twelve cases that should concern compliance leaders who rely on self-reporting credit as a mitigant.

The UK and Singapore actions illustrate a "control, don't just fine" posture. The FCA's First Supervisory Notice against Euro Exchange Securities UK Ltd imposed no penalty but froze the firm's ability to onboard customers or accept funds, ring-fenced safeguarded funds pending independent remediation of every client file, and mandated weekly reporting — a response to findings that all ten reviewed client files were inadequate, that 4,968 transaction-monitoring alerts had been closed as not suspicious in a single file (3,294 with no documented rationale, only one ever escalated, and all reviewed by a single individual). Singapore's MAS took three enforcement actions in the period — two FSM Act 2022 prohibition orders (Andrew Tiew Siew Ing, 10-year PO for fraud; Li Jinbo, 3-year PO for market rigging) and one full criminal prosecution of Samlit Moneychanger and two of its officers (19 counts, each carrying fines up to S$1 million on conviction, not yet imposed) — again without a single monetary penalty in this reporting window. The UK's other three actions were individual prohibitions: former MLRO Dharmendra Solanki (unauthorised money-lending and money laundering, GBP 169,941.89 confiscation order but no FCA fine), and Alec Finch and his son Robert Finch of AFL Insurance Brokers, whose Level 5 (maximum severity) integrity breaches — a "major fraud" that misused £3.51m in client money — carried assessed penalties of £121,200 and £169,800 respectively, both reduced 100% to £0 on verified financial hardship and replaced with full prohibition orders. Robert Finch's case is one of only two the dataset flags as egregious.

The substantive findings point to governance and process failure, not technology gaps, as the defining weakness of the period. Governance Failure (34.4%, 11 of 32 findings) and Process Design Flaw (31.3%, 10 of 32) together account for nearly two-thirds of all findings, while Insufficient Technology registers zero — no institution in this period was cited for lacking monitoring tools, only for failing to operate, staff, or govern the ones they had. Process Design Flaw findings also carried the heaviest penalty weight ($6,550,379.08), ahead of Governance Failure ($3,069,717.50), reflecting DNB's emphasis on ABN AMRO Bank N.V.'s structural gatekeeper failures: a two-month delay detecting a EUR 500,000+ cash pass-through pattern that continued even after an "unacceptable" risk classification, risk indicators (Russia sanctions-evasion signals, dual-use goods, opaque end users) never assessed in combination, and an unsubstantiated downgrade from "unacceptable" to "medium" risk — findings that drove the EUR 8.5 million ($9,783,500) fine, the period's largest. By domain, Investigations & Reporting was both the most frequently cited (14 findings across 9 entities) and the highest-priority category (5 High-priority findings, versus 2 in Transaction Monitoring, 1 in KYC & Onboarding and none in Sanctions Screening) — consistent with a pattern of firms detecting or generating red flags internally and then failing to escalate, document, or report them.

Repeat-offender risk is the sharpest signal in the Dutch data. CCV Group B.V. was fined twice by DNB in this period alone: EUR 2,656,250 ($3,057,343.75) for transaction-monitoring gaps that left a "substantial" share of merchants unmonitored for nearly two years (the "Ecom-gap" and "PF7-gap" labeling failures), compounded by a 25% culpability uplift because DNB had already sanctioned CCV for the same monitoring norm in 2019–2020; and separately EUR 625,000 ($719,375) for operating without a systematic integrity risk analysis (SIRA) for roughly seven years, a lapse DNB labeled a "very serious violation" — the Dutch supervisory analogue to egregious and the dataset's second egregious action. Cultural/Tone Issues (15.6%, 5 findings, concentrated entirely in Investigations & Reporting) and Data Quality Issues (12.5%, 4 findings) round out the root-cause picture, the latter carrying $1,478,715.28 in associated penalties.

For compliance leaders, three implications stand out. First, the absence of any voluntary self-disclosure across twelve actions — spanning fraud, sanctions-evasion signals, and multi-year monitoring gaps — suggests detection, not just remediation, remains the industry's weak point; institutions should treat internally-flagged-but-unescalated risk indicators (as at ABN AMRO and Euro Exchange) as the pattern most likely to draw regulatory attention. Second, regulators are increasingly willing to act against individuals even where firm-level penalties are zero or waived: the FCA's three UK prohibitions and MAS's two Singapore prohibition orders — plus criminal charges against Samlit's two officers — show personal accountability persisting independent of a firm's financial capacity to pay. Third, the CCV precedent is a warning against treating remediation as closed the moment a fine is paid — prior enforcement for an unresolved control gap becomes an aggravating factor, not a mitigating one, in the next cycle.

Penalty Analysis

All figures below reflect the underlying enforcement documents with no manual recomputation. None of the twelve actions' penalties required an unconverted-currency caveat; the three zero-value regulators (FCA, MAS, MAS/SPF) reflect actual $0 monetary penalties imposed, not a conversion failure.

Penalties by Country

CountryTotal (USD)Average (USD)Count
Netherlands$13.6M$4.5M3
Canada$0.2M$0.1M2
United Kingdom$0.0M$0.0M4
Singapore$0.0M$0.0M3

Penalties by Regulator

RegulatorTotal (USD)Average (USD)Count
DNB$13.6M$4.5M3
FINTRAC$0.2M$0.1M2
FCA$0.0M$0.0M4
MAS$0.0M$0.0M2
MAS/SPF$0.0M$0.0M1

Penalties by Industry

IndustryTotal (USD)Average (USD)Count
Banking$9.8M$4.9M2
FinTech$3.8M$0.9M4
Gaming$0.2M$0.2M1
Corporate/Non-Financial$0.0M$0.0M1
Insurance$0.0M$0.0M3
Broker-Dealer$0.0M$0.0M1

Regulatory and Geographic Patterns

This month's twelve actions split into two starkly different enforcement philosophies, and the split runs almost entirely along jurisdictional lines rather than violation severity. The Netherlands' DNB accounts for just three of the twelve actions but $13.56 million of the $13.73 million in total penalties recorded this period — 98.7% of all monetary punishment in the dataset — while the UK's FCA (four actions) and Singapore's MAS/MAS-SPF (three actions), a combined 58% of enforcement volume, produced zero dollars in monetary penalties between them. Compliance teams that benchmark jurisdictional risk primarily off headline fine totals will badly misread this month's data: the UK and Singapore actions were not lenient, they simply express severity through different instruments.

The Dutch fines are concentrated and turnover-scaled. DNB fined ABN AMRO Bank N.V. EUR 8.5 million ($9.78 million) for failing to conduct adequate ongoing due diligence on high-risk clients — a case where the statutory EUR 5 million cap was explicitly set aside in favor of a turnover-linked regime given the bank's EUR 8.7 billion net turnover, with the fine reduced only 15% under the simplified-settlement procedure after ABN AMRO admitted the facts. DNB also fined CCV Group B.V. twice in the same publication cycle — EUR 2.66 million ($3.06 million) for transaction-monitoring gaps spanning 2021–2024, and EUR 625,000 ($719,375) for operating seven years without a systematic integrity risk analysis, the latter explicitly labeled a "very serious violation" (zeer ernstige overtreding) and its EUR 500,000 base uplifted 25% for the seriousness and long (seven-year) duration of the breach. DNB is the only regulator in this set willing to both label conduct at its highest severity tier and attach a commensurate fine — CCV's SIRA case is one of only two "egregious" designations in the entire dataset, and it is the one that actually cost money.

The FCA's zero-penalty actions are not soft outcomes. Robert Finch and Alec Finch, former director/CEO and director of AFL Insurance Brokers, were both assessed at Level 5 — the FCA's maximum seriousness tier — for a "major fraud" that misused £3.51 million in client money; their individual penalties were calculated at £169,800 and £121,200 respectively before being reduced 100% to £0 on verified financial hardship, with the substantive sanction instead a public misconduct finding plus a full prohibition order. Robert Finch's case is this dataset's other "egregious" designation — proof that egregiousness and fine size are decoupled once individual insolvency enters the calculus. The FCA's institutional action tells the same story in a different register: its First Supervisory Notice against Euro Exchange Securities UK Ltd imposed no fine at all, but froze the firm's ability to onboard customers or accept new funds and ring-fenced safeguarded funds pending independent third-party confirmation of CDD/EDD remediation on every client file — a response to findings that all ten reviewed client files were inadequate and that 4,968 alerts had been closed as not suspicious with 3,294 carrying no documented rationale. For an EMI, an operating freeze is a more existential consequence than most fines this dataset records.

MAS follows the same non-monetary pattern, backed by criminal process. All three Singapore actions — the 10-year prohibition order against Andrew Tiew Siew Ing (32 months' imprisonment for cheating), the 3-year prohibition order against Li Jinbo (market-rigging conspiracy), and the pending criminal prosecution of Samlit Moneychanger Pte. Ltd. and its Director and Compliance Manager (19 counts of failing to comply with an MAS complaints-handling direction, plus obstruction charges) — carry no monetary penalty from MAS itself, yet each rests on either a secured criminal conviction or an active prosecution with fines up to S$1 million per count still in play. Canada's FINTRAC sits at the opposite end of the monetary scale from DNB: administrative monetary penalties of CAD 212,025 ($151,174) against Atlantic Lottery Corporation for a missed STR and inadequate risk assessment, and CAD 33,000 ($23,529) against VIP Realty Inc. for a lapsed two-year program-effectiveness review — real fines, but an order of magnitude below the Dutch actions even on a per-violation basis.

The industry cut confirms geography, not sector, is driving penalty exposure. FinTech firms in this dataset ranged from Euro Exchange Securities ($0, systemic control failure) and Samlit Moneychanger ($0, pending prosecution) to CCV Group ($3.78 million combined across two Dutch actions) — comparable underlying severity, radically different price tags, determined almost entirely by which regulator held the file. The same is true in Banking, where the sector's entire $9.78 million penalty total traces to one Dutch action (ABN AMRO) against one $0 UK action (Dharmendra Solanki's prohibition). For multi-jurisdiction programmes, the implication is direct: local subsidiaries operating under DNB face fine exposure calculated against group turnover and compounded by repeat-offender uplift (as CCV's history shows), while subsidiaries under FCA or MAS should expect operational restrictions, prohibition orders, or criminal referral as the primary lever — consequences that can halt a business line faster than any fine and that a compliance program benchmarked only on jurisdictional penalty averages will systematically underweight. Programs should track regulatory posture by instrument type (fines vs. restrictions vs. prohibition vs. criminal referral) alongside penalty size, and treat a Dutch entity's remediation history as a live multiplier on future exposure rather than a closed chapter.

Compliance Theme Analysis

Where enforcement pressure concentrates

Investigations & Reporting was the most heavily implicated compliance domain this cycle, generating 14 of the 32 total findings (43.8%) and touching 9 of the 11 distinct entities (10 of the 12 actions) — over 80% of the dataset. It also carries the sharpest severity profile: 5 of its 14 findings were rated High priority, meaning this single domain accounts for 5 of the 8 High-priority findings recorded across the entire run (62.5%). Just as notably, every one of the cycle's five Cultural/Tone Issues root-cause findings sits inside Investigations & Reporting — none appear in KYC & Onboarding, Transaction Monitoring, or Sanctions Screening. That concentration is not abstract: it is the domain where Robert Finch and Alec Finch (AFL Insurance Brokers) were found to have orchestrated a "major fraud" involving false accruals and misused client-trust money — assessed by the FCA at Level 5, its maximum seriousness, with Robert Finch's conduct explicitly flagged egregious — and where Dharmendra Solanki, an approved MLRO, was found running an unauthorised, threatening money-lending operation on the side. When investigations and reporting break down in this dataset, it is disproportionately a leadership-integrity failure, not a documentation gap.

KYC & Onboarding tells a different story. It generated the second-highest volume of findings (10, across 5 entities) but almost none of the severity: only 1 was rated High, with 9 of 10 rated Medium. Governance Failure dominates its root-cause mix (6 of 10 findings), exemplified by Euro Exchange Securities UK Ltd, where the FCA found all ten reviewed client files inadequate — missing CDD, EDD/source-of-funds, and PEP/sanctions/adverse-media screening, including a missed FBI-investigation hit in open-source media — and by ABN AMRO, where DNB found ongoing due diligence relied "decisively" on unverified client statements and an unsubstantiated downgrade from "unacceptable" to "medium" risk. KYC weaknesses in this cycle are broad and structural but, on the evidence to date, less frequently the primary driver of an egregious finding on their own.

Transaction Monitoring sits between the two: 6 findings across 5 entities, but 2 of 6 rated High (33%) — a higher severity ratio than KYC despite the lower volume — and it is the domain most associated with Data Quality Issues (2 of the dataset's 4 such findings). CCV Group B.V.'s EUR 2.66M DNB fine is the clearest illustration: monitoring rules (BR0076/BR0078) sat inoperative, a "PF7-gap" mislabelled transactions for a year, merchant profiles went un-updated because CDD analysts lost system access, and 25 of 49 sampled alerts were closed without adequate investigation — a data-feed and access-control problem, not a model-tuning one. Sanctions Screening remains the smallest domain by volume (2 findings, 2 entities, both Medium priority) but is worth flagging precisely because of that thinness: its only two appearances this cycle were embedded inside two of the largest, most systemic actions (Euro Exchange, ABN AMRO), never standing alone.

The multi-domain pattern

The co-occurrence data confirms that Investigations & Reporting functions as the connective tissue across this cycle's failures rather than an isolated control point. It pairs with KYC & Onboarding in 6 actions — the single most common domain combination — and with Transaction Monitoring in 5. Even Sanctions Screening, the lowest-volume domain, co-occurs with Investigations & Reporting in both of its 2 appearances and never surfaces alone. Practically, this means a firm rarely fails at "screening" or "monitoring" in a vacuum; the finding regulators write up is that alerts generated by weak KYC or screening were then also mishandled, under-escalated, or never reported. Euro Exchange Securities UK Ltd is the starkest single-entity example: flagged across all four domains at once, with 4,968 transaction-monitoring alerts closed as "not suspicious," 3,294 with no documented rationale, and only one ever escalated — reviewed by a single individual. ABN AMRO's EUR 8.5M (USD 9.78M) fine, the largest penalty of the cycle, shows the same four-domain pattern: a two-month delay detecting a EUR 500,000+ cash pass-through, unassessed Russia sanctions-evasion signals, and delayed FIU-NL reporting, all traced back to one root deficiency — inadequate ongoing due diligence — cascading through the rest of the lifecycle. CCV Group's two separate DNB fines surfaced in the same 2026 publication cycle (the EUR 2.66M monitoring fine and a EUR 625,000 fine for operating seven years with no systematic integrity risk analysis, DNB's "very serious violation" and this cycle's other egregious finding) show that where governance and process gaps are structural, they recur across examination cycles rather than resolving. By contrast, VIP Realty's single-domain, single-finding action — one missed two-year AML program effectiveness review — drew this cycle's smallest penalty (USD 23,529), consistent with the pattern that isolated, single-domain gaps carry materially less financial and reputational weight than compounding, multi-domain ones. Notably, none of the 12 actions involved a voluntary self-disclosure; every finding in this dataset was surfaced by an examination, a criminal proceeding, or third-party civil litigation, not by the institution itself.

Prioritisation recommendations

  1. Treat Investigations & Reporting as the top supervisory priority. It carries the highest entity coverage, the majority of High-priority findings, and 100% of this cycle's Cultural/Tone Issues findings. Prioritise independent QA sampling of alert disposition and SAR/STR decisions, single-reviewer bottleneck elimination (per Euro Exchange), and MLRO/board-level integrity attestation — the Solanki and Finch cases show that leadership-level conduct failures, not documentation gaps, are what escalate this domain to egregious.
  2. Manage KYC & Onboarding as a breadth problem, not yet a severity crisis. With 90% of its findings rated Medium, resource ongoing-due-diligence triggers, periodic-review cadence, and EDD documentation discipline (per Euro Exchange and ABN AMRO) ahead of wholesale onboarding-system rebuilds.
  3. Audit Transaction Monitoring data lineage as a distinct workstream from alert tuning. CCV's data-feed and access-control gaps — not model design — drove this cycle's second-largest single penalty; firms should verify monitoring systems are actually receiving complete, current transaction and merchant data before investing in detection-logic improvements.
  4. Do not deprioritise Sanctions Screening on volume alone. Its two findings this cycle both sat inside the dataset's largest, most systemic actions — integrate screening review into the same case file as KYC/EDD rather than treating it as a standalone checklist item.
  5. Fund governance, process, and culture remediation ahead of new technology. Governance Failure (34.4% of findings) and Process Design Flaw (31.3%) together account for two-thirds of all findings this cycle, while Insufficient Technology and External Factors each account for zero — the evidence does not support technology gaps as this cycle's primary driver.
  6. Stress-test case files for joined-up failure, not siloed compliance. Given that Investigations & Reporting pairs with KYC & Onboarding in 6 actions and Transaction Monitoring in 5, internal audit should specifically test whether a KYC gap also shows up as an unescalated alert or an unfiled SAR in the same file — the pattern regulators are finding — rather than auditing each domain independently.

Domain Finding Frequency

DomainFindingsEntities
Investigations & Reporting149
KYC & Onboarding105
Transaction Monitoring65
Sanctions Screening22

Multi-Domain Co-Occurrence

Domain PairCo-Occurrence Count
Investigations & Reporting + KYC & Onboarding6
Investigations & Reporting + Transaction Monitoring5
KYC & Onboarding + Transaction Monitoring3
Investigations & Reporting + Sanctions Screening2
KYC & Onboarding + Sanctions Screening2
Sanctions Screening + Transaction Monitoring2

Root Cause Analysis

The dominant pattern: governance and process, not technology

Across the 32 findings extracted from this month's 12 actions, two root causes account for nearly two-thirds of all findings: Governance Failure (11 findings, 34.4%) and Process Design Flaw (10 findings, 31.3%). Cultural/Tone Issues (5, 15.6%) and Data Quality Issues (4, 12.5%) trail well behind, with Resource Constraints and Information Siloing each appearing just once (3.1%). Most notably, Insufficient Technology and External Factors register zero findings in this run. Not a single one of the 12 actions — spanning UK, Singapore, Canadian, and Dutch regulators — was attributed to firms lacking the tools to detect the underlying risk. ABN AMRO Bank N.V. had the systems to see a EUR 500,000+ cash pass-through pattern; DNB's finding was that the bank took two months to act on it and let an "unacceptable" risk classification get quietly downgraded without substantiation. Euro Exchange Securities UK Ltd's transaction-monitoring platform generated 4,968 alerts in a single client file — the failure was that a single individual reviewed them, 3,294 carried no documented rationale, and only one was ever escalated. The consistent story this month is that firms possess adequate detection capability and fail at the governance layer sitting on top of it: who reviews outputs, who challenges risk downgrades, and whether policy is actually followed.

Penalty-weighted exposure: process design carries the heaviest cost

Weighting root causes by the USD penalties tied to each action reframes the picture. Of the USD 13,734,922 in total penalties assessed this month, Process Design Flaw accounts for USD 6,550,379 — 47.7% of all penalty dollars, despite representing only 31.3% of findings by count. Governance Failure follows at USD 3,069,717 (22.3%), then Cultural/Tone Issues at USD 1,956,700 (14.2%), Data Quality Issues at USD 1,478,715 (10.8%), and Information Siloing at USD 679,410 (4.9%). Resource Constraints and Insufficient Technology carried zero penalty weight — consistent with the fact that the one Resource Constraints finding (Euro Exchange Securities UK Ltd's single-reviewer bottleneck) sat inside an action where the FCA imposed restrictions rather than a fine.

The concentration of penalty dollars in Process Design Flaw is driven by this month's two largest fines. DNB's EUR 8.5 million (USD 9,783,500) action against ABN AMRO — the largest single penalty this run — cited Process Design Flaw alongside Governance Failure and Cultural/Tone Issues: risk indicators (large cash flows, high-risk-country transactions, dual-use goods, possible Russia sanctions-evasion signals) were never assessed in combination, a design flaw in how the bank's due-diligence process integrated its own signals rather than a detection failure. DNB's EUR 2,656,250 (USD 3,057,344) fine against CCV Group B.V. for its continuous-monitoring gaps — the "Ecom-gap" (2021–June 2023) and "PF7-gap" labeling error (July 2023–July 2024) that left transactions unmonitored, plus 25 of 49 sampled alerts not adequately investigated — layered Process Design Flaw onto Data Quality Issues and this month's sole Information Siloing finding (CDD analysts losing system access). Notably, CCV was a repeat offender, having already been fined in 2020 for the same Wwft norm, and drew a 25% culpability uplift as a result — a direct illustration of process-design debt compounding penalty exposure over time.

How root causes vary by domain

The root-cause mix shifts sharply depending on which compliance domain is in view, and the pattern is instructive for where each function should focus remediation:

  • KYC & Onboarding (10 findings) is overwhelmingly a governance story: 6 of its 10 findings are Governance Failure, versus 3 Process Design Flaw and 1 Information Siloing. This is the domain where ABN AMRO's unverified client statements and unsubstantiated risk downgrade, Euro Exchange Securities' ten-for-ten inadequate client files, and Atlantic Lottery's un-approved and non-current compliance policies all land. The through-line is oversight discipline failing to keep pace with — or simply never being applied to — otherwise-adequate onboarding processes.
  • Transaction Monitoring (6 findings) is the only domain where Resource Constraints and Data Quality Issues concentrate (1 and 2 findings respectively, alongside 1 Process Design Flaw and 2 Governance Failure). This is squarely CCV's un-fed monitoring rules (BR0076/BR0078 inoperative for a substantial share of merchants) and Euro Exchange's single-person, thousands-of-alerts review bottleneck — data and staffing gaps specific to keeping monitoring pipelines complete and adequately resourced, not detection-logic failures.
  • Sanctions Screening is the smallest domain (2 findings) and both are Process Design Flaw — reflecting ABN AMRO's failure to weigh sanctions-evasion signals alongside other risk indicators rather than a screening-tool gap.
  • Investigations & Reporting (14 findings, the largest domain) is where all 5 of this month's Cultural/Tone Issues findings sit, alongside 4 Process Design Flaw, 3 Governance Failure, and 2 Data Quality Issues. This domain captures the month's individual-conduct actions: Dharmendra Devji Solanki running an unauthorised, predatory money-lending business while serving as an approved MLRO; Alec Finch and Robert Finch's Level-5 "major fraud" at AFL Insurance Brokers, involving false accounting accruals and misrepresentations to induce a £2.12 million share sale; and Samlit Moneychanger's compliance manager facing obstruction-of-justice charges for interfering with a Singapore Police Force investigation. Tone-at-the-top failures at the individual and senior-management level, not process gaps, are the defining root cause where reporting and investigative integrity break down.

The co-occurrence data reinforces that these domain failures rarely stay contained: Investigations & Reporting overlaps with KYC & Onboarding in 6 findings and with Transaction Monitoring in 5 — the highest pairings this month — meaning a governance or process gap in one domain routinely surfaces as a reporting or escalation failure downstream (e.g., ABN AMRO's delayed and never-filed unusual-transaction reports to FIU-NL following its onboarding and monitoring gaps).

Strategic recommendations

Prioritize governance architecture over new detection technology. With zero findings attributed to Insufficient Technology and 70% of penalty dollars concentrated in Process Design Flaw and Governance Failure combined, institutions running a "buy more tooling" playbook are solving the wrong problem this cycle. The higher-yield investment is in the control layer around existing systems: mandatory dual review or escalation triggers when a client's risk classification is downgraded (the exact gap DNB cited at ABN AMRO), documented rationale requirements for closed alerts rather than bulk dispositions (the gap at both Euro Exchange Securities and CCV), and periodic, senior-officer-approved policy review cycles (the gap at Atlantic Lottery and VIP Realty).

Treat MLRO and senior-management fitness as an ongoing control, not a one-time approval gate. Every Cultural/Tone Issues finding this month attached to Investigations & Reporting, and every one of those cases was detected through criminal prosecution or civil litigation rather than internal escalation — Solanki's conviction, the Finches' High Court judgment, Samlit's compliance manager's obstruction charges. Firms should build continuous conduct-monitoring and external-litigation/adverse-media screening into MLRO and director oversight, not rely solely on initial approved-person vetting.

Fund monitoring-pipeline completeness audits, not just alert-volume capacity. The Transaction Monitoring domain's distinctive mix of Data Quality Issues and Resource Constraints points to a specific, checkable failure mode: transactions or merchant profiles silently excluded from monitoring scope (CCV's Ecom-gap and PF7-gap) and single points of failure in alert review (Euro Exchange's lone reviewer). A periodic reconciliation between transaction volume and monitored volume, plus minimum staffing ratios tied to alert throughput, would have surfaced both gaps before they became fines.

Require combinatorial, not sequential, risk-indicator review in onboarding and sanctions screening. ABN AMRO's core failure — individually-known risk indicators (cash flows, high-risk jurisdictions, dual-use goods, sanctions-evasion signals) never assessed together — is a process-design fix, not a technology gap: build explicit sign-off steps that force a composite risk view before EDD conclusions are finalized, particularly given this pattern's outsized share (47.7%) of this month's total penalty exposure.

Watch for the governance-plus-cultural or governance-plus-process combination as the egregiousness threshold. Both actions flagged egregious this month — Robert Finch's prohibition (Governance Failure plus Cultural/Tone Issues) and CCV's SIRA fine (Governance Failure plus Process Design Flaw plus Data Quality Issues, DNB's "zeer ernstige overtreding" for operating seven years with no integrity risk analysis at all) — paired Governance Failure with a second root cause rather than standing alone. Institutions with an existing Governance Failure finding in a self-assessment should treat any accompanying process or cultural gap as materially elevating enforcement risk, not as an independent, lower-priority issue.

Root Cause Frequency

Root CauseCount% of Findings
Governance Failure1134.4%
Process Design Flaw1031.3%
Cultural/Tone Issues515.6%
Data Quality Issues412.5%
Resource Constraints13.1%
Information Siloing13.1%
Insufficient Technology00.0%
External Factors00.0%

Root Cause by Domain

Root CauseKYC & OnboardingTransaction MonitoringSanctions ScreeningInvestigations & Reporting
Governance Failure6203
Process Design Flaw3124
Cultural/Tone Issues0005
Data Quality Issues0202
Information Siloing1000
Resource Constraints0100
Insufficient Technology0000
External Factors0000

Penalty by Root Cause (Priority-Weighted Allocation: High ×3, Medium ×2, Low ×1)

Root CausePenalty (USD)
Process Design Flaw$6.6M ($6,550,379.08)
Governance Failure$3.1M ($3,069,717.50)
Cultural/Tone Issues$2.0M ($1,956,700.00)
Data Quality Issues$1.5M ($1,478,715.28)
Information Siloing$0.7M ($679,409.72)
Resource Constraints$0.0M ($0.00)
Insufficient Technology$0.0M ($0.00)
External Factors$0.0M ($0.00)

Priority Distribution

Priority reflects the severity decision tree applied to each finding at extraction time (High: penalty >$10M attributable, conduct labelled egregious, gap enabled actual illegal activity, or a criminal referral resulted; Medium: significant control weakness with explicit regulatory criticism; Low: a documentation/procedural gap with no evidence of exploitation). The cross-tab below shows how the 32 findings this run distribute across the four compliance domains — Investigations & Reporting carries both the highest volume and the highest concentration of High-priority findings, while KYC & Onboarding and Sanctions Screening are almost entirely Medium.

DomainHighMediumLow
KYC & Onboarding190
Transaction Monitoring240
Sanctions Screening020
Investigations & Reporting563

AI Investment Themes

The findings above also point to where AI-assisted controls could most directly close this cycle's gaps — useful context for compliance and technology teams weighing their own roadmap.

Governance Failure

Automated client-money reconciliation with ML anomaly detection over client-account flows

  • Technology: Automated CASS client-money reconciliation with rules-plus-ML transaction anomaly detection
  • Expected benefit: Detects improper withdrawals of client trust money in days rather than years and closes the falsified-calculation mechanism (£3.51m extracted via 25-day calculations), protecting client funds and reducing insolvency-concealment risk.
  • ROI timeline: 6-12 months
  • Risks: Privileged insiders overriding or disabling the pipeline — needs immutable logging and independent oversight of the monitoring itself; ledger/bank-feed data quality — garbage-in reconciliations create false assurance; alert fatigue in small firms without dedicated compliance staffing; regulatory reliance requires validated, explainable calculations under CASS/SUP audit.
  • Rationale: Highest-impact governance control in the set: addresses a marquee client-money theft (£3.51m, undetected 6+ years) with a High-feasibility, fast-ROI reconciliation. Distinct from the customer-transaction and journal-entry anomaly picks by data domain (CASS client vs office-account flows) and control fix (independent reconciliation escalating to a NED).

LLM decision-review copilot for risk-classification governance

  • Technology: LLM-based decision-review copilot auditing risk-rating changes against the full case file
  • Expected benefit: 100% coverage of reclassification decisions with evidence-linked review, blocking unsubstantiated downgrades from 'unacceptable' that deactivate enhanced monitoring, with an auditable rationale trail for the supervisor.
  • ROI timeline: 12-18 months
  • Risks: Explainability demands from DNB and EU AI Act high-risk decision-support obligations; over-reliance eroding rather than strengthening human challenge; hallucination risk requiring strict retrieval-grounding on file contents.
  • Rationale: Targets the governance essence — oversight and challenge of the decisions themselves (the Client 4 unsubstantiated downgrade) — at 100% coverage versus manual sampling, High feasibility. Distinct from the Cultural investigation copilot by target: risk-rating reclassification versus investigation closure quality.

LLM regulatory-change management and policy gap analysis

  • Technology: LLM pipeline mapping statutes, ministerial directives and sector guidance against internal policies to flag gaps and draft redlines
  • Expected benefit: Continuous assurance that policies stay current with regulatory change (the 'missing key regulatory requirements' FINTRAC found), drastically shortened update cycles, and documented traceability from each obligation to a control.
  • ROI timeline: 3-6 months
  • Risks: LLM hallucination requires legal/compliance review of outputs; regulatory corpus must be kept authoritative and current; approval workflow must remain human-owned to satisfy the senior-officer approval requirement.
  • Rationale: Covers the program-currency failure pattern (outdated/missing policy requirements) at the lowest cost and fastest ROI (3-6mo, High feasibility). A regulatory-corpus-to-policy mapping archetype that appears nowhere else in the selected set.

Perpetual KYC / event-driven review trigger engine

  • Technology: Event-driven review trigger engine over customer-data changes, risk-rating movements and unusual-activity indicators
  • Expected benefit: Reviews fire when risk changes rather than never or only under regulator pressure, replacing the failed calendar-based process, with a complete audit trail of review timing, steps and conclusions per reg 28(11)/27(8).
  • ROI timeline: 6-12 months
  • Risks: Trigger over-firing creating review backlogs a small team cannot absorb; dependence on remediated underlying customer data; change-management burden on a firm with weak governance.
  • Rationale: Addresses the pervasive governance failure of reviews that never happened even under the firm's own policy, at High feasibility. Distinct from the onboarding IDP pick by focusing on the ongoing review-cadence trigger layer rather than new-customer decisioning.

Process Design Flaw

Intelligent document processing with explainable onboarding risk-scoring

  • Technology: OCR/LLM document extraction plus rules-plus-ML customer risk-scoring at onboarding
  • Expected benefit: Consistent, auditable CRA/CDD at onboarding — catching expired ID, unsupported proof of address and mismatched-entity records, and generating a documented risk rationale reviewers approve before transacting is enabled (all ten files lacked this).
  • ROI timeline: 6-12 months
  • Risks: Model and extraction errors on poor-quality legacy documents; regulator scrutiny of automated risk-scoring explainability — human approval must remain in the loop; garbage-in risk given the firm's existing data-quality problems.
  • Rationale: Covers the most common process gap — undocumented CRA and defective identity/beneficial-owner verification — at High feasibility. Distinct from the Data-Quality archive-indexing pick by purpose: forward-looking onboarding decisioning versus backward-looking records retrieval.

Transliteration-aware sanctions screening with adverse-media and connected-party resolution

  • Technology: Fuzzy/phonetic name-matching screening with NLP adverse-media analysis and entity resolution for connected parties
  • Expected benefit: Complete, timely screening of customers and their directors/owners — defeating the misspelled-name failure and surfacing missed adverse media (e.g. the alleged money-laundering scheme/FBI investigation) — with every potential match dispositioned and audited per regs 28 and 35.
  • ROI timeline: 3-9 months
  • Risks: False-positive volume overwhelming a thinly resourced adjudication team; adverse-media source coverage and precision limits; auto-disposition of matches would attract regulatory challenge — human adjudication with QA required.
  • Rationale: The set's only sanctions-screening pick, covering a core AML pillar and two distinct failures (name-matching plus missed media/connected parties) at High feasibility and fast ROI. No near-duplicate elsewhere.

Behavioural transaction anomaly detection with network analytics

  • Technology: Machine-learning models on account-level behavioural sequences combined with graph analytics linking feeder entities
  • Expected benefit: Cuts detection latency from the observed 2+ months to days, auto-flags materially similar transactions the bank missed, and triggers restrictions preventing post-'unacceptable' activity (the EUR 130,000 that still flowed after classification).
  • ROI timeline: 12-24 months
  • Risks: False-positive volume overwhelming investigation capacity; model-validation and governance burden under supervisory scrutiny; counterparty data quality limiting network-linking accuracy.
  • Rationale: The core transaction-monitoring detection-design pick, addressing slow detection and missed-similar-transaction gaps. Distinct from the client-money reconciliation (Governance) and journal-entry (Cultural) anomaly picks by data domain (customer transactions/counterparty networks) and problem (missed suspicious activity).

Deterministic threshold-reporting engine with automated FIU filing and evidence tracking

  • Technology: Deterministic rules engine with automated FIU unusual-transaction report generation and filing-evidence archiving
  • Expected benefit: Near-zero missed or late objective-indicator reports (five were missed; lookbacks landed 2-5 weeks late) and instant, evidence-backed proof of filing that CCV could not substantiate — at low cost because the indicator is fully deterministic.
  • ROI timeline: 3-6 months
  • Risks: Upstream dependency: only works if the TM system actually receives all transactions (Data-Quality fixes are a prerequisite); capturing intended-but-unexecuted transactions requires pre-execution events; duplicate-filing controls needed when lookbacks overlap live detection.
  • Rationale: The cheapest, fastest reporting-workflow fix (3-6mo) covering the objective-indicator reporting failure. Deliberately non-ML, making it distinct from every other pick and complementary to the ML detection layers.

Cultural/Tone Issues

Continuous adverse-media and public-records screening of approved persons

  • Technology: NLP-based perpetual adverse-media and public-records screening with entity resolution
  • Expected benefit: Detects criminal proceedings or undisclosed business activity by senior managers (SMF16/17) in days rather than years — here offending ran ~3.5 years and surfaced only on arrest — enabling prompt suspension and regulator notification.
  • ROI timeline: 6-12 months
  • Risks: False positives on common names causing unfair employment action; data-protection and employment-law constraints on monitoring staff; variable reliability and coverage of adverse-media and court-record sources.
  • Rationale: Directly targets the tone-at-the-top failure of undetected senior-manager misconduct, at High feasibility. Distinct from the sanctions-screening pick by subject and purpose — monitoring employees/approved persons for integrity, not screening customers for sanctions.

Journal-entry anomaly detection with NLP ledger-to-communications cross-referencing

  • Technology: ML anomaly detection on accounting journals combined with NLP cross-referencing of emails and board minutes against ledger entries
  • Expected benefit: Detects fictitious revenue accruals and balance-sheet inflation within one or two accounting cycles instead of the 6+ years achieved here, with an independent evidence trail that survives senior-management override.
  • ROI timeline: 12-18 months
  • Risks: Senior insiders with admin rights can suppress or tune alerts — requires independent alert routing to the audit committee/external auditor; false positives on legitimate but unusual accruals causing alert fatigue; privacy and legal constraints on mining employee communications; model governance and explainability requirements for audit reliance.
  • Rationale: Addresses the canonical management-override / false-accounting culture (an accrual stood while a broker's own email said the account was 'not won'). Distinct from the client-money reconciliation pick by fraud type (revenue fabrication vs client-money theft) and control (independent alert routing of accrual anomalies).

GenAI investigation copilot with enforced evidence standards

  • Technology: Generative-AI investigation copilot embedded in case management with structured evidence-standard enforcement
  • Expected benefit: Raises the floor of investigation quality and consistency, produces an indicator-by-indicator, regulator-ready audit trail, and refuses closure while risk indicators remain undispositioned — institutionalising the critical depth DNB found lacking across all five files.
  • ROI timeline: 12-18 months
  • Risks: Technology cannot substitute for the skepticism culture change the findings imply — must pair with training and incentives; hallucination/omission risk in generated case summaries; supervisory acceptance of AI-assisted investigation records.
  • Rationale: Converts the 'holistic assessment' expectation into an enforced workflow — the most direct AI answer to a weak-skepticism culture — at High feasibility. Distinct from the Governance decision-review copilot by target: investigation depth/closure quality rather than risk-rating reclassification.

Data Quality Issues

Data-completeness reconciliation with ingestion-volume anomaly detection

  • Technology: Automated processed-vs-ingested reconciliation with ML anomaly detection on transaction and merchant-profile ingestion volumes
  • Expected benefit: Eliminates multi-year silent monitoring gaps (feed breaks that ran 1-3+ years) by flagging them within hours, and enables precise impact quantification CCV twice could not provide to DNB — the primary driver of the EUR 2.66M fine.
  • ROI timeline: 3-6 months
  • Risks: Alert noise from seasonal/volume shifts requiring baseline tuning; dependence on a reliable source-of-truth feed to reconcile against; coverage blind spots if new channels/labels are onboarded outside the control.
  • Rationale: The standout Data-Quality pick — directly addresses the primary fine driver (silent feed/ingestion gaps) at the fastest ROI and High feasibility. Wholly distinct: it monitors the completeness of the monitoring pipeline itself rather than any customer-facing control.

Intelligent indexing of unstructured record archives for regulator-request retrieval

  • Technology: OCR, format-normalisation and LLM classification/entity-linking over unstructured document archives
  • Expected benefit: Converts a ~180,000-document, partly unreadable archive into per-customer, per-control indexed records so regulator requests are answered within deadline, makes evidence gaps visible and remediable, and demonstrates record retention against MLR reg 40 / reg 28(16).
  • ROI timeline: 3-6 months
  • Risks: Classification errors mis-filing evidence against the wrong customer; genuinely illegible or missing source documents cannot be recovered by tooling — gaps still require customer re-outreach; data-protection controls needed when processing customer records with AI tooling.
  • Rationale: Addresses the second distinct Data-Quality failure mode — unfindable/unproducible records on regulator request — at High feasibility and fast ROI. Framed as backward-looking archive retrieval/production, keeping it distinct from the forward-looking onboarding IDP pick in Process Design.

Strategic Recommendations

1. Rebuild periodic due-diligence and risk-reclassification governance — the single largest driver of penalty exposure this cycle

Governance Failure was the most common root cause identified (11 of 32 findings, 34.4%) and, together with Process Design Flaw (10 findings, 31.3%), accounts for nearly two-thirds of all findings in the cycle. The clearest illustration is DNB's EUR 8.5 million fine against ABN AMRO (USD 9.78M, 71% of the cycle's total penalty value), imposed for a structural failure to conduct ongoing due diligence on high-risk retail clients: a two-month delay in detecting a EUR 500,000+ cash pass-through pattern that continued even after the client had been classified "unacceptable," an unsubstantiated downgrade from "unacceptable" to "medium" risk, and a failure to assess large-cash, high-risk-country, dual-use-goods and Russia sanctions-evasion indicators in combination. DNB was explicit that investigations relied "decisively" on unverified client statements and that non-cooperation carried no consequences. CCV Group shows what happens when this gap goes unaddressed: its EUR 2.66M fine included a 25% culpability uplift specifically because CCV was a repeat offender on the same Wwft norm it was first cited for in 2019-2020.

Action items:

  • Deploy an LLM-based decision-review copilot over every risk-rating reclassification (not a sample) — the ABN AMRO downgrade that let monitoring lapse would have been caught at 100% coverage rather than left to manual review (12-18 month ROI; requires immutable logging so privileged insiders cannot suppress the review itself).
  • Replace calendar-based periodic reviews with an event-driven trigger engine that fires on risk-rating movement, customer-data change, or unusual-activity indicators — directly targeting the "reviews that never happened even under the firm's own policy" pattern (6-12 month ROI).
  • Build in an explicit, auditable step requiring combined (not siloed) assessment of risk indicators — cash-flow size, geography, product type, sanctions-exposure signals — before any risk downgrade is approved.

2. Institutionalize investigation quality and evidence standards — the most frequent and highest-priority failure domain

Investigations & Reporting generated more findings (14) than any other domain, touched 9 of the cycle's 11 distinct entities (10 of 12 actions), and carried the most High-priority findings of any domain (5, versus 2 for Transaction Monitoring and 1 for KYC & Onboarding). It also co-occurs most often with other domains — 6 joint findings with KYC & Onboarding and 5 with Transaction Monitoring — indicating a shared root cause rather than isolated incidents. The FCA's supervisory notice against Euro Exchange Securities UK is the starkest example: 4,968 alerts closed as "not suspicious" in a single file, 3,294 with no documented rationale at all, only one ever escalated, and the entire alert population reviewed by a single individual. CCV Group shows the same pattern in its EUR 2.66M fine — 25 of 49 sampled alerts not timely or adequately investigated, including undocumented end-of-day bulk closures. Atlantic Lottery was separately fined CAD 212,025 (USD 151,174) in part for failing to file an STR despite multiple ML/TF indicators, a violation FINTRAC classified "Very Serious."

Action items:

  • Embed a GenAI investigation copilot in case management that enforces indicator-by-indicator evidence standards and refuses closure while risk indicators remain undispositioned — this converts DNB's "holistic assessment" expectation from an aspiration into an enforced workflow (12-18 month ROI).
  • Deploy a deterministic (non-ML) threshold-reporting engine for objective STR/UTR indicators with automated FIU filing and evidence archiving — the fastest, cheapest fix in the portfolio (3-6 months) and the direct answer to Atlantic Lottery's missed filing and CCV's late lookbacks.
  • Eliminate single-reviewer bottlenecks structurally: require independent second-review routing for any file where one individual is the sole adjudicator, as at Euro Exchange.

3. Fix transaction-monitoring pipeline integrity before investing further in detection models

Data Quality Issues drove 4 of 32 findings but were the proximate cause of one of the cycle's two egregious-adjacent, highest-value fintech fines. DNB's EUR 2.66M penalty against CCV Group rested on multi-year silent monitoring gaps: the "Ecom-gap" (2021 to June 2023) and "PF7-gap" labeling error (July 2023 to July 2024) meant a "substantial" share of merchants had no effective monitoring for extended periods, monitoring rules BR0076/BR0078 were inoperative, and merchant profiles went un-updated because CDD analysts lost system access. Detection models layered on top of an unreliable feed produce false assurance — precisely DNB's finding.

Action items:

  • Implement automated ingestion-volume reconciliation with anomaly detection comparing transactions/merchant-profiles processed against transactions ingested, flagging feed breaks within hours rather than years (3-6 month ROI, High feasibility — the fastest-payback item in the entire portfolio).
  • Sequence AI investment correctly: treat this pipeline-integrity control as a prerequisite for any behavioral anomaly-detection or network-analytics model, since both are only as good as the underlying feed.
  • Require quantified impact statements (volume/duration/customers affected) for any historical monitoring gap discovered — CCV's inability to precisely quantify its own gap to DNB was itself an aggravating factor.

4. Rebuild onboarding CDD/EDD and unify sanctions/adverse-media screening

KYC & Onboarding was the second-most-frequent domain (10 findings, 5 entities), and Sanctions Screening — while lower-volume (2 findings, 2 entities) — surfaced in combination with KYC in 2 findings and with Transaction Monitoring in 2 more, never in isolation. The FCA's Euro Exchange action is the marquee case: all ten reviewed client files were inadequate across CDD, EDD/source-of-funds, and PEP/sanctions/adverse-media screening, including a missed open-source media report of an alleged money-laundering scheme under FBI investigation — a gap serious enough to trigger a total restriction on onboarding new customers. ABN AMRO's failure pattern was adjacent: accepting client end-user statements without verification amid a shift in transshipment-country trade patterns, missing Russia sanctions-evasion signals.

Action items:

  • Deploy OCR/LLM document extraction with explainable, rules-plus-ML onboarding risk-scoring so every file carries a documented, reviewer-approved risk rationale before the customer can transact — none of Euro Exchange's ten sampled files had this (6-12 month ROI).
  • Pair onboarding with fuzzy/phonetic sanctions-name matching plus NLP adverse-media analysis and connected-party (director/beneficial-owner) resolution — the only way to catch both misspelled-name evasion and missed media coverage like the FBI-investigation gap, with human adjudication retained given false-positive risk (3-9 month ROI, fastest in the KYC set).
  • Extend end-user/source-of-funds verification requirements specifically for trade and transshipment-exposed customers, closing the gap DNB cited at ABN AMRO.

5. Make senior-manager and approved-person integrity a continuous, evidenced control

Cultural/Tone Issues accounted for 5 of 32 findings (15.6%) but sit behind two of this cycle's most severe individual actions. The FCA prohibited Dharmendra Solanki, a former SMF17 Money Laundering Reporting Officer, after he ran an unauthorised, predatory money-lending business — intimidating vulnerable borrowers — for roughly 3.5 years (November 2018–May 2022) while serving as an approved MLRO, undetected for roughly 3.5 years until his 18 May 2022 arrest by law enforcement (guilty plea October 2023). Separately, the FCA's Decision Notices against Alec Finch and Robert Finch assessed their conduct at Level 5 — the FCA's maximum seriousness rating — for a "major fraud" that diverted £3.51 million from a statutory client-money trust account over more than three years via falsified accounting accruals, one of which stood on the books even after a broker's own email stated the underlying business was "not won." Notably, all four UK actions this cycle carried £0 monetary penalties (two waived on verified hardship, one where the FCA imposed only a prohibition with no fine levied, one pending) yet resulted in prohibition orders or a full authorisation restriction — regulators are substituting career-ending sanctions for fines when firms/individuals cannot pay.

Action items:

  • Run continuous NLP-based adverse-media and public-records screening on approved persons and senior managers, not just customers — Solanki's unauthorised business and criminal exposure should have surfaced in months, not the 3.5 years it took (6-12 month ROI; pair with employment-law review given false-positive risk on common names).
  • Deploy journal-entry anomaly detection cross-referenced against internal communications (emails, board minutes) via NLP — the exact control that would have caught an accrual contradicted by the originating broker's own email, with alerts routed independently to the audit committee/external auditor so senior insiders cannot suppress them (12-18 month ROI).
  • Treat "£0 penalty, full prohibition" outcomes as a signal, not a reprieve: build remediation plans around license/authorization risk for senior individuals, since that is now the operative consequence regardless of financial capacity to pay.

6. Rebalance program investment by jurisdiction and by true regulatory risk, not fine totals alone

Three of this cycle's twelve actions — all from the Netherlands' DNB — account for USD 13.56 million of the USD 13.73 million in total penalties (98.7%), at an average of USD 4.52 million per action versus FINTRAC's USD 87,351 average. Firms with Dutch banking or payment-institution licenses should treat DNB exposure as the top financial-risk line item this cycle. But financial severity is not the whole risk picture: zero of the twelve actions involved a voluntary self-disclosure, and four UK actions carrying no fine at all still produced a total onboarding suspension (Euro Exchange) or full prohibition (Solanki, both Finches) — outcomes that threaten license continuity and franchise value in ways a penalty figure doesn't capture. The two actions this cycle DNB or the FCA characterized in egregious terms — CCV's "very serious violation" (zeer ernstige overtreding) for operating roughly seven years with no systematic integrity risk analysis at all, and Robert Finch's Level-5 fraud finding — both stem from absence of a foundational control (a SIRA; basic client-money segregation integrity), not a partial one.

Action items:

  • Weight remediation budgets toward jurisdictions with demonstrated high-severity regulators (DNB this cycle) while not deprioritizing UK/MAS exposure, where the consequence is authorization risk rather than fine risk.
  • Institute a standing self-disclosure protocol and track it as a KPI — a zero-VSD cycle across twelve actions suggests self-reporting is not yet embedded as a mitigation lever compliance teams are using.
  • Run a foundational-control inventory (SIRA/enterprise risk assessment, client-money segregation controls, documented CRA methodology) before adding detection-layer AI — CCV's and Atlantic Lottery's fines both trace to an absent foundational document, which no amount of downstream monitoring sophistication would have cured.

Methodology & Limitations

This analysis follows a fixed extraction, statistics, and report-generation methodology: a fixed compliance-domain taxonomy (KYC & Onboarding, Transaction Monitoring, Sanctions Screening, Investigations & Reporting), an eight-category root-cause taxonomy, and a priority decision tree applied consistently to every finding. All AI-generated content in this report — extracted findings, narrative insights, and AI investment recommendations — was reviewed for accuracy, completeness, and consistency with the underlying source documents before publication. All 12 of the documents discovered for this run were successfully extracted; none failed extraction.

Source coverage is limited to publicly disclosed enforcement actions — settlements resolved without public notice, informal supervisory actions, and actions by regulators that do not publish full orders are excluded, so this dataset understates total enforcement activity in the period. Extraction accuracy depends on document clarity; findings are extracted by an AI model instructed to be conservative and avoid fabrication, but heavily redacted or unusually formatted documents (several actions in this run, including Euro Exchange Securities UK Ltd and both ABN AMRO and CCV Group filings, contained redacted passages) may result in incomplete extraction. Currency conversion for cross-jurisdiction penalty comparisons uses exchange rates as of the analysis run date (2026-08-02, sourced from exchangerate-api.com/open.er-api.com) and is not adjusted for intra-period fluctuations over long violation periods spanning multiple years. AI use case attribution maps use cases to root causes based on the finding they address; where a single action contains multiple root causes within the same domain, only the most prevalent root cause receives attribution, so some secondary causes may be under-represented in the AI Investment Themes section. Root cause categorisation maps each finding to one of eight fixed categories reflecting the primary cause stated or most strongly implied in the source document, even where a finding plausibly has multiple contributing causes.

Sources

Every figure above traces back to the regulator's own published order or release. Browse the lists and programs we track in our data catalog to see how these entities and their affiliates map to your own screening book.

RegulatorRespondentPenalty (USD)Primary sourceAccessed
FCADharmendra Devji Solanki$0https://www.fca.org.uk/publication/final-notices/mr-dharmendra-solanki-2026.pdf2026-08-03
FCAEuro Exchange Securities UK Ltd$0https://www.fca.org.uk/publication/supervisory-notices/euro-exchange-securities-uk-ltd-2026.pdf2026-08-03
FCAAlec Finch$0https://www.fca.org.uk/publication/decision-notices/decision-notice-2026-alec-finch.pdf2026-08-03
FCARobert Finch$0https://www.fca.org.uk/publication/decision-notices/decision-notice-2026-robert-finch.pdf2026-08-03
MASAndrew Tiew Siew Ing$0https://www.mas.gov.sg/regulation/enforcement/enforcement-actions/2026/mas-issues-prohibition-order-against-mr-andrew-tiew-siew-ing-for-cheating-offences2026-08-03
MAS/SPFSamlit Moneychanger Pte. Ltd.$0https://www.mas.gov.sg/regulation/enforcement/enforcement-actions/2026/samlit-moneychanger-and-two-individuals-to-be-charged2026-08-03
MASMr Li Jinbo$0https://www.mas.gov.sg/regulation/enforcement/enforcement-actions/2026/mas-issues-prohibition-order-against-mr-li-jinbo2026-08-03
FINTRACAtlantic Lottery Corporation Inc.$151,173.82https://fintrac-canafe.canada.ca/new-neuf/nr/2026-07-09-1-eng2026-08-03
FINTRACVIP Realty Inc.$23,529.00https://fintrac-canafe.canada.ca/new-neuf/nr/2026-07-09-2-eng2026-08-03
DNBABN AMRO Bank N.V.$9,783,500.00https://www.dnb.nl/media/au5htfdo/bestuurlijke-boete-wwft-abn-amro.pdf2026-08-03
DNBCCV Group B.V. (2026-03-02 action)$3,057,343.75https://www.dnb.nl/media/yckprgyb/openbare-versie-boetebesluit-ccv2.pdf2026-08-03
DNBCCV Group B.V. (2020-07-09 action)$719,375.00https://www.dnb.nl/media/uqslluht/boetebesluit.pdf2026-08-03

Turn this into a screening action

Screen against the sources behind this post


← All posts