Population boundaryMetro Bank · FCA
Source-to-monitoring completeness was not proven.
Official finding. A data-feed logic error meant some transactions did not reach monitoring. The FCA Final Notice says Metro had taken no steps before its 2019 lookback to check completeness of data fed into the automated TM system and later ad-hoc reconciliations did not initially cover transaction records.
FCRisk synthesis. Completeness should be evidenced at the source-to-control boundary, not inferred from successful downstream processing.
Primary source — FCA Final Notice ↗
Population boundaryDanske Bank · Central Bank of Ireland
Filtering changed the monitored population.
Official finding. Historic filters in Danske's automated system erroneously excluded customer categories from transaction monitoring.
FCRisk synthesis. Filters, exclusions and eligibility logic should be treated as controlled policy decisions because they define who or what the control can see.
Primary source — Central Bank of Ireland ↗
Population boundaryTD Bank · DOJ / FinCEN
Entire transaction classes sat outside automated monitoring.
Official finding. DOJ states that domestic ACH, most check activity and other transaction types were intentionally excluded from automated monitoring. FinCEN's 2024 order additionally requires a data-governance review covering relevant data sources, systems, flows, accuracy, completeness, consistency, effectiveness and timeliness.
FCRisk synthesis. Transaction-scope decisions and data governance are inseparable when scope determines the population available to detection.
Primary source — U.S. DOJ ↗ · FinCEN Consent Order ↗
Semantic boundaryNatWest · FCA
The transaction arrived with the wrong risk meaning.
Official finding. NatWest's automated system interpreted some cash deposits as cheque deposits, causing them to be subject to less stringent rules rather than cash-specific monitoring.
FCRisk synthesis. Record presence is not enough. Mapping correctness determines whether monitoring applies the intended risk logic.
Primary source — FCA Agreed Statement of Facts ↗
Context boundaryMonzo · FCA
Insufficient customer data weakened transaction interpretation.
Official finding. The FCA Final Notice states that Monzo's failure to gather sufficient customer data meant it could not effectively assess whether transactions were consistent with expected activity or suspicious.
FCRisk synthesis. Customer context is part of the decision dataset, even when stored outside the transaction-monitoring platform.
Primary source — FCA Final Notice ↗
Context boundarySantander UK · FCA
Intended activity was not reliably connected to observed behaviour.
Official finding. Santander had ineffective systems for verifying customer information about business activity and did not properly monitor what customers said would flow through accounts against actual deposits.
FCRisk synthesis. Data can exist yet remain functionally outside the control if it is not operationalised in ongoing risk decisions.
Primary source — FCA ↗
Reference-data boundaryStarling Bank · FCA
The screening engine saw only a fraction of the sanctions population.
Official finding. The FCA Final Notice describes a longstanding misconfiguration under which individual customers were effectively screened against only a small subset of designated persons in the relevant consolidated list.
FCRisk synthesis. Screening effectiveness depends on authoritative-list ingestion and matching configuration as much as on the existence of a screening engine.
Primary source — FCA Final Notice ↗