Data integrity · Transaction Monitoring12 Nov 2024 · UK
Metro Bank — monitoring coverage failed at the data boundary
Official finding. The FCA found that an error in how transaction data was fed into Metro Bank's automated monitoring system meant some transactions were not monitored, and that the bank did not have a mechanism consistently checking that all relevant transactions were entering the system until December 2020.
AMLTMData completenessReconciliationIssue escalation
FCRisk interpretation. A detection control cannot be effective if its input population is not demonstrably complete. The case illustrates the dependency between upstream data integrity, monitoring coverage, escalation of control concerns and sustained verification.
Primary source — FCA ↗
TM design · Data integrity17 Dec 2021 · UK
HSBC — scenario coverage, calibration and data quality failed together
Official finding. The FCA identified serious weaknesses in HSBC's automated transaction monitoring over eight years, including insufficient consideration of scenario risk coverage, inadequate testing and updating of parameters, and failures to check the accuracy and completeness of data feeding and held within monitoring systems.
AMLTMScenario coverageCalibrationData quality
FCRisk interpretation. Monitoring effectiveness is a system outcome. Scenario design, parameter calibration and input-data integrity must all be evidenced; strength in one layer cannot compensate for an uncontrolled weakness in another.
Primary source — FCA ↗
TM coverage · Configuration15 Sep 2022 · Ireland
Danske Bank — historic filters excluded customers from monitoring
Official finding. The Central Bank of Ireland found that historic data filters in Danske's automated monitoring system erroneously excluded categories of customers from transaction monitoring for years, including some high- and medium-risk customers. An internal audit identified inadequacies in 2015, but adequate action and communication to the Irish branch were delayed.
AML/CFTTMCoverageConfigurationAudit escalation
FCRisk interpretation. Legacy configuration is not benign merely because it is stable. Cross-border or group-wide platforms require explicit local applicability checks, population assurance and a mechanism that turns audit findings into timely remediation.
Primary source — Central Bank of Ireland ↗
Enterprise AML · Data governance10 Oct 2024 · US
TD Bank — growth, resourcing, monitoring and data governance converged
Official finding. FinCEN found that TD Bank willfully failed to maintain an AML programme meeting BSA requirements, knew the programme was not appropriately designed or adequately resourced, allowed significant suspicious-activity backlogs to persist, and left large volumes of activity inadequately monitored. FinCEN required an independent monitor, historical transaction analysis, an end-to-end AML review and, for the first time in a FinCEN action, accountability and data-governance reviews.
AMLGovernanceResourcingSARData governance
FCRisk interpretation. Persistent AML failure can be systemic rather than a single-control defect. Governance, investment, data, detection, escalation and reporting form one operating system; remediation must therefore address root causes rather than only clear backlogs.
Primary source — FinCEN ↗
Recidivism · Sustainable remediation3 Aug 2026 · US
UBS Financial Services — remediation failure became a control failure of its own
Official finding. FinCEN's 2026 action states that UBSFS did not remediate weaknesses previously identified in its automated monitoring of foreign-currency wires, subsequently failed to appropriately monitor more than 50,000 such wires with an aggregate value above $10 billion, and also had CDD deficiencies involving high-risk customers. FinCEN required a lookback and independent AML-programme review.
AMLTMCDDRecidivismRemediation assurance
FCRisk interpretation. Closure evidence matters as much as remediation design. A finding that is declared addressed without sustainable verification can reappear as both the original control weakness and a governance failure around assurance, transparency and accountability.
Primary source — FinCEN ↗ · FCRisk case note →
Crypto · TM configuration6 Nov 2025 · Ireland
Coinbase Europe — configuration faults created a large monitoring gap
Official finding. The Central Bank of Ireland found faults in Coinbase Europe's transaction-monitoring configuration that resulted in more than 30 million transactions not being properly monitored during a 12-month period. It also found that completing retrospective monitoring took almost three years, after which thousands of suspicious transaction reports were submitted.
CryptoTMConfigurationBacklogSTR timeliness
FCRisk interpretation. At digital-asset scale, a configuration defect can become a population-level control failure very quickly. Detection integrity requires preventive configuration assurance, monitoring of monitoring, and recovery capacity capable of handling retrospective review without multi-year delay.
Primary source — Central Bank of Ireland ↗
Crypto · KYC · Sanctions21 Nov 2023 · US / Global
Binance — business model and senior-management choices undermined AML controls
Official finding. FinCEN found that Binance willfully failed to maintain an effective AML programme, including categorical KYC gaps and failures to report suspicious activity. OFAC separately resolved apparent sanctions violations involving transactions between U.S. users and users in sanctioned jurisdictions or blocked persons and required sanctions compliance monitoring.
CryptoKYCSARSanctionsGovernance
FCRisk interpretation. Control weakness can be structural when commercial design and management decisions create deliberate exceptions to the intended control perimeter. Technology then scales the consequences of the governance choice rather than causing the failure by itself.
Primary source — FinCEN ↗ · Primary source — OFAC ↗
Sanctions · Screening coverage2 Oct 2024 · UK
Starling Bank — screening existed, but list coverage was incomplete
Official finding. The FCA said Starling discovered that its automated screening system had for years screened customers against only a fraction of the full list of persons subject to financial sanctions; the FCA also found repeated breaches of a restriction on opening accounts for high-risk customers.
SanctionsScreeningCoverageConfigurationGovernance
FCRisk interpretation. The existence of a screening platform is not evidence of screening effectiveness. Assurance must establish the authoritative list, ingestion completeness, matching configuration, exception handling and the actual population screened.
Primary source — FCA ↗
Business banking · Customer understanding9 Dec 2022 · UK
Santander UK — stated customer activity and observed behaviour diverged
Official finding. The FCA found serious and persistent gaps in Santander UK's AML controls for Business Banking customers, including ineffective systems to verify information about customers' intended business activity and failures to properly monitor expected account activity against what was actually occurring.
CDDBusiness bankingExpected activityTMRemediation
FCRisk interpretation. Customer information creates control value only if it is operationalised. Expected activity should inform monitoring and observed behaviour should, in turn, challenge and refresh customer understanding and risk assessment.
Primary source — FCA ↗
Growth · Control scalability8 Jul 2025 · UK
Monzo — Financial Crime controls did not keep pace with growth
Official finding. The FCA found that Monzo failed to design, implement and maintain adequate customer onboarding, customer risk assessment and transaction monitoring systems as its customer base grew rapidly, and later repeatedly breached a restriction on onboarding high-risk customers.
OnboardingCustomer riskTMGovernanceChange
FCRisk interpretation. Rapid growth is a control-change event. Capacity, risk models, monitoring, governance and restrictions need to scale with the business rather than remain calibrated to an earlier operating state.
Primary source — FCA ↗
Enterprise risk · Governance11 Jul 2023 · Australia
Crown — risk assessment, controls and board oversight were not aligned
Official finding. AUSTRAC states that Crown admitted its AML/CTF programmes were not based on appropriate risk assessments, lacked appropriate systems and controls to manage risk, and were not subject to appropriate Board and senior-management oversight. High-risk activity was able to continue without appropriate intervention.
AML/CTFRisk assessmentHigh-risk customersBoard oversightOperating model
FCRisk interpretation. A framework can fail before a transaction reaches a detection system. If enterprise risk assessment, control design and senior oversight are disconnected, individual downstream controls operate without a reliable risk architecture.
Primary source — AUSTRAC ↗
Sanctions · Escalation26 Jan 2026 · UK
Bank of Scotland — sanctions lessons span screening, escalation and training
Official finding. OFSI imposed a £160,000 monetary penalty for breaches of the Russia financial sanctions regime. In its subsequent lessons publication, OFSI highlighted how weaknesses in screening, escalation and training can expose firms to sanctions-breach risk.
SanctionsScreeningEscalationTraining
FCRisk interpretation. Sanctions control effectiveness is an end-to-end operating outcome: detection, human interpretation, escalation and informed action must work together. A technically functioning screening step is not sufficient on its own.
Primary source — OFSI ↗ · OFSI lessons ↗