Growth · Customer controlsMonzo · FCA
Customer and product growth outpaced key Financial Crime controls.
Official finding. The FCA states that Monzo's customer base grew rapidly and that its Financial Crime controls failed to keep pace with customer and product growth, with weaknesses in onboarding, customer risk assessment and transaction monitoring.
FCRisk synthesis. Scale can expose a structural dependency between acquisition, customer information, risk assessment and monitoring effectiveness.
Primary source — FCA ↗
Growth · SanctionsStarling · FCA
Rapid growth coincided with weaknesses in sanctions controls and high-risk onboarding restrictions.
Official finding. The FCA states that Starling grew rapidly while measures to tackle Financial Crime did not keep pace, and separately identified longstanding sanctions-screening defects and breaches of a restriction on high-risk onboarding.
FCRisk synthesis. Scaling a customer base requires proportional scaling of screening coverage, testing, governance and restrictions management.
Primary source — FCA ↗
Configuration · Retrospective workloadCoinbase Europe · Central Bank of Ireland
A configuration defect propagated into a major retrospective monitoring burden.
Official finding. The Central Bank of Ireland found faults in Coinbase Europe's transaction-monitoring configuration that meant more than 30 million transactions were not properly monitored; completing the affected monitoring took almost three years.
FCRisk synthesis. At high transaction scale, a technical defect can become an operational-capacity and regulatory-reporting problem as soon as retrospective remediation is required.
Primary source — Central Bank of Ireland ↗
Products · Change · ResourcingTD Bank · DOJ / FinCEN
Risk and products changed while monitoring architecture remained static.
Official finding. U.S. authorities described transaction types outside automated monitoring, long periods without new monitoring scenarios despite emerging risks and new products/services, and material programme-resourcing weaknesses.
FCRisk synthesis. Control scalability is not simply adding investigators; risk scope, scenarios, data governance and operating capacity must evolve together.
Primary source — U.S. DOJ ↗ · FinCEN ↗