Cross-Case Failure Intelligence · Synthesis 01

Recurring Transaction Monitoring Failure Patterns.

Across selected UK, Irish and US enforcement actions, monitoring failure repeatedly appears as an end-to-end control-chain problem — not simply a weak rule or a poorly tuned threshold.

Published by FCRisk · Last reviewed: 27 August 2026
FCRisk synthesis

A monitoring platform can be operational while the monitoring control is ineffective.

The selected evidence shows multiple, distinct ways for monitoring to fail: relevant activity may never enter the monitoring perimeter; scenarios may not cover known risks; parameters may make detection ineffective; transaction meaning may be wrong; customer context may be insufficient; or alerts and suspicious activity may not be investigated and reported effectively.

Interpretive boundary

This page synthesises primary-source findings across individual cases. It does not assert that every institution or every enforcement action exhibits these patterns, nor does it attribute the cross-case synthesis itself to any regulator.

Six recurring mechanisms

Where the monitoring chain breaks.

01

Population outside the perimeter

Relevant customers or transaction classes are excluded, filtered or never delivered to monitoring.

02

Scenario coverage does not match risk

The platform runs, but the scenario set does not cover known or changing money-laundering risks.

03

Calibration undermines detection

Rules exist but thresholds, parameters or configuration make them insufficiently risk-sensitive.

04

Data meaning is incomplete or wrong

Transactions or customer context reach monitoring in a form that does not support the intended risk decision.

05

Investigation and reporting break downstream

Detection output does not translate reliably into timely investigation, escalation and suspicious activity reporting.

06

Assurance tests operation, not effectiveness

Without reconciliation, coverage testing, scenario-risk review and post-change assurance, a long-running control gap can remain invisible.

Primary-source evidence

Different cases illuminate different failure layers.

8 evidence anchors
Population completenessMetro Bank · FCA

Transactions never reached the monitoring control.

Official finding. The FCA found that a data-feed error meant transactions around account opening were not monitored, and that Metro did not have an effective mechanism consistently checking that all relevant transactions were fed into the monitoring system until December 2020.

FCRisk synthesis. Reconciliation is part of monitoring effectiveness when the control depends on upstream population completeness.

Primary source — FCA ↗

Scenario · Calibration · DataHSBC · FCA

Three control layers failed together.

Official finding. The FCA identified weaknesses in scenario risk coverage, testing and updating of system parameters, and checks over the accuracy and completeness of data feeding and held within monitoring systems.

FCRisk synthesis. Scenario design, calibration and data integrity are interdependent components of one monitoring outcome.

Primary source — FCA ↗

Filtering · CoverageDanske Bank · Central Bank of Ireland

Historic filters removed customers from monitoring.

Official finding. The Central Bank of Ireland found that historic filters in Danske's automated system erroneously excluded certain customer categories from transaction monitoring.

FCRisk synthesis. A monitoring exclusion is itself a risk decision and requires explicit ownership, rationale and periodic revalidation.

Primary source — Central Bank of Ireland ↗

Scope · ChangeTD Bank · DOJ / FinCEN / OCC

Monitoring scope and scenarios did not evolve with risk.

Official finding. DOJ states that TD Bank excluded domestic ACH, most check activity and other transaction types from automated monitoring, and added no new monitoring scenarios from 2014 through 2022 despite known deficiencies, emerging risks and new products and services.

FCRisk synthesis. Monitoring scope must be treated as a governed, revisitable risk decision — especially when products, channels and risk exposure change.

Primary source — U.S. DOJ ↗ · FinCEN Consent Order ↗

Classification · CalibrationNatWest · FCA

Cash was interpreted as lower-risk cheque activity.

Official finding. The FCA states that some cash deposits were incorrectly recognised by NatWest's automated monitoring system as cheque deposits and therefore were not subjected to cash-specific monitoring rules; the FCA also described calibration and escalation failures.

FCRisk synthesis. Correct transaction semantics are a monitoring control dependency: the same transaction can produce a different risk outcome if its type is misclassified.

Primary source — FCA ↗

Customer contextSantander UK · FCA

Expected activity was not effectively connected to observed activity.

Official finding. The FCA found ineffective systems for verifying customer information about intended business activity and failures to properly monitor expected account activity against what was actually occurring.

FCRisk synthesis. Transaction monitoring is stronger when customer understanding becomes an operational detection input rather than static onboarding information.

Primary source — FCA ↗

Customer data · InvestigationMonzo · FCA

Monitoring could not compensate for weak customer data.

Official finding. The FCA's Final Notice states that insufficient customer data reduced Monzo's ability to assess whether transactions were consistent with expected activity, alongside weaknesses in transaction-monitoring processes, procedural guidance and staff capability.

FCRisk synthesis. Detection effectiveness cannot be isolated from onboarding data and investigation capability.

Primary source — FCA Final Notice ↗

Configuration · BacklogCoinbase Europe · Central Bank of Ireland

A technology defect created a large retrospective monitoring requirement.

Official finding. The Central Bank of Ireland states that Coinbase Europe failed to fully and properly monitor more than 30 million transactions and was required to conduct additional monitoring over a further transaction population.

FCRisk synthesis. A configuration defect can propagate from technical control failure into operational backlog, retrospective review and delayed suspicious-activity reporting.

Primary source — Central Bank of Ireland ↗

Control implication

Monitor the monitoring control.

FCRisk interpretation: a defensible TM framework needs evidence across population completeness, risk-to-scenario coverage, parameter effectiveness, data integrity, change control, alert handling and outcome testing.

A practical assurance chain

Risk coverage → in-scope population → source-to-control reconciliation → scenario inventory → parameter testing → data correctness → change/migration testing → alert/investigation QA → reporting outcome → sustained control evidence.

The FCA's current wholesale-bank supervision material separately emphasises end-to-end testing, data lineage, completeness controls, reconciliation and alerts for stale or incomplete feeds.

Primary source — FCA Wholesale Banks Supervision ↗

Related synthesis

Data-Boundary & Coverage Failures

Go deeper into the upstream population, mapping and reference-data dependencies that can cause a functioning control to operate on the wrong scope.

Explore the data-boundary synthesis →

Related synthesis

Why Financial Crime Remediation Fails

Examine why known control weaknesses can persist even after fixes, programmes and formal remediation activity begin.

Explore remediation failure →