Cross-Case Failure Intelligence · Synthesis 03

Why Financial Crime Remediation Fails.

Enforcement evidence repeatedly shows that identifying a weakness and starting a programme are not the same as removing the underlying risk. Sustainable remediation requires causal scope, complete implementation, outcome evidence and durable control operation.

Published by FCRisk · Last reviewed: 27 August 2026
FCRisk synthesis

The difficult part is not opening the issue. It is proving that the risk has been removed.

Across selected cases, remediation failure takes several forms: known weaknesses remain open for years; a technical fix is implemented without sustained verification; improvement programmes address symptoms but not underlying weaknesses; audit or regulatory findings fail to convert into accountable closure; or rapid business change overtakes the remediation design.

Closure standard

FindingRoot causeComplete scopeFixImpact reviewEffectiveness evidenceSustained operation
Six recurring remediation failure modes

Why formally active remediation can still leave residual risk.

01

Known issue, weak conversion to action

Concerns are identified by regulators, audit or employees but do not produce timely, accountable corrective action.

02

Fix without sustained verification

A defect is corrected, but no control proves that the corrected process remains complete and effective.

03

Symptom remediation

Individual gaps are improved while underlying architecture, ownership or operating-model weaknesses remain.

04

Closure without effectiveness evidence

Policies, code or artefacts exist, but outcome testing and independent challenge do not demonstrate the intended risk reduction.

05

Remediation cannot keep pace with change

Growth, products, channels or risk exposure evolve faster than the control uplift.

06

Repeat failure / recidivism

Previously identified deficiencies reappear or remain materially unresolved after formal commitments.

Primary-source evidence

Cases where the remediation story matters as much as the original defect.

7 evidence anchors
Underlying weaknessSantander UK · FCA

Earlier improvements did not adequately address the underlying weaknesses.

Official finding. Santander began an improvement programme in 2013; the FCA states that although changes produced some improvements, Santander later concluded they did not adequately address the underlying weaknesses and in 2017 decided on a comprehensive restructuring of processes and systems.

FCRisk synthesis. A programme can deliver activity and still fail causal closure if the target state does not address structural drivers of the weakness.

Primary source — FCA ↗

Audit findingDanske Bank · Central Bank of Ireland

Internal audit identified monitoring inadequacies before adequate corrective action.

Official finding. The Central Bank of Ireland's enforcement narrative links long-standing monitoring exclusions with an internal-audit finding and delayed adequate remediation.

FCRisk synthesis. Assurance only protects the firm if findings are translated into owned, timely and evidenced corrective action.

Primary source — Central Bank of Ireland ↗

Repeatedly highlightedGuaranty Trust Bank UK · FCA

Weaknesses were repeatedly raised but not fixed appropriately.

Official finding. The FCA states that AML weaknesses were repeatedly highlighted to GT Bank by internal and external sources, including the FCA, but the bank failed to take appropriate action to fix them.

FCRisk synthesis. Repeat findings are a signal to examine issue ownership, root-cause scope, closure governance and the quality of effectiveness testing — not just the individual control action.

Primary source — FCA ↗

Growth · Resourcing · ChangeTD Bank · DOJ / OCC

Known deficiencies remained while risk, products and the business evolved.

Official finding. DOJ states that TD's monitoring programme remained effectively static for years despite known deficiencies, emerging risks and new products/services; the OCC separately imposed growth restrictions and measures intended to ensure sufficient remediation resources.

FCRisk synthesis. Sustainable remediation must be designed against the future operating state, not only the business that existed when the issue was first raised.

Primary source — U.S. DOJ ↗ · Primary source — OCC ↗

FCRisk remediation test

Closure should be evidence of risk removal, not completion of activity.

A defensible closure argument should connect the original finding to root cause, affected population, implemented change, retrospective impact, effectiveness testing and sustained operation.

Seven closure questions

1. What exactly failed?

2. What caused it, including upstream/downstream dependencies?

3. What is the complete affected population and period?

4. Does the fix remove the cause or only the symptom?

5. What retrospective impact or lookback is required?

6. What evidence proves the control now achieves its intended outcome?

7. What ongoing control would detect recurrence?

FCRisk → NFRisk boundary

Intelligence becomes transformation when action is required.

FCRisk: what do enforcement cases reveal about why remediation fails?

NFRisk: how should a remediation or transformation mandate be structured, governed and assured to address the underlying capability?

Related synthesis

Data-Boundary & Coverage Failures

Many remediation programmes fail when they correct a downstream symptom but do not prove the upstream population and data boundary.

Explore data-boundary failures →