top of page

Why banks and other financial institutions get fined, and why the gap stays open for years

  • Writer: FinScan
    FinScan
  • 5 hours ago
  • 9 min read



Financial institutions are fined for failures in their systems and controls. Enforcement notices have a lot in common, whatever the size of the fine. Read them and the same pattern keeps appearing. Something in the business changed, the controls stayed as they were, and the gap between them stayed open long after someone inside the company had spotted it.


The size, age or license doesn't seem to matter, and neither does the regulator. The same story turns up in the UK, the US and the EU, at banks a few years old, banks with a century of history, broker-dealers, money transmitters and payments companies.


What enforcement notices say about why banks and payments companies are fined


The FCA's October 2024 notice against Starling Bank describes a bank that grew from about 43,000 customers in 2017 to 3.6 million in 2023, with financial crime controls that didn't keep pace with the business. Nine months later the FCA used almost the same words about Monzo, which went from around 600,000 customers in 2018 to more than 5.8 million in 2022.


The New York Department of Financial Services fined Block in April 2025 over policies and processes that hadn't kept up with its growth while the OCC's 2024 consent order against TD Bank says the bank chased growth without first building the compliance program to support it.


Growth is a change regulators often cite, because customer numbers are easy to point to. Acquisitions, new products, new markets and system changes are reasons to revisit controls and technology settings. Failure to do so can also create common pitfalls for missing important signals that point to suspicious activity or bad actors.


The changes that put financial crime controls at risk


A screening setup reflects choices about which customers and payments go through it, which lists it runs against and where the thresholds sit. Those choices were right for the institution that existed when they were made. Each change below moves the population, the data, or both.


Various changes can put financial crime controls at risk.
Various changes can put financial crime controls at risk.

Volume growth. Growth changes how much a control can handle. The FCA found that Monzo's onboarding, customer risk assessment and monitoring hadn't been designed or maintained to match a customer base that grew almost tenfold between 2018 and 2022. Some customers were onboarded with obviously implausible addresses.


New products and channels. Block added Bitcoin to Cash App. Under the settings the NYDFS order describes, alerts didn't fire until a receiving wallet had more than 1% exposure to wallets connected to terrorism, and wallets weren't blocked until that exposure passed 10%. Transactions involving mixing services were rated medium risk for years.


New markets and corridors. A new country brings its own sanctions regimes, list obligations and PEP definitions, along with names in scripts and formats the matching rules have never seen. Rules tuned for a domestic customer base struggle with transliterated names and different name orders. A new market can also bring a new supervisor. After Brexit, Wise's European business moved under a Belgian license, and the National Bank of Belgium reviewed it as part of a market-wide exercise. The review found Wise lacked proof of address for hundreds of thousands of customers, as reported by the Financial Times, and Wise was put into a formal remediation plan.


Acquisitions and carve-outs. Acquired customers arrive with the seller's CDD standard, data model and screening history. The buyer owns all of it from the day the deal closes. Records that matched reliably in the seller's system may not match in the buyer's, and the customers may sit outside the risk appetite applied to everyone else. US bank M&A picked up sharply through 2025, with more than 150 deals announced.


Partner and platform distribution. When customers come in through a partner, an agent, a marketplace or an embedded finance deal, screening runs on data someone else collected. Missing middle names, cut-off addresses, mixed date formats and empty country fields weaken matching. Those gaps are already in the records by the time they reach screening.


System migrations and configuration changes. Starling's screening system was set up incorrectly from July 2017, so customers were screened against only part of the UK sanctions list. Between July 2022 and January 2023 that meant 39 of the 3,088 designated people on it, and the system produced no sanctions alerts for individual customers. Those were the months when new designations were being added after the invasion of Ukraine. Nothing looked wrong from the outside, which is part of why the problem lasted nearly six years.


Changes in the customer, not the institution. The mix of customers shifts over time without anyone deciding to change it, toward business accounts, non-residents or higher-risk sectors. Individual customers change too. FINRA's August 2026 findings against UBS Financial Services describe retail customers with links to higher-risk countries, unexplained changes in where they lived and worked, adverse media and possible political exposure, none of it picked up. Their risk ratings stayed low, so their money movements drew less attention.


Why known control gaps stay open for years


In August 2026 FinCEN fined UBS Financial Services $125m, the largest Bank Secrecy Act penalty ever imposed on a broker-dealer, with parallel SEC, FINRA and CFTC actions bringing the total to $173m. FinCEN had previously fined them $14.5m in 2018 over foreign currency wire monitoring. UBS said it would fix the problems. The new order, which covers January 2019 to June 2023, found the same failures continuing. FinCEN learned about them through its own investigation, not from UBS.


The FCA raised serious concerns with Starling during its 2021 review of challenger bank controls. Starling agreed to stop onboarding high-risk customers until it had dealt with them, then opened more than 54,000 accounts for 49,000 high-risk customers between September 2021 and November 2023. Monzo had a supervisory review in late 2017, followed by a letter setting out weaknesses in onboarding data, risk assessment and enhanced due diligence. It later signed up over 34,000 high-risk customers while a similar restriction applied. The FCA added £10m to Monzo's penalty for that alone.


... the company had documented their operational problems and chose to continue with the risk.

TD Bank launched Zelle in 2017. Its own AML investigators flagged that the monitoring system had no rules covering the new payment type. They asked for Zelle-specific rules in October 2020, and the rules went live in 2023. In between, AML managers were told that new scenario development counted as regrettable spend unless it was absolutely required.


Six state regulators fined Wise US $4.2m in July 2025, partly for not correcting deficiencies earlier examinations and its own audits had already found. In July 2026 the OCC denied it a national trust bank charter, citing longstanding AML deficiencies and management that had shown a persistent inability to manage money laundering and terrorist financing risk. The charter would have given Wise direct access to the US payment system.


The common thread in each case was the company had documented their operational problems and chose to continue with the risk.


How to check whether your screening still fits the business you have now



Institutions that catch this early ask a short set of questions when something changes, rather than waiting for the next scheduled review.


Does the screened population match the real one? The number of customer records going through screening should match the number of customers on file. The payments screened should match what the payment systems processed. When Starling corrected its configuration and rescreened its existing customers, it produced roughly 48,000 alerts.


Which lists, and which entries within them? A vendor can deliver a full list on time and the screening system can still load only part of it. Filters applied when the data comes in, such as one that keeps only entries with a domestic link or only individuals rather than companies, narrow what gets screened against while everything appears to be working. The check is against the source list, not against the confirmation that the feed arrived.


Has anyone tested it against a known match? Starling ran for nearly six years without anyone putting a designated party through the live flow to see whether it alerted.


What is the quality of the data going in? Screening only works on the party data it's given. Incomplete names, missing dates of birth, addresses in one long line of free text and empty country fields all weaken matching, however well the engine is tuned. The move to structured addresses under ISO 20022 is making the same issue easier to see in payment flows.


Does the record get looked at again when the customer changes? A risk rating set at onboarding doesn't stay accurate on its own. Adverse media, a move abroad, a new political role or a new controlling owner all change the customer without changing the record. Ongoing screening against media, PEP and watchlist sources picks those changes up between reviews.


Who owns each open finding, and what happens when the date slips? Enforcement notices reconstruct the internal trail, including who raised a gap and what they were told in return. TD's request for Zelle rules sat for more than two years, and the answer its AML managers got is now quoted in a public consent order.


Where else this shows up: payments companies and insurers


Obligations follow the activity, not the license. The UBS orders were against a broker-dealer, and the Block and Wise orders against money transmitters. The same questions work for a payments company onboarding merchants through a platform, or adding a new corridor. Insurers screen at issue and again at claim, because the parties include policyholders, beneficiaries, claimants, brokers and the owners behind corporate policyholders. A claim can be paid years after the policy was written.


Most of the companies named here fixed the problem once they started. Outside testing found Starling's systems working properly by November 2023 for customer screening and March 2024 for payment screening, about a year after the internal review that found it. The notice itself covers failings between December 2019 and November 2023.


Frequently asked questions


What can an unresolved control gap cost beyond the fine?

The bigger cost is usually growth. An open gap can block a license, delay a market entry or hold up a product launch, and supervisors can restrict what the business sells while remediation runs. Starling and Monzo spent years under restrictions on onboarding high-risk customers, and the OCC's refusal of Wise's charter in July 2026 closed off direct access to the US payment system.

Growth itself isn't a breach. Regulators have been clear that growing is fine as long as the controls grow with it, and the NYDFS said as much when it fined Block. What draws enforcement is the stretch of time when the business has grown and the controls haven't caught up.

No rule sets a deadline, but regulators weigh the time between finding a gap and closing it, along with whether the institution limited the affected activity while it worked. Starling and Monzo were both marked down for onboarding that carried on after each had agreed to stop, and the FCA added money to Monzo's penalty to deter it. Wise was cited for not correcting deficiencies raised in earlier examinations.

It helps to treat the acquired customers as a new screening population rather than one that arrives already checked. That means looking at what the seller screened against, what its data looks like, whether the records will match once loaded, and whether the customers fit your own risk appetite.

The record suggests it does. FinCEN called UBS Financial Services a repeat offender when it imposed $125m in August 2026, having fined them $14.5m in 2018 over related monitoring weaknesses, and noted that UBS hadn't reported the continuing failures itself. The FCA used the same logic with Monzo.

They generally have to be screened again. When Starling corrected its configuration and rescreened its existing customers, roughly 48,000 alerts came out, and each of those needed review. The size of that lookback depends on how long the gap ran, which is why the delay costs more than the original error.


Sources

  • FinCEN, "FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations," 3 August 2026, and accompanying Consent Order

  • FINRA, "FINRA Fines UBS Financial $20 Million for Anti-Money Laundering Violations," August 2026, with parallel SEC and CFTC orders

  • FCA, Final Notice: Starling Bank Limited, published 2 October 2024, and accompanying press release

  • FCA, Final Notice: Monzo Bank Ltd, 7 July 2025, and accompanying press release

  • NYDFS, Consent Order and press release re: Block, Inc., 10 April 2025

  • Multistate Consent Order, Wise US, Inc., 9 July 2025 (California, Massachusetts, Minnesota, Nebraska, New York and Texas), and NYDFS press release

  • National Bank of Belgium remediation plan for Wise Europe, as reported by the Financial Times, November 2024

  • OCC, decision denying the national trust bank charter application of Wise National Trust, July 2026

  • OCC, Consent Order AA-ENF-2024-77 (TD Bank, N.A.), and FinCEN Consent Order 2024-02, 10 October 2024

bottom of page