Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Financial Intelligence Analysis Unit (FIAU) €1.62m 100 % · 5 cases
- Information and Data Protection Commissioner (IDPC) €1,000 0 % · 1 case
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 2 | €1.3m |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 1 | €69,000 |
| Q2 2026 | 1 | €1,000 |
| Q3 2026 | 2 | €257,721 |
6 cases
31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports €97,622
The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.
Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction
- Published
- 4 Sep 2026
- Settlement Agreement Publication Notice – EM@NEY P.L.C. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination €160,099
At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.
A customer risk assessment belongs before business starts, not in a later remediation project.
Risk-based customer profiles and source of funds
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction; remediation demonstrated
- Published
- 2 Sep 2026
- Settlement Agreement Publication Notice – MiFinity Malta Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register €69,000
Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.
Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The bank continuously attempted to upload reports
- Published
- 6 Mar 2026
- Administrative Measure Publication Notice – BNF Bank p.l.c. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2025 C2D Payment Solutions LimitedMalta: 243,537 EUR against C2D Payment Solutions for ignoring cash risks €243,537
The financial institution did not take into account its customers’ significant cash exposure in its customer risk assessment, so that almost all customers were rated low risk – even with cash deposits of over 100,000 EUR. The Financial Intelligence Analysis Unit (FIAU) imposed 243,537 EUR and a follow-up directive; the fine was open to appeal at the time of publication.
Cash is an explicit high-risk factor – a risk model that ignores it is worthless.
Recognising cash as a risk factor
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 5(5)(a)(ii), 7(1)(c), 7(1)(d), 7(2)(a), 21 PMLFTR
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 23 Jun 2025
- Administrative Measure Publication Notice – C2D Payment Solutions Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2025 OKCoin Europe LimitedMalta: 1.05 million EUR against crypto exchange OKCoin Europe over anti-money laundering deficiencies €1.05m
During an on-site examination in 2023, the Financial Intelligence Analysis Unit (FIAU) found deficiencies at the crypto service provider in its business risk assessment (including product risks), customer risk assessment, customer profiles, ongoing monitoring, suspicious transaction reporting and record-keeping. It imposed 1,054,269 EUR and a follow-up directive; the fine was open to appeal at the time of publication.
Crypto providers are held to the same due diligence standards as banks – the risk assessment must cover their own products.
Anti-money laundering for crypto-assets
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Reg. 5(1), 5(4), 5(5), 7, 11, 15(3), 21 PMLFTR; FIAU Implementing Procedures
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 3 Apr 2025
- Administrative Measure Publication Notice – OKCoin Europe Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link