Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by levelWhat for?
by area of lawAll areas of law
- Money laundering and terrorist financing €356.3m 54 % · 7 cases
- Capital markets and financial supervision €127.5m 19 % · 2 cases
- Consumer protection and online retail €87.1m 13 % · 1 case
- Environment and sustainability €34.1m 5 % · 2 cases
- Information security and cyber €21.6m 3 % · 10 cases
- Whistleblower protection €17.5m 3 % · 4 cases
- Sanctions and export control €9.89m 2 % · 1 case
- Bribery and corruption €4.04m 1 % · 1 case
- AI and digital regulation €367,242 0 % · 2 cases
Who?
by company- The Toronto-Dominion Bank €113m 17 % · 1 case
- UBS Financial Services Inc. €108.4m 16 % · 1 case
- Two Sigma Investments LP und Two Sigma Advisers LP €87.6m 13 % · 1 case
- FleetCor Technologies Inc. (heute Corpay Inc.) €87.1m 13 % · 1 case
- Canaccord Genuity LLC €69.2m 11 % · 1 case
- BMO Capital Markets Corp. €39.9m 6 % · 1 case
- Block, Inc. €36.1m 5 % · 1 case
- Paxos Trust Company, LLC €22.8m 3 % · 1 case
- DWS Investment Management Americas Inc. €17.9m 3 % · 1 case
- J.P. Morgan Securities LLC €16.5m 3 % · 1 case
- 20 more€60m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 1 | €17.9m |
| Q4 2023 | 1 | €913,159 |
| Q1 2024 | 3 | €16.9m |
| Q2 2024 | 1 | €9.23m |
| Q3 2024 | 3 | €947,956 |
| Q4 2024 | 3 | €130m |
| Q1 2025 | 3 | €129.4m |
| Q2 2025 | 1 | €36.1m |
| Q3 2025 | 4 | €32.1m |
| Q4 2025 | 3 | €14.2m |
| Q1 2026 | 2 | €72.6m |
| Q2 2026 | 1 | €1.92m |
| Q3 2026 | 4 | €196.2m |
30 cases
22 Sep 2026 OTC Link LLCOTC Link: 575,000 USD – security policies never completed despite examination findings €501,614
From 2016 to 2025, the operator of the OTC Link ATS trading system lacked complete policies on systems security, access control and vulnerability management as required under Regulation SCI. Although the examiners of the U.S. Securities and Exchange Commission (SEC) had criticised the gaps in several examinations, drafts remained unfinished; the SEC issued a censure and imposed 575,000 USD.
Track supervisory examination findings with a deadline and a responsible person – points that remain open repeatedly become expensive.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Regulation SCI, Rule 1001(a)(1)–(3)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
Original amount 575,000 USD, converted at the ECB reference rate of 22 Sep 2026.
- SEC Censures OTC Link LLC for Repeated Compliance Failures Related to Regulation SCI (22.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Sep 2026 FleetCor Technologies Inc. (heute Corpay Inc.)FleetCor/Corpay pays 100 million USD over hidden fees on fuel cards €87.1m
In 2023, a federal court found by way of summary judgment that the fuel card provider had charged its predominantly small business customers hidden or unauthorised fees and misrepresented savings; an appeals court upheld this in 2026. According to the FTC, the fees added up to hundreds of millions of dollars, and late fees were also charged despite punctual payment. Under the settlement resolving the administrative proceedings, FleetCor and CEO Ronald Clarke are paying 100 million USD for refunds; the order is not yet final.
Fees hidden behind links or in account documents are deemed not to have been disclosed – including vis-à-vis business customers.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Section 5 FTC Act
- Action
- Disgorgement of profits
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- CEO Ronald Clarke is named in the press release as a party involved.
- Published
- 17 Sep 2026
Original amount 100,000,000 USD, converted at the ECB reference rate of 17 Sep 2026.
- FleetCor Agrees to Pay $100 Million to Resolve Administrative Action After Federal Court Finds It Violated the FTC Act Press release of an authority
- FTC Case: Fleetcor Technologies, In the Matter of (Docket 9403) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies €216,375
The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.
Even small financial service providers must keep documented patch policies and regular risk assessments.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
- Published
- 5 Aug 2026
Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Aug 2026 UBS Financial Services Inc.FinCEN: 125 million USD against UBS Financial Services as a repeat offender €108.4m
The US Financial Crimes Enforcement Network (FinCEN) imposed 125 million USD on the broker-dealer – the highest BSA penalty against a broker-dealer to date. UBSFS admitted wilful infringements: the AML programme was inadequate, more than 50,000 foreign currency transfers totalling more than 10 billion USD were not adequately monitored and suspicious activity reports were not filed; it is already the second enforcement action after 2018.
Monitoring gaps left unremedied after an earlier enforcement action lead, the second time round, to a multiple of the original penalty.
- Authority / court
- Financial Crimes Enforcement Network (FinCEN)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Bank Secrecy Act (BSA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- intentional
- Repeat case
- yes
- Mitigating circumstances
- Up to 15 million USD (remaining amount due by 31 May 2028) may be waived to the extent that UBSFS bears the costs of the independent review of its AML programme and implements its recommendations
- Published
- 3 Aug 2026
Original amount 125,000,000 USD, converted at the ECB reference rate of 3 Aug 2026.
- FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations Press release of an authority
- FinCEN Consent Order Imposing Civil Money Penalty – UBS Financial Services Inc. (Number 2026-02) Decision of an authority
- FinCEN Enforcement Actions Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification €1.92m
In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.
Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 30 Apr 2026
Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.
- DFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental Press release of an authority
- Consent Order to Delta Dental 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2026 Canaccord Genuity LLCFinCEN: 80 million USD against Canaccord Genuity over AML and correspondent banking deficiencies €69.2m
The US Financial Crimes Enforcement Network (FinCEN) imposed 80 million USD on the broker-dealer, which admitted wilful BSA infringements: no effective AML programme, no due diligence on correspondent accounts of foreign financial institutions and failure to file suspicious activity reports in connection with securities fraud. Remedial measures that had been promised were not implemented for years.
Implement remedial measures promised in writing to the supervisory authority genuinely and swiftly – years of delay aggravate the later sanction.
- Authority / court
- Financial Crimes Enforcement Network (FinCEN)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Bank Secrecy Act (BSA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 6 Mar 2026
Original amount 80,000,000 USD, converted at the ECB reference rate of 6 Mar 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Feb 2026 Paxful Holdings Inc.Crypto platform Paxful: 4 million USD penalty after guilty plea to BSA infringements €3.36m
Following a guilty plea to charges including conspiracy to operate an unlicensed money transmitting business and to violate the AML obligations of the Bank Secrecy Act, the peer-to-peer crypto platform was sentenced to a penalty of 4 million USD. 112.5 million USD would have been appropriate, but the US Department of Justice (DOJ) found an inability to pay; in December 2025, FinCEN had additionally imposed a civil penalty of 3.5 million USD.
Crypto platforms without registration and KYC face criminal liability – up to the limit of their ability to pay.
- Authority / court
- U.S. Department of Justice
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Travel Act; Verschwörung zum Betrieb eines nicht lizenzierten Geldtransfergeschäfts und zur Verletzung der AML-Pflichten des Bank Secrecy Act
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Mitigating circumstances
- Penalty limited from 112.5 million to 4 million USD because of proven inability to pay
- Published
- 11 Feb 2026
Original amount 4,000,000 USD, converted at the ECB reference rate of 10 Feb 2026.
- Virtual Asset Trading Platform Sentenced for Violating the Travel Act and Other Federal Criminal Charges Press release of an authority
- FinCEN Assesses $3.5 Million Penalty Against Paxful for Facilitating Suspicious Activity Involving Illicit Actors Press release of an authority
- FinCEN Consent Order Imposing Civil Money Penalty – Paxful, Inc. and Paxful USA, Inc. (Number 2025-02) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 IPI Partners, LLCPrivate equity firm IPI held oligarch's funds for four years after designation €9.89m
In 2017/2018, the Chicago fund manager specialising in data centres took in capital from the Russian oligarch Suleiman Kerimov via nested structures and continued to manage this investment for four years after his designation in April 2018. The US Treasury's Office of Foreign Assets Control (OFAC) assessed the case as non-egregious and not voluntarily self-disclosed.
Screen investors through to the beneficial owner and re-check them when new designations occur – nested structures do not protect against liability.
Checking beneficial owners of investors and fund structures
- Authority / court
- U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Ukraine-/Russia-Related Sanctions Regulations (31 C.F.R. part 589); IEEPA
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- No prior violations in five years; cooperation improved significantly only after initially insufficient engagement (including waiver of attorney-client privilege), hence only limited credit
- Published
- 2 Dec 2025
Original amount 11,485,352 USD, converted at the ECB reference rate of 2 Dec 2025.
- OFAC Enforcement Release: IPI Partners, LLC Settles with OFAC for $11,485,352 (02.12.2025) Decision of an authority
- OFAC – 2025 Enforcement Information Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools €2.4m
Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.
Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 14 Oct 2025
Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- DFS Secures More than $19 Million from Auto Insurance Companies over Data Breaches Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Aug 2025 Paxos Trust Company, LLCNYDFS: 26.5 million USD against Paxos over AML deficiencies in Binance business €22.8m
The New York State Department of Financial Services (NYDFS) imposed a penalty of 26.5 million USD on the crypto trust company because Paxos did not maintain an effective BSA/AML programme before 2023: KYC checks and risk ratings were inadequate, and transaction monitoring and suspicious activity reporting procedures had gaps, including in connection with the business relationship with Binance, contrary to a 2020 agreement. In addition, Paxos must invest at least 22 million USD in its compliance programme.
Companies that distribute products via partner platforms must include those platforms' customer and transaction risks in their own AML programme.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- New York Banking Law §§ 39, 44; AML-Vorschriften des NYDFS und Bank Secrecy Act
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 7 Aug 2025
Original amount 26,500,000 USD, converted at the ECB reference rate of 7 Aug 2025.
- In the Matter of Paxos Trust Company, LLC – Consent Order Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Aug 2025 Liberty Mutual Insurance CompanyLiberty Mutual: declination against 4.7 million USD after bribery of Indian state bank employees €4.04m
From 2017 to 2022, the Indian subsidiary Liberty General Insurance paid around 1.47 million USD to employees of six state-owned banks so that they would refer bank customers to its insurance products; the payments were booked as marketing expenses and routed through third parties. The DOJ declined to prosecute; Liberty Mutual is disgorging 4,699,088 USD in profits.
Employees of state-owned banks are public officials – sales commissions paid to them are bribes, even if they are booked as marketing.
Distribution partnerships with state-owned banks, payments disguised as marketing
- Authority / court
- U.S. Department of Justice (Fraud Section; USAO District of Massachusetts)
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- FCPA, 15 U.S.C. § 78dd-2; Corporate Enforcement and Voluntary Self-Disclosure Policy (Declination)
- Action
- Disgorgement of profits
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure (March 2024), full cooperation, root cause analysis, termination of those involved, improved controls including rules on messaging apps.
- Published
- 7 Aug 2025
Original amount 4,699,088 USD, converted at the ECB reference rate of 7 Aug 2025.
- DOJ Declination Letter – Liberty Mutual Insurance Company (07.08.2025) Decision of an authority
- DOJ Criminal Division: CEP Declinations Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jul 2025 Wise US, Inc.Six US states: 4.2 million USD against Wise US over AML programme deficiencies €3.59m
In a coordinated multistate proceeding brought by six states – the New York State Department of Financial Services (NYDFS) with the supervisory authorities of CA, MN, NE, TX and MA – the money transmitter must pay 4.2 million USD. An examination (July 2022 to September 2023) found, among other things, a lack of independent AML reviews at an appropriate frequency, late suspicious activity reports, data quality problems in transaction monitoring and unremedied earlier findings; Wise does not admit any legal infringements and must conduct a lookback.
Remedy findings from earlier examinations and audits on time – otherwise they become a ground for sanctions in their own right.
- Authority / court
- New York State Department of Financial Services (NYDFS) mit den Aufsichtsbehörden von CA, MN, NE, TX und MA
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Bundes- und einzelstaatliches Recht zu Geldtransfer und BSA/AML (u. a. 31 CFR 1022.320)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Remedial measures already initiated and lookback
- Published
- 9 Jul 2025
Original amount 4,200,000 USD, converted at the ECB reference rate of 9 Jul 2025.
- Consent Order – Wise US, Inc. (Multi-State) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Apr 2025 Block, Inc.NYDFS: 40 million USD against Block (Cash App) over AML deficiencies €36.1m
The New York State Department of Financial Services (NYDFS) imposed 40 million USD on the operator of Cash App for serious gaps in its BSA/AML programme, including insufficient customer due diligence, a lack of risk-based controls and untimely transaction monitoring. Rapid growth in 2019/2020 led to a considerable backlog of alerts; an independent monitor is being appointed.
Scale compliance capacity with growth – a backlog of alerts is a supervisory infringement in its own right.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- BSA/AML-, Geldtransfer- und Virtual-Currency-Vorschriften des NYDFS
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Cooperation and remedial measures already initiated
- Published
- 10 Apr 2025
Original amount 40,000,000 USD, converted at the ECB reference rate of 10 Apr 2025.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA €1.92m
When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.
Anyone changing data flows must know the security processes – training development teams is part of cyber defence.
Secure software development and change processes
Missing or inadequate training played a role in the decision.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- PayPal has since remedied the deficiencies.
- Published
- 23 Jan 2025
Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.
- DFS-Pressemitteilung vom 23.01.2025: Cybersecurity-Vergleich mit PayPal, Inc. (2 Mio. $) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jan 2025 Two Sigma Investments LP und Two Sigma Advisers LPTwo Sigma: 90 million USD – known weaknesses in investment models left unremedied for years €87.6m
Employees identified weaknesses in investment models that could affect client returns by March 2019 at the latest, but Two Sigma only acted in August 2023; there were no policies, and one employee made unauthorised changes to more than a dozen models. In addition, separation agreements required employees to declare that they had not filed any complaint with authorities. The U.S. Securities and Exchange Commission (SEC) imposed 90 million USD; Two Sigma had already repaid 165 million USD to clients.
Model risks need a change and approval procedure – and identified weaknesses need a binding deadline for remediation.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Investment Advisers Act of 1940 (Antifraud, Compliance Rule 206(4)-7); Exchange Act Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Mitigating circumstances
- Voluntary repayment of 165 million USD to affected funds and accounts.
Original amount 90,000,000 USD, converted at the ECB reference rate of 16 Jan 2025.
- SEC Charges Two Sigma for Failing to Address Known Vulnerabilities in its Investment Models (16.01.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Jan 2025 BMO Capital Markets Corp.BMO Capital Markets: 40.7 million USD – inadequate supervision of bond desk €39.9m
From December 2020 to May 2023, staff on the agency CMO bond desk sold mortgage-backed bonds worth around 3 billion USD using misleading metrics; the broker-dealer’s supervisory procedures contained no requirements for the structuring and sale of these bonds. BMO paid 19,417,908 USD in disgorgement, 2,241,507 USD in interest and a civil penalty of 19 million USD.
Tailor supervisory procedures to the actual products and sales practices of each desk – generic policies are not enough.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Securities Exchange Act of 1934, Section 15(b)(4)(E) (Failure to supervise)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
Original amount 40,659,415 USD, converted at the ECB reference rate of 13 Jan 2025.
- SEC Charges BMO Capital Markets with Failing to Supervise Agency Bond Desk (13.01.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Nov 2024 Invesco Advisers, Inc.Invesco Advisers: 17.5 million USD for inflated ESG integration percentages €16.2m
From 2020 to 2022, Invesco told clients that 70 to 94 per cent of the parent company's assets under management were ‘ESG integrated’, but counted passive ETFs that did not take ESG into account and had no written definition of ESG integration. The U.S. Securities and Exchange Commission (SEC) imposed 17.5 million USD, a censure and a cease-and-desist order.
Sustainability metrics used in sales need a written definition and a traceable calculation.
Verifiable metrics in ESG marketing
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Investment Advisers Act of 1940
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 8 Nov 2024
Original amount 17,500,000 USD, converted at the ECB reference rate of 8 Nov 2024.
- SEC Charges Invesco Advisers for Making Misleading Statements About Supposed Investment Considerations Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Oct 2024 The Toronto-Dominion BankFederal Reserve: 123.5 million USD against Toronto-Dominion Bank over AML oversight failure €113m
The Board of Governors of the Federal Reserve System imposed 123.5 million USD on the Canadian parent company because it neglected risk management and oversight of its US retail business, so that a US subsidiary was used to launder hundreds of millions of dollars. TD must move the AML programme to the US and commission an independent review of the board and management; the sanctions of all authorities involved (DOJ, FinCEN, OCC) add up to around 3.09 billion USD.
Parent companies are responsible for effective AML oversight of their foreign business – failures there can lead to sanctions running into billions.
- Authority / court
- Board of Governors of the Federal Reserve System
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- US-Anti-Geldwäschegesetze (laut Federal Reserve)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Liability of senior managers
- Independent review of board and management ordered
- Published
- 10 Oct 2024
Original amount 123,500,000 USD, converted at the ECB reference rate of 10 Oct 2024.
- Federal Reserve Board fines Toronto-Dominion Bank $123.5 million for violations related to anti-money laundering laws Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Tradition SEF LLCTradition SEF: 875,000 USD – emergency and security tests not brought before the board €789,284
The swap trading platform did not fully inform its board of the results of emergency, technology risk and penetration tests, did not regularly test its business continuity and disaster recovery capabilities and had no adequate risk management. It also failed to produce documents requested during an examination on time despite extensions of deadlines; the Commodity Futures Trading Commission (CFTC) imposed 875,000 USD.
Contingency plans only count if they are tested regularly and the results are noted by the entire governing body.
- Authority / court
- Commodity Futures Trading Commission (CFTC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Commodity Exchange Act; CFTC-Regeln zu System Safeguards für Swap Execution Facilities
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
Original amount 875,000 USD, converted at the ECB reference rate of 1 Oct 2024.
- CFTC Orders Tradition SEF LLC to Pay $875,000 for System Safeguards Violations … (01.10.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2024 GQG Partners LLCSEC: GQG Partners pays 500,000 US dollars over NDAs and severance agreement €448,229
The asset manager had twelve job applicants sign NDAs that prohibited voluntary reports to authorities, and, in a settlement agreement, required a former employee who had announced a report to the SEC to confirm that he had not initiated any investigation and to withdraw statements already made. The U.S. Securities and Exchange Commission (SEC) took cooperation and remediation into account and imposed 500,000 US dollars.
Companies concluding a settlement with a whistleblower may require neither the withdrawal of nor a waiver of reports to authorities.
Handling announced reports to authorities in separation negotiations
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a); Investment Advisers Act Section 203(e)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 50 to 249
- Mitigating circumstances
- Cooperation with the SEC and prompt remedial measures
- Published
- 26 Sep 2024
Original amount 500,000 USD, converted at the ECB reference rate of 26 Sep 2024.
- In the Matter of GQG Partners LLC, Release No. 34-101200 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Sep 2024 TransUnionSEC: TransUnion pays 312,000 US dollars over waivers of whistleblower awards €282,532
Between May 2019 and September 2023, TransUnion had senior employees waive potential awards for reports to authorities in 29 severance, separation and incentive agreements; three consulting agreements prohibited voluntary disclosures to authorities. As part of a sweep against seven listed companies, TransUnion paid 312,000 US dollars to the U.S. Securities and Exchange Commission (SEC); the contract templates were amended.
Separation and employment agreements must restrict neither reports to authorities nor the entitlement to whistleblower awards.
Whistleblower protection in contract templates (HR/Legal)
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Amendment of the templates after contact by the SEC, information provided to those affected, and cooperation
- Published
- 9 Sep 2024
Original amount 312,000 USD, converted at the ECB reference rate of 9 Sep 2024.
- SEC Charges Seven Public Companies with Violations of Whistleblower Protection Rule Press release of an authority
- In the Matter of TransUnion, Release No. 34-100975 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2024 Nationwide Planning Associates, Inc.; NPA Asset Management, LLC; Blue Point Strategic Wealth Management, LLCSEC: Nationwide Planning and partners pay 240,000 US dollars over reporting prohibitions €217,195
From May 2021 to February 2024, the three New Jersey firms had eleven retail clients sign confidentiality agreements in connection with settlement payments that permitted reports to the SEC only at the SEC's initiative; in some cases, clients had to confirm that they had never contacted and would never contact authorities. Penalties imposed by the U.S. Securities and Exchange Commission (SEC): 160,000 (NPA Asset Management), 70,000 (Nationwide Planning) and 10,000 US dollars (Blue Point).
Complaint settlements with clients must not require an assurance not to contact authorities.
Whistleblower protection in complaint and settlement processes
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 4 Sep 2024
Original amount 240,000 USD, converted at the ECB reference rate of 4 Sep 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC €9.23m
In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.
Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.
Internal escalation of cyber incidents to compliance
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Mar 2024 Delphia (USA) Inc.SEC ‘AI washing’: Delphia pays 225,000 US dollars for fabricated AI use €206,574
From 2019 to 2023, the investment adviser claimed to use AI and machine learning to analyse client data for investment decisions but did not have these capabilities. In a settlement with the U.S. Securities and Exchange Commission (SEC) (without admission), Delphia paid 225,000 US dollars.
Statements about the use of AI in marketing and investor information must be technically verifiable.
Permissible advertising claims about AI capabilities
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- Investment Advisers Act of 1940; Marketing Rule
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 18 Mar 2024
Original amount 225,000 USD, converted at the ECB reference rate of 18 Mar 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Mar 2024 Global Predictions Inc.SEC ‘AI washing’: Global Predictions pays 175,000 US dollars for AI advertising promises €160,668
In 2023, the investment adviser falsely advertised itself as the ‘first regulated AI financial advisor’ offering AI-driven expert forecasts, misrepresented tax-loss harvesting and used impermissible liability clauses. In a settlement with the U.S. Securities and Exchange Commission (SEC), the company paid 175,000 US dollars.
Superlatives such as ‘first AI adviser’ are statements of fact and must be checked before publication.
Permissible advertising claims about AI capabilities
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- Investment Advisers Act of 1940; Marketing Rule
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 18 Mar 2024
Original amount 175,000 USD, converted at the ECB reference rate of 18 Mar 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jan 2024 J.P. Morgan Securities LLCSEC: J.P. Morgan Securities pays 18 million US dollars over gagging clauses in client settlements €16.5m
From March 2020 to July 2023, JPMS had hundreds of retail clients who received credits or settlement payments of more than 1,000 US dollars sign confidentiality agreements that permitted responses to SEC enquiries but prohibited voluntary contact with the SEC. The U.S. Securities and Exchange Commission (SEC) imposed 18 million US dollars.
Confidentiality clauses with clients must not exclude voluntary reporting to supervisory authorities either.
Whistleblower protection in settlement and confidentiality agreements
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Published
- 16 Jan 2024
Original amount 18,000,000 USD, converted at the ECB reference rate of 16 Jan 2024.
- J.P. Morgan to Pay $18 Million for Violating Whistleblower Protection Rule Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2023 First American Title Insurance CompanyNYDFS: $1 million against First American over open document links €913,159
The EaglePro application generated links to transaction documents without login and without an expiry date; according to a journalist, by changing the sequential document number, 885 million documents containing, among other things, social security and bank data could be retrieved. Users were told not to send sensitive data, but there were no technical barriers. The penalty was imposed by the New York State Department of Financial Services (NYDFS).
Instructions to users do not replace technical controls – sharing links need authentication and an expiry date.
Classification and sending of sensitive documents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR §§ 500.3, 500.7 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 1,000,000 USD, converted at the ECB reference rate of 27 Nov 2023.
- Consent Order to First American Title Insurance Company Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Sep 2023 DWS Investment Management Americas Inc.DWS Investment Management Americas: 19 million USD for misleading ESG statements €17.9m
From 2018 until the end of 2021, the Deutsche Bank subsidiary presented ESG as part of its ‘DNA’ but did not implement the ESG integration policies it had promised. It is paying 19 million USD for the ESG misstatements; in separate proceedings over deficiencies in its anti-money laundering programme, a further 6 million USD was added.
ESG marketing statements must be backed by processes that are actually practised and documented; otherwise they become a regulatory risk.
Truthful sustainability communication in sales and marketing
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Sections 206(2), 206(4) Investment Advisers Act; Rules 206(4)-7 und 206(4)-8
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 25 Sep 2023
Original amount 19,000,000 USD, converted at the ECB reference rate of 25 Sep 2023.
Checked against the official source on 25 Sep 2026 · Direct link