Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
- Money laundering and terrorist financing €662.2m 63 % · 48 cases
- Capital markets and financial supervision €163.8m 16 % · 29 cases
- Consumer protection and online retail €89.3m 8 % · 6 cases
- Environment and sustainability €34.1m 3 % · 2 cases
- Information security and cyber €33m 3 % · 16 cases
- Data protection €20.2m 2 % · 23 cases
- Whistleblower protection €17.5m 2 % · 4 cases
- Sanctions and export control €15.4m 1 % · 2 cases
- Competition law €11.6m 1 % · 2 cases
- Bribery and corruption €4.04m 0 % · 2 cases
- 1 more€367,242
Who?
by company- The Toronto-Dominion Bank €113m 11 % · 1 case
- UBS Financial Services Inc. €108.4m 10 % · 1 case
- Xeltox Enterprises Ltd. (Cryptomus) €108.1m 10 % · 1 case
- Two Sigma Investments LP und Two Sigma Advisers LP €87.6m 8 % · 1 case
- FleetCor Technologies Inc. (heute Corpay Inc.) €87.1m 8 % · 1 case
- Canaccord Genuity LLC €69.2m 7 % · 1 case
- Nationwide Building Society €50.4m 5 % · 1 case
- J.P. Morgan SE €45m 4 % · 1 case
- BMO Capital Markets Corp. €39.9m 4 % · 1 case
- Block, Inc. €36.1m 3 % · 1 case
- 120 more€304.2m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 2 | €25.4m |
| Q4 2023 | 6 | €8.17m |
| Q1 2024 | 8 | €25.2m |
| Q2 2024 | 3 | €18.4m |
| Q3 2024 | 4 | €1.9m |
| Q4 2024 | 11 | €157.3m |
| Q1 2025 | 13 | €142.3m |
| Q2 2025 | 10 | €41.4m |
| Q3 2025 | 20 | €70.1m |
| Q4 2025 | 19 | €245.4m |
| Q1 2026 | 12 | €76.9m |
| Q2 2026 | 14 | €19.6m |
| Q3 2026 | 14 | €219.6m |
136 cases
22 Sep 2026 OTC Link LLCOTC Link: 575,000 USD – security policies never completed despite examination findings €501,614
From 2016 to 2025, the operator of the OTC Link ATS trading system lacked complete policies on systems security, access control and vulnerability management as required under Regulation SCI. Although the examiners of the U.S. Securities and Exchange Commission (SEC) had criticised the gaps in several examinations, drafts remained unfinished; the SEC issued a censure and imposed 575,000 USD.
Track supervisory examination findings with a deadline and a responsible person – points that remain open repeatedly become expensive.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Regulation SCI, Rule 1001(a)(1)–(3)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
Original amount 575,000 USD, converted at the ECB reference rate of 22 Sep 2026.
- SEC Censures OTC Link LLC for Repeated Compliance Failures Related to Regulation SCI (22.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Sep 2026 FleetCor Technologies Inc. (heute Corpay Inc.)FleetCor/Corpay pays 100 million USD over hidden fees on fuel cards €87.1m
In 2023, a federal court found by way of summary judgment that the fuel card provider had charged its predominantly small business customers hidden or unauthorised fees and misrepresented savings; an appeals court upheld this in 2026. According to the FTC, the fees added up to hundreds of millions of dollars, and late fees were also charged despite punctual payment. Under the settlement resolving the administrative proceedings, FleetCor and CEO Ronald Clarke are paying 100 million USD for refunds; the order is not yet final.
Fees hidden behind links or in account documents are deemed not to have been disclosed – including vis-à-vis business customers.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Section 5 FTC Act
- Action
- Disgorgement of profits
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- CEO Ronald Clarke is named in the press release as a party involved.
- Published
- 17 Sep 2026
Original amount 100,000,000 USD, converted at the ECB reference rate of 17 Sep 2026.
- FleetCor Agrees to Pay $100 Million to Resolve Administrative Action After Federal Court Finds It Violated the FTC Act Press release of an authority
- FTC Case: Fleetcor Technologies, In the Matter of (Docket 9403) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers €177,187
As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.
Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- No established damage to investors; remedial measures already taken during the investigation.
- Published
- 16 Sep 2026
Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.
- FI ger AIFM Capital en anmärkning och en sanktionsavgift (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies Order
Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.
Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 16 Sep 2026
- Finantsinspektsioon tegi Wallester AS-ile ettekirjutuse (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports €97,622
The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.
Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction
- Published
- 4 Sep 2026
- Settlement Agreement Publication Notice – EM@NEY P.L.C. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination €160,099
At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.
A customer risk assessment belongs before business starts, not in a later remediation project.
Risk-based customer profiles and source of funds
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction; remediation demonstrated
- Published
- 2 Sep 2026
- Settlement Agreement Publication Notice – MiFinity Malta Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect €11.5m
From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.
Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.
Coordination of terms and conditions among competitors
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 17 Aug 2026
Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.
- Chairman of the Czech Competition Authority Definitively Confirms Fines for Meal Voucher Issuers’ Cartel Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Aug 2026 Citibank, N.A., London BranchOFSI imposes 4.7 million GBP on Citibank London over Russia payments €5.54m
Mainly between February and November 2022, the London branch processed 970 payments totalling around 19.7 million GBP that breached Russia and anti-corruption sanctions. The causes were overloaded alert handling after the wave of designations, delayed escalation and human error; the bank voluntarily disclosed most of the breaches and received a 20% reduction from HM Treasury's Office of Financial Sanctions Implementation (OFSI).
During waves of designations, alert handling needs additional trained capacity – backlogs and wrong decisions in screening are themselves sanctions breaches.
Handling sanctions alerts, escalation and freezing
- Authority / court
- HM Treasury, Office of Financial Sanctions Implementation (OFSI)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Russia (Sanctions) (EU Exit) Regulations 2019; Global Anti-Corruption Sanctions Regulations 2021; s. 146 Policing and Crime Act 2017
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Predominantly voluntary disclosure and cooperation (20% reduction); exceptional burden caused by the 2022 sanctions packages taken into account
- Published
- 2 Sep 2026
Original amount 4,732,830.58 GBP, converted at the ECB reference rate of 11 Aug 2026.
- OFSI: Imposition of Monetary Penalty – Citibank, N.A., London Branch Decision of an authority
- OFSI – Enforcement of financial sanctions (Sammlung) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies €216,375
The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.
Even small financial service providers must keep documented patch policies and regular risk assessments.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
- Published
- 5 Aug 2026
Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Aug 2026 UBS Financial Services Inc.FinCEN: 125 million USD against UBS Financial Services as a repeat offender €108.4m
The US Financial Crimes Enforcement Network (FinCEN) imposed 125 million USD on the broker-dealer – the highest BSA penalty against a broker-dealer to date. UBSFS admitted wilful infringements: the AML programme was inadequate, more than 50,000 foreign currency transfers totalling more than 10 billion USD were not adequately monitored and suspicious activity reports were not filed; it is already the second enforcement action after 2018.
Monitoring gaps left unremedied after an earlier enforcement action lead, the second time round, to a multiple of the original penalty.
- Authority / court
- Financial Crimes Enforcement Network (FinCEN)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Bank Secrecy Act (BSA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- intentional
- Repeat case
- yes
- Mitigating circumstances
- Up to 15 million USD (remaining amount due by 31 May 2028) may be waived to the extent that UBSFS bears the costs of the independent review of its AML programme and implements its recommendations
- Published
- 3 Aug 2026
Original amount 125,000,000 USD, converted at the ECB reference rate of 3 Aug 2026.
- FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations Press release of an authority
- FinCEN Consent Order Imposing Civil Money Penalty – UBS Financial Services Inc. (Number 2026-02) Decision of an authority
- FinCEN Enforcement Actions Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps €210,000
Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.
Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.
Ongoing monitoring of business relationships and suspicious activity reporting
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 17 Sep 2026
- Volksbank Düsseldorf Neuss eG: Bafin setzt Bußgelder fest Press release of an authority
- Bekanntmachung zur Volksbank Düsseldorf Neuss eG (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time €187,500
The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.
Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.
Threshold monitoring and notification deadlines for shareholdings
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- § 33 Abs. 1 Satz 1 WpHG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 22 Jul 2026
- Brown Capital Management LLC: BaFin setzt Geldbußen fest Decision of an authority
- Bekanntmachung der BaFin zur Brown Capital Management LLC (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR €2.15m
The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.
Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – Moody's Deutschland GmbH (ESMA43-857238790-2075) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR €362,000
Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.
Running daily fines make every delay expensive – supervisory orders need top-management priority.
- Authority / court
- Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Published
- 30 Jun 2026
- Lietuvos bankas, Pranešimas 2026-06-30 (Archivkopie web.archive.org von lb.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options €1m
In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.
Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
- Published
- 26 Jun 2026
- FSMA – Règlement transactionnel Banque Degroof Petercam (26.06.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies €40,000
Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.
Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.
Customer due diligence and suspicious transaction reports
- Authority / court
- Banca d'Italia
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Corrective measures initiated
- Banca Popolare Commerciale Spa – Provvedimento n. 190 del 23 giugno 2026 (AML) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jun 2026 CACEIS Bank (UK Branch)FCA: public censure for CACEIS UK over deficient checks on a custody client Reprimand or warning
The UK Financial Conduct Authority (FCA) issued a public censure because the London branch opened and operated accounts for the wealth manager WealthTek, although its own register searches showed that it lacked permissions to hold client assets, and overlooked a restriction noted in the register; 16 monitoring alerts were not worked through over two years, and more than £314 million flowed through the accounts. In view of cooperation and a voluntary payment of £31.7 million to WealthTek clients, the FCA refrained from imposing a fine (otherwise £23.1 million after discount).
Anyone who notices a discrepancy in the register must clarify and document it before accounts are activated.
Register checks and follow-up on identified KYC gaps
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Section 205 FSMA (Public Censure) wegen Verstoßes gegen FCA Principle 2; Maßstab u. a. SYSC 6.1.1R, 6.3.1R, 6.3.3R und Regulations 18, 27, 28 MLR 2017
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cooperation, acknowledgement of the deficiencies and a voluntary payment of £31,714,068 to those harmed
- Published
- 25 Jun 2026
- Final Notice 2026: CACEIS Bank (UK Branch) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence €12.9m
For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.
The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.
Enhanced due diligence for high-risk customers
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 17 Jun 2026
Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.
- FI ger Ikano Bank en anmärkning och en sanktionsavgift (17.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients €100,000
For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.
When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.
Appropriateness assessment when selling complex products
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
- Action
- Other
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 24 Aug 2026
- CySEC Board Decision – Robomarkets Ltd – Settlement €100.000 Decision of an authority
- CySEC Board Decisions Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists €400,000
The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.
Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.
Insider lists and handling of inside information
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Market abuse and insider dealing
- Legal basis
- Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
- Published
- 15 May 2026
- Finanssivalvonta – Oma Säästöpankki Oyj:lle 400 000 euron yhteinen seuraamusmaksu (15.5.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2026/227 vom 13.05.2026 (Oma Säästöpankki Oyj) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary €150,000
One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.
Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.
Care in master data maintenance / register reconciliation
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi du 4 avril 2014 relative aux assurances, Art. 259
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- IT adjustments to prevent recurrence.
- Published
- 5 May 2026
- FSMA – Règlement transactionnel P&V Assurances SC (05.05.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification €1.92m
In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.
Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 30 Apr 2026
Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.
- DFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental Press release of an authority
- Consent Order to Delta Dental 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Liquidnet Canada Inc.Liquidnet Canada: confidential order data passed on to unauthorised persons €369,572
The operator of alternative trading systems passed on confidential order and trading information from its fixed income and equity platforms to unauthorised employees, lacked adequate safeguards and was initially not forthcoming with the regulator. Sanctions: administrative penalty of 600,000 CAD, 75,000 CAD in costs, a reprimand and an external review.
Technically restrict access rights to confidential client data and review them regularly – and make complete reports to the regulator.
Need-to-know principle and protection of confidential trading data
- Authority / court
- Capital Markets Tribunal (Ontario) auf Antrag der Ontario Securities Commission
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- National Instrument 21-101, s. 5.10(1)-(3); Securities Act (Ontario) ss. 127(1), 127.1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cooperation, self-report, no prior record
Original amount 600,000 CAD, converted at the ECB reference rate of 15 Apr 2026.
- Oral Reasons for Approval of a Settlement: Ontario Securities Commission v Liquidnet Canada Inc Court decision
- Proceeding: Ontario Securities Commission v Liquidnet Canada Inc Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Mar 2026 13010431 Canada Inc. (Necosmart)FINTRAC: 693,742 CAD against crypto service provider Necosmart over missing suspicious transaction reports €434,295
The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 693,742.50 CAD on the Edmonton money services business, which also exchanges virtual currencies, for five violations: repeated failure to file suspicious transaction reports, lack of written compliance policies, insufficient enhanced measures for high-risk transactions, lack of a risk assessment and incomplete records of occupation and transactions for crypto exchanges.
Small crypto exchange offices need the same basic framework as banks: risk analysis, policies, enhanced scrutiny and reporting.
Recognising and reporting grounds for suspicion in crypto exchange
- Authority / court
- Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 14 May 2026
Original amount 693,742.5 CAD, converted at the ECB reference rate of 27 Mar 2026.
- FINTRAC imposes an administrative monetary penalty on 13010431 Canada Inc. Press release of an authority
- Public notice of administrative monetary penalties Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Mar 2026 Dinosaur Merchant Bank LimitedDinosaur Merchant Bank: 338,000 GBP – CFD trading without market abuse surveillance €389,760
After a new order management system was introduced in June 2024, CFD transactions with an underlying value of around 3.05 billion USD were not captured by automated trade surveillance. The bank identified the error in October 2024 but only remedied it in May 2025; the Financial Conduct Authority (FCA) imposed 338,000 GBP after a 30% cooperation discount.
With every system migration, check whether surveillance systems actually capture the new data flows.
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 16 Abs. 2 UK MAR; SYSC 6.1.1R; FCA Principle 3
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Full cooperation (30% discount); CFD business discontinued in May 2025.
Original amount 338,000 GBP, converted at the ECB reference rate of 27 Mar 2026.
- FCA fines Dinosaur Merchant Bank Limited for market abuse surveillance failures (27.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions €70,000
Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.
Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.
Regulatory reporting
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Admission of the failures / cooperation.
- Published
- 25 Mar 2026
- Finanssivalvonta – Familiam Asset Management Oy:lle 70 000 euron yhteinen seuraamusmaksu (25.3.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2025/1838 vom 25.03.2026 (Familiam Asset Management Oy) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2026 Canaccord Genuity LLCFinCEN: 80 million USD against Canaccord Genuity over AML and correspondent banking deficiencies €69.2m
The US Financial Crimes Enforcement Network (FinCEN) imposed 80 million USD on the broker-dealer, which admitted wilful BSA infringements: no effective AML programme, no due diligence on correspondent accounts of foreign financial institutions and failure to file suspicious activity reports in connection with securities fraud. Remedial measures that had been promised were not implemented for years.
Implement remedial measures promised in writing to the supervisory authority genuinely and swiftly – years of delay aggravate the later sanction.
- Authority / court
- Financial Crimes Enforcement Network (FinCEN)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Bank Secrecy Act (BSA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 6 Mar 2026
Original amount 80,000,000 USD, converted at the ECB reference rate of 6 Mar 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register €69,000
Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.
Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The bank continuously attempted to upload reports
- Published
- 6 Mar 2026
- Administrative Measure Publication Notice – BNF Bank p.l.c. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Feb 2026 MBaer Merchant Bank AGFINMA withdraws MBaer Merchant Bank's licence over serious anti-money laundering deficiencies Order
Following enforcement proceedings, the Swiss Financial Market Supervisory Authority (FINMA) found serious, systematic deficiencies in anti-money laundering due diligence, organisation and risk management; the bank enabled clients to circumvent official asset freezes and executed transactions for sanctioned persons. FINMA had withdrawn the bank's licence and ordered its liquidation; with the withdrawal of the appeal before the Federal Administrative Court, the orders took effect on 27 February 2026. The day before, FinCEN had proposed designating the bank as an institution of primary money laundering concern.
Systematic anti-money laundering and sanctions deficiencies can cost a bank its licence – not just money.
- Authority / court
- Eidgenössische Finanzmarktaufsicht (FINMA)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Schweizer Geldwäschereirecht und Bankenaufsichtsrecht (laut FINMA)
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 50 to 249
- Published
- 27 Feb 2026
- FINMA-Verfahren: MBaer Merchant Bank AG in Liquidation Press release of an authority
- Massnahmen bei MBaer Merchant Bank AG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 BVwG reduces FMA penalty against private bank over unclarified beneficial owners €356,000
From 2017 to 2020, an Austrian bank specialising in private and investment banking had not adequately examined the ownership and control structure of an offshore holding client despite the lack of evidence on shareholders, trust arrangements and beneficial owners. The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the infringement but reduced the additional penalty imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 17 December 2024 from 476,000 to 356,000 EUR (total penalty 436,000 EUR less FMA penalties already paid), because the FMA had taken the seriousness of the offence into account twice and the bank had cooperated, admitted its errors and terminated the client relationship; an appeal on points of law has been permitted.
For offshore holdings with trustees, prove the beneficial owner with supporting documents – a self-declaration is not enough.
Identifying beneficial owners in holding and trust structures
- Authority / court
- Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 17.12.2024
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 9 Abs. 1 erster Satz i. V. m. § 6 Abs. 1 Z 2 FM-GwG; § 35 Abs. 1 und 3 i. V. m. § 34 Abs. 1 Z 2 und Abs. 2 FM-GwG; § 22 Abs. 9 FMABG (Zusatzstrafe)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Reduction by the court because the wrongfulness of the offence had been counted twice, cooperation, admission of the facts and of guilt, and termination of the client relationship
- BVwG W204 2306222-1 vom 20.02.2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR €1.37m
The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.
Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – REGIS-TR S.A. (ESMA43-857238790-1634) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 BVwG upholds 588,000 EUR FMA penalty against major bank over incorrect risk classification €588,000
The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) dismissed the appeal of a listed major Austrian bank and upheld the fine of 588,000 EUR (plus 58,800 EUR in procedural costs) imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 19 November 2024. From 2017 to 2020, the bank had not adequately risk-classified three business relationships and had disregarded sector risks such as gambling and precious metals trading as well as cash intensity; an appeal on points of law has been permitted.
Customers from gambling or precious metals trading with a high share of cash belong in a higher risk class – otherwise the enhanced obligations are missing.
Risk classification of cash-intensive high-risk sectors
- Authority / court
- Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 19.11.2024
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 6 Abs. 5 i. V. m. § 34 Abs. 1 Z 2 und § 35 Abs. 1–3 FM-GwG
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- BVwG W204 2304676-1 vom 17.02.2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Feb 2026 Paxful Holdings Inc.Crypto platform Paxful: 4 million USD penalty after guilty plea to BSA infringements €3.36m
Following a guilty plea to charges including conspiracy to operate an unlicensed money transmitting business and to violate the AML obligations of the Bank Secrecy Act, the peer-to-peer crypto platform was sentenced to a penalty of 4 million USD. 112.5 million USD would have been appropriate, but the US Department of Justice (DOJ) found an inability to pay; in December 2025, FinCEN had additionally imposed a civil penalty of 3.5 million USD.
Crypto platforms without registration and KYC face criminal liability – up to the limit of their ability to pay.
- Authority / court
- U.S. Department of Justice
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Travel Act; Verschwörung zum Betrieb eines nicht lizenzierten Geldtransfergeschäfts und zur Verletzung der AML-Pflichten des Bank Secrecy Act
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Mitigating circumstances
- Penalty limited from 112.5 million to 4 million USD because of proven inability to pay
- Published
- 11 Feb 2026
Original amount 4,000,000 USD, converted at the ECB reference rate of 10 Feb 2026.
- Virtual Asset Trading Platform Sentenced for Violating the Travel Act and Other Federal Criminal Charges Press release of an authority
- FinCEN Assesses $3.5 Million Penalty Against Paxful for Facilitating Suspicious Activity Involving Illicit Actors Press release of an authority
- FinCEN Consent Order Imposing Civil Money Penalty – Paxful, Inc. and Paxful USA, Inc. (Number 2025-02) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Jan 2026 CCV Group B.V.Netherlands: payment institution CCV without integrity risk analysis – 406,125 EUR fine €406,125
Until March 2018, the payment institution had no systematic integrity risk analysis (SIRA) and therefore no systematic identification and analysis of integrity risks for its gatekeeper function. The Dutch central bank (De Nederlandsche Bank, DNB) imposed the fine in 2020; following objection and appeal proceedings, it was fixed at the reduced amount of 406,125 EUR by the decision of 28 January 2026 and was published in July 2026.
Without a documented integrity risk analysis, any money laundering prevention lacks its foundation – and that alone is subject to fines.
- Authority / court
- De Nederlandsche Bank (DNB)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 3:10 Wet op het financieel toezicht (Wft); Art. 10 Besluit prudentiële regels Wft (Bpr)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Mitigating circumstances
- Fine reduced in the objection and appeal proceedings
- Published
- 21 Jul 2026
- Fine for CCV Group B.V. for lack of SIRA Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2026 Cardif Lux Vie S.A.Cardif Lux Vie: 615,000 EUR over deficiencies in money laundering questionnaires and customer files €615,000
An on-site inspection in 2023 revealed that the life insurer in some cases did not handle the mandatory money laundering risk assessment questionnaires in compliance with the rules, that the employees responsible lacked sufficiently precise instructions and that customer files contained many incorrect answers. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 615,000 EUR.
Risk questionnaires are only as good as the guidance given to those who complete them – clear work instructions and training are part of this.
Money laundering risk assessment by employees
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 8-4, 8-5; Règlement CAA 20/03
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Close cooperation with the CAA during and after the inspection; remediation plan for all deficiencies submitted promptly.
- Published
- 1 Jul 2026
- CAA – Sanction administrative Cardif Lux Vie S.A. (01.07.2026) Decision of an authority
- CAA – Sanctions et autres mesures administratives Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link