Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
- Money laundering and terrorist financing €662.2m 63 % · 48 cases
- Capital markets and financial supervision €163.8m 16 % · 29 cases
- Consumer protection and online retail €89.3m 8 % · 6 cases
- Environment and sustainability €34.1m 3 % · 2 cases
- Information security and cyber €33m 3 % · 16 cases
- Data protection €20.2m 2 % · 23 cases
- Whistleblower protection €17.5m 2 % · 4 cases
- Sanctions and export control €15.4m 1 % · 2 cases
- Competition law €11.6m 1 % · 2 cases
- Bribery and corruption €4.04m 0 % · 1 case
- 1 more€367,242
Who?
by company- The Toronto-Dominion Bank €113m 11 % · 1 case
- UBS Financial Services Inc. €108.4m 10 % · 1 case
- Xeltox Enterprises Ltd. (Cryptomus) €108.1m 10 % · 1 case
- Two Sigma Investments LP und Two Sigma Advisers LP €87.6m 8 % · 1 case
- FleetCor Technologies Inc. (heute Corpay Inc.) €87.1m 8 % · 1 case
- Canaccord Genuity LLC €69.2m 7 % · 1 case
- Nationwide Building Society €50.4m 5 % · 1 case
- J.P. Morgan SE €45m 4 % · 1 case
- BMO Capital Markets Corp. €39.9m 4 % · 1 case
- Block, Inc. €36.1m 3 % · 1 case
- 119 more€304.2m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 2 | €25.4m |
| Q4 2023 | 6 | €8.17m |
| Q1 2024 | 8 | €25.2m |
| Q2 2024 | 3 | €18.4m |
| Q3 2024 | 4 | €1.9m |
| Q4 2024 | 10 | €157.3m |
| Q1 2025 | 13 | €142.3m |
| Q2 2025 | 10 | €41.4m |
| Q3 2025 | 20 | €70.1m |
| Q4 2025 | 19 | €245.4m |
| Q1 2026 | 12 | €76.9m |
| Q2 2026 | 14 | €19.6m |
| Q3 2026 | 14 | €219.6m |
135 cases
22 Sep 2026 OTC Link LLCOTC Link: 575,000 USD – security policies never completed despite examination findings €501,614
From 2016 to 2025, the operator of the OTC Link ATS trading system lacked complete policies on systems security, access control and vulnerability management as required under Regulation SCI. Although the examiners of the U.S. Securities and Exchange Commission (SEC) had criticised the gaps in several examinations, drafts remained unfinished; the SEC issued a censure and imposed 575,000 USD.
Track supervisory examination findings with a deadline and a responsible person – points that remain open repeatedly become expensive.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Regulation SCI, Rule 1001(a)(1)–(3)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
Original amount 575,000 USD, converted at the ECB reference rate of 22 Sep 2026.
- SEC Censures OTC Link LLC for Repeated Compliance Failures Related to Regulation SCI (22.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Sep 2026 FleetCor Technologies Inc. (heute Corpay Inc.)FleetCor/Corpay pays 100 million USD over hidden fees on fuel cards €87.1m
In 2023, a federal court found by way of summary judgment that the fuel card provider had charged its predominantly small business customers hidden or unauthorised fees and misrepresented savings; an appeals court upheld this in 2026. According to the FTC, the fees added up to hundreds of millions of dollars, and late fees were also charged despite punctual payment. Under the settlement resolving the administrative proceedings, FleetCor and CEO Ronald Clarke are paying 100 million USD for refunds; the order is not yet final.
Fees hidden behind links or in account documents are deemed not to have been disclosed – including vis-à-vis business customers.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Section 5 FTC Act
- Action
- Disgorgement of profits
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- CEO Ronald Clarke is named in the press release as a party involved.
- Published
- 17 Sep 2026
Original amount 100,000,000 USD, converted at the ECB reference rate of 17 Sep 2026.
- FleetCor Agrees to Pay $100 Million to Resolve Administrative Action After Federal Court Finds It Violated the FTC Act Press release of an authority
- FTC Case: Fleetcor Technologies, In the Matter of (Docket 9403) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers €177,187
As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.
Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- No established damage to investors; remedial measures already taken during the investigation.
- Published
- 16 Sep 2026
Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.
- FI ger AIFM Capital en anmärkning och en sanktionsavgift (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies Order
Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.
Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 16 Sep 2026
- Finantsinspektsioon tegi Wallester AS-ile ettekirjutuse (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports €97,622
The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.
Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction
- Published
- 4 Sep 2026
- Settlement Agreement Publication Notice – EM@NEY P.L.C. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination €160,099
At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.
A customer risk assessment belongs before business starts, not in a later remediation project.
Risk-based customer profiles and source of funds
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction; remediation demonstrated
- Published
- 2 Sep 2026
- Settlement Agreement Publication Notice – MiFinity Malta Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect €11.5m
From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.
Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.
Coordination of terms and conditions among competitors
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 17 Aug 2026
Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.
- Chairman of the Czech Competition Authority Definitively Confirms Fines for Meal Voucher Issuers’ Cartel Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Aug 2026 Citibank, N.A., London BranchOFSI imposes 4.7 million GBP on Citibank London over Russia payments €5.54m
Mainly between February and November 2022, the London branch processed 970 payments totalling around 19.7 million GBP that breached Russia and anti-corruption sanctions. The causes were overloaded alert handling after the wave of designations, delayed escalation and human error; the bank voluntarily disclosed most of the breaches and received a 20% reduction from HM Treasury's Office of Financial Sanctions Implementation (OFSI).
During waves of designations, alert handling needs additional trained capacity – backlogs and wrong decisions in screening are themselves sanctions breaches.
Handling sanctions alerts, escalation and freezing
- Authority / court
- HM Treasury, Office of Financial Sanctions Implementation (OFSI)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Russia (Sanctions) (EU Exit) Regulations 2019; Global Anti-Corruption Sanctions Regulations 2021; s. 146 Policing and Crime Act 2017
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Predominantly voluntary disclosure and cooperation (20% reduction); exceptional burden caused by the 2022 sanctions packages taken into account
- Published
- 2 Sep 2026
Original amount 4,732,830.58 GBP, converted at the ECB reference rate of 11 Aug 2026.
- OFSI: Imposition of Monetary Penalty – Citibank, N.A., London Branch Decision of an authority
- OFSI – Enforcement of financial sanctions (Sammlung) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies €216,375
The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.
Even small financial service providers must keep documented patch policies and regular risk assessments.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
- Published
- 5 Aug 2026
Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Aug 2026 UBS Financial Services Inc.FinCEN: 125 million USD against UBS Financial Services as a repeat offender €108.4m
The US Financial Crimes Enforcement Network (FinCEN) imposed 125 million USD on the broker-dealer – the highest BSA penalty against a broker-dealer to date. UBSFS admitted wilful infringements: the AML programme was inadequate, more than 50,000 foreign currency transfers totalling more than 10 billion USD were not adequately monitored and suspicious activity reports were not filed; it is already the second enforcement action after 2018.
Monitoring gaps left unremedied after an earlier enforcement action lead, the second time round, to a multiple of the original penalty.
- Authority / court
- Financial Crimes Enforcement Network (FinCEN)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Bank Secrecy Act (BSA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- intentional
- Repeat case
- yes
- Mitigating circumstances
- Up to 15 million USD (remaining amount due by 31 May 2028) may be waived to the extent that UBSFS bears the costs of the independent review of its AML programme and implements its recommendations
- Published
- 3 Aug 2026
Original amount 125,000,000 USD, converted at the ECB reference rate of 3 Aug 2026.
- FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations Press release of an authority
- FinCEN Consent Order Imposing Civil Money Penalty – UBS Financial Services Inc. (Number 2026-02) Decision of an authority
- FinCEN Enforcement Actions Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps €210,000
Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.
Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.
Ongoing monitoring of business relationships and suspicious activity reporting
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 17 Sep 2026
- Volksbank Düsseldorf Neuss eG: Bafin setzt Bußgelder fest Press release of an authority
- Bekanntmachung zur Volksbank Düsseldorf Neuss eG (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time €187,500
The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.
Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.
Threshold monitoring and notification deadlines for shareholdings
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- § 33 Abs. 1 Satz 1 WpHG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 22 Jul 2026
- Brown Capital Management LLC: BaFin setzt Geldbußen fest Decision of an authority
- Bekanntmachung der BaFin zur Brown Capital Management LLC (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR €2.15m
The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.
Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – Moody's Deutschland GmbH (ESMA43-857238790-2075) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR €362,000
Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.
Running daily fines make every delay expensive – supervisory orders need top-management priority.
- Authority / court
- Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Published
- 30 Jun 2026
- Lietuvos bankas, Pranešimas 2026-06-30 (Archivkopie web.archive.org von lb.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options €1m
In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.
Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
- Published
- 26 Jun 2026
- FSMA – Règlement transactionnel Banque Degroof Petercam (26.06.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies €40,000
Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.
Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.
Customer due diligence and suspicious transaction reports
- Authority / court
- Banca d'Italia
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Corrective measures initiated
- Banca Popolare Commerciale Spa – Provvedimento n. 190 del 23 giugno 2026 (AML) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jun 2026 CACEIS Bank (UK Branch)FCA: public censure for CACEIS UK over deficient checks on a custody client Reprimand or warning
The UK Financial Conduct Authority (FCA) issued a public censure because the London branch opened and operated accounts for the wealth manager WealthTek, although its own register searches showed that it lacked permissions to hold client assets, and overlooked a restriction noted in the register; 16 monitoring alerts were not worked through over two years, and more than £314 million flowed through the accounts. In view of cooperation and a voluntary payment of £31.7 million to WealthTek clients, the FCA refrained from imposing a fine (otherwise £23.1 million after discount).
Anyone who notices a discrepancy in the register must clarify and document it before accounts are activated.
Register checks and follow-up on identified KYC gaps
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Section 205 FSMA (Public Censure) wegen Verstoßes gegen FCA Principle 2; Maßstab u. a. SYSC 6.1.1R, 6.3.1R, 6.3.3R und Regulations 18, 27, 28 MLR 2017
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cooperation, acknowledgement of the deficiencies and a voluntary payment of £31,714,068 to those harmed
- Published
- 25 Jun 2026
- Final Notice 2026: CACEIS Bank (UK Branch) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence €12.9m
For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.
The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.
Enhanced due diligence for high-risk customers
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 17 Jun 2026
Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.
- FI ger Ikano Bank en anmärkning och en sanktionsavgift (17.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients €100,000
For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.
When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.
Appropriateness assessment when selling complex products
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
- Action
- Other
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 24 Aug 2026
- CySEC Board Decision – Robomarkets Ltd – Settlement €100.000 Decision of an authority
- CySEC Board Decisions Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists €400,000
The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.
Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.
Insider lists and handling of inside information
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Market abuse and insider dealing
- Legal basis
- Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
- Published
- 15 May 2026
- Finanssivalvonta – Oma Säästöpankki Oyj:lle 400 000 euron yhteinen seuraamusmaksu (15.5.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2026/227 vom 13.05.2026 (Oma Säästöpankki Oyj) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary €150,000
One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.
Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.
Care in master data maintenance / register reconciliation
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi du 4 avril 2014 relative aux assurances, Art. 259
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- IT adjustments to prevent recurrence.
- Published
- 5 May 2026
- FSMA – Règlement transactionnel P&V Assurances SC (05.05.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification €1.92m
In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.
Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 30 Apr 2026
Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.
- DFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental Press release of an authority
- Consent Order to Delta Dental 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Liquidnet Canada Inc.Liquidnet Canada: confidential order data passed on to unauthorised persons €369,572
The operator of alternative trading systems passed on confidential order and trading information from its fixed income and equity platforms to unauthorised employees, lacked adequate safeguards and was initially not forthcoming with the regulator. Sanctions: administrative penalty of 600,000 CAD, 75,000 CAD in costs, a reprimand and an external review.
Technically restrict access rights to confidential client data and review them regularly – and make complete reports to the regulator.
Need-to-know principle and protection of confidential trading data
- Authority / court
- Capital Markets Tribunal (Ontario) auf Antrag der Ontario Securities Commission
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- National Instrument 21-101, s. 5.10(1)-(3); Securities Act (Ontario) ss. 127(1), 127.1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cooperation, self-report, no prior record
Original amount 600,000 CAD, converted at the ECB reference rate of 15 Apr 2026.
- Oral Reasons for Approval of a Settlement: Ontario Securities Commission v Liquidnet Canada Inc Court decision
- Proceeding: Ontario Securities Commission v Liquidnet Canada Inc Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Mar 2026 13010431 Canada Inc. (Necosmart)FINTRAC: 693,742 CAD against crypto service provider Necosmart over missing suspicious transaction reports €434,295
The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 693,742.50 CAD on the Edmonton money services business, which also exchanges virtual currencies, for five violations: repeated failure to file suspicious transaction reports, lack of written compliance policies, insufficient enhanced measures for high-risk transactions, lack of a risk assessment and incomplete records of occupation and transactions for crypto exchanges.
Small crypto exchange offices need the same basic framework as banks: risk analysis, policies, enhanced scrutiny and reporting.
Recognising and reporting grounds for suspicion in crypto exchange
- Authority / court
- Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 14 May 2026
Original amount 693,742.5 CAD, converted at the ECB reference rate of 27 Mar 2026.
- FINTRAC imposes an administrative monetary penalty on 13010431 Canada Inc. Press release of an authority
- Public notice of administrative monetary penalties Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Mar 2026 Dinosaur Merchant Bank LimitedDinosaur Merchant Bank: 338,000 GBP – CFD trading without market abuse surveillance €389,760
After a new order management system was introduced in June 2024, CFD transactions with an underlying value of around 3.05 billion USD were not captured by automated trade surveillance. The bank identified the error in October 2024 but only remedied it in May 2025; the Financial Conduct Authority (FCA) imposed 338,000 GBP after a 30% cooperation discount.
With every system migration, check whether surveillance systems actually capture the new data flows.
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 16 Abs. 2 UK MAR; SYSC 6.1.1R; FCA Principle 3
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Full cooperation (30% discount); CFD business discontinued in May 2025.
Original amount 338,000 GBP, converted at the ECB reference rate of 27 Mar 2026.
- FCA fines Dinosaur Merchant Bank Limited for market abuse surveillance failures (27.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions €70,000
Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.
Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.
Regulatory reporting
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Admission of the failures / cooperation.
- Published
- 25 Mar 2026
- Finanssivalvonta – Familiam Asset Management Oy:lle 70 000 euron yhteinen seuraamusmaksu (25.3.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2025/1838 vom 25.03.2026 (Familiam Asset Management Oy) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2026 Canaccord Genuity LLCFinCEN: 80 million USD against Canaccord Genuity over AML and correspondent banking deficiencies €69.2m
The US Financial Crimes Enforcement Network (FinCEN) imposed 80 million USD on the broker-dealer, which admitted wilful BSA infringements: no effective AML programme, no due diligence on correspondent accounts of foreign financial institutions and failure to file suspicious activity reports in connection with securities fraud. Remedial measures that had been promised were not implemented for years.
Implement remedial measures promised in writing to the supervisory authority genuinely and swiftly – years of delay aggravate the later sanction.
- Authority / court
- Financial Crimes Enforcement Network (FinCEN)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Bank Secrecy Act (BSA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 6 Mar 2026
Original amount 80,000,000 USD, converted at the ECB reference rate of 6 Mar 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register €69,000
Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.
Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The bank continuously attempted to upload reports
- Published
- 6 Mar 2026
- Administrative Measure Publication Notice – BNF Bank p.l.c. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Feb 2026 MBaer Merchant Bank AGFINMA withdraws MBaer Merchant Bank's licence over serious anti-money laundering deficiencies Order
Following enforcement proceedings, the Swiss Financial Market Supervisory Authority (FINMA) found serious, systematic deficiencies in anti-money laundering due diligence, organisation and risk management; the bank enabled clients to circumvent official asset freezes and executed transactions for sanctioned persons. FINMA had withdrawn the bank's licence and ordered its liquidation; with the withdrawal of the appeal before the Federal Administrative Court, the orders took effect on 27 February 2026. The day before, FinCEN had proposed designating the bank as an institution of primary money laundering concern.
Systematic anti-money laundering and sanctions deficiencies can cost a bank its licence – not just money.
- Authority / court
- Eidgenössische Finanzmarktaufsicht (FINMA)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Schweizer Geldwäschereirecht und Bankenaufsichtsrecht (laut FINMA)
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 50 to 249
- Published
- 27 Feb 2026
- FINMA-Verfahren: MBaer Merchant Bank AG in Liquidation Press release of an authority
- Massnahmen bei MBaer Merchant Bank AG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 BVwG reduces FMA penalty against private bank over unclarified beneficial owners €356,000
From 2017 to 2020, an Austrian bank specialising in private and investment banking had not adequately examined the ownership and control structure of an offshore holding client despite the lack of evidence on shareholders, trust arrangements and beneficial owners. The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the infringement but reduced the additional penalty imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 17 December 2024 from 476,000 to 356,000 EUR (total penalty 436,000 EUR less FMA penalties already paid), because the FMA had taken the seriousness of the offence into account twice and the bank had cooperated, admitted its errors and terminated the client relationship; an appeal on points of law has been permitted.
For offshore holdings with trustees, prove the beneficial owner with supporting documents – a self-declaration is not enough.
Identifying beneficial owners in holding and trust structures
- Authority / court
- Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 17.12.2024
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 9 Abs. 1 erster Satz i. V. m. § 6 Abs. 1 Z 2 FM-GwG; § 35 Abs. 1 und 3 i. V. m. § 34 Abs. 1 Z 2 und Abs. 2 FM-GwG; § 22 Abs. 9 FMABG (Zusatzstrafe)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Reduction by the court because the wrongfulness of the offence had been counted twice, cooperation, admission of the facts and of guilt, and termination of the client relationship
- BVwG W204 2306222-1 vom 20.02.2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR €1.37m
The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.
Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – REGIS-TR S.A. (ESMA43-857238790-1634) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 BVwG upholds 588,000 EUR FMA penalty against major bank over incorrect risk classification €588,000
The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) dismissed the appeal of a listed major Austrian bank and upheld the fine of 588,000 EUR (plus 58,800 EUR in procedural costs) imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 19 November 2024. From 2017 to 2020, the bank had not adequately risk-classified three business relationships and had disregarded sector risks such as gambling and precious metals trading as well as cash intensity; an appeal on points of law has been permitted.
Customers from gambling or precious metals trading with a high share of cash belong in a higher risk class – otherwise the enhanced obligations are missing.
Risk classification of cash-intensive high-risk sectors
- Authority / court
- Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 19.11.2024
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 6 Abs. 5 i. V. m. § 34 Abs. 1 Z 2 und § 35 Abs. 1–3 FM-GwG
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- BVwG W204 2304676-1 vom 17.02.2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Feb 2026 Paxful Holdings Inc.Crypto platform Paxful: 4 million USD penalty after guilty plea to BSA infringements €3.36m
Following a guilty plea to charges including conspiracy to operate an unlicensed money transmitting business and to violate the AML obligations of the Bank Secrecy Act, the peer-to-peer crypto platform was sentenced to a penalty of 4 million USD. 112.5 million USD would have been appropriate, but the US Department of Justice (DOJ) found an inability to pay; in December 2025, FinCEN had additionally imposed a civil penalty of 3.5 million USD.
Crypto platforms without registration and KYC face criminal liability – up to the limit of their ability to pay.
- Authority / court
- U.S. Department of Justice
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Travel Act; Verschwörung zum Betrieb eines nicht lizenzierten Geldtransfergeschäfts und zur Verletzung der AML-Pflichten des Bank Secrecy Act
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Mitigating circumstances
- Penalty limited from 112.5 million to 4 million USD because of proven inability to pay
- Published
- 11 Feb 2026
Original amount 4,000,000 USD, converted at the ECB reference rate of 10 Feb 2026.
- Virtual Asset Trading Platform Sentenced for Violating the Travel Act and Other Federal Criminal Charges Press release of an authority
- FinCEN Assesses $3.5 Million Penalty Against Paxful for Facilitating Suspicious Activity Involving Illicit Actors Press release of an authority
- FinCEN Consent Order Imposing Civil Money Penalty – Paxful, Inc. and Paxful USA, Inc. (Number 2025-02) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Jan 2026 CCV Group B.V.Netherlands: payment institution CCV without integrity risk analysis – 406,125 EUR fine €406,125
Until March 2018, the payment institution had no systematic integrity risk analysis (SIRA) and therefore no systematic identification and analysis of integrity risks for its gatekeeper function. The Dutch central bank (De Nederlandsche Bank, DNB) imposed the fine in 2020; following objection and appeal proceedings, it was fixed at the reduced amount of 406,125 EUR by the decision of 28 January 2026 and was published in July 2026.
Without a documented integrity risk analysis, any money laundering prevention lacks its foundation – and that alone is subject to fines.
- Authority / court
- De Nederlandsche Bank (DNB)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 3:10 Wet op het financieel toezicht (Wft); Art. 10 Besluit prudentiële regels Wft (Bpr)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Mitigating circumstances
- Fine reduced in the objection and appeal proceedings
- Published
- 21 Jul 2026
- Fine for CCV Group B.V. for lack of SIRA Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2026 Cardif Lux Vie S.A.Cardif Lux Vie: 615,000 EUR over deficiencies in money laundering questionnaires and customer files €615,000
An on-site inspection in 2023 revealed that the life insurer in some cases did not handle the mandatory money laundering risk assessment questionnaires in compliance with the rules, that the employees responsible lacked sufficiently precise instructions and that customer files contained many incorrect answers. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 615,000 EUR.
Risk questionnaires are only as good as the guidance given to those who complete them – clear work instructions and training are part of this.
Money laundering risk assessment by employees
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 8-4, 8-5; Règlement CAA 20/03
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Close cooperation with the CAA during and after the inspection; remediation plan for all deficiencies submitted promptly.
- Published
- 1 Jul 2026
- CAA – Sanction administrative Cardif Lux Vie S.A. (01.07.2026) Decision of an authority
- CAA – Sanctions et autres mesures administratives Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers €1.5m
The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).
Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Dec 2025
- Banci izrečena upravna novčana kazna u iznosu od 1,5 milijuna eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Dec 2025 Nationwide Building SocietyFCA: £44 million against Nationwide over financial crime controls €50.4m
The UK Financial Conduct Authority (FCA) imposed £44,078,500 (after a 30% discount) because, from October 2016 to July 2021, the building society had no effective systems to keep due diligence and risk assessments for personal customers up to date, and did not identify personal accounts used for business purposes. As a result, one customer received 24 fraudulent Covid furlough payments totalling £27.3 million.
Keep customer profiles continuously up to date – anyone who postpones known weaknesses for years ends up paying for the abuse.
Identifying personal accounts used for business purposes
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- FCA Principle 3; SYSC 6.1.1R und 6.3.1R
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- 30% settlement discount
- Published
- 12 Dec 2025
Original amount 44,078,500 GBP, converted at the ECB reference rate of 11 Dec 2025.
- FCA fines Nationwide £44m for failings in financial crime controls Press release of an authority
- 2025 fines | FCA Enforcement database of an authority
- Final Notice: Nationwide Building Society (11.12.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Dec 2025 „ЗП Либра“ ООДZP Libra: 44,205 leva for poaching customers using competitor’s trade secrets €22,602
With the help of an employee of its competitor I&G Insurance Brokers who later moved to ZP Libra, the broker unfairly concluded a brokerage agreement to the detriment of the competitor and used the competitor’s trade secrets to poach customers. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) imposed 29,470 leva (1% of 2024 turnover, Art. 36(1) ZZK – Bulgarian Protection of Competition Act) and 14,735 leva (0.5%, Art. 37(1) ZZK); fines totalling 1,000 leva were also imposed on the employee.
When hiring employees from competitors, make sure they do not bring customer lists or secrets with them – otherwise both the company and the individual are liable.
Taking customer data and trade secrets when changing employer
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 36 Abs. 1, Art. 37 Abs. 1 ZZK
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Fines on the employee involved (1,000 leva in total)
- Published
- 16 Dec 2025
Original amount 44,205 BGN, converted at the ECB reference rate of 11 Dec 2025.
- КЗК Публичен електронен регистър – Производство (Решение № 1175 от 11.12.2025; Volltext als PDF im Register) Official register or notice
- КЗК санкционира „ЗП Либра“ ООД за нелоялна конкуренция, 17.12.2025 (Archivkopie web.archive.org von cpc.bg) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Dec 2025 Invest in OÜLender Invest in OÜ pays 16,000 EUR for failing to submit annual accounts €16,000
The lender did not submit its 2024 annual report, together with the audit report, the resolution on the appropriation of profits and the minutes of the shareholders’ meeting, to the financial supervisory authority on time. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed a fine of 16,000 EUR; the maximum is 1 million EUR or 10% of annual turnover. Date = publication.
Even small supervised lenders need a reliable deadline calendar for mandatory supervisory reports.
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- § 56 Abs. 3, § 96 Abs. 2 KAVS (Gesetz über Kreditgeber und -vermittler)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 10 Dec 2025
- Finantsinspektsioon tegi Invest in OÜ-le 16 000 eurot trahvi (10.12.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 IPI Partners, LLCPrivate equity firm IPI held oligarch's funds for four years after designation €9.89m
In 2017/2018, the Chicago fund manager specialising in data centres took in capital from the Russian oligarch Suleiman Kerimov via nested structures and continued to manage this investment for four years after his designation in April 2018. The US Treasury's Office of Foreign Assets Control (OFAC) assessed the case as non-egregious and not voluntarily self-disclosed.
Screen investors through to the beneficial owner and re-check them when new designations occur – nested structures do not protect against liability.
Checking beneficial owners of investors and fund structures
- Authority / court
- U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Ukraine-/Russia-Related Sanctions Regulations (31 C.F.R. part 589); IEEPA
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- No prior violations in five years; cooperation improved significantly only after initially insufficient engagement (including waiver of attorney-client privilege), hence only limited credit
- Published
- 2 Dec 2025
Original amount 11,485,352 USD, converted at the ECB reference rate of 2 Dec 2025.
- OFAC Enforcement Release: IPI Partners, LLC Settles with OFAC for $11,485,352 (02.12.2025) Decision of an authority
- OFAC – 2025 Enforcement Information Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ €1.5m
When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.
Cookie settings must apply across all domains of a service – including when users move to affiliated sites.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Corrections during the proceedings, cooperation.
- CNIL, Délibération SAN-2025-011 du 27 novembre 2025 (Légifrance) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Nov 2025 Avida Finans ABAvida Finans: 20 million SEK for loans to consumers unable to repay €1.82m
The Swedish financial supervisory authority Finansinspektionen (FI) examined consumer loans granted by the lender over four weeks in summer 2024 and found at least around 30 cases in which consumers without the ability to repay received loans. FI issued a remark and imposed 20 million SEK.
Carry out credit checks consistently even under sales pressure and verify them internally through sample checks.
Creditworthiness assessment in sales
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Consumer protection and online retail
- Legal basis
- Konsumentkreditlagen (2010:1846), Kreditprüfung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Nov 2025
Original amount 20,000,000 SEK, converted at the ECB reference rate of 11 Nov 2025.
- Avida Finans får en anmärkning och en sanktionsavgift för bristande kreditprövningar (11.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Nov 2025 Coinbase Europe LimitedIreland: 21.5 million EUR against Coinbase Europe – 30 million transactions unchecked €21.5m
In a settlement of 5 November 2025, the Central Bank of Ireland imposed a reprimand and 21,464,734 EUR (after a 30% discount on 30,663,906 EUR) for breaches of transaction monitoring obligations between April 2021 and March 2025: because of configuration errors in the monitoring system, more than 30 million transactions worth over 176 billion EUR – around 31% of all transactions – were not properly monitored over a period of twelve months. The subsequent review took almost three years and led to 2,708 suspicious transaction reports; the High Court confirmed the sanction on 12 January 2026, and it is the Central Bank's first enforcement action in the crypto sector.
Test monitoring rules regularly for complete coverage – a silent configuration error can go undetected for years.
- Authority / court
- Central Bank of Ireland
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Published
- 6 Nov 2025
- Enforcement Action against Coinbase Europe Limited Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Oct 2025 Landesbank Hessen-Thüringen Girozentrale (Helaba)BaFin: fine against Helaba over inadequate monitoring systems for money laundering prevention €20,000
By decision of 28 October 2025 (final since 7 November 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 20,000 EUR because, from October 2022 to September 2023, the Landesbank operated data processing systems for money laundering prevention that were only partially adequate. Under the German Banking Act (KWG), the criteria by which monitoring identifies suspicious transactions must be documented, and the systems must be checked regularly by an independent auditor.
Transaction monitoring needs documented indicators and a regular independent quality review – the mere existence of software is not enough.
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- § 56 Abs. 2 Nr. 11b KWG (Betrieb angemessener Datenverarbeitungssysteme zur Geldwäscheprävention)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 10 Dec 2025
- Mangelhafte Geldwäscheprävention: BaFin setzt Bußgeld gegen die Landesbank Hessen-Thüringen Girozentrale fest Press release of an authority
- Bekanntmachung zur Landesbank Hessen-Thüringen Girozentrale Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login €865,000
Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.
Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 28 Oct 2025
- Finlex – Tietosuojavaltuutettu 23.10.2025 (pankin tunnistamispalvelun muutosprosessi) Decision of an authority
- Tietosuojavaltuutettu – Aktialle seuraamusmaksu tietoturvapuutteista vahvan sähköisen tunnistamisen palvelussa (28.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Oct 2025 Taxshelter.be SATaxshelter.be: 75,000 EUR for missing prospectus supplement on guarantee risks €75,000
After the tax authority had refused the tax shelter certificates for a financed show and the insurer left cover open, the provider failed to inform investors of this material risk in good time by means of a prospectus supplement. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 75,000 EUR with publication by name.
New material risks for investors trigger an immediate obligation to publish a supplement – not only in the next annual prospectus.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Verordnung (EU) 2017/1129 Art. 23; Loi du 11 juillet 2018 (Loi Prospectus)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 21 Oct 2025
- FSMA – Règlement transactionnel Taxshelter.be (21.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2025 Xeltox Enterprises Ltd. (Cryptomus)FINTRAC: record penalty of 177 million CAD against crypto payment service Cryptomus €108.1m
The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 176,960,190 CAD on the crypto payment service registered in British Columbia. In July 2024 alone, 1,068 suspicious transaction reports were not filed – including on transactions linked to child sexual abuse material, fraud, ransomware and sanctions evasion – as well as 1,518 reports of large virtual currency transactions; in addition, there were violations of a ministerial directive and a lack of policies and risk assessment. The company has appealed to the Federal Court.
Crypto services without a functioning reporting system are sanctioned per report not filed – the total can threaten their existence.
- Authority / court
- Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 22 Oct 2025
Original amount 176,960,190 CAD, converted at the ECB reference rate of 16 Oct 2025.
- FINTRAC imposes an administrative monetary penalty on Xeltox Enterprises Ltd. Press release of an authority
- Public notice of administrative monetary penalties Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Oct 2025 Zimpler ABZimpler: 3 million SEK over anti-money laundering deficiencies at gambling-related payment service €272,245
Between July 2023 and April 2024, the payment service provider, a substantial part of whose business is linked to the gambling sector, had gaps in its general risk assessment (including a missing assessment of its currency exchange service), in its customer risk assessment and in customer due diligence. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 3 million SEK.
Include every new product – even an ancillary service such as currency exchange – in the money laundering risk assessment before launch.
Money laundering risks in the gambling environment
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 15 Oct 2025
Original amount 3,000,000 SEK, converted at the ECB reference rate of 15 Oct 2025.
- Zimpler får en anmärkning och sanktionsavgift (15.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools €2.4m
Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.
Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 14 Oct 2025
Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- DFS Secures More than $19 Million from Auto Insurance Companies over Data Breaches Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 AS Inbank FinanceOrder against Inbank Finance over deficiencies in creditworthiness assessment Order
During an inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) found that Inbank Finance’s internal rules on assessing the creditworthiness of consumers did not fully comply with the law and that the assessment itself showed deficiencies. It issued an order requiring the company to remedy the deficiencies by mid-December. Date = publication.
Creditworthiness assessments must be documented, rule-based and actually applied in day-to-day business.
Responsible lending in sales
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Consumer protection and online retail
- Legal basis
- Gesetz über Kreditgeber und -vermittler (KAVS), verantwortungsvolle Kreditvergabe
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 14 Oct 2025
- Finantsinspektsioon tegi AS-ile Inbank Finance ettekirjutuse (14.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 J.P. Morgan SEBaFin: 45 million EUR against J.P. Morgan SE over late suspicious activity reports €45m
By decision of 13 October 2025 (final since 30 October 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 45 million EUR on J.P. Morgan SE because the institution had culpably breached its duty of supervision in the internal processes for filing money laundering suspicious activity reports; from 4 October 2021 to 30 September 2022, suspicious activity reports were systematically not filed on time. BaFin points out that, in the case of systematic infringements, the amount of the fine can be based on the institution's total turnover.
File suspicious activity reports without delay – systematic backlogs in the reporting process are themselves an infringement, and the fine can then be calculated on the basis of the institution's total turnover.
Filing money laundering suspicious activity reports without delay
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- § 130 Abs. 1 OWiG (Aufsichtspflichtverletzung) i. V. m. Pflichten nach dem GwG (Verdachtsmeldungen); Bekanntmachung nach § 57 Abs. 1 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Published
- 6 Nov 2025
- Mängel in der Geldwäscheprävention: Bußgeld in Höhe von 45 Millionen Euro gegen J.P. Morgan SE Press release of an authority
- Bekanntmachung zur J.P. Morgan SE (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Wonderinterest Trading LtdCyprus: 100,000 EUR against Wonderinterest Trading over misleading client information €100,000
For 2022 to 2024, the Cyprus Securities and Exchange Commission (CySEC) found that the investment firm had no adequate compliance procedures, did not define target markets for its financial instruments, did not act in the best interests of clients and did not inform clients in a fair, clear and not misleading manner. It imposed fines of 50,000, 30,000 and 20,000 EUR; a judicial review of the decision has been recorded.
Advertising statements by financial service providers must present risks in a balanced way – marketing belongs in the compliance approval process.
Fair and not misleading marketing communications
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Sec. 17(2), 17(3)(c), 22(1), 25(1), 25(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 22, 44 Delegierte VO (EU) 2017/565
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 17 Dec 2025
- CySEC Board Decision – Wonderinterest Trading Ltd – Total fine €100.000 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Finamore S.A.Finamore: licence of insurance broker withdrawn over serious deficiencies Other
The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broking firm’s licence (effective from 1 December 2025), among other things for using unregistered intermediaries, lacking internal expertise, insufficiently protected confidential data, economically unexplained payment flows with affiliated companies, incomplete or false information provided to the supervisory authority and deficient customer information.
False information to the supervisory authority and unregistered distribution partners can cost the business its existence – not just a fine.
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 303 Abs. 3 lit. c
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 29 May 2026
- CAA – Sanction administrative FINAMORE S.A. (29.05.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers Reprimand or warning
After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).
Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.
Security testing for software releases of interfaces
- Authority / court
- Banka Slovenije
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Liability of senior managers
- Reprimand also issued to the responsible Director of IT Development (Dejan Pust).
- Razkritje informacij o izrečeni sankciji pravni in odgovorni osebi – Nova Ljubljanska banka d. d. Decision of an authority
- Banka Slovenije – Informacije o izrečenih ukrepih Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2025 Go West Invest SAGo West Invest: 10,000 EUR for outdated information note in tax shelter offering €10,000
From June 2021 to October 2024, the company, which raises tax shelter funds through public offerings, kept a public offering on its website with an information note from 2020 without publishing an updated note and filing it with the Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA); several dozen investors with an investment volume of under 5 million EUR were affected. The FSMA accepted a settlement of 10,000 EUR.
Investor information has an expiry date – a deadline calendar for mandatory documents prevents infringements.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Loi du 11 juillet 2018 (Loi Prospectus), Art. 10, 11
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 16 Sep 2025
- FSMA – Règlement transactionnel SA Go West Invest (16.09.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service €1.8m
After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.
Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
- Published
- 10 Sep 2025
- Finlex – Tietosuojavaltuutettu 8.9.2025, TSV/3606/2024 (pankin tunnistuspalvelu) Decision of an authority
- Tietosuojavaltuutettu – S-Pankille seuraamusmaksu S-mobiilin tietoturvahaavoittuvuudesta (10.09.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Sep 2025 „Paysera LT“, UABPaysera took over e-money institution Contis without approval – 400,000 EUR €400,000
Paysera acquired 100% of the shares in UAB ‘Finansinės paslaugos „Contis“’ before the assessment period had expired and without a non-objection from the supervisory authority; in April 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) objected to the acquisition owing to a lack of documents on reputation, financial soundness and money laundering risks. In addition, the annual financial statements and other reports were not approved and submitted on time. Fine of 400,000 EUR and obligation to remedy by 30 September 2025. Source: archived copy of the press release.
Complete acquisitions of holdings in supervised institutions only after approval – otherwise voting rights are suspended and fines loom.
- Authority / court
- Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Elektroninių pinigų ir elektroninių pinigų įstaigų įstatymas (Inhaberkontrolle, Berichtspflichten)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 5 Sep 2025
- Lietuvos bankas, Pranešimas 2025-09-05 (Archivkopie web.archive.org von lb.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Sep 2025 Blacktower Financial Management (Cyprus) LtdCyprus: Blacktower Financial Management pays 70,000 EUR over conflicts of interest €70,000
For the period November 2020 to May 2025, the Cyprus Securities and Exchange Commission (CySEC) investigated the investment firm’s handling of conflicts of interest and its general conduct of business and information obligations towards clients. The proceedings ended with a settlement of 70,000 EUR, which the company has paid.
Conflicts of interest must be identified, documented and managed vis-à-vis clients – adviser training is the basis for this.
Recognising conflicts of interest in investment advice
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 24(1), 25(1) Gesetz über Wertpapierdienstleistungen 2017; Art. 37(4) CySEC-Gesetz
- Action
- Other
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 17 Nov 2025
- CySEC Board Decision – Blacktower Financial Management (Cyprus) Ltd – Settlement €70.000 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Aug 2025 Varengold Bank AGBaFin: 3.3 million EUR fine and penalty payment against Varengold Bank €3.8m
By decision of 22 August 2025, Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 3.3 million EUR because the bank systematically filed suspicious activity reports late from June 2023 to March 2025; in February 2025, a penalty payment of 500,000 EUR had already been imposed for failure to comply with a 2023 order concerning Iran-related transactions (total 3.8 million EUR). In addition, in July 2025 BaFin ordered comprehensive remediation of the deficiencies in money laundering prevention, with an action plan and reporting obligations.
Failing to implement a supervisory order risks penalty payments and a comprehensive package of measures in addition to the fine.
Suspicious activity reports and handling of high-risk transactions
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Bußgeld: § 56 Abs. 1 S. 1 Nr. 69, Abs. 3 GwG; Anordnung: § 51 Abs. 2 GwG, § 44 Abs. 1 KWG; Zwangsgeld: § 14 VwVG i. V. m. § 17 FinDAG; Bekanntmachung nach § 57 Abs. 1 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Published
- 16 Sep 2025
- Varengold Bank AG: BaFin ordnet umfassende Mängelbeseitigung in der Geldwäscheprävention an und setzt Geldbuße fest Press release of an authority
- Bekanntmachungen zur Varengold Bank AG (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Aug 2025 Bank J. Safra Sarasin AGBank J. Safra Sarasin: 3.5 million CHF fine for money laundering in the Petrobras complex €3.73m
Between 2011 and 2014, the bank did not take all the necessary organisational precautions, with the result that bribes flowed to Petrobras executives through several account relationships (around 71 million USD in attempted or completed aggravated money laundering). Fine of 3.5 million CHF; because of a settlement of 16 million CHF with Petrobras, the Office of the Attorney General of Switzerland (Bundesanwaltschaft, OAG) waived a compensation claim. A former asset manager was separately given a suspended prison sentence.
Unusual payment flows involving clients close to PEPs must be escalated and, if necessary, rejected – responsibility lies with the bank as an organisation.
Anti-money laundering and PEP clients
- Authority / court
- Bundesanwaltschaft
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 102 Abs. 2 StGB i. V. m. Art. 305bis Abs. 1 und 2 StGB
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Time elapsed since the offence, organisational corrective measures after the affair became known; no compensation claim because of the payment of 16 million CHF to Petrobras.
- Liability of senior managers
- A former asset manager was separately given a suspended prison sentence of six months for aggravated money laundering (offences committed at another Swiss bank).
- Published
- 22 Aug 2025
Original amount 3,500,000 CHF, converted at the ECB reference rate of 22 Aug 2025.
- Bundesanwaltschaft verurteilt Bank J. Safra Sarasin AG (Strafbefehl) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Aug 2025 J.P. Morgan (Suisse) SAJ.P. Morgan (Suisse): 3 million CHF fine in the 1MDB complex for deficient anti-money laundering controls €3.2m
Between October 2014 and July 2015, around 174 million CHF from predicate offences in the 1MDB complex passed through the bank in 43 transfers, even though negative information about the Petrosaudi managers involved was publicly available. The Office of the Attorney General of Switzerland (Bundesanwaltschaft) convicted the bank by summary penalty order and imposed 3 million CHF; a compensation claim was waived because the 1MDB fund is being compensated as a private claimant.
Publicly available negative information about clients must feed into the risk assessment and be capable of stopping transactions.
Customer due diligence and adverse media screening
- Authority / court
- Bundesanwaltschaft
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 102 Abs. 2 StGB i. V. m. Art. 305bis Abs. 1 und 2 StGB
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Time elapsed since the offence, very good cooperation in the proceedings, compensation of the private claimant (1MDB).
- Published
- 22 Aug 2025
Original amount 3,000,000 CHF, converted at the ECB reference rate of 22 Aug 2025.
- Fall 1MDB: Bank JP Morgan Suisse mit Strafbefehl verurteilt Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR €2,990
A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.
Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.
Identity verification and fraud detection in remote applications
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 12 Aug 2025
Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.
- ANSPDCP – Comunicat de presă 12.08.2025 (Asociația Casa de Ajutor Reciproc „FLEXICREDIT”) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Aug 2025 Paxos Trust Company, LLCNYDFS: 26.5 million USD against Paxos over AML deficiencies in Binance business €22.8m
The New York State Department of Financial Services (NYDFS) imposed a penalty of 26.5 million USD on the crypto trust company because Paxos did not maintain an effective BSA/AML programme before 2023: KYC checks and risk ratings were inadequate, and transaction monitoring and suspicious activity reporting procedures had gaps, including in connection with the business relationship with Binance, contrary to a 2020 agreement. In addition, Paxos must invest at least 22 million USD in its compliance programme.
Companies that distribute products via partner platforms must include those platforms' customer and transaction risks in their own AML programme.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- New York Banking Law §§ 39, 44; AML-Vorschriften des NYDFS und Bank Secrecy Act
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 7 Aug 2025
Original amount 26,500,000 USD, converted at the ECB reference rate of 7 Aug 2025.
- In the Matter of Paxos Trust Company, LLC – Consent Order Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Aug 2025 Liberty Mutual Insurance CompanyLiberty Mutual: declination against 4.7 million USD after bribery of Indian state bank employees €4.04m
From 2017 to 2022, the Indian subsidiary Liberty General Insurance paid around 1.47 million USD to employees of six state-owned banks so that they would refer bank customers to its insurance products; the payments were booked as marketing expenses and routed through third parties. The DOJ declined to prosecute; Liberty Mutual is disgorging 4,699,088 USD in profits.
Employees of state-owned banks are public officials – sales commissions paid to them are bribes, even if they are booked as marketing.
Distribution partnerships with state-owned banks, payments disguised as marketing
- Authority / court
- U.S. Department of Justice (Fraud Section; USAO District of Massachusetts)
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- FCPA, 15 U.S.C. § 78dd-2; Corporate Enforcement and Voluntary Self-Disclosure Policy (Declination)
- Action
- Disgorgement of profits
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure (March 2024), full cooperation, root cause analysis, termination of those involved, improved controls including rules on messaging apps.
- Published
- 7 Aug 2025
Original amount 4,699,088 USD, converted at the ECB reference rate of 7 Aug 2025.
- DOJ Declination Letter – Liberty Mutual Insurance Company (07.08.2025) Decision of an authority
- DOJ Criminal Division: CEP Declinations Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers Order
The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.
Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Ettekirjutus-hoiatus nr 2.1-1/24/1048-2575-22 (ESTO AS), 23.07.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2025 Condor Courtiers & Conseillers S.à r.l.Condor Courtiers & Conseillers: licence withdrawn for using unlicensed introducers Other
Following an on-site inspection in 2024, the Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broker’s licence (effective 15 September 2025): there was no effective management by approved managers, unlicensed ‘introducers’ were de facto selling insurance, and the broker’s licence, together with its sub-intermediary network, was improperly made available to third parties.
A distribution licence is not transferable – anyone who ‘rents it out’ to third parties or lets introducers sell risks having it withdrawn.
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 273, 274, 283, 286, 303
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 16 Sep 2025
- CAA – Sanction administrative CONDOR COURTIERS & CONSEILLERS S.à r.l. (16.09.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert €80,000
A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.
Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.
Identity verification for customer requests by e-mail (social engineering)
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.
- Garante privacy, Provvedimento del 10 luglio 2025 [10154110] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jul 2025 Wise US, Inc.Six US states: 4.2 million USD against Wise US over AML programme deficiencies €3.59m
In a coordinated multistate proceeding brought by six states – the New York State Department of Financial Services (NYDFS) with the supervisory authorities of CA, MN, NE, TX and MA – the money transmitter must pay 4.2 million USD. An examination (July 2022 to September 2023) found, among other things, a lack of independent AML reviews at an appropriate frequency, late suspicious activity reports, data quality problems in transaction monitoring and unremedied earlier findings; Wise does not admit any legal infringements and must conduct a lookback.
Remedy findings from earlier examinations and audits on time – otherwise they become a ground for sanctions in their own right.
- Authority / court
- New York State Department of Financial Services (NYDFS) mit den Aufsichtsbehörden von CA, MN, NE, TX und MA
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Bundes- und einzelstaatliches Recht zu Geldtransfer und BSA/AML (u. a. 31 CFR 1022.320)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Remedial measures already initiated and lookback
- Published
- 9 Jul 2025
Original amount 4,200,000 USD, converted at the ECB reference rate of 9 Jul 2025.
- Consent Order – Wise US, Inc. (Multi-State) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jul 2025 Barents Reinsurance S.A.Barents Reinsurance: maximum fine of 250,000 EUR over governance deficiencies €250,000
The reinsurer breached the principle of specialisation in reinsurance business, its approved manager was not effectively present on site and had insufficient powers, the governance system including oversight of outsourced functions was inadequate, and orders from a 2019 inspection had not been implemented or only partially. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed the statutory maximum of 250,000 EUR; the company cooperated.
On-site substance is a supervisory requirement: management, powers and oversight of outsourced functions must genuinely be located in the home country.
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 49, 71, 81, 274, 303
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cooperation with the CAA during and after the inspection.
- Published
- 8 Aug 2025
- CAA – Sanction administrative BARENTS REINSURANCE S.A. (08.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2025 Monzo Bank LimitedFCA: £21 million against Monzo over lax account opening for high-risk customers €24.5m
The UK Financial Conduct Authority (FCA) imposed £21,091,300 (after a 30% discount) because, from 2018 to 2020, Monzo onboarded customers on the basis of sparse and sometimes obviously implausible information – such as well-known London landmarks given as addresses. Despite a requirement not to take on any more high-risk customers, the bank opened more than 34,000 such accounts up to 2022.
Automated onboarding needs plausibility checks – and supervisory requirements must be implemented in a technically effective way.
Plausibility checks in customer onboarding
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- FCA Principle 3 (PRIN 3); s. 55L FSMA (Verstoß gegen Auflage)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Published
- 8 Jul 2025
Original amount 21,091,300 GBP, converted at the ECB reference rate of 7 Jul 2025.
- FCA fines Monzo £21m for failings in financial crime controls Press release of an authority
- 2025 fines | FCA Enforcement database of an authority
- Final Notice: Monzo Bank Limited (07.07.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data €101,000
Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).
Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.
Access control and deletion periods for register data
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cap due to public tasks (Art. 44 of the Implementing Act).
- Published
- 2 Jul 2025
- Izrečeno osam upravnih novčanih kazni u ukupnom iznosu od 350.500,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2025 Swilly Mulroy Credit Union LimitedIreland: small credit union accepted cash from non-members without checks €36,273
Between 2014 and 2021, the credit union solicited cash from persons without an account and accepted 2,329 cash deposits totalling 8.75 million EUR without the required anti-money laundering checks; the board had known about the risk since 2015, and there was no self-reporting. The Central Bank of Ireland imposed a reprimand and 36,273 EUR (after a 30% discount on 51,819 EUR).
Even small cooperative banks must identify cash from non-customers – and would do better to self-report known risks.
Identification for cash deposits by non-customers
- Authority / court
- Central Bank of Ireland
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Criminal Justice (Money Laundering and Terrorist Financing) Act 2010; Credit Union Act 1997
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Liability of senior managers
- The board had known about the risks since 2015 without taking remedial action
- Published
- 2 Jul 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2025 Banca Privata Leasing SpaBanca d'Italia: 60,000 EUR against Banca Privata Leasing over deficiencies in AML organisation €60,000
An on-site inspection from February to May 2024 revealed deficiencies in organisation and internal controls relating to customer profiling, due diligence obligations and active cooperation (suspicious transaction reports). The Bank of Italy (Banca d'Italia) imposed an administrative fine of 60,000 EUR, taking into account the corrective measures taken.
Sound customer profiling is the basis for risk-appropriate due diligence and reporting.
- Authority / court
- Banca d'Italia
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–20, 24, 25, 35, 36 d.lgs. 231/2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Corrective measures taken
- Banca Privata Leasing Spa – Provvedimento n. 197 del 24 giugno 2025 (AML) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2025 C2D Payment Solutions LimitedMalta: 243,537 EUR against C2D Payment Solutions for ignoring cash risks €243,537
The financial institution did not take into account its customers’ significant cash exposure in its customer risk assessment, so that almost all customers were rated low risk – even with cash deposits of over 100,000 EUR. The Financial Intelligence Analysis Unit (FIAU) imposed 243,537 EUR and a follow-up directive; the fine was open to appeal at the time of publication.
Cash is an explicit high-risk factor – a risk model that ignores it is worthless.
Recognising cash as a risk factor
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 5(5)(a)(ii), 7(1)(c), 7(1)(d), 7(2)(a), 21 PMLFTR
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 23 Jun 2025
- Administrative Measure Publication Notice – C2D Payment Solutions Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jun 2025 Banque Pictet et Cie SABanque Pictet: 2 million CHF fine for laundering Petrobras bribes €2.13m
Between 2010 and 2013, an asset manager at the bank validated 54 transfers through which bribes of around 4.1 million USD connected with SBM Offshore's charter contracts with Petrobras were concealed. The bank had not classified high-risk accounts as such and had inadequately monitored transfers; the Office of the Attorney General of Switzerland (Bundesanwaltschaft) imposed a fine of 2 million CHF, and the former employee received a suspended prison sentence.
Risk classification and transaction monitoring must take effect before individual relationship managers approve payments.
High-risk clients and transaction monitoring
- Authority / court
- Bundesanwaltschaft
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 102 Abs. 2 StGB i. V. m. Art. 305bis und Art. 322septies StGB
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Time elapsed since the offence, very good cooperation, organisational corrective measures after the Petrobras affair became known.
- Liability of senior managers
- Former asset manager: suspended prison sentence of six months (probation period of two years).
- Published
- 17 Jun 2025
Original amount 2,000,000 CHF, converted at the ECB reference rate of 17 Jun 2025.
- Banque Pictet et Cie SA und ehemaliger Vermögensverwalter per Strafbefehl verurteilt Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Jun 2025 Svea Finance AS200,000 EUR fine against Svea Finance over deficient creditworthiness assessment €200,000
Between December 2023 and February 2024, Svea Finance’s internal rules on consumer lending did not comply with the law (50,000 EUR), and the company concluded credit agreements without assessing all prescribed creditworthiness components (150,000 EUR). Fines totalling 200,000 EUR for two misdemeanours. Date = publication.
Creditworthiness assessments must cover all factors prescribed by law – gaps in internal policies are sanctioned separately.
Responsible lending
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Consumer protection and online retail
- Legal basis
- § 98 Abs. 2 und § 99 Abs. 2 KAVS
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Jun 2025
- Finantsinspektsioon trahvis Svea Finance AS-i kokku 200 000 euroga (11.06.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2025 CaixaBank, S.A.AEPD: 200,000 EUR against CaixaBank over continued storage of a non-customer's data €200,000
A person who was not (or no longer) a customer received a letter from CaixaBank about an update to its privacy statement, announcing that she would be contacted about her advertising preferences. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) considered the continued storage of her data to be an infringement of the principle of storage limitation and imposed 200,000 EUR; the bank's request for reconsideration was dismissed as inadmissible.
Before mass mailings, check whether the recipients' data may still be stored at all – former customers should be deleted, not written to.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- AEPD Resolución PS/00140/2024 (EXP202302270) Decision of an authority
- AEPD Resolución recurso de reposición PS/00140/2024 (Datum der Ausgangsentscheidung 05.06.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jun 2025 LocalBitcoins OyLocalBitcoins: 500,000 EUR for failing to identify customers when opening accounts €500,000
During an inspection in 2024, the Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) found that the crypto trading platform had not identified and verified its customers when establishing permanent business relationships. Taking the company’s financial situation into account, it imposed 500,000 EUR; LocalBitcoins has appealed to the Helsinki Administrative Court.
KYC is a prerequisite for every business relationship – not an obligation to be met retrospectively once volumes grow.
Customer identification (KYC)
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Finnisches Geldwäschegesetz – Identifizierung und Verifizierung von Kunden
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 3 Jun 2025
- Finanssivalvonta – LocalBitcoins Oy:lle 500 000 euron seuraamusmaksu (3.6.2025) Press release of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Apr 2025 Bondora ASBondora must pay 200,000 EUR for breaching responsible lending rules €200,000
From 6 December 2023 to 24 February 2024, Bondora concluded consumer credit agreements without assessing all criteria provided for by law and satisfying itself of the borrowers’ ability to repay. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed 200,000 EUR. Date = publication.
Automated credit decisions do not release lenders from the full statutory creditworthiness assessment.
Responsible lending
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Consumer protection and online retail
- Legal basis
- § 99 Abs. 2 KAVS
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 30 Apr 2025
- Finantsinspektsioon trahvis Bondora AS-i 200 000 euroga (30.04.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2025 Iberinform Internacional, S.A.AEPD: 720,000 EUR against business information agency Iberinform for purchased data on entrepreneurs €720,000
Since 2008, Iberinform had obtained data on sole traders through a supply contract with Camerdata and used it to enrich its own files for commercial information services. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found no legal basis for this and no information of the data subjects, and imposed 360,000 EUR for each (720,000 EUR in total) as well as an order to bring the processing into compliance; the request for reconsideration (recurso de reposición) was rejected.
Companies that purchase personal data from third parties need their own legal basis and must actively inform the data subjects.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 14 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- AEPD Resolución PS/00150/2024 (EXP202404645) Decision of an authority
- AEPD Resolución recurso de reposición PS/00150/2024 (Datum der Ausgangsentscheidung 14.04.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Apr 2025 Block, Inc.NYDFS: 40 million USD against Block (Cash App) over AML deficiencies €36.1m
The New York State Department of Financial Services (NYDFS) imposed 40 million USD on the operator of Cash App for serious gaps in its BSA/AML programme, including insufficient customer due diligence, a lack of risk-based controls and untimely transaction monitoring. Rapid growth in 2019/2020 led to a considerable backlog of alerts; an independent monitor is being appointed.
Scale compliance capacity with growth – a backlog of alerts is a supervisory infringement in its own right.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- BSA/AML-, Geldtransfer- und Virtual-Currency-Vorschriften des NYDFS
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Cooperation and remedial measures already initiated
- Published
- 10 Apr 2025
Original amount 40,000,000 USD, converted at the ECB reference rate of 10 Apr 2025.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2025 OKCoin Europe LimitedMalta: 1.05 million EUR against crypto exchange OKCoin Europe over anti-money laundering deficiencies €1.05m
During an on-site examination in 2023, the Financial Intelligence Analysis Unit (FIAU) found deficiencies at the crypto service provider in its business risk assessment (including product risks), customer risk assessment, customer profiles, ongoing monitoring, suspicious transaction reporting and record-keeping. It imposed 1,054,269 EUR and a follow-up directive; the fine was open to appeal at the time of publication.
Crypto providers are held to the same due diligence standards as banks – the risk assessment must cover their own products.
Anti-money laundering for crypto-assets
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Reg. 5(1), 5(4), 5(5), 7, 11, 15(3), 21 PMLFTR; FIAU Implementing Procedures
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 3 Apr 2025
- Administrative Measure Publication Notice – OKCoin Europe Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Mar 2025 FXNET LimitedCyprus: FXNET pays 225,000 EUR under settlement over organisational and CFD breaches €225,000
The investigation covering 2021 to 2022 concerned compliance organisation, product governance, record-keeping obligations, safeguarding of client funds, client information, suitability and appropriateness assessments and the CFD restrictions for retail investors. Following board resolutions of 17 and 31 March 2025, the Cyprus Securities and Exchange Commission (CySEC) concluded a settlement of 225,000 EUR, which has been paid.
Safeguarding client funds and keeping proper records are basic duties of every investment firm – gaps quickly add up in a settlement.
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 17, 22(1), 25, 26(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; Art. 37(4) CySEC-Gesetz
- Action
- Other
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 11 Nov 2025
- CySEC Board Decision – FXNET Limited – Settlement €225,000 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2025 The London Metal Exchange (LME)London Metal Exchange: 9.2 million GBP – controls and escalation failed in nickel turmoil €11m
When the nickel price rose to over 100,000 USD within just over an hour on 8 March 2022, only junior staff were on duty during Asian trading hours, and they had not been trained to recognise a disorderly market; they did not escalate and even switched off price bands. The Financial Conduct Authority (FCA) imposed a fine on the recognised investment exchange for the first time: 9.2 million GBP after a 30% discount.
Critical infrastructure needs trained staff around the clock and clear escalation paths – including at night and at off-peak times.
Escalation of unusual market conditions; training of shift staff
Missing or inadequate training played a role in the decision.
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- FCA REC 2.5.1 (Recognition Requirements); Art. 18 RTS 7 (MiFID II)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Early settlement (30% discount); improvements since March 2022.
Original amount 9,200,000 GBP, converted at the ECB reference rate of 20 Mar 2025.
- FCA: First FCA enforcement action and fine against Recognised Investment Exchange (20.03.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long €10,000
The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.
Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση – Διατήρηση δεδομένων πέραν της νόμιμης περιόδου (ΟΧΣ, 10.03.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Mar 2025 MAKI podjetje za turizem, trgovino in storitve d.o.o. KoperBureau de change MAKI: transaction limit of 1,000 EUR over unresolved anti-money laundering deficiencies Order
During a follow-up inspection, Banka Slovenije (Bank of Slovenia) found that the company had not remedied the anti-money laundering deficiencies it had been ordered to address in 2023; some infringements are considered serious. It limited transactions to 1,000 EUR per customer per day, ordered monthly reports and set a deadline of 30 June 2025.
Supervisory orders that are not implemented lead to business restrictions – working through them requires responsible persons and deadline control.
Anti-money laundering in small financial service providers
- Authority / court
- Banka Slovenije
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 164 ZPPDFT-2, Art. 280 ZBan-3, Art. 42.a ZBS-1
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Razkritje informacij o izrečenem ukrepu subjektu nadzora – MAKI d.o.o. Koper Decision of an authority
- Banka Slovenije – Informacije o izrečenih ukrepih Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Feb 2025 Morgan Stanley (Switzerland) GmbHMorgan Stanley (Switzerland): 1 million CHF fine for organisational deficiency in money laundering case €1.06m
In 2010, the company's legal predecessor did not take all necessary and reasonable organisational precautions to prevent a relationship manager from committing aggravated money laundering with assets derived from bribery offences in Greece. The Office of the Attorney General of Switzerland (Bundesanwaltschaft) concluded the proceedings with a summary penalty order of 1 million CHF.
Under corporate criminal law, organisational deficiencies do not become time-barred when the employee leaves – controls must be demonstrably effective.
- Authority / court
- Bundesanwaltschaft
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 102 Abs. 2 StGB i. V. m. Art. 305bis StGB
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 27 Feb 2025
Original amount 1,000,000 CHF, converted at the ECB reference rate of 27 Feb 2025.
- Bundesanwaltschaft schliesst Strafuntersuchung gegen Morgan Stanley (Switzerland) GmbH mit Strafbefehl ab Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent Reprimand or warning
An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.
Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.
Disclosure of customer data to agents and colleagues in their own matters
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The company implemented the order
- Απόφαση – Γνωστοποίηση περιστατικού παραβίασης δεδομένων (Trust International Insurance, 07.02.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms Order
From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.
Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.
Handling access requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 1 Jul 2025
- Verfügung des EDÖB gegen die Cembra Money Bank AG Press release of an authority
- Verfügung des EDÖB vom 29. Januar 2025 gegen Cembra Money Bank AG Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA €1.92m
When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.
Anyone changing data flows must know the security processes – training development teams is part of cyber defence.
Secure software development and change processes
Missing or inadequate training played a role in the decision.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- PayPal has since remedied the deficiencies.
- Published
- 23 Jan 2025
Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.
- DFS-Pressemitteilung vom 23.01.2025: Cybersecurity-Vergleich mit PayPal, Inc. (2 Mio. $) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jan 2025 Two Sigma Investments LP und Two Sigma Advisers LPTwo Sigma: 90 million USD – known weaknesses in investment models left unremedied for years €87.6m
Employees identified weaknesses in investment models that could affect client returns by March 2019 at the latest, but Two Sigma only acted in August 2023; there were no policies, and one employee made unauthorised changes to more than a dozen models. In addition, separation agreements required employees to declare that they had not filed any complaint with authorities. The U.S. Securities and Exchange Commission (SEC) imposed 90 million USD; Two Sigma had already repaid 165 million USD to clients.
Model risks need a change and approval procedure – and identified weaknesses need a binding deadline for remediation.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Investment Advisers Act of 1940 (Antifraud, Compliance Rule 206(4)-7); Exchange Act Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Mitigating circumstances
- Voluntary repayment of 165 million USD to affected funds and accounts.
Original amount 90,000,000 USD, converted at the ECB reference rate of 16 Jan 2025.
- SEC Charges Two Sigma for Failing to Address Known Vulnerabilities in its Investment Models (16.01.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Jan 2025 BMO Capital Markets Corp.BMO Capital Markets: 40.7 million USD – inadequate supervision of bond desk €39.9m
From December 2020 to May 2023, staff on the agency CMO bond desk sold mortgage-backed bonds worth around 3 billion USD using misleading metrics; the broker-dealer’s supervisory procedures contained no requirements for the structuring and sale of these bonds. BMO paid 19,417,908 USD in disgorgement, 2,241,507 USD in interest and a civil penalty of 19 million USD.
Tailor supervisory procedures to the actual products and sales practices of each desk – generic policies are not enough.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Securities Exchange Act of 1934, Section 15(b)(4)(E) (Failure to supervise)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
Original amount 40,659,415 USD, converted at the ECB reference rate of 13 Jan 2025.
- SEC Charges BMO Capital Markets with Failing to Supervise Agency Bond Desk (13.01.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jan 2025 Εθνική Τράπεζα της Ελλάδος Α.Ε. (National Bank of Greece)Greece: 120,000 EUR against National Bank of Greece after misdirected payment via mobile number €120,000
An IRIS transfer made by mobile number via the bank’s app ended up with an uninvolved customer instead of the intended recipient because the number had been assigned incorrectly. By Decision 3/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed 100,000 EUR for inaccurate data, insufficient security, lack of data protection by design and failure to notify the data breach, as well as 20,000 EUR for breach of the right of access.
Even a single misdirected payment can be a notifiable data breach – customer complaints must be assessed internally as a possible incident.
Recognising and reporting data breaches
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. d und f, Art. 15, 25, 32, 33, 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση 3/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jan 2025 Arian Financial LLPFCA: small broker Arian Financial fined over cum-ex money laundering risks €344,791
From January to September 2015, the broker had no effective systems against financial crime and was therefore exposed to the risk of facilitating fraudulent trading and money laundering in connection with cum-ex trades. Following proceedings before the Upper Tribunal, the UK Financial Conduct Authority (FCA) set the fine at £288,962.53 instead of the £744,745 originally intended.
Even small brokers must question unusually lucrative, circular trading patterns before executing them.
Recognising warning signs in unusual trading structures
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- FCA Principles 2 und 3 (PRIN 2, PRIN 3)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction by the Upper Tribunal
- Published
- 10 Jan 2025
Original amount 288,962.53 GBP, converted at the ECB reference rate of 9 Jan 2025.
- FCA fines Arian Financial LLP for failings relating to cum-ex trading Press release of an authority
- 2025 fines | FCA Enforcement database of an authority
- Final Notice: Arian Financial LLP (09.01.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Jan 2025 Luxembourg credit institution: 175,000 EUR for late responses to data subject requests €175,000
Following 47 complaints, the Commission nationale pour la protection des données (Luxembourg data protection authority, CNPD) found that a Luxembourg credit institution (pseudonymised in the decision as ‘Société A’) had not responded to data subjects’ requests on time; the CNPD did not accept the reference to the COVID-19 pandemic. It issued a reprimand (rappel à l’ordre) and imposed 175,000 EUR.
Data subject requests require deadline tracking and a monitored DPO mailbox – staff shortages are no excuse.
Deadlines for data subject requests
- Authority / court
- Commission nationale pour la protection des données (CNPD) – formation restreinte
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 12 Abs. 3 und 4
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- CNPD – Délibération n° 1FR/2025 du 6 janvier 2025 (Société A) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father Reprimand or warning
A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.
HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.
Confidential delivery of HR correspondence
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση – Παράπονο vs Eurolife Ltd (23.12.2024) Decision of an authority
- 28/03/2025 Αποφάσεις: Οκτώβριος – Δεκέμβριος 2024 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links €950,000
On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.
Personal links are not access protection – sensitive customer data requires authentication and regular security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 20 Dec 2024
- Tietosuojavaltuutettu – Sambla Groupille seuraamusmaksu (20.12.2024) Press release of an authority
- Finlex – Tietosuojavaltuutettu 17.12.2024 (lainanvertailupalvelu) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Dec 2024 Leonteq AG (Finanzgruppe Leonteq)Leonteq: distribution via unregulated partners – confiscation of 9.3 million CHF in profits €9.98m
The Swiss Financial Market Supervisory Authority (FINMA) found serious breaches of risk management obligations and of the requirement to guarantee irreproachable business conduct: the financial group monitored its distribution chain inadequately and in some cases worked with dubious, unregulated distributors that sold products in countries not intended for them without authorisation. FINMA ordered governance requirements, the termination of these relationships, the appointment of an audit agent and the confiscation of 9.3 million CHF in profits; the ruling was not yet final at the time of publication.
Anyone who distributes via third parties is liable for their regulatory status – sales partners require due diligence just like customers.
- Authority / court
- Eidgenössische Finanzmarktaufsicht (FINMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Finanzmarktaufsichtsgesetz (FINMAG)
- Action
- Disgorgement of profits
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Good cooperation in the proceedings; Leonteq had already strengthened compliance and distribution controls of its own accord and terminated relationships with suspicious distributors
Original amount 9,300,000 CHF, converted at the ECB reference rate of 12 Dec 2024.
- FINMA schliesst Verfahren gegen Leonteq ab Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Dec 2024 Salva Kindlustuse ASSalva Kindlustus: 10,000 EUR for motor insurance advertising without mandatory notice €10,000
Through Europark Estonia, the insurer placed advertising for motor third-party liability insurance that lacked the statutory notice referring to the insurance terms, and incorrectly stated on policies that the contracts had been concluded through a registered insurance agent. Fine of 10,000 EUR. Date = publication.
Anyone using distribution partners for advertising and concluding contracts must itself check their mandatory disclosures and registration.
Mandatory disclosures in financial advertising; management of distribution partners
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 254 Abs. 2 KindlTS (Versicherungstätigkeitsgesetz); Werbegesetz
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 3 Dec 2024
- Finantsinspektsioon trahvis Salva Kindlustuse AS-i 10 000 euroga (03.12.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 Macquarie Bank Limited, London BranchMacquarie Bank London: 13 million GBP – trader concealed over 400 fictitious trades €15.6m
From June 2020 to February 2022, a trader on the metals and commodities desk was able to book over 400 fictitious trades and circumvent three key internal controls in order to conceal losses; the bank was partly aware of the weaknesses but did not remedy them in time. Unwinding the positions cost around 57.8 million USD; the Financial Conduct Authority (FCA) imposed 13 million GBP on the bank and banned the trader Travis Klein.
Close known control weaknesses in trading with a deadline and a responsible person – otherwise a lone perpetrator becomes an organisational failure.
Recognising and reporting circumvention of controls in trading
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- FCA Principles for Businesses, Principle 3 (Systeme und Kontrollen); s. 206 Financial Services and Markets Act 2000
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Liability of senior managers
- Prohibition order imposed on the trader; no fine imposed on him on grounds of serious financial hardship.
Original amount 13,031,400 GBP, converted at the ECB reference rate of 26 Nov 2024.
- FCA: MBL fined £13m for serious control failures that allowed trader to conceal over 400 fictitious trades (26.11.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Nov 2024 Banus Port Vagyonkezelő Zrt.Banus Port: 250 million HUF for fictitious trading in 4iG shares €608,080
From September 2023 to May 2024, the asset management company used transactions worth several billion forints to create false signals about the trading volume of 4iG shares (‘painting the tape’). The Magyar Nemzeti Bank (Central Bank of Hungary, MNB) prohibited any repetition, imposed 250 million HUF and filed a criminal complaint.
Transactions that mainly simulate turnover are market manipulation – even without a price target.
- Authority / court
- Magyar Nemzeti Bank (MNB)
- Area of law
- Capital markets and financial supervision · Market abuse and insider dealing
- Legal basis
- Art. 12, 15 MAR (Marktmanipulation), Beschluss H-PJ-III-B-26/2024
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 22 Nov 2024
Original amount 250,000,000 HUF, converted at the ECB reference rate of 22 Nov 2024.
- Banus Port Zrt.: piaci manipuláció, 250 milliós bírság Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Nov 2024 Invesco Advisers, Inc.Invesco Advisers: 17.5 million USD for inflated ESG integration percentages €16.2m
From 2020 to 2022, Invesco told clients that 70 to 94 per cent of the parent company's assets under management were ‘ESG integrated’, but counted passive ETFs that did not take ESG into account and had no written definition of ESG integration. The U.S. Securities and Exchange Commission (SEC) imposed 17.5 million USD, a censure and a cease-and-desist order.
Sustainability metrics used in sales need a written definition and a traceable calculation.
Verifiable metrics in ESG marketing
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Investment Advisers Act of 1940
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 8 Nov 2024
Original amount 17,500,000 USD, converted at the ECB reference rate of 8 Nov 2024.
- SEC Charges Invesco Advisers for Making Misleading Statements About Supposed Investment Considerations Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Nov 2024 Deželna banka Slovenije d. d.Deželna banka Slovenije: 90,000 EUR for deficient credit risk provisioning €90,000
From 2018 to mid-2023, the bank had no adequate policies for impairments and provisions under IFRS 9 and the EBA guidelines on credit risk. Banka Slovenije (Bank of Slovenia) imposed 90,000 EUR on the bank and 2,500 EUR each on the chair of the management board and a board member.
In Slovenia, governance deficiencies in risk management are also sanctioned personally against board members.
- Authority / court
- Banka Slovenije
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 171, Art. 396 Abs. 1 Nr. 19 ZBan-3
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Liability of senior managers
- Fines of 2,500 EUR each on the chair of the management board, Marko Rozman, and the board member Barbara Cerovšek Zupančič.
- Razkritje informacij o izrečeni sankciji pravni in odgovorni osebi – Deželna banka Slovenije d. d. Decision of an authority
- Banka Slovenije – Informacije o izrečenih ukrepih Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Oct 2024 The Toronto-Dominion BankFederal Reserve: 123.5 million USD against Toronto-Dominion Bank over AML oversight failure €113m
The Board of Governors of the Federal Reserve System imposed 123.5 million USD on the Canadian parent company because it neglected risk management and oversight of its US retail business, so that a US subsidiary was used to launder hundreds of millions of dollars. TD must move the AML programme to the US and commission an independent review of the board and management; the sanctions of all authorities involved (DOJ, FinCEN, OCC) add up to around 3.09 billion USD.
Parent companies are responsible for effective AML oversight of their foreign business – failures there can lead to sanctions running into billions.
- Authority / court
- Board of Governors of the Federal Reserve System
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- US-Anti-Geldwäschegesetze (laut Federal Reserve)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Liability of senior managers
- Independent review of board and management ordered
- Published
- 10 Oct 2024
Original amount 123,500,000 USD, converted at the ECB reference rate of 10 Oct 2024.
- Federal Reserve Board fines Toronto-Dominion Bank $123.5 million for violations related to anti-money laundering laws Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Tradition SEF LLCTradition SEF: 875,000 USD – emergency and security tests not brought before the board €789,284
The swap trading platform did not fully inform its board of the results of emergency, technology risk and penetration tests, did not regularly test its business continuity and disaster recovery capabilities and had no adequate risk management. It also failed to produce documents requested during an examination on time despite extensions of deadlines; the Commodity Futures Trading Commission (CFTC) imposed 875,000 USD.
Contingency plans only count if they are tested regularly and the results are noted by the entire governing body.
- Authority / court
- Commodity Futures Trading Commission (CFTC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Commodity Exchange Act; CFTC-Regeln zu System Safeguards für Swap Execution Facilities
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
Original amount 875,000 USD, converted at the ECB reference rate of 1 Oct 2024.
- CFTC Orders Tradition SEF LLC to Pay $875,000 for System Safeguards Violations … (01.10.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2024 GQG Partners LLCSEC: GQG Partners pays 500,000 US dollars over NDAs and severance agreement €448,229
The asset manager had twelve job applicants sign NDAs that prohibited voluntary reports to authorities, and, in a settlement agreement, required a former employee who had announced a report to the SEC to confirm that he had not initiated any investigation and to withdraw statements already made. The U.S. Securities and Exchange Commission (SEC) took cooperation and remediation into account and imposed 500,000 US dollars.
Companies concluding a settlement with a whistleblower may require neither the withdrawal of nor a waiver of reports to authorities.
Handling announced reports to authorities in separation negotiations
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a); Investment Advisers Act Section 203(e)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 50 to 249
- Mitigating circumstances
- Cooperation with the SEC and prompt remedial measures
- Published
- 26 Sep 2024
Original amount 500,000 USD, converted at the ECB reference rate of 26 Sep 2024.
- In the Matter of GQG Partners LLC, Release No. 34-101200 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Sep 2024 TransUnionSEC: TransUnion pays 312,000 US dollars over waivers of whistleblower awards €282,532
Between May 2019 and September 2023, TransUnion had senior employees waive potential awards for reports to authorities in 29 severance, separation and incentive agreements; three consulting agreements prohibited voluntary disclosures to authorities. As part of a sweep against seven listed companies, TransUnion paid 312,000 US dollars to the U.S. Securities and Exchange Commission (SEC); the contract templates were amended.
Separation and employment agreements must restrict neither reports to authorities nor the entitlement to whistleblower awards.
Whistleblower protection in contract templates (HR/Legal)
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Amendment of the templates after contact by the SEC, information provided to those affected, and cooperation
- Published
- 9 Sep 2024
Original amount 312,000 USD, converted at the ECB reference rate of 9 Sep 2024.
- SEC Charges Seven Public Companies with Violations of Whistleblower Protection Rule Press release of an authority
- In the Matter of TransUnion, Release No. 34-100975 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2024 Nationwide Planning Associates, Inc.; NPA Asset Management, LLC; Blue Point Strategic Wealth Management, LLCSEC: Nationwide Planning and partners pay 240,000 US dollars over reporting prohibitions €217,195
From May 2021 to February 2024, the three New Jersey firms had eleven retail clients sign confidentiality agreements in connection with settlement payments that permitted reports to the SEC only at the SEC's initiative; in some cases, clients had to confirm that they had never contacted and would never contact authorities. Penalties imposed by the U.S. Securities and Exchange Commission (SEC): 160,000 (NPA Asset Management), 70,000 (Nationwide Planning) and 10,000 US dollars (Blue Point).
Complaint settlements with clients must not require an assurance not to contact authorities.
Whistleblower protection in complaint and settlement processes
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 4 Sep 2024
Original amount 240,000 USD, converted at the ECB reference rate of 4 Sep 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing €950,490
In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.
Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.
Misdirected documents and notification of data subjects
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 9 Sep 2024
Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.
- Kara dla mBanku za niezawiadomienie osób poszkodowanych wyciekiem danych Press release of an authority
- Decyzja DKN.5131.1.2024 z 20 sierpnia 2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2024 HSBC Private Bank (Suisse) SAFINMA: HSBC Private Bank (Suisse) breached anti-money laundering rules for two PEPs Order
The Swiss Financial Market Supervisory Authority (FINMA) found that, for two politically exposed persons, the bank insufficiently clarified the origin and purpose of assets – transactions of more than 300 million USD from a Lebanese state institution between 2002 and 2015 – and only reported them to the reporting office in September 2020. It ordered a review of all PEP relationships, a ban on new PEP relationships until the review is completed and the appointment of an audit agent; the decision was not final at the time of publication (date of the announcement used as decision date).
In PEP relationships, document the origin and purpose of large payments; a report made years later is no report.
Dealing with politically exposed persons (PEPs)
- Authority / court
- Eidgenössische Finanzmarktaufsicht (FINMA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Schweizer Geldwäschereirecht (laut FINMA)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Jun 2024
- FINMA-Verfahren: HSBC Private Bank (Suisse) SA hat gegen Geldwäschereiregeln verstossen Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC €9.23m
In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.
Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.
Internal escalation of cyber incidents to compliance
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Apr 2024 N26 Bank AGBaFin: 9.2 million EUR against N26 over systematically late suspicious activity reports €9.2m
By final decision of 24 April 2024, Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 9.2 million EUR on the neobank because it had systematically filed money laundering suspicious activity reports late in 2022.
Send suspicious activity reports to the FIU without delay – systematically late reporting risks fines running into millions.
Suspicious activity reports without delay
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- § 56 Abs. 1 Nr. 69, Abs. 3 GwG (verspätete Verdachtsmeldungen, § 43 Abs. 1 GwG); Bekanntmachung nach § 57 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 21 May 2024
- Geldwäscheprävention: BaFin setzt Geldbuße gegen N26 Bank AG fest Press release of an authority
- Bekanntmachung zur N26 Bank AG (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2024 Banque Audi (Suisse) SAFINMA confiscates 3.9 million CHF in profits from Banque Audi (Suisse) €4.01m
The Swiss Financial Market Supervisory Authority (FINMA) found serious infringements of anti-money laundering rules in PEP relationships: insufficient clarification of the origin of assets, failure to report to the reporting office despite unexplained transaction purposes and a serious breach of the duty to provide information, because a critical internal audit report was not handed over. It confiscated 3.9 million CHF in profits, imposed a capital surcharge of 19 million CHF and a two-year ban on new PEP and high-risk relationships (date of the announcement used as decision date).
Withholding critical audit reports from the supervisory authority considerably aggravates a money laundering case.
PEP clarifications and openness towards the supervisory authority
- Authority / court
- Eidgenössische Finanzmarktaufsicht (FINMA)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Schweizer Geldwäschereirecht; Gewinneinziehung und Auskunftspflicht nach Finanzmarktaufsichtsrecht (laut FINMA)
- Action
- Disgorgement of profits
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 25 Mar 2024
Original amount 3,900,000 CHF, converted at the ECB reference rate of 25 Mar 2024.
- FINMA-Verfahren: Banque Audi (Suisse) SA hat gegen Geldwäschereiregeln verstossen Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2024 Scope Ratings GmbHScope Ratings: conflicts of interest not identified and disclosed – 2.2 million EUR €2.2m
The Berlin-based credit rating agency lacked adequate procedures, internal controls and organisational arrangements to deal with conflicts of interest, did not disclose a potential conflict and concealed ancillary services it had provided to a rated entity. ESMA found negligent infringements and imposed fines of 2,197,500 EUR.
Systematically record and disclose ancillary services for customers whom you are at the same time rating or auditing.
Identifying and disclosing conflicts of interest
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Anhang III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Published
- 22 Mar 2024
- Decision of the Board of Supervisors – Scope Ratings GmbH (ESMA43-1868696574-770) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Mar 2024 Delphia (USA) Inc.SEC ‘AI washing’: Delphia pays 225,000 US dollars for fabricated AI use €206,574
From 2019 to 2023, the investment adviser claimed to use AI and machine learning to analyse client data for investment decisions but did not have these capabilities. In a settlement with the U.S. Securities and Exchange Commission (SEC) (without admission), Delphia paid 225,000 US dollars.
Statements about the use of AI in marketing and investor information must be technically verifiable.
Permissible advertising claims about AI capabilities
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- Investment Advisers Act of 1940; Marketing Rule
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 18 Mar 2024
Original amount 225,000 USD, converted at the ECB reference rate of 18 Mar 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Mar 2024 Global Predictions Inc.SEC ‘AI washing’: Global Predictions pays 175,000 US dollars for AI advertising promises €160,668
In 2023, the investment adviser falsely advertised itself as the ‘first regulated AI financial advisor’ offering AI-driven expert forecasts, misrepresented tax-loss harvesting and used impermissible liability clauses. In a settlement with the U.S. Securities and Exchange Commission (SEC), the company paid 175,000 US dollars.
Superlatives such as ‘first AI adviser’ are statements of fact and must be checked before publication.
Permissible advertising claims about AI capabilities
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- Investment Advisers Act of 1940; Marketing Rule
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 18 Mar 2024
Original amount 175,000 USD, converted at the ECB reference rate of 18 Mar 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported €336,066
A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.
Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.
Risk assessment and notification of data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 2 Apr 2024
Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.59.2022 vom 12.03.2024 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years €18,331
The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.
Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.
Recognising misdirected mail and reporting it internally
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 2 Apr 2024
Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.28.2023 vom 12.03.2024 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jan 2024 J.P. Morgan Securities LLCSEC: J.P. Morgan Securities pays 18 million US dollars over gagging clauses in client settlements €16.5m
From March 2020 to July 2023, JPMS had hundreds of retail clients who received credits or settlement payments of more than 1,000 US dollars sign confidentiality agreements that permitted responses to SEC enquiries but prohibited voluntary contact with the SEC. The U.S. Securities and Exchange Commission (SEC) imposed 18 million US dollars.
Confidentiality clauses with clients must not exclude voluntary reporting to supervisory authorities either.
Whistleblower protection in settlement and confidentiality agreements
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Published
- 16 Jan 2024
Original amount 18,000,000 USD, converted at the ECB reference rate of 16 Jan 2024.
- J.P. Morgan to Pay $18 Million for Violating Whistleblower Protection Rule Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jan 2024 Lombard International Assurance S.A.Lombard International Assurance: 1.68 million EUR over missing overall money laundering risk assessment €1.68m
During an inspection in 2021/2022, the Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) found that the life insurer had not prepared an overall assessment of its money laundering risks, that guidance for employees on due diligence obligations (beneficial owners, high-risk countries, PEPs) was inadequate and that it was not checked whether the intermediaries used fulfilled their due diligence obligations. It imposed 1,682,000 EUR.
Without a documented overall risk assessment, a risk-based approach cannot be demonstrated – intermediaries must also be monitored.
Due diligence obligations regarding beneficial owners and PEPs
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 2-2, 8-4, 8-5; Règlement CAA 20/03
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 20 Mar 2024
- CAA – Sanction administrative Lombard International Assurance S.A. (20.03.2024) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2023 First American Title Insurance CompanyNYDFS: $1 million against First American over open document links €913,159
The EaglePro application generated links to transaction documents without login and without an expiry date; according to a journalist, by changing the sequential document number, 885 million documents containing, among other things, social security and bank data could be retrieved. Users were told not to send sensitive data, but there were no technical barriers. The penalty was imposed by the New York State Department of Financial Services (NYDFS).
Instructions to users do not replace technical controls – sharing links need authentication and an expiry date.
Classification and sending of sensitive documents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR §§ 500.3, 500.7 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 1,000,000 USD, converted at the ECB reference rate of 27 Nov 2023.
- Consent Order to First American Title Insurance Company Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Nov 2023 UAB „Finansinės paslaugos „Contis““Contis: 840,000 EUR for anti-money laundering delegated to partners without oversight €840,000
The e-money institution had delegated anti-money laundering tasks to its distribution partners without monitoring them; customer profiles were often not completed, risks (including from crypto-assets) were not assessed, monitoring was insufficient and the second and third lines of defence for ICT risks were missing. Fine of 840,000 EUR, obligation to remedy the deficiencies and restriction on business expansion. Source: archived copy of the press release.
AML duties can be delegated to distribution partners, responsibility cannot – without oversight of the partners, the institution is liable.
- Authority / court
- Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Pinigų plovimo ir teroristų finansavimo prevencijos įstatymas; IKT-Risikomanagement-Anforderungen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The institution submitted a remediation plan and had initiated first steps.
- Published
- 24 Nov 2023
- Lietuvos bankas, Pranešimas 2023-11-24 (Archivkopie web.archive.org von lb.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Nov 2023 OTP Bank Nyrt.OTP Bank: 49.4 million HUF over late suspicious transaction reports €130,215
The bank did not report several suspicious cases to the financial intelligence unit without delay, its monitoring produced delayed hits owing to incorrectly set filter parameters, and its risk assessment, customer due diligence and documentation of anti-money laundering training showed deficiencies. The Magyar Nemzeti Bank (Central Bank of Hungary, MNB) imposed a total of 49.375 million HUF and set deadlines for remediation by August 2024.
Validate monitoring parameters regularly – and training is expressly among the obligations that are inspected.
Recognising and reporting suspected money laundering in good time
Missing or inadequate training played a role in the decision.
- Authority / court
- Magyar Nemzeti Bank (MNB)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Ungarisches Geldwäschegesetz (Pmt.); Beschluss H-PM-I-B-76/2023
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- The bank had already initiated remedial measures for several of the infringements.
- Published
- 21 Nov 2023
Original amount 49,375,000 HUF, converted at the ECB reference rate of 21 Nov 2023.
- Hiányosságok az OTP Bank pénzmosási bejelentési és belső ellenőrzési rendszerében Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator €23,362
The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.
Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.
Avoiding misdirected e-mails; reporting data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- intentional
- Repeat case
- yes
- Published
- 23 Nov 2023
Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.
- UODO: Kolejna administracyjna kara pieniężna za niezgłoszenie naruszenia ochrony danych osobowych (23.11.2023) Press release of an authority
- UODO, Decyzja DKN.5131.55.2022 vom 18.10.2023 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2023 Swiss Life (Luxembourg)Swiss Life (Luxembourg): 790,000 EUR over deficiencies in anti-money laundering €790,000
An inspection in 2021 revealed that the life insurer had not carried out an overall assessment of its money laundering risks and that the guidance for employees on due diligence obligations (beneficial owners, high-risk countries, PEPs) was inadequate. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 790,000 EUR.
The overall money laundering risk assessment is the basis of all due diligence obligations and must be in place before new business relationships are entered into.
Customer due diligence in insurance distribution
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 2-2, 8-4, 8-5; Règlement CAA 20/03
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 3 Jul 2024
- CAA – Sanction administrative Swiss Life (Luxembourg) (03.07.2024) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Oct 2023 EOS Matrix d.o.o.Croatia: 5.47 million EUR against debt collection company EOS Matrix after data leak €5.47m
An anonymous tip-off accompanied by a USB stick proved that data of 181,641 debtors had leaked from the debt collection company’s records; there were no systems for detecting unusual data retrievals. In addition, EOS Matrix stored health data up to and including diagnoses, data of non-debtors and call recordings without a legal basis; the Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 5.47 million EUR.
Employees’ free-text notes can turn into impermissible health data – clear recording rules and monitoring of data retrievals are mandatory.
No recording of health data in call notes
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 2, Art. 6 Abs. 1, Art. 9 Abs. 2, Art. 12, 13, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 5 Oct 2023
- Debt collection agency EOS Matrix d.o.o. imposed with administrative fine in the amount of 5.47 million EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Sep 2023 ADM Investor Services International LimitedFCA: £6.47 million against ADM Investor Services over outdated AML controls €7.48m
The UK Financial Conduct Authority (FCA) imposed £6,470,600 (after a 30% discount) because, between September 2014 and October 2016, the derivatives broker had only a rudimentary customer risk assessment, no firm-wide money laundering risk assessment and no adequate ongoing monitoring; its policies referred to outdated legislation. The FCA had already raised concerns in 2014.
Policies that refer to repealed legislation are a sure sign of a dead AML programme.
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- FCA Principle 3; SYSC
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Published
- 2 Oct 2023
Original amount 6,470,600 GBP, converted at the ECB reference rate of 29 Sep 2023.
- FCA fines ADM Investor Services International Limited £6,470,600 for serious financial crime control failings Press release of an authority
- Final Notice: ADM Investor Services International Limited (29.09.2023) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Sep 2023 DWS Investment Management Americas Inc.DWS Investment Management Americas: 19 million USD for misleading ESG statements €17.9m
From 2018 until the end of 2021, the Deutsche Bank subsidiary presented ESG as part of its ‘DNA’ but did not implement the ESG integration policies it had promised. It is paying 19 million USD for the ESG misstatements; in separate proceedings over deficiencies in its anti-money laundering programme, a further 6 million USD was added.
ESG marketing statements must be backed by processes that are actually practised and documented; otherwise they become a regulatory risk.
Truthful sustainability communication in sales and marketing
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Sections 206(2), 206(4) Investment Advisers Act; Rules 206(4)-7 und 206(4)-8
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 25 Sep 2023
Original amount 19,000,000 USD, converted at the ECB reference rate of 25 Sep 2023.
Checked against the official source on 25 Sep 2026 · Direct link