Pricing
Language

30-09-2026

AML Fines and Sanctions Cases: Six Enforcement Lessons

Six AML and sanctions cases reveal failures in screening, due diligence and monitoring. Learn which controls could help—and which need separate action.

Share

Major AML fines and sanctions cases are useful only when the lesson matches the failure. A missing sanctions-list record, inadequate customer due diligence and unreported suspicious activity are different problems. None can be fixed by buying one screening tool and assuming the whole compliance programme is covered.

These six documented cases span 2012–2024. They are not a ranking of the largest fines: the authorities used different legal powers, currencies, settlements and penalty calculations. Each case identifies the authority's finding, the relevant control and the boundary of name screening.

Six AML and sanctions enforcement cases at a glance

CaseAuthority and outcomeControl lessonRole of name screening
HSBC, 2012U.S. DOJ deferred prosecution agreement and $1.256bn forfeitureCorrespondent-bank due diligence and sanctions controlsRelevant to named parties, not a substitute for correspondent due diligence
BNP Paribas, 2014U.S. DOJ guilty-plea agreement and almost $9bn in penaltiesSanctions evasion and concealed payment informationRelevant, but deliberate concealment also requires governance and payment controls
ING, 2018Dutch prosecution settlement of €775mCustomer due diligence, transaction monitoring and escalationA supporting input, not a behavioural-monitoring system
Danske Bank, 2022U.S. DOJ guilty plea and $2.059bn criminal forfeitureMisrepresented AML controls and high-risk customer activityCannot repair inaccurate customer information or deceptive governance
Binance, 2023U.S. DOJ guilty plea and resolution exceeding $4bnAML programme and sanctions restrictionsRelevant to supplied parties, but not a complete crypto or transaction-monitoring control
Starling Bank, 2024UK FCA fine of £28,959,426Incomplete sanctions-list screening and high-risk account controlsDirect example of source-coverage and testing failure

The outcomes above describe specific resolutions, not directly comparable totals. See each authority's release in the sources below.

HSBC: correspondent due diligence and sanctions exposure

In 2012, HSBC Holdings and HSBC Bank USA entered a deferred prosecution agreement with the U.S. Department of Justice that included $1.256bn in forfeiture. The case joined two failures that are easy to blur together: weak AML oversight of foreign correspondent accounts and prohibited transactions involving sanctioned countries.

On the AML side, the DOJ said HSBC Bank USA had severely understaffed its compliance function and failed to monitor enormous flows from HSBC Mexico despite known risk. It rated Mexico in its lowest risk category and did not adequately monitor more than $670bn in wires and $9.4bn in physical-dollar purchases from that affiliate. Prosecutors said at least $881m in drug-trafficking proceeds passed through HSBC Bank USA. These were failures of correspondent due diligence, risk classification, transaction monitoring and group oversight—not simply missed name matches.

The sanctions conduct exposed a different weakness. According to the DOJ, HSBC Group affiliates removed or omitted sanctioned-party and country information from U.S.-dollar payment messages, used less-transparent cover payments and continued despite internal warnings that the U.S. bank could not properly screen those payments. Even a well-configured filter cannot match an identity that has deliberately been stripped from the message it receives.

The warnings were not theoretical. The DOJ said HSBC Bank USA raised concerns as early as 2001 that cover payments prevented it from confirming whether the underlying transactions met U.S. sanctions requirements. Group affiliates nevertheless continued the practice. This is a failure at the point where payment information is assembled and passed between institutions: the U.S. bank's screening control depended on facts that another part of the group chose not to send.

The outcome also involved more than the headline forfeiture. The DOJ reported separate civil AML penalties and said HSBC committed to group-wide compliance changes and independent oversight under the deferred prosecution agreement. Those measures reflect the breadth of the failure: staffing, correspondent-risk decisions, transaction surveillance, payment-message integrity and escalation across the group all mattered. A team learning from this case should examine the actual data a downstream filter receives, compare it with the original payment instruction and verify that warnings about missing or altered fields reach a decision-maker.

Operational lesson: define which correspondent institutions, customers and payment parties enter each control. Screening a supplied name can surface a candidate sanctions match. It cannot establish the quality of correspondent due diligence, analyse transaction behaviour or make a reporting decision.

BNP Paribas: sanctions evasion is more than a matching problem

The DOJ announced in 2014 that BNP Paribas had agreed to plead guilty and pay almost $9bn in penalties for processing transactions through the U.S. financial system on behalf of sanctioned Sudanese, Iranian and Cuban entities. The authority said the bank knowingly moved more than $8.8bn over roughly eight years, including transactions involving specifically designated entities.

The mechanism matters more than the headline penalty. The DOJ described the use of other financial institutions to disguise the bank's and sanctioned parties' roles, instructions not to name sanctioned entities in U.S.-bound payment messages, and the removal of identifying references. In one Cuban-payment example, after payments were blocked, the bank stripped references to Cuban entities and resubmitted the funds as a lump sum. Internal warnings about the arrangements did not stop the conduct.

This was not a case where a slightly better similarity threshold would, by itself, have solved the problem. The relevant party data was concealed upstream of the filter, while the business kept routing prohibited payments. The operational control must preserve complete payment-party information, make alterations visible and escalate evidence of deliberate evasion.

The DOJ described a structured route around the controls. So-called satellite banks helped obscure both BNP Paribas's role and the sanctioned parties' involvement in U.S.-bound transfers. Internal emails acknowledged the sanctions risk, yet the arrangements continued. The bank also processed Cuban transactions after blocked payments had made the risk visible. In other words, the problem was not simply a list update that had been missed; the organisation had information about the restricted activity and maintained a way for it to proceed.

The legal resolution makes the distinction important. The announced criminal plea concerned a conspiracy to violate U.S. sanctions laws, and the nearly $9bn figure combined forfeiture and a fine; other regulators announced related measures, with credits between some payments. Treating all of that as a single 'screening fine' would distort the case. The practical review is whether the firm can reconstruct an original payment, every transformation of its party data and the approval trail for exceptions—especially after a transaction has already been blocked.

Operational lesson: screen the parties and identifiers actually available to the payment workflow, preserve the original information and investigate plausible matches. A matching engine cannot compensate for deliberately removed or altered payment data. Escalation, oversight and sanctions legal analysis remain essential.

ING: name screening cannot detect transaction patterns

The Netherlands Public Prosecution Service announced a €775m settlement with ING in 2018 after finding structural shortcomings in its Dutch AML controls. Prosecutors said customers were accepted without sufficient investigation of their risks, some were placed in the wrong risk segments, accounts were inadequately monitored and unusual transactions were reported late or not at all.

The authority described a compliance function that was understaffed and insufficiently trained. Transaction-monitoring settings generated only a limited set of signals, and the bank investigated too few of them. In one example, a trading company's account moved about €150m in flows that had little apparent connection to its stated business; monitoring alerts were set aside with little investigation. In another, ING reported bribery-linked payments far too late and had not sufficiently established the actual owner of the recipient company.

The breakdown was end to end: weak onboarding information fed an inaccurate customer-risk view; monitoring and investigation did not correct it; reporting came late. A name-screening result could contribute information about a supplied person or entity, but it would not reveal that these account flows were inconsistent with the customer's business.

The Dutch authority gave further examples of the gap between a customer's stated business and observed activity. A building-materials sole trader with no Dutch address used mobile ATMs in Suriname in a way investigators described as a currency-exchange operation, while a separate produce-trading case involved cash deposits that were barely flagged. These examples show why an account can have a complete set of name checks and still present an obvious behavioural question: does the money movement make sense for the customer the bank says it knows?

The €775m settlement comprised a €675m fine and €100m disgorgement, according to the prosecution service. It said warnings from the Dutch central bank and improvement programmes had not adequately corrected the structural weaknesses. For a compliance team, the useful test is to trace one anomalous customer from onboarding file to risk classification, monitoring scenario, alert closure and any report to the FIU. The question is not whether a tool produced an alert; it is whether the facts available at each step were investigated and acted on.

Operational lesson: a customer name check answers whether supplied identity data may match a configured risk source. It does not detect unusual account behaviour, reconstruct the source of funds or decide whether a transaction should be reported. Treat customer risk assessment and transaction-monitoring processes as distinct from name screening.

Danske Bank: local weaknesses and inaccurate assurances

Danske Bank pleaded guilty in the United States in 2022 to conspiring to commit bank fraud and agreed to $2.059bn in criminal forfeiture. Its Estonian branch ran a profitable non-resident customer business, including customers outside Estonia who needed U.S.-dollar access. The DOJ said the branch processed $160bn through U.S. banks for this population between 2008 and 2016.

Prosecutors described little oversight of these customers and transactions. Branch employees worked with customers to obscure the true nature of payments, including through shell companies that hid ownership of funds. By at least 2014, internal audits, regulators and a whistleblower had put Danske Bank on notice of suspicious activity and inadequate local controls. Yet the bank gave U.S. correspondent banks misleading information about the Estonian branch's customers, AML programme and transaction-monitoring capability so those banks would maintain access.

The U.S. charge was bank fraud against the correspondent banks, not a finding that a particular sanctions-screening algorithm missed a listed name. Screening cannot repair deliberately misleading customer information or substitute for truthful partner disclosures and effective controls at a distant branch.

The correspondent relationship explains why the inaccurate assurances mattered. The U.S. banks needed information about the Estonian branch's customer base, AML programme and monitoring to decide whether to maintain dollar accounts. Danske knew those banks expected complete and accurate answers; the DOJ said they would not have maintained or opened the accounts without them. The branch's $160bn in U.S.-processed flows therefore sat behind a control description that concealed material weaknesses from the institutions providing access.

The chronology is also part of the lesson. By February 2014, internal audits, regulators and a whistleblower had raised concerns about suspicious customers and the adequacy of branch controls, yet the misleading information continued. A credible review should compare management's external assurances with branch-level evidence: high-risk customer files, ownership information actually obtained, alert investigation capacity and unresolved internal findings. A sanctions or PEP screen may contribute to that evidence, but it cannot certify the truth of the wider programme described to a banking partner.

Operational lesson: test what each branch or partner actually does and can evidence. A screening result is only as useful as the supplied customer data, the source configuration and the process that acts on it. It cannot correct misleading representations about the wider AML programme.

Binance: sanctions, onboarding and AML programme design

In 2023, Binance pleaded guilty to U.S. AML, unlicensed money-transmitting and sanctions offences in a coordinated resolution exceeding $4bn. Its founder and then CEO separately pleaded guilty to failing to maintain an effective AML programme and resigned as CEO. The DOJ described a platform that served U.S. customers while prioritising growth over the controls that this business required.

For years, users could open accounts and trade with no identifying information beyond an email address. The DOJ said Binance lacked comprehensive KYC, did not systematically monitor transactions and never filed a suspicious activity report with FinCEN. It also knew that its trading engine would connect U.S. users with users in sanctioned jurisdictions, yet did not implement controls to prevent those trades. Prosecutors identified more than $898m in trades between U.S. users and users ordinarily resident in Iran from January 2018 to May 2022.

This case shows why identity capture, sanctions controls, geographic and transaction restrictions, behavioural monitoring and reporting are connected but separate. A sanctions name check has limited value when the operator has not collected enough reliable customer data or has designed the trading flow to proceed despite known restrictions.

The operating choices were specific. Binance announced in 2019 that it would block U.S. users and launched a separate U.S. exchange, yet the DOJ said it worked to retain valuable U.S. VIP customers, including by helping some move holdings to offshore-entity accounts or supply information suggesting they were not in the United States. It did not begin requiring KYC information from all users until August 2021, and users who had not supplied it could continue trading until May 2022. The sanctions issue was therefore intertwined with account-location and access controls, not just a person's name on a list.

The DOJ's reference to Binance's 'matching engine' means the exchange's trade-matching system, not sanctions name-matching software. It connected U.S. users with users ordinarily resident in Iran while the business knew the legal problem. The practical audit should test whether the platform can establish who is trading, which jurisdictional restrictions apply to the pair, whether those restrictions are enforced before execution and whether monitoring and reporting can detect conduct that slips through. Checklynx's party screening can inform part of that sequence, but it does not perform the exchange's geographic, trading or behavioural controls.

Operational lesson: sanctions screening of supplied people and entities is one control in a broader customer and transaction process. It does not by itself verify identity, assess wallet activity, detect suspicious transaction patterns or satisfy every restriction affecting a crypto service. See the separate VASP sanctions-screening guide for the defined party-screening workflow.

Starling Bank: incomplete sanctions-list coverage

The UK's Financial Conduct Authority fined Starling Bank £28,959,426 in 2024 for financial-crime systems and controls failings. Starling grew from about 43,000 customers in 2017 to 3.6 million in 2023, but, according to the FCA, its controls did not keep pace. In January 2023 the bank discovered that its automated system had, since 2017, screened customers against only a fraction of the full list of people subject to financial sanctions.

This is a direct source-coverage failure: an automated check can run successfully and still produce a misleadingly clean result if the configured list is incomplete. The FCA said a subsequent internal review found wider systemic problems in the sanctions framework and that Starling later reported multiple potential sanctions breaches. The practical test is therefore not just whether screening runs, but whether the intended source data reaches production in full and stays complete after updates.

There was also a separate governance failure. After the FCA identified concerns in 2021, Starling agreed not to open new accounts for high-risk customers until its controls improved. The FCA said it nevertheless opened more than 54,000 accounts for 49,000 high-risk customers from September 2021 to November 2023. A name-screening engine could not enforce that supervisory account-opening restriction on its own.

The two defects need separate owners. One concerns source coverage: the automated system ran, but checked customers against only part of the sanctions population the bank was meant to use. The other concerns an account-opening restriction: even if a name check had been technically sound, the bank's onboarding process still needed to enforce the agreed high-risk-customer limit. The FCA said the bank later identified wider sanctions-framework problems and reported potential breaches; it did not say that every account opened in breach of the restriction belonged to a sanctioned person.

This is the case in the set that most directly tests a screening implementation. A useful control pack would retain the approved source inventory, evidence that every expected record reached production, regression tests after feed or configuration changes, sample positive and negative matches, and a record of who resolved alerts. Separately, the firm should test whether a restricted customer category can advance through onboarding at all. Those tests ask different questions and should fail independently when their respective controls break.

Operational lesson: document the intended sanctions sources, verify that the complete approved data reaches production and test the live configuration after changes. Running checks is not enough if the input list is incomplete. The account-opening restriction was a separate control failure; name screening alone would not enforce it.

What these cases mean for a screening programme

The cases do not prove that a particular vendor would have prevented any outcome. They do suggest practical questions for teams reviewing their own controls:

  1. Population: Which customers, companies, supplied owners, counterparties and payment parties actually enter screening?
  2. Sources: Are the approved lists complete and current in the production configuration?
  3. Matching and investigation: Can analysts examine identifiers and source context before resolving a candidate?
  4. Decision ownership: Who can hold, release, escalate or report, and where is that decision recorded?
  5. Separate controls: Which gaps belong to due diligence, behavioural transaction monitoring, payment data quality or governance instead?

Checklynx supports sanctions screening, PEP screening, ongoing re-screening and case evidence for supplied parties. It does not verify identity or source of funds, discover every owner, detect behavioural transaction patterns, file suspicious-activity reports or decide the final legal response. For a broader implementation method, use the practical sanctions-screening guide.

Frequently asked questions

Were all six cases sanctions-screening failures?

No. BNP Paribas and Starling have direct sanctions-control lessons. HSBC and Binance involved sanctions as well as wider AML failures. ING and Danske principally illustrate due-diligence, monitoring, escalation or governance failures. Calling all six a simple name-matching failure would misstate the authorities' findings.

Would better sanctions-screening software have prevented these penalties?

The enforcement records do not establish that counterfactual. Appropriate software can support defined party checks, source coverage, review and evidence. It cannot replace accurate upstream data, transaction monitoring, reporting, governance or legal judgement.

What should a team test after reading these cases?

Test representative in-scope parties against the production sources and settings, including expected matches and non-matches. Then trace a candidate through analyst review, escalation and the retained decision. Test separate transaction-monitoring and reporting controls on their own terms rather than treating a name-screening test as an AML-programme audit.

Official sources

Share
Blog

Footer

AML Fines and Sanctions Cases: Six Enforcement Lessons