Business-identity and ownership analysis must connect corporate structure, authority, claimed purpose, transaction behavior, and cross-border evidence. A static company file cannot answer every risk question.
CASE 002
Netherlands
ABN AMRO Bank N.V.
Authority
NL-NPPS
Public event
2021-04-19
A low-risk label or process completion cannot substitute for evidence that customer and reporting risk are correctly understood and acted upon across the lifecycle.
CASE 003
United Kingdom
Arian Financial LLP - FCA Final Notice
Authority
Financial Conduct Authority
Public event
2025-01-09
KYB evidence is not a control until it is read, reconciled, risk-assessed, and connected to plausible business purpose and ongoing monitoring.
CASE 004
New Zealand
ASB Bank AML/CFT penalty
Authority
Reserve Bank of New Zealand
Public event
2026-06-10
Monitoring, data, governance and management awareness must remain connected over time; a program cannot rely on historic design or nominal policy compliance.
CASE 005
Cross-border / not specified
AUSTRAC Proceedings Against Westpac
Authority
Australian Transaction Reports and Analysis Centre
Public event
20 Nov. 2019
Illustrates that product and channel complexity require coherent program control.
CASE 006
Australia
AUSTRAC reform implementation and enforcement register
Authority
AUSTRAC
Public event
2025-2026
A reform program requires a law-to-control migration, scope mapping, configuration, validation and BAU evidence; public enforcement remains a test of actual operation.
CASE 007
Germany
BaFin measures on N26 Bank AG
Authority
BaFin
Public event
2021-11-01
A common digital platform and fast growth need entity-level AML/CFT governance, monitoring, data, escalation and evidence that meet supervisory scrutiny.
CASE 008
United Kingdom
Barclays - FCA Financial-Crime Risk Action
Authority
Financial Conduct Authority
Public event
2025-07-16
Monitoring must form part of an integrated customer, product, and governance system.
CASE 009
United Kingdom
Barclays Bank UK final notice
Authority
Financial Conduct Authority
Public event
2025-07-14
Final notices should be used as control-evidence case studies: establish facts, affected systems/decisions, root causes, remediation proof and limits of inference.
CASE 010
Cross-border / not specified
Binance Global Resolution
Authority
U.S. Department of Justice / U.S. Commodity Futures Trading Commission
Public event
21 Nov. and 18 Dec. 2023
Illustrates enterprise failure where global product reach and compliance controls diverge.
CASE 011
United States / global
Binance Holdings - OFAC Settlement
Authority
Office of Foreign Assets Control
Public event
2023-11-21
Sanctions controls must be designed for the actual product, customer, and cross-border operating model.
CASE 012
United States / global digital-asset platform
Binance resolution
Authority
DOJ / FinCEN
Public event
2023-11-21
A platform’s global reach, customer access, entity model, transaction data and controls must be reconciled to the legal obligations that apply to its activity.
CASE 013
United States
Bittrex, Inc.
Authority
Financial Crimes Enforcement Network
Public event
2022-10-11
Digital-asset customer diligence must be designed for the actual counterparty, geography, transaction, and technology-risk model rather than copied from a generic retail flow.
CASE 014
United States
CFPB Zelle Fraud Litigation Announcement
Authority
Consumer Financial Protection Bureau
Public event
2024-12-17
Payment-fraud oversight may concern network design, institution controls, customer outcomes, and escalation, not only individual transaction review.
CASE 015
Global
CPMI Correspondent Banking Final Report
Authority
Committee on Payments and Market Infrastructures
Public event
2016-07-13
A transparent, well-governed payment chain supports integrity and sustainable access.
CASE 016
Australia
Crown Melbourne and Crown Perth
Authority
AU-AUSTRAC
Public event
2023-07-11
An assessment cannot be treated as a static document. Governance must test whether it is reflected in controls, decisions, oversight, and live evidence.
CASE 017
Australia
Crown Resorts
Authority
AUSTRAC / Federal Court
Public event
2023-07-11
A risk assessment must change as the risk changes.
CASE 018
United States / Estonia branch context
Danske Bank Estonia
Authority
United States Department of Justice
Public event
2022-12-13
Global claims need local evidence.
CASE 019
Cross-border / not specified
Danske Bank Resolution
Authority
U.S. Department of Justice
Public event
13 Dec. 2022
Illustrates global governance and local-risk visibility failures.
CASE 020
Netherlands
DNB administrative fine on ABN AMRO
Authority
De Nederlandsche Bank
Public event
2021
Customer due diligence is an operating evidence system; national enforcement can surface root causes relevant to group policy, data and assurance.
CASE 021
Cross-border / not specified
EDPB Article 48 Guidance
Authority
European Data Protection Board
Public event
5 June 2025
Illustrates cross-border authority-request data governance.
CASE 022
Cross-border / not specified
EU Artificial Intelligence Act
Authority
European Union
Public event
13 June 2024
Illustrates external legal overlay for AI use.
CASE 023
European Union
EU Transfer-of-Funds Regulation
Authority
European Union
Public event
2023-05-31
Payment transparency requirements are legal and data-design requirements, not merely formatting preferences.
CASE 024
Cross-border / not specified
FATF 2026 Global Overview of PPPs and Data Protection Arrangements
Authority
Financial Action Task Force
Public event
July 2026
Illustrates lawful information sharing and public-private partnership design.
CASE 025
Global
FATF Complex Proliferation Financing and Sanctions Evasion Schemes
Authority
Financial Action Task Force
Public event
2025-06-20
PF risk needs dedicated risk assessment, multi-source intelligence, and a controlled legal-to-operational translation.
CASE 026
Cross-border / not specified
FATF DeFi Targeted Report
Authority
Financial Action Task Force
Public event
24 July 2026
Illustrates functional decomposition and DeFi accountability.
CASE 027
Global
FATF Effectiveness Methodology
Authority
Financial Action Task Force
Public event
2026-06-01
A monitoring program needs outcome evidence as well as policy and process existence.
CASE 028
Cross-border / not specified
FATF Offshore VASP Risk Report
Authority
Financial Action Task Force
Public event
11 Mar. 2026
Illustrates supervisory perimeter and counterparty-control risk.
CASE 029
Global
FATF Proliferation-Financing Guidance
Authority
Financial Action Task Force
Public event
2021-06-29
PF risk requires a broader data and intelligence model than bare sanctions-list matching.
CASE 030
Cross-border / not specified
FATF Public-Private Information-Sharing Overview
Authority
Financial Action Task Force
Public event
July 2026
Illustrates information-sharing governance across jurisdictions.
CASE 031
United States
FinCEN Money Mule Advisory
Authority
Financial Crimes Enforcement Network
Public event
2019-11-22
Typology signals can improve questions and scenarios but must be combined with institution-specific evidence.
CASE 032
United States
FinCEN Section 314(b) Fact Sheet
Authority
Financial Crimes Enforcement Network
Public event
2026-08-09
Information sharing should have explicit eligibility, purpose, safeguards, and records.
CASE 033
Canada
FINTRAC administrative monetary penalty on Binance Holdings Limited
Authority
FINTRAC
Public event
2024-05-09
Virtual-asset activity should be evaluated through coverage, registration, customer, transaction, report, governance and evidence design—not a generic “crypto” label.
CASE 034
Canada
FINTRAC sanctions-property reporting update
Authority
FINTRAC
Public event
2025
Sanctions and AML reporting may share intelligence but require distinct legal source, property/control analysis, report and evidence.
Financial-crime transparency architecture must be designed around lawful access, purpose limitation and evidence, not an assumption of universal public data.
CASE 039
European Union
Luxembourg Business Registers and Sovim
Authority
Court of Justice of the European Union
Public event
2022-11-22
Transparency infrastructure must be designed with lawful access, privacy, purpose limitation, and auditability. Public availability is not a universal KYB design assumption.
CASE 040
Singapore
MAS actions against nine financial institutions
Authority
Monetary Authority of Singapore
Public event
2025-07-04
A common group policy requires local regulated-entity proof.
CASE 041
United States
Metropolitan Commercial Bank
Authority
Federal Deposit Insurance Corporation
Public event
2023
The regulated entity must retain a complete map of delegated customer-lifecycle tasks, data, authority, assurance, and escalation.
CASE 042
United Kingdom
NatWest
Authority
Financial Conduct Authority
Public event
2021-12-13
Control framework presence does not establish effective execution.
CASE 043
United Kingdom
NatWest - FCA AML Enforcement Action
Authority
Financial Conduct Authority
Public event
2021-12-13
Case investigation, customer understanding, monitoring, escalation, and action must work as a joined system.
CASE 044
United Kingdom
NatWest AML enforcement
Authority
Financial Conduct Authority
Public event
2021-12-13
Cash-intensive or anomalous activity must be understood against customer behavior, risk appetite, escalation and reliable evidence; policy presence is not control operation.
CASE 045
Cross-border / not specified
NIST Generative AI Profile
Authority
National Institute of Standards and Technology
Public event
26 July 2024
Illustrates GenAI governance and safety evidence.
CASE 046
United States
OFAC Maritime Sanctions Guidance
Authority
Office of Foreign Assets Control
Public event
2024-10-31
Maritime information can be relevant to a risk-based inquiry, but must be assessed with source quality, legal scope, and operational timing in mind.
CASE 047
Mainland China
Revised PRC Anti-Money Laundering Law announcement
Authority
State Council
Public event
2024-11-09
Legal change in Mainland China should trigger an entity/product/data/workflow/evidence impact assessment rather than a global policy assertion.
CASE 048
United Kingdom
Santander UK
Authority
Financial Conduct Authority
Public event
2022-12-09
Remediation must be durable, evidenced, and independently retested.
CASE 049
United States
Seagate - BIS Export Enforcement Action
Authority
Bureau of Industry and Security
Public event
2023-04-19
Export-control compliance requires accountable classification, rule translation, transaction controls, escalation, and evidence of execution.
CASE 050
United States / Singapore / cross-border
Seagate Technology - BIS Export-Control Order
Authority
Bureau of Industry and Security
Public event
2023-04-19
Item, end-user, technology, and licensing analysis cannot be replaced by name screening.
Registry information can be valuable and still contain false declarations. A KYB program must preserve provenance, test contradictions, and avoid a blanket 'registry verified' conclusion.
CASE 052
Singapore
Singapore Shared Responsibility Framework
Authority
Monetary Authority of Singapore
Public event
2024-10-16
Scam prevention and outcomes can require coordinated cross-industry operating responsibilities.
CASE 053
United Kingdom
Starling Bank - FCA Financial-Crime Controls Action
Authority
Financial Conduct Authority
Public event
2024-10-02
Stated controls must be reflected in the actual population, workflow, and governance.
CASE 054
United Kingdom
Starling Bank financial-crime enforcement
Authority
Financial Conduct Authority
Public event
2024-10-02
Growth, automation and customer experience need explicit control gates, quality evidence, independent challenge and senior ownership.
CASE 055
United Kingdom
Starling Bank financial-crime final outcome
Authority
Financial Conduct Authority
Public event
2024-10-02
A fast-growing digital operating model needs pre-defined growth gates, evidence of control operation, and independent challenge before expanding exposure.
CASE 056
Cross-border / not specified
Starling Bank Financial-Crime Systems and Controls Action
Authority
Financial Conduct Authority
Public event
2 Oct. 2024
Illustrates systems/control drift and growth risk.
CASE 057
United Kingdom
Starling Bank Limited
Authority
UK-FCA
Public event
2024-10-02
A risk boundary only exists when it is mechanically enforced at the decision point and independently tested; a committee minute or voluntary restriction alone is not a control.
CASE 058
Taiwan
Taiwan FSC Bank of Taiwan administrative penalty
Authority
Financial Supervisory Commission
Public event
2025-03-11
Onboarding, payment activity, ongoing due diligence, monitoring and conduct must be viewed as an integrated control system.
Regional leaders should test whether country-level changes create a hidden cross-border gap in data, reports, customer actions or model governance.
CASE 060
United States
TD Bank - FinCEN Consent Order
Authority
Financial Crimes Enforcement Network
Public event
2024-10-10
Scenario inventory, data coverage, change control, escalation, and tested remediation are inseparable.
CASE 061
United States
TD Bank BSA resolution
Authority
Department of Justice / FinCEN
Public event
2024-10-10
Scale, growth, data and staffing choices must be read as one control system; volume alone cannot excuse a program whose monitoring and governance are ineffective.
CASE 062
Cross-border / not specified
TD Bank BSA/AML Enforcement
Authority
Financial Crimes Enforcement Network / U.S. Department of Justice
Public event
10 Oct. 2024
Illustrates transaction population and data/control coverage failure.
CASE 063
Cross-border / not specified
TD Bank BSA/AML Enforcement
Authority
Financial Crimes Enforcement Network
Public event
10 Oct. 2024
Illustrates that technology does not replace accountable AML program ownership.
CASE 064
United States; Canada group context
TD Bank, N.A. and related U.S. holding company resolution
Authority
US-FINCEN
Public event
2024-10-10
The governance lesson is not simply to spend more. It is to demonstrate a defensible link between risk assumptions, capacity, control coverage, escalation, and resource allocation.
CASE 065
Cross-border / not specified
Tornado Cash Sanctions Action
Authority
U.S. Department of the Treasury
Public event
8 Aug. 2022
Illustrates sanctions architecture for virtual-currency identifiers.
CASE 066
United States
U.S. Interagency Tri-Seal Compliance Note
Authority
BIS, Department of Justice, and OFAC
Public event
2023-03-02
Third-party intermediaries, data inconsistencies, and routing changes should be controlled as risk hypotheses with evidence and escalation.
CASE 067
Mexico
UIF-CNBV coordination agreement
Authority
UIF / CNBV
Public event
2026-03-16
Changes in intelligence-supervisory coordination should trigger data, report, governance, training and regulatory-readiness impact assessment.
CASE 068
United States
USAA Federal Savings Bank enforcement action
Authority
FinCEN
Public event
2022-03-17
Customer onboarding, risk classification, monitoring, governance and testing need an evidentiary thread that can withstand independent review.
CASE 069
Australia
Westpac - AUSTRAC AML Contraventions
Authority
Australian Transaction Reports and Analysis Centre
Public event
2020-09-24
Payment transparency, data quality, due diligence, monitoring, and reportable-event controls are interdependent.
CASE 070
Australia
Westpac Banking Corporation
Authority
AUSTRAC
Public event
2020-09-24
EDD must be activated by material behavior and linked to monitoring, investigations, reporting, and quality assurance - not isolated to onboarding.
CASE 071
Australia
Westpac Banking Corporation
Authority
AU-AUSTRAC
Public event
2020-10-21
Risk governance must test concentration and cross-border exposure at the level of the relationship and channel, not merely at a total-bank average.
CASE 072
Australia
Westpac civil penalty proceedings
Authority
AUSTRAC
Public event
2019-11-20
Payment scale and product growth must be accompanied by guardrails, visibility, and a demonstrated ability to identify and act on risk.