BANK MONEY LAUNDERING CASES: MAJOR AML FAILURES, FINES AND LESSONS

Compliance

What the cases of TD Bank, HSBC, Danske Bank, ING, ABN AMRO and others teach us about suspicious activity reporting, transaction monitoring and financial crime compliance.

 

Banks occupy a critical position in the global fight against financial crime. They process enormous volumes of transactions every day and are expected to understand their customers, monitor transactions, identify unusual activity and report suspicions to the appropriate Financial Intelligence Unit.

Yet some of the world’s largest banks have themselves been at the center of major money-laundering and anti-money laundering enforcement cases.

The circumstances vary considerably. Some banks have pleaded guilty to criminal offences. Others have been sanctioned for serious failures in customer due diligence, transaction monitoring or suspicious activity reporting. Investigations such as the FinCEN Files have also revealed enormous volumes of suspicious transactions processed by global banks.

Understanding the distinction between these situations is important for compliance professionals and the general public.

 

BUILDING ON THE FINCEN FILES

This article builds on our earlier publication, “Unveiling the Systemic Compliance Failures in Banks: Insights from the FinCEN Files”, which examined the compliance weaknesses highlighted by the FinCEN Files.

Here, we take the discussion further by looking at major enforcement cases and distinguishing between criminal or institutional misconduct, serious anti-money laundering and reporting failures, and documented exposure to suspicious transactions.

 

 

THREE DIFFERENT TYPES OF CASES

It would be misleading to describe every bank appearing in a money-laundering investigation as having “laundered money.” The cases can broadly be divided into three categories.

🔴 Criminal or Serious Institutional Findings

These are the most serious cases. They include banks that pleaded guilty to criminal offences, admitted serious misconduct as part of a criminal resolution, or were subject to formal findings connecting institutional failures to money laundering.

Examples include TD Bank, HSBC, Danske Bank, Rabobank, NatWest, ING Bank and ABN AMRO.

🟠 Willful or Repeated Anti-Money Laundering and Reporting Failures

These cases involve authorities establishing serious failures in controls designed to detect and prevent financial crime. These can include failure to adequately monitor transactions, investigate significant warning signs, submit required suspicious activity reports, maintain adequate customer information, appropriately manage high-risk customers or correct known deficiencies.

Such findings can be extremely serious without necessarily establishing that the bank itself committed the criminal offence of money laundering.

🟡 Documented Exposure to Suspicious Transactions

This category includes banks appearing prominently in investigations such as the FinCEN Files, without an equivalent official finding that the bank itself committed money laundering.

A suspicious transaction is not automatically a criminal transaction. Likewise, filing a suspicious activity report can demonstrate that a bank identified and reported potentially suspicious activity.

The relevant questions are therefore often when the bank identified the activity, what it knew about the customer, whether it reported the concerns promptly and what it did after identifying the risk.

 

 

TD BANK: A LANDMARK CRIMINAL CASE

The 2024 TD Bank case represents one of the most significant bank anti-money laundering enforcement actions in United States history.

United States authorities found pervasive and systemic deficiencies in the bank’s anti-money laundering controls. During part of the relevant period, approximately 92 percent of TD Bank’s transaction volume was not monitored through its automated transaction-monitoring system, representing approximately 18.3 trillion United States dollars of transaction activity.

Authorities identified three money-laundering networks that collectively transferred more than 670 million United States dollars through TD Bank accounts. One network was assisted by five TD Bank employees.

TD Bank pleaded guilty to offences including conspiracy to launder monetary instruments and violations of the United States Bank Secrecy Act. The Department of Justice criminal resolution amounted to approximately 1.89 billion United States dollars, while combined United States enforcement penalties were approximately 3 billion United States dollars.

The consequences did not stop with the institution. More than two dozen individuals were prosecuted in connection with laundering schemes involving TD Bank accounts. Former bank employees have subsequently pleaded guilty to facilitating money laundering.

The case demonstrates how persistent failures to address known weaknesses can progress from compliance deficiencies to institutional criminal liability.

 

 

HSBC: DRUG MONEY AND DEFICIENT CONTROLS

The HSBC case remains one of the most widely known examples of major bank anti-money laundering failures.

United States authorities found that serious deficiencies in HSBC’s anti-money laundering controls allowed Mexican and Colombian drug-trafficking organizations to launder at least 881 million United States dollars in drug proceeds through the bank.

HSBC also failed to adequately monitor enormous volumes of transactions involving HSBC Mexico despite the significant money-laundering risks associated with the business.

In 2012, HSBC entered into a Deferred Prosecution Agreement with the United States Department of Justice and agreed to a major financial settlement.

A Deferred Prosecution Agreement is an arrangement under which prosecution is deferred for a specified period while an organization complies with agreed conditions. These may include paying penalties, cooperating with authorities, improving compliance systems and being supervised by an independent monitor. Successful completion can result in the charges being dismissed.

HSBC was subject to a five-year agreement, independent monitoring and significant compliance reforms. Senior executives were not criminally prosecuted as part of the principal resolution.

 

 

DANSKE BANK: THE ESTONIA SCANDAL

Danske Bank’s Estonia branch became the center of one of Europe’s largest money-laundering scandals.

Between approximately 2007 and 2015, the branch maintained a large portfolio of high-risk non-resident customers, including customers from Russia and other countries in the former Soviet Union.

Approximately 200 billion euros flowed through the non-resident portfolio. This does not mean that 200 billion euros was proven to be criminal money. It represents the enormous volume of transactions passing through the high-risk portfolio.

United States authorities found that Danske Bank misrepresented the state of its anti-money laundering controls and customer risks to United States correspondent banks.

Danske Bank pleaded guilty to conspiracy to commit bank fraud and agreed to a multibillion-dollar resolution. The case resulted in extensive restructuring of the bank’s compliance and anti-money laundering operations.

 

 

ING BANK AND ABN AMRO: THE DUTCH EXPERIENCE

Two of the Netherlands’ largest banks have faced major enforcement actions concerning structural anti-money laundering deficiencies.

ING Bank

Dutch prosecutors concluded that ING had serious and structural shortcomings in areas including customer due diligence and transaction monitoring. These shortcomings allowed customers to use ING accounts for money laundering.

The Dutch Public Prosecution Service attributed culpable money laundering to ING.

In 2018, ING agreed to pay 775 million euros, consisting of a 675 million euro fine and 100 million euros in disgorgement.

Former Chief Executive Officer Ralph Hamers was subsequently investigated concerning possible personal responsibility. The proceedings ultimately did not result in his conviction.

ABN AMRO

Dutch prosecutors identified serious deficiencies in customer identification, ongoing monitoring, termination of problematic customer relationships and reporting of unusual transactions.

In 2021, ABN AMRO agreed to pay 480 million euros, consisting of a 300 million euro fine and 180 million euros in disgorgement.

Former directors were investigated concerning possible personal criminal responsibility, but those investigations did not ultimately result in convictions.

These Dutch cases demonstrate an important distinction between establishing institutional responsibility and proving the personal criminal liability of individual directors.

 

 

RABOBANK: WHEN COMPLIANCE DEFICIENCIES WERE CONCEALED

United States authorities found that Rabobank National Association failed to maintain an effective anti-money laundering program and did not adequately investigate and report suspicious transactions associated with areas presenting significant risks of drug trafficking and organized crime.

The case became more serious because deficiencies were concealed from regulators.

Rabobank pleaded guilty and agreed to forfeit approximately 368.7 million United States dollars, in addition to a 500,000 dollar fine.

A former executive also admitted involvement in efforts to obstruct the regulatory examination of the bank’s anti-money laundering program.

The case demonstrates an important distinction: having deficient controls is serious, but knowingly concealing those deficiencies from a regulator can substantially increase the legal consequences.

 

 

NATWEST: WARNING SIGNS WERE ALREADY THERE

The NatWest case provides a useful example of why transaction monitoring cannot simply be a technical exercise.

A customer, Fowler Oldfield, deposited approximately 365 million pounds, including approximately 264 million pounds in cash, despite the customer’s expected activity being considerably different.

Warning signs concerning the customer’s cash activity were raised internally, but the bank’s controls did not respond adequately.

NatWest eventually pleaded guilty to three offences under the United Kingdom’s Money Laundering Regulations and was fined approximately 264.8 million pounds.

It was the first criminal prosecution of a bank by the United Kingdom Financial Conduct Authority under those regulations.

 

 

CAPITAL ONE: THOUSANDS OF MISSING SUSPICIOUS ACTIVITY REPORTS

Capital One is particularly important when examining whether banks properly reported suspicious transactions.

The United States Financial Crimes Enforcement Network found that Capital One willfully failed to file thousands of required Suspicious Activity Reports connected with its Check Cashing Group.

The bank also failed to file thousands of required Currency Transaction Reports. The violations resulted in suspicious transactions going unreported in a timely and accurate manner, including transactions associated with organized crime, fraud, tax evasion and other financial crimes.

The Financial Crimes Enforcement Network imposed a 390 million United States dollar civil money penalty.

This case provides a particularly clear example of an official finding concerning failure to meet financial-crime reporting obligations.

 

 

JPMORGAN CHASE: SUSPICION WITHOUT PROPER REPORTING

JPMorgan Chase’s relationship with Bernard Madoff provides another important reporting example.

The bank had information that caused it to become suspicious of Madoff’s activities and took steps to protect its own financial interests.

However, the United States Financial Crimes Enforcement Network subsequently found that JPMorgan failed to properly report suspicious transactions associated with the Madoff scheme and determined that the bank had willfully violated the Bank Secrecy Act.

The case illustrates a fundamental principle of anti-money laundering compliance:

Identifying something suspicious internally is not enough.

Where the applicable legal reporting threshold is met, the institution must also report the suspicion to the competent authority within the required timeframe.

 

 

DEUTSCHE BANK AND THE FINCEN FILES

Deutsche Bank occupies an important position in this discussion, but its case needs to be described carefully.

The FinCEN Files investigation by the International Consortium of Investigative Journalists identified approximately 1.3 trillion United States dollars in transactions reported as suspicious involving Deutsche Bank, the largest amount associated with a bank in the leaked dataset.

This does not mean that Deutsche Bank laundered 1.3 trillion dollars. The figure represents transactions described as suspicious in the leaked reports.

There is, however, separate regulatory evidence of significant compliance failures involving high-risk relationships, including Danske Bank Estonia and FBME Bank.

The combination of documented regulatory failures and the FinCEN Files makes Deutsche Bank an important case study, but the distinction between suspicious transactions and proven money laundering must be maintained.

 

 

WHAT DID THE FINCEN FILES REVEAL?

The FinCEN Files were based on more than 2,100 leaked Suspicious Activity Reports and related records submitted to the United States Financial Crimes Enforcement Network.

The records described more than 2 trillion United States dollars in suspicious transactions.

Five global banks attracted particular attention:

  • Deutsche Bank
  • JPMorgan Chase
  • Standard Chartered
  • Bank of New York Mellon
  • HSBC

Other major institutions appearing in the data included Barclays and Société Générale.

There is, however, an essential point that is sometimes lost when the FinCEN Files are discussed publicly:

A Suspicious Activity Report is not proof of a crime.

Banks are expected to submit these reports when they identify activity meeting the applicable reporting threshold. Filing a report can therefore demonstrate that an anti-money laundering control operated as intended.

The more significant questions concern whether banks reacted appropriately to repeated warning signs, understood who was behind transactions, submitted reports promptly, and appropriately managed or terminated relationships presenting unacceptable financial-crime risks.

 

 

WHAT DOES “TURNING A BLIND EYE” ACTUALLY MEAN?

The phrase “turning a blind eye” should be used cautiously. From a legal and compliance perspective, it is more useful to examine documented conduct.

Particularly serious indicators include situations where a bank:

  • repeatedly ignores significant transaction-monitoring alerts;
  • knows that customer information is materially incomplete but continues the relationship without adequate mitigation;
  • fails to investigate clear financial-crime warning signs;
  • deliberately excludes significant transactions from monitoring;
  • fails to submit required reports to the relevant Financial Intelligence Unit;
  • submits reports only after excessive delays;
  • continues processing transactions after identifying serious unexplained activity;
  • fails to correct deficiencies already identified by regulators; or
  • conceals compliance weaknesses from regulators.

The strongest cases are those where authorities establish knowledge or deliberate conduct, rather than an isolated human error or control failure.

 

 

WHY SUSPICIOUS ACTIVITY REPORTING MATTERS

Banks cannot be expected to prove that every suspicious customer is a criminal. That is not their role.

Their responsibility is to maintain appropriate systems to identify and assess suspicious activity and, where the applicable legal threshold is met, report it to the competent Financial Intelligence Unit or other designated authority.

Financial Intelligence Units can combine information received from different institutions and other sources to identify patterns that an individual bank may not be able to see.

Failure by one institution to report suspicious activity can therefore affect the wider financial intelligence system.

At the same time, more reports do not automatically mean better compliance. Reports need to be timely, meaningful and supported by appropriate investigation and customer monitoring.

 

 

A LESSON BEYOND BANKING

These cases demonstrate that the size, reputation and resources of a financial institution do not eliminate financial-crime risk.

Large international banks face particular challenges because of the enormous number of transactions they process, extensive correspondent banking networks, operations across multiple jurisdictions and complex customer relationships.

Technology is important, but these cases also demonstrate that effective anti-money laundering compliance depends on people making appropriate decisions when warning signs appear.

A sophisticated monitoring system has limited value if alerts are ignored. A customer risk rating has limited value if known high-risk relationships receive no additional scrutiny. A Suspicious Activity Report has limited value if it is submitted years after the relevant transactions.

 

 

THE CENTRAL LESSON FOR COMPLIANCE PROFESSIONALS

The major enforcement cases repeatedly return to the same fundamental principles:

Know the customer. Understand the expected activity. Monitor what actually happens. Investigate significant deviations. Escalate concerns. Report suspicious activity when legally required. Document the reasoning.

Compliance professionals also need sufficient independence and authority to challenge commercially valuable relationships.

The objective is not to eliminate every possible financial-crime risk. No financial institution can guarantee that criminals will never use its services.

The objective is to establish reasonable and effective controls, recognize significant warning signs, and act when those warning signs appear.

The difference between an institution that encounters money laundering and an institution that becomes the subject of a major enforcement case can ultimately depend on what it does after it knows, or should reasonably have known, that something is wrong.

 

Major bank money laundering and AML enforcement cases, highlighting compliance failures, suspicious activity reporting, and regulatory penalties.
Major bank money laundering cases highlight the importance of effective AML controls, transaction monitoring, suspicious activity reporting, and timely compliance action.

 

 

Disclaimer

This article is provided for educational and general information purposes only and does not constitute legal, regulatory, compliance or financial advice.

The cases are based on publicly available information from regulators, government authorities and identified investigative sources. Including a bank does not necessarily mean the bank committed money laundering. Suspicious transactions, Suspicious Activity Reports and inclusion in the FinCEN Files do not by themselves establish criminal conduct.

The amounts cited may represent criminal proceeds, suspicious transactions, customer activity, or unmonitored transaction volumes and should therefore be interpreted in the context of each case.

 

 

Sources

ARIDAN. (2024, March 7). Unveiling the systemic compliance failures in banks: Insights from the FinCEN Files.

 

Financial Conduct Authority. (2021, December 13). NatWest fined £264.8 million for anti-money laundering failures.

 

Financial Crimes Enforcement Network. (2014, January 7). FinCEN assesses record $461 million civil money penalty against JPMorgan Chase for Bank Secrecy Act violations. U.S. Department of the Treasury.

 

Financial Crimes Enforcement Network. (2021, January 15). FinCEN announces $390,000,000 enforcement action against Capital One, National Association, for violations of the Bank Secrecy Act. U.S. Department of the Treasury.

 

International Consortium of Investigative Journalists. (2020). FinCEN Files.

 

International Consortium of Investigative Journalists. (2020). FinCEN Files: Data and charts.

 

International Consortium of Investigative Journalists. (2020, September 20). Global banks defy U.S. crackdowns by serving oligarchs, criminals and terrorists.

 

New York State Department of Financial Services. (2020, July 7). DFS fines Deutsche Bank $150 million for significant compliance failures.

 

Openbaar Ministerie. (2018, September 4). ING betaalt 775 miljoen vanwege ernstige nalatigheden bij voorkomen witwassen.

 

Openbaar Ministerie. (2021, April 19). ABN AMRO betaalt 480 miljoen euro vanwege ernstige tekortkomingen bij het bestrijden van witwassen.

 

U.S. Department of Justice. (2010, March 17). Wachovia enters into deferred prosecution agreement and agrees to forfeit $110 million.

 

U.S. Department of Justice. (2012, December 11). HSBC Holdings Plc. and HSBC Bank USA N.A. admit to anti-money laundering and sanctions violations, forfeit $1.256 billion in deferred prosecution agreement.

 

U.S. Department of Justice. (2015, March 12). Commerzbank AG admits to sanctions and Bank Secrecy Act violations, agrees to forfeit $563 million and pay $79 million fine.

 

U.S. Department of Justice. (2018, February 7). Bank pleads guilty, pays historic penalty for concealing anti-money laundering failures.

 

U.S. Department of Justice. (2022, December 13). Danske Bank pleads guilty to fraud on U.S. banks in multi-billion dollar scheme to access the U.S. financial system.

 

U.S. Department of Justice. (2024, October 10). TD Bank pleads guilty to Bank Secrecy Act and money laundering conspiracy violations in $1.8B resolution.

 

U.S. Department of Justice. (2024). United States of America v. TD Bank, N.A.

 

U.S. Department of Justice. (2026, January 6). TD Bank insider pleads guilty to facilitating money laundering.

Tags :

Compliance

Share This :

Latest in the Journal