Skip to main content
AML Fines Rose 50% -- Here's What FailedAML and KYC
5 min readFor AML/KYC Compliance Officers

AML Fines Rose 50% -- Here's What Failed

Between 2020 and 2023, regulatory penalties for AML violations increased by 50%. This isn't just a compliance trend; it's a pattern of control failures.

Most of these penalties stem from broken processes: inadequate Customer Due Diligence (CDD), missing Enhanced Due Diligence (EDD) for high-risk clients, and monitoring systems that failed to flag obvious issues. This isn't about regulatory complexity; it's about fundamental gaps in how your team implements and sustains AML controls.

If your institution hasn't been fined yet, you're not immune. You're next unless you fix the weaknesses regulators keep finding.

What Happened

The 50% increase in AML fines reflects a consistent enforcement pattern: regulators are identifying the same control deficiencies across institutions of all sizes. These deficiencies focus on three core requirements under the Bank Secrecy Act and USA PATRIOT Act:

  1. Identity Verification failures: Institutions onboarded clients without confirming identity using reliable, independent sources.
  2. Risk assessment gaps: CDD processes didn't evaluate client risk profiles, transaction patterns, or geographic exposure.
  3. Monitoring breakdowns: Ongoing surveillance failed to detect structuring, unusual transaction volumes, or relationships with Politically Exposed Persons (PEPs).

Penalties aren't evenly distributed. Institutions relying on checkbox compliance, running KYC once at onboarding and never revisiting client risk, faced the largest fines. Those with risk-based, continuous monitoring faced fewer enforcement actions.

Which Controls Failed

Identity Verification (IDV)

Institutions collected identification documents but didn't verify them against independent data sources. This often meant accepting scanned driver's licenses or passports without cross-referencing government databases, credit bureaus, or utility records. The Financial Action Task Force (FATF) requires verification using reliable, independent sources. Accepting unverified documents doesn't meet that standard.

Customer Due Diligence (CDD)

CDD programs existed on paper but didn't assess actual risk. Teams collected information on client occupation, source of funds, and transaction purpose, then filed it without analysis. They didn't evaluate whether a client's stated business activity matched their transaction volume, whether their geographic footprint aligned with sanctions lists, or whether their relationships included PEPs.

FATF recommends Risk-Based Customer Due Diligence: tailor your scrutiny to the risk the client presents. Low-risk clients (a salaried employee opening a checking account) warrant simplified checks. High-risk clients (a cash-intensive business with cross-border wire activity) require Enhanced Due Diligence. Most penalized institutions applied the same shallow process to everyone.

Enhanced Due Diligence (EDD)

When institutions flagged high-risk clients, they didn't escalate to EDD. EDD requires deeper investigation: source of wealth verification, beneficial ownership identification, and documented rationale for accepting the relationship despite elevated risk. Missing EDD is a common finding in enforcement actions because it's visible in the file. Either the documentation exists or it doesn't.

Ongoing Monitoring

Transaction monitoring systems were deployed but not tuned. Alert thresholds were set too high to reduce false positives, so genuine suspicious activity didn't trigger review. Institutions didn't update risk scores when client behavior changed, a dormant account suddenly receiving large wire transfers kept its low-risk rating because no one re-evaluated it.

The Bank Secrecy Act requires institutions to maintain and update customer information, including risk ratings. Monitoring isn't static; it's a continuous reassessment.

What the Standards Require

The Bank Secrecy Act and USA PATRIOT Act establish four core obligations:

  1. Customer Identification Program (CIP): Verify identity using name, date of birth, address, and identification number. Verification must use documents, non-documentary methods, or a combination.

  2. Customer Due Diligence (CDD): Understand the nature and purpose of customer relationships. Identify beneficial owners of legal entity customers. Develop a customer risk profile based on expected activity.

  3. Enhanced Due Diligence (EDD): Conduct additional scrutiny for higher-risk customers, including PEPs, customers from high-risk jurisdictions, and accounts with unusual transaction patterns.

  4. Ongoing Monitoring: Conduct surveillance to identify and report suspicious transactions. Update customer information and risk profiles as circumstances change.

The FFIEC BSA/AML Examination Manual provides the examination framework. Examiners look for documented policies, evidence of risk-based decision-making, and audit trails showing that your team acted on the information you collected.

Lessons and Action Items

Re-verify existing clients using independent sources

Pull a sample of your current customer base. For each client, confirm that identity verification relied on at least two independent sources. If you accepted only a scanned document, you have a gap. Implement a remediation plan to verify those identities using non-documentary methods (database checks, utility verification, employment confirmation).

Implement tiered CDD based on client risk profiles

Document your risk criteria. Define what constitutes low, medium, and high risk in your customer base. Low-risk might be employed individuals with predictable salary deposits and local transaction patterns. High-risk might be cash-intensive businesses, clients with beneficial owners in FATF high-risk jurisdictions, or accounts with frequent international wires.

Apply simplified CDD to low-risk clients. Require Enhanced Due Diligence for high-risk clients before account opening. This isn't optional. It's how you demonstrate risk-based compliance.

Tune your transaction monitoring system

Review your alert thresholds. If you're generating fewer than 50 alerts per month in an institution processing thousands of transactions, your thresholds are too high. Work backward from known typologies: structuring typically involves deposits just under $10,000. If your alert threshold is $15,000, you won't catch it.

Test your system quarterly using synthetic scenarios. Simulate structuring, rapid movement of funds, and transactions involving sanctioned jurisdictions. Confirm that alerts fire as expected.

Trigger risk re-assessment on specific events

Don't wait for annual reviews. Build triggers that force re-evaluation when:

  • Transaction volume increases by more than 50% in a 30-day period
  • A client initiates their first international wire
  • Watchlist Screening identifies a new PEP relationship
  • A beneficial owner changes

These events signal potential risk changes. Your CDD should reflect current risk, not the risk profile from account opening.

Document EDD decisions with specific rationale

When you accept a high-risk client, document why. "Client accepted based on long-standing banking relationship and verified source of wealth from real estate holdings in [jurisdiction]" is defensible. "Client accepted" is not. Examiners will review your EDD files. Make sure the decision rationale is explicit and tied to mitigating controls.

The 50% increase in fines tells you what regulators are finding. The question is whether they'll find it at your institution.

You Might Also Like