What Happens When AML Goes Wrong: Lessons From the Cases That Shook the Industry

Pathik Shah Pathik Shah 23 min read AML Insights
Article Summary

  • The major AML enforcement cases of the past two decades — from the correspondent banking failures of the mid-2000s to the private banking scandals of the 2010s — share a set of structural features that repeat across institutions, jurisdictions, and time periods, and that the compliance officer can learn from without experiencing firsthand.
  • The patterns that produced the most serious failures were not single events or individual bad actors. They were cultures, governance structures, and programme designs that systematically suppressed the warning signals present long before the failure became visible.
  • The compliance officer who understands how these failures developed, what the warning signals were, and why they were not acted upon, is in the best position to recognise those signals in their own institution before they become the next case study.
  • The personal accountability dimension has grown substantially with senior manager accountability regimes in the UK, Singapore, Australia, and elsewhere, and the officer who understands what personal liability looks like is better positioned to protect themselves through the quality of their own conduct.
  • Every major AML enforcement case is, ultimately, a story about the gap between what the compliance programme said it would do and what it actually did. Closing that gap is the most important preventive action available.

AML Expert
Talk to an expert

AML Expert

Get tailored guidance on your compliance obligations, SAR filing, or AML program review.

Reach Out Now

Authored by

Pathik Shah

Founder, NIYEAHMA Consultants LLP

CAMS | FCA | CISA | CS | DISA (ICAI) | FAFP (ICAI)

28 years in AML/CFT advisory across UAE, UK, Singapore, India, Hong Kong, Australia and the GCC

Expert Panel

Dipali Vora — AML/CFT Practitioner | Associate Member, ICSI

Jyoti Maheshwari — AML/CFT Practitioner | Published in ACAMS Today & AMLverse

A Career Spent With the Aftermath

I have spent most of my career not in the calm middle of compliance, where programmes are running smoothly and examinations are routine, but at the edges, where something has gone wrong or is about to. In twenty-eight years of AML/CFT practice across the GCC and Asia-Pacific, I have been engaged in the aftermath of regulatory enforcement actions, in the remediation of programmes that examiners have found wanting, and in the health checks of institutions that suspected their programme was not as strong as it appeared on paper.

What I have learned from this vantage point is not primarily technical. The technical knowledge is important, and this series has covered it in detail. What I have learned from sitting with the consequences of AML failures is something different: a pattern recognition that comes from seeing the same structural problems appear in different institutions, different jurisdictions, and different time periods, and from understanding why they persist despite the very real efforts of many intelligent and well-intentioned people.

The cases I am drawing on in this article are not the famous public cases that have been analysed to exhaustion in the compliance literature. They are the cases I have been close to professionally — the institutions that called me after an examination or an enforcement action, where I sat with the compliance team, the legal counsel and the board and asked the question that matters most in those moments: how did it come to this?

The answer, almost invariably, involves the same set of structural features. Not the same facts, not the same product or customer or jurisdiction, but the same architecture of failure. Understanding that architecture is the most useful thing I can offer the compliance officer who wants to avoid becoming a case study themselves.

The Architecture of AML Failure: Six Structural Features

Feature One: The Programme That Existed on Paper Only

The most common structural feature of a major AML failure is the gap between the written programme and the operational reality. The compliance policy said that all new customers would be subjected to beneficial ownership verification. In practice, relationship managers were routinely onboarding customers with incomplete CDD, on the grounds that the documentation would follow. The documentation often did not follow, and the backlog grew quietly for years before anyone counted it.

The written programme is not, in itself, a compliance control. It is a description of what the controls should be. The control is the process that actually happens. Where these two things diverge, the written programme creates a false sense of security: the examiner who reviews the policy and finds it comprehensive does not yet know that it is not followed. The examination that tests operational reality, rather than documentation quality, finds the gap.

I have reviewed files where a CDD policy of genuine quality had been written by an excellent compliance professional, approved by the board, and filed in the compliance management system. The relationship managers whose names appeared in those files had not read them. The onboarding process did not follow it. The supervisory team had not tested whether it was followed. The gap between the policy and the practice was total, and it had existed for years before the examination found it.

Feature Two: The Culture That Punished Escalation

The second structural feature is a culture in which escalating compliance concerns create professional risk for the person who raises them. This culture does not usually announce itself. It operates through subtler mechanisms: the relationship manager whose PEP concern was overridden and who learned not to raise concerns again; the compliance analyst whose alert was closed by management without explanation, who concluded that thorough analysis was not valued; the MLRO whose STR recommendation was challenged by the business head and who found that the challenge was not resolved in their favour.

A culture that punishes escalation fails to provide a warning when a major failure is developing. It produces silence. The compliance officer who has learned that raising concerns is professionally costly will not raise them. The transaction that should have generated an STR will not, because the compliance analyst who spotted the indicators also knows what happens to the people who file too many reports. The pattern that should have been escalated to the MLRO will not be, because the relationship manager has learned that escalation damages their relationship with their client and their standing with their business head.

The cultural dimension of AML failure is the hardest to address because it is the hardest to see. A governance review that examines the policy framework and the committee structure cannot easily detect a culture of silence. The examiner who asks, "Do staff feel comfortable raising compliance concerns?" will receive the answer the institution's leadership believes is true. Finding the real answer requires a different kind of examination: looking at the pattern of escalations, the proportion of alerts that result in STRs, and the career trajectories of people who raise uncomfortable concerns.

Feature Three: The Governance Structure That Protected the Business

The third structural feature is a governance structure in which the compliance function reports to the business rather than independently of it, or in which the commercial interest has an effective veto over compliance decisions. This structure does not always take the obvious form of the compliance officer reporting to the business head. It can be more subtle: the MLRO who attends the business committee as an observer rather than a voting participant; the compliance function whose budget is controlled by the business line it supervises; the board risk committee whose membership is dominated by executives with commercial accountability.

When the compliance function does not have genuine independence from the business, the decisions that compliance and business disagree on are resolved in favour of the business. The client that compliance has concerns about is onboarded because the business head has assured the board that the concerns are manageable. The STR that compliance wants to file is delayed because the business head has asked for time to speak to the client. The EDD requirement that compliance has identified is waived because the client has expressed displeasure at being asked for documentation.

Every one of these individual decisions may be defensible in isolation. The business head may be right that the concerns are manageable. The delay may ultimately not affect the filing. The waiver may be proportionate. But the pattern, over time, of compliance decisions being resolved in favour of the business produces a programme that exists to manage the appearance of compliance rather than to identify and respond to financial crime risk.

Lesson 1

The gap between policy and practice is the most common source of major AML failure. A written programme that is not followed is not a compliance programme. It is a liability: it describes a standard the institution is not meeting and creates evidence that the institution knew what was required and chose not to do it. The compliance officer's most important operational responsibility is ensuring that the written programme matches what actually happens, and testing that match at regular intervals through operational review and internal audit.

Lesson 2

A culture that punishes escalation produces silence, not compliance. The health of the escalation culture is the most important indicator of whether a compliance programme will work when it is tested. The compliance officer in a culture where escalation is professionally costly must either change that culture, with the explicit support of the board and the CEO, or recognise that the programme cannot be genuinely effective in the current environment. Changing the culture requires more than a statement of values: it requires consistent demonstration, at every level, that raising concerns is protected and valued.

Lesson 3

Compliance independence is not a structural formality. It is the precondition for every other control. The compliance function that does not have genuine independence from the business cannot provide genuine oversight of it. The independence required is not only organisational, though the reporting line matters. It is also financial, with budget allocation that does not give the business a veto over compliance resource; it is cultural, with leadership that demonstrates that compliance is not subordinate to commercial interest; and it is personal, with the MLRO and compliance leaders who are willing to maintain their position when it is challenged.

Feature Four: The Monitoring Programme That Generated Noise, Not Intelligence

The fourth structural feature is a transaction monitoring programme that generated large volumes of alerts without producing useful intelligence. The institution had deployed a monitoring platform, configured a set of rules, and generated thousands of alerts per month. The analyst team investigated and closed those alerts, achieving impressive closure rates. The STR filing rate was low by industry standards. The monitoring programme was, in effect, a compliance theatre production: it demonstrated activity without producing detection.

I have reviewed programmes where the false positive rate exceeded ninety-eight percent, where the vast majority of alerts were closed as a matter of routine without substantive analysis, and where the analyst team had developed a set of heuristics for rapid closure that bore no relationship to the risk indicators the alerts were supposed to be detecting. The institution could demonstrate, to any examiner, that its monitoring programme was operational. It could not demonstrate, and had not asked itself, whether the programme would actually detect financial crime in its customer base.

The monitoring programme that generates noise rather than intelligence is particularly dangerous because it creates a false sense of security. The MLRO who receives monthly reports showing thousands of alerts investigated and closed, and a modest number of STRs filed, may believe that the programme is working. What they are actually seeing is a measure of activity, not effectiveness. The alerts being closed are not suspicious: they never were. The suspicious activity, if it is present, may not be generating alerts at all.

Feature Five: The Senior Management Who Did Not Want to Know

The fifth structural feature, and perhaps the most professionally confronting, is senior management who were not uninformed about the compliance problems in their institution. They were selectively informed. The board reports they received described the programme in terms that emphasised its positive features and minimised or omitted its weaknesses. The MLRO who told the board that the programme was "generally effective with some areas for improvement" was not lying, but was also not telling the board what it needed to know: that the areas for improvement were structural and material.

The governance regime that exists in financial services is premised on the idea that senior management has both the right and the responsibility to know the genuine state of their compliance programme. A board that approves an AML programme without understanding its material weaknesses is not providing adequate governance. A board that is not told about those weaknesses by the people who know about them is not being served by those people.

The personal accountability frameworks that now exist in the UK through SMCR, in Singapore through the Guidelines on Individual Accountability and Conduct, and in Australia through the Financial Accountability Regime (which replaced the Banking Executive Accountability Regime in 2024), are designed specifically to address this structural feature. They create personal accountability for senior managers to ensure that they are genuinely informed, not merely formally informed, about the state of their institution's compliance. They also create personal accountability for the MLRO to ensure that their board reporting reflects the genuine state of the programme, not the state the programme would like to be in.

Lesson 4

A monitoring programme that produces alerts but not intelligence is not a compliance control. The test of a transaction monitoring programme is not how many alerts it generates but how many of those alerts represent genuine suspicious activity. The compliance officer who cannot answer this question about their own programme has not validated it. The validation of the monitoring programme is a core compliance obligation that cannot be delegated to the technology vendor and cannot be inferred from alert volume.

Lesson 5

Board reporting that describes the programme favourably is not the same as board reporting that gives the board what it needs. The MLRO's board report is a governance document with a specific purpose: to give the board the information it needs to exercise effective oversight of the AML programme. A report that emphasises positive metrics while omitting material weaknesses is not meeting that purpose, regardless of whether it is technically accurate. The MLRO who has drafted a board report should ask: if the board reads this and acts on it, will they make better governance decisions? If not, the report needs to change.

Feature Six: The Remediation That Did Not Stick

The sixth structural feature is specific to the aftermath of enforcement actions and significant examination findings: the remediation programme that addressed the surface symptoms without changing the underlying culture and governance. The institution invested in technology, hired additional analysts, updated its policies, and retrained its staff. Two years later, an independent review found that the substantive problems persisted: the culture still punished escalation, the governance still protected the business, and the monitoring programme was still generating noise rather than intelligence.

Remediation that does not address the structural features of the failure will not prevent the next one. The institution that responds to an enforcement action by adding people and technology to a programme whose governance and culture remain unchanged is spending significant resources to produce better-documented versions of the same failures. The examiner who returns after the remediation period and finds the same structural issues is not surprised. They have seen it before.

Genuine remediation requires the institution to change the things that actually caused the failure, not the things that were easiest to change. If the failure was caused by a culture that punished escalation, remediation requires changing that culture, with the demonstrated commitment of the CEO and the board. If it was caused by a governance structure that protected the business, remediation requires changing that structure. These are harder changes than hiring more analysts and deploying more technology, and they take longer and cost more. But they are the changes that prevent the next failure.

The remediation programmes I have seen succeed are the ones where the CEO stood in front of the entire organisation, not just the compliance team, and said: what happened here was not acceptable, this is what we are changing, and this is how you will know we mean it. The ones that failed had excellent written remediation plans, impressive technology deployments, and compliance teams that had expanded significantly. What they did not have was a CEO who had communicated that the culture had changed. You cannot remediate culture in a spreadsheet.

Pathik Shah | Founder, NIYEAHMA Consultants LLP

The Personal Accountability Dimension

The enforcement landscape has changed significantly in the past decade in one specific respect that every compliance officer must understand: the personal accountability of senior managers, including the MLRO, for AML failures that occurred within their area of responsibility. This is not a theoretical risk. Individuals have been banned from working in financial services in the UK, Singapore, Australia, and the United States as a result of AML compliance failures. Criminal charges have been brought in the most serious cases. The compliance officer who assumes that enforcement actions attach to institutions rather than to people is working with an outdated mental model.

The personal accountability framework creates a specific obligation for the compliance officer and the MLRO. It is not enough to have a written programme. It is not enough to have filed the required reports. It is not enough to have raised concerns internally. The question that the accountability framework asks is whether the individual took all reasonable steps to ensure the programme was effective, and whether they escalated material concerns to the appropriate level of governance. The person who did both of these things and documented doing them is in the strongest position. The person who did neither is in the most exposed position.

The documentation of reasonable steps is not a bureaucratic formality. It is the primary evidence of what the compliance officer did. The MLRO who raised a material concern with the business head and did not follow up when the response was inadequate, and did not document the concern, the response, and the follow-up, has no evidence that they took reasonable steps. The MLRO who documented each escalation, each response, and each decision has a record that demonstrates their conduct. In an enforcement context, that record is the difference between a finding against the institution and a finding against the individual.

The personal accountability regime changed how I think about my own role and how I advise the MLROs I work with. The question is no longer only "is the programme adequate?" It is also "if this goes wrong, can I demonstrate what I did?" Those are different questions and they produce different behaviours. The MLRO who is thinking about demonstrable conduct is a more rigorous professional than the one who is thinking only about programme quality. Not because the programme matters less, but because demonstrable conduct requires the programme to actually do what it says it does, not just to say it.

Jyoti Maheshwari | AML/CFT Practitioner | Published in ACAMS Today and AMLverse

What the Warning Signals Look Like

The structural features of AML failure described above generate specific, observable warning signals that the compliance officer can identify and act on. None of these signals, in isolation, is definitive evidence that a major failure is developing. But the pattern of multiple signals, appearing together and persisting over time, is a reliable indicator that the programme has structural problems that require urgent attention.

The warning signals I most consistently look for when I assess a compliance programme are: a high ratio of alerts closed to STRs filed, which may indicate that the monitoring programme is generating noise rather than intelligence; a pattern of compliance concerns that were raised and then resolved in favour of the business without documented governance; MLRO board reports that are consistently positive without acknowledging material weaknesses; CDD files that are consistently marked complete but that contain documentation gaps when individually reviewed; and a compliance team whose members describe a culture in which raising concerns is professionally costly.

None of these signals requires a formal examination to identify. They are visible to the compliance officer who is asking the right questions about their own programme. The discipline of asking those questions, regularly and honestly, is the most effective early warning system available. The compliance officer who does this is not being pessimistic about their programme. They are being professional about it.

Warning Signals That a Programme Has Structural Problems
  • The ratio of transaction monitoring alerts to STRs filed is consistently very high, with the vast majority of alerts closed as false positives without documented analytical justification.
  • Compliance concerns raised by the team are consistently resolved in favour of the business, with no documented governance process for managing the disagreement.
  • MLRO board reporting is consistently positive, with material programme weaknesses described as "areas for improvement" rather than the material concerns they are.
  • CDD files are marked complete in the management system but contain documentation gaps when individually reviewed, suggesting that completion is being recorded before documentation is received.
  • The compliance team describes a culture in which raising concerns damages professional standing, with examples of concerns being discouraged, overridden, or ignored.
  • The internal audit function has not independently tested the operational effectiveness of the compliance programme within the past two years.
  • The remediation of previous examination findings has focused on technology and headcount without addressing the governance and cultural dimensions of the identified failures.
Lesson 6

Remediation that does not address the structural cause of the failure will not prevent the next one. The compliance officer who has oversight of a remediation programme must insist that the remediation addresses the actual causes of the failure, not the most visible symptoms. A governance failure requires governance remediation. A cultural failure requires cultural remediation. Technology and headcount address operational capacity, not governance or culture. The compliance officer who accepts a remediation plan limited to operational improvements when the failure was structural is accepting the risk of a repeat.

Practitioner Checklist: Identifying and Addressing Structural Risk Before It Becomes a Failure
  • Conduct an annual test of the gap between the written compliance programme and operational practice, using operational review, case sampling, and staff interviews to identify divergences.
  • Assess the escalation culture by reviewing the pattern of compliance concerns raised and their resolution, and by creating a confidential channel for staff to report cultural concerns about compliance.
  • Confirm the independence of the compliance function in governance, budget, and culture, and identify any structural features that give the business an effective veto over compliance decisions.
  • Validate the transaction monitoring programme against the question of whether it would detect the specific financial crime most likely in the institution's context, not only whether it is generating alerts.
  • Review MLRO board reports for the past two years and assess whether they accurately reflect the material weaknesses in the programme, not only its positive features.
  • Ensure the documentation of compliance escalations, concerns, and decisions is sufficient to demonstrate the reasonable steps taken by the MLRO and compliance leadership in any subsequent accountability assessment.
  • Assess any current remediation programme for whether it addresses the structural causes of the identified failures or only their operational symptoms.
  • Conduct a confidential staff survey on the compliance culture, specifically testing whether staff feel able to raise concerns without professional consequences.
  • Ensure the internal audit function has the independence, capability, and mandate to test the operational effectiveness of the compliance programme, not only its documentation.
  • Apply the personal accountability question to every material compliance decision: if this decision is reviewed by an enforcement authority, can I demonstrate the basis on which I made it and the reasonable steps I took?

Got questions

Frequently Asked Questions

Everything you need to know about preventing structural AML failure and how AML Guild supports your business.

This is one of the most professionally difficult situations a compliance officer can face, and there is no answer that eliminates all the risk. The compliance officer's obligation is to escalate the concern through every available governance channel: to the MLRO if they are not the MLRO, to the board risk committee if the business head is not responsive, and ultimately to the regulator if the governance channels within the institution have been exhausted without adequate response. Each escalation should be documented, including the concern raised, the response received, and the follow-up taken. The compliance officer who has documented a genuine and persistent effort to address a structural problem is in a much stronger position in a subsequent accountability assessment than one who identified the problem and took no action.

The MLRO's obligation to give the board an honest picture of the programme's weaknesses is not in conflict with maintaining confidence in the compliance function. A board that is told about material weaknesses and is given a specific plan for addressing them can have confidence in the compliance leadership's honesty and competence. A board that is given consistently positive reports and then discovers a major failure has every reason to question whether the compliance leadership was either unaware of the problems or chose not to disclose them. The honest report, accompanied by a specific remediation plan, is the approach that builds genuine confidence. The positive report that papers over material weaknesses is the approach that destroys it when the failure becomes visible.

In practice, no. A compliance programme depends on the willingness of front-line staff to identify and escalate suspicious activity, on the willingness of relationship managers to apply CDD requirements consistently even when it creates friction with clients, and on the willingness of compliance analysts to document their concerns and maintain their assessments when those assessments are challenged. All of these behaviours require a culture that protects and values escalation. An institution whose culture punishes escalation will produce a programme that looks complete on paper but that systematically suppresses the human behaviours that make the programme work. The compliance officer in this situation faces a choice between changing the culture, with the support of the CEO and the board, and acknowledging that the programme cannot be genuinely effective in the current environment.

The MLRO should maintain a record of every material compliance decision they have made or contributed to, including the specific basis for the decision, the alternatives considered, and the governance approval obtained. They should maintain a record of every material concern they have escalated, including the concern raised, to whom it was escalated, the response received, and any follow-up taken. They should maintain a record of every STR decision, including the specific indicators that gave rise to the suspicion and the basis for the decision to file or not to file. And they should maintain a record of every material programme weakness identified and the steps taken to address it. These records should be maintained contemporaneously, not reconstructed after the fact, and should be stored in a way that the MLRO can access them independently of the institution's own systems.

The institution faces financial penalties, remediation requirements, restrictions on business activities, and reputational damage. The individual MLRO, under the personal accountability frameworks that now exist in the UK, Singapore, and Australia, faces personal financial penalties, a ban from working in regulated financial services, and, in the most serious cases, criminal prosecution. The standard applied to the individual is whether they took all reasonable steps to ensure the programme was effective and whether they escalated material concerns appropriately. The MLRO who can demonstrate both of these things is in the strongest position. The one who cannot is exposed to findings that may result in consequences that are career-ending and potentially criminal.

Work with this expert
Pathik Shah
Pathik Shah Founder, NIYEAHMA Consultants LLP

Work With Pathik Shah on Compliance Health Checks

Whether you are conducting a health check of your institution's compliance programme to identify structural vulnerabilities before they become failures, supporting a board in understanding the genuine state of its AML programme, managing the aftermath of a regulatory examination, or advising a compliance team on how to document their conduct under a personal accountability regime, Pathik Shah and the AML Guild network provide the practitioner experience that comes from working at the edges of compliance, where the lessons that matter most are learned.