financial crime Archives -

AML supervision has become one of the most intensely scrutinised areas in banking and financial services compliance. Regulators across the EU, UK, and US have dramatically increased enforcement actions against firms with inadequate anti-money laundering controls — and the pace of regulatory change in 2026 shows no sign of slowing. For compliance teams and risk officers, understanding where the principal failure points lie is essential to building programmes that withstand supervisory scrutiny.

Why AML Supervision Risk Is Escalating

The global AML and financial crime landscape has shifted fundamentally over the past three years. The FATF Recommendations continue to drive national-level legislative reform, while the EU’s Anti-Money Laundering Authority (AMLA) is now operational and imposing direct supervisory mandates on high-risk obligated entities. In the US, FinCEN’s beneficial ownership registry under the Corporate Transparency Act (CTA) has added new layers of compliance obligation, particularly for correspondent banking and cross-border transactional business.

Against this backdrop, firms that have not modernised their AML compliance infrastructure face compounding risk: not just regulatory penalty, but reputational harm and the operational disruption of remediation programmes imposed under supervisory direction.

Key Risk Areas in AML Supervision

1. Transaction Monitoring Gaps

Transaction monitoring remains the most commonly cited deficiency in AML supervisory findings. Regulators consistently identify tuning failures — systems that generate too many false positives without catching genuine risk, or that have not been recalibrated to reflect changes in product mix, customer base, or typology guidance. FATF’s updated guidance on risk-based transaction monitoring places the onus firmly on firms to document and evidence their calibration methodology, including threshold decisions and scenario logic.

Key risk indicators in this area include: failure to monitor cash transactions below reporting thresholds, insufficient coverage of digital asset and crypto-adjacent activity, and alert backlogs that result in investigations being completed outside of required timeframes.

2. Customer Risk Stratification and KYC Inadequacies

Customer risk rating models that were designed years ago may no longer reflect the risk profile of the current customer base. Regulators pay particular attention to whether firms have applied enhanced due diligence (EDD) consistently to high-risk customers, including Politically Exposed Persons (PEPs), high-net-worth individuals, and customers operating in high-risk jurisdictions as identified by FATF’s grey and black lists.

A common supervisory concern is the failure to refresh customer due diligence on a risk-rated cycle — firms that onboard clients correctly but fail to update KYC records when material changes occur are routinely cited in enforcement actions. Baretzky & Partners’ KYC framework advisory specifically addresses this gap through ongoing monitoring design and trigger-based refresh protocols.

3. Sanctions Screening Infrastructure

Sanctions compliance sits at the intersection of AML and financial crime risk, and screening failures have resulted in some of the largest financial penalties in recent enforcement history. The convergence of EU, UN, US OFAC, and UK OFSI sanctions regimes — particularly following escalation of Russia-related designations — has significantly increased the complexity of maintaining effective screening infrastructure.

Key risks include: screening system lag time (screens that are updated too infrequently), failure to screen against all relevant lists, inadequate fuzzy matching logic for name variants and transliterated names, and insufficient documentation of screening decisions. Firms operating in multiple jurisdictions must also manage conflicting obligations between regimes.

4. Governance and Accountability Frameworks

Supervisors are increasingly focused on governance — specifically, whether the MLRO has adequate authority and resource, whether the Board and Senior Management are receiving meaningful AML MI, and whether there is a documented three-lines-of-defence model with clear accountability. The Senior Managers and Certification Regime (SMCR) in the UK, and equivalent accountability frameworks in the EU and US, have made personal liability for AML failures a real and pressing concern for individual executives.

Regulators expect to see documented Board-level risk appetite statements for financial crime, supported by regular management information reports that track programme performance against defined metrics — not simply activity metrics, but outcome measures.

5. Regulatory Response and Remediation Readiness

When supervisors initiate an AML review — whether via a themed examination, Dear CEO letter, or enforcement action — the firm’s response capability is itself a supervisory risk. Firms that lack documented policies, cannot produce evidence of control operation, or whose compliance teams are unable to articulate the design rationale for key controls, consistently receive more adverse findings.

Remediation programmes imposed by regulators under supervisory direction are enormously disruptive and costly. Proactive investment in programme quality assurance — including independent testing, look-back reviews, and model validation — significantly reduces the risk of mandated remediation.

How Baretzky & Partners Supports AML Supervision Risk Management

Baretzky & Partners operates an AML and financial crime advisory practice that covers the full compliance lifecycle. Our FATF-aligned methodology and deep knowledge of EU, UK, US, and international sanctions regimes means we are well-positioned to support firms across all the key risk areas identified above.

Our AML supervision support services include: AML programme gap analysis and maturity assessment; transaction monitoring model validation and recalibration; KYC framework design and EDD protocol development; sanctions screening infrastructure review; governance and MLRO effectiveness assessment; and regulatory response and remediation programme management.

Whether your organisation is preparing for a regulatory examination, responding to supervisory findings, or proactively strengthening its financial crime framework ahead of AMLA’s expanded supervisory scope, our specialists can deliver findings and recommendations within defined timeframes.

AML Supervision in 2026: The Strategic Imperative

The direction of travel in AML supervision is unambiguous: regulators are more resourced, more coordinated, and more willing to use enforcement tools than at any previous point. The establishment of AMLA, combined with FinCEN’s continued rulemaking activity and the FCA’s publication of its three-year strategy placing financial crime at the top of its supervisory agenda, means that the window for addressing programme gaps is narrowing.

For banks, payment institutions, and other obligated entities, the strategic imperative is clear: invest now in programme quality assurance, governance infrastructure, and the specialist advisory capability needed to navigate an increasingly demanding supervisory environment.

For enquiries about AML supervision risk management, programme assessment, or regulatory response support, contact Baretzky & Partners via our enquiry form or reach our specialists directly at info@baretzky.com.

Anti-money laundering (AML) enforcement has accelerated dramatically over the past decade. Regulators across the US, UK, EU, and Asia-Pacific are issuing record-breaking fines, expanding personal liability to executives, and publishing deferred prosecution agreements that name institutions and individuals in detail. For compliance officers, risk managers, and banking counsel, understanding the current penalty landscape is no longer optional — it is a core operational requirement.

This article provides a practical overview of how AML penalties and sanctions work in 2026, what triggers enforcement, and how organisations can reduce their exposure.


The Scale of Modern AML Penalties

Global AML fines have reached unprecedented levels. Between 2020 and 2025, regulators issued over $25 billion in AML-related penalties to financial institutions worldwide. The United States remains the most aggressive enforcer, with the Department of Justice (DOJ), Financial Crimes Enforcement Network (FinCEN), and Office of Foreign Assets Control (OFAC) all maintaining active enforcement programmes. The UK’s Financial Conduct Authority (FCA) and the European Banking Authority (EBA) have similarly intensified oversight, particularly post-FATF mutual evaluations.

Common penalty categories include civil monetary penalties, criminal fines, deferred prosecution agreements (DPAs), and non-prosecution agreements (NPAs). In the most serious cases — particularly those involving sanctions violations or terrorist financing — institutions face asset freezes, licence revocations, and the appointment of independent compliance monitors at their own expense.


What Triggers AML Enforcement

Regulatory action is typically triggered by one or more of the following:

  • Failure to file Suspicious Activity Reports (SARs) — Financial institutions are required to report suspicious transactions. Systematic failures to file, or deliberate delays, attract severe penalties.
  • Inadequate Know Your Customer (KYC) procedures — Insufficient customer due diligence, particularly at onboarding, remains the leading cause of enforcement action.
  • Sanctions screening failures — Processing transactions involving OFAC-listed parties, or failing to maintain current screening lists, is treated as a strict liability offence in the US.
  • Correspondent banking negligence — Banks providing services to foreign financial institutions without adequate oversight of those institutions’ AML controls are increasingly liable for downstream violations.
  • Beneficial ownership gaps — Failure to identify and verify ultimate beneficial owners, particularly in corporate and trust structures, is a growing area of enforcement focus.

Personal Liability: The Shift Toward Individual Accountability

A significant enforcement trend is the expansion of personal liability. Regulators in the UK, US, and EU are increasingly pursuing individual executives, compliance officers, and board members alongside institutions. The UK’s Senior Managers and Certification Regime (SMCR) places direct accountability on named individuals for AML failures within their area of responsibility. In the US, the DOJ’s revised corporate criminal enforcement policy explicitly encourages individual prosecutions.

This shift means that compliance professionals must maintain contemporaneous documentation of their decisions, escalations, and recommendations — both to demonstrate good faith and to establish that responsibility was appropriately discharged.


OFAC Sanctions: A Strict Liability Framework

OFAC sanctions violations are particularly consequential because they operate on a strict liability basis — intent is not required for a civil violation. Any transaction involving a Specially Designated National (SDN) or a blocked country, regardless of whether the institution was aware, may result in a penalty. Mitigating factors — such as voluntary self-disclosure, a robust compliance programme, and lack of prior violations — can reduce penalties significantly, but the base exposure remains high.

Organisations operating internationally must maintain real-time sanctions screening, understand the jurisdictional reach of US secondary sanctions, and have documented escalation procedures for potential matches.


The Role of Compliance Programmes in Penalty Mitigation

Regulators consistently apply mitigating treatment to institutions that can demonstrate a robust, risk-based compliance programme. Key elements include:

  • A documented AML/CFT policy reviewed and approved at board level
  • Regular risk assessments calibrated to the institution’s specific client base, geographies, and product mix
  • Independent testing and audit of the AML programme
  • Ongoing training for all relevant staff
  • A clear escalation and reporting structure for suspicious activity

Voluntary self-disclosure to regulators, while not without risk, is generally treated as a significant mitigating factor. Institutions that discover violations and proactively report them — rather than waiting for examination findings — typically receive more favourable resolutions.


Practical Steps for Compliance Teams in 2026

Given the current enforcement environment, compliance teams should prioritise the following:

  1. Update beneficial ownership registers — Ensure all corporate clients have current UBO data, with verification appropriate to risk level.
  2. Review correspondent banking relationships — Conduct enhanced due diligence on correspondent accounts, particularly those in higher-risk jurisdictions.
  3. Test SAR filing processes — Ensure triage, escalation, and filing workflows are functioning and that staff understand thresholds.
  4. Validate sanctions screening coverage — Confirm that all products and payment channels are included in screening and that list updates are applied in real time or near real time.
  5. Document compliance officer decisions — Maintain records of how and why specific decisions were made, particularly in high-risk situations.

Conclusion

AML enforcement in 2026 is more rigorous, more personal, and more cross-border than at any previous point. Financial institutions and their advisors must treat compliance not as a cost centre but as a strategic function — one that protects the organisation’s licence to operate and the careers of those responsible for it. Organisations that invest in robust frameworks, clear documentation, and proactive engagement with regulators are best positioned to manage their exposure in an increasingly unforgiving regulatory environment.

Baretzky and Partners LLP provides AML/CFT advisory services, compliance programme reviews, and regulatory response support to financial institutions and multinationals operating across multiple jurisdictions. Contact our team to discuss your compliance requirements.