Signature Bank’s collapse in March 2023 demonstrated how rapidly a large commercial bank can fail when concentrated deposits, reputational contagion and inadequate liquidity preparation converge.
The New York State Department of Financial Services took possession of the bank on 12 March 2023 and appointed the Federal Deposit Insurance Corporation as receiver. At the end of 2022, Signature reported approximately US$110.4 billion in assets and US$88.6 billion in deposits, making its failure one of the largest in United States history.
The immediate cause was a liquidity crisis. Following the wind-down of Silvergate Bank and the failure of Silicon Valley Bank, Signature received more than 1,600 withdrawal requests totalling approximately US$18.6 billion on 10 March—equivalent to around one-fifth of its deposits.
Its ability to survive the run was weakened by concentrated funding, insufficient contingency arrangements, limited immediately available liquidity and longstanding deficiencies in risk management.
Regulatory reviews also revealed serious weaknesses in Signature’s anti-money laundering, counter-terrorist-financing and sanctions controls. Examiners were considering a formal consent order concerning apparent violations when the bank closed.
Those compliance failings require precise interpretation. Regulators did not conclude that money laundering or sanctions breaches directly caused the bank run. The primary causes were poor management, liquidity weakness and overreliance on large deposits capable of leaving quickly.
The AML and sanctions findings nevertheless matter because they formed part of the same institutional pattern: rapid growth, increasing complexity, inadequate board challenge and delayed remediation of supervisory concerns.
Key Takeaways
- Signature Bank Failed Primarily Because of Liquidity and Management Weaknesses
- AML and Sanctions Deficiencies Reflected Broader Governance Failures
- Rapid Growth Can Outpace Financial Crime Control Capacity
- Concentrated Deposits Can Create Significant Prudential Vulnerability
- Digital-Asset Exposure Can Amplify Reputational and Liquidity Risk
- Unresolved AML Findings Can Signal Persistent Governance Weakness
- Repeat Supervisory Findings Require Root-Cause Remediation
- Real-Time Payments Compress the Time Available for Financial Crime Controls
- Batch Screening May Be Insufficient for Instant Payment Environments
- Board Oversight Must Evolve With Institutional Size and Complexity
- Financial Crime and Prudential Risks Should Not Be Managed in Isolation
- Supervisory Delays Can Allow Control Weaknesses to Persist
- Customer Risk Intelligence Can Support Liquidity and Funding Analysis
- Growth, Product Innovation and Risk Appetite Must Remain Aligned
- Control Effectiveness Should Be Measured Through Outcomes, Not Policies Alone
Listen the podcast
Watch the video
Why the Signature Bank case matters now
Signature was not a distressed institution gradually losing deposits over several years. It was a rapidly growing commercial bank whose business model depended heavily on large corporate and institutional relationships.
Its assets increased from approximately US$51 billion at the end of 2019 to US$118 billion at the end of 2021. That expansion introduced new customers, products, payment activity and operational dependencies.
The bank developed major businesses in commercial real estate, private equity fund banking, venture banking and digital-asset services. It also operated Signet, a real-time payment platform through which approved customers could transfer funds continuously.
Rapid growth is not inherently unsafe. It becomes dangerous where governance, staffing, technology and control functions do not expand at the same speed.
Signature’s case shows that prudential and financial-crime risks should not be treated as independent disciplines. The same board that oversees liquidity concentration must also understand whether customer due diligence, transaction monitoring and sanctions screening remain proportionate to the institution’s changing profile.
What actually caused the bank to fail
The FDIC concluded that Signature’s failure resulted primarily from illiquidity during a bank run, with poor management identified as the root cause.
Management pursued rapid growth without developing adequate risk controls for the bank’s size, complexity and funding structure. Signature relied heavily on large depositors whose balances could be withdrawn rapidly and whose funds generally exceeded standard deposit-insurance limits.
The bank also lacked sufficient contingency funding arrangements. When the run accelerated, it struggled to identify and pledge enough eligible collateral to obtain emergency liquidity.
By the afternoon of 12 March, the FDIC’s best-case estimate placed Signature’s available liquidity at approximately US$3 billion, or around 4% of deposits. Regulators concluded that the bank could not reopen safely the following morning.
The collapse was therefore not principally an asset-quality event or an AML enforcement action. It was a funding failure triggered by depositor flight and magnified by weak preparation.
Financial-crime deficiencies should be understood as evidence of broader governance weakness—not substituted for the documented cause of closure.
The concentration behind the run
Signature’s deposit base created a structural vulnerability.
Large commercial customers can move substantial balances through online banking and wire-transfer systems within hours. Their decisions may also be correlated because customers share advisers, investors, industries and information networks.
At year-end 2022, Signature reported that approximately 90% of its deposits exceeded insured limits. A later FDIC study refined that estimate after accounting for possible pass-through insurance on pooled, escrow and custodial accounts.
Using transaction-level data, the 2026 study estimated that no more than approximately 72% of Signature’s deposits were uninsured immediately before the crisis and cited an FDIC estimate of around 67% at failure.
The revised figures do not remove the risk. They show that headline uninsured-deposit ratios depend on how beneficial ownership and pass-through coverage are calculated.
The later analysis also found that size mattered independently of insurance status. The largest depositors were significantly more likely to withdraw all or nearly all their funds, including money held in accounts that may have qualified for pass-through protection.
For liquidity planning, customer concentration can therefore be as important as formal insurance coverage.
The role of digital-asset customers
Signature became strongly associated with the cryptocurrency sector after expanding its digital-assets banking business.
Digital-asset companies accounted for approximately 20% of deposits at the end of 2022 and around 18% shortly before closure. The bank had already announced plans to reduce that concentration following volatility across the sector.
The direct role of crypto customers should not be overstated. New York regulators found that withdrawals from digital-asset businesses were broadly proportionate to their share of the deposit base.
The greater problem was reputational association. Markets, customers and social-media commentary grouped Signature with Silvergate and Silicon Valley Bank, despite differences between their portfolios and client bases.
When confidence deteriorated, the “crypto bank” label accelerated concern among customers outside the digital-assets sector.
The case demonstrates that reputational concentration can produce liquidity consequences even where the underlying customers do not account for most withdrawals. A bank may become associated with one volatile sector strongly enough that concerns spread across its entire depositor base.
What regulators found in the AML programme
The 2022 BSA, AML and OFAC targeted review had not been finalised when Signature closed.
A draft supervisory letter concluded that the AML and counter-terrorist-financing programme required improvement and that the bank’s overall AML and OFAC risk profile was high.
Examiners stated that the board and senior management had not provided appropriate oversight of the internal-control structure, leading to numerous new and repeat findings. The draft also referred to apparent violations of FDIC rules and regulations.
Eight of the 13 matters requiring board attention arising from 2022 targeted reviews concerned AML-related weaknesses. The remaining matters addressed corporate governance, liquidity and fund banking.
An MRBA is a serious supervisory finding requiring immediate attention and prioritisation by the board. It is not equivalent to a criminal charge, civil penalty or final adjudication that a violation occurred.
The FDIC was considering a formal consent order addressing AML, counter-terrorist-financing and OFAC weaknesses. Signature’s closure prevented the contemplated action from proceeding through the ordinary supervisory remediation process.
Why the findings were not isolated
Signature had previously been subject to an informal enforcement action in 2016 concerning BSA and AML internal-control weaknesses. Regulators closed that action in June 2018 after determining that the identified issues had been addressed.
Subsequent examinations continued to identify AML and OFAC concerns.
At the end of the 2019 examination cycle, three of seven outstanding MRBAs related to BSA, AML and sanctions compliance. One had remained open from the previous cycle, while two were new.
An AML and OFAC MRBA dating from the 2018 cycle remained unresolved at the end of the 2020 examination cycle. By the end of that cycle, 61 supervisory recommendations across different risk areas remained outstanding.
The pattern matters more than any single finding. A control weakness may be remediated technically while the underlying governance conditions—weak ownership, insufficient challenge or inadequate resources—remain unchanged.
When the institution continues expanding, old deficiencies can reappear in new products, customer segments and transaction channels.
The control challenge created by real-time payments
Real-time payment systems can provide significant commercial benefits. Customers gain continuous access to funds, immediate settlement and reduced dependence on traditional banking hours.
The same speed compresses the time available for financial-crime controls.
A conventional transfer may pass through several operational stages before settlement. A continuously available platform requires sanctions screening, customer-risk data, transaction monitoring and escalation processes that can operate at comparable speed.
Batch screening performed after transactions have settled may be inadequate where funds can move through several counterparties during the delay.
Real-time systems also increase liquidity sensitivity. Depositors do not need to wait for a branch to open or a payment team to begin work. Large balances can leave through digital channels as confidence deteriorates.
Product governance must therefore consider AML, sanctions, fraud, cyber and liquidity risks together. A payment platform should not be approved solely because the technology functions or customer demand exists.
Why board oversight failed to keep pace
Regulators repeatedly concluded that Signature’s informal decision-making model had become unsuitable for an institution of its size and complexity.
The bank’s private-client culture gave experienced bankers considerable autonomy. That model may support close customer relationships, but it can create inconsistent challenge and unclear accountability when the institution expands into higher-risk sectors.
The 2022 corporate-governance review identified weaknesses in organisational structure, decision-making processes, product implementation, risk indicators, operational-risk oversight and control self-assessments.
Regulators also described management as insufficiently responsive to supervisory findings. Growth, deposits and profitability appeared to receive greater attention than timely remediation.
A board cannot oversee AML or sanctions risk effectively through high-level reporting alone. It requires reliable information on unresolved findings, alert backlogs, customer-review delays, sanctions-screening performance, control overrides and the resources required to address them.
Where management reports that an issue is progressing, the board should be able to test whether the underlying exposure has actually declined.
Supervisory weaknesses also contributed
Responsibility did not rest exclusively with Signature’s management.
The FDIC’s later material-loss review found missed opportunities to downgrade the bank’s management rating and take stronger action earlier.
Signature retained satisfactory composite and management ratings despite longstanding liquidity deficiencies, emerging governance concerns and an expanding backlog of supervisory issues.
Written supervisory communications were also delayed. Some examination reports were issued many months after the relevant review period, reducing their value as forward-looking interventions.
Staffing shortages and turnover affected the FDIC’s New York supervisory team. Temporary personnel did not always possess the large-bank experience or specialist knowledge required for Signature’s changing risk profile.
The lesson is not that supervisors should manage banks. It is that recurring findings require timely escalation when an institution does not remediate them or when growth makes the residual risk more significant.
Why AML and liquidity risk intersect
AML weaknesses do not usually cause deposit runs directly. They can nevertheless affect liquidity through several pathways.
A major enforcement action can damage confidence, prompt customers or counterparties to leave and restrict access to clearing or correspondent relationships.
Inadequate customer-risk management can also prevent the bank from understanding the stability of its funding. Deposits linked to exchanges, investment funds, payment companies or other financial intermediaries may be operationally concentrated even when held across multiple legal accounts.
Sanctions exposure can lead to frozen payments, trapped funds and urgent regulatory intervention.
Financial-crime data can therefore support prudential analysis. Customer type, beneficial ownership, transaction velocity, geographic exposure and dependency on payment platforms all help explain how deposits may behave during stress.
The strongest institutions do not combine the second line of defence into one undifferentiated function. They ensure that AML, sanctions, treasury, operational risk and liquidity teams share material intelligence and understand their overlapping dependencies.
What an evidence-led review looks like
A credible review begins with the bank’s actual business model.
Analysts should identify which customer groups generate deposits, transaction volume and revenue, and how quickly those balances can move.
AML risk assessments should be reconciled with product, sector and liquidity assessments. A customer segment described as strategically important in commercial planning should not appear as a minor exposure in the financial-crime risk assessment.
Control performance should be measured using outcomes rather than policy completion. Relevant evidence includes unresolved alerts, overdue customer reviews, sanctions false-positive volumes, data-quality failures and repeated manual overrides.
The board should also receive information showing whether growth is increasing the exposure faster than controls can absorb it.
Where supervisors identify repeat findings, management should demonstrate why the previous remediation failed and whether the root cause lies in technology, staffing, governance or risk appetite.
What a resilient control stack looks like
The first layer is integrated risk appetite. Customer, product, funding and transaction risks should be assessed before growth targets are approved.
The second is independent product governance covering AML, sanctions, fraud, cyber, operational resilience and liquidity.
The third is scalable customer due diligence. Onboarding and periodic reviews must keep pace with customer growth and changes in beneficial ownership or activity.
The fourth is real-time or near-real-time screening proportionate to payment speed.
The fifth is reliable transaction monitoring supported by complete customer, account and counterparty data.
The sixth is board-level issue governance. Repeat findings, missed deadlines and control overrides should trigger escalation rather than routine extensions.
The seventh is liquidity segmentation based on depositor behaviour, operational relationships, concentration and withdrawal capability—not insurance status alone.
The eighth is realistic stress testing that assumes digital withdrawals, correlated customers and weekend or after-hours events.
Finally, supervisors and internal assurance functions should test whether remediation has changed risk in practice rather than merely producing new documentation.

What this means for financial crime leaders
Signature Bank should not be remembered as an institution that collapsed because of AML deficiencies.
It failed because an extraordinary run exposed inadequate liquidity preparation, concentrated funding and weak management. Its AML and sanctions findings reveal how the same governance culture affected another critical control area.
For financial crime leaders, the case demonstrates that compliance cannot scale independently of the business. New customer segments, payment platforms and deposit strategies change the institution’s exposure even where formal policies remain unchanged.
The most important warning sign is not one adverse examination finding. It is the accumulation of repeat issues, delayed remediation and continued expansion while the control environment remains incomplete.
A resilient institution connects financial-crime intelligence with product governance, funding analysis and operational resilience.
Signature’s collapse occurred when depositor confidence moved faster than the bank’s ability to respond. Its unresolved AML and sanctions weaknesses show that supervisory concerns had already been moving faster than management’s ability—or willingness—to remediate them.
What Financial Institutions Should Consider
- Align Financial Crime Controls With Business Growth
- Integrate AML, Sanctions and Prudential Risk Assessments
- Strengthen Board-Level Oversight of Repeat Findings
- Escalate Missed Remediation Deadlines
- Ensure Customer Due Diligence Scales With Growth
- Apply Real-Time or Near-Real-Time Sanctions Screening
- Strengthen Transaction Monitoring for Instant Payments
- Integrate Customer, Account and Counterparty Data
- Review High-Risk Customer and Sector Concentrations
- Reconcile Financial Crime Risk With Funding Concentration
- Strengthen Product Governance Before Launch
- Include AML, Fraud, Cyber and Liquidity Risks in Product Approval
- Monitor Alert Backlogs and Overdue Customer Reviews
- Track Manual Overrides and Data-Quality Failures
- Conduct Root-Cause Analysis of Recurring Control Deficiencies
- Strengthen Cross-Functional Intelligence Sharing
- Stress-Test Controls Against Rapid Digital Withdrawals
- Measure Whether Remediation Actually Reduces Residual Risk
- Ensure Risk Infrastructure Expands at the Same Pace as Revenue and Deposits
Download the briefing
Signature Bank’s Collapse: Analysis of Rapid Growth and Governance Failures




Signature Bank did not collapse because of an anti-money laundering enforcement action. It failed because an extraordinary deposit run exposed concentrated funding, inadequate contingency planning and management’s inability to mobilise sufficient liquidity under severe time pressure.
Its unresolved AML and sanctions deficiencies are nevertheless integral to understanding the wider institutional failure. They reveal a governance environment in which business growth, customer acquisition and product expansion repeatedly moved faster than risk-management capacity, board oversight and supervisory remediation.
The case demonstrates that prudential risk and financial crime compliance cannot operate as isolated disciplines. Large uninsured or operationally concentrated deposits, high-velocity payment systems, digital-asset customers and complex corporate relationships affect both liquidity behaviour and financial crime exposure. Institutions need to understand not only who their customers are, but how quickly their funds can move and how reputational events may influence collective withdrawal decisions.
For boards and senior management, repeated supervisory findings should be treated as indicators of structural weakness rather than administrative issues awaiting closure. Remediation must address the underlying causes—whether inadequate staffing, poor data, weak accountability or an aggressive risk appetite—not merely produce new policies and documentation.
Ultimately, Signature Bank’s collapse shows what can happen when confidence, technology and customer behaviour move faster than institutional decision-making. Banks that integrate AML, sanctions, product governance, liquidity planning and operational resilience will be better positioned to recognise when rapid commercial growth is creating risks that the control environment can no longer absorb.