Anti-money laundering enforcement in the United Kingdom and France is often compared through annual fine totals. The largest number attracts the headline, institutions are ranked by penalty value and regulators are described as becoming more or less aggressive according to the amount collected.
That approach can be misleading.
A regulatory fine, criminal court penalty, asset-forfeiture order, gambling settlement and anti-corruption agreement are legally different outcomes. They may be imposed by different authorities, concern different conduct and apply different evidential standards.
The United Kingdom’s 2022 enforcement record was dominated by a £107.8 million Financial Conduct Authority penalty against Santander UK for serious and persistent weaknesses in its business-banking AML controls. The FCA imposed £215.8 million in fines across all regulatory categories during the year, substantially below its 2021 total.
In France, the principal AML supervisor for banks, payment institutions and insurers was the Autorité de contrôle prudentiel et de résolution. Its Sanctions Committee issued three AML, counter-terrorist-financing and asset-freezing decisions in 2022, imposing combined penalties of €2.35 million.
Those figures do not support a simple narrative in which the UK and France competed through record AML fines. They reveal two enforcement systems using different combinations of supervision, administrative sanctions, criminal proceedings, asset recovery and remediation.
The deeper lesson is that enforcement should be judged by the control weaknesses identified and the behaviour changed—not only by the value of the final penalty.
Key Takeaways
- AML Enforcement Remains a Major European Regulatory Priority
- The UK Continues to Demonstrate Strong Financial Crime Enforcement
- France Has Increased the Severity of Financial Crime Penalties
- Large Fines Often Reflect Systemic Control Weaknesses
- High-Risk Customers Require Effective Ongoing Monitoring
- Customer Onboarding Controls Must Be Supported by Post-Onboarding Surveillance
- Money Services Businesses Create Elevated Financial Crime Exposure
- Challenger Banks and Fintechs Face Increasing AML Scrutiny
- Rapid Customer Onboarding Can Increase Financial Crime Vulnerabilities
- Gambling Operators Remain Exposed to Significant AML Enforcement Risk
- Third-Party Relationships Can Create Additional Compliance Exposure
- Regulatory Enforcement Extends Beyond Traditional Banks
- Asset Forfeiture Is Becoming an Important Financial Crime Disruption Tool
- Enforcement Trends Highlight the Cost of Weak Financial Crime Governance
- Regulatory Penalties Should Be Treated as Indicators of Broader Control Failures
Listen the podcast
Watch the video
Why the 2022 enforcement record still matters
The cases concluded in 2022 exposed control failures that remain central to AML enforcement.
Institutions were criticised for accepting customer information without testing whether it was credible, failing to compare expected activity with actual transactions, operating incomplete monitoring scenarios and allowing high-risk relationships to continue after warning signs had emerged.
Payment businesses and digital banks faced particular scrutiny because rapid onboarding, automated decision-making and high transaction volumes allowed commercial growth to move faster than financial-crime controls.
Correspondent banking, cross-border remittances and cash-connected products also remained prominent. These activities can be legitimate and economically important, but they expose institutions to customers and counterparties whose underlying activity may be difficult to verify.
The enforcement record therefore reflected a broader regulatory concern: firms had policies describing risk-based compliance but could not always demonstrate that those policies affected onboarding, monitoring, investigation or customer exit.
The Santander penalty and expected activity
The FCA fined Santander UK £107.8 million after identifying prolonged weaknesses affecting more than 560,000 business-banking customers between December 2012 and October 2017.
The bank did not adequately verify information concerning the nature and expected scale of customers’ businesses. It also failed to monitor effectively whether actual account activity corresponded with the anticipated profile.
One customer described itself as a small translation business and declared expected monthly deposits of approximately £5,000. Within six months, the account was receiving millions of pounds and rapidly transferring the money elsewhere.
Santander’s AML function recommended closure in 2014, but weaknesses in internal processes meant that the relationship continued. Although law enforcement later requested that the account remain open temporarily, the bank failed to maintain appropriate control of that arrangement and did not close the account until regulatory intervention.
The case illustrates why expected activity is not a static field completed during onboarding. It should form part of the institution’s monitoring logic.
Where turnover, payment corridors, transaction velocity or counterparties diverge materially from the declared business model, the institution must determine whether the customer has grown legitimately, provided inaccurate information or is being used to move illicit funds.
Why identifying a red flag is not enough
Many enforcement cases do not involve the complete absence of alerts. The institution detects something unusual but fails to convert that information into action.
An alert may be closed without adequate investigation. An account-exit recommendation may remain in a queue. A law-enforcement request may not be reviewed when it expires. Responsibility may move between operations, compliance and relationship management without one function owning the outcome.
This creates a gap between detection and disruption.
A transaction-monitoring system can generate thousands of alerts while producing little risk reduction if cases are delayed, poorly investigated or repeatedly returned for more information.
Institutions therefore need to measure the complete alert lifecycle: when the activity occurred, when it was detected, how long the investigation took, who authorised the conclusion and whether the customer’s risk assessment or account status changed.
Regulators increasingly treat unresolved alerts and ineffective escalation as governance failures, not merely operational backlogs.
Correspondent banking and Ghana International Bank
The FCA also fined Ghana International Bank £5.8 million in 2022 for weaknesses in controls governing correspondent banking relationships.
Correspondent banking allows one financial institution to provide payment and other services to another bank. It is essential for cross-border commerce, remittances and access to international financial markets.
The arrangement can also create indirect exposure. The correspondent may process transactions for the respondent bank’s customers without holding a direct relationship with those individuals or businesses.
Enhanced due diligence should therefore establish the respondent institution’s ownership, management, business model, customer base, regulatory environment and AML framework.
The FCA found that Ghana International Bank had not adequately performed or evidenced the additional checks required for certain overseas banking relationships.
This case reinforced a recurring enforcement principle: longstanding relationships and institutional status do not remove the need for documented, risk-based assessment.
Challenger banks and rapid onboarding
In 2022, the FCA published a review of financial-crime controls at challenger banks.
The regulator recognised that digital onboarding could improve competition and customer access. It also identified weaknesses in customer-risk assessment, enhanced due diligence, transaction monitoring and suspicious-activity reporting.
Some institutions did not gather enough information about income or occupation. Others applied broad risk categories that did not reflect how particular customers would use their accounts.
The concern was not digital onboarding itself. It was the assumption that speed and simplified customer experience could be achieved without sufficiently strong identity, behavioural and transaction controls.
Later enforcement confirmed that the issue had not disappeared. Starling Bank was fined approximately £29 million in 2024 for financial-crime weaknesses involving sanctions screening and breaches of restrictions on opening accounts for high-risk customers.
Monzo received a £21.1 million penalty in 2025 for inadequate financial-crime systems and repeated breaches of an account-opening restriction.
The consistent message is that regulatory requirements imposed during remediation form part of the control environment. Breaching them can be as serious as the original deficiency.
Data quality as an enforcement issue
Metro Bank’s £16.7 million penalty in 2024 demonstrated that a transaction-monitoring system is only as effective as the data entering it.
More than 60 million transactions, valued at over £51 billion, were not adequately monitored during the relevant period because of deficiencies in the system’s configuration, data feeds and exception handling.
Some customer, account and transaction records were rejected because of data-quality problems. The processes intended to identify and correct those failures did not ensure that the affected activity was monitored promptly—or at all.
This is not simply an information-technology problem.
When relevant transactions never reach the monitoring engine, the bank cannot generate alerts, investigate activity or determine whether a suspicious-activity report is required.
A resilient AML programme therefore needs data lineage showing how information moves from source systems into screening and monitoring platforms. Rejected files, missing fields, interface failures and manual workarounds must be independently tracked.
Management information based only on alerts successfully generated can provide false assurance where the system does not measure what it failed to ingest.
The UK enforcement model extends beyond the FCA
UK AML enforcement is distributed across several bodies.
The FCA supervises authorised financial institutions and registered cryptoasset businesses. HM Revenue and Customs supervises several other regulated sectors. The Gambling Commission oversees gambling operators, while professional bodies historically supervised many legal and accountancy firms.
Law-enforcement agencies, prosecutors and courts can pursue criminal offences, confiscation and account-forfeiture measures.
In 2022, the FCA obtained its first account-forfeiture order, recovering £2 million held in accounts belonging to QPay Europe. The proceedings concerned funds associated with an alleged US wire-fraud scheme and were brought under proceeds-of-crime legislation rather than through an ordinary regulatory fine.
The Gambling Commission separately imposed a £17 million regulatory settlement on Entain for AML and social-responsibility failures.
These outcomes should not be added together and described as one category without qualification. They measure different enforcement functions: preventive supervision, regulatory discipline, asset recovery and criminal-justice intervention.
Correcting the French enforcement picture
The original reporting attributed large AML penalties to the French Anti-Corruption Agency and associated the agency with cases involving financial institutions and major industrial companies.
That framing combined separate legal systems.
The AFA helps public bodies and companies prevent and detect corruption, influence peddling and related integrity offences. Its independent Sanctions Committee can impose penalties for failures to maintain anti-corruption compliance arrangements, with a maximum corporate fine of €1 million.
It does not serve as the principal AML supervisor for French banks and insurers.
That role belongs to the ACPR, which supervises customer due diligence, beneficial ownership, transaction monitoring, suspicious-transaction reporting and asset-freezing controls.
Corporate settlements concerning bribery, corruption or tax offences may be negotiated by prosecutors through conventions judiciaires d’intérêt public and validated by a court. The AFA may supervise a compliance programme attached to such a settlement, but it does not become the authority imposing every associated financial penalty.
Regulatory analysis must preserve these distinctions. Otherwise, anti-bribery, tax, AML and customer-protection outcomes are incorrectly presented as one enforcement category.
What the ACPR actually did in 2022
The ACPR opened six AML/CFT disciplinary proceedings, issued six formal notices and sent 26 action letters during 2022.
Its Sanctions Committee concluded three AML, CFT and asset-freezing cases.
The New Caledonia postal and telecommunications authority received a €150,000 penalty for serious weaknesses affecting risk classification, beneficial-owner identification, customer knowledge, politically exposed person controls, transaction monitoring and asset-freezing arrangements.
W-HA, an electronic-money institution associated with the Orange Money France service, was fined €700,000. The ACPR found weaknesses in customer knowledge and transaction monitoring, including excessive reliance on transaction limits rather than meaningful behavioural analysis. The deficiencies contributed to failures to report suspicious transactions and were particularly significant because the product involved wire transfers, cash exposure and payments involving higher-risk jurisdictions.
Crédit Agricole’s Languedoc regional bank received a €1.5 million penalty. Its monitoring system used an incomplete set of scenarios and could not detect certain forms of unusual activity.
The three decisions imposed €2.35 million in AML-related fines. The ACPR’s larger €14.4 million total for the year included unrelated customer-protection sanctions.
Why smaller fines can still matter
Penalty value does not provide a complete measure of enforcement intensity.
A regulator may impose a moderate fine while requiring extensive remediation, restricting activities, naming the institution publicly or increasing ongoing supervisory scrutiny.
The reputational and operational costs can exceed the penalty. A firm may need to replace systems, refresh customer files, appoint additional employees and conduct historical transaction reviews.
French sanctions also provide detailed statements of regulatory expectations. The W-HA decision clarified that discussing a product with the supervisor before launch does not transfer responsibility for the control framework to the regulator.
An institution remains responsible for testing whether monitoring works once real customers, transactions and geographic risks enter the system.
Similarly, the Crédit Agricole case showed that an otherwise functioning AML programme can remain materially deficient where its scenario coverage does not address foreseeable risks.
France’s wider enforcement strengths and gaps
FATF’s 2022 evaluation found that France achieved strong results in financial intelligence, money-laundering investigations and prosecutions, including complex and high-end cases.
The assessment also identified areas requiring improvement. Complex investigations could take considerable time, and some non-financial sectors required stronger risk-based supervision.
France’s enforcement capability therefore cannot be assessed through ACPR fines alone.
Tracfin disseminates financial intelligence, prosecutors pursue criminal proceedings, courts impose penalties and confiscation, customs authorities address cross-border offences, and sector supervisors enforce preventive obligations.
The central effectiveness question is whether those components exchange information and produce cases proportionate to France’s risks—including corruption, tax crime, fraud, organised crime and the use of corporate and property structures.
Enforcement after 2022
UK enforcement continued to focus on governance, monitoring coverage and high-risk customer decisions.
Alongside the Starling, Metro and Monzo cases, the FCA fined Barclays entities £42 million in 2025 for separate financial-crime risk-management failings.
Nationwide Building Society received a £44.1 million penalty later that year for weaknesses in customer due diligence, risk assessment and transaction monitoring. The FCA stated that, since 2021, it had imposed 13 bank penalties totalling more than £300 million for AML systems-and-controls failings.
France continued using targeted ACPR sanctions and supervisory remediation. Treezor, a banking-as-a-service and electronic-money institution, was fined €1 million in 2024 after the Sanctions Committee identified deficiencies in areas including risk classification and related controls.
The cases show that enforcement is moving beyond traditional incumbent banks. Digital banks, embedded-finance providers and payment institutions are expected to demonstrate the same control effectiveness while managing different technology, distribution and customer-risk models.
The move towards supervisory consolidation
Both jurisdictions are entering a period of structural change.
The UK government decided that the FCA should assume AML supervisory responsibility for legal, accountancy and trust-and-company-service providers currently overseen by multiple professional bodies and parts of HMRC’s regime.
The reform is intended to reduce fragmentation and strengthen consistency, although implementation will require the FCA to develop sector-specific expertise and supervise a much broader population.
Within the European Union, the new Anti-Money Laundering Authority began building its operations in 2025.
AMLA is expected to select 40 high-risk cross-border financial institutions during 2027 and begin direct supervision in 2028. It will also coordinate national authorities and promote more consistent risk assessment and enforcement.
For French institutions, ACPR supervision will increasingly operate within this common European framework.
What an evidence-led enforcement response looks like
Institutions should not respond to a major penalty by correcting only the control named in the final notice.
A transaction-monitoring failure may originate in inaccurate onboarding data, incomplete product governance or weak system interfaces. A delayed account closure may reflect unclear authority and commercial resistance rather than a simple procedural mistake.
Root-cause analysis should identify why the weakness survived internal audit, compliance testing and board oversight.
The institution should reconstruct the complete customer journey: information collected at onboarding, risk rating, expected activity, monitoring coverage, alerts, investigations, regulatory reports and exit decisions.
Remediation should then be tested against real transactions and customer files. A new policy, scenario or committee does not prove that risk has fallen.
The board should receive measurable evidence showing whether alert delays, missing data, overdue reviews and repeat exceptions are declining.
What a resilient control stack looks like
The first layer is a current enterprise-wide financial-crime risk assessment connected to actual customers, products, countries and delivery channels.
The second is reliable customer due diligence capable of establishing ownership, business purpose, source of funds and expected activity.
The third is data governance ensuring that complete and accurate information reaches monitoring and screening systems.
The fourth is risk-sensitive transaction monitoring combining scenarios, behavioural analytics and documented threshold governance.
The fifth is effective case management. Alerts must result in timely decisions, escalations and changes to customer treatment.
The sixth is control over high-risk onboarding and account restrictions. Exceptions should require independent approval and remain visible to senior management.
The seventh is quality suspicious-activity reporting that explains the suspected criminal behaviour and relevant flow of funds.
Finally, boards should treat repeat findings as evidence that the institution has not addressed the root cause, even where individual action plans have technically been closed.

What this means for financial crime leaders
The enforcement records of the UK and France should not be reduced to a competition over fine totals.
The UK has used large public penalties, criminal proceedings, asset-forfeiture measures and sector reviews to communicate expectations. France has combined ACPR supervision with financial intelligence, judicial enforcement, anti-corruption oversight and increasingly coordinated European structures.
Despite those institutional differences, the underlying control failures are highly consistent.
Firms accept unverified customer information, fail to compare expected and actual activity, operate incomplete monitoring systems, lose transactions through poor data and delay action after identifying risk.
The strongest financial-crime programmes will therefore study the facts behind enforcement decisions rather than the headline amount.
A penalty shows where a regulator concluded that the control environment failed. Sustainable remediation requires the institution to determine why the failure remained undetected, why management tolerated it and whether the same weakness exists elsewhere.
Enforcement becomes effective when it changes those conditions—not simply when the fine is paid.
What Financial Institutions Should Consider
- Strengthen Enterprise-Wide AML Risk Assessments
- Apply Enhanced Due Diligence to High-Risk Customers
- Strengthen Money Services Business Controls
- Improve Ongoing Customer Monitoring
- Review Transaction Monitoring Effectiveness
- Strengthen Suspicious Transaction Reporting Processes
- Ensure Rapid Onboarding Does Not Weaken KYC Controls
- Assess Financial Crime Risks Before Launching New Products
- Strengthen Third-Party Due Diligence
- Monitor Regulatory Findings Across Relevant Jurisdictions
- Conduct Root-Cause Analysis of AML Control Failures
- Strengthen Board and Senior Management Oversight
- Ensure Compliance Resources Scale With Business Growth
- Test AML Controls for Effectiveness Rather Than Design Alone
- Strengthen Remediation Governance and Accountability
- Track Repeat Findings and Overdue Remediation Actions
- Integrate Regulatory Enforcement Intelligence Into Risk Assessments
- Benchmark AML Programmes Against Enforcement Lessons
- Treat Regulatory Fines as Signals for Preventive Control Enhancement




The enforcement records of the United Kingdom and France demonstrate why anti-money laundering effectiveness cannot be measured through headline penalties alone.
Large fines attract attention, but the most important findings concern the operational weaknesses behind them: unverified customer information, incomplete transaction monitoring, poor data quality, inadequate correspondent-banking controls and delayed action after suspicious activity has already been identified.
The comparison also shows the importance of legal and institutional precision. FCA penalties, ACPR sanctions, criminal proceedings, asset-forfeiture orders and anti-corruption settlements are different enforcement outcomes. Combining them into one total can obscure which authority acted, what misconduct was established and which control failure the case was intended to address.
For financial institutions, the practical lesson is that formal compliance provides limited protection where controls do not influence real decisions. Expected account activity must be compared with actual behaviour, monitoring systems must receive complete data, and customer-exit or escalation recommendations must be implemented within clearly defined timeframes.
Boards and senior management should pay particular attention to recurring deficiencies. A repeated finding usually indicates that the institution has corrected a symptom without addressing the underlying cause—whether weak accountability, insufficient resources, defective technology or commercial resistance to compliance decisions.
Ultimately, enforcement becomes meaningful when it changes how institutions identify, investigate and disrupt financial crime. The strongest programmes will look beyond the size of the fine and examine why the weakness remained undetected, why remediation failed and whether the same control gap exists elsewhere in the organisation.