Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/Banking: how the sector works/Regulation, major laws and compliance/KYC, AML and the cost of dirty money
3/5+150 XP

Regulation, major laws and compliance

10The regulators who can shut your bank down+15011Basel and the capital rulebook in practice+15012KYC, AML and the cost of dirty money+15013Protecting the customer: conduct and fair treatment+15014Building a compliance function that survives an audit+150

KYC, AML and the cost of dirty money

KYC, AML and the cost of dirty money

In December 2012, HSBC agreed to pay US authorities roughly $1.9 billion to settle charges that it had let Mexican drug cartels launder hundreds of millions of dollars through its accounts. Investigators found the bank's Mexican unit had moved so much cash across the US border that traffickers used specially designed boxes sized to fit through HSBC teller windows. No executive went to prison. The bank paid, promised to fix its controls, and moved on.

That case, and the Danske Bank scandal that followed, defined the modern era of anti money laundering enforcement. This lesson explains what the rules actually require when a bank onboards a customer, why banks flood regulators with reports, and how these two failures became textbook cautionary tales.

The core problem: banks are the gatekeepers

Money laundering is the process of making money from crime (drugs, fraud, corruption, trafficking) look like it came from legitimate sources. It usually happens in three stages: placement (getting cash into the financial system), layering (moving it through many transactions to obscure the trail), and integration (spending it as if it were clean).

Governments cannot inspect every transaction. So they push the job onto banks. This is the foundation of AML (Anti Money Laundering): the set of laws requiring financial institutions to detect and report suspicious activity.

The bank is legally deputized. If it fails, the bank pays.

KYC: knowing who you are dealing with

KYC (Know Your Customer) is the first line of defense. Before a bank opens an account, it must verify who the customer really is.

In the US, the legal backbone is the Bank Secrecy Act (BSA) of 1970, strengthened massively by the USA PATRIOT Act of 2001 after the September 11 attacks. The PATRIOT Act introduced the Customer Identification Program (CIP) rule, which requires banks to collect and verify:

  • Name
  • Date of birth
  • Address
  • An identification number (Social Security number, passport, or business tax ID)

In the EU, the equivalent framework runs through a series of Anti Money Laundering Directives (the latest being the 6th, or 6AMLD) and, from 2024, a new single EU Anti Money Laundering Regulation plus a central agency, AMLA (the Anti Money Laundering Authority), based in Frankfurt and beginning direct supervision of high risk institutions during 2026.

Beyond basic ID: risk-based due diligence

KYC is not one size fits all. Banks apply Customer Due Diligence (CDD) proportional to risk.

  • A salaried customer opening a checking account: standard CDD.
  • A Politically Exposed Person (PEP), meaning a senior government official or their close associates who pose higher corruption risk: Enhanced Due Diligence (EDD), with source of wealth checks and senior sign off.
  • A shell company registered offshore with no clear business: EDD or refusal.

A critical requirement is identifying the Ultimate Beneficial Owner (UBO): the real human who ultimately owns or controls a company, even when hidden behind layers of holding entities. In the US, the Corporate Transparency Act now requires many companies to report beneficial ownership to FinCEN (the Financial Crimes Enforcement Network, the US Treasury bureau that runs AML).

For a plain-language overview of the US framework, FinCEN's own site is the authoritative free resource: fincen.gov.

Ongoing monitoring and the SAR

KYC at onboarding is only the start. Banks must monitor customers for the life of the relationship.

Automated transaction monitoring systems flag anomalies: a retiree suddenly receiving $50,000 wire transfers from three countries, or an account structured to stay just under reporting thresholds (called structuring or "smurfing").

When something looks wrong, the bank files a SAR (Suspicious Activity Report) with FinCEN. In the EU the equivalent is a STR (Suspicious Transaction Report) filed to a national FIU (Financial Intelligence Unit).

Key facts about SARs:

  • They must be filed within a set window (30 days in the US after detecting the suspicious activity).
  • Tipping off the customer that a SAR was filed is itself a crime.
  • Banks also file CTRs (Currency Transaction Reports) automatically for cash transactions above $10,000. A CTRCTRClick-Through Rate (CTR) is the percentage of people who click a link, ad, or call to action out of those who viewed it.View full definition → is routine and not an accusation; a SAR signals suspicion.

US institutions file millions of SARs per year (FinCEN reported well over 3 million SAR filings annually in recent years, per its public statistics). The volume is enormous, which creates its own problem: too many low quality reports can bury the genuinely important ones.

Case study 1: HSBC

The HSBC failure was not a single missed transaction. It was systemic.

  • Its Mexican affiliate classified Mexico as low risk despite obvious cartel exposure.
  • It cleared US dollar transactions for banks in sanctioned countries by stripping identifying information from wire messages so filters would not catch them.
  • Its monitoring systems were underfunded and understaffed relative to the risk.

The 2012 settlement (about $1.9 billion) came with a Deferred Prosecution Agreement (DPA): criminal charges filed but suspended, provided the bank reformed and accepted an independent monitor. The DPA became the standard enforcement tool for large banks, criticized by some as letting institutions buy their way out.

Case study 2: danske bank

The Danske Bank case is the largest known money laundering scandal in European history.

Between roughly 2007 and 2015, Danske Bank's small Estonian branch processed an estimated 200 billion euros in suspicious transactions, much of it from Russia and former Soviet states, routed through non resident customer accounts.

The failure was structural:

  • The Estonian branch ran on a separate IT platform, so head office monitoring did not cover it.
  • Whistleblower warnings were ignored for years.
  • Correspondent banking (where Danske used larger banks to clear dollar transactions) spread the contamination.

In 2022, Danske Bank pleaded guilty in the US and agreed to forfeiture and penalties totaling around $2 billion, coordinated across US and Danish authorities. Its CEO had already resigned in 2018.

The lesson banks drew: a "small" foreign branch can generate an existential fine. Group wide, consistent controls are not optional.

Knowledge check

1. Why do governments require banks, rather than inspecting transactions themselves, to detect and report money laundering?

2. A criminal deposits large amounts of cash from drug sales into several bank accounts. Which stage of money laundering does this represent?

3. What is the primary purpose of a Know Your Customer (KYC) program?

MULTIPLE CHOICE

4. Select ALL correct answers about how the HSBC case illustrates AML enforcement principles.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL correct answers describing what a Customer Identification Program (CIP) requires banks to collect and verify.

Select all the correct answers.

Why this costs banks so much

AML is one of the largest compliance line items in banking. Global spending on financial crime compliance runs into the tens of billions of dollars annually (industry surveys consistently estimate this range, though exact figures vary by methodology).

The costs fall into three buckets:

1. People: large teams of analysts investigating alerts and filing SARs.

2. Technology: transaction monitoring, sanctions screening, and increasingly machine learning to cut false positives.

3. Fines and remediation: when controls fail.

There is a real tension here. Over-flagging wastes money and annoys legitimate customers (a phenomenon called de-risking, where banks simply close whole categories of accounts, like money transfer firms serving immigrant communities, because the risk is not worth it). Under-flagging invites the next billion dollar fine.

Sanctions: the adjacent obligation

AML sits next to sanctions screening, and the two are often confused. Sanctions are government prohibitions on doing business with specific people, entities, or countries.

In the US, sanctions are enforced by OFAC (Office of Foreign Assets Control), part of the Treasury. Banks must screen every customer and transaction against the SDN list (Specially Designated Nationals). Processing a payment for a sanctioned party is a strict liability offense: intent does not matter, and penalties are severe. Since 2022, Russia related sanctions have dramatically expanded the screening burden across US and EU banks.

Key Takeaways

  • KYC is a legal gate, not a formality. Under the US Bank Secrecy Act and PATRIOT Act (and the EU's AML Directives and new AMLA regime), banks must verify identity, identify the ultimate beneficial owner, and apply enhanced due diligence to higher risk customers like PEPs.
  • The SAR is the core reporting weapon. Banks must file Suspicious Activity Reports promptly, must not tip off the customer, and file automatic Currency Transaction Reports for cash over $10,000.
  • HSBC (roughly $1.9 billion, 2012) and Danske Bank (roughly $2 billion, 2022) show that AML failures are systemic, not accidental: weak risk classification, siloed IT, ignored whistleblowers, and correspondent banking spread the damage.
  • Compliance is a permanent, expensive constraint. Banks balance over-flagging (cost and de-risking) against under-flagging (catastrophic fines), which shapes who gets banked at all.
  • Sanctions screening (OFAC in the US) is strict liability: intent is irrelevant, and it has grown sharply since 2022.

Previous

Basel and the capital rulebook in practice

Next

Protecting the customer: conduct and fair treatment