In December 2012, HSBC agreed to pay US authorities roughly $1.9 billion to settle charges that it had let Mexican drug cartels launder hundreds of millions of dollars through its accounts. Investigators found the bank's Mexican unit had moved so much cash across the US border that traffickers used specially designed boxes sized to fit through HSBC teller windows. No executive went to prison. The bank paid, promised to fix its controls, and moved on.
That case, and the Danske Bank scandal that followed, defined the modern era of anti money laundering enforcement. This lesson explains what the rules actually require when a bank onboards a customer, why banks flood regulators with reports, and how these two failures became textbook cautionary tales.
Money laundering is the process of making money from crime (drugs, fraud, corruption, trafficking) look like it came from legitimate sources. It usually happens in three stages: placement (getting cash into the financial system), layering (moving it through many transactions to obscure the trail), and integration (spending it as if it were clean).
Governments cannot inspect every transaction. So they push the job onto banks. This is the foundation of AML (Anti Money Laundering): the set of laws requiring financial institutions to detect and report suspicious activity.
The bank is legally deputized. If it fails, the bank pays.
KYC (Know Your Customer) is the first line of defense. Before a bank opens an account, it must verify who the customer really is.
In the US, the legal backbone is the Bank Secrecy Act (BSA) of 1970, strengthened massively by the USA PATRIOT Act of 2001 after the September 11 attacks. The PATRIOT Act introduced the Customer Identification Program (CIP) rule, which requires banks to collect and verify:
In the EU, the equivalent framework runs through a series of Anti Money Laundering Directives (the latest being the 6th, or 6AMLD) and, from 2024, a new single EU Anti Money Laundering Regulation plus a central agency, AMLA (the Anti Money Laundering Authority), based in Frankfurt and beginning direct supervision of high risk institutions during 2026.
KYC is not one size fits all. Banks apply Customer Due Diligence (CDD) proportional to risk.
A critical requirement is identifying the Ultimate Beneficial Owner (UBO): the real human who ultimately owns or controls a company, even when hidden behind layers of holding entities. In the US, the Corporate Transparency Act now requires many companies to report beneficial ownership to FinCEN (the Financial Crimes Enforcement Network, the US Treasury bureau that runs AML).
For a plain-language overview of the US framework, FinCEN's own site is the authoritative free resource: fincen.gov.
KYC at onboarding is only the start. Banks must monitor customers for the life of the relationship.
Automated transaction monitoring systems flag anomalies: a retiree suddenly receiving $50,000 wire transfers from three countries, or an account structured to stay just under reporting thresholds (called structuring or "smurfing").
When something looks wrong, the bank files a SAR (Suspicious Activity Report) with FinCEN. In the EU the equivalent is a STR (Suspicious Transaction Report) filed to a national FIU (Financial Intelligence Unit).
Key facts about SARs:
US institutions file millions of SARs per year (FinCEN reported well over 3 million SAR filings annually in recent years, per its public statistics). The volume is enormous, which creates its own problem: too many low quality reports can bury the genuinely important ones.
The HSBC failure was not a single missed transaction. It was systemic.
The 2012 settlement (about $1.9 billion) came with a Deferred Prosecution Agreement (DPA): criminal charges filed but suspended, provided the bank reformed and accepted an independent monitor. The DPA became the standard enforcement tool for large banks, criticized by some as letting institutions buy their way out.
The Danske Bank case is the largest known money laundering scandal in European history.
Between roughly 2007 and 2015, Danske Bank's small Estonian branch processed an estimated 200 billion euros in suspicious transactions, much of it from Russia and former Soviet states, routed through non resident customer accounts.
The failure was structural:
In 2022, Danske Bank pleaded guilty in the US and agreed to forfeiture and penalties totaling around $2 billion, coordinated across US and Danish authorities. Its CEO had already resigned in 2018.
The lesson banks drew: a "small" foreign branch can generate an existential fine. Group wide, consistent controls are not optional.
Vérification des acquis
1. Why do governments require banks, rather than inspecting transactions themselves, to detect and report money laundering?
2. A criminal deposits large amounts of cash from drug sales into several bank accounts. Which stage of money laundering does this represent?
3. What is the primary purpose of a Know Your Customer (KYC) program?
4. Select ALL correct answers about how the HSBC case illustrates AML enforcement principles.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers describing what a Customer Identification Program (CIP) requires banks to collect and verify.
Sélectionnez toutes les réponses correctes.
AML is one of the largest compliance line items in banking. Global spending on financial crime compliance runs into the tens of billions of dollars annually (industry surveys consistently estimate this range, though exact figures vary by methodology).
The costs fall into three buckets:
1. People: large teams of analysts investigating alerts and filing SARs.
2. Technology: transaction monitoring, sanctions screening, and increasingly machine learning to cut false positives.
3. Fines and remediation: when controls fail.
There is a real tension here. Over-flagging wastes money and annoys legitimate customers (a phenomenon called de-risking, where banks simply close whole categories of accounts, like money transfer firms serving immigrant communities, because the risk is not worth it). Under-flagging invites the next billion dollar fine.
AML sits next to sanctions screening, and the two are often confused. Sanctions are government prohibitions on doing business with specific people, entities, or countries.
In the US, sanctions are enforced by OFAC (Office of Foreign Assets Control), part of the Treasury. Banks must screen every customer and transaction against the SDN list (Specially Designated Nationals). Processing a payment for a sanctioned party is a strict liability offense: intent does not matter, and penalties are severe. Since 2022, Russia related sanctions have dramatically expanded the screening burden across US and EU banks.