If you work in compliance, you already assign risk ratings to customers, countries, and relationships. Low, medium, high, or some variation of that scale, sitting in a system somewhere and quietly determining how closely your organisation monitors a given relationship.
One major banking enforcement case is worth understanding because it shows what can happen when that rating is wrong, at a scale most people never imagine possible.
Here is the plain version of what happened.
Between 2006 and 2010, a major international bank had classified a particular country as low risk. That single decision meant hundreds of billions of dollars in transactions from that country did not pass through certain automated monitoring systems designed to identify suspicious activity, because low-risk relationships were excluded from that scrutiny by design.
At the same time, a regulatory investigation found that billions of dollars in bulk cash moved through some of the bank's highest-risk accounts without adequate monitoring either.
You do not need to work in banking to see the problem.
A jurisdiction experiencing significant organised-crime activity, with billions in cash moving across its borders, was being treated as substantially less concerning than the underlying risk environment suggested.
The consequence was that hundreds of millions of dollars in suspected illicit proceeds moved through the institution without being identified at the time.
The case also included evidence suggesting that criminal networks viewed the institution as a convenient channel for moving illicit funds. That detail is particularly important because it illustrates how quickly a weakness in a control environment can become known and exploited externally.
The institution ultimately agreed to pay a substantial financial penalty and entered into a deferred prosecution agreement.
If you are not familiar with that term, it generally means prosecutors agree to hold criminal charges in abeyance subject to specific conditions. These can include enhanced compliance requirements, independent monitoring, remediation programmes, and measures designed to improve accountability within the organisation.
The case generated significant debate about enforcement, individual accountability, and whether imposing criminal consequences on a systemically important financial institution could create broader financial stability concerns.
But the most useful lesson is not the size of the penalty.
It is the role of the risk rating.
A risk rating is not a formality that gets completed once and forgotten. It can determine which transactions receive additional scrutiny, which controls are triggered, and where monitoring resources are concentrated.
The institution did not necessarily lack technology or monitoring capability.
The bigger issue was whether those capabilities were being directed toward the relationships and jurisdictions where the underlying risk actually existed.
And that raises a question worth asking in any compliance programme:
Does your current risk rating reflect what is actually happening in a relationship or jurisdiction today, or does it reflect an assumption that nobody has revisited in years?
A later enforcement case involving another major financial institution demonstrated that regulators can take a significantly different approach over time, including requiring stronger forms of accountability and imposing substantial financial penalties.
The broader lesson is simple:
Regulatory expectations move. Risk environments change. Your compliance framework needs to move with them.
If your risk methodology is still calibrated to what regulators considered acceptable many years ago, it may already be behind where the bar sits today.
For those interested in the underlying case:
The discussion above is based on publicly available regulatory and enforcement materials relating to a major international banking enforcement case, including US government and congressional records.
Sources: U.S. Department of Justice (2012) and U.S. Senate Permanent Subcommittee on Investigations (2012), public enforcement and hearing records concerning the case.
Disclaimer: Content posted is for informational and knowledge sharing purposes only, and is not intended to be a substitute for professional advice related to tax, finance or accounting. The view/interpretation of the publisher is based on the available Law, guidelines and information. Each reader should take due professional care before you act after reading the contents of that article/post. No warranty whatsoever is made that any of the articles are accurate and is not intended to provide, and should not be relied on for tax or accounting advice.Contributor
Related Posts

One of the most useful lessons from major financial crime cases is also one of the easiest to overlo...
Read More
Why third-party payment processor relationships remain one of the harder due diligence problems in t...
Read More
UAE, 21 August, 2026: The UAE Federal Tax Authority (FTA) has introduced a new Advance Pricing ...
Read More