Blog

Jurisdictions & Regulation

2022 Financial Crime Penalties: The Cost of Non-Compliance

The major 2022 AML and terrorism-financing enforcement actions with verified figures, from Danske Bank's criminal forfeiture to Santander UK's FCA fine.

The 2022 enforcement year was defined by four resolutions: Danske Bank's USD 2.059 billion criminal forfeiture, Lafarge's USD 777.78 million terrorism-financing plea, Santander UK's GBP 107.8 million FCA fine and USAA's USD 140 million Bank Secrecy Act penalty. Each traced back to monitoring and reporting failures left unaddressed for years.

Key takeaways

  • Danske Bank's Danish criminal case closed on 14 December 2022 with a DKK 3.5 billion fine and DKK 1.249 billion confiscated, the largest money laundering fine ever imposed in Denmark.
  • Lafarge SA was the first company prosecuted in the United States for material support to terrorism, showing that terrorism-financing exposure is not limited to regulated financial institutions.
  • Santander UK's failures ran from 31 December 2012 to 18 October 2017 and touched more than 560,000 business banking customers, with over GBP 298 million flowing through accounts before closure.
  • Bittrex paid a single USD 29,280,829.20 penalty covering both a FinCEN AML case and an OFAC sanctions settlement, because the same weak onboarding data caused both breaches.
  • Every 2022 figure has since been exceeded. TD Bank's USD 3.09 billion resolution in October 2024 reset the ceiling for Bank Secrecy Act enforcement.

Which 2022 penalties were the largest, and what triggered them?

The 2022 cases split into two groups. Danske Bank and Lafarge were criminal prosecutions in the United States, resolved by guilty plea. Santander UK, USAA and Bittrex were regulatory actions, resolved by final notice or consent order without any admission of criminality.

InstitutionAuthorityDateAmountCore failure
Danske BankUS Department of Justice13 December 2022USD 2.059 billion forfeitureBank fraud conspiracy over Estonian branch controls
Danske BankUS Securities and Exchange Commission13 December 2022USD 413 millionMisleading investors on AML compliance
Danske BankCopenhagen City Court, on prosecution by SSK14 December 2022DKK 3.5 billion fine, DKK 1.249 billion confiscatedUnmonitored transactions and weak group oversight
Lafarge SA and Lafarge Cement SyriaUS Department of Justice18 October 2022USD 777.78 millionMaterial support to ISIS and the al-Nusrah Front
Santander UKFinancial Conduct Authority9 December 2022GBP 107,793,300Business banking AML systems and controls
USAA Federal Savings BankFinCEN, with credited OCC penalty17 March 2022USD 140 millionAML programme and suspicious activity reporting
BittrexFinCEN and OFAC11 October 2022USD 29,280,829.20No transaction monitoring, no SARs, sanctions exposure

Read the amounts against duration rather than institution size. Santander's conduct period ran almost five years, Danske's Estonian non-resident portfolio ran until the start of 2016, and Bittrex filed no suspicious activity reports at all for more than three years.

What did Danske Bank actually plead guilty to?

Not money laundering. On 13 December 2022 Danske Bank pleaded guilty to one count of conspiracy to commit bank fraud, because it had misrepresented the customer base and AML controls of its Estonian branch to US correspondent banks in order to obtain access to the US financial system. The Department of Justice announcement records criminal forfeiture of USD 2.059 billion.

The customers concerned were non-residents of Estonia, many of them Russian, and between 2009 and 2016 they generated as much as 99 per cent of the branch's profits. The SEC brought a parallel case on disclosure rather than laundering, settled for USD 413 million made up of USD 178.6 million in disgorgement, USD 55.8 million in prejudgment interest and a USD 178.6 million civil penalty.

Denmark closed its own criminal case a day later. The Danish prosecution service confirmed a DKK 3.5 billion fine plus DKK 1.249 billion in confiscated profit, citing head-office failure to monitor branch transactions, and failure to act on a whistleblower warning received in late 2013.

Why was Lafarge prosecuted for terrorism financing rather than money laundering?

Because the payments themselves were the offence. Lafarge SA and Lafarge Cement Syria paid ISIS and the al-Nusrah Front so that a cement plant in northern Syria could keep operating through 2013 and 2014. That is material support to a designated foreign terrorist organisation, a distinct crime from disguising the proceeds of one.

The scale was small relative to the penalty. Nearly USD 6 million in payments protected roughly USD 70.3 million of revenue, and the Eastern District of New York recorded total financial penalties of USD 777.78 million, comprising USD 687 million in forfeiture and USD 90.78 million in criminal fines.

Two operational points follow for non-financial groups. Sanctions and terrorist-list screening has to cover suppliers, intermediaries, local fixers and security providers, not only customers. And a subsidiary operating in a conflict zone needs group-level payment approval, because local management will otherwise price the payments as an operating cost.

What did the FCA find wrong at Santander UK?

Verification, not identification. Santander collected what business banking customers said their expected activity would be and then never checked reality against it. The FCA final notice of 9 December 2022 imposed a GBP 107,793,300 fine for failures between 31 December 2012 and 18 October 2017 affecting more than 560,000 business banking customers.

One example in the notice does the explaining. A purported translations business opened an account declaring GBP 5,000 in expected monthly deposits, and received millions within six months. The AML team recommended closure in March 2014, yet the account stayed open until September 2015 and kept receiving and transferring millions of pounds throughout.

More than GBP 298 million passed through accounts before they were closed. The defect was not detection but escalation: alerts were raised, a closure decision was made, and no process existed to enforce it. Our note on where most AML programmes fail covers this pattern in more detail.

What did USAA's penalty say about scaling a compliance function?

That growth without compliance investment is itself a finding. FinCEN assessed USD 140 million on 17 March 2022 for wilful Bank Secrecy Act violations between January 2016 and April 2021. USAA admitted it failed to maintain an AML programme meeting the statutory minimum, and failed to report thousands of suspicious transactions accurately or on time.

The aggravating factor was notice. Federal regulators had already identified the deficiencies and given USAA the opportunity to remediate, and the bank repeatedly failed to do so. Regulators treat an unremediated prior finding as a separate, worse fact than the original gap.

The structure of the penalty is worth noting for anyone modelling exposure. FinCEN's own penalty was USD 80 million, and it credited the USD 60 million civil penalty the Office of the Comptroller of the Currency had assessed for the same underlying conduct, so USAA paid USD 140 million in total to the US Treasury rather than USD 200 million.

Why did Bittrex pay both FinCEN and OFAC?

Because one data failure breached two regimes. Bittrex collected internet protocol and physical address information at onboarding and then did not screen it against sanctioned jurisdictions. OFAC's settlement records over USD 263 million in virtual currency transactions by users apparently located in Cuba, Iran, Sudan, Syria and the Crimea region of Ukraine.

The AML side was worse. FinCEN found that between February 2014 and December 2018 Bittrex relied on as few as two staff with minimal AML training to review manually all transactions for suspicious activity, at times more than 20,000 a day, and filed no suspicious activity reports at all between February 2014 and May 2017.

The settlement mechanics matter. FinCEN assessed USD 29,280,829.20 and credited the USD 24,280,829.20 OFAC payment against it, so the combined cash cost was the larger figure alone. For exchanges, this remains the clearest statement that sanctions and PEP screening must run on onboarding data, not just on names. See also our crypto sector page.

How does 2022 compare with enforcement since?

Every 2022 ceiling has been passed. TD Bank's guilty plea on 10 October 2024 produced roughly USD 3.09 billion across four US authorities and made it the first US bank to plead guilty to conspiracy to commit money laundering. In the UK, the FCA has kept fining at a steady cadence rather than escalating amounts.

FirmDateFineConduct period cited
NatWestDecember 2021GBP 264,772,619.95Criminal conviction under the 2007 Regulations
Gatehouse Bank14 October 2022GBP 1,584,100Financial crime systems and controls
Santander UK9 December 2022GBP 107,793,30031 December 2012 to 18 October 2017
Guaranty Trust Bank UK10 January 2023GBP 7,671,800Repeat AML control weaknesses
Monzo8 July 2025GBP 21,091,300October 2018 to August 2020
Nationwide12 December 2025GBP 44 millionAnti-financial-crime systems and controls

Australia moved in the same direction against gaming operators. The Federal Court ordered Crown Melbourne and Crown Perth to pay AUD 450 million on 11 July 2023, and SkyCity Adelaide AUD 67 million on 7 June 2024, following the AUD 1.3 billion ordered against Westpac on 21 October 2020. Our betting and gaming page sets out those obligations.

Which control failures recur across all of these cases?

Four defects appear in nearly every file. The first is monitoring that does not cover the whole book, whether because a branch sits outside group systems, as at Danske, or because manual review cannot keep pace with volume, as at Bittrex.

The second is stated activity never tested against actual activity. Santander held the expected-turnover figure and the real deposit data in the same organisation and never compared them. The third is escalation without enforcement, where a closure or filing decision is taken and then not carried out.

The fourth is repeat findings. USAA had been told, Guaranty Trust Bank UK was fined a second time, and in both cases the earlier warning increased the penalty rather than mitigating it. A live AML risk assessment that is actually recalculated is the control that catches all four, because each defect shows up first as a mismatch between rated risk and observed behaviour.

What should a compliance team do with these figures?

Use them as test cases, not as headlines. Take each failure above and ask whether your own controls would surface it. Could you produce, today, a list of customers whose transaction volumes exceed their declared expectations by an order of magnitude? Santander could not, for five years.

Then check enforcement. Every case here involved a decision that was made and not executed, so run a report on alerts closed without documented rationale and on account-closure decisions still open past their due date. That report is usually more damning than any screening gap, and it is entirely within your own data.

Finally, look at coverage boundaries. Subsidiaries, branches, acquired portfolios and non-customer counterparties are where monitoring stops, and all four appear in these penalties. Continuous rescreening of the customer record, which is how MemberCheck is designed to work, closes the gap between a scheduled review and a change in risk. Definitions sit in the glossary of AML terms; for the following year see top AML/CTF penalties in 2023, the US regime explained, and our jurisdictions and regulation collection.

FAQ

Common questions.

What was the largest AML-related penalty of 2022?
Danske Bank's resolution over its Estonian branch. The bank agreed to criminal forfeiture of USD 2.059 billion in its guilty plea to conspiracy to commit bank fraud on 13 December 2022, paid USD 413 million to settle SEC charges, and the following day received a DKK 3.5 billion fine plus DKK 1.249 billion confiscation from the Copenhagen City Court.
Why was Lafarge SA prosecuted, and how much did it pay?
Lafarge SA and its Syrian subsidiary pleaded guilty in October 2022 to conspiring to provide material support to ISIS and the al-Nusrah Front, paying nearly USD 6 million to those groups so a Syrian cement plant could keep operating. Financial penalties totalled USD 777.78 million, comprising USD 687 million in forfeiture and USD 90.78 million in criminal fines. It was the first corporate material-support-for-terrorism prosecution in the United States.
How much was USAA Federal Savings Bank fined and why?
FinCEN assessed a USD 140 million civil money penalty on 17 March 2022 for wilful Bank Secrecy Act violations between January 2016 and April 2021. USAA admitted it failed to maintain an adequate AML programme and failed to report thousands of suspicious transactions accurately or on time. Of the total, USD 80 million was FinCEN's penalty and USD 60 million reflected a credited OCC penalty.
What did the FCA fine Santander UK for in 2022?
On 9 December 2022 the FCA fined Santander UK GBP 107,793,300 for AML failures affecting more than 560,000 business banking customers between 31 December 2012 and 18 October 2017. The bank did not verify what customers said their business activity would be, and over GBP 298 million passed through accounts before they were closed.
Has any AML penalty since 2022 exceeded the Danske Bank resolution?
Yes. TD Bank's resolution of approximately USD 3.09 billion on 10 October 2024 across the Department of Justice, FinCEN, the OCC and the Federal Reserve is the largest Bank Secrecy Act penalty imposed to date, and TD Bank was the first US bank to plead guilty to conspiracy to commit money laundering.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.