The largest AML/CTF penalty of 2023 was Binance's global resolution of more than USD 4.3 billion, announced on 21 November 2023. AUSTRAC's A$450 million order against Crown was the largest casino penalty of the year, and UK regulators penalised banks, brokers and betting operators for the same recurring control failures.
Key takeaways
- Binance's resolution split into a USD 3.4 billion FinCEN penalty and a USD 968 million OFAC settlement, plus USD 2.85 billion across the CFTC action, and a further USD 150 million suspended against the monitorship.
- Crown Melbourne and Crown Perth were ordered to pay A$450 million on 11 July 2023, payable over two years, after admitting their AML/CTF programmes were not based on appropriate risk assessments.
- Every FCA money laundering fine of 2023 turned on risk assessment and ongoing monitoring, not on missing identity documents.
- Settling early is worth roughly a third of the penalty: the FCA's 30% discount saved Guaranty Trust Bank (UK) GBP 3,287,900 on a single case.
- The 2023 records did not hold. FinCEN assessed USD 1.3 billion against TD Bank in October 2024, its largest ever against a depository institution.
What made up Binance's USD 4.3 billion resolution?
The headline figure was not a single fine. It was a simultaneous global settlement across four US authorities, and the components matter because each attaches to a different obligation. The US Treasury announced on 21 November 2023 that FinCEN assessed a USD 3.4 billion civil money penalty and OFAC a USD 968 million settlement, with a five-year monitorship and a requirement that Binance exit the United States entirely.
A further USD 150 million FinCEN penalty was suspended, collectable if Binance fails to meet its compliance undertakings. The CFTC's parallel consent order required Binance to disgorge USD 1.35 billion and pay a USD 1.35 billion civil monetary penalty, with Changpeng Zhao personally liable for a USD 150 million CFTC civil monetary penalty. Zhao and Binance pleaded guilty to federal charges on the same day.
The conduct finding is the part worth reading twice. Treasury recorded that Binance processed transactions linked to terrorist financing, ransomware and narcotics across more than 100,000 transactions and never filed a single suspicious activity report, while permitting over 1.5 million trades that breached US sanctions.
Why did AUSTRAC's Crown penalty matter beyond its size?
Because Crown admitted the findings, and the admissions read as a checklist of programme design failure rather than isolated errors. AUSTRAC and Crown jointly proposed A$450 million on 30 May 2023, and on 11 July 2023 the Federal Court of Australia ordered Crown Melbourne and Crown Perth to pay it in instalments over two years, plus AUSTRAC's costs.
Crown admitted its AML/CTF programmes were not based on appropriate risk assessments, lacked systems and controls proportionate to its risks, and were not subject to appropriate board and senior management oversight. AUSTRAC recorded that Crown continued a relationship with a major junket operator until 2021 despite awareness of organised crime allegations, and failed to monitor billions of dollars in transactions including international payment flows.
One example gives the scale in concrete terms. Between March 2016 and December 2018 there were at least 75 suspicious incidents involving roughly A$23 million in cash in a single private gaming room to which Crown Melbourne had given one junket operator exclusive access. Our Australia country coverage page sets out the underlying obligations.
Which 2023 penalties should be on a comparison sheet?
Seven actions account for most of the year's significance across three regulators and three sectors. Amounts are shown in the currency in which they were imposed, which is a detail secondary reporting routinely loses.
| Case | Date | Authority | Amount | Failure cited |
|---|---|---|---|---|
| Binance Holdings | 21 November 2023 | FinCEN and OFAC | USD 3.4bn and USD 968m | No suspicious activity reports filed; sanctions monitoring deliberately undermined |
| Crown Melbourne and Crown Perth | 11 July 2023 | AUSTRAC, Federal Court order | A$450m over two years | Programmes not based on appropriate risk assessments; billions in transactions unmonitored |
| Deutsche Bank AG | 19 July 2023 | Federal Reserve Board | USD 186m | Insufficient remedial progress under 2015 and 2017 consent orders |
| William Hill group licensees | 28 March 2023 | UK Gambling Commission | GBP 19.2m settlement | Social responsibility and AML failures across three licensed businesses |
| Guaranty Trust Bank (UK) Limited | 10 January 2023 | FCA | GBP 7,671,800 | Customer risk assessments often not performed or documented; repeat findings |
| ADM Investor Services International | 2 October 2023 | FCA | GBP 6,470,600 | No firm-wide money laundering risk assessment; little evidence of periodic reviews |
| Al Rayan Bank PLC | 11 January 2023 | FCA | GBP 4,023,600 | Source of wealth and source of funds not checked on large deposits |
Two patterns fall out of the table. Sector is a poor predictor of exposure, and the cited failures are almost interchangeable between a global exchange, an Australian casino and a small UK bank.
What did regulators actually cite in the FCA cases?
Not identity verification. In all three 2023 FCA money laundering cases the finding sat upstream, in risk assessment, or downstream, in monitoring. The FCA fined Guaranty Trust Bank (UK) Limited GBP 7,671,800 for weaknesses between October 2014 and July 2019, noting the bank often did not assess or document the money laundering risk posed by its customers and failed to monitor customer transactions and relationships to the required standard.
The aggravating factor there was repetition. The FCA had fined the same bank GBP 525,000 in August 2013 for serious and systemic failings, and the 2023 notice records that internal and external sources, including the FCA, repeatedly flagged the same weaknesses without adequate action.
ADM Investor Services International had no firm-wide money laundering risk assessment at all, a customer risk assessment the FCA described as basic, and little evidence of periodic customer reviews, despite warnings from 2014 and a follow-up visit in 2016. Al Rayan Bank failed to check source of wealth and source of funds on large deposits between April 2015 and November 2017, compounded by inadequate staff training.
How much does settling early change a UK penalty?
By almost exactly 30%, and the 2023 cases let you see the arithmetic. Firms that do not dispute the FCA's findings and agree to settle qualify for a 30% discount on the penalty the FCA would otherwise impose. Each of the three notices states the undiscounted figure.
| Firm | Penalty imposed | Penalty without settlement discount | Value of the discount |
|---|---|---|---|
| Guaranty Trust Bank (UK) Limited | GBP 7,671,800 | GBP 10,959,700 | GBP 3,287,900 |
| ADM Investor Services International | GBP 6,470,600 | GBP 9,243,738 | GBP 2,773,138 |
| Al Rayan Bank PLC | GBP 4,023,600 | GBP 5,748,000 | GBP 1,724,400 |
ADM Investor Services International is the instructive one. It accepted the FCA's findings but used the partly contested case process to ask the Regulatory Decisions Committee to assess the penalty level, and still kept the discount. Accepting facts and contesting quantum are separable decisions, which is worth knowing before an enforcement notice lands.
How did the UK Gambling Commission treat AML failures in 2023?
Differently from the FCA, and the terminology matters for benchmarking. The GBP 19.2 million that three William Hill group licensees agreed to pay on 28 March 2023 was a regulatory settlement, not a fine, and the full amount was directed to socially responsible purposes. It split as GBP 12.5 million for WHG (International), GBP 3.7 million for Mr Green, and GBP 3 million for the retail business covering 1,344 premises.
The Commission's chief executive said the failings were widespread enough that licence suspension was seriously considered. The AML findings included policies that gave no guidance on what to do with customer profiling results, and an absence of hard stops to halt further spend before risk profiling was complete.
Volume is the point here rather than any single case. The Commission noted it had fined two Kindred Group operators a combined GBP 7.2 million the previous week, and had concluded 26 enforcement cases since the start of 2022 with operators paying over GBP 76 million. See our note on updated casino regulations in the United Kingdom and the betting and gaming sector page.
Have the 2023 records been beaten since?
Yes, on both sides of the table, which is why treating 2023 as a ceiling misreads the trend. In October 2024 FinCEN assessed a record USD 1.3 billion penalty against TD Bank, the largest against a depository institution in its history, with a four-year independent monitorship, inside a wider resolution of roughly USD 3.09 billion.
Australian casino enforcement also continued past Crown. AUSTRAC and SkyCity Adelaide proposed A$67 million on 17 May 2024, and the Federal Court ordered that penalty on 7 June 2024. The same public register shows proceedings against The Star Pty Limited and The Star Entertainment QLD Limited commenced on 30 November 2022, and civil penalty proceedings against Entain Group filed on 16 December 2024.
The direction of travel is toward monitorships and independent oversight alongside the money. A monitorship is a multi-year operating constraint, so the true cost of a 2023-style finding is rarely the number in the press release. Our comparison of 2022 financial crime penalties shows how quickly the baseline moved.
Which of these findings can you test in your own programme?
Each cited failure maps to a query you can run against your own data this quarter, which is the only reason to read enforcement notices at all. Start with the risk assessment, since it was the first finding in the Crown, ADM Investor Services International and Guaranty Trust Bank cases.
Four checks reproduce most of what examiners found in 2023:
- Can you produce a dated, board-approved money laundering risk assessment, and show at least one control whose configuration changed because of it?
- For your highest-risk customers, how many have a documented risk rating and a recorded source of wealth, expressed as a percentage rather than a policy statement?
- What proportion of transaction volume passes through monitoring scenarios, and when was a scenario last added or retuned?
- How many alerts were closed in the last quarter with no recorded rationale, and how many suspicious matter reports resulted?
MemberCheck exists to make the second and third of those answerable continuously rather than at review time, through ongoing PEP and sanctions screening tied to the customer record and transaction monitoring that keeps its scenario history. The upstream artefact still has to be yours: see AML risk assessment, why a structured risk assessment framework matters, and further analysis under jurisdictions and regulation.



