The AML Fine Leaderboard • 2025

The biggest AML penalties of 2025, and what they had in common

In 2025, regulators handed down some of the largest anti-money-laundering penalties on record. Different institutions, different regulators, different countries. The failures behind almost every one were the same.

$504M largest single penalty on the board (OKX, US DOJ)
7 headline enforcement actions featured here
4 regulators behind them: DOJ, FCA, SEC, CBI
100% rooted in KYC, monitoring, or screening gaps
The Leaderboard

2025's costliest compliance failures

Ranked by penalty size. Each one traces back to a gap that screening and monitoring were supposed to close.

🥇
OKX

Staff helped users bypass identity verification. More than $5B in suspicious transactions went unmonitored.

$504M
US DOJ • Feb 2025
🥈
KuCoin

Pleaded guilty to Bank Secrecy Act violations. Operated without an effective AML program.

$300M
US DOJ • Jan 2025
🥉
Nationwide

Years of transaction monitoring and customer due diligence failures.

£44M
FCA • Dec 2025
4
Barclays

High-risk clients left unmonitored. Around £46.8M in criminal funds passed through undetected.

£42M
FCA • Jul 2025
5
Robinhood

Weak AML oversight and gaps in suspicious transaction reporting.

$45M
SEC • Mar 2025
6
Monzo

Onboarded more than 34,000 high-risk customers with weak ongoing monitoring.

£21M
FCA • Jul 2025
7
Coinbase EU

More than 30 million transactions worth around €176B were left unscreened.

€21.5M
Central Bank of Ireland • 2025

Figures reflect publicly announced regulatory penalties from 2025 and represent headline amounts reported at the time of each action. Sources: US Department of Justice, UK Financial Conduct Authority, US Securities and Exchange Commission, and the Central Bank of Ireland. This page is for general information and is not legal advice.

The Common Thread

Different cases. Same three failures.

Strip away the logos and the regulators, and nearly every penalty above comes back to one of these.

Weak KYC

Customers were onboarded without proper identity verification, or checks stopped after sign-up. The institution never really knew who it was dealing with.

Poor transaction monitoring

Suspicious activity moved through accounts without flags. The volume was there to catch, but the monitoring wasn't built to see it.

Gaps in ongoing screening

Risk status was checked once and never revisited. A customer who became a PEP or a sanctioned entity slipped through unnoticed.

The cost of non-compliance keeps climbing. The cost of getting it right doesn't have to.

Every case on this board points back to the same gaps Sentinel ™ was built to close: continuous identity verification, real-time monitoring, and screening that never stops after onboarding, all with a complete audit trail to prove it at examination.

2,100+ sanctions and watchlist sources Continuous monitoring, not one-time checks Full audit trail for every decision 0.3% false positive rate

Make sure your institution never lands on next year's board.

A short walkthrough of Sentinel ™ will show you where the gaps behind these penalties could exist in your own program, and how to close them.