Wise Was Denied a Bank Charter. Will DNB License Qivalis?
On 21 July 2026, the US Office of the Comptroller of the Currency has rejected Wise’s application to establish a national trust bank recently. The decision should attract attention far beyond the United States.
The OCC did not treat Wise’s existing anti-money-laundering deficiencies as historical baggage that could be separated from a new licence application. It examined whether the proposed bank would depend on control systems that had already proved inadequate, and concluded that Wise had not demonstrated that the new institution would operate with an effective AML/CFT framework.
Meanwhile, Qivalis is seeking authorisation from De Nederlandsche Bank as an electronic money institution. The company plans to launch a euro-denominated stablecoin in the second half of 2026, subject to regulatory approval. Qivalis now comprises 37 European banks and markets that institutional backing as a source of trust. Yet several of its member banks have some of Europe’s most serious documented histories of AML, sanctions and financial-crime control failures.
Wise and Qivalis are not legally identical. The OCC decision does not dictate DNB’s answer. But it establishes a principle that DNB should not ignore:
A new licence should depend on evidence that known control failures have been effectively remedied—not on the creation of a new entity, product or brand.
Why the OCC rejected Wise
According to OCC the proposed institution would have offered multi-currency accounts, payment processing and fiduciary services, while relying substantially on Wise US and other group entities for AML/CFT compliance.
The decision followed a 2025 enforcement action concerning deficiencies in Wise US’s AML/CFT programme. The OCC identified deficiencies in suspicious-activity investigations, transaction-monitoring data, timely filing of suspicious-activity reports, independent review and remediation of previously identified weaknesses.
Crucially, the OCC did not merely point to the existence of an enforcement action. It examined the proposed bank’s dependence on the wider Wise control environment. The authority stated that it could not conclude that Wise National Trust would have an effective AML/CFT programme until Wise addressed the existing deficiencies and developed an enhanced enterprise-wide framework.
The OCC also found that the proposed organisers, management and board had not demonstrated sufficient competence in the relevant AML/CFT and banking requirements. The application was rejected because it presented significant supervisory and compliance concerns.
The regulatory message is unusually clear:
Existing compliance failures remain relevant where a new institution will rely on the same people, systems, governance or group infrastructure.
Qivalis is still awaiting authorisation
Qivalis describes its planned stablecoin as secure, fully regulated, fully compliant and “powered by Europe’s leading banks”. Yet its own disclosure confirms that it is not currently authorised and does not issue electronic money or provide payment services to the public. Its EMI application remains pending before DNB.
The consortium includes founding members such as ING, Danske Bank, BNP Paribas, SEB and UniCredit. In May 2026, another 25 institutions joined, including ABN AMRO, Swedbank, Rabobank, Nordea, AIB and Bank of Ireland.
Large-bank participation may provide capital, liquidity, distribution and technical expertise. But it is not evidence that the new system is safe.
Qivalis cannot invoke the institutional prestige of its members as proof of trustworthiness while treating their documented control failures as irrelevant history.
ING: the central test for Qivalis
ING is not merely one of Qivalis’s participating banks. It was among the project’s founders and has played a leading role in developing the planned euro stablecoin. That makes ING’s financial-crime record directly relevant to DNB’s assessment of Qivalis’s pending EMI licence.
EFRI – representing hundreds of Payvision and ING’s victims for years – has documented that record extensively. In September 2018, ING paid EUR 775 million after the Dutch Public Prosecution Service found serious and structural failures in customer due diligence, risk classification, transaction monitoring, suspicious-transaction reporting and the termination of unacceptable customer relationships. The authorities described an under-resourced and fragmented control structure in which commercial interests repeatedly prevailed over compliance. EFRI examined the lack of personal accountability in €775m AML Scandal, Zero Accountability for Hamers and ING’s wider compliance history in ING’s Checkered Money Laundering Track Record.
The decision in early 2018 to acquire a high-risk payment processor with Payvision’s merchant portfolio is difficult to reconcile with ING’s claim that its risk assessment and control culture had already been materially strengthened. Only months later, ING agreed to pay EUR 775 million following findings of serious and structural AML failures.
The Payvision case makes the issue concrete. ING had provided banking infrastructure to Payvision before acquiring control of the payment processor. EFRI’s investigations show how Payvision processed large-scale card payments for the Barak and Lenhoff fraud platforms while accumulating extreme chargeback levels, thousands of fraud reports, regulatory warnings and 273 suspicious-activity reports. These findings are set out in The Payvision Chats: When Payment Infrastructure Becomes Fraud Infrastructure, Summary of Our Findings in the Payvision Case and EFRI’s legal actions against Payvision and ING.
The relevance to Qivalis is not that Payvision and a stablecoin issuer are the same business. The lesson lies in the control architecture. ING was at different times Payvision’s account bank, financing partner, majority shareholder and sole owner. Yet it remains unclear how information from account monitoring, acquisition due diligence, group governance and Payvision’s own fraud and AML controls was connected—and why intervention came so late.
Nor can the Houston settlement simply be dismissed as a historic case that ended ING’s financial-crime problems. More recent proceedings show that AML-related concerns continued to arise across the group.
In March 2025, Spain published a final administrative sanction against ING Bank N.V.’s Spanish branch, based on a Council of Ministers decision adopted in July 2023. ING was fined EUR 3,919,300 and publicly reprimanded for a very serious AML breach: failure to report suspicious activity after indications of possible money laundering or terrorist financing had already been raised internally. The sanction concerned the same legal bank that is a founding participant in Qivalis
ING Luxembourg remains involved in criminal proceedings concerning alleged AML deficiencies in several customer files. According to ING’s own regulatory disclosures, a Luxembourg court decided in November 2024 to refer the case to the Tribunal correctionnel. ING Luxembourg appealed that procedural decision, and no final finding has been made.
In Belgium, ING agreed in May 2026 to pay EUR 1.6 million following a money-laundering investigation connected with former EU Commissioner Didier Reynders. The payment did not constitute an admission of guilt and resulted in the allegations against ING Belgium being dropped. The Brussels prosecutor nevertheless stated that the investigation had confirmed indications of possible complicity by ING Belgium in money laundering.
The Dutch Payvision investigation itself was concluded only in April 2024. Payvision was not prosecuted (as it was anyway closed down), but two former directors received penalty orders for structural breaches of Dutch AML law during a period extending to April 2020, when Payvision was already majority-owned and later wholly owned by ING.
These cases differ in scope and legal status. Spain involved a final administrative sanction; Belgium ended in a settlement without admission of guilt; Luxembourg remains contested; and Payvision concerned former managers of a former subsidiary. They should not be presented as one continuous offence.
Together, however, they undermine the claim that ING’s financial-crime control problems belong exclusively to a distant period preceding the 2018 settlement. The relevant question for Qivalis is not whether ING launched remediation programmes. It is why AML-related sanctions, settlements and criminal proceedings continued to emerge across the group years after ING claimed to have fundamentally strengthened its control environment.
Qivalis will involve an issuer, dozens of banks, distributors, reserve holders, custodians, wallet providers, exchanges and liquidity providers. DNB should therefore require Qivalis to show who consolidates fraud and AML intelligence, who can challenge or restrict a founding member, who has authority to freeze activity and who remains accountable when warning signals are dispersed across institutions.
ING’s history does not automatically disqualify Qivalis. But it removes any basis for regulatory deference. The Payvision experience and the more recent ING cases show that bank ownership, regulatory status and remediation claims do not by themselves ensure effective fraud detection, escalation and timely intervention.
Is ING repeating the Payvision pattern?
The speed and strategic rationale of the Payvision acquisition raise a further question for Qivalis. ING announced the transaction on 29 January 2018 and completed it less than seven weeks later, presenting Payvision as a way to strengthen its position in the fast-growing e-commerce payments market. The subsequent collapse of Payvision showed the danger of allowing strategic urgency to outrun effective financial-crime due diligence. Is ING now repeating the same pattern? by moving rapidly into a strategically important new payment market before the underlying fraud, governance and control risks have been fully tested? If so, the consequences will not be confined to another failed acquisition. A pan-European stablecoin could expose tens of thousands of consumers to a payment infrastructure whose weaknesses become visible only after the losses have occurred.
The problem extends beyond ING
ING is not the only Qivalis member with a substantial AML record.
ABN AMRO paid EUR 480 million in 2021 after Dutch prosecutors found years of serious and structural AML failures, including deficient customer reviews, incorrect risk classification, inadequate transaction monitoring and failures to end unacceptable relationships.
Swedbank was fined SEK 4 billion in 2020 for serious deficiencies in its anti-money-laundering controls and its governance of Baltic subsidiaries. Sweden’s financial regulator found that the bank had not acted adequately despite repeated internal and external warnings.
SEB was fined SEK 1 billion for deficiencies in identifying and managing money-laundering risks in its Baltic operations and weaknesses in group governance and control.
Danske Bank’s Estonian operation became one of the largest European money-laundering scandals. BNP Paribas and UniCredit have also faced major sanctions-enforcement cases. These histories differ legally and should not be collapsed into one category. But together they destroy the simplistic proposition that a consortium of major regulated banks is inherently a low-risk structure.
Thirty-seven banks do not create thirty-seven layers of protection
A consortium may spread expertise. It may also spread responsibility until no institution owns the complete failure.
Different Qivalis members will bring different risk appetites, monitoring systems, customer standards and escalation thresholds. A transfer may begin in one bank, pass through a Qivalis wallet, move to an external address and reach an exchange or liquidity provider elsewhere.
One institution may know the customer. Another may see the wallet. A third may receive the victim report. Qivalis may see issuance and redemption but not the deception that caused the transfer.
Unless those signals are connected, the new system may reproduce the central weakness already visible in conventional payment fraud:
Every participant sees its own transaction, while nobody takes responsibility for the complete fraud chain.
The speed and programmability of stablecoins make this risk more serious. Faster settlement means less time to detect, freeze or recover funds.
What DNB should require
DNB should not reject Qivalis merely because some member banks have troubled histories. That would be guilt by association rather than supervision.
But neither should DNB treat the continued licensing of those banks as proof that the relevant lessons have been learned.
Qivalis should have to demonstrate an independent compliance and risk function capable of challenging a founding bank, shareholder or major distributor. It should show how fraud and AML information will be shared across institutions, who can restrict a member or distribution channel, who decides whether an address or transfer should be frozen and who remains accountable when commercial interests conflict with compliance.
The Wise decision is important because the OCC refused to accept prospective assurances while the wider control environment remained deficient. DNB should apply the same substantive principle: the new institution must prove that its governance and systems are adequate for the risks inherent in the payment infrastructure it proposes to operate.
A governance chart is not proof. A policy document is not proof. The institutional prestige of the consortium is not proof.
The relevant proof lies in how the infrastructure works when the first serious warning arrives.
Bank Reputation Is Not a Fraud Control
Qivalis may offer genuine benefits, including stronger euro-denominated settlement infrastructure and reduced dependence on dollar-based stablecoins. Those potential benefits justify rigorous scrutiny, not regulatory deference.
The OCC’s Wise decision shows that a regulator can refuse market access when unresolved deficiencies, group dependence and inadequate governance undermine confidence in a proposed institution. Qivalis is a different applicant under a different legal regime, but the underlying question is the same: has it demonstrated that the control failures documented across several of its sponsoring banks cannot simply reappear inside a faster, more complex and more fragmented payment infrastructure?
Qivalis cannot rely on the institutional reputation of its 37 banks as evidence of safety while treating their AML and financial-crime histories as irrelevant. Bank ownership is not a fraud control. Regulatory status is not a fraud control. Reputation is not a fraud control.
Until Qivalis demonstrates how risks will be identified across institutional boundaries, how intervention will occur before assets disappear and who remains accountable when something goes wrong, “powered by Europe’s leading banks” remains a marketing claim, not evidence of safety.




