AMLA’s Deterrence Gap: Weak Fines, Weak Impact

AMLA activity over effectiveness

AMLA’s Deterrence Gap: Weak Fines, Weak Impact

AMLA is presented as Europe’s answer to fragmented and ineffective anti-money laundering supervision. A Union-level AML supervisor is necessary. But a supervisor’s effectiveness does not depend only on its mandate. It depends on consequences.

Recent criticism of the EU’s AML reform increasingly questions whether the new framework will meaningfully disrupt illicit finance or merely improve the formal architecture of supervision. That concern is justified. Europe does not only need harmonised AML rules. It needs an enforcement model that changes incentives for banks, PSPs, EMIs, acquirers, crypto ramps and other financial-crime gatekeepers.

This is one of AMLA’s central weaknesses.

AMLA can impose sanctions on selected obliged entities. But key deterrence tools remain fragmented or incomplete: licence withdrawal remains with licensing authorities; publication of sanctions is not a proactive public warning system; victims do not receive automatic compensation; and senior managers can often avoid meaningful personal consequences.

If AMLA is to work, AML failure must become economically irrational for institutions and personally consequential for decision-makers. Otherwise, fines remain a cost of doing business.

Headline penalties do not prove deterrence

AML fines are often presented as “record penalties”. That language can mislead.

A sanction should not be assessed only by its nominal amount. It should be assessed against revenues, profits, avoided compliance costs, enabled transaction flows, repeat conduct and victim harm.

Recent U.S. cases show the arithmetic problem.

TD Bank agreed in 2024 to pay approximately USD 3.09 billion in AML-related penalties. But TD’s adjusted total revenue for 2024 was approximately USD 41.7 billion. The penalty therefore represented roughly 7.4% of one year’s adjusted group revenue. Significant, but absorbable at group level.

Capital One’s 2021 FinCEN penalty was USD 390 million. Capital One reported total net revenue of USD 28.5 billion for 2020. The penalty represented approximately 1.4% of one year’s net revenue.

USAA Federal Savings Bank paid USD 140 million in combined FinCEN and OCC penalties in 2022. USAA reported revenue of USD 36 billion for 2022. The penalty represented approximately 0.4% of one year’s revenue.

UBS Financial Services was fined USD 125 million in 2026 for Bank Secrecy Act and AML violations. FinCEN described it as the largest BSA penalty ever imposed on a broker-dealer. Yet UBS Group reported total revenues of approximately USD 49.6 billion for 2025. The penalty represented roughly 0.25% of one year’s group revenues.

That ratio matters. Banks are not ordinary market participants. They are licensed gatekeepers to the financial system. Their public function is not only to process transactions and generate fees. It is to prevent the financial system from being used for fraud proceeds, laundering, sanctions evasion and other illicit flows.

The personal-accountability gap is equally striking. These U.S. cases produced large institutional penalties, consent orders, remediation programmes and governance language. But they did not produce a visible deterrence model in which senior bank executives or board members personally paid a proportionate price for the underlying AML failures. TD’s Chief Compliance Officer left amid the AML investigation, and TD later announced CEO transition and board renewal. But that is not the same as a sanctions architecture in which the individuals responsible for a bank’s AML control environment face personal fines, regulatory bans or criminal consequences when the institution becomes a gateway for illicit finance. The enforcement target remains overwhelmingly corporate.

Europe was already warned: ING and Payvision

ING is the clearest European example.

In September 2018, ING Bank N.V. accepted a EUR 775 million settlement with the Dutch Public Prosecution Service for serious and structural AML failures over many years. At the time, it was one of the most significant AML settlements in Europe.

Yet earlier that same year, ING had already acquired control over Payvision.

In January 2018, ING announced the acquisition of a 75% stake in Payvision at a total company valuation of EUR 360 million. According to ING, the transaction was completed in the first quarter of 2018. ING described Payvision as a fast-growing international omnichannel payment service provider and presented the acquisition as a strategic move into merchant services and e-commerce payments.

That chronology is difficult to ignore.

A bank that would, only months later, accept one of Europe’s largest AML settlements had already acquired control over a high-growth payment processor. Payvision was later linked to serious AML concerns and fraud-related merchant acquiring. ING subsequently reported that Payvision was phased out, that its activities and customer transfers were completed, and that Payvision’s licence was withdrawn at Payvision’s request.

The governance point is equally important.

Both events occurred while Ralph Hamers was CEO of ING: the Payvision acquisition and the EUR 775 million AML settlement. Steven van Rijswijk, ING’s current CEO, was also not an outsider to the control environment. He was ING’s Chief Risk Officer and a member of the Executive Board during the relevant period.

In a functioning deterrence model, serious and structural AML failures should trigger hard questions about the senior executives responsible for the institution’s risk and control environment. Instead, Ralph Hamers left ING in 2020 to become Group CEO of UBS, one of the world’s largest banking groups. Steven van Rijswijk moved from Chief Risk Officer to CEO of ING.  The same concern appears in payment and stablecoin markets: Gijs op de Weegh, a former Payvision founder and manager who signed merchant contracts with Gal Barak-linked entities, is now operating StablR, a licensed stablecoin issuer in Malta.

The missing management-accountability effect in European AML enforcement is evident.

If one of Europe’s largest AML penalties did not prevent the same banking group from acquiring and later exiting a problematic payment subsidiary, Europe should ask whether AML penalties deter misconduct or merely price it. AMLA will not change incentives if enforcement remains primarily corporate while senior decision-makers remain professionally untouched.

Deutsche Bank and the repeat-failure issue

Deutsche Bank illustrates the repeat-failure problem more starkly than a single AML case could.

The issue is not one isolated penalty. It is the accumulated enforcement record of a global financial institution that has repeatedly told markets, regulators and the public that it was strengthening controls, compliance and anti-financial-crime governance.

According to Violation Tracker Global, Deutsche Bank has been linked to 121 penalty records worldwide since 2010, with total penalties of approximately USD 16.67 billion. Of these, 84 records fall into the category of financial offenses, with penalties of approximately USD 12.19 billion. Violation Tracker’s U.S. database separately records 102 penalty records for Deutsche Bank-related entities since 2000, with total penalties exceeding USD 20 billion.

Even if one isolates narrower AML and sanctions-related cases, the pattern remains serious.

In 2015, Deutsche Bank agreed to pay USD 258 million to U.S. authorities for sanctions violations involving transactions connected to countries and entities subject to U.S. sanctions. In 2017, it paid USD 425 million to the New York Department of Financial Services and GBP 163 million to the UK Financial Conduct Authority in the Russian mirror-trading case, where around USD 10 billion of unknown origin was moved out of Russia. In 2017, the U.S. Federal Reserve imposed a further USD 41 million penalty for AML deficiencies. In 2020, the New York Department of Financial Services imposed USD 150 million in connection with Deutsche Bank’s relationship with Jeffrey Epstein and correspondent banking relationships with Danske Bank Estonia and FBME Bank. In 2023, the Federal Reserve imposed another USD 186 million penalty for insufficient progress in addressing AML and sanctions compliance deficiencies previously identified in 2015 and 2017. In 2025, BaFin imposed EUR 23.05 million in administrative fines for further regulatory breaches. In 2026, Deutsche Bank’s London branch was fined GBP 165,000 for a breach of the UK Russia sanctions regime.

The precise legal categories differ: AML deficiencies, sanctions violations, correspondent banking failures, high-risk client monitoring failures, market-conduct issues and internal-control breaches. But that is exactly the point. Deutsche Bank’s record is not a single failure in one business line. It is a repeated pattern of control failures across jurisdictions, products and time periods.

Deutsche Bank is not evidence that fines are never imposed. It is evidence that repeated fines do not necessarily change institutional behaviour.

AMLA Has Teeth — But Not Enough Bite

The new EU AML framework gives AMLA important enforcement powers, but those powers remain structurally incomplete.

Under Article 21 AMLAR, AMLA may impose administrative measures on selected obliged entities. Under Article 22 AMLAR, AMLA may impose pecuniary sanctions where a selected obliged entity intentionally or negligently breaches directly applicable AML/CFT requirements under Regulation (EU) 2023/1113, Regulation (EU) 2024/1624 or binding AMLA decisions. Under Article 23 AMLAR, AMLA may impose periodic penalty payments to enforce compliance with certain measures or obligations. Article 25 AMLAR provides for publication of administrative measures, pecuniary sanctions and periodic penalty payments.

That sounds substantial. But the limits are decisive.

First, AMLA does not have direct licence-withdrawal power. Under Article 21(2)(g) AMLAR, where authorisation should be suspended or withdrawn, AMLA may only propose such action to the competent licensing authority. If that authority declines, it must give reasons. This is escalation power, not direct licence control.

Second  AMLA does have some direct reach over individuals, but not the reach that would actually change behaviour. Article 21 AMLAR already allows AMLA to name a responsible natural person in a public statement (Article 21(2)(c)), to order that person to cease and desist (Article 21(2)(d)), to require changes in the governance structure (Article 21(2)(f)), and most significantly  to temporarily ban any person exercising managerial responsibilities, or any other natural person held responsible for the breach, from exercising managerial functions in obliged entities (Article 21(3)(e)).

So the claim is not that AMLA cannot touch managers at all. The claim is that its personal toolkit is shallow where it matters most:

  • AMLA has no power to impose personal pecuniary sanctions on individuals. The fines under Article 22 AMLAR target the entity, not the board member, CEO, CRO or senior manager who owned the failed control environment. AML failure can bankrupt a compliance budget; it does not empty a director’s own pocket.
  • The Article 21(3)(e) ban is temporary, not a permanent fit-and-proper disqualification. A responsible executive can be sidelined for a period not durably barred from the regulated financial sector across the Union.
  • AMLA has no criminal competence. Where conduct reaches the criminal threshold, AMLA can only refer; it cannot prosecute.
  • All of this operates only within selected obliged entities, a small subset of the financial sector — and only in respect of the directly applicable Union rulebook, not national law transposing the AML Directive.

Third, Article 25 AMLAR provides for publication after enforcement decisions. That is not the same as a proactive public warning system for high-risk PSPs, EMIs, acquirers, banks or crypto-related gatekeepers repeatedly linked to fraud flows.

These limits matter. AMLA can fine the institution, name a manager, and suspend him from management for a time, but it cannot make the failure personally expensive, cannot end a career in finance for good, cannot prosecute, and cannot withdraw the licence itself. Unless these gaps are closed in practice, Europe risks reproducing the old enforcement pattern: the entity pays, management is reshuffled rather than held to account, the licence remains, and the market moves on.

AMLA’s effectiveness will depend on whether it can push Europe beyond settlement pricing

A credible AMLA-era deterrence model is not only about new powers. It is about using the powers AMLA already has and closing the gaps it does not. Five elements are decisive.

First, fines must be calibrated to the affected business and the economic benefit of weak controls, not only to abstract seriousness. For PSPs, EMIs and acquirers, the relevant metrics should include transaction volume, merchant fees, chargebacks, fraud-linked flows and avoided compliance costs. A penalty that is smaller than the profit generated by the failure is not a deterrent; it is a licence fee.

Second, repeat failures must trigger escalation. A second or third AML failure should not be priced like an isolated event. Recidivism must move an institution up the sanctions scale — towards the upper turnover-based thresholds, business restrictions and licence escalation — not back to the settlement table at first-offence levels.

Third, personal accountability must become real — by using the powers that already exist and adding the ones that do not. Article 21 AMLAR already allows AMLA to name responsible individuals, order them to cease, require governance changes and temporarily ban them from managerial functions in obliged entities. These powers must actually be used, not left dormant on the page. But two gaps must be closed at Union level. First, AMLA cannot impose personal pecuniary sanctions: Article 22 reaches the entity, not the CEO, CRO or board member who owned the failed control environment. Second, the Article 21 ban is only temporary — it is not a durable fit-and-proper disqualification from the regulated sector. A credible model needs personal fines, lasting professional bans and, where the conduct meets the criminal threshold, referral for prosecution. AMLA itself has no criminal competence; the referral pathway must therefore work.

Fourth, AMLA’s licence-escalation powers must become visible. Under Article 21(2)(g) AMLAR, AMLA can only propose suspension or withdrawal of authorisation to the competent licensing authority. If AMLA makes that proposal and the authority refuses, the disagreement should not disappear into confidential supervisory correspondence. Where a business model depends on suspicious flows, the public interest requires that the refusal — and its reasons — be transparent.

Fifth, enforcement must connect to victim redress. Pecuniary sanctions under AMLAR flow to the public purse, not to the people whose funds moved through the gatekeeper. Deterrence that never reaches victims is incomplete. A credible model must link AML enforcement to actual restitution — through the EU asset-recovery and confiscation regime and by leaving room for collective private action under the Representative Actions Directive (EU) 2020/1828 and national civil law — rather than treating a fine paid to the state as the end of the matter. Public enforcement and private redress are not alternatives; a system that delivers only the first leaves victims to absorb the loss.

Conclusion: AMLA must choose effectiveness over activity

Money laundering is too often treated as a technical compliance failure. It is not.

Money laundering is not a victimless crime. It is the infrastructure that allows drug trafficking, corruption, sanctions evasion, organised crime, cyber fraud, online investment scams and other predicate offences to become profitable. Without financial gatekeepers willing or unable to stop suspicious flows, criminal proceeds do not simply disappear. They enter the regulated financial system, gain legitimacy and become usable.

This is why AMLA must not be assessed by activity alone.

For years, Europe has responded to financial-crime scandals with more rules, more reports, more policies, more risk assessments, more committees and more supervisory coordination. Regulation followed regulation. Guidance followed guidance. Institutions wrote stronger AML language into annual reports. Supervisors announced remediation plans. Yet the same question was rarely asked with sufficient seriousness:

Will any of this reduce money laundering in practice?

That is the effectiveness test AMLA must now face.

AMLA should not measure success by the number of supervisory reviews completed, reports issued, policies assessed or fines announced. Those are activity metrics. They do not prove disruption.

The relevant questions are harder.

Will AMLA reduce the ability of fraud networks to access EU payment infrastructure? Will it identify high-risk PSPs, EMIs, acquirers and banks before victim funds move? Will it make senior managers personally and professionally afraid of serious AML failures? Will it force licensing authorities to act where business models depend on suspicious flows? Will it make financial-crime enablement economically irrational?

If the answer is no, AMLA risks becoming another layer of regulatory activity without sufficient enforcement effect.

Europe does not need AML activism. It needs AML effectiveness.

And effectiveness means consequences: for institutions, for licences and for the individuals who control financial-crime gatekeepers.

More about this topic.