A €314,000 Pass-Through at a DNB-Licensed EMI: The FINOM/Banking Circle/ Triventa Account

FINOM/Banking Circle

FINOM/Banking Circle/Triventa: a €314k pass-through at a DNB-licensed EMI

A fact-based EFRI Case Note built on the FINOM account statement, Companies House filings, Banking Circle’s Article 15 GDPR response, the DNB register and public-register publications, a Sumsub onboarding report, correspondence, a Kifid decision and published Dutch judgments. It makes no finding of criminal or regulatory liability against FINOM Payments B.V., Banking Circle S.A. or any other party. 

Anyone who has traced online-investment-fraud money knows the first rule: the victim never wires a criminal. He wires a clean-looking company account at a licensed European institution, because that is exactly what makes the instruction credible. This case note follows a single deposit of €54,000 (credited on 1 Oct 2025),  from a German victim’s bank, through the business account of a days-old British shell held at FINOM Payments B.V., a Dutch electronic-money institution (EMI) licensed and supervised by De Nederlandsche Bank (DNB), onward to accounts at Banking Circle S.A., a Luxembourg credit institution licensed and supervised by the CSSF and into a virtual IBAN that had been opened months earlier in the victim’s own name, by identity theft, without his knowledge.

FINOM’s own detailed defence is set out in full below, on its own terms. The German criminal investigation was dismissed on 11 March 2026 for want of an identifiable perpetrator every trace ran abroad and has since been reopened as new cross-border evidence came in (sourced by the victim). What remains is a documented money trail and a precise question about where accountability, and recovery, can realistically attach.

Background: a six-week account

On 25 November 2025 a German investment-fraud victim — an EFRI member — filed a criminal complaint. In his account, online scammers posing as seasoned investment managers under the trading name “Bayshore Global Management” won his confidence with the promise of safe, secure returns, and sustained the deception through a simulated trading platform, near-daily contact over WhatsApp, misused company names, and a rotating set of credible-looking foreign company accounts he was directed to fund. He authorised every payment because, at each step, the story held together, he simply could not imagine that he was being lied to at every turn. It is textbook social engineering: patient, total, and built to look exactly like the real thing.

Over nine weeks he — a retiree with a long career in senior management — made ten transfers totalling €163,103, between 15 September and 17 November 2025, to five beneficiary accounts at European institutions in four countries: the Netherlands, Malta, Italy and Greece. The itemised transfer list compiled for the Mainz police (case VN 359009/25112025/1115) sets them out:

Transactions FINOM

The single largest transfer, and the best-documented, is the €54,000 to FINOM. This report follows the money through FINOM and Banking Circle. The €44,100 that reached an OpenPayd virtual IBAN in five instalments is a technically separate rail with its own onward sweep to a Maltese e-money master account, and it is the subject of a forthcoming EFRI analysis; the same POBO virtual-IBAN mechanism recurs there. 

Following the €54,000: FINOM, Triventa, Banking Circle

The facts below come from a chain of “follow-the-money” enquiries, the victim’s own approaches to the institutions and his data-subject access requests (Solaris SE, which confirmed the account was held not by it but by FINOM; then FINOM and Banking Circle), together with the Mainz prosecutor’s investigation, whose file we could check. 

 From those enquiries, the following is established:

  1. Triventa Ltd and its FINOM account. Triventa Ltd was incorporated in England and Wales on 18 August 2025 (Companies House no. 16657754; registered office 60 Ashburnham Road, London NW10 5SE; broad SIC classifications 47910 and 46900) with £1 of nominal capital. Its account at FINOM Payments B.V. (IBAN NL19 FNOM 0755 1664 29) was opened on 29 August 2025,  eleven days after the company existed on paper. (Companies House; FINOM statement.)
  2. The KYC check, and how little it reached. The customer due diligence FINOM ran was a single Sumsub identity screening, “created for Finom,” APPROVED on 27 August 2025, of the individual named as Triventa’s director and ultimate beneficial owner: document quality, security features, fraud-pattern checks, data validation, facial match and liveness. The Sumsub report therefore documents identity verification for that individual. It does not document whether and how FINOM separately assessed ownership and control of the company, its business purpose, expected turnover, expected customer profile, source of funds or anticipated transaction pattern. Those matters may have been addressed in other onboarding records not contained in the material presently available to the victim, law enforcement resp. EFRI.
  3. The pass-through, and who fed it. Between 2 September and 13 October 2025 the account took in 67 credits totalling €314,183.31, overwhelmingly from private individuals with German names and German IBANs (a handful Austrian and Swiss), further victims of the same scheme, and moved the money on to virtual bank accounts offered by Banking Circle almost as fast as it arrived: €313,725, or 99.85% of the inflow, went straight out to two accounts also named Triventa Ltd at Banking Circle (€102,500 to a Danish IBAN, DK31…, BIC SXPYDKKK; €211,225 to a German IBAN, DE11…, BIC SXPYDEHH). The account closed on 20 October 2025 at a zero balance. (FINOM statement, prosecutor’s file.)
  4. Fees to FINOM’s parent. The platform operator and FINOM’s parent company, PNL Fintech B.V., charged the account a monthly “Corporate plan” fee of €149 (on 2 and 29 September 2025). The first of those fees alone consumed nearly three-quarters of the account’s opening €200 of funding. So the shell account was, throughout its short life, a fee-paying customer of the FINOM group. (FINOM statement.)
  5. The victim’s own €54,000. His credit arrived on 2 October 2025; the same day, €63,500 left for the Danish Banking Circle account. Because roughly fifty remitters’ funds were commingled, no euro traces cleanly from his payment to a specific onward wire.
  6. A virtual IBAN opened in the victim’s own name — at Banking Circle. Banking Circle’s Article 15 GDPR response (24 June 2026) showed that the funds reached a POBO (Payment-On-Behalf-Of) virtual IBAN personalised in the victim’s own name, opened on 10 February 2025 , roughly eight months before he was contacted – the personal account for the victim held with Banking Circle closed on 29 April 2026 – then swept onward with crypto conversion suspected. On the ledger it reads as “the victim pays the victim,” though he never knew of, or controlled, the account. (Banking Circle Art. 15 response; supplementary complaint.)
  7. The controlling platform remains undisclosed. Banking Circle stated (20 July 2026) that it holds “no IP address logs, device identifiers, or comparable technical endpoint records relating to underlying customers of its clients.” The platform that generated the virtual IBAN survives in its systems only as a merchant UUID, further information,  it says, will solely provided on a formal law-enforcement request. The victim neither requested nor controlled that virtual IBAN. This raises a separate Article 15 GDPR question: what personal data relating to the victim were supplied to Banking Circle by its client for the creation and operation of that virtual IBAN, and what information Banking Circle holds about the source of those data.

What each institution disclosed — and to whom

 The disclosure pattern is itself telling: each institution gave the victim’s side only what a civil claim strictly needs, and kept the substance for law enforcement and, in Banking Circle’s case, its refusal to disclose the identity of the client behind the virtual IBAN, and the source of the victim’s name-data, is at least legally questionable 

FINOM. To the victim directly (December 2025 – January 2026) it disclosed nothing of substance, citing its status as a regulated EMI and pointing him to his bank and the police. To his lawyer, once the power of attorney and the police report were on file, it confirmed the account holder’s name and registered address, — Triventa Ltd, 60 Ashburnham Road, London — “in order for your client to initiate civil proceedings“; the recall history (a formal recall received on 25 November 2025, the account by then closed and empty); and, on 23 January 2026, its formal legal position (addressed below). It declined to disclose its transaction-monitoring mechanics or thresholds, and said it would give “necessary information” to police or prosecutors through official channels. The two most revealing documents, the Triventa account statement and the Sumsub report  did not come from FINOM at all; they reached the victim through the prosecutor’s file.

Banking Circle. Banking Circle’s subsequent Article 15 GDPR response revealed that one of Banking Circle’s clients had used its infrastructure to create a POBO virtual IBAN personalised in the victim’s own name months before the victim was contacted, without his knowledge or involvement. Banking Circle also stated that it holds no IP, device or endpoint records on the underlying customers of its clients. It withheld the one thing he most needed — the plaintext identity of the partner platform that generated the IBAN — as third-party data, forwarded that request to its Compliance department, and said the identity is resolvable only on a formal law-enforcement request, for which it had secured the data internally.

Read together, the victim could establish, civilly, enough to name Triventa and to prove a virtual IBAN opened in his own name — but not enough to reach the party that actually controlled the money. 

FINOM's legal position: the relativity wall

Payment service providers approached by fraud victims frequently reject claims on the basis that the victim is not their customer and that, consequently, no duty of care is owed to them. FINOM’s letter of 23 January 2026 goes considerably further. Rather than relying solely on the absence of a contractual relationship, FINOM sets out a detailed legal and factual defence addressing the purpose of AML/KYC obligations, the investor’s own responsibility, the adequacy of its onboarding procedures and the timing of its transaction monitoring. It is therefore worth examining closely.

First, KYC does not protect the victim: FINOM invokes Article 6:163 of the Dutch Civil Code: any appeal to breaches of anti-money-laundering law and KYC requirements is barred because those duties exist “to protect the general societal interest in preventing financial crime, and not to protect third parties “as you”.  In plain terms: even if monitoring failed, the argument runs, the AML rulebook was not written to protect this victim, so its breach founds no claim by him. This is the first wall.

Second, the investor’s own duty of care: FINOM cites settled case law that the primary duty in investment activity “lies on the individual investor and cannot be attributed to third-party banks and payment service providers,” and stresses that the victim authorised the payment through his own bank.

Third, KYC adequacy: FINOM states there was “no failure in the verification of the business registration documents or the identification of the legal representative” and that the account “was onboarded in full compliance with Dutch Wwft requirements.”

Fourth,  monitoring and timing: FINOM says it is “legally prohibited from commenting on the specific mechanics or thresholds” of its monitoring, that it acted on the recall promptly, and that the recall (25 November) came almost two months after the 2 October transfer by which time the funds were gone. 

Who is FINOM Payments B.V.

The licensed entity is FINOM Payments B.V., Amsterdam (Jachthavenweg 109-H; Dutch company no. 78680751; LEI 7245008GWLPQCA1S1726; SBI codes 66199 and 74990), a wholly-owned subsidiary of PNL Fintech B.V., which operates the platform and acts as agent. PNL Fintech is not itself licensed: as an *agent* under the Wft/PSD2 it provides services under FINOM’s authorisation and responsibility — yet, as the Triventa statement shows, it is PNL, not the licensed entity FINOM Payments B.V., that levied the account’s monthly subscription fee.

DNB’s public register records FINOM Payments B.V. as a payment institution and electronic-money institution (licence R180074) with effect from 11 November 2021, authorised to issue electronic money and to provide the full range of payment services. It has filed annual accounts since financial year 2022.

The filed accounts document a sharp scale-up. Net turnover rose from €901,591 (2023) to €6,511,980 (2024) — a 622% increase; total assets from €2.02m to €18.97m; cash and cash equivalents from €1.23m to €13.71m. A €16.5m capital contribution lifted the share premium to €21.5m.

The composition of that turnover is the point to record. Of the €6,511,980 net turnover for 2024, €2.90m — some 45% — is booked as revenue from “customer-acceptance procedures, with no further breakdown in the accounts; €1.47m is attributed to payment services and €1.42m to VISA interchange. Interest income reached a further €2.92m, of which €2.74m came from a safeguarding account.  The same accounts already record Banking Circle among FINOM’s operational and fee-account infrastructure, before the Triventa events.

The Triventa statement shows, it is PNL, not FINOM Payments B.V., that levied the account’s monthly subscription fee.

The money above the licence has a Russian profile. FINOM Payments B.V. is owned outright by PNL Fintech B.V.; above it, the DNB publication in the Staatscourant (Stcrt. 2024, 8803), on decisions dated 21 November 2023, approves indirect qualifying holdings in the EMI — in the 10–20% and 10–30% bands — held, among others, by Target Global entities (Target Global Holding Ltd; Target Global Selected Opportunities Ltd; a Series Clearloop 2 vehicle), by the founder of the Russian payments group Qiwi, and by further investors. Target Global  – a venture firm with Russian founding roots – is also a documented investor in Mercuryo, the Russian-linked crypto on/off-ramp EFRI has analysed separately. These are register facts, stated without inference of shared conduct.

What the Dutch court files add

FINOM appears in more than one set of Dutch court proceedings — and in the most recent it is a named defendant, not a bystander. None of these decisions finds that FINOM acted wrongfully; what they show is a payment institution whose accounts recur in fraud fact-patterns and which the courts have begun to treat as a source of evidence victims can compel.

In Amsterdam, 15 July 2026 (ECLI:NL:RBAMS:2026:7338, kort geding, C/13/789513 / KG ZA 26-522), an investment-fraud victim brought summary proceedings against three defendants — an individual account holder, the French payment institution SWAN S.A.S. and FINOM Payments B.V. — and obtained a disclosure order: the court directed FINOM, on pain of a substantial daily penalty for non-compliance, to hand over the complete transaction history of the account concerned for a defined period. The decision turns on FINOM’s role as the account-providing payment institution and its duty to produce records; it makes no assessment of FINOM’s own conduct or duty of care. For EFRI the mechanism is the point — where enforcement stalls, the regulated intermediary is not only the findable node but a compellable one: a victim can force the account trail into the open through the civil courts.

In Rotterdam, 4 March 2026 (ECLI:NL:RBROT:2026:2259), a judgment on the “Altreserve” crypto-investment (boiler-room) fraud recorded that victim funds reached two FINOM accounts — one held by an individual (€9,879.83), one by a recently established sole trader presenting itself as a “billing agent” (€41,393.54) — before being forwarded onward. The victim had initially sued FINOM as well but withdrew that claim, so the court made no finding on FINOM’s conduct; the “billing agent” itself was held liable for 75% of the sum it had received, after a contributory-negligence reduction.

Earlier, in Amsterdam, 23 March 2023 (ECLI:NL:RBAMS:2023:1670, kort geding) — a case against a different bank — the court set out the risk signature of pass-through activity: abrupt volume, third-party credits, same-day foreign transfers, no coherent business rationale. FINOM featured there only as an account the terminated customer mentioned holding, but those signatures overlap closely with the questions the Triventa statement raises.

 

What to know about Banking Circle?

 Banking Circle S.A. is a full bank, and a far larger, faster-growing one. It is a Luxembourg credit institution (CSSF register B00000408; RCS Luxembourg B222310; registered office 2 Boulevard de la Foire, L-1528 Luxembourg; German branch at Maximilianstrasse 54, Munich), licensed by the CSSF on 27 February 2020. It  is a pure business-to-business settlement and correspondent bank supplying cross-border payment rails, accounts, FX and  centrally here, virtual IBANs to other payment firms, EMIs, banks and marketplaces, which pass them on to their own customers. Its origins are in Saxo Bank (launched as Saxo Payments in 2013, rebranded Banking Circle in 2017); Saxo sold it to the private-equity group EQT in July 2018 for roughly US$300m, and EQT remains the owner.

The scale dwarfs FINOM’s. Banking Circle states it processes more than €1.5 trillion in payments a year (a 108% compound annual growth rate since 2016, up from about €130bn at its 2020 licence and €250bn in 2021), for 850+ institutions, and has issued more than 35 million virtual accounts (29 million IBANs) — on EFRI’s own analysis “arguably the largest issuer in Europe’s vIBAN stack” (see Virtual IBANs — a Risk for Consumers?, which reads the layered Payment-On-Behalf-Of model against the European Banking Authority’s 2024 warnings on know-your-customer’s-customer gaps). Its audited 2024 accounts show net operating income of €220.7m (2023: €125.2m, +76%) and net profit of €67.3m (2023: €12.7m), on a balance sheet of €4.33bn.

The figure that deserves scrutiny sits off the balance sheet. Banking Circle began fiduciary operations only in 2023, and within a single year the client funds it holds in that capacity rose from €1.24bn to €6.08bn — a 389% jump — while the associated fee income grew from €9.5m to €71.7m (+655%). The published accounts do not break that €6.08bn down how much is PSP safeguarding, how much is fund or stablecoin-reserve money, how much is other trust structures and that composition is the central unanswered question about what Banking Circle now holds, and for whom. It is not, on the timeline, explained by the bank’s stablecoin: Banking Circle S.A. issued EURI,  a euro-pegged token it markets as the first MiCA-regulated stablecoin backed by an EU bank only on 26 August 2024, after the fiduciary book had already reached €1.24bn at end-2023. What the token marks is the wider positioning — Banking Circle as a banking, safeguarding and settlement layer for third-party digital assets, extended since 2026 with a crypto-asset-service (CASP) component. The billions came first; the stablecoin is a newer product on top.

Where Banking Circle appears in fraud

Banking Circle’s virtual IBANs are already documented in an international investment-fraud structure independent of this case. The OCCRP investigation “Scam Empire” (2025) traced victim money from fraud platforms (Equitiz, Equistak, Saturn4u) through a UK payment structure to two recipient companies, Penta Pacific Group Ltd and NRG Applied Sciences Ltd,  that received it on Banking Circle virtual IBANs. Banking Circle confirmed to OCCRP that those IBANs were assigned in its systems to a payment service provider, and that Penta and NRG were that PSP’s customers rather than Banking Circle’s direct clients; the PSP was not named. That establishes no knowledge or involvement on Banking Circle’s part, but it documents Banking Circle vIBAN infrastructure receiving victims’ funds in a second, unrelated fraud, and puts the accountability question at the gatekeeper level: what a virtual-IBAN issuer knows, or can obtain, about the end-customers behind its clients’ accounts.

The customer-facing record is poor. On Trustpilot the bank scores 1.5 out of 5 across some 137 reviews, overwhelmingly one-star — frozen or inaccessible funds, unexplained account closures, unreachable support, and complaints, from people who reached a Banking Circle IBAN through one of its clients, that the bank is used in scams, with responsibility deflected to the client PSP. 

That B2B structure is precisely what this case ran into: Banking Circle’s stated position is that it holds no endpoint records on the underlying customers of its clients, and resolves the identity of the platform behind a virtual IBAN only for law enforcement, the structural counterpart, at the scale of tens of millions of virtual IBANs and a fiduciary book that quintupled in a year, to the opacity documented above.

Did Kifid help?

Desperately looking for help the victim also approached the Dutch Financial Ombudsman. Kifid  in its decision of 12 May 2026 (ref. 26.02338/R.G.),  held that a complainant needs a contractual relationship with the institution; the victim had none  – “the simple fact that the beneficiary holds an account at Finom is not sufficient”. Kifid  closed the file for want of jurisdiction, with no ruling, in either direction, on KYC or monitoring. 

Our Assessment

This section is EFRI’s own evaluation, written from a victim-protection perspective. It is analysis, not a finding of law.

For EFRI, this €54,000 payment leg is a near-perfect illustration of the central problem in cross-border investment-fraud recovery: the regulated payment intermediary is often the structurally indispensable, identifiable and solvent node in a chain whose actual operators are anonymous, offshore or otherwise beyond the victim’s practical reach.

Here, the criminal investigation initially stalled for want of an identifiable perpetrator and was reopened only after the victim himself assembled additional parts of the cross-border payment trail. The FINOM account, by contrast, is identifiable and documented: a DNB-licensed EMI provided an account to a British company incorporated only eleven days before the account was opened. In six weeks, that account received €314,183 in 67 credits, overwhelmingly from private individuals, and transferred €313,725 — 99.85% of its inflows — onward to accounts at Banking Circle.

The next layer illustrates a different problem. Banking Circle’s records show that one of its clients had used its POBO infrastructure to create a virtual IBAN personalised in the victim’s name months before the victim was even contacted by the fraudsters. The victim had neither requested nor controlled that virtual IBAN. Yet the identity of the Banking Circle client behind the relevant merchant UUID remains undisclosed to him. Banking Circle says that it holds no IP addresses, device identifiers or comparable endpoint data relating to the underlying customers of its clients, while the identity associated with the merchant identifier can be addressed through formal law-enforcement channels. In EFRI’s view that refusal is legally contestable: a data subject whose own name was placed on an account is, under Article 15(1)(c) GDPR as read by the CJEU in C-154/21, entitled to the actual identity of recipients — not merely categories — and, under Article 15(1)(g), to the available information as to the source of data not collected from him. “Only on a law-enforcement request” is not, in itself, a recognised ground of refusal; the point is one for the Luxembourg supervisor (CNPD) to test.

The result is a striking asymmetry. The regulated institutions and the payment infrastructure are identifiable; the victim and his money are identifiable; but the party that inserted the victim’s identity into the virtual-IBAN structure remains hidden from him behind the B2B layer. Accountability therefore has to be examined at the regulated nodes through which the money and the underlying account structures necessarily passed.

FINOM’s relativity defence shows precisely how difficult that is — and why it is the right legal question to test. FINOM argues that AML and KYC obligations protect “the general societal interest” rather than individual third parties such as the victim. That is the relativiteit / Schutzzweck barrier on which intermediary-liability claims may ultimately turn.

But the issue should not be reduced to whether the victim can derive a damages claim directly from the Wwft. A separate question is whether the actual conduct of a regulated payment intermediary, assessed against the circumstances known or reasonably observable to it, can support an autonomous duty-of-care claim under Dutch tort law. That distinction matters here. The material presently available documents FINOM’s identity verification through Sumsub; it does not show what FINOM recorded about Triventa’s expected business activity, expected turnover or customer profile, nor how that expected profile was compared with the transaction pattern that followed.

And that pattern is difficult to ignore: a £1 British company, eleven days old when its FINOM account was opened, received €314,183 from dozens of private individuals within six weeks and passed 99.85% of those funds onward. Onward movement of near-100% of inflows is not, by itself, proof of anything — an agency or billing account may legitimately do exactly that; what puts this pattern in issue is the combination: a days-old £1 shell, dozens of unconnected private remitters, same-name onward accounts and no visible business rationale. FINOM says it is prohibited from disclosing the mechanics and thresholds of its transaction monitoring. It has not disclosed whether any suspicious activity reports were filed with the Dutch FIU in relation to the Triventa account, despite the unusually high volume and rapid onward movement of funds. Nor has FINOM explained why the Triventa account was closed after only six weeks of operation, or what triggered that closureThose undisclosed records — together with the complete onboarding file — are precisely where the central factual question lies: what did FINOM expect this customer to do, what did it actually observe, and when did the divergence become material?

The opacity is therefore not an abstraction; it is measured in the recovery process. A POBO virtual-IBAN structure can place the name of an underlying person on an account identifier without putting the B2B client that created that identifier on the face of the IBAN. A victim exercising his GDPR access rights can obtain the virtual IBAN, its creation date, a master-account identifier and a merchant UUID, yet still not know the identity of the Banking Circle client that supplied his personal data and caused the virtual IBAN to be created. A criminal investigation can stall because the relevant traces lead abroad, while the information required to continue the trail remains distributed across regulated institutions in different jurisdictions.

Delay is not an incidental feature of this architecture; it functions as one of its protections. A victim told to “wait for law enforcement” is being pointed down the slowest road available. Mutual legal assistance between EU member states — the mechanism on which a cross-border criminal trail depends — routinely takes many months, and often years: in EFRI’s own casework a single assistance request between Munich and Amsterdam, concerning Payvision, took seven months to answer. The institutions that direct victims there can hardly be unaware of that. Every month of it lets funds move further, evidence age and companies dissolve — and it unsettles the question a defendant raises first in any later civil claim: when did limitation begin to run? Both German and Dutch law tie the start of the limitation period to the moment the victim knows the damage and the identity of the liable party (§ 199(1) BGB; art. 3:310 BW) — the very knowledge these disclosure refusals withhold. The effect is not comfort but uncertainty: a contested threshold the victim must litigate before the merits are reached, even as, against the intermediaries already known to him, the clock may already be running.

Nor does “wait for law enforcement” deliver even once a file exists. An injured party’s right to inspect the investigation file (§ 406e StPO) is regularly deferred while the investigation is live — precisely when the trail is freshest — so that months, sometimes years, pass before the victim sees what the state already holds. And the one channel built to be fast and cheap is closed to him by design: Kifid dismissed his complaint not on the merits but for want of a contractual relationship, because the ombudsman scheme is constructed for an institution’s own customers, not for a defrauded payer who is nobody’s customer. Criminal enforcement is slow; civil disclosure is slow; and the ADR route does not admit him at all. That combination — not any single refusal — is the system a cross-border fraud victim actually faces, and it is why an ombudsman model designed around bilateral customer relationships is structurally unfit for third-party fraud harm.

Every additional layer increases the cost and complexity of recovery. That is why, for EFRI, recovery has to be built, not awaited. The FINOM account statement is, in substance, a ready-made list of some fifty remitters. It does not by itself establish liability or the admissibility of a collective action. It does, however, provide the evidentiary starting point for identifying further victims, comparing their factual circumstances and assessing whether collective redress against one or more regulated intermediaries is viable.

We state the limits of the evidence clearly. Commingling prevents the victim’s €54,000 from being traced euro-for-euro into a particular onward transfer. The Dutch judgments cited concern other cases. The reopened criminal investigation still identifies no perpetrator. The Sumsub report available to EFRI is not necessarily FINOM’s complete onboarding file. And neither FINOM nor Banking Circle is, on the present record, a proven wrongdoer.

None of those limitations removes the supervisory question. A DNB-supervised EMI carried €314,183 through the account of a days-old company in six weeks, with 99.85% of the inflows passed onward. Downstream, Banking Circle infrastructure contained a virtual IBAN personalised in the name of a victim who had never requested it, created by a Banking Circle client whose identity remains undisclosed to that victim.

Those facts do not establish liability. They do establish the questions that matter: what was known, what should reasonably have been detected, what controls operated at each layer, and when should intervention have occurred? Those are questions a  risk-based supervisor should be able to answer.

More about this topic.