Free guide: How to use AI in compliance
Back

AML Enforcement by the Numbers: 2026 Year to Date (September 2026 Edition)

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 18, 2026Updated September 18, 2026
A bar chart of 2026 AML enforcement penalties, three tall bars for UBS, Canaccord and Swedbank over a long tail of smaller fines, with 23 actions and about 324 million dollars as of 18 September 2026

AML enforcement in 2026 so far, from Zyphe's open dataset: 23 actions, about $324 million in penalties, three fines carrying 79 percent, and what repeats.

Table of contents
  • Zyphe's open AML enforcement dataset holds 23 actions dated in 2026 as of 18 September, with about 324 million US dollars in recorded penalties across 14 of them. Nine actions carried no monetary penalty: charter denials, remediation orders, censures, sanctions designations and identity-data breaches.
  • Three fines account for 79 percent of the year's total: FinCEN's 125 million dollar penalty against UBS Financial Services, FinCEN's 80 million dollar penalty against Canaccord Genuity, and the New York Department of Financial Services' 50 million dollar penalty against Swedbank.
  • FinCEN alone accounts for 205 million dollars, or 63 percent of the 2026 total, from two broker-dealer cases.
  • The median penalty among actions with a recorded amount is about 8.6 million dollars, which is where most of the year's supervisory activity actually sits.
  • Eleven of the 23 actions were classic AML or Bank Secrecy Act fines. The rest split between identity-data breaches, sanctions actions, customer due diligence orders with no fine, governance findings and GDPR enforcement aimed at KYC data.
  • The third quarter to date logged 10 actions and about 189 million dollars, most of it the UBS and Swedbank penalties in a five-week window in July and August.

AML enforcement is the set of penalties, orders, censures and public actions that regulators and prosecutors take against firms for failures in anti-money laundering controls, including customer due diligence, transaction monitoring, suspicious activity reporting and sanctions screening. This edition counts the actions Zyphe has logged with a primary source for 2026 so far.

TL;DR

As of 18 September 2026 the dataset behind our AML enforcement tracker holds 23 actions dated this year, about 324 million dollars in penalties, and three fines that make up 79 percent of that total. FinCEN drove 63 percent of the money from two cases. The typical action, once the three outliers are set aside, is a single-digit-million penalty for monitoring that did not produce reports or due diligence that was not refreshed. Identity-data breaches, sanctions designations and orders with no fine attached are a third of the year's entries, which is why counting only fines undercounts the year. Every number below links to its row and its primary source.

How much did AML enforcement cost in 2026 so far?

MeasureValue as of 18 September 2026
Actions logged, dated 202623
Actions with a recorded monetary penalty14
Penalties recorded, converted to US dollars at the rate on the recordabout 324 million dollars
Largest single penalty125 million dollars, UBS Financial Services, FinCEN
Median penalty among the 14 with an amountabout 8.6 million dollars
Smallest recorded penalty10,283 pounds, Ranson Houghton LLP, Solicitors Regulation Authority
Actions with no monetary penalty9
Records in the whole dataset since November 202327

The total is dominated by three cases and the median tells the truer story. Half of the penalised firms paid less than 8.6 million dollars, and the actions with no penalty attached, a denied bank charter for Wise, a supervisory order for Helaba, a censure with 31.7 million pounds of client redress for CACEIS UK, two OFAC designations, an EU-wide GDPR sweep and three breaches, are the ones compliance teams should read most carefully, because they show what regulators act on before the fine arrives.

Which AML enforcement actions were the largest of 2026?

RankFirmRegulatorPenaltyDateWhat the record says
1UBS Financial ServicesFinCEN125 million dollars3 August 2026Second penalty for a broker-dealer AML programme under an unremediated consent order
2Canaccord GenuityFinCEN80 million dollars6 March 2026AML programme judged by what it caught, not what the written policy said
3SwedbankNYDFS50 million dollars16 July 2026Concealment from the supervisor punished separately from the underlying laundering
4Ikano BankFinansinspektionen140 million Swedish kronor17 June 2026The general risk assessment treated as an enforceable obligation on its own
5Poste Italiane and PostepayGarante12.5 million euros17 April 2026GDPR necessity test applied to fraud-prevention device surveillance

The three largest together are 255 million dollars, 79 percent of the year. Our analyses of each sit behind the tracker rows: the UBS penalty, the Canaccord penalty and the Swedbank penalty. The two FinCEN cases are both broker-dealers, and both records turn on the gap between the programme on paper and the alerts it generated, which is the same finding FinCEN made against TD Bank in 2024 at twenty-four times the size.

Which regulators drove AML enforcement in 2026?

RegulatorActionsPenalties recorded
FinCEN (United States)2205 million dollars
NYDFS (New York)150 million dollars
Finansinspektionen (Sweden)1140 million kronor, about 15.1 million dollars
Garante (Italy)112.5 million euros, about 14.6 million dollars
De Nederlandsche Bank (Netherlands)211.16 million euros combined, about 13 million dollars
Department of Justice (United States)19.79 million dollars
SEC (United States)17.5 million dollars
Central Bank of the UAE120 million dirhams, about 5.4 million dollars
PRA (United Kingdom)12 million pounds
UK Gambling Commission1609,104 pounds
OFAC (United States)360,764 dollars in one settlement, two designations with no penalty
OCC, BaFin, FCA, SRA, EDPB5one small fine, four actions with no penalty or with redress instead

FinCEN's two cases are 63 percent of the year's money. Dutch enforcement is the most frequent European source, with DNB fining both ABN AMRO and the payment processor CCV within a week in July. The UK appears four times but for small or non-monetary actions, and the FCA's action was a censure with client redress rather than a fine.

What did AML enforcement look like by type and jurisdiction?

By type of action, 2026 to date:

  • AML or Bank Secrecy Act fines: 11
  • Identity-data breaches: 3
  • Sanctions actions: 3 (one OFAC settlement, two designations)
  • Customer due diligence orders with no fine: 2 (Wise, Helaba)
  • Integrity and governance findings: 2 (CACEIS UK, Bank of London)
  • GDPR enforcement aimed at KYC or customer data: 2 (Poste Italiane, the EDPB transparency sweep)

By jurisdiction: United States 11, United Kingdom 4, Netherlands 2, and one each for Germany, Sweden, Italy, the UAE, an EU-wide action and a global vendor incident. The US share is inflated by the three sanctions entries and two of the three breaches; on the eleven classic AML fines alone the split is US 5, Europe 5 (two UK, two Dutch, one Swedish), UAE 1.

What happened in AML enforcement in the third quarter of 2026?

The quarter to 18 September logged 10 actions and about 189 million dollars. July produced seven of them: the OCC's denial of Wise's bank charter over an open AML order, BaFin's customer due diligence order against Helaba, the Swedbank penalty, the two DNB fines, the AssuranceAmerica breach and OFAC's designation of a PCC laundering network using crypto rails. August produced three: the UBS penalty, the Gambling Commission's 609,104 pound settlement with QuinnBet after a platform migration silently dropped a control, and OFAC's 60,764 dollar settlement with Rice Lake Weighing Systems over a foreign subsidiary. Nothing meeting the inclusion criteria had been logged for September by the 18th.

What do the 2026 AML enforcement findings have in common?

Each row carries a one-line lesson drawn from the regulator's own findings. Grouped, the year reads like this.

  1. Monitoring that did not produce reports. Merrill Lynch knew a threshold was miscalibrated and left it; CCV had merchants outside the monitored population, so no alerts existed to tune; ABN AMRO accepted customer explanations without verifying them; UBS was penalised a second time under an order it had not remediated. Four of the eleven fines are, at root, transaction monitoring that existed on paper.
  2. Due diligence not completed or not refreshed. Helaba and ABN AMRO were both acted on for customer due diligence on high-risk or existing customers rather than onboarding, and Wise was refused a bank charter over an unresolved AML order, which is the ongoing half of customer due diligence that budgets tend to forget.
  3. Governance over the programme. EagleBank's senior management overrode compliance; the Bank of London could not show the data trail behind its numbers; the CBUAE imposed personal liability on a compliance officer; Ikano was fined for the quality of its risk assessment itself.
  4. The perimeter keeps widening. A solicitors' firm, a payment processor, a gambling operator, an auto insurer holding driver's licence numbers and a weighing-equipment maker's foreign subsidiary all appear. AML enforcement in 2026 is not a banking story.
  5. Concealment is punished on its own. Swedbank's penalty record separates what was hidden from the supervisor from the underlying failure, and prices the hiding.

How many identity-data breaches were logged in 2026?

Three: the database attributed to IDMerit with roughly one billion records, an attribution the vendor disputes; Sumsub's intrusion through a third-party support platform, undetected for about 18 months; and AssuranceAmerica's breach affecting 6,998,886 people including driver's licence numbers. The dataset holds five breaches in total since May 2025 and publishes them as a separate file, and the narrative log with per-incident analysis is the KYC breach tracker. None of the five involved a cryptographic break; each came through a credential, a misconfiguration, an exposed artefact or a person, which is the argument for not holding the documents at all once the check is done.

How is this AML enforcement dataset compiled?

Inclusion. An action is logged when a regulator, prosecutor or court publishes a penalty, order, censure, designation or denial for an AML, sanctions, KYC or customer-data control failure, or when an identity-data breach is confirmed by the holder, a regulator or two independent named publications. Each row carries the primary source URL, the regulator, the jurisdiction, the type, the date, the amount in the original currency and in US dollars at the rate on the record, a two-sentence summary and a one-line lesson.

Exclusion. Private litigation, unconfirmed press reports, actions with no public record, and ordinary supervisory findings that were not published as enforcement.

Cadence. Rows are added as our daily regulatory news review confirms them, usually within a week of publication. This by-the-numbers edition is published monthly; the figures are as of the date in the title and the tracker page recalculates its headline statistics on every build.

Access. The full dataset is downloadable as CSV, JSON and RSS from the tracker page, which publishes Dataset schema markup and a suggested citation. Each row has a permanent anchor. Corrections are recorded on our corrections page.

How can you use the numbers?

Quote them with the as-of date and link the row. Benchmark your own control failures against the lesson column rather than the amount: the amount reflects the firm's size and history, the lesson reflects the control. Use the no-penalty rows to argue for budget before the fine, since a charter denial or a remediation order costs more than most of this year's fines. And if the pattern in section six describes your monitoring, our AML software evaluates every payment against deterministic rules before it settles and lets you backtest any rule for free on stored transactions, which is the cheapest way to find out whether your thresholds would have caught what the regulators found.

The bottom line

Twenty-three actions, about 324 million dollars, three fines carrying 79 percent of it, and a median under nine million. The headline number will always be set by whichever large institution was under an old order when the year began. The useful signal is in the other twenty rows: the orders with no fine, the small penalties on firms that never thought of themselves as regulated for money laundering, and the same three findings repeating under different regulators' letterheads.

This post is a summary of public records and Zyphe's own dataset, not legal advice. Where a regulator's record and this summary differ, the record is right and we would like to hear about it.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

About 324 million US dollars across the 14 actions with a recorded penalty in Zyphe's dataset as of 18 September 2026, converted at the rates on each record. Three fines, UBS at 125 million dollars, Canaccord Genuity at 80 million and Swedbank at 50 million, make up 79 percent of that total.

FinCEN's 125 million dollar civil money penalty against UBS Financial Services on 3 August 2026, for a broker-dealer anti-money laundering programme that remained deficient under an earlier unremediated consent order. It is the largest FinCEN penalty against a broker-dealer on the record.

By money, FinCEN, with 205 million dollars from two broker-dealer cases, 63 percent of the year's total. By count, OFAC has three entries, De Nederlandsche Bank two and FinCEN two; the rest of the regulators appear once each.

Twenty-three actions dated in 2026 are logged as of 18 September, of which eleven are classic AML or Bank Secrecy Act fines. The remainder are identity-data breaches, sanctions actions, customer due diligence orders without a fine, governance findings and GDPR enforcement aimed at KYC data.

Transaction monitoring that existed on paper but did not produce reports, customer due diligence on high-risk or existing customers that was not refreshed, and governance failures where management overrode or under-resourced compliance. Concealment from a supervisor was penalised separately in the Swedbank case.

The 324 million dollar figure includes every recorded monetary penalty in the dataset for 2026, which covers one GDPR fine against Poste Italiane and one PRA governance fine against the Bank of London as well as AML and sanctions penalties. Excluding those two, AML and sanctions penalties alone total about 307 million dollars.

Rows are added as the daily regulatory news review confirms them, usually within a week of the regulator's publication. This by-the-numbers post is published monthly with figures as of the date in its title, and the tracker page recalculates its headline statistics on every site build.

From the AML enforcement tracker page at zyphe.com, as CSV, JSON or RSS, with Dataset schema markup and a suggested citation. The identity-data breach subset is also published as its own CSV linked from the KYC breach tracker post.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML