Free guide: How to use AI in compliance
Bar chart of Monzo customers rising from 0.6 million in 2018 to 5.8 million in 2022 past a flat line of controls, with a £21.1m penalty tag.

The Monzo AML fine was £21.1m. What the FCA Final Notice found, how 26,325 high-risk accounts broke a restriction, and the lessons every fintech should apply.

Table of contents
  • The Financial Conduct Authority (FCA) fined Monzo Bank £21,091,300 in a Final Notice dated 7 July 2025. Without the 30% settlement discount the penalty would have been £30,130,475.
  • Two breaches: weak financial crime controls from 1 October 2018 to 4 August 2020, and repeated breaches of a restriction on onboarding high-risk customers from 5 August 2020 to 30 June 2022.
  • Monzo opened 33,039 accounts in breach of the restriction, 26,325 of them for high-risk customers. The "over 34,000" figure in the headlines is a separate estimate of customers who may have slipped through.
  • The control failings account for £19.3 million of the £30.1 million pre-discount penalty. The restriction breach scored only £805,250 on the FCA's formula, then received a £10 million deterrence uplift, a thirteenfold increase.
  • Customers grew from about 590,000 in February 2018 to 5.8 million in February 2022. The FCA's finding is that key controls did not keep pace.

The Monzo AML fine is the £21,091,300 penalty the UK Financial Conduct Authority imposed on Monzo Bank in July 2025 for inadequate financial crime controls between 2018 and 2020, and for opening 26,325 accounts for high-risk customers between 2020 and 2022 in breach of a restriction it had agreed with the regulator.

TL;DR

Monzo grew roughly tenfold in four years while its onboarding checks, customer risk assessment and transaction monitoring stayed built for a much smaller bank. When the FCA intervened in 2020, Monzo agreed a restriction on taking on high-risk customers and then breached it for almost two years. The control failings make up about two thirds of the penalty. The restriction breach is the part the FCA chose to make an example of, multiplying its formula figure thirteenfold, and the lesson for every fintech is that a regulatory restriction has to be enforced by the onboarding system itself, not by policy.

This article is general information about a published enforcement decision, not legal advice.

What was the Monzo AML fine?

The Monzo AML fine is a financial penalty of £21,091,300 imposed by the FCA on Monzo Bank Limited. The Final Notice is dated 7 July 2025 and the FCA announced it the next day in a press release. Monzo agreed to resolve the matter at an early stage and received the FCA's 30% stage 1 settlement discount, without which the penalty would have been £30,130,475.

The Notice records two separate breaches. The first is a breach of Principle 3 of the FCA's Principles for Businesses, which requires a firm to organise its affairs responsibly and effectively with adequate risk management systems, covering 1 October 2018 to 4 August 2020. The second is a breach of a requirement on Monzo's permission, known as the VREQ, between 5 August 2020 and 30 June 2022.

Therese Chambers, the FCA's joint executive director of enforcement and market oversight, framed the case in one line: "Banks are a vital line of defence in the collective fight against financial crime."

The Notice concerns control failings. It does not find that Monzo itself laundered money. The FCA's case is that weak controls left the bank exposed to being used for financial crime.

What happened, and when?

The case runs for almost seven years from the start of the failings to the Final Notice. Every date below is taken from the Final Notice.

DateEvent
February 2018Monzo has about 590,000 customers
1 October 2018Start of the period of inadequate financial crime controls
Early 2019Address verification withdrawn as an identity verification control
June 2020FCA raises concerns about onboarding controls
July 2020Address verification reinstated
5 August 2020The VREQ restricting high-risk customer onboarding takes effect
14 August 2020FCA requires Monzo to appoint a skilled person to review its controls
18 September 2020Skilled person's first report: risk assessment and due diligence did not fully align with the Money Laundering Regulations
December 2021FCA agrees a first modification of the restriction
February 2022Monzo has 5.8 million customers
30 June 2022End of the period in which the VREQ was breached
August 2024Skilled person's final report
November 2024Last remediation recommendation met
26 February 2025FCA lifts all remaining requirements
7 July 2025Final Notice issued; announced 8 July 2025

The shape of the timeline is the lesson. Growth came first, controls second, and the regulator third.

Which control failings did the FCA find?

The FCA's summary is that key elements of Monzo's financial crime framework did not keep pace with the firm's expansion. Paragraph 5.3 of the Final Notice lists seven specific failings in the period before the restriction.

  1. Customer due diligence at onboarding was inadequate, including no information gathered on the purpose and intended nature of the business relationship. Our glossary entry on customer due diligence sets out what that step normally captures.
  2. Addresses were not verified, so implausible addresses went through (see below).
  3. Beneficial owners and persons with significant control of business customers were not verified. The ultimate beneficial owner check is basic KYB, and it was missing.
  4. The customer risk assessment was inadequate in both scope and method, so the bank could not reliably tell a low-risk customer from a high-risk one.
  5. Transaction monitoring was weak, and Monzo relied on it anyway.
  6. There was no clear enhanced due diligence process for high-risk customers who were not politically exposed.
  7. Enhanced due diligence on politically exposed persons was inadequate.

The customer risk assessment is the failing that sits underneath the others. Every downstream control, from how deep due diligence goes to how often a customer is reviewed, takes its cue from the risk rating. If the rating is wrong, the rest of the framework is calibrated to the wrong customer.

How did Monzo breach the VREQ?

A VREQ is a voluntary requirement: a restriction a firm applies for on its own permission, usually because the regulator has asked it to, which then binds it like any other requirement. The FCA imposed Monzo's under section 55L(5)(a) of the Financial Services and Markets Act 2000. From 5 August 2020 it barred Monzo from opening accounts for high-risk customers and required additional checks and documentation on onboarding.

Monzo breached it for almost two years. According to the Final Notice, the bank opened 33,039 accounts in breach of the VREQ. Of those, 26,325 were for high-risk customers. The other 6,714 were opened without the additional checks and documentation the restriction required.

The widely reported "over 34,000 high-risk customers" is a different number. Monzo estimated that where VREQ controls were not applied, or were applied to the wrong information, 34,262 high-risk customers may have been onboarded across 167,444 accounts. That is an upper estimate of exposure, not the count of confirmed breaches, and it is worth keeping the two apart when citing the case.

Why did the restriction breach cost so much more?

The FCA's penalty calculation (Final Notice, section 6) shows how it weighs the two breaches. Penalties start as a percentage of the revenue earned during the breach. Monzo's relevant revenue was £107,362,365 for the control failings period and only £4,473,612 for the restriction breach, and the FCA rated both breaches at seriousness level 4, taking 15% and then adding 20% for aggravating factors.

StepControl failings (Principle 3)Restriction breach (VREQ)
Relevant revenue£107,362,365£4,473,612
After seriousness and aggravation£19,325,225£805,250
Deterrence upliftnone£10,000,000
Before the 30% discount£19,325,225£10,805,250

The control failings are the larger share of the Monzo AML fine, about two thirds. The striking number is the other column. On the formula, breaching the restriction was worth £805,250, a figure the FCA said would not deter Monzo or other firms, so it added £10,000,000 for that breach alone (paragraph 6.25).

That is the signal to take away. Once a regulator has identified the gap and agreed a restriction, a firm is judged on whether its systems honour it, and the FCA will override its own formula to make a breach of that kind expensive.

Was dropping address checks the real problem?

The most quoted detail in the case is that Monzo accepted customers giving addresses such as Buckingham Palace, 10 Downing Street and Monzo's own business address. The Final Notice also lists PO boxes, mail-forwarding addresses, addresses of customers Monzo had already offboarded, and foreign addresses paired with UK postcodes.

The background is a decision in early 2019. Monzo withdrew address verification as an identity verification control, having concluded it was not a reliable indicator of criminal propensity. For almost all of that period a customer only had to pass the selfie identity check. Monzo's own data showed that about 20% of existing customers, and 47% of those rated higher risk, had failed the address check before it was dropped. Monzo reinstated address verification in July 2020.

Here is the nuance a fair reading needs. The Final Notice states that the absence of address verification was not contrary to prevailing guidance on the Money Laundering Regulations. The problem was that Monzo's risk appetite was to serve UK residents only, and without address checks it could not tell who was one. The failing was not the missing check as such. It was running a control framework that could not enforce the bank's own stated risk appetite. For what a proportionate address check involves, see our entry on proof of address.

How does Monzo compare with Starling and Metro Bank?

Monzo was the third UK bank fined for financial crime control failings in under a year, and the FCA noted it was the tenth fine on a bank for such failings in four years.

BankPenaltyFinal NoticeCore failing
Starling Bank£28,959,42627 September 2024Financial crime controls and breach of a restriction on high-risk customers
Metro Bank£16,675,20012 November 2024Transaction monitoring: over 60 million transactions worth over £51bn not properly monitored
Monzo Bank£21,091,3007 July 2025Controls did not keep pace with growth; 26,325 high-risk accounts opened in breach of the VREQ

Sources: FCA press releases for Starling, Metro Bank and Monzo.

Starling and Monzo share the pattern that matters most: both were already under a restriction on high-risk customers and both breached it. Metro's case is the monitoring version of the same problem, which is where our analysis of the TD Bank $3 billion lesson picks up on the US side. We log these actions as they land in the AML enforcement tracker.

What should fintechs change after the Monzo AML fine?

Each failing in the Final Notice maps to a control a growing fintech can actually run.

What went wrong at MonzoThe lessonThe control that prevents it
Address checks dropped to cut onboarding drop-offFix friction with better checks, not fewerAutomated plausibility checks at onboarding, with re-verification when data changes
Customer risk assessment inadequate in scope and methodA risk rating is not a one-off onboarding scoreRisk ratings that update as screening results, behaviour and customer data change (perpetual KYC)
Transaction monitoring did not scale with a tenfold customer baseSize monitoring for projected growth, not current volumeTransaction monitoring with alert triage that scales, keeping a human on every decision
26,325 high-risk accounts opened under a restrictionA restriction written in a policy is not a controlRestriction rules enforced inside the onboarding flow, blocking restricted customer types with an audit trail that proves it
No clear enhanced due diligence for non-PEP high-risk customersHigh risk needs a defined path, not case-by-case judgementA documented enhanced due diligence workflow triggered by the risk rating

Each of these is a system decision, not a policy memo: perpetual KYC keeps risk ratings moving, transaction monitoring with human-approved alert triage scales with volume, and a documented enhanced due diligence workflow gives high-risk customers a defined path.

The common thread is that Monzo's controls were point-in-time while its risk was continuous. A customer verified with a selfie in 2019 stayed verified; a risk rating set at onboarding did not move. Event-driven, continuous review is the structural answer, and our guide to KYC for neobanks and perpetual CDD walks through how to run it without collapsing conversion. For neobank-specific onboarding, see KYC for neobanks.

There is also a privacy lesson that usually gets missed. The pressure that led Monzo to drop address checks was conversion. Tighter checks do not have to mean collecting and storing more personal data: verifying an attribute without keeping the underlying document is how you keep both the control and the conversion rate.

Has anything changed since the Final Notice?

By the time the Monzo AML fine was announced, the remediation was already done. The skilled person's final report arrived in August 2024, the last recommendation was met in November 2024, and the FCA lifted all remaining requirements on 26 February 2025. Monzo's Annual Report 2026 records the penalty as paid and treats it as an exceptional cost for the year. We found no further FCA financial crime action against Monzo after July 2025.

That order of events is itself instructive. The fine arrived almost three years after the breaches ended and five months after the restrictions were lifted. Enforcement lags the conduct by years, so the controls a firm runs today decide the Final Notice it may read in 2029.

The bottom line

The Monzo AML fine is not a story about one bad decision. It is a story about controls that stood still while a bank grew tenfold, followed by a restriction that the onboarding system did not enforce. The first failing produced two thirds of the penalty; the second produced a £10 million uplift the FCA added to make the point. If your KYC is still point-in-time, book a demo to see how continuous verification and restriction rules enforced in the flow keep your controls moving at the speed of your growth.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

The FCA fined Monzo £21,091,300 in a Final Notice dated 7 July 2025. The penalty would have been £30,130,475, but Monzo settled early and received the FCA's 30% stage 1 discount. £10 million of the pre-discount figure was a deterrence uplift for breaching the restriction on high-risk customers.

For two breaches. Its financial crime controls were inadequate from October 2018 to August 2020, a breach of Principle 3. Then, from August 2020 to June 2022, it repeatedly breached a restriction on its permission by opening accounts for high-risk customers.

Monzo opened 33,039 accounts in breach of the restriction, of which 26,325 were for high-risk customers. The figure of more than 34,000 often quoted is Monzo's own estimate of high-risk customers who may have been onboarded where controls were not applied.

A VREQ is a voluntary requirement: a restriction a firm applies for on its own regulatory permission, usually at the regulator's request, which then binds it. Monzo's VREQ took effect on 5 August 2020 and restricted it from opening accounts for high-risk customers.

The Final Notice does not find that Monzo laundered money. It finds that Monzo's controls were inadequate and that it breached a regulatory restriction, which exposed the bank to a higher risk of being used for financial crime.

Monzo withdrew address verification in early 2019, judging it an unreliable indicator of criminal propensity, and relied mainly on a selfie identity check. Implausible addresses, including Buckingham Palace and 10 Downing Street, then went through. Address verification was reinstated in July 2020.

Starling Bank was fined £28,959,426 in 2024 and Metro Bank £16,675,200 in 2024, both for financial crime control failings. The FCA said the Monzo penalty was the tenth it had imposed on a bank for such failings in four years.

Keep verification quality independent of conversion pressure, update customer risk ratings continuously, size transaction monitoring for projected growth, and enforce any regulatory restriction inside the onboarding system with an audit trail, rather than relying on staff to follow a policy.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML