Learn more about the latest security and privacy threats
Back

The ABN AMRO fine: DNB penalises 8.5 million euro due diligence failures on high-risk customers

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 13, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "The ABN AMRO fine: DNB penalises 8.5 million euro due diligence failures on high-risk customers".

De Nederlandsche Bank fined ABN AMRO 8.5 million euros for weak ongoing monitoring of high-risk clients. What the ABN AMRO fine means for your CDD duties.

Table of contents

De Nederlandsche Bank has imposed an 8.5 million euro ABN AMRO fine for failing to monitor its highest-risk customers, five years after the bank paid 480 million euros to settle a criminal money laundering case. The regulator found monitoring was, in its words, insufficiently critical, and that the bank leaned on customer explanations it never verified.

  • De Nederlandsche Bank (DNB) fined ABN AMRO 8.5 million euros in a decision dated 6 July 2026 for inadequate customer due diligence on high-risk clients.
  • The failures ran from September 2023 to September 2024 and centred on weak ongoing monitoring, not onboarding checks, showing that risk does not stop at account opening.
  • In five sample files DNB found unexamined red flags: large cash withdrawals, high-risk countries, frequent commission payments, dual-use goods, and possible circumvention of Russia sanctions through intermediaries.
  • The bank relied on what customers told it rather than on objective, verifiable evidence, and closed enquiries while material uncertainty remained.
  • The penalty lands five years after ABN AMRO's 480 million euro settlement over 2014 to 2020 failures, so this is a repeat theme, not a first offence.

What did DNB find in the ABN AMRO fine?

DNB found that ABN AMRO carried out inadequate customer due diligence on a portion of its high-risk customers between September 2023 and September 2024. In its published enforcement notice, DNB called the bank's ongoing monitoring "insufficiently critical, thorough and decisive" and issued an 8.5 million euro penalty under the Dutch anti-money laundering act, the Wwft.

The failure was not about opening accounts for the wrong people. It was about what happened after onboarding. DNB looked at how the bank watched customers it had already flagged as high risk, and concluded that the monitoring did not do its job. ABN AMRO accepted the decision and said it had deployed thousands of staff over recent years to strengthen its financial crime controls.

DetailFigure
Penalty8.5 million euros
Period examinedSeptember 2023 to September 2024
Sample files cited5 high-risk customer files
RegulatorDe Nederlandsche Bank (DNB)
Legal basisWwft (Dutch AML and CTF Act)
Decision date6 July 2026

Why did the ongoing monitoring fail?

The monitoring failed because ABN AMRO treated customer explanations as answers rather than as claims to be tested. In the five files DNB examined, concrete risk indicators were present, yet the bank did not investigate them with enough depth and closed enquiries while heightened risk and open questions remained.

The indicators were not subtle. DNB listed large cash withdrawals by private individuals, transactions involving high-risk or increased-risk jurisdictions, and large, frequent commission payments. Some files pointed to dual-use goods, items with both civilian and military applications that sit under export control, and to signals that customers might be helping to circumvent sanctions against Russia through intermediaries. The core defect, in DNB's words, was that the bank "relied to a significant extent on customer explanations without adequately verifying them against objective and verifiable information." A plausible story from a client is not evidence, and treating it as evidence is how a monitoring programme quietly stops working.

What does the ABN AMRO fine change for your obligations?

The ABN AMRO fine does not create new duties, but it sharpens how supervisors read the existing ones. It is a concrete example of a regulator penalising the quality of ongoing monitoring and source verification, not a missed onboarding check. Map it to four obligations you already hold.

First, enhanced due diligence and ongoing monitoring. Under the Wwft, the EU anti-money laundering directives, and FATF Recommendation 10, high-risk relationships require enhanced scrutiny that continues for the life of the account. Periodic review that rubber-stamps a file is not monitoring; DNB expects escalation when indicators cluster. If the boundary between these regimes is unclear, our primer on the difference between KYC and AML sets out where each obligation sits.

Second, source of funds and source of wealth. The decision turns on unverified customer explanations. Verifying source of funds means corroborating a claim against objective evidence, such as documents, registry data, or a verified identity, rather than recording what the customer said and moving on.

Third, sanctions and export-control screening. The dual-use and Russia-circumvention signals mean sanctions screening cannot stop at name matching. It has to reach the economic substance of a transaction, including counterparties, goods, and routing through intermediaries.

Fourth, alert handling and record-keeping. Closing an alert while uncertainty persists is the specific behaviour DNB punished. Your audit trail must show why an enquiry was resolved, not merely that it was closed.

What is still uncertain about the ABN AMRO fine?

The open question in the ABN AMRO fine is why a supervised bank that paid 480 million euros in 2021 was still failing ongoing monitoring in 2024. Remediation programmes are expensive and slow, and this decision suggests fixes did not reach every high-risk portfolio in time.

There is also a scale question. At 8.5 million euros the ABN AMRO fine is a fraction of the 2021 settlement, which reflects that this is a targeted DNB administrative penalty over a defined period, not a criminal settlement over years of conduct. Compliance leaders should not read the smaller number as a smaller warning. The heavier risk is reputational and supervisory: a second finding narrows a bank's room to argue that shortcomings were historic.

A further uncertainty is whether other institutions carry the same defect. If a bank of ABN AMRO's remediation budget still over-relied on customer explanations, thinner-resourced firms almost certainly do, and DNB now has a template for finding it. The engineering burden of fixing this, rebuilding monitoring logic and source-of-funds evidence at scale, is real and often underestimated.

How does this compare with earlier Dutch AML penalties?

Against ING's 775 million euro settlement in 2018 and ABN AMRO's own 480 million euros in 2021, the 8.5 million euro ABN AMRO fine is small in money but consistent in theme. Dutch supervisors have spent a decade penalising the same weakness: banks that know a customer is risky but fail to keep watching and verifying. The pattern, not the euro figure, is the signal.

The 2018 ING settlement of 775 million euros and the 2021 ABN AMRO settlement of 480 million euros were criminal resolutions covering years of systemic failure across client acceptance, transaction monitoring, and exit. The 2026 penalty is narrower: an administrative fine over a single year and a subset of files. Read together, they show a supervisor that keeps returning to ongoing monitoring and source verification as the weak points, regardless of how much a bank has already paid or promised to fix. The theme crosses borders: Sweden's regulator recently fined Ikano Bank over risk-assessment failures, and a US settlement showed EagleBank penalised for years of ignored monitoring signals.

CaseYearAmountAuthorityCore failing
ING2018775 million eurosPublic Prosecution ServiceSystemic AML failures, 2010 to 2016
ABN AMRO2021480 million eurosPublic Prosecution ServiceAcceptance, monitoring, exit, 2014 to 2020
ABN AMRO20268.5 million eurosDe Nederlandsche BankOngoing monitoring of high-risk clients

How should compliance teams respond?

Start by pressure-testing the assumption at the centre of this case: that a customer's explanation is enough. Pull a sample of high-risk files and ask whether each source-of-funds conclusion rests on independent evidence or on what the client asserted. Then check whether your alert-closure records show reasoning, not just outcomes, and whether sanctions screening reaches goods, counterparties, and intermediaries rather than names alone. Finally, confirm that a high-risk classification triggers monitoring that actually escalates, rather than a calendar review that never changes the rating.

The deeper fix is to reduce how much you rely on self-asserted data in the first place. Zyphe verifies identity by reading the NFC chip in a passport or ID to ICAO 9303 and eIDAS standards with two-step liveness and no image upload, so a customer's claimed identity is checked against cryptographic evidence rather than a story. Personal data is sharded across a decentralised network with no central honeypot, and a reusable KYC credential lets a verified customer re-present without repeating the whole process. You can see how the verification flow works, or, if replacing unverified explanations with verifiable evidence is on your roadmap, book a demo.

The bottom line

The ABN AMRO fine is small in euros and large in meaning. A well-resourced bank, years past a landmark settlement, was still accepting customer explanations in place of evidence and letting high-risk files drift. For any team running KYC and AML, the lesson is that onboarding is the easy part. The durable risk sits in ongoing monitoring and source verification, and the fix is to anchor decisions in data you can prove rather than stories you were told.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

DNB found that ABN AMRO performed inadequate customer due diligence on a portion of its high-risk customers between September 2023 and September 2024. The bank's ongoing monitoring was not critical or thorough enough, and it relied on customer explanations without verifying them against objective evidence. DNB imposed an 8.5 million euro penalty under the Wwft.

It is far smaller. In 2021 ABN AMRO paid 480 million euros to settle a criminal money laundering case covering 2014 to 2020. The 2026 penalty of 8.5 million euros is a targeted administrative fine from DNB over a single year and a subset of files, so the figures are not directly comparable in scope.

It confirms that supervisors treat monitoring after onboarding as a live obligation. Flagging a customer as high risk is not enough; the firm must keep testing indicators, escalate when they cluster, and avoid closing enquiries while material uncertainty remains. Weak ongoing monitoring, not a failed onboarding check, drove this penalty.

Some of the sample files showed possible involvement in dual-use goods, items with civilian and military uses that fall under export controls, and signals that customers might be circumventing sanctions against Russia through intermediaries. DNB faulted the bank for not investigating these signals with enough depth rather than for a confirmed breach.

Verify source of funds and identity against objective evidence rather than customer statements, document the reasoning behind every alert closure, and make high-risk classifications trigger monitoring that genuinely escalates. Reducing reliance on self-asserted data, including through verified digital identity, closes the exact gap DNB penalised.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo