New York's DFS hit Swedbank with a 50 million dollar penalty for withholding Baltic subsidiary and Panama Papers data from its regulators. What it means.
Table of contents
The Swedbank NYDFS penalty is a 50 million dollar settlement, signed on 15 July 2026 and approved by New York's financial regulator on 16 July 2026, over the bank withholding information about its Baltic subsidiaries' links to the Panama Papers. The regulator punished the concealment itself, not the underlying money laundering, across responses spanning 2016 to 2019.
- New York's Department of Financial Services (DFS) secured a 50 million dollar civil penalty from Swedbank AB and its New York Branch for failing to produce responsive information to three special-report requests.
- The violation is not money laundering. It is the deliberate carve-out of the bank's Estonia, Latvia and Lithuania subsidiaries from what DFS asked for.
- A compliance officer wrote, in an internal message quoted in the consent order, that removing the Baltics from scope was the point.
- The order cites New York Banking Law section 125(3), the transparency duty that a foreign bank branch owes its host regulator.
- It is the third public enforcement action against Swedbank tied to its Baltic operations, after a 2020 Swedish fine and a 2023 OFAC settlement.
What did the Swedbank NYDFS penalty actually punish?
The Swedbank NYDFS penalty punishes a failure to cooperate, not a failure to detect crime. DFS found that when it asked Swedbank about its exposure to the Panama Papers, the bank answered as if only its New York Branch mattered and quietly excluded its Baltic subsidiaries, where the real connections sat.
The Panama Papers, roughly 11.5 million records leaked from the law firm Mossack Fonseca on 3 April 2016, named Swedbank customers. Within days, the bank's own compliance chief told the board that Swedbank Estonia had identified clients using Mossack Fonseca as a registered agent, and that a 2015 payment by a Lithuanian customer traced to a politically exposed person. DFS opened its inquiry on 19 April 2016.
The bank's New York Branch replied on 27 April 2016 that it was unaware of relevant connections. That answer was narrowly true for the branch and materially incomplete for the group. The most damaging evidence is an internal line from the bank's then chief compliance officer, quoted in the consent order, explaining why the Baltic units were cut from a later production: "That's why I wanted to remove them out of the scope". DFS treated that as intent, not oversight.
| Fact | Detail |
|---|---|
| Penalty | 50,000,000 dollars |
| Order signed | 15 July 2026, approved 16 July 2026 |
| Regulator | New York State Department of Financial Services |
| Legal basis | New York Banking Law sections 37, 39, 44 and 125(3) |
| Conduct | Withholding responsive information across 2016 to 2019 |
How did Swedbank withhold the information?
Swedbank withheld information through three regulatory cycles, each time reading the Baltic subsidiaries out of a request that plainly covered them. The pattern matters because it turns a single lapse into a documented course of conduct, which is what elevated the Swedbank NYDFS penalty from a technical finding to a 50 million dollar settlement.
In 2018, external counsel told DFS the request covered the bank's "global operations" and that Swedbank would search its head office and global branch network. It did not. On 24 March 2018 a staffer flagged that a prior Baltic search returned many Mossack Fonseca matches, and the compliance officer replied that this was exactly why she wanted them out of scope. The March and April 2018 responses omitted the Baltics entirely and mis-stated a Swedish supervisory review as clean, when in fact the regulator had issued three improvement recommendations.
| Date | Event |
|---|---|
| 3 April 2016 | Mossack Fonseca leak names Swedbank customers |
| 19 April 2016 | DFS issues its first special-report request |
| 27 April 2016 | New York Branch replies, omits group exposure |
| 21 February 2018 | DFS issues a follow-up request |
| March to April 2018 | Bank responses exclude the Baltic subsidiaries |
| 20 February 2019 | DFS issues a third request after media reports |
| 6 March 2019 | First substantive Baltic documents produced |
What does the Swedbank NYDFS penalty change for your obligations?
The Swedbank NYDFS penalty sharpens a duty many teams treat as procedural: when a regulator requests information, the response must be complete, accurate and truthful across the whole regulated group, not just the entity that received the letter. The order rests on New York Banking Law section 125(3), the reporting-accuracy duty for foreign branches, and section 37, the Superintendent's power to demand special reports.
For customer due diligence and enhanced due diligence, the case is a reminder that adverse findings do not stay local, a point that also runs through recent broker-dealer actions such as Canaccord's record FinCEN penalty. Swedbank held knowledge of Mossack Fonseca links, politically exposed persons and foreign supervisory inquiries at head office while its branch pleaded ignorance. Under a group-wide programme, that knowledge should have surfaced to the regulator. Firms should map which entity holds which record and confirm that a request to one unit triggers a search across affiliates that share customers and compliance systems.
For record-keeping and disclosure, the lesson is to evidence scope. DFS could reconstruct exactly what Swedbank searched, what it found and what it chose not to send. Compliance teams should be able to show the same audit trail in reverse: the request, the search parameters, the responsive material and the sign-off. Characterising a foreign regulator's review as free of "adverse findings" when it carried recommendations was itself treated as a misstatement, so how you summarise other supervisors' conclusions is now a live risk.
What is still uncertain after the Swedbank NYDFS penalty?
Three things remain unresolved: whether DFS pursues the underlying Baltic money laundering, whether any individual faces personal sanction, and how firms reconcile a United States production demand with European bank-secrecy law. The consent order expressly reserves DFS's right to act on transactions or conduct that Swedbank did not disclose, so the Swedbank NYDFS penalty may not close the file. Other agencies are not bound by this settlement either.
Individual accountability is the sharpest uncertainty. The bank dismissed the compliance officer and its former chief executive, and most of the board was replaced, yet the order itself names no individuals and imposes no personal bars. Regulators increasingly pursue named compliance leaders, and the quoted internal messages are the kind of evidence that supports that. Whether any authority follows the paper trail to a person is unresolved.
There is also a genuine scope tension for honest firms. A regulator's request can be ambiguous, and reading it narrowly is sometimes defensible rather than evasive. The safe reading after this case is to raise scope questions with the regulator in writing rather than resolve them unilaterally and silently. Cross-border data and bank-secrecy rules complicate that, because producing Baltic subsidiary records to a United States regulator can collide with local privacy law, and the order offers no guidance on squaring the two.
How does the Swedbank NYDFS penalty compare with past fines?
The Swedbank NYDFS penalty is smaller in dollars than the bank's earlier sanctions but distinct in kind, because it targets candour toward a regulator rather than transaction monitoring. Set against precedent, 50 million dollars for withholding information is a substantial figure, and it lands on a bank that has already paid heavily for the same Baltic operations.
| Date | Authority | Amount | Basis |
|---|---|---|---|
| March 2020 | Swedish FSA (Finansinspektionen) | SEK 4 billion (around 390 million dollars) | AML control failures in Baltic operations, 2007 to 2019 |
| June 2023 | OFAC (US Treasury) | 3,430,900 dollars | 386 apparent Crimea sanctions breaches via the Latvian unit |
| July 2026 | NYDFS | 50,000,000 dollars | Withholding responsive information from the regulator |
The through-line across all three is the same set of Baltic subsidiaries and the same underlying problem: a group that treated non-resident, offshore-heavy business as someone else's risk, the same failure mode behind older bank cases like the EagleBank BSA settlement. Reducing how much sensitive customer data any single entity holds, and how much of it must be handed around during an inquiry, is one structural way to shrink that surface.
How should compliance teams respond?
Treat every regulatory request as group-wide by default, and confirm scope in writing before you narrow it. Build a defensible audit trail that records the request, the entities searched, the responsive material and the approver. Reconcile how you describe other supervisors' findings, because understating a foreign regulator's recommendations was itself penalised here. Escalate any decision to exclude an affiliate to senior legal, not to a compliance inbox.
Structurally, the exposure grows with how much personal and KYC data each entity hoards. Zyphe takes a different route: identity is verified once across a distributed network of 60,000 plus nodes, personal data is sharded so no single node holds a complete record, and the customer keeps the key, so there is no central honeypot to withhold, leak or misreport. That model, explained in how Zyphe works and applied in our KYB software, means verification results carry a per-region audit trail you can hand a regulator without shipping raw customer files across borders. To see how that maps to your onboarding stack, book a demo.
The bottom line
The Swedbank NYDFS penalty is a warning about candour, not detection. A bank can pass its transaction-monitoring reviews and still face a heavy penalty for how it answers a regulator. For teams running KYC and AML programmes, the takeaways are to treat requests as group-wide, to evidence exactly what was searched and sent, and to raise scope disputes openly. The less sensitive data any single entity holds, the smaller the temptation, and the risk, of getting that answer wrong.
Cited sources
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.