Regulatory Update
Everyone Reads the £44 Million Fine. Nobody Reads the £5,500 Ones.
A year of UK anti-money-laundering enforcement, with the control failure named against each case. The pattern that emerges is not the one the industry talks about: by volume, most enforcement is not about firms with bad controls. It is about firms nobody was supervising at all.
By Thomas Geater· 29 August 2026 · 9 min read
The FCA fined Nationwide Building Society £44,078,500 in December. Every compliance newsletter in the country covered it.
In the same period HMRC issued 369 penalties across its supervised sectors. The average was about £5,500. I have not seen a single one of them written up anywhere.
Both are UK anti-money-laundering enforcement. They describe almost completely different failures, and the second group is far larger. This is an attempt to put a year of it in one place, with the actual finding named against each case rather than the headline number, because the numbers are the least interesting part.
The top end: systems that existed and did not work
Nationwide Building Society, £44,078,500. Final Notice 12 December 2025. The conduct ran from October 2016 to July 2021, which is nearly five years. The FCA found breaches of Principle 3 and of the requirement to maintain adequate policies and procedures to counter financial crime risk. Two specific deficiencies are worth pulling out: ineffective systems for conducting customer risk assessments, and ineffective refreshing of customer due diligence.
Neither of those is a detection failure. A risk assessment that does not work and a CDD refresh that does not happen are both failures at the point of knowing who the customer is, months or years before any transaction gets scored.
Barclays, £42 million in total. July 2025. Two separate matters, penalised together: one relating to WealthTek, one to Stunt & Co. The FCA’s framing was poor handling of financial crime risk rather than a single systems failure.
And then 2026 went quiet. The FCA’s running total for the year to date stands at just over £16 million across all enforcement, not only financial crime. That is a collapse from the previous period, and the regulator’s own stated position is that it is running fewer investigations faster. Whether that produces better outcomes is a real question and it is too early to answer it.
The gambling sector: the busiest supervisor nobody watches
The Gambling Commission has been the most active AML supervisor in the UK by volume of action, and almost none of it reaches the mainstream compliance press.
Evolution, £4.75 million. 23 July 2026. A software and casino game host licence holder, settled following a licence review.
Petfre, operator of betfred.com, £900,000. 30 June 2026. Regulatory settlement following a licence review.
QuinnBet (Gibraltar) Limited, £609,104. A series of anti-money-laundering and social responsibility failures found on investigation.
Between May and December 2025 the Commission took regulatory action against thirteen operators for AML, counter-terrorist-financing, social responsibility, technical and hosting failures. In 2024/25 it carried out 9,700 compliance actions, up from 4,200 the year before, and one in four firms assessed failed to reach a rating of good or satisfactory.
The recurring findings it names are worth reading next to the FCA’s: persistent social responsibility failures, inadequate customer interaction, insufficient affordability assessment, and weak AML controls. Two of those four are about knowing the customer’s circumstances rather than about monitoring their transactions.
The bottom end, which is most of it
HMRC published its latest enforcement list on 9 February 2026, naming businesses that failed to meet their obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
In the six months to September 2025 it issued 369 penalties totalling £1,881,237.
Here is the number that should stop you. Three hundred and thirty-two of those 369 were for trading without AML registration.
Not for a weak risk assessment. Not for an inadequate monitoring system. For operating a regulated business without being registered for supervision at all.
By sector: estate agents took 170 penalties totalling £835,842. Accountancy service providers took 134, worth £513,930. Eleven money service businesses were fined £45,253 between them.
The largest single penalty was £104,000, for failure to apply for registration at the required time. The average penalty for failing to register was about £5,500.
The middle is empty, and that is the finding
Put the three supervisors side by side and the distribution is strange.
At one end, a handful of large institutions fined tens of millions for controls that existed, were documented, were staffed, and did not work.
At the other, several hundred small firms fined a few thousand pounds each for having no controls, because they were never in the supervisory system to begin with.
There is very little in between.
That matters because almost the entire public conversation about anti-money-laundering, including most of what I write, is about the first group. Model risk, transaction monitoring coverage, alert quality, the appropriate use of AI in due diligence. All of it presumes a firm that has a compliance function, has bought tooling, and is trying.
By volume of enforcement, that firm is the exception. The modal UK AML penalty in the last year went to an estate agent who had not registered.
I do not think this means the sophisticated end does not matter. Nationwide’s £44 million was earned across five years of a control environment that did not do what it said it did, and the sums moving through a building society dwarf anything an unregistered estate agent handles. Severity and volume are different measurements and both are real.
But it does mean something about where attention sits. The failures that generate research, conference panels and vendor products are not the failures that generate most enforcement. A market has grown up around solving the problems of firms that are already trying, because those are the firms with budgets.
What this looks like from outside the UK
One comparison, because it points the same way.
The Bank of Lithuania published four enforcement measures in 2026. Walletto UAB was fined €290,000 for AML and counter-terrorist-financing deficiencies including internal controls and provision of information to the regulator. UAB ConnectPay was fined €110,000, and the finding included failure to apply proper customer identification measures. UAB Pervesk was fined €244,000 for inadequate customer risk assessment, and temporarily prohibited from serving high-risk customers. UAB Lux International Payment System was temporarily prohibited from serving new and existing customers on 4 August while an inspection continued.
Two of those four turn on customer identification and customer risk assessment rather than on transaction monitoring or reporting.
Set that beside Nationwide’s ineffective customer risk assessment and ineffective CDD refresh, and beside the Gambling Commission’s findings on customer interaction and affordability, and a second pattern appears underneath the first.
The enforcement is moving to the front of the process. Not to whether the firm watched the money once it moved, but to whether it understood who was moving it before it did.
That is the part I would watch, and it is the part I write about, because generated identity documents and synthetic applicants attack exactly there and leave nothing behind for a monitoring system to find later.
A note on what this is
This is the first of these I have put together. It exists because I wanted the year in one place with the findings named rather than the fines, and no such thing appeared to exist.
If it is useful and you would want it periodically, say so and I will keep doing it. If nobody does, it was still worth compiling once.
Sources: FCA Final Notices and press releases; HMRC enforcement publication of 9 February 2026; Gambling Commission enforcement action reports; Bank of Lithuania enforcement notices. All figures as published by the relevant authority.
Written by
Thomas Geater
I write The Typology Files, on financial-crime compliance and what generative and agentic AI are doing to it. BSc Business Management with Finance, University of Brighton. I work independently and take on advisory and writing engagements.