
2025 in Numbers: How Financial Crime and Enforcement Scaled in a Single Year
July 26, 2026
Monthly Digest for AML, Sanctions, Fraud and Financial Crime Professionals: Volume 5
August 2, 2026The opening months of 2026 brought important changes in anti-money laundering supervision, enforcement, sanctions controls, cyber-enabled fraud, and digital assets. This digest explains the developments compliance teams should assess and the operational questions they raise.
The EU Begins a New AML Supervisory Era
On 1 January 2026, EU-level AML responsibilities moved from the European Banking Authority to the Anti-Money Laundering Authority. AMLA is intended to coordinate financial intelligence units, support the EU single rulebook, and eventually supervise selected high-risk cross-border institutions directly.
Institutions operating across Europe should prepare for more centralized and consistent supervision while monitoring the detailed standards and implementation timetable.
FATF Updates Jurisdictions Under Increased Monitoring
At its February 2026 plenary, FATF added Kuwait and Papua New Guinea to the list of jurisdictions under increased monitoring.
Financial institutions should:
- reassess geographic exposure involving the two jurisdictions;
- review correspondent-banking and cross-border payment activity;
- document any resulting changes to risk ratings and monitoring thresholds; and
- continue applying a risk-based approach rather than treating list status as an automatic transaction decision.
FATF also drew attention to cyber-enabled fraud and digital-asset risks.
US Reporting Expands for Residential Real Estate
FinCEN’s Residential Real Estate Reporting Rule extended financial crime reporting to certain non-financed residential property transfers involving legal entities or trusts. The rule was designed to address the misuse of all-cash property purchases to conceal beneficial ownership or the source of funds.
Title companies, legal professionals, and real estate intermediaries should confirm the rule’s current effective date, their reporting role, and the transactions that fall within scope before relying on this summary.
An USD 80 Million US Broker-Dealer Penalty
In March 2026, FinCEN imposed an USD 80 million civil penalty on Canaccord Genuity LLC for Bank Secrecy Act violations.
The action highlighted recurring weaknesses:
- suspicious activity reports were not filed;
- trading activity was not monitored effectively; and
- AML governance and remediation were inadequate.
The case reinforced that broker-dealers and other non-bank financial institutions face substantial exposure when known weaknesses remain unresolved.
A UK Sanctions Screening Failure
The UK Office of Financial Sanctions Implementation fined Bank of Scotland £160,000 after funds were made available to a designated person. The original account linked the breach to a name-matching problem involving spelling differences.
The operational lesson extends beyond having a screening platform. Institutions also need reliable source data, appropriate matching logic, effective alert review, and documented escalation.
Coordinated Action Involving a Swiss Bank
US authorities proposed restricting MBaer Merchant Bank AG’s access to the US financial system over alleged links to illicit actors associated with Russia and Iran. Switzerland’s regulator, FINMA, later ordered the bank’s liquidation.
The episode illustrated how authorities in different jurisdictions may coordinate when they identify severe or systemic AML concerns.
Cyber-Enabled Fraud Drives Money Laundering Risk
Fraud schemes increasingly combine:
- phishing and social engineering;
- AI-generated impersonation and deepfake scams; and
- mule accounts used to move proceeds rapidly across borders.
These methods make coordination between fraud detection, cybersecurity, transaction monitoring, and AML investigations essential.
Stablecoins and Unhosted Wallets
Stablecoins and self-hosted wallets can allow rapid peer-to-peer value transfers outside some traditional control points. That can make ownership, source-of-funds analysis, and the tracing of subsequent transfers more difficult.
Compliance teams should assess whether they have appropriate blockchain analytics, counterparty risk data, customer due diligence, and escalation routes for crypto-related activity.
Key Actions for Compliance Teams
- Track the transition to centralized EU supervision.
- Update geographic-risk assessments when FATF list status changes.
- Confirm current real estate reporting obligations with primary sources.
- Treat data quality and governance as core control issues.
- Connect fraud and AML monitoring rather than operating them in isolation.
- Review stablecoin and unhosted-wallet exposure.
For implementation guidance, see Financial Crime Lab’s resources on AML transaction-monitoring framework, sanctions compliance programs, and crypto-asset compliance requirements.
Adapted from the Financial Crime Lab LinkedIn newsletter published on 8 March 2026.
This article is for informational purposes only and does not constitute legal, regulatory, or compliance advice. Confirm current requirements, effective dates, and enforcement details with the relevant authorities before acting.

