What 2025's AML Enforcement Data Actually Reveals About Where Screening Fails

A corrected look at 2025's AML enforcement year, using verified Fenergo, OFAC, NYDFS, CSBS, UKGC, and Institute for Financial Integrity data to show that global fines fell for the second straight year, even as enforcement pivoted sharply away from banks and onto crypto exchanges, fintechs, and gambling operators, and what each major action reveals about a distinct compliance control failure.

Basit Nayani
,
August 5, 2026

Global AML enforcement fell for the second consecutive year in 2025, to $3.8 billion, down from $4.6 billion in 2024 and $6.6 billion in 2023. Not a single US bank faced a major AML or sanctions penalty in 2025…the first time that has happened in more than two decades. Crypto exchanges, money transmitters, fintechs, and gambling operators absorbed nearly all of the enforcement volume. 

This begs the question: Who are regulators actually watching, and why.

Why the numbers might be wrong…

According to a Norton Rose Fullbright commentary, global AML fines hit $10.4 billion in 2025. While this number has since been copied across dozens of compliance blogs, it doesn’t quite align with the primary tracking data.

Fenergo, the industry's standard source for aggregated enforcement figures, reports that penalties for AML, KYC, sanctions, and customer due diligence failures totalled $3.8 billion globally in 2025, down from $4.6 billion in 2024 and $6.6 billion in 2023 - a second consecutive decline, and not one that was evenly distributed. North American penalties fell 58 percent year over year, while EMEA penalties rose 767 percent and APAC penalties rose 44 percent, driven largely by the conclusion of long-running European investigations. The single largest individual penalty of the year, $985 million, was issued by French authorities against a Swiss bank over AML failings.

In other words, enforcement didn’t get lighter, but it did get redirected. 

{{snippets-guide}}

Examining the four failures

Most year-end enforcement roundups list fines in descending order by size, treating "AML fine" as a single category This obscures the fact that 2025's largest actions represent four distinct kinds of control failure. 

Threshold misconfiguration

NYDFS's April 2025 consent order against Block, Inc. centered on a key failure: Bitcoin wallet screening configured to alert only above 1 percent exposure to terrorism-connected funds and to block only above 10 percent. The order states directly that any amount of funds transferred to terrorism-connected wallets is illegal, and that setting alert thresholds above zero without a documented risk-based justification falls short of the regulatory requirement. Block paid $40 million to NYDFS for this specific failure. Even though Block had a vendor and a compliance team, the tool was set up wrong.

Ownership resolution

OFAC's enforcement action against GVA Capital Ltd., a San Francisco-based venture capital firm, produced the year's largest sanctions-specific penalty at $216 million, for knowingly managing investments on behalf of a sanctioned Russian oligarch. In other words, they failed to resolve beneficial ownership through layered fund structures, the kind of gap that name-based screening against a sanctions list won’t catch on its own.

Scale and backlog

In a separate January 2025 action, a coalition of 48 state financial regulators fined Block $80 million over Bank Secrecy Act and AML program deficiencies tied to Cash App, distinct from the NYDFS matter three months later. This settlement is frequently and incorrectly conflated with a $175 million CFPB settlement announced the same week, which addressed a different problem entirely: weak fraud investigation and consumer redress practices on Cash App, not AML screening. Treating the $175 million CFPB figure as an AML fine overstates the AML-specific total (which is $120 million across NYDFS and the states) and understates how much of Block's 2025 regulatory exposure was actually about fraud handling rather than money laundering controls. 

Risk re-categorization

The UK Gambling Commission fined Platinum Gaming Limited, operator of Unibet.co.uk, £10 million in October 2025 for AML and social responsibility failings, its second penalty in two years following a £2.9 million fine in 2023. The specific finding was that customers previously blocked or self-excluded on an affiliated platform were able to open new accounts and gamble, because the AML policy lacked clarity on how a customer's prior risk history should carry forward into a new relationship. This is a customer due diligence continuity failure, not a screening-at-onboarding failure. The customer had already been flagged once. The system did not remember.

Four fines, four different root causes: threshold calibration, ownership resolution, operational scale, and risk continuity. A vendor or program that solves one of these does not automatically solve the others.

The Bank That Wasn't Fined

The most striking finding in the 2025 enforcement data is what did not happen. According to the Institute for Financial Integrity's review of the year's AML/CFT and sanctions actions, not one bank faced a major US penalty for AML or sanctions violations in 2025. If the pattern holds through year-end, it will be the first time in over 20 years that no bank appears among the major US enforcement actions.

Instead, US enforcement activity concentrated almost entirely on non-bank financial services. Crypto exchanges accounted for by far the largest share of AML/CFT penalties at $927.5 million, followed by money transmitters at $161.2 million, securities firms at $46.9 million, and casinos at $32.3 million. 

Sanctions-specific penalties totalled over $238 million, led by the GVA Capital case. The pattern also extended to state-level coordination: in July 2025, five state regulators jointly fined Wise US $4.2 million over suspicious activity reporting deficiencies and transaction monitoring data integrity issues, a smaller but structurally similar action to the Block settlement earlier in the year.

This proves that supervisory attention has shifted to the sectors where growth has outpaced compliance maturity, crypto, fintech, and gambling, sectors that in many cases built consumer-facing products faster than they built the AML infrastructure to match.

Why the Compliance-Maturity Gap Is the Real Enforcement Target

Read across the four failure types and the sector data together, and a single thesis holds up better than "enforcement is intensifying" or "enforcement is easing." Regulators in 2025 were applying pressure precisely where program maturity had not caught up with product growth.

Block's own NYDFS order makes this argument explicitly about itself: the failures the regulator identified date to the period of Cash App's most rapid user growth, when the platform's compliance program had not scaled proportionally to its user base. 

Platinum Gaming's repeat penalty tells a similar story at a different scale, a known risk (customers who had already triggered account closures elsewhere) was not carried forward into a new onboarding decision. GVA Capital's case shows the same pattern in a professional services context, a firm whose ownership-resolution capability had not kept pace with the sophistication of the structures it was screening.

For a compliance leader evaluating their own exposure, the useful question to ask is "which of these four failure modes does my program most resemble, and is my screening infrastructure's sophistication keeping pace with how fast my customer base or transaction volume is growing." 

A program that has not revisited its match thresholds since launch, that resolves beneficial ownership manually and inconsistently, that lacks the throughput to clear its alert queue at current volume, or that does not carry customer risk history forward across product lines, is exhibiting one of the exact patterns that produced 2025's largest penalties.

Where 2026 Enforcement Is Likely to Concentrate

Several structural changes suggest the sector redirection seen in 2025 will continue rather than reverse. The EU's new Anti-Money Laundering Authority is moving toward direct supervisory authority over a subset of high-risk entities, which will shift more enforcement weight toward Europe regardless of what US regulators do. FATF's ongoing work on Recommendation 16 continues to push payment transparency requirements toward real-time screening at the point of transaction, raising the bar for what counts as an adequate control in the payments sector specifically.

Enforcement outside traditional financial services also bears watching. UK law firms faced record AML penalties from the Solicitors Regulation Authority and Solicitors Disciplinary Tribunal in 2025, with six-figure fines for gaps in firm-wide risk assessments, client and matter risk scoring, and PEP identification, a signal that professional services firms without dedicated compliance infrastructure are increasingly exposed to the same scrutiny previously reserved for regulated financial institutions.

The throughline for 2026 planning is the same one 2025's data supports: enforcement follows growth that has outpaced controls, wherever that growth is happening.

2025 Enforcement Actions Mapped to Control Failure

Enforcement action

Amount

Underlying control failure

NYDFS v. Block, Inc. (April 2025)

$40 million

Threshold misconfiguration: alert and block thresholds set above zero tolerance without documented risk-based justification

OFAC v. GVA Capital Ltd.

$216 million

Ownership resolution: failure to identify sanctioned beneficial ownership through layered fund structures

48-state coalition v. Block, Inc. (January 2025)

$80 million

Operational scale: AML program capacity did not scale with transaction and user growth

UK Gambling Commission v. Platinum Gaming Ltd.

£10 million

Risk continuity: prior customer risk history not carried forward into new account decisions

State regulators v. Wise US, Inc. (July 2025)

$4.2 million

Data integrity: suspicious activity reporting and transaction monitoring data quality gaps

A program exhibiting more than one of these patterns is looking at a compliance infrastructure that has not been re-evaluated since it was first built, which is the exact condition every action in this table shares.

Our Vendor Selection Guide covers how to evaluate whether a screening provider's threshold configuration, ownership-resolution capability, and monitoring throughput can actually keep pace with your growth, rather than lagging behind it the way each of the programs in the table above did.

{{snippets-case}}

Final thoughts

The four failure modes in this year's enforcement data (threshold misconfiguration, ownership resolution, operational scale, and risk continuity) aren't sector-specific, but show up wherever a compliance program's sophistication hasn't kept pace with its growth. 

It doesn’t matter whether you operate a business in fintech, banking, gaming or crypto; it's which of these four patterns your own screening infrastructure is closest to.

sanctions.io is a highly reliable and cost-effective solution for real-time screening. AI-powered and with an enterprise-grade API with 99.99% uptime are reasons why customers globally trust us with their compliance efforts and sanctions screening needs.

To learn more about how our sanctions, PEP, and criminal watchlist screening service can support your organisation's compliance program: Book a free Discovery Call.

We also encourage you to take advantage of our free 7-day trial to get started with your sanctions and AML screening (no credit card is required).

New Sanctions Screening Guide
Download our free Sanctions Screening Guide
Download our FREE Sanctions Screening Guide and learn how to set up an effective sanctions screening process in your organization.
Download our FREE Sanctions Screening Guide and learn how to set up an effective sanctions screening process in your organization.
New Case Study
Screening Vendor Selection Guide - The Top 5 Features to Look Out For
Discover how technology companies streamline global sanctions compliance with sanctions.io
Discover the Top 5 features to look for in a screening vendor using our Vendor Selection Guide.
Basit Nayani
With experience in digital marketing, business development, and content strategy across mainland Europe, the UK and Asia, Basit Nayani joined the team as Head of Marketing & Growth in 2025.
Enjoyed this read?

Subscribe to our Newsletter right now and never miss again any new Articles, Guides and more useful content for your AML and Sanctions compilance.

Success! Your email has been successfully registered for our newsletter.
Oops! Something went wrong while submitting the form.