Regulatory Fine

Regulatory Fine

A regulatory fine is a financial penalty a regulator imposes on a firm for breaking the rules. In anti-money laundering, weak controls and sanctions breaches have produced some of the largest fines in history, running into billions of dollars.

Key takeaways

  • A regulatory fine is a penalty a regulator imposes for breaking the rules.
  • AML and sanctions failures have led to multi-billion-dollar fines.
  • BNP Paribas paid about $8.9 billion for sanctions breaches in 2014.
  • Binance paid about $4.3 billion for AML and sanctions failures in 2023.
  • TD Bank paid about $3.09 billion for AML failures in 2024.
  • A fine is often only part of the cost, alongside remediation and reputational damage.

$8.9B

BNP Paribas penalty for sanctions violations, 2014

Source: US Department of Justice

$4.3B

Binance penalty for AML and sanctions failures, 2023

Source: US Department of Justice

$3.09B

TD Bank penalty for AML failures, 2024

Source: US Department of Justice

What is a regulatory fine?

A regulatory fine is money a firm is ordered to pay for breaking rules a regulator enforces. In compliance, it is the most visible consequence of getting things wrong, and often the one that makes the news.

Fines are not taxes or fees. They are penalties, imposed after a failure, meant to punish the firm and warn others. In anti-money laundering, they have reached sums that would have seemed unthinkable a generation ago.

The failures behind them are usually about controls. Read more: the breakdowns often trace back to a weak AML compliance program.

Why regulators fine firms

Regulators fine firms to change behavior, not just to raise money. A fine has two jobs: to punish the firm that failed, and to make every other firm pay attention.

The logic is deterrence. If weak controls cost nothing, firms would underinvest in them, so regulators make the cost of failure high enough to focus minds. A large, public fine tells the whole industry that a particular failure will not be tolerated.

Fines also signal priorities. When regulators start fining a certain failure heavily, firms know where to look in their own operations. A pattern of penalties in one area is, in effect, a public map of where regulators are turning their attention next.

What triggers an AML fine

AML fines tend to come from a familiar set of failures. Each represents a gap that let, or could have let, dirty money through.

  • Weak controls. An AML program that does not do its job.
  • Poor monitoring. Failing to watch transactions properly.
  • Missed reports. Not filing suspicious activity reports when required.
  • Sanctions breaches. Processing payments for restricted parties.
  • Weak due diligence. Onboarding customers without knowing who they are.

Often a single case involves several of these at once, which is part of why the penalties grow so large.

The biggest AML and sanctions fines

The largest penalties give a sense of the stakes. Each followed a serious, sustained failure, and each was announced by the US authorities.

In 2014, BNP Paribas agreed to pay about $8.9 billion for processing transactions that breached US sanctions on several countries. In 2023, the crypto exchange Binance was penalized about $4.3 billion for AML and sanctions failures. And in 2024, TD Bank paid about $3.09 billion after admitting sweeping AML failures, the largest penalty of its kind against a US bank.

These are the headline numbers, but similar failures produce large fines every year, well below the record level.

Get an indicative AML risk rating

See where your money laundering risk is concentrated so you can close gaps before they cost you.

Try the AML Risk Assessment →

How fines are calculated

Regulators do not pick fine amounts at random. Several factors shape the final figure, even if the exact method varies.

  • Seriousness. How bad the failure was, and how much risk it created.
  • Duration. How long the problem went uncorrected.
  • Harm. Whether dirty money actually flowed, and how much.
  • Cooperation. Whether the firm self-reported and helped, or resisted.
  • History. Whether the firm had been warned or fined before.

A firm that owns up and fixes the problem is usually treated more leniently than one that hides it and is caught.

Cooperation can make a striking difference to the final figure. Regulators often give meaningful credit to firms that self-report, hand over evidence, and remediate quickly, while treating concealment as an aggravating factor that pushes the penalty higher.

Beyond the fine

The fine is often not the biggest cost. For many firms, what follows hurts more than the payment itself.

A serious case can bring a court-appointed monitor watching the firm for years, forced spending on remediation, restrictions on growth, and lasting reputational damage. In the TD Bank case, regulators capped the bank’s US assets, limiting its ability to grow, a penalty that can outlast the fine. Customers and investors also draw their own conclusions.

Worth knowing. The dollar figure of a fine is only the visible part. Behind it sit years of remediation, the cost of a monitor, lost business, and a dent in trust that can take far longer to repair than the balance sheet. For many firms, the lesson of a large fine is that prevention would have been far cheaper than the cure.

Fines vs other enforcement

A fine is one tool among several, and often it comes bundled with others. It helps to see where it sits.

Action What it is
Regulatory fine A financial penalty for breaking the rules
Criminal charges Prosecution, which can include guilty pleas and individual liability
Business restrictions Limits on activity, such as an asset cap
Loss of license Removing the right to operate

The largest AML cases often combine a fine with a criminal plea and a monitor, which is why they land so heavily.

How firms avoid regulatory fines

Avoiding fines is, in the end, about running a program that works. A few priorities do most of the protecting.

  1. Invest in controls. Build and maintain a program that matches the firm’s risk.
  2. Monitor and report. Watch transactions and file reports when required.
  3. Screen properly. Check customers and payments against sanctions lists.
  4. Fix issues fast. Address gaps early, before they become findings.

Set out your controls in an AML policy

Generate a tailored AML policy draft that documents the controls regulators expect to see.

Open the AML Policy Generator →

Screen a customer against watchlists

Run one search across sanctions, PEP, and adverse media data to catch risks before they cost you.

Try Combined AML Screening →

Frequently asked questions

What is a regulatory fine?

A regulatory fine is a financial penalty a regulator imposes on a firm for breaking the rules it enforces. In anti-money laundering, fines follow failures such as weak controls, poor monitoring, missed reports, or sanctions breaches. They are penalties, not fees, meant to punish the firm and warn others, and in AML they have reached billions of dollars.

What are the biggest AML fines ever?

Among the largest are BNP Paribas, which paid about $8.9 billion for sanctions breaches in 2014, Binance, penalized about $4.3 billion for AML and sanctions failures in 2023, and TD Bank, which paid about $3.09 billion for AML failures in 2024. Each followed a serious, sustained failure and was announced by US authorities.

Why do regulators fine firms for AML failures?

Regulators fine firms to change behavior, not just to raise money. A fine punishes the firm that failed and warns every other firm to pay attention. The logic is deterrence: if weak controls cost nothing, firms would underinvest in them, so regulators make the cost of failure high enough to focus minds across the industry.

What triggers an AML fine?

AML fines are triggered by failures such as weak controls, poor transaction monitoring, failing to file suspicious activity reports, processing payments for sanctioned parties, and onboarding customers without proper due diligence. Often a single case involves several of these at once, which is part of why the penalties can grow so large.

How are regulatory fines calculated?

Regulators weigh factors such as how serious the failure was, how long it went uncorrected, whether dirty money actually flowed, whether the firm self-reported and cooperated, and whether it had been warned or fined before. A firm that owns up and fixes the problem is usually treated more leniently than one that hides it and is caught.

What was the TD Bank fine?

In 2024, TD Bank agreed to pay about $3.09 billion to resolve investigations into its anti-money laundering failures, the largest penalty of its kind against a US bank. Regulators also capped the bank’s US assets, limiting its ability to grow. The case followed years of weak transaction monitoring that left large volumes of activity unchecked.

Why was BNP Paribas fined $8.9 billion?

In 2014, BNP Paribas agreed to pay about $8.9 billion after admitting it processed billions of dollars of transactions that breached US sanctions on countries including Sudan, Iran, and Cuba. It was one of the largest sanctions-related penalties ever, and it signaled that even very large banks would face severe consequences for breaching sanctions.

Is a fine the only consequence of AML failure?

No. The fine is often not the biggest cost. A serious case can bring a court-appointed monitor watching the firm for years, forced spending on remediation, restrictions on growth such as an asset cap, and lasting reputational damage. For many firms, what follows the fine hurts more than the payment itself.

What is the difference between a fine and criminal charges?

A regulatory fine is a financial penalty for breaking the rules. Criminal charges are a prosecution, which can include guilty pleas and, in some cases, liability for individuals. The largest AML cases often combine a fine with a criminal plea and a monitor. Criminal action is generally reserved for the most serious and deliberate failures.

Can individuals be fined for AML failures?

Yes, in some cases. While most large penalties fall on firms, regulators and prosecutors can also pursue individuals, including compliance officers and executives, for serious failures. Individual accountability has become a growing focus, with authorities signaling that people involved in AML failures, not just their firms, can face consequences.

How can firms avoid regulatory fines?

Firms avoid fines by running a program that works: investing in controls that match their risk, monitoring transactions and filing reports when required, screening customers and payments against sanctions lists, and fixing gaps early before they become findings. Prevention is almost always far cheaper than the fine and the remediation that follow a failure.

Do regulatory fines apply outside banking?

Yes. While banks feature in the largest cases, regulatory fines for AML failures can apply to any regulated firm, including payment firms, crypto exchanges, and other financial institutions. The Binance case, involving a crypto exchange, shows that newer sectors face the same enforcement. Any firm covered by AML rules can be fined for failing to meet them.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 12, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: a regulatory fine is a financial penalty a regulator imposes for breaking the rules, and AML failures have produced some of the largest fines in history.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.