Every enforcement notice tells the same story: the business changed, the controls didn't, and someone inside knew about the gap for years. This pattern appears whether the regulator is the FCA, NYDFS, or OCC, whether the institution is a century-old bank or a three-year-old fintech, and whether the fine is £29 million or $125 million.
The myth that rapid growth inevitably breaks compliance systems protects no one. What breaks systems is the choice to keep running them unchanged after the business they were built for no longer exists. Here are the myths that keep that choice looking defensible.
Myth 1: "Our screening system is working, we're getting alerts"
Reality: Alerts prove the system is running, not that it's configured correctly.
Starling Bank's screening system ran from July 2017 to January 2023, screening customers against 39 of the 3,088 designated persons on the UK sanctions list. It produced no sanctions alerts for individual customers during that period, even after the invasion of Ukraine when new designations were added. The system appeared to be working because it was processing records and producing output.
The only way to know if your screening catches what it should is to test it against a known match. Put a designated party through the live flow and confirm it alerts. Check that the number of records screened matches the number of customers on file and the number of payments your systems processed. Verify that the lists loaded into your screening engine match the source lists your vendor delivered, not just that the feed arrived on time.
Myth 2: "We'll fix it in the next system upgrade"
Reality: Regulators measure the time between identifying a gap and closing it, and they penalize institutions that keep operating while the clock runs.
TD Bank's AML investigators asked for Zelle-specific transaction monitoring rules in October 2020. The product had launched in 2017. The rules went live in 2023. In between, AML managers were told that new scenario development counted as regrettable spend unless it was absolutely required. That three-year delay is now quoted in a public consent order from the OCC.
The FCA added £10 million to Monzo's penalty specifically because the bank onboarded more than 34,000 high-risk customers while under a restriction it had agreed to. Starling did the same, opening accounts for 49,000 high-risk customers between September 2021 and November 2023 after agreeing to stop. Both institutions documented the operational problems and chose to continue with the risk.
If you've identified a control gap, you have three choices: fix it, limit the affected activity until you fix it, or accept that the time between now and closure will be cited in an enforcement notice.
Myth 3: "The vendor delivers the list, so we're covered"
Reality: A complete list can arrive on time and your system can still screen against only part of it.
Filters applied when sanctions data loads can narrow what gets screened against while everything appears normal. A filter that keeps only entries with a domestic link, or only individuals rather than entities, or only records that match a particular format will silently exclude designations. Starling's system was set up incorrectly from the start, which is why it screened against 39 people instead of 3,088.
Your check isn't against the confirmation that the feed arrived. It's against the source list itself. Count the entries in what you received, count what loaded into your screening engine, and investigate any difference. If your vendor says they delivered 5,000 records and your system shows 3,200, the missing 1,800 aren't being screened.
Myth 4: "We did CDD at onboarding, so the customer is clean"
Reality: Customers change between reviews, and those changes don't update the record on their own.
FINRA's August 2026 findings against UBS Financial Services described retail customers with links to higher-risk countries, unexplained changes in where they lived and worked, adverse media, and possible political exposure. None of it was picked up because their risk ratings stayed low from onboarding. Low ratings meant their money movements drew less attention.
A risk rating set in 2019 doesn't describe the customer in 2025. Political roles change, controlling owners change, addresses change, and adverse media accumulates. Ongoing screening against PEP, sanctions, and adverse media sources between periodic reviews catches those changes. So does a trigger to reassess when a customer's transaction pattern shifts materially or when they notify you of a change in circumstances.
Myth 5: "Our internal audit found the issue, so we're being proactive"
Reality: Finding a gap and documenting it doesn't reduce the penalty if you don't close it.
Six state regulators fined Wise US $4.2 million in July 2025 partly for not correcting deficiencies that earlier examinations and its own audits had already found. In July 2026, the OCC denied Wise a national trust bank charter, citing longstanding AML deficiencies and management's persistent inability to manage money laundering and terrorist financing risk. The charter would have given Wise direct access to the US payment system.
FinCEN fined UBS Financial Services $125 million in August 2026, the largest Bank Secrecy Act penalty ever imposed on a broker-dealer. FinCEN had previously fined them $14.5 million in 2018 over foreign currency wire monitoring. UBS said it would fix the problems. The new order found the same failures continuing through June 2023.
Internal awareness of a control gap doesn't mitigate the enforcement outcome. It makes it worse because it shows you chose to operate with the gap open.
What to Do Instead
Ask a short set of questions when something changes, rather than waiting for the next scheduled review:
Does the screened population match the real one? The number of customer records going through screening should match the number of customers on file. When Starling corrected its configuration and rescreened existing customers, it produced roughly 48,000 alerts.
Has anyone tested it against a known match? Put a designated party through the live flow to confirm it alerts. This catches configuration errors that make the system look like it's working when it isn't.
What's the quality of the data going in? Incomplete names, missing dates of birth, addresses in one long line of free text, and empty country fields all weaken matching. The move to structured addresses under ISO 20022 is making this issue easier to see in payment flows.
Who owns each open finding, and what happens when the date slips? Enforcement notices reconstruct the internal trail, including who raised a gap and what they were told in return. TD's request for Zelle rules sat for more than two years, and the answer its AML managers received is now quoted in a public consent order.
Your controls were right for the institution that existed when they were built. Every acquisition, new product, new market, system migration, and volume threshold crossed moves the population, the data, or both. The gap between what your controls were designed for and what they're screening now doesn't close itself.



