This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
The first few months of 2025 delivered a sharp warning to fintech firms across the globe as four major players – OKX, Robinhood, Block and Revolut – were hit with a combined total of over half a billion dollars in penalties tied to anti-money laundering (AML) failures. These arenโt fringe cases or minor firms. Theyโre well-funded businesses that have extensive compliance resources. But none of that spared them from the consequences of flawed compliance programmes.
What stands out is how familiar the problems are: missed red flags, AML policies that didnโt reflect how the business actually worked, and systems that couldnโt keep up with day-to-day operations.ย
Just last year, TD Bank faced a $3 billion penalty after pleading guilty to conspiracy to commit money laundering, marking the largest such case against a bank in US history. Similarly, in the UK, Starling Bank was fined nearly ยฃ29 million by the Financial Conduct Authority (FCA) for its “shockingly lax” financial crime controls.
Cases of AML non-compliance continue to make headlines, reminding us time and again of the importance of maintaining effective compliance programmes, especially as firms scale and diversify their offerings.
So, where are fintechs continuing to fall short?
OKX fined $500m after allowing more than $1tn of transactions unchecked
In February, OKX pleaded guilty to violating US AML laws and was fined $500 million after failing to implement adequate AML processes and soliciting American customers without proper registration.
From 2018 to early 2024, the Seychelles-headquartered firm facilitated more than $1 trillion in transactions by American customers, even though its international entity wasnโt registered in the United States. It was later discovered that OKX was used by a significant number of customers to move the proceeds of suspected criminal activity, with over $5 billion in transactions flagged as suspicious or linked to illicit funds.
Despite policies against American users, OKX allowed retail customers to open accounts, transfer funds and trade without completing necessary procedures. In some cases, OKX employees were found to have advised customers on how to bypass KYC (Know Your Customer) processes and encouraged the use of VPNs to conceal their locations.
The company pleaded guilty to operating an unlicensed money transmitting business and has agreed to hire an external compliance consultant until February 2027 to improve its practices.
One of the clearest messages from the OKX case is that AML policies on paper are meaningless if they aren’t followed through in practice. It’s not enough to have client onboarding rules and regulatory requirements sitting in a manual or buried in onboarding documents. Staff must be equipped with the right tools and knowledge, and regularly reminded that circumventing AML compliance controls puts the whole business at risk.
But beyond policies and procedures, the bigger issue is culture. If compliance is seen as merely an administrative burden, rather than a core component of decision-making during customer-facing interactions and onboarding, it becomes a ticking time bomb.
Compliance teams should regularly audit not just systems and processes as standard, but also understand employee knowledge, behaviour and attitudes. The OKX case shows just how dangerous it can be when a companyโs internal culture and its employees become careless about compliance obligations – and how expensive such a disconnect can be when it surfaces.
Robinhood handed $26m fine for violating multiple FINRA rules
In March, the popular US-based trading platform, Robinhood, found itself facing a $26 million fine from the Financial Industry Regulatory Authority (FINRA) for failing โto establish and implement reasonable anti-money laundering programs, which caused the firm to fail to detect, investigate or report suspicious activityโ.
Robinhoodโs violations included not detecting suspicious activity, failing to verify customer identities and ignoring system red flags. FINRA found that the firm lacked reasonable customer identification procedures, allowed thousands of accounts to be opened without properly verifying identities, and failed to act on signs of manipulative trading and suspicious money movement. Even red flags related to account takeovers by hackers and misleading social media promotions went unchecked.
The enforcement letter issued to Robinhood by FINRA highlighted some alarming issues. The platform allowed thousands of accounts to be opened without verifying identities as required. Such blatant failure to verify customers accurately can lead to serious risks, including money laundering, fraud and other financial crimes.ย
For fintechs, especially those handling high customer onboarding volumes, this is a clear reminder that identity verification and KYC are core to building trust and managing risk. If you donโt know who your customers are, you canโt assess their risk, you canโt monitor their behaviour effectively, and you canโt act quickly when something doesnโt look right.
Blockโs $40m settlement for AML and KYC failures
In early April, Block, the parent company of Cash App, agreed to pay a $40 million fine to New York’s Department of Financial Services (NYDFS) for failing to adequately manage AML measures and KYC compliance.
The NYDFS investigation revealed that Block’s compliance infrastructure failed to keep pace with the rapid growth of Cash App, particularly after the introduction of Bitcoin transactions in 2018. The regulator identified critical lapses, including โinadequate customer due diligence, failure to implement sufficient risk-based controls designed to prevent money laundering and illicit activity, and failure to effectively and timely monitor transactionsโ.
An internal investigation uncovered over 8,000 Cash App accounts linked to a Russian criminal network, further highlighting the gaps in Blockโs KYC and onboarding practices. The company also agreed to hire an independent monitor as part of the settlement.
Cash App is projected to hit 61.2 million users in the US by 2027 (an increase of 15.7 million users from 2023) and with an estimated $283 billion of inflows in 2024, Block’s case demonstrates the consequences of inadequate customer due diligence (CDD) and the importance of strong compliance oversight, especially when firms are growing at remarkable rates.ย
Many fintech firms will be all too aware of the challenges faced by Block: rapid growth, product expansion and the pressure to scale without friction. But growth isnโt an excuse for poor AML controls.ย
Blockโs compliance framework didnโt evolve at the same pace as its user base or its product offerings. When Bitcoin functionality was added, the systems built to monitor and flag risk didn’t keep up.
Firms must ensure that their compliance functions keep pace with company growth and that they have effective systems to detect and prevent financial crimes. Regularly ask yourself: do our controls match our risks? Are our systems keeping up with our growth?
When the risk profile shifts, the compliance and onboarding process has to shift with it.
Revolutโs record-breaking โฌ3.5m fine over money laundering prevention failures
Just a day after Blockโs $40 million fine, Lithuania’s central bank imposed a โฌ3.5 million fine on Revolut Bank UAB. It marked the largest penalty ever issued by the regulator, following a routine inspection that identified serious deficiencies in the fintech’s AML controls.ย
Specifically, the central bank found that Revolut had “violations and shortcomings in the monitoring of business relationships and operations,” leading to instances where the bank did not adequately identify suspicious activity and transactions. While no confirmed cases of money laundering were found, the inspection highlighted the need for big improvements in Revolutโs existing AML procedures.
Revolutโs case emphasises the importance of thorough customer due diligence (CDD) at the outset of any business relationship. Fintech companies must implement effective Know Your Business (KYB) procedures to ensure that they properly understand who their corporate clients are. This includes verifying the identity of directors and beneficial owners, understanding the nature of their business, and continuously monitoring their risk profiles and transactions for signs of suspicious activity or increased risk of financial crime.
Whatโs more, the fact that Revolut faced scrutiny for failing to appropriately monitor their clients shows how ongoing scrutiny of business relationships is vital. Client risk profiles can change dramatically from the beginning of a commercial relationship, increasing risk and the threat of financial crime.ย
AML compliance doesnโt stop at onboarding. Itโs an ongoing process that depends on continuous, real-time monitoring. Changes in a customerโs status such as new sanctions, negative media coverage, shifts in directorship, unusual transaction patterns or signs of political exposure can happen at any time. Failing to monitor these developments puts firms at risk of overlooking illegal activities, which could lead to financial crime, regulatory fines, reputational damage or even loss of operating licences.
Also from our Opinions section