
In July 2025 the UK regulator fined a major British bank GBP 42 million across two separate notices. The two cases involved different customers, different teams, and different years. They failed in the same shape.
In the first, the bank opened a client money account for a wealth management firm. A check of the public register of authorised firms would have shown that this firm was not permitted to hold client money at all. The check was not made. Clients deposited GBP 34 million into the account. The bank later made a voluntary payment of over GBP 6 million to those clients.
In the second, a customer received GBP 46.8 million from a business already under investigation for large-scale money laundering. The bank did not gather enough information when the relationship began and did not monitor it adequately afterwards. Law enforcement warned the bank. The bank learned of police raids on the connected business. It still did not reassess its exposure.
Neither failure was a failure to have information. In the first, the disqualifying fact was on a public register, available to anyone, before the account existed. In the second, the warning arrived directly from law enforcement and the bank was told.
The information existed. It did not reach the moment where somebody acted.
That gap has a name in most control frameworks, usually something like ineffective operation, and it is the most common reason a control that looks fine on paper produces an enforcement notice. The policy said to check. The register was public. The check did not happen at the moment the account was opened.
It is tempting to read cases like this as carelessness, and that reading is comfortable because it implies your own organisation is fine as long as your people are diligent. The more useful reading is that the gap is built into how organisations are shaped.
The fact that would have stopped the decision usually lives somewhere else. It is in a different system from the one the person is working in. It is held by a different team, on a different floor, with a different reporting line. Or it arrived at a different time, months before or after the moment it became relevant, and nobody was watching for the connection.
Consider what the first case actually required. Someone opening an account would have had to know that a register existed, know that this particular customer type made it relevant, leave the onboarding workflow, run the search, interpret the result, and act on it. Every one of those steps is reasonable. The chance of all six happening reliably, every time, across every account opener, without the check being built into the workflow itself, is low.
The second case is the same shape with a longer timeline. The warning arrived. The relationship continued. Between those two facts sat an assumption that someone would connect them.
Judging this bank is easy and produces nothing. The useful exercise is locating the same shape in your own operation, and three questions do it.
| Question | What a bad answer sounds like |
|---|---|
| Which decisions depend on a fact held outside the system where the decision is made? | “They know to check the other system.” |
| When a warning arrives about an existing relationship, what specifically happens next, and who owns it? | “It goes to the team and they review it.” |
| If the check were skipped, how long before anyone noticed? | “It would come up at the next review.” |
The pattern in the bad answers is that each one describes an intention rather than a mechanism. A control that depends on somebody remembering is a control that works until the day it is needed most, which tends to be a busy day.
The reliable version of each of these moves the check into the path of the work.
The register lookup happens inside the onboarding screen, at the point of opening, with the result recorded. The warning creates a task with an owner and a deadline rather than an email to a shared mailbox. The skipped check produces an exception that surfaces somewhere, rather than silence that looks identical to compliance.
None of that requires more diligence from the people doing the work. It requires the fact to be present where the decision is made, which is a design question rather than a training question.
There is a second benefit, and it is the one that matters when the regulator arrives rather than when the mistake is avoided. A check built into the workflow produces a record of itself. A check that depends on somebody remembering produces nothing when it works and nothing when it does not, which means the two states are indistinguishable afterwards.
That is the position the bank in the first case found itself in. Establishing that the register was consulted for other accounts, on other days, by other people, is difficult when consulting it was a habit rather than a step. The absence of a record is not proof the check was skipped, and it is also not a defence. Our piece on what counts as an audit trail covers the shape of a record that survives that question.
This is worth stating plainly, because the temptation to overclaim from a case like this is real.
A pre-send communication check would not have prevented either of these failures. They were customer due diligence and monitoring failures, in onboarding and relationship management systems, and no amount of language checking touches that. Anyone telling you otherwise is selling.
What transfers is the pattern. There is a narrow instance of exactly this shape inside written communication, and it is worth naming because most organisations have it and few have closed it.
Deciding whether a sentence can safely go to a given recipient often depends on a fact held somewhere else: whether that recipient is covered by a confidentiality agreement, and what categories it protects. That fact lives in a contracts folder. The decision happens in a mail client. Between them sits the same assumption as above, that somebody will remember to connect the two.
The failure mode is identical and much smaller in consequence. Someone attaches a document, or forwards a thread whose history carries commercial terms, to a contact who never signed anything. The information that would have stopped it was in the organisation the whole time.
Bringing the agreement register into the moment of writing is the same move as bringing the public register into the moment of account opening. The check runs where the decision happens, and it leaves a record that it ran.
That is the specific thing our NDA Guard does: it holds who signed what, and evaluates the recipient list against it while the message is still open. It is a small control with a narrow scope, and the reason it works is position rather than sophistication.
Run the three questions above against your own high-consequence decisions this quarter. Wherever the answer describes an intention rather than a mechanism, you have found the shape that produced a GBP 42 million penalty at an organisation with considerably more compliance resource than yours. The fix is almost never asking people to try harder.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →