
A UK digital bank agreed a requirement with its regulator: it would not open new accounts for high-risk customers until its financial crime controls improved. That is a commitment given in writing, by a firm that meant it, at a moment when the regulator’s attention was fully engaged.
Over the following two years it opened more than 54,000 accounts for around 49,000 high-risk customers.
Separately, the bank discovered in 2023 that its automated sanctions screening had been checking customers against only a fraction of the full sanctions list. It had been doing so since 2017. Six years, an automated system reporting normally, screening a small part of what everyone believed it screened.
The regulator fined the bank close to GBP 29 million, reduced from roughly GBP 41 million for settling early.
Neither was a decision. Nobody chose to breach the requirement, and nobody configured the screening system to check a fraction of the list. In both cases a control existed, was documented, was believed to be operating, and was not.
That state has a particular danger to it. An organisation with a missing control knows it has a gap and can plan around it. An organisation with a control it wrongly believes is working has no gap in its risk register, allocates no attention to it, and reports it as green.
The screening failure is the sharper illustration. An automated system produces output continuously. Output arriving on schedule reads as the system working. Nothing about a partial list check looks different from a full one unless somebody tests what the system is actually comparing against.
The bank went from roughly 43,000 customers in 2017 to 3.6 million in 2023. The regulator’s finding was that financial crime measures did not keep pace.
That phrasing is worth unpacking, because it describes something that happens to every scaling firm and rarely announces itself.
A control designed for one volume degrades at another without changing its behaviour. A manual review step that works at forty a week silently becomes a rubber stamp at four hundred. A threshold calibrated against one customer mix generates unusable noise against a different one, and the team responds by widening it. A weekly exception report that one person read carefully becomes a file nobody opens.
In each case the control still runs, still produces evidence that it ran, and still appears in the framework. What changed is whether anyone acts on the output, and that change is invisible from the control inventory.
The screening failure ran from 2017 to 2023 inside a firm with a compliance function, external auditors, and a regulator paying attention. Understanding how that is possible is more useful than assuming the people involved were inattentive.
Assurance activity tends to test whether a system is configured and running. Confirming that the screening tool is deployed, scheduled, and producing alerts is a reasonable test, and it passes in a firm checking a fraction of the list exactly as it passes in a firm checking all of it.
Testing the completeness of the reference data is a different exercise, and it is nobody’s obvious job. The compliance team owns the obligation and treats the tool as a technical matter. The technology team owns the tool and treats the list as a compliance matter. The list sits between them, and it is the part that failed.
This pattern generalises to any control that depends on reference data kept current by someone other than the person relying on it: sanctions lists, restricted lists, insider lists, approved counterparties, and the agreement registers that decide who may receive what. Each one has an owner for the mechanism and an owner for the content, and the gap between them is where silent failure lives.
The countermeasure is a positive test rather than an inspection. Insert a known item that should be caught, and confirm that it was. A control that has never been tested with something it should stop has never been tested.
The distinction that would have caught both failures is between knowing a control exists and knowing it operates.
| Assumption | Assurance |
|---|---|
| The screening system runs nightly | A known sanctioned name was inserted last quarter and the system flagged it |
| We do not onboard high-risk customers | A monthly count of accounts opened by risk band, reviewed by a named person |
| Staff escalate unusual activity | Escalation volumes tracked over time, with a view on what a fall means |
| The policy prohibits it | Exceptions to the policy are counted, and the count is not zero |
The right column has a common property: each one produces a number that can move. A control described in words can only be present or absent. A control that emits a measurement can be seen degrading, which is the only way anyone catches the slow failures.
The last row deserves a note. A control reporting zero exceptions over a long period is more often a sign that the detection has stopped working than a sign of perfect compliance. Zero is a suspicious number in an operating control, and it should trigger a test rather than reassurance.
There is a specific lesson for any firm that has given an undertaking to a regulator, agreed a remediation plan, or answered a supervisory letter with a description of what it will do.
That description is now a control you are measured against. The regulator has it in writing, it is dated, and the assessment at the next engagement is whether the operating reality matches it.
Firms routinely treat these commitments as a communication task, drafted carefully by compliance and legal, closed once sent. The bank in this case did not breach its requirement in a single decision. It breached it 54,000 times over two years, which means nothing was watching the specific thing it had promised to watch.
The practical response is to convert every commitment made to a regulator into a monitored metric on the day it is made, with a named owner and a reporting line. If a commitment cannot be expressed as something countable, it is unlikely to be something you can later prove you kept.
Step four is where the findings are. A commitment with no owner and no metric has been running unobserved for however long it has existed.
The common thread across both failures is the absence of a continuous record that the control was doing what it was believed to do. Not a policy, not an architecture diagram, an ongoing measurement.
That is the property worth insisting on in any control you buy or build, including in the narrow area we work in. A check on written communication should produce a count of how often it acted, on what, and what happened next, available to you without asking anyone. Our audit trail is designed to produce exactly that, at department level, so the question of whether the control is operating has a number attached to it rather than an assurance.
Pick your three most important controls and ask what number would fall if each one quietly stopped working. If you cannot name the number, or nobody is watching it, that control is currently in the same state as an automated screening system checking a fraction of a list. For what a defensible operating record looks like, see our piece on what counts as an audit trail.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →