17 August 2026
Supervisory Enforcement and Institutional Liability of EU Credit Institutions in the Field of AML and Sanctions Compliance
From isolated breaches to institutional responsibility
European Union credit institutions face a regulatory model in which liability increasingly extends beyond individual failures or identifiable unlawful transactions. Supervisors are examining whether banks have built and maintained effective systems capable of preventing money laundering, terrorist financing and sanctions circumvention.
A bank may face enforcement action even where no completed money laundering offence or sanctions violation can be established, if its customer due diligence (CDD), transaction monitoring, beneficial ownership controls or internal escalation procedures were materially deficient. The central question is not limited to whether a bank processed a particular suspicious payment. It also concerns whether the institution was organised to detect and prevent the underlying risk.
This development reflects the preventive character of EU financial crime regulation. Credit institutions are expected to identify risks before illicit funds enter or move through the financial system. That responsibility places governance, risk management and compliance culture at the centre of institutional accountability.
Money laundering and the importance of the predicate offence
Money laundering is dependent on the existence of criminal property. The proceeds must originate from criminal conduct, commonly referred to as the predicate offence. That offence may involve fraud, corruption, drug trafficking, tax-related crime, organised crime, sanctions evasion or other serious criminal activity, depending on the applicable national law.
The predicate offence matters for banks because suspicious activity rarely presents itself as a completed laundering offence. Instead, institutions must assess whether transactions, assets or business relationships may be connected to proceeds of crime. Funds generated through a predicate offence can be layered through companies, payment accounts, trade transactions, investment structures or cross-border transfers before being integrated into the legitimate economy.
EU AML rules therefore require credit institutions to take preventive steps rather than wait for a criminal conviction. They must identify customers, verify beneficial owners, understand the purpose and intended nature of business relationships, monitor transactions and report suspicions to the relevant financial intelligence unit (FIU). These duties apply even where the precise predicate offence has not been established.
This creates an important distinction between criminal liability and supervisory liability. Criminal proceedings generally require proof of an offence and the applicable mental element under national law. Supervisory enforcement may instead focus on whether the bank failed to maintain adequate controls, ignored warning signs, or did not respond appropriately to a risk that should have been identified.
The distinction explains why major enforcement cases have involved structural weaknesses rather than only proven laundering transactions. Settlements as well as substantial administrative fines demonstrate that authorities may treat failures in customer files, transaction monitoring and governance as serious institutional misconduct.
The EU AML framework is becoming more uniform
The EU AML framework developed through successive directives. The Fourth Anti-Money Laundering Directive introduced a stronger risk-based approach, while the Fifth Directive expanded transparency requirements and addressed risks linked to technological developments and virtual assets. The criminal law dimension was addressed separately through the directive on combating money laundering by criminal law.
This legislative structure produced a detailed common framework, but directives required national transposition. Differences consequently remained in domestic legislation, supervisory methods, administrative procedures and enforcement priorities.
The 2024 AML package moves towards greater uniformity. Regulation (EU) 2024/1624 establishes directly applicable rules for preventing the use of the financial system for money laundering or terrorist financing. Direct application reduces the scope for divergent national wording and implementation. It does not, however, remove every source of inconsistency. Supervisory judgment, investigative practice and national penalty systems continue to influence outcomes.
The result is a system in which the substantive obligations are increasingly European, while enforcement remains partly national. Banks operating across several Member States must therefore apply common group-wide standards while responding to different supervisory expectations.
Sanctions compliance creates a separate but connected risk
EU restrictive measures pursue foreign policy and security objectives rather than the primary financial crime objectives of AML regulation. They may impose asset freezes, prohibit funds or economic resources from being made available to designated persons, and restrict dealings in specific sectors or markets.
Their legal structure is distinctive. The Council adopts Common Foreign and Security Policy decisions under Article 29 of the Treaty on European Union, while economic and financial measures are generally implemented through regulations under Article 215 of the Treaty on the Functioning of the European Union. Those regulations are directly applicable and bind private actors, including credit institutions.
Banks must screen customers and transactions, freeze assets where required, prevent prohibited transfers and report relevant information. Sanctions lists may change rapidly, and restrictions often involve complex rules concerning ownership, control, indirect benefit and circumvention.
The practical challenge is that sanctions compliance and AML compliance use many of the same controls, but they operate according to different legal logic. AML supervision is generally risk-based and allows room for judgment. Sanctions prohibitions can be more categorical and leave less room for interpretation. A bank may therefore need to make a risk-based assessment under AML rules while applying a more prescriptive prohibition under a sanctions regulation.
Beneficial ownership and control remain critical pressure points
The assessment of ownership and control is one of the most difficult areas for credit institutions. A designated individual may not appear as the direct account holder or shareholder. The relevant relationship may instead involve a chain of companies, nominees, trusts, informal influence or indirect economic benefit.
The same facts may also have consequences under both regimes. Weak beneficial ownership verification may prevent a bank from identifying a sanctioned person behind a corporate customer. It may also prevent the bank from recognising that funds are linked to a predicate offence or suspicious laundering activity.
EU rules prohibit direct and, in relevant circumstances, indirect access to funds or economic resources for designated persons. Yet the practical indicators of control and influence may not always be applied consistently by national authorities. Banks must make detailed factual and legal assessments without possessing formal authority to determine the meaning of every uncertain concept.
This places institutions in a difficult position. Under-compliance may expose them to significant penalties, while an excessively broad interpretation may restrict legitimate business and affect customers who have not engaged in unlawful conduct.
Cross-border supervision leaves banks exposed to divergent outcomes
Supervision of AML compliance has traditionally been carried out by national authorities. Sanctions enforcement is also largely dependent on national competent authorities, despite the EU origin of the underlying restrictions.
This arrangement creates several forms of uncertainty. Authorities may differ in their assessment of customer due diligence, transaction monitoring, beneficial ownership, internal reporting and senior management responsibility. They may also apply different approaches to investigations, settlements, penalty calculation and the relationship between administrative and criminal proceedings.
The Danske Bank matter illustrates the difficulty of allocating supervisory responsibility in a cross-border banking group. Concerns connected to the bank’s Estonian branch raised questions about the respective roles of home and host supervisors. The case also showed that institutional accountability extends beyond the bank itself to the supervisory architecture responsible for identifying and addressing cross-border risks.
For a banking group, the challenge is practical as well as legal. A central compliance framework must be sufficiently consistent to manage group-wide risks, but sufficiently adaptable to meet local requirements. Where supervisory expectations conflict or remain unclear, institutions may adopt the strictest available approach across the group. That can reduce regulatory exposure, but it may also increase costs and lead to the withdrawal of legitimate services.
Over-compliance is a predictable response to uncertainty
De-risking and over-compliance are direct consequences of a liability model that combines severe penalties with uncertain standards. A bank may refuse a transaction, delay a payment or terminate a relationship not because a legal prohibition clearly applies, but because the institution considers the regulatory consequences of being wrong too serious.
This is especially common where a customer has connections to a high-risk jurisdiction, a complex ownership structure or a sector affected by restrictive measures. Enhanced checks can be appropriate, but a blanket refusal to provide services may go beyond what is necessary to manage the actual risk.
The legal framework must therefore balance effective financial crime prevention with proportionality, legal certainty and access to legitimate economic activity. The Court of Justice has repeatedly confirmed that AML and sanctions measures pursue legitimate objectives, but remain subject to fundamental rights and judicial control.
In Kadi, the Court held that restrictive measures must comply with the EU legal order and fundamental rights. Bank Mellat reinforced the need for adequate evidence, reasoning and procedural safeguards. Rosneft confirmed that restrictive measures adopted in the foreign policy context remain open to judicial review. These principles are relevant to banks because institutional compliance cannot be assessed in complete isolation from the clarity and legality of the rules being applied.
AMLA introduces a stronger European supervisory dimension
The establishment of the Anti-Money Laundering Authority marks a major change in EU financial supervision. AMLA has both direct and indirect responsibilities. It will directly supervise selected high-risk financial institutions with significant cross-border activities and coordinate national authorities responsible for the broader supervisory population.
Its mandate also includes developing common methodologies, facilitating information exchange and addressing disagreements between national supervisors. These functions are intended to reduce the differences that have historically affected enforcement and to make supervisory expectations more consistent.
AMLA is not a general EU sanctions authority. Nevertheless, its work may improve sanctions compliance indirectly. Better information exchange, more reliable ownership assessments and stronger supervision of AML controls can help banks identify sanctions risks and detect structures designed to conceal the proceeds of crime or facilitate circumvention.
Its success will depend on more than formal powers. National authorities will continue to investigate many breaches and impose many penalties. Domestic procedural rules and penalty regimes will remain important. Consistent outcomes will require common supervisory standards, effective cooperation and clear communication with the institutions subject to supervision.
What institutional liability means for banks
The emerging model of liability places the quality of a bank’s control environment at the centre of enforcement. Institutions should expect scrutiny of whether their systems are appropriate to their business model, customer base, geographic exposure and transaction profile.
A credible framework must connect customer onboarding, beneficial ownership analysis, sanctions screening, transaction monitoring, suspicious activity reporting and senior management oversight. Weakness in one area can undermine the others. For example, poor customer information may weaken both the detection of laundering linked to a predicate offence and the identification of indirect sanctions exposure.
Supervisors are also likely to examine whether alerts are investigated effectively, whether decisions are documented, whether compliance concerns reach senior management and whether known deficiencies are corrected promptly. A written policy is not enough if the bank’s systems, staffing and governance do not make the policy effective in practice.
The direction of travel is clear. Liability is increasingly institutional rather than purely transactional. Banks are expected to show that they have designed, funded, tested and improved their controls in response to identified risks.
The central challenge is consistent enforcement
The EU has developed a strong and increasingly detailed framework for preventing money laundering, terrorist financing and sanctions circumvention. The main weakness is no longer the absence of obligations. It is the uneven application of those obligations.
A directly applicable rule can still produce different outcomes if authorities interpret key concepts differently, investigate inconsistently or impose materially different penalties. AMLA may reduce this fragmentation, particularly for high-risk cross-border institutions, but it will not eliminate the continuing role of national authorities.
For credit institutions, the practical standard will remain demanding. They must prevent the movement of illicit proceeds, identify the predicate-offence risks behind suspicious activity, comply with restrictive measures and protect the institution against liability arising from weaknesses in its own organisation.
The long-term legitimacy of the EU framework will depend on maintaining both sides of that equation. Enforcement must be strong enough to deter banks from treating AML and sanctions controls as formal exercises. At the same time, supervisory expectations must be clear enough for institutions to understand the conduct required of them and precise enough to prevent liability from becoming a penalty for uncertainty itself.
Dive deeper
- Research ¦ Nikolina Djuragic, Supervisory Enforcement and Institutional Liability of EU Credit Institutions in the Field of AML and Sanctions Compliance, Stanford-Vienna European Union Law Working Paper No. 143, http://ttlf.stanford.edu. ¦ Link