Commerzbank AG
FCA enforcement action, 2020
What failed
Long-running failure to conduct timely CDD and to fix known monitoring weaknesses despite internal warnings.
Read the final noticeThe controls that would have caught it
These controls map directly to this failure. Open any one in the Control Builder to set your own thresholds, owners and systems, then export an implementation-ready spec.
In short, the firm needed
- Periodic CDD refresh with overdue tracking
- Remediation of known monitoring gaps to deadline
- Automated coverage checks for un-monitored accounts
- Senior accountability for backlog clearance
Expected Activity Profiling at Onboarding
PreventiveCustomer Due Diligence
At sign-up, ask and record what normal looks like for this customer (how much, how often, to where) so monitoring can later spot when they behave nothing like that.
- Starting threshold:
- Profile mandatory for all customers; for higher-risk customers require itemised expected monthly turnover, expected corridors and expected counterparties. Flag for review where declared turnover exceeds 3x the income/turnover implied by occupation or filed accounts, or where declared geographies include high-risk jurisdictions not explained by the stated business.
- First-line owner:
- Onboarding / KYC Operations team
Customer Risk Assessment & Rating
PreventiveCustomer Due Diligence
Score each new and existing customer for money-laundering risk from clear factors (who they are, what they do, where they are) so the firm spends most effort on the riskiest ones.
- Starting threshold:
- 3-band model: high if any override (sanctions nexus, PEP, high-risk-jurisdiction nexus per reg.33) OR weighted score >=70/100; medium 40-69; low <40. High = EDD + annual review; medium = standard CDD + biennial review; low = simplified where permitted + triennial review.
- First-line owner:
- KYC Operations / Onboarding team (with model owned by Compliance)
High-Risk Corridor & Geography Monitoring
DetectiveTransaction Monitoring
Watches payments to and from higher-risk countries and routes, and flags activity that does not fit the customer or looks designed to disguise where money is really going.
- Starting threshold:
- Any payment to/from a high-risk jurisdiction not in the customer's declared geographies; OR cumulative value to high-risk corridors > 2x declared expectation in a rolling 30 days; OR 5+ low-value payments to a single TF-risk geography in a rolling 30 days.
- First-line owner:
- Financial Crime Operations Analyst (transaction monitoring / sanctions-adjacent)
Ongoing CDD & Periodic Review
PreventiveOngoing Monitoring
Every customer's identity and risk information is refreshed on a fixed schedule so the firm never relies on stale onboarding data.
- Starting threshold:
- Periodic review cadence: high risk every 12 months, medium risk every 24 months, low risk every 36 months; review case opens 30 days before due date.
- First-line owner:
- KYC / Client Lifecycle Management team
Trigger-Based (Event-Driven) Review
DetectiveOngoing Monitoring
When something material changes about a customer, the firm reviews them straight away instead of waiting for the next scheduled review.
- Starting threshold:
- Any catalogued trigger opens a review within 1 business day; high-severity triggers (sanctions/PEP confirmed match, SAR filed, change of control, new high-risk corridor exceeding GBP 10,000 in 30 days) escalate to enhanced review the same day.
- First-line owner:
- Financial Crime Operations / KYC Refresh team
Dynamic Customer Re-Rating
DetectiveOngoing Monitoring
The customer's risk score is recalculated automatically from their real behaviour, so a customer who starts acting riskier is re-rated without waiting for a manual review.
- Starting threshold:
- Recompute scores nightly; auto-escalate the rating band when the residual score rises by 20 or more points or crosses a band boundary; require analyst sign-off before any rating downgrade takes effect.
- First-line owner:
- Financial Crime Analytics / Customer Risk team
Agent & Distributor Oversight
PreventiveOngoing Monitoring
The firm vets and keeps watch over the agents and distributors who sell or move money on its behalf, so a rogue or nested agent cannot smuggle dirty money through its rails.
- Starting threshold:
- Re-due-diligence high-risk agents annually and others every two years; flag any agent whose monthly volume rises by 50 percent or more versus its trailing 6-month average, or that transacts in a corridor not in its approved profile; cap and review any agent originating volume above the limit set in its agreement.
- First-line owner:
- Agent / Partner Management team
SAR / STR Process & Timeliness
CorrectiveGovernance & Reporting
A clear, fast route for staff to raise a suspicion, for the MLRO to decide, and for a report to reach the authorities on time without tipping off the customer.
- Starting threshold:
- Internal report acknowledged by the nominated officer within 1 business day; SAR submitted to the NCA within 5 business days of the decision to disclose; DAML requested before any consent-dependent act, with no transaction processed against a pending defence.
- First-line owner:
- Financial Crime Operations / investigators raising and drafting internal reports
Alert & Case Backlog Management
CorrectiveGovernance & Reporting
Stop financial crime alerts and cases piling up unworked by tracking how old they are, fixing the cause, and stepping in fast when the queue grows.
- Starting threshold:
- Standard alerts worked within their queue SLA (e.g. 5 business days); high-risk and sanctions items within 1-2 business days; backlog trigger at a defined threshold (e.g. >2% of open items past SLA, or any sanctions item past SLA) invoking the remediation playbook; oldest open item tracked and capped.
- First-line owner:
- Financial Crime Operations team lead (queue management and throughput)
Typologies behind this case
Related enforcement cases
Next steps
Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.