Metro Bank plc
FCA enforcement action, 2024
What failed
An automated-system gap meant accounts opened from a certain date were never monitored, leaving tens of millions of transactions unscreened.
Read the final noticeThe controls that would have caught it
These controls map directly to this failure. Open any one in the Control Builder to set your own thresholds, owners and systems, then export an implementation-ready spec.
In short, the firm needed
- End-to-end coverage testing of transaction monitoring
- Reconciliation between the onboarding and monitoring populations
- Alerting on accounts excluded from monitoring
- Independent assurance over monitoring coverage
Transaction-Monitoring Scenario Coverage Assurance
DetectiveTransaction Monitoring
Checks that the firm's monitoring rules actually cover the risks the firm faces, so no major money-laundering pattern is left with no rule watching for it.
- Starting threshold:
- Zero unmapped assessed risks and zero in-scope product/channel populations missing from TM data feeds; any single coverage gap is an exception requiring a remediation plan with an owner and date.
- First-line owner:
- TM / Detection Engineering Lead (scenario estate owner)
Transaction-Monitoring Threshold Tuning
CorrectiveTransaction Monitoring
Regularly tests and adjusts monitoring rule settings so the firm catches real risk without drowning analysts in pointless alerts, with evidence for every change.
- Starting threshold:
- Trigger a tuning review for any scenario whose true-positive yield falls below 5% (over-alerting) or whose below-the-line sample shows any productive (SAR-worthy) activity in the just-missed band (under-alerting); each change requires simulated impact and documented sign-off.
- First-line owner:
- TM Optimisation / Detection Engineering Analyst
Onboarding Fraud & Identity Controls
PreventiveCustomer Due Diligence
At sign-up the firm checks the applicant is a real, unique person using their genuine identity and device, blocking fake, stolen and bulk-created accounts before they open.
- Starting threshold:
- Decline on failed identity verification or failed liveness; route to manual review when the fraud score is in the top 5 percent or when 3 or more applications in 24 hours share a device fingerprint, residential address or funding instrument.
- First-line owner:
- Onboarding / Fraud Operations team
Monitoring Coverage Reconciliation
DetectiveOngoing Monitoring
The firm regularly proves that every account and every payment is actually being watched by its monitoring system, so nothing slips through an un-monitored gap.
- Starting threshold:
- Daily transaction-count reconciliation with a 0.1 percent variance tolerance; weekly full account-population reconciliation; zero tolerance for any account, product line or payment channel with no mapped monitoring scenario.
- First-line owner:
- Financial Crime Systems / Monitoring Operations team
Independent Assurance & Control Testing
DetectiveGovernance & Reporting
People independent of the day-to-day teams regularly test whether financial crime controls actually work, so weaknesses are found internally before a regulator finds them.
- Starting threshold:
- A risk-based assurance plan covering all high-residual-risk controls at least annually (lower-risk controls on a multi-year rotation); sampling sized to a defensible confidence level; every finding rated, owned, dated and re-tested at closure; no high-severity finding closed without independent verification.
- First-line owner:
- Control owners (remediate findings); first-line QA where it performs in-line checking
Typologies behind this case
Related enforcement cases
Next steps
Enforcement data is sourced from the FCA fines dataset. The control mapping is an analyst view of what would have addressed the failings described in the public notice, not a statement of the regulator's findings.