The compliance-failure question that opened last week’s edition sharpened dramatically this week. Senate Finance Committee Democrats published a four-year investigation alleging that Bank of America, Deutsche Bank and JPMorgan Chase collectively delayed reporting more than $1.4 billion in Jeffrey Epstein-linked transactions across nearly two decades. OFAC widened its crypto sanctions doctrine to Iran’s rahbar and IRGC funding networks, targeting Shelbit and Aban Tether at the settlement layer. AUSTRAC took 96 crypto ATMs offline in Australia. The UK National Crime Agency is defending itself against an unprecedented lawsuit from two sitting MPs over alleged SAR leaks. And an Italian court ordered house arrests in a €33 million VAT carousel fraud built on ghost companies importing Chinese clothing. The through-line: the machinery of financial reporting itself, the SAR system, the sanctions list, the VASP register, is being tested in every direction at once, both by criminals and by the political actors who hold the machinery accountable.
On 4 August, Senate Finance Committee Ranking Member Ron Wyden released the findings of a four-year investigation alleging that Bank of America, Deutsche Bank and JPMorgan Chase violated federal anti-money laundering laws by failing to screen and report Jeffrey Epstein’s suspicious transactions in a timely manner. Reuters reported that Bank of America failed to properly screen $170 million in payments from Leon Black to Epstein, Deutsche Bank delayed reporting more than $250 million in suspicious wire transfers including payments to women in Russia and Eastern Europe, and JPMorgan delayed reporting over $1 billion in transfers. The American Prospect added that Wyden intends to introduce legislation requiring senior managers to sign annual attestations for high-net-worth accounts, imposing individual fines and prison sentences for late SAR filing, and clawing back bonuses paid to executives responsible for BSA violations. American Banker noted that JPMorgan filed 469 SARs in August 2019 covering $1.1 billion in wire transfers after Epstein’s death, dating back to 2003.
The mechanism at issue here is not fraud detection. It is the deliberate, calibrated non-detection of activity that a bank’s own controls flagged as anomalous, in cases where the client generated fee revenue sufficient to override the compliance incentive. This is not a system failure, it is what a functioning system produces when the reward structure for maintaining a client relationship outweighs the expected cost of BSA non-compliance. Under Sutherland’s differential association, the routinisation of “acceptable” delay across senior banking staff is precisely the mechanism by which the offence class becomes normalised inside firms. The proposed legislative response, personal attestations and bonus clawbacks, is a shift toward what Braithwaite would call responsive regulation, targeting the individual whose sign-off is the last line of defence rather than the firm as an abstract entity. Whether that shift lands depends on whether individual bankers now believe attestation liability is real. Historically the answer has been no.
On 7 August, OFAC designated two digital asset exchanges alongside founder Siavash Kayvanpour and a network of front companies in the UAE, Poland and Georgia. Reuters, whose July 31 investigation prompted the designation, reported that Shelbit acted as a $4 billion Iranian sanctions evasion hub, moving funds for Iran’s central bank, one of the world’s largest illegal online gambling networks, and IRGC-linked addresses. TRM Labs’ blockchain analysis put Shelbit’s total settlement exposure at $6.3 billion, with over $1 million flowing from IRGC wallets to Shelbit addresses and more than $2 million flowing back. Cryptopolitan added that Shelbit serviced a Persian-language online gambling network of over 2,000 sites and processed tens of millions in gambling proceeds. Notably, Dubai’s Virtual Assets Regulatory Authority (VARA) had issued enforcement actions against Shelbit General Trading in both January 2025 and July 2026, but the exchange remained operational until the OFAC designation.
The salient fact is not that Shelbit moved $4 billion. It is that a regulator, VARA, had twice publicly ordered the entity to stop and been ignored, until a US sanctions designation converted a licensing dispute into an existential financial constraint. This is the emerging structure of hybrid regulation in cross-border crypto: local licensing regimes lack coercive reach against unlicensed operators, so the operational chokehold sits at the level of secondary sanctions. Under routine activity theory, VARA existed as a potential guardian but lacked the capable enforcement needed to modify offender behaviour. OFAC’s designation restores that capability by making foreign financial institutions that transact with Shelbit personally exposed to secondary sanctions under EO 13902. The interesting displacement question is whether Iran’s rahbar network migrates to jurisdictions with weaker VASP enforcement, or whether it fragments into smaller settlement layers below the OFAC threshold of interest. The latter is likelier, and harder to police.
On 10 August, AUSTRAC suspended Cryptolink’s VASP registration for three months, taking its network of 96 crypto ATMs offline effective 9 August. AML Intelligence noted that the suspension followed Cryptolink’s failure to submit required threshold transaction reports and its refusal to respond to a regulatory information request, both breaches of an October 2025 enforceable undertaking Cryptolink had already signed following a A$56,340 penalty. AUSTRAC CEO Brendan Thomas said the regulator has ongoing concerns about the company’s ability to manage high-risk transactions through its CATMs, a category AUSTRAC has flagged as an escalating money laundering risk since 2024.
Crypto ATMs are the purest routine activity target in modern financial crime. They provide a cash-to-crypto conversion point that is geographically distributed, physically unattended, and typically operated by firms with thin compliance capacity, converting a highly regulated banking transaction into a digital-asset transfer in a matter of minutes. What is significant about AUSTRAC’s action is not the penalty size but the willingness to remove the operator from the market for a defined period. Situational crime prevention literature (Clarke, 1980) argues that unattended cash-conversion machines create an environment where the offender’s expected cost is low and the guardian is absent. Suspending the operator, rather than fining it, is the situational analogue of removing the target itself. If AUSTRAC extends this posture, the crypto ATM density gradient across Australia should decline within the year. The question is whether other regulators follow, or whether displacement flows into jurisdictions with lighter VASP enforcement.
The UK’s National Crime Agency, according to Law360 via MLex, confirmed on 10 August that it is investigating claims by Reform MPs Nigel Farage and Richard Tice that private banking transaction details from suspicious activity reports were leaked to the press. Bloomberg reported that the two MPs filed High Court proceedings on 7 August seeking more than £25,000 in damages for misuse of private information, breach of confidence and unlawful data processing. The Guardian’s earlier reporting established that banking staff at several institutions filed SARs on transactions involving senior Reform figures, including a £5 million gift to Farage from a cryptocurrency billionaire and transfers involving deputy leader Tice, donor Fiona Cottrell and George Cottrell.
The SAR regime depends on a bilateral asymmetry: banks report suspicions to law enforcement without informing the customer, and law enforcement uses the report as investigative intelligence rather than as public accusation. Both halves of that asymmetry are now under pressure. If SAR contents leak into the press, banks will file fewer, or file more defensively. If MPs can sue the receiving agency for handling the report, the political cost of maintaining the system rises. This is a legitimacy crisis of the reporting infrastructure, not a failure of any individual filing. Historically, comparable pressure in other jurisdictions (South Africa, Malta) has produced a chilling effect on high-risk-politically-exposed-person reporting. The question is whether the UK’s professional norms among compliance officers hold long enough for the litigation to resolve without regime-level change.
On 10 August, at the request of the European Public Prosecutor’s Office in Venice, the Milan judge for preliminary investigations issued house arrest orders against two Chinese nationals accused of directing a VAT carousel scheme worth over €33 million. The Venice Guardia di Finanza investigation, as summarised by Law360, identified companies formally managed by front persons with no criminal records or assets, while the actual control sat with a Milan-based couple exercising de facto direction since 2019. Missing-trader companies generated millions in sales without filing VAT returns. Enforcement of the asset seizure order was limited because the suspects held no attributable Italian assets.
VAT carousels are the textbook example of what Levi and others have called crime-as-arbitrage: the criminal enterprise exploits a structural feature of EU tax law (zero-rated cross-border supplies) rather than manufacturing a novel offence. The Milan case is important because it demonstrates the durability of the model even under intense post-2018 enforcement. Front-person structures are a displacement response to beneficial-ownership registers: the register captures the front person but not the underlying director. The most consequential detail in the EPPO release is that the seizure order could only be partially enforced because the suspects held no Italian assets. This is the ceiling on VAT-fraud recovery under current cooperation frameworks, and it is not going to move until asset tracing and freeze-and-restore mechanisms across EU-China and EU-third-country jurisdictions become materially faster.
Following the February 2026 collapse of Market Financial Solutions, Financial Crime Matters reported on 9 August that the FCA is intensifying scrutiny of unregulated lenders by requesting information from approximately 900 “Annex 1 firms”, entities required to register for AML supervision but not authorised for regulated activity. MLex reported that around 1,200 money brokers and leasing companies will face increased regulatory scrutiny in aggregate.
The Annex 1 category was designed as a light-touch supervisory ring around firms whose principal business is not financial services but which nonetheless touch the payment system. The MFS collapse has demonstrated that this ring has become an accumulation point for money-laundering risk: firms with the reporting obligations of a financial institution but without the supervision. When regulatory intensity varies sharply across a boundary within a market, the offender-facing side of that boundary becomes a target. The FCA’s response, which is essentially a top-down data harvest, is a reasonable first step, but the underlying architectural problem is that Annex 1 status is defined by activity rather than by risk. Until the taxonomy is restructured, each supervisory sweep will surface roughly the same category of failure.
The record UBS $125 million FinCEN penalty covered last week was joined this week by companion CFTC and FINRA orders totalling $28 million, with CFTC assessing $8 million for supervision failures affecting AML transaction monitoring and FINRA fining UBS Financial Services $20 million for AML compliance program failures. Both orders are credited against the $125 million total. AML RightSource podcast analysis noted this is the second FinCEN action against UBS since a December 2018 consent order covered materially similar failures.
The multi-agency architecture around the UBS penalty matters more than the headline number. FinCEN, FINRA, SEC and CFTC each hold a partial view of a broker-dealer’s compliance surface, and each historically prosecuted in isolation. The coordinated resolution converts what would previously have been four sequential, separately-negotiated settlements into a single consolidated event. Under deterrence theory, this compresses the perceived-cost function: firms can no longer treat AML failure as an item-by-item settlement problem stretched over years. Whether that compression holds depends on whether coordination becomes a standard prosecutorial habit or remains reserved for exceptional cases. The historical base rate suggests the latter.
On 17 July, the DOJ entered into a deferred prosecution agreement with Nebraska-based Scoular Company for $10.2 million to resolve conspiracy charges under the FCPA. Between 2013 and 2019, Scoular employees directed Mexican customs brokers to pay more than $400,000 in bribes to Mexican agricultural officials to allow shipments of contaminated corn and other products to cross the US-Mexico border despite failed inspections. Crowell & Moring’s analysis noted this is the first FCPA corporate resolution DOJ has framed explicitly around cartel-adjacent conduct, with the customs bribery treated as materially supporting the border crossing infrastructure that transnational criminal organisations depend on. Paul Weiss confirmed Scoular was not eligible for a declination because the company did not voluntarily self-report.
The shift here is that FCPA is now being used as a national security instrument rather than an anti-corruption instrument. The predicate misconduct is small (roughly $400,000 in bribes) relative to the resolution size ($10.2 million), because DOJ is pricing the case not by the harm done but by the value of the infrastructure the bribes maintained: the crossing of contaminated goods that generate cartel-friendly logistics revenue. Firms operating at the US-Mexico border should now update their compliance calculus to include cartel-nexus exposure, not just anti-bribery exposure, on any customs facilitation payment. This is a substantial expansion of FCPA-adjacent risk and remains under-priced in most border-facing compliance programs.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved