Last week the reporting layer was on trial (Edition #18) has now been followed by the week the reporting layer was (in one significant jurisdiction) formally dismantled. On 11 August the US Treasury issued a final rule permanently removing beneficial ownership information reporting obligations for US companies and US persons under the Corporate Transparency Act, and confirmed it will delete previously reported data on US persons from the database. Two days later, FinCEN published a Financial Trend Analysis showing that financial institutions had flagged nearly five billion dollars linked to suspected human smuggling over three years. The two announcements together define the tension of the moment: the US is scaling back one class of reporting obligation while pointing to another as evidence of the reporting infrastructure’s continuing value. Against that backdrop, the SEC and CFTC brought parallel charges against Goliath Ventures in a $425 million crypto Ponzi, Ireland launched an international money-laundering probe into the €1 billion Kinahan network, BaFin publicly warned a former managing director in a first-of-its-kind AML executive-liability move, and AUSTRAC published new detail on the Cryptolink suspension. The through-line: who is inside the reporting perimeter, and what happens to the perimeter when the political will to defend it fractures.
On 11 August, the US Treasury issued a final rule permanently removing the requirement for US companies and US persons to report beneficial ownership information to FinCEN under the Corporate Transparency Act. Sidley’s analysis confirmed the rule adopts the exemptions set out in the March 2025 interim final rule, exempts US persons who obtained FinCEN IDs from any obligation to update or correct that information, and requires FinCEN to delete previously reported information about any individuals it reasonably believes to be US persons. Foreign entities registered to do business in the US remain within the reporting perimeter but do not report US-person beneficial owners. Law360’s follow-up reporting documented immediate criticism from lawmakers and transparency campaigners that the change encourages money laundering through US shell companies.
The Corporate Transparency Act is a consequential post-FATF reform of the US financial-crime perimeter. Its rollback is not a technical adjustment; it is a shift in what the US treats as the reporting frontier. Under routine activity theory, the beneficial-owner register functioned as a low-cost, high-coverage guardian: it did not stop offending, but it modified the cost curve for anyone using a US company as a laundering vehicle by making anonymity harder to purchase. Its withdrawal removes that guardian at scale. The interesting question is whether the FATF Mutual Evaluation cycle can generate enough external pressure to reverse the decision. Historical base rates suggest FATF’s soft-law leverage on the US is limited. What follows is likely a displacement effect inside the domestic US market: shell-structure formation returns to Delaware, Wyoming and Nevada as the offender-preferred layer, while foreign investigators lose the marginal transparency gains they had begun to accrue.
On 13 August, FinCEN published a Financial Trend Analysis documenting that between 2023 and 2025, financial institutions filed Bank Secrecy Act reports flagging nearly $5 billion in transactions connected to suspected human smuggling. Opus Datum’s summary noted the report identifies characteristic transaction patterns including structured cash deposits at money service businesses along migration corridors, layered transfers through personal accounts of border-adjacent employees, and rapid transfers to Mexico, the Northern Triangle countries and China.
This is the most politically salient framing of the SAR data set in a decade, and it is happening the same week the US narrowed its beneficial-ownership perimeter. The Treasury is making the argument that transaction-level reporting captures more actionable intelligence than entity-level ownership disclosure. Under rational choice theory, human smuggling generates a high volume of small, structurable payments whose observability is a function of the number of eyes at the intermediating money-service tier. That is exactly what SAR filings are designed to surface. The risk is asymmetric: transaction reporting captures the cash-in-cash-out corridor, but it does not surface who ultimately owns the smuggling enterprise. Losing beneficial-ownership data on US entities makes the upstream principal harder to reach even when downstream flows are well documented.
On 11 August, the SEC filed charges against Goliath Ventures Inc. and founder Christopher A. Delgado, alleging a multi-year Ponzi scheme that raised at least $425 million from over 1,300 investors. The SEC litigation release details that investors were promised monthly returns of 3% to 10% from purported crypto asset liquidity pools, but Defendants did not invest any funds in liquidity pools; Delgado allegedly misappropriated at least $51 million for personal use, including homes, luxury vehicles, a yacht and travel. Yahoo Finance reported the CFTC brought parallel charges the same day. Cryptopolitan noted that defendants also used new investor funds to pay Ponzi returns and hired sales agents on commission to recruit further investors, while fabricating account statements to reflect fictitious returns.
The most useful lens for Goliath is not the crypto element, which is largely irrelevant to the operational structure, but the classical Ponzi topology dressed in a crypto vocabulary. The offering was unregistered, the investment thesis was unverifiable at investor level, and the internal accounting was falsified end to end. This is Charles Ponzi’s original architecture, updated for the yield-farming discourse. The interesting variable is the sales-agent commission structure: the compensation model recruits intermediaries whose earnings depend on volume and who therefore internalise the promise as truth. That commission structure is the mechanism by which a small fraud becomes a $425 million fraud. Regulatory response to Goliath will focus on registration and disclosure. The behavioural lesson sits in the sales-agent tier.
Following the 9 August extradition of Daniel Kinahan from the UAE to Ireland, The Irish Times reported on 11 August that Gardaí have opened an international money-laundering investigation into the estimated €1 billion Kinahan organisation. AML Intelligence confirmed the inquiry involves law enforcement in Ireland, Australia, Britain, Spain, the United States and the UAE. The focus is on assets held by senior Kinahan figures who are tax-domiciled outside Ireland, placing them beyond the reach of the Criminal Assets Bureau and requiring coordination with foreign asset-recovery mechanisms.
The Kinahan enterprise is a textbook example of what Nicholas Lord and Karin van Wingerde have called organisational asset architectures: legitimate corporate vehicles arranged transnationally so that offender control persists while ownership is diffused across jurisdictions with divergent transparency norms. The 2022 US OFAC designations, which functioned much as the recent Shelbit action did, and immediately shrank its access to correspondent banking. Extradition converts a diplomatic posture into a criminal case. The subsequent asset-recovery phase is the true stress test. Under rational choice, the deterrent effect of the Kinahan takedown on comparable networks depends less on the extradition and more on whether the resulting asset recovery is proportional to the enterprise value; the historic ratio in comparable European cases has been below ten percent.
BaFin, according to AML Observatory reporting on 12 August, issued a formal AML warning to a former managing director of an unnamed German financial institution over serious, persistent organisational deficiencies. FinCrime Central summarised that the action targets individual executive accountability rather than the firm itself, and follows BaFin’s June order to NordLB and its earlier order to Helaba, both of which addressed remediation at institution level.
German AML enforcement has historically pursued institutions and left individuals largely unnamed. A formal, public executive-level warning is a move that mirrors the direction of travel signalled by Senator Wyden’s Epstein-report legislative proposal in Lab Report #18: individual liability for the sign-off function inside compliance. Under Braithwaite’s responsive-regulation framework, the personal warning sits below prosecution but above institutional censure; its effect depends on whether other national regulators regard the German precedent as generative. If BaFin’s next action names the individual publicly and imposes an industry ban, the German trajectory will have crossed the threshold that Wyden’s Wall Street proposals aim to establish by statute.
Cifas, the UK’s national fraud database operator, reported that more than 13,000 money mule cases were logged to the National Fraud Database in the first half of 2026, a 69% year on year rise. FinCrime Agent’s coverage notes the increase is not attributable to a single scheme but reflects the aggregate growth of mule-network activity across the UK banking sector.
The mule tier is the softest layer of the fraud value chain. It has neither the technical sophistication of the scam-compound operator nor the financial exposure of the account holder, and it sits at the intersection of two conditions that routine activity theory identifies as generative of offending: high accessibility of the target (retail bank accounts) and low guardianship at the recruitment layer (social media, WhatsApp, encrypted messaging platforms). Cifas’s figure implies UK onboarding and ongoing-monitoring controls are being outpaced by the recruitment velocity of the upstream fraud economy. This is a structural signal, not a cyclical one. Expect the FCA to move the debate about ongoing customer due diligence away from principle-based supervision and toward specific mule-detection requirements before the year is out.
On 14 August, the FCA banned Paul Taylor and Esmeralda Toni from working in UK financial services and imposed fines totalling nearly £610,000. MLex reported that Taylor, former CEO of Blue Horizon Asset Management, falsified documents claiming ownership of a €200 million bond portfolio in support of a proposed acquisition of a UK bank and a subsequent attempt to acquire an English football club; Toni, the former managing director, was found to have knowingly assisted the deception. Both statements were relied upon by the FCA and PRA in their acquisition assessments.
This is a textbook example of the trust-arbitrage function of the regulatory approval process. The FCA/PRA change-of-control assessment operates on the assumption of good-faith disclosure. When candidates fabricate the foundational financial claim on which the assessment is made, they exploit a governance mechanism designed to protect market integrity as a route into it. The FCA’s use of a personal ban and a substantial personal fine, rather than a firm-level penalty, is the appropriate response: the offence was the misrepresentation of individual capacity, not an institutional failure. Under rational choice, the deterrent effect of the ban is generated less by the fine and more by the industry-exclusion element, which materially destroys the value of the offender’s professional capital.
According to Radical Compliance reporting on 12 August, a Wisconsin commercial-grade scales manufacturer paid $60,700 to OFAC to settle eight sanctions violations. Between 2019 and 2021, the company’s Italian subsidiary sold weighing equipment into Iran, apparently as a result of unclear parent-company compliance instructions rather than deliberate evasion.
The Wisconsin case is small in dollar terms but is netherless instructive. OFAC’s settlement narrative frames the underlying error as an internal-communication failure: the parent did not clearly transmit its sanctions compliance policy to the Italian subsidiary. Under Sutherland’s differential association, this is a local-culture offence: the Italian office operated within a professional environment where the Iran restriction was under-salient, and the parent’s failure to reinforce the constraint let the local norm dominate. The settlement is calibrated to the theory: modest financial penalty, high public visibility, and detailed remediation obligations focused on subsidiary-level training. This is what OFAC does when the goal is deterrence-by-example across a diffuse compliance population rather than punishment of the specific offender.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved