$931m in Q2 fines shows escalation, not detection, is failing

fines

Global enforcement penalties in the second quarter of 2026 reached their highest level in four quarters, according to a new analysis of regulatory activity by Corlytics, although the total remained well below the figure recorded in Q2 2025.

The review of 37 penalties exceeding $1m, which together topped $931m, points to a consistent lesson: firms are rarely punished for having no controls at all.

Instead, they are sanctioned because those controls were never updated, escalated or overseen properly. Supervision failures and unactioned alerts featured in nearly a third of the cases studied, suggesting the industry’s weakest link is acting on warnings rather than detecting problems in the first place.

Individual conduct, including by senior managers, appeared in ten actions. The SEC imposed a $100m penalty on Western Asset Management over misconduct by former chief investment officer Ken Leech, who pleaded guilty to obstructing an investigation into an alleged cherry-picking scheme that steered profitable first-day trades to favoured portfolios.

Deputy US attorney Sean Buckley said, “Investment managers, like Leech, are entrusted by the SEC and the public at large to comply with their duty to be honest to regulators and fair to their clients. Today’s plea reflects the commitment of this office and its law enforcement partners to protecting everyday investors — in New York City and abroad — from investment advisers who violate their legal commitments and seek to deceive clients for their gain or the gain of others.”

Data privacy remained a major European theme. The Dutch regulator AP fined Netherlands-registered MLU BV $117.5m (€100m) after its Yango taxi app moved sensitive driver and customer data, including licence scans, locations and social security numbers, to Russia.

AP chair Aleid Wolfsen said, “In Russia, personal data is not as well protected as in Europe. This may allow the Russian government to gain access to this data. The sensitive data of both customers and drivers should therefore have been extra well protected, especially given the absence of an independent data protection authority in Russia. We observed that this was not done properly. That is very serious. For example, because it can pose safety risks to people.”

Financial crime and AML shortcomings generated seven fines worth roughly $87m combined. CACEIS BANK (UK Branch) agreed a $41.7m (£31.7m) voluntary ex-gratia payment after ignoring 16 transaction monitoring alerts linked to WealthTek, while Maryland lender EagleBank paid $9.7m over a decade-long cheque kiting scheme that executives repeatedly shielded from compliance staff.

Merrill Lynch paid the SEC $7.5m for relying on transaction monitoring software it knew was miscalibrated, and Canada’s CIRO fined Independent Trading Group around $2.05m for gatekeeper failures around two foreign broker-dealer clients.

Insurance intermediation accounted for three of the quarter’s ten largest fines, headlined by AssuredPartners’ $107m civil settlement with the US DoJ over ineligible Affordable Care Act enrolments, and Société Générale’s $23.3m (€20m) ACPR penalty for failing to disclose information about insurance sold with packaged accounts.

Australia stood out among jurisdictions, issuing its largest ever fine of $208m (A$300m) against CfD issuer Union Standard International Group and its representatives, alongside a first-of-a-kind $24.5m (A$35m) penalty against HSBC over scam protection failures.

ASIC chair Sarah Court said, “Banks have been well on notice about the risks of scams for some time. They have now been given a clear message to have adequate controls and ensure their interactions with scam victims help – not hinder.” Court added, “This is one of the first cases of its kind globally and sends a clear message that protecting customers from scams is a core responsibility of banks.”

The report concludes that firms must actively refresh compliance frameworks whenever the business changes, because governing controls effectively is fast becoming as critical as the controls themselves. For decision-makers who need early sight of where regulators strike next, our daily briefing delivers the strategic intelligence that keeps compliance leaders ahead of the enforcement curve.

Download the full enforcement report by Corlytics here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.