Financial institutions are pouring money into sophisticated monitoring tools. According to Vinay Vyas, the real threat to compliance lies elsewhere: in a culture that quietly decides the rules do not apply.
According to Argus Pro, drawing on two decades spent working on some of the world’s most complex financial crime investigations, Vyas argues that technology and process are rarely to blame when controls collapse. Almost every major failure, they contend, can be traced back to organisational culture.
One case Vyas led resulted in a $2.6bn fine for the bank involved. On paper, the institution had everything regulators expect: documented policies, transaction monitoring and dedicated compliance teams.
What it lacked was an environment where those controls were genuinely respected. Employees doubted that raising a concern would make any difference, and they had little faith that they would be protected if they spoke up. In effect, the culture had settled the outcome long before regulators stepped in.
The case of TD Bank offers a more recent warning. In October 2024, the lender agreed to pay around $3bn to US regulators, the largest penalty ever imposed under the Bank Secrecy Act. The Department of Justice pointed to ‘long-term, pervasive, and systemic deficiencies’ in the bank’s compliance programme, noting that more than 92% of transactions went unmonitored between 2018 and 2024.
Beneath the technical breakdowns sat a deeper problem. Staff reportedly referred to the institution internally as ‘America’s most convenient bank’ for money laundering. Managers turned a blind eye, and in one branch a manager made light of suspicious activity in a company email. Leadership also enforced a ‘flat-cost’ budget for compliance even as the business expanded rapidly, leaving the teams tasked with stopping illicit activity squeezed for resources.
For Vyas, the lesson is clear. The systems pointed staff towards the right action, but the culture pushed them in another direction. Even the most advanced transaction monitoring offers little protection if those operating it believe nobody cares about the alerts.
Vyas stresses that this is not an attack on firms now working to remediate. Rather, the pattern recurs across jurisdictions, business sizes and institution types. The quality of a firm’s systems, they argue, matters less than the cultural environment in which those systems operate.
Compliance leaders are urged to prioritise honest self-examination over comforting metrics. Key questions include whether teams feel empowered to escalate concerns or pressured to handle them quietly, whether the person who flags suspicious activity is rewarded, whether leadership views compliance spending as a cost to cut or a business necessity, and whether staff at every level understand why the controls exist.
Ultimately, technology is only a tool. Culture determines whether that tool succeeds or fails.
Read the full ArgusPro post here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





