Issue #12 | July 14, 2026 | 7 min read

SECTION 1: The Brief

Danske Bank's Tallinn branch moved roughly €200 billion for customers with no real business being there. What actually turned that into a $2 billion guilty plea wasn't the volume. It was what group management told the American banks holding its dollar accounts about it.

This issue covers how one branch's non-resident portfolio became a US bank fraud conspiracy charge, what a two-year gap between a written warning and any action actually looks like, plus a first look at where financial crimes careers are headed and new video breakdowns dropping across the week.

SECTION 2: Main Feature

ENFORCEMENT ACTION

The Board Knew in 2014. The Money Kept Moving Until 2016.

Danske Bank pleaded guilty to defrauding its own U.S. correspondent banks, not to failing to catch a money laundering scheme it didn't know about

Danske Bank, Denmark's largest financial institution, ran a single branch in Tallinn, Estonia that processed roughly €200 billion in transactions for non-resident customers, mostly Russian and other former Soviet-state nationals, between 2007 and 2015. In December 2022, Danske pleaded guilty in US federal court to one count of conspiracy to commit bank fraud and agreed to forfeit approximately $2.06 billion. The SEC separately charged the bank with defrauding investors about the state of its AML program; the forfeiture was structured to satisfy the SEC's disgorgement and penalty findings rather than stack a second multi-billion-dollar payment on top.

What DOJ actually charged wasn't a failure to detect laundering in Estonia. It was that Danske misled the American banks providing its US-dollar correspondent accounts, the accounts that let a Danish bank's Baltic branch touch the US financial system at all, about the adequacy of its AML program between 2008 and 2016. The branch didn't just have weak controls. Group management represented those controls as sound to the correspondent banks giving it dollar access, while the board had already been told in writing that the branch might be knowingly dealing with criminals.

€200 billion — suspicious transactions that moved through Danske's single Estonia branch, 2007–2015
$2.06 billion — forfeiture in Danske's December 2022 guilty plea to conspiracy to commit bank fraud
2014 — the year Danske's board discussed an internal whistleblower's warning that the branch might be "knowingly dealing with criminals"

Every correspondent banking relationship runs on the same dependency Danske exploited. Danske isn't a US bank. Its access to US-dollar clearing depended entirely on other banks agreeing to hold correspondent accounts for it, and those banks relied on Danske's own representations about its AML program instead of independently verifying what was happening inside the Estonia branch. That's not a gap unique to this case. It's the load-bearing assumption underneath most cross-border banking relationships, and Danske is what it looks like when a counterparty decides that assumption is safe to abuse.

Red flags in this case

  • A single branch representing a small share of group deposits but processing transaction volume wildly out of proportion to the bank's regional footprint

  • Non-resident account holders with no plausible commercial connection to the country where their accounts were held

  • Internal escalation describing account activity as potentially criminal, reaching board level, without a documented or timely response

  • Group-level representations of AML program adequacy made to correspondent banks and public investors that didn't reflect what the board already knew

  • Roughly two years between the board being warned in writing and the suspicious volume actually stopping

If you sit anywhere in a correspondent banking relationship, either providing the account or holding one, this is the case for why "the counterparty attests their program is adequate" can't be where your due diligence ends. Transaction volume by branch or subsidiary, measured against that entity's stated business footprint, is independently verifiable. You don't need to trust anyone's self-assessment to check whether a small Baltic branch is moving money like a major financial center.

The compliance program that would have caught this already existed inside Danske. It sat in board minutes for two years before it did anything at all.

Source: DOJ, "Danske Bank Pleads Guilty to Fraud on U.S. Banks in Multi-Billion Dollar Scheme to Access the U.S. Financial System," December 13, 2022 | SEC, "SEC Charges Danske Bank with Fraud for Misleading Investors about Its Anti-Money Laundering Compliance Failures in Estonia," December 13, 2022

SECTION 3: Intelligence Briefing

INTELLIGENCE BRIEFING

FinCEN — On May 11, FinCEN issued an alert on money laundering by Iran's Islamic Revolutionary Guard Corps through front companies, financial facilitators, and digital assets. The alert details how the IRGC uses a shadow fleet of poorly regulated vessels to smuggle oil, multi-jurisdictional exchange houses and front companies to launder the proceeds, and, increasingly, unlicensed digital asset exchanges to move value while evading sanctions. Institutions should cite the key term FIN-2026-Alert002 in SAR field 2 when filing on related activity. Source: FinCEN, "FinCEN Issues Alert to Stop Money Laundering by Iranian Revolutionary Guard Corps," May 11, 2026.

OFAC — On June 1, OFAC settled with FTI Consulting for $1.05 million over indirect dealings in prohibited VTB Bank debt. FTI structured its engagement through a law firm rather than invoicing the sanctioned Russian bank directly, and OFAC still found liability. The settlement is a clean reminder that routing a transaction through an intermediary doesn't move the sanctions exposure anywhere; it just adds a step someone still has to screen. Source: OFAC, Settlement Agreement between OFAC and FTI Consulting, Inc., June 1, 2026.

SECTION 4: From the Source

FROM THE SOURCE

"Whistleblowing disclosure – knowingly dealing with criminals in the Estonia branch."

That's the subject line Howard Wilkinson, who'd headed Danske's Baltic trading desk, put on an email to Copenhagen management after Christmas 2013. The board discussed it during the first week of January 2014. Wilkinson was never told what, if anything, the bank did in response. The suspicious volume through the Estonia branch kept flowing for roughly two more years after that meeting.

The subject line is most of the finding by itself. Not "some accounts look unusual" but a direct statement, from inside the bank, that the institution itself might be committing a crime. Whatever happened in that boardroom, "the AML program is adequate" is not the sentence two more years of that warning sitting unanswered should have produced.

— Howard Wilkinson's internal disclosure, cited in DOJ and SEC settlement materials and subsequent public reporting on the Danske Bank Estonia matter, 2013–2014

SECTION 5: Career Intel

CAREER INTEL

The Bureau of Labor Statistics projects 3% growth for compliance officers between 2024 and 2034, about average for all occupations, with roughly 33,300 openings a year and a 2024 median wage of $78,420. Read as one job title, that's a flat, unremarkable outlook.

It isn't one job title. Cases like Danske are why correspondent banking and cross-border due diligence have become their own hiring lane inside compliance, distinct from generalist BSA/AML analyst roles. Institutions rebuilding non-resident account reviews and correspondent relationship monitoring after enforcement actions need people who've actually worked cross-border EDD, not just domestic account monitoring. If you're early in your career, that's the specialization worth angling toward. It reads on a resume as "correspondent banking" or "cross-border AML," not "compliance officer."

Source: U.S. Bureau of Labor Statistics, Occupational Outlook Handbook, Compliance Officers, 2024–2034 projections

SECTION 6: Now on Video

NOW ON VIDEO

This issue's Danske Bank breakdown is getting cut into video across the week, new clips landing on YouTube Shorts and TikTok Tuesday through Friday. Same sourcing, same red flags, 60 seconds each.

Find us at @theamlbrief on both platforms, or start at theamlbrief.com.

SECTION 5 — CTA Block

If someone forwarded this to you, welcome.

The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:

[BUTTON: Subscribe → theamlbrief.com]

Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.

The AML Brief | theamlbrief.com

Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.

Keep reading