Issue #22 | September 22, 2026 | 7 min read

The Brief

Swedbank's $386 million fine wasn't what put anyone in prison. The part that did was two newspaper interviews.

This issue covers how a Baltic non-resident deposit business that moved tens of billions in high-risk flows for years produced a record fine from Sweden's regulator, and how the bank's own CEO turned a compliance failure into a personal criminal conviction just by describing it to reporters the way she did.

Main Feature

Swedbank's Fine Came From the Baltic Failures. Its CEO's Prison Sentence Came From Talking About Them.

Sweden's regulator found years of ignored warnings about the bank's Estonian operations. A Swedish appeals court later found something separate: the CEO lied about it to the press right before an earnings report.

On March 19, 2020, Sweden's Finansinspektionen (FI) fined Swedbank SEK 4 billion, roughly $386 million, the largest fine ever issued by a Swedish regulator, for serious deficiencies in how the bank governed anti-money laundering controls at its Baltic subsidiaries. Estonia's own financial supervisor issued a separate corrective order the same day, not an additional fine. FI's investigation, run jointly with Estonian, Latvian, and Lithuanian authorities, covered Swedbank's Estonian subsidiary from 2015 through the first quarter of 2019, and found what FI called large deficiencies in governance, insufficient risk awareness and resources, weak customer risk classification, and a transaction monitoring system that didn't understand what its own high-risk customers were actually doing. An independent report Swedbank itself commissioned found the bank's Baltic branches had actively sought out high-risk clients and passed at least $40 billion in high-risk transactions between 2014 and 2019.

None of that was news to Swedbank's own management. FI's decision states plainly that the bank "had been aware of suspected money laundering activities in the Baltics" and had received multiple internal and external reports warning about the deficiencies, and didn't take sufficient action. When FI came asking questions directly, the bank made things worse: FI documented instances of incomplete information in November 2016 and October 2018, and in March 2019, during the height of the scrutiny, gave FI information that was simply false. The story broke into public view in February 2019, when Swedish broadcaster SVT aired reporting alleging roughly $5.8 billion in suspicious flows connecting Swedbank and Danske Bank's Estonian operations, some of the same customers moving through both banks' accounts in the same corridor this newsletter covered with Danske Bank's own $2 billion DOJ forfeiture back in Issue #12.

SEK 4,000,000,000 (~$386M) — FI's fine, the largest in Swedish regulatory history at the time
$40,000,000,000+ — in high-risk transactions Swedbank's own commissioned report found moved through its Baltic branches, 2014–2019
15 months — the prison sentence a Swedish appeals court gave Swedbank's former CEO in 2024, for what she told reporters in 2018
0 — enforcement actions the SEC or DOJ ultimately brought against Swedbank over any of this, both investigations closed without action by early 2026

Swedbank's board fired CEO Birgitte Bonnesen in March 2019, the day after SVT ran a follow-up story. That might have been the end of her personal exposure. It wasn't. Prosecutors charged her with aggravated fraud over two interviews she gave in October 2018, timed to the bank's third-quarter earnings report, in which she told Swedish media that Swedbank's Estonian operations had no suspicious money-laundering links. A Stockholm district court acquitted her in January 2023, reasoning that vague or incomplete statements aren't automatically criminal. Prosecutors appealed. In September 2024, the Svea Court of Appeal reversed that acquittal and sentenced Bonnesen to 15 months for "gross swindling," finding those specific interview statements conveyed a "misleading message" about a problem she already knew existed.

Red flags in this case

  • Multiple internal and external reports warned about Baltic AML deficiencies for years before any public disclosure, and management didn't act on them

  • A regulator supervising an active inquiry received incomplete information twice and outright false information once

  • A subsidiary's high-risk non-resident customer base grew large enough to move tens of billions annually before group-level governance treated it as a group-level problem

  • The CEO's public description of the bank's own compliance status, made to time a market-moving earnings report, became the basis for a personal criminal conviction independent of the underlying laundering findings

  • The same Baltic corridor and some of the same customers surfaced in a peer bank's laundering scandal, and neither bank's monitoring caught the overlap on its own

The part of this case a headline about "$386 million Baltic laundering fine" misses entirely: the money-laundering findings and the criminal conviction rest on two different sets of facts. Nobody went to prison for the transaction volume. Someone went to prison for describing that volume incorrectly to a reporter, in a way a court decided crossed from imprecise into misleading. If your executives are ever asked to characterize the state of an ongoing AML remediation to the press or to investors, that description is not a communications exercise. It's a statement of fact a court can later hold you to, separately from whatever the underlying compliance program actually did.

Source: Finansinspektionen, "Swedbank Receives a Warning and an Administrative Fine of SEK Four Billion," March 19, 2020 | Estonian Financial Supervision Authority, corrective order, March 19, 2020 | Svea Court of Appeal, judgment against Birgitte Bonnesen, September 10, 2024

Controls & Testing

Risk & Control Matrix

Risk

Control

A subsidiary's high-risk, non-resident customer volume grows large before group-level governance treats it as a group-level issue

A consolidated reporting threshold requiring board-level escalation once any subsidiary's high-risk or non-resident portfolio crosses a defined volume, regardless of that subsidiary's standalone materiality to the group

Internal and external reports flag AML deficiencies repeatedly without triggering sufficient remediation

A tracked issue-closure log for AML findings from internal audit, external consultants, correspondent banks, or regulators, with mandatory board risk committee escalation for any item still open past a defined deadline

Public statements by executives about the status of AML remediation aren't checked against the institution's own internal findings before release

A disclosure-control process requiring legal and compliance sign-off on any public statement characterizing AML program status, cross-referenced against the current internal findings register

Information submitted to a regulator during an active supervisory inquiry is incomplete or inaccurate

A documented regulatory-response protocol requiring review by staff independent of the business line under inquiry before any submission goes to the supervisor

Suspicious customers or flows shared across peer institutions in the same high-risk corridor go undetected because monitoring doesn't look past the bank's own walls

Participation in a cross-institution information-sharing arrangement for the specific high-risk corridor, with monitoring rules updated to reflect jurisdiction-specific indicators identified through that sharing

Audit Test Steps

An audit program built around this typology could test for it by:

  1. Pulling the population of AML deficiency findings raised by internal audit, external consultants, correspondent banks, or regulators over the trailing 12 months, and testing whether each was tracked to closure by its target date, with escalation to the board for anything still open past that date.

  2. Selecting a sample of public statements (earnings calls, press interviews, investor communications) referencing the AML program's remediation status, and testing whether each was reviewed and approved against the current internal findings register before release.

  3. Calculating the trailing 12-month transaction volume for the institution's highest-risk non-resident or high-risk customer segment at the subsidiary level, and testing whether it was reported to group-level governance once it crossed the institution's defined escalation threshold.

  4. Selecting a sample of information requests received from a regulator during the period, and testing whether the response was independently reviewed for completeness and accuracy by staff outside the business line under inquiry before submission.

  5. Testing whether the institution participates in an information-sharing arrangement covering its highest-risk geographic corridor, and if so, whether monitoring rules were updated to reflect any jurisdiction-specific red flags identified through that sharing during the period.

Intelligence Briefing

FinCEN — On September 2, FinCEN joined the Federal Reserve, FDIC, NCUA, and OCC in a joint statement clarifying that SAR confidentiality rules don't stop a bank from talking to a customer about a suspicious or potentially fraudulent transaction, or an account closure — as long as the bank doesn't reveal that a SAR was filed or what it said. Nothing about the confidentiality rule itself changed. Source: FinCEN, Federal Reserve, FDIC, NCUA, and OCC, "Agencies Issue Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers," September 2, 2026.

FinCEN — On September 3, FinCEN published an analysis of nearly $13 billion in suspected digital asset scam activity, reviewing 33,904 BSA reports filed between September 2023 and December 2025 covering pig butchering, romance baiting, and cryptocurrency confidence schemes, with victims identified in all 50 states. It's a reminder that SAR filing volume on a known typology is itself a measure of program health — one this issue's Main Feature shows can still fail badly even when the filings exist somewhere in the system. Source: FinCEN, "FinCEN Identifies Nearly $13 Billion Linked to Suspected Digital Asset Scams Operated by Overseas Scam Centers," September 3, 2026.

Career Intel

The AML Act of 2020 gave FinCEN authority to pay whistleblowers 10 to 30 percent of any penalty over $1 million that their information helps collect, with a presumption toward the higher end when the recovery is $15 million or less. FinCEN only sent the rule implementing the program to the Federal Register for public comment in April 2026, and no award has been paid out under it yet.

Swedbank's case is a reminder of why that number exists. FI's own decision says the bank received multiple internal and external reports about the Baltic deficiencies for years before any of it became public. Someone inside that chain saw those reports. The gap between seeing a warning and it actually reaching a regulator or the public used to depend entirely on internal escalation working as designed. It's a data point worth knowing for anyone whose own escalation channel might fail the same way.

AI in Financial Crimes Compliance

HSBC replaced its rules-based transaction-monitoring engine with a machine-learning system built on Google Cloud's Anti Money Laundering AI product, marketed as Dynamic Risk Assessment, trained on the bank's own transaction history rather than a fixed set of manually written rules.

Instead of firing an identical alert every time a transaction matches a preset pattern (a wire over a certain amount, a flagged country pair) the model scores each customer's activity against patterns learned from years of the bank's own confirmed-suspicious and confirmed-clean dispositions, then ranks alerts by risk instead of treating every rule-hit the same. Google Cloud has reported the approach cut HSBC's false-positive alert volume by roughly 60 percent, while increasing the share of alerts that turned out to be genuinely suspicious two to four times over, and cut the time to process transaction data from weeks to days.

A model trained on an institution's own historical dispositions inherits whatever those dispositions got wrong. If a typology, like a subsidiary's non-resident customer base, was consistently under-flagged by human analysts in the training data, the model learns to keep under-flagging it, just faster and more quietly. Since the model is now doing the triage that used to generate a rule-hit for a human to review, the audit question stops being "did the rule fire correctly" and becomes "what did the model decide not to surface, and can anyone explain why."

Tip Line

Got any idea for something you'd want to see covered here? Doesn't have to fit neatly into a category. If you think it's interesting, we probably will too.

Send it to [email protected].

If someone forwarded this to you, welcome.

The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:

[BUTTON: Subscribe → theamlbrief.com]

Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.

The AML Brief | theamlbrief.com

Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.