Skip to content
All issues

FinCrime Intelligence Weekly

Issue №11 · Aug 3 – 9, 2026

UBS's $125m repeat AML fine, OFAC's Shelbit crypto sanctions, the FCA's transaction reporting overhaul, a UK money mule surge, and the Senate's Epstein SAR report.

FinCrime Intelligence Weekly - Issue 11: The week enforcement caught up with red flags everyone already had
MB

Marco’s Take

Marco Beranzoni

Five stories this week, one recurring fault line: timing. UBS’s Bank Secrecy Act failure was not a design gap. The bank simply did not act on volume and geography red flags across more than 60,000 wires, and it had already been fined for similar failures in 2018. The Senate Finance Committee’s Epstein report describes the same pattern at a different scale: three major banks processed over $1.4 billion in transfers before flagging them retroactively in 2019, years after the activity began. Shelbit and Aban Tether ran a shell company network across three countries for long enough to move funds toward Iran’s IRGC before OFAC caught up, following a Reuters investigation rather than a bank’s own alert.

None of these firms lacked a monitoring framework on paper. What they lacked was a mechanism that converted a known red flag into a filed SAR or a closed account before the money moved again. My uncomfortable ask this week: pull the last five alerts your team closed as false positives and time how long each one sat open before disposition. If the median is measured in weeks rather than days, that gap is where the next enforcement case is quietly forming.

See you next Monday. Marco

The 5 stories that matter

Regulatory Radar

What changed this week, why it matters, and what to do about it.

US

OFAC pushed back its authorization deadline for transactions in Venezuela's 2020 8.5 percent sovereign oil bond to 17 September 2026, extending a general license that had been due to lapse.

Why it matters:Firms holding or transacting in the bond avoid an abrupt compliance gap, but the extension is time limited and the underlying Venezuela sanctions program remains otherwise unchanged.

Action:Diarise the new 17 September 2026 date now and confirm exactly which counterparties or custody positions the license actually covers before it expires.

Global

OFAC removed Fly Baghdad Airlines and its associated aircraft from its counter terrorism sanctions list on 5 August 2026, alongside an update to a related individual designation.

Why it matters:Screening systems that still flag the airline or its aircraft tail numbers will generate false positives and waste investigative time on a party that is no longer designated.

Action:Push the delisting into sanctions screening lists and watchlists this week and close out or reclassify any open cases tied to Fly Baghdad.

EU

The EU's Anti-Money Laundering Authority opened a survey of payment firms and e-money institutions in early August 2026, asking about their experience working with local supervisors.

Why it matters:Responses will feed directly into AMLA's redesign of the supervisory framework, making the survey a rare direct channel for payment firms to shape how they are supervised going forward.

Action:Payment and e-money compliance leads should locate the survey and submit a considered response rather than leaving it to government affairs teams alone.

EU

Enforcement obligations for high risk AI systems under the EU AI Act's Annex III, covering credit scoring, insurance risk assessment, and fraud detection tools, became live on 2 August 2026.

Why it matters:Firms running AI driven fraud detection or credit models in scope now face penalties of up to 15 million euros or 3 percent of global annual turnover, whichever is higher, for non-compliance.

Action:Confirm which fraud, credit, or insurance risk models qualify as high risk under Annex III and check that conformity assessments and human oversight documentation are actually in place.

Typology of the week

Shell Network Layering Through Unlicensed Crypto Exchanges

How it works

An unlicensed or loosely licensed crypto exchange takes in customer funds and routes them through a web of shell companies registered across multiple jurisdictions, none of which has an obvious commercial link to the exchange or to each other. An online gambling platform is layered into the chain, blending genuine betting activity with fund transfers so the money trail resembles ordinary gaming turnover rather than a deliberate transfer chain. The layered funds are then converted back to fiat, or moved to wallets controlled by or on behalf of a sanctioned end user, with the shell companies and the gambling front absorbing most of the scrutiny that would otherwise fall on the exchange itself.

Red flags

  • Crypto exchange operating without a licence or verifiable registration in the jurisdictions where it accepts customer funds
  • Shell companies with no discernible business activity acting as counterparties or beneficiaries on wire and crypto transfers
  • Transaction patterns that route consistently through an online gambling platform without matching genuine betting volume
  • Corporate structures spanning several jurisdictions with directors, registered agents, or addresses that repeat across unrelated entities
  • Wallet or counterparty addresses that cluster around known sanctioned jurisdictions or intermediary hubs despite customer declared locations elsewhere

Sectors exposed

Virtual asset service providers and crypto exchanges Correspondent and payment banks processing wires tied to shell company networks Online gambling and gaming platforms Company formation agents and registered agent providers Trade finance and remittance businesses operating in intermediary jurisdictions

Controls to review

  • Beneficial ownership verification depth for corporate customers registered in intermediary jurisdictions
  • Transaction monitoring rules tuned to detect gambling turnover inconsistent with genuine player activity
  • Sanctions screening coverage extended to crypto wallet addresses and virtual asset counterparties, not just fiat counterparties
  • Correspondent banking due diligence on payment volumes routed through newly onboarded shell entities
  • Escalation thresholds for corporate structures spanning multiple jurisdictions with no clear commercial rationale

Example

The real world reference case for this typology is the Shelbit and Aban Tether network. On 7 August 2026, US Treasury's OFAC sanctioned both crypto exchanges for laundering funds toward Iran's IRGC through shell companies registered across Georgia, Poland, and the UAE, alongside an online gambling operation, following a Reuters investigation that estimated the evasion scheme at around $4 billion. This is a genuine, sourced enforcement case, not an illustrative composite.

Crypto, Fraud & AI

EU AI Act high risk obligations for fraud detection and credit scoring systems become enforceable

As of 2 August 2026, Annex III obligations covering credit scoring, insurance risk assessment, and fraud detection AI are legally live, with penalties reaching 15 million euros or 3 percent of global annual turnover. Fincrime teams running AI in these categories should treat conformity assessment and human oversight documentation as immediate priorities, not year end housekeeping.

Vendor study claims financial firms face the most AI-assisted fraud but are adapting fastest

Regula's AI Identity Readiness Scorecard, published 4 August 2026, reports that financial services face more AI-assisted fraud activity than any other sector surveyed while also improving readiness faster than the rest of the market. This is an industry vendor claim rather than an independently verified finding, useful as a discussion prompt for identity verification budgets, not as a benchmark to cite unqualified.

Career & Skills Corner

Track Your Own Alert Latency, Not Just Your Closure Rate

Most analysts and MLROs can quote how many alerts they cleared last month, but far fewer can say how long the average alert sat open before a decision was made. That second number is the one that shapes a career and a regulatory file equally. A practitioner who can walk into a review and say precisely how long red flags took to reach a decision, and why, demonstrates the kind of operational control that promotion panels and examiners both look for. Building this habit is simple: keep a running personal log, even a basic spreadsheet, of alert open dates against disposition dates for a month, then look for the outliers. Bring that pattern to a manager with a proposed fix rather than waiting to be asked. Speed paired with sound judgment, evidenced rather than claimed, is what separates a competent analyst from one who gets trusted with harder cases and, eventually, with people.

What I’m watching next week

Next week I will be watching whether the Wyden report's findings on Bank of America, Deutsche Bank, and JPMorgan prompt any public signal from the Department of Justice, since a Senate committee report is not itself a charging document. I am also tracking whether OFAC's action against Shelbit and Aban Tether leads to further crypto exchange designations tied to the same shell company network, given how these investigations tend to widen once one node is exposed.

Want to do this for a living?

Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.

AML & Financial Crime course →