Regulators punish firms for ignoring their own controls in Q2

Q2

Global regulators handed out more than $931m in penalties above the $1m mark during the second quarter of 2026, the largest quarterly total in a year, with a pair of first-of-a-kind sanctions hinting that novel enforcement approaches may become more common, Corlytics detailed in their recent enforcement report. 

The central lesson from the quarter’s 37 major penalties is that firms are rarely punished for missing frameworks. Instead, they are being caught out by neglecting to update, escalate and oversee the controls they already have. Supervision lapses and ignored alerts featured in nearly a third of the cases examined, pointing to escalation, rather than detection, as the industry’s weakest point.

Individual conduct appeared in 10 actions. The SEC imposed a $100m penalty on Western Asset Management over the behaviour of its former chief investment officer Ken Leech, who admitted obstructing an investigation into an alleged cherry-picking scheme that steered profitable first-day trades towards favoured portfolios. Foundations Investment Advisors and its former chief executive Byron Rice were penalised $1.2m and $354,675 respectively over fiduciary and compliance breaches.

Data privacy remained prominent in Europe. The Dutch regulator AP fined MLU BV, operator of the Yango taxi app, $117.5m for sending sensitive driver and customer data to Russia, while authorities in Italy, France and the UK also acted. In the US, Delta Dental reached a $2.25m settlement with the NYSDFS over weak cyber incident response.

Financial crime accounted for seven penalties worth around $87m combined, led by CACEIS Bank UK’s $41.7m voluntary payment linked to the WealthTek affair. EagleBank paid $9.7m after senior executives repeatedly overrode compliance staff attempting to shut down a decade-long cheque kiting scheme run partly by an associate of the bank’s former chair.

Insurance intermediation produced three of the quarter’s ten largest fines, including AssuredPartners’ $107m civil settlement over ineligible Affordable Care Act enrolments and Société Générale’s $23.3m ACPR penalty for mis-selling insurance alongside packaged accounts.

Australia stood out, issuing its largest ever fine of $208m against CfD issuer Union Standard and imposing a first-of-a-kind $24.5m scam-controls penalty on HSBC. ASIC chair Sarah Court said, “Banks have been well on notice about the risks of scams for some time. They have now been given a clear message to have adequate controls and ensure their interactions with scam victims help – not hinder.”

AP chair Aleid Wolfsen said, “In Russia, personal data is not as well protected as in Europe. This may allow the Russian government to gain access to this data. The sensitive data of both customers and drivers should therefore have been extra well protected, especially given the absence of an independent data protection authority in Russia. We observed that this was not done properly. That is very serious. For example, because it can pose safety risks to people.”

The quarter’s message is unambiguous: governing controls is now as critical as having them.

Download the full enforcement report by Corlytics here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.