Financial institutions keep spending heavily on compliance technology, yet the most damaging control failures continue to trace back to something no software can fix.
According to Vinay Vyas, who has more than 20 years’ experience on some of the world’s most complex financial crime cases, the root cause is rarely technology or process. It is culture, as detailed in a recent Argus Pro post.
The author points to one major case they led, in which a bank was fined $2.6bn. On paper, the institution appeared well protected. It had written policies, transaction monitoring and dedicated compliance teams. What it lacked was an environment where those controls were taken seriously.
Employees doubted that raising concerns would lead to action, and they had little faith that they would be protected if they spoke up. In effect, the culture had settled the outcome long before regulators became involved.
A more recent example reinforces the point. In October 2024, TD Bank agreed to pay around $3bn to US regulators, the largest penalty ever imposed under the Bank Secrecy Act. The Department of Justice cited ‘long-term, pervasive, and systemic deficiencies’ in the bank’s compliance programme, noting that more than 92% of transactions went unmonitored between 2018 and 2024.
While the technical shortcomings were serious, the finer detail reveals a deeper problem. Staff reportedly joked internally that the lender was ‘America’s most convenient bank’ for money laundering. Managers ignored warning signs, and one branch manager dismissed suspicious activity with laughter in a company email. Meanwhile, leadership enforced a ‘flat-cost’ budget on compliance even as the business expanded quickly, leaving the teams tasked with stopping illicit flows under growing strain.
The lesson, Vyas argues, is that systems can tell staff what to do, but culture determines whether they actually do it. Even the most sophisticated monitoring platform offers little protection if the people operating it believe no one cares about the alerts.
Importantly, Vyas stresses this is not an attack on firms now working to remediate their failings. The concern is that the same pattern recurs across jurisdictions, business sizes and types of financial institution.
For compliance leaders, that shifts the focus away from whether systems are adequate and towards the environment in which they operate. Reassuring dashboards matter less than candid answers to difficult questions.
Do compliance teams feel able to escalate issues, or pressured to handle them quietly? Are those who flag suspicious activity rewarded? Does leadership view compliance spending as a cost to be trimmed or a business necessity? And do employees at every level truly understand why controls exist?
Ultimately, technology is only a tool. Culture is the setting that decides whether that tool succeeds or fails.
Read the full ArgusPro post here.
Copyright © 2026 FinTech Global









