When the fine lands on you personally
October 1, 2026
- Featured article
- Industry and regulatory news
Exploring the global shift toward individual accountability in AML enforcement and what it means for compliance officers who cannot demonstrate how their country risk decisions were reached.
On 24 June 2026, the Central Bank of the UAE announced two penalties from the same investigation. A foreign bank branch received a fine of AED 20 million for significant, repeated failures in its AML, counter-terrorist financing, and sanctions controls. The branch's Head of Compliance and MLRO received a separate fine of AED 300,000 in his own name for failing to fulfil the responsibilities of his role.
The MLRO was not accused of facilitating money laundering. No criminal act was alleged. The basis for the personal fine was an administrative failure: inadequate execution of a compliance function. Under Federal Decree-Law No. 10 of 2025, which came into force on 14 October 2025 and replaced the UAE's entire AML framework, that is sufficient for personal liability.
A global shift in who pays
Across jurisdictions, regulators are increasingly targeting the individuals responsible for frameworks that failed, alongside the institutions themselves.
In July 2025, Singapore's MAS imposed S$27.45million in composition penalties on nine financial institutions for AML failures connected to the 2023 S$3 billion money laundering case. Alongside the institutional penalties, MAS issued prohibition orders and reprimands against 18 individuals, including CEOs, Chief Operating Officers, and relationship managers. Prohibition orders ranged from three to six years. In March 2026, MAS issued further prohibition orders of 16 and 7 years respectively against two former relationship managers convicted of charges connected to the same case. FATF's May 2026 mutual evaluation of Singapore recognised the enforcement sweep as a model of responsive individual accountability.
In the US, the OCC explicitly uses enforcement actions against institution-affiliated parties, including compliance officers and senior managers, as a deterrent. The Haider case - in which FinCEN assessed a $1 million civil penalty against the former Chief Compliance Officer of MoneyGram in 2014 for wilful Bank Secrecy Act violations - established the legal basis for individual compliance officer liability in the US, a precedent regulators have built on since. The EU's Sixth Anti-Money Laundering Directive extends criminal liability to individuals, including compliance officers and directors, who fail to prevent or report money laundering within their organisations.
What changed under UAE Federal Decree-Law No. 10 of 2025
The UAE case is the most significant recent development in personal AML liability for compliance professionals and deserves specific attention. The new law introduced a "should have known" standard for senior managers and compliance officers. Under the previous framework, prosecutors needed to demonstrate actual knowledge of illicit activity. Under Decree-Law 10, knowledge can be inferred from objective circumstances a reasonable compliance officer in that role should have identified and acted on.
This matters because it represents a materially lower evidentiary threshold than the wilful violation standard applied in the US Haider case. An MLRO is now exposed in the UAE not only for what they knew, but for what they should have known given the information available to them. The May 2025 precedent established the pattern: a branch manager was personally fined AED 500,000 and permanently banned from the UAE financial sector following an AED 200 million sanction against his exchange house. The June 2026 case confirmed the same approach applies to MLROs and Heads of Compliance specifically, independently of the institutional fine and in the same enforcement action.
The country risk dimension
Personal liability has made the compliance question more specific. When a regulator asks how a country risk rating was reached, the person answering that question increasingly faces personal exposure that regulators across the UAE, Singapore, and the US are now actively exercising.
The specific vulnerabilities are documented in recent enforcement findings across multiple jurisdictions: customer risk assessments that did not reflect actual jurisdiction risk, EDD that was not applied where the risk evidence required it, transaction monitoring calibrated to corridor risk that was never properly assessed, and documented policies that did not reflect what was happening in practice. In each case, the institutional failure traced back to a process that a compliance officer had signed off on, or failed to challenge.
A compliance officer who cannot demonstrate how a country risk rating was reached, what sources informed it, who reviewed it, and when it was last updated, faces personal exposure that was theoretical two years ago and is operational today. The UAE case establishes that administrative failure - the absence of adequate process - is sufficient grounds for a personal fine.
What defensible looks like
Personal liability gives robust, documented country risk assessment a more direct purpose: professional protection for the individuals responsible for the framework.
At KnowYourCountry, our methodology has been trusted by regulated businesses and government agencies for over 20 years. Our assessments across 245+ jurisdictions are built around the risk categories regulators use to evaluate AML/CFT quality, including a recently expanded methodology covering proliferation financing, environmental crime, arms trafficking, and transparency and beneficial ownership as standalone categories. Every data point cites a verifiable source, every change has analyst sign-off, and updates are tracked and documented. The methodology is entirely human-overseen.
When a regulator asks how a country risk decision was reached, the answer needs to hold up. For the compliance officers and MLROs increasingly in the frame, that answer now carries personal weight.
Subscribe to Country AML Risk News
Don’t want to miss an issue? Get this newsletter delivered straight to your inbox.