AML Fine Exposure Estimator
Model the scale of regulatory penalty a control failure could expose your firm to, using the sanctioning frameworks that supervisors actually apply — breach type, duration, scope, and whether you self-reported.
Model an exposure scenario
Updates liveHow supervisors actually set a penalty
Penalty frameworks differ in detail between regimes but share a common shape. A supervisor starts from a figure anchored to either the financial benefit derived from the breach or the revenue associated with the affected business, adjusts it for the seriousness of the conduct, adjusts again for aggravating and mitigating factors, then applies a discount for early settlement or cooperation. This model follows the same sequence, which is why the inputs are the ones supervisors actually weigh.
Seriousness
The nature of the failure dominates. A record-keeping deficiency found in a routine inspection sits at one end. A sanctions breach, a systemic failure to screen, or a failure to report suspicious activity that allowed criminal proceeds to move sits at the other, because the harm is not hypothetical. Governance failures attract particular weight where a supervisor concludes senior management knew or should have known.
Duration and scope
How long the failure ran, and how much of the book it touched, converts a control weakness into a systemic one in the supervisor's eyes. A gap affecting a handful of files over three months reads as an operational lapse. The same gap across half the book over four years reads as a failure of the control framework itself, and is priced accordingly.
Conduct after discovery
This is the single factor most within a firm's control, and it moves outcomes substantially. Self-reporting before the supervisor finds the issue, remediating comprehensively rather than minimally, and cooperating fully through the investigation attract meaningful reductions in almost every regime. Prior enforcement history, incomplete disclosure or obstruction have the opposite effect.
What this model deliberately excludes
- Criminal liability and prosecution of individuals, which in several regimes carries imprisonment.
- Disgorgement of profits, which can dwarf the penalty itself.
- Licence restrictions, business prohibitions, growth caps and the imposition of a skilled person or independent monitor.
- The cost of remediation, which for a large back-book exercise frequently exceeds the fine.
- Loss of correspondent banking relationships and the commercial damage that follows.
What supervisors look for when they arrive
In most enforcement actions the underlying control existed. What was missing was evidence that it had been applied consistently and that exceptions had been handled properly.
Evidence, not intent
A policy document proves what you intended. An immutable audit trail showing every check, every decision, every approver and every override rationale proves what you did.
Consistency across files
Supervisors sample. If ten files produce ten different approaches to the same risk factor, the finding is about the framework rather than the files.
Timeliness of the response
How quickly a sanctions hit was actioned, a suspicious pattern escalated, or a periodic review completed is measurable — and it is measured.
One Constellation is built so that the evidence is a by-product of doing the work rather than a separate exercise before an inspection. Every customer is scored on the same matrix, every screening alert carries its disposition and rationale, every document is version-controlled against the customer record, and every approval records who gave it and under what authority. Reporting is generated on demand rather than reconstructed from shared drives when a supervisor asks.
About AML penalties
Other free compliance tools
Be able to prove it, not just say it
Book a 30-minute demo and see how every check, decision, approval and override is captured as regulator-ready evidence by default.
