One Constellation
Free Interactive Tool

AML Fine Exposure Estimator

Model the scale of regulatory penalty a control failure could expose your firm to, using the sanctioning frameworks that supervisors actually apply — breach type, duration, scope, and whether you self-reported.

Eight regimes Illustrative modelling only Nothing is stored

Model an exposure scenario

Updates live
Indicative exposure range
to
Midpoint as a share of turnover
Headline statutory ceiling
Combined aggravating multiplier
What is moving the number
    Read this before using any figure here. This is an illustrative model, not legal advice, not a prediction and not a substitute for counsel. Regulators set penalties case by case using their own published frameworks, and outcomes are shaped by facts this tool cannot capture — the nature of the harm, the firm's history, precedent, negotiation, and in many cases parallel criminal or civil proceedings. Actual outcomes routinely fall well outside any modelled range in both directions. Statutory references are simplified summaries and may not reflect recent amendments. If you are facing or anticipating an enforcement matter, take qualified legal advice. Nothing you type here is transmitted or stored.
    Methodology

    How supervisors actually set a penalty

    Penalty frameworks differ in detail between regimes but share a common shape. A supervisor starts from a figure anchored to either the financial benefit derived from the breach or the revenue associated with the affected business, adjusts it for the seriousness of the conduct, adjusts again for aggravating and mitigating factors, then applies a discount for early settlement or cooperation. This model follows the same sequence, which is why the inputs are the ones supervisors actually weigh.

    Seriousness

    The nature of the failure dominates. A record-keeping deficiency found in a routine inspection sits at one end. A sanctions breach, a systemic failure to screen, or a failure to report suspicious activity that allowed criminal proceeds to move sits at the other, because the harm is not hypothetical. Governance failures attract particular weight where a supervisor concludes senior management knew or should have known.

    Duration and scope

    How long the failure ran, and how much of the book it touched, converts a control weakness into a systemic one in the supervisor's eyes. A gap affecting a handful of files over three months reads as an operational lapse. The same gap across half the book over four years reads as a failure of the control framework itself, and is priced accordingly.

    Conduct after discovery

    This is the single factor most within a firm's control, and it moves outcomes substantially. Self-reporting before the supervisor finds the issue, remediating comprehensively rather than minimally, and cooperating fully through the investigation attract meaningful reductions in almost every regime. Prior enforcement history, incomplete disclosure or obstruction have the opposite effect.

    What this model deliberately excludes

    • Criminal liability and prosecution of individuals, which in several regimes carries imprisonment.
    • Disgorgement of profits, which can dwarf the penalty itself.
    • Licence restrictions, business prohibitions, growth caps and the imposition of a skilled person or independent monitor.
    • The cost of remediation, which for a large back-book exercise frequently exceeds the fine.
    • Loss of correspondent banking relationships and the commercial damage that follows.
    The controllable part

    What supervisors look for when they arrive

    In most enforcement actions the underlying control existed. What was missing was evidence that it had been applied consistently and that exceptions had been handled properly.

    📋

    Evidence, not intent

    A policy document proves what you intended. An immutable audit trail showing every check, every decision, every approver and every override rationale proves what you did.

    🔁

    Consistency across files

    Supervisors sample. If ten files produce ten different approaches to the same risk factor, the finding is about the framework rather than the files.

    ⏱️

    Timeliness of the response

    How quickly a sanctions hit was actioned, a suspicious pattern escalated, or a periodic review completed is measurable — and it is measured.

    One Constellation is built so that the evidence is a by-product of doing the work rather than a separate exercise before an inspection. Every customer is scored on the same matrix, every screening alert carries its disposition and rationale, every document is version-controlled against the customer record, and every approval records who gave it and under what authority. Reporting is generated on demand rather than reconstructed from shared drives when a supervisor asks.

    Questions

    About AML penalties

    How are AML fines calculated?+
    Most supervisors publish a penalty framework that starts from a figure linked either to the benefit derived from the breach or to revenue from the affected business area, then adjusts for seriousness, duration, scope, aggravating and mitigating factors, and finally applies a settlement discount. The frameworks are structured, but they leave substantial discretion, which is why any model of them can only be indicative.
    Is a fine the largest cost of an AML failure?+
    Frequently not. Remediation of a back book, the cost of a skilled person or independent monitor, business restrictions or growth caps, the loss of correspondent banking relationships, and the management time absorbed by an investigation regularly exceed the penalty itself. Criminal exposure for individuals sits outside the financial calculation entirely.
    Does self-reporting reduce the penalty?+
    In most regimes, meaningfully. Self-reporting before the supervisor discovers the issue, remediating comprehensively and cooperating throughout are recognised mitigating factors, and the reduction applied is often substantial. It is also the factor most within a firm's control once a problem has occurred.
    Can individuals be held personally liable?+
    Yes. Many regimes provide for action against senior managers, money laundering reporting officers and directors, including personal financial penalties, prohibition from holding regulated roles, and in serious cases criminal prosecution and imprisonment. Governance failures are treated as individual accountability failures as much as institutional ones.
    Are the statutory ceilings in this tool exact?+
    No. They are simplified summaries of headline provisions intended to give a sense of scale, and they may not reflect recent amendments, sector-specific rules, or the way per-violation structures aggregate in practice. Verify the current position for your regime with counsel before relying on any figure.
    How can we reduce exposure in practice?+
    Apply your risk methodology consistently to every customer, screen continuously rather than at onboarding only, keep periodic review current, and make sure every decision leaves an evidenced trail with a named approver. Most enforcement findings are about the gap between the documented control and the demonstrable execution of it. See our AML and CFT solution.

    Be able to prove it, not just say it

    Book a 30-minute demo and see how every check, decision, approval and override is captured as regulator-ready evidence by default.

    Scroll to Top