Expertise

Blog
How to Prevent Compliance Failures That Cost Millions
AI
AMER
Compliance
Regulatory

The most expensive compliance failures rarely involve anything breaking. No system goes down, no rule is deleted, no corners are cut. Every control operates exactly as designed, only for a version of the business that no longer exists.
This is how fast-growing financial institutions accumulate regulatory risk: not through negligence, but through drift.
Controls calibrated for an early-stage user base become inadequate as the business grows: transaction volumes rise, new products launch, and criminals adapt. The gap between actual risk and designed controls widens gradually at first, then rapidly.
The industry keeps learning the price of that gap, one settlement at a time.
What That Gap Costs
Earlier this month, Block – the payments provider behind Cash App – agreed a $45m settlement with a coalition of 46 US state attorneys general over allegations that its platform failed to adequately protect users from scams and fraud.
Block denied wrongdoing, and the allegations will feel familiar to anyone watching the sector: insufficient fraud controls, gaps in customer resolution, and marketing that outpaced protection.
That familiarity tells a story. Settlements of this kind have become a recurring feature of the fintech landscape, and they rarely stem from a single bad decision, rogue team, or missing rule.
They emerge structurally, from how institutions design, resource, and govern their controls. That structure is worth understanding, because it can be engineered against.
Compliance Failures Are Built, Not Broken
An organisation onboarding thousands of users a day is not the same institution it was at launch, even if its policies, thresholds, and staffing suggest otherwise. This pattern is visible across recent enforcement actions in the sector.
Allegations in the Cash App case included the absence of limits on account creation – allowing a single fraudster to operate networks of accounts – and incentives that encouraged growth while making it harder for customers to recover funds.
Whatever the merits of those claims, the underlying dynamic is familiar to anyone inside a scaling organisation: growth metrics are measured daily; control adequacy is assessed annually, if at all.
This asymmetry drives failure. When product velocity is governed in real time and risk capacity retrospectively, institutions are structurally set up to discover gaps through incidents, rather than design.
The Gap Between Detection and Resolution
Structural drift explains how gaps form. What happens after detection explains why they cost so much.
Financial crime programmes have traditionally been judged on identifying suspicious activity – alerts raised, reports filed, accounts flagged. Regulators are now asking a harder question: what happened to the customer?
The settlement terms are telling. Alongside financial remedies, the company committed to guaranteed access to live customer support – including telephone assistance and extended chat coverage. Regulators treated resolution as a compliance control, not a service feature.
This reflects a broader convergence. Consumer protection and financial crime prevention are collapsing into a single expectation: institutions must not only detect harm, but respond consistently, quickly, and at scale.
A detection programme that generates alerts faster than they can be investigated – or identifies victims faster than they can be helped – is, from a supervisory perspective, incomplete.
The economics explain why this gap is common. Detection runs on software; resolution runs on people. Institutions that grow tenfold rarely scale investigation and remediation capacity to match, and the difference accumulates as backlog, inconsistency, and, ultimately, enforcement risk.
The Threat Is Scaling Faster Than the Response
If internal drift were the only problem, institutions could eventually catch up. But the external picture is deteriorating at a pace that makes standing still equivalent to falling behind.
Reported consumer fraud losses in the US reached a record of roughly $16bn in 2025, up around 25% year-on-year and more than 400% since 2020 [1].
Behind these numbers sits a change in the nature of the adversary. Fraud is now industrialised: criminal networks operate with the coordination, tooling, and division of labour of legitimate enterprises, and they have adopted AI with striking speed.
The FBI recorded nearly $900m in losses from AI-enabled scams in 2025 alone [2], and Deloitte projects that generative AI could drive US fraud losses to $40bn by 2027 [3].
When attackers can generate convincing scam content, synthetic identities, and coordinated account networks at near-zero marginal cost, control frameworks that depend on linear human review are not merely inefficient, they are arithmetically outmatched.
An organisation can be diligent and well-intentioned yet still fall behind, because the operating model itself cannot absorb the volume.
Beyond Efficiency: How AI Improves Compliance Decisions
AI may be accelerating the threat, but it is also the most powerful tool to address it.
Its efficiency gains are well documented: faster queues, lower cost per alert, scalable capacity. But efficiency is the entry point, not the destination. The real impact lies in improving decision quality and consistency.
Consider the gaps highlighted in the recent case. Networks of connected accounts are difficult for rule-based systems and siloed review to detect, because each account appears unremarkable in isolation. AI systems that reason across entities can surface these networks, identifying patterns rather than fragments.
Consistency is another contribution. Human decision-making, however skilled, varies across analysts, across shifts, across the thousandth alert of the day. Two customers presenting identical risk profiles can receive different outcomes, and in a consumer protection context, that inconsistency is itself a source of harm and regulatory exposure.
Well-governed AI decisioning applies the same reasoning to the same facts every time, and does so at whatever volume the business generates. Scale stops being the enemy of quality.
Governance is where these gains are won or lost. An AI system that resolves alerts but cannot explain its reasoning simply relocates the compliance problem.
The standard institutions should demand is that every automated decision carries a documented, human-readable rationale that an investigator can review, a model risk team can validate, and a regulator can audit.
Explainability is not a feature of responsible AI adoption; it is the precondition for it. Systems built this way do something subtle but important: they convert compliance decisions from an operational cost into an institutional record of reasoning.
Designing for an Evolving Institution
For organisations drawing lessons from this case, the question is how to build frameworks that do not quietly age out of adequacy.
Scale controls with growth, by design: Risk capacity should be governed with the same cadence as product metrics. If onboarding volumes double, the institution should be able to state in advance, not in retrospect, how detection, investigation, and resolution capacity absorb that change.
Treat resolution as a control: Measure not only alerts raised but harms remediated: response times, consistency of outcomes, and the quality of the customer's path to a human when it matters. Supervisors are already doing this.
Move from transaction-level to network-level visibility: Individual accounts and payments are the wrong unit of analysis for modern fraud. The companies that see relationships – shared devices, funding patterns, behavioural linkage – will find what siloed reviews cannot.
Automate with an audit trail, not instead of one: Adopt AI where it improves decisions, and hold it to a governance standard: explainable rationale, human oversight where judgement is genuinely required, and full traceability from data to outcome.
Prepare for the Institution You Are Becoming
The most expensive compliance failures are rarely failures of intent. They are failures of architecture, with frameworks designed for yesterday applied to today's volumes, and examined only after harm has occurred.
The recent settlement will be remembered as a single company's regulatory event, but its real significance is as a case study in how the gap between growth and governance forms, and how predictably it is discovered.
The organisations that avoid the next such settlement will not be those that write more rules or hire faster than fraud grows. They will be the ones that treat compliance as an engineering discipline: decisions that remain consistent at any scale, explainable in every instance, and designed for the institution they are becoming, not the one they used to be.
Share article








