All Insights
Financial Crime

When the alerts go quiet: the 2026 surveillance fine, and the trap of controls that look complete

A £338k FCA fine wasn't about a missing surveillance system — it was about one that stopped seeing the trades that mattered. Here's the lesson for every monitoring and AML framework.

13 May 2026 · 4 min read


In March 2026 the FCA fined Dinosaur Merchant Bank Limited £338,000 — not because it lacked a surveillance system, but because the one it had stopped seeing the trades that mattered. After the firm switched on a new order-execution platform, CFD trading jumped by roughly 45%, and around $3.05 billion of trades flowed through between June and October 2024 without ever being fed into its automated surveillance tools. In the same window, alerts fell by 42%. Nobody caught it, because the board's monthly compliance reports showed alert counts without the comparison — this month against last — that would have made the drop obvious.

The root cause is one every firm should recognise: a change in the business wasn't matched by a change in the controls. The new platform went live with no change-control assessment of market-abuse risk, no check that trade data was actually reaching the surveillance engine, and — for much of the period — no written procedures for handling, escalating, or reporting alerts. The board had even been told, months earlier, that the system was missing items from a news feed used to trigger insider-dealing alerts. The consequence was real: genuinely suspicious trades slipped through, including one client who made £433,685 ahead of bid speculation, and a later sequence generating profits well into seven figures.

The question is not "do you have a policy?" but "does the control actually work, in your live environment, at your current volumes, after your latest system change?"

This is the part that matters for every firm, not just CFD brokers. The FCA is no longer reassured by controls that look complete on paper. Its recent enforcement across market abuse and anti-money laundering tells the same story: the question is not "do you have a policy?" but "does the control actually work, in your live environment, at your current volumes, after your latest system change?" A transaction-monitoring rule set that was well-calibrated two years ago can quietly decay as products, channels, and volumes shift. An alert scenario that has never fired isn't reassurance — it's a red flag worth investigating.

Two further points from the notice are worth sitting with. First, remediation helps but doesn't buy you out of enforcement. The firm cooperated fully, closed the CFD business, hired specialists, and replaced its system — and still received only a modest reduction in the penalty. Second, the FCA is moving faster and seeing more: this case ran nine months from opening to public outcome, and the regulator now processes tens of millions of transaction reports every day and is investing heavily in the data capability to spot outliers. The window to get ahead of a problem is shrinking.

What firms should do

  • Tie control reviews to change, not the calendar. Every material change to a product, platform, or execution route should trigger a documented reassessment of financial-crime risk, and a check that data is reaching your monitoring and surveillance systems — before go-live, or immediately after.
  • Treat silent alerts as a question, not a comfort. Test and recalibrate scenarios and thresholds regularly. If a rule never triggers, find out why.
  • Give the board MI that can actually reveal a failure. Alert volumes mean little in isolation; trends, comparisons against prior periods, and breakdowns by product and type are what let senior management see a control breaking.
  • Write it down. Undocumented policies for alert handling, escalation, and calibration are themselves treated as failings — even where the underlying judgement was sound.
  • Pressure-test what you already have. If your AML or surveillance controls were examined tomorrow, would they demonstrate effective risk management — or just a well-written set of documents?

Sources: FCA press release and Final Notice, Dinosaur Merchant Bank Limited (24–27 March 2026); Norton Rose Fulbright and Addleshaw Goddard commentary (April–May 2026); Therese Chambers, FCA speech "Beyond the headlines" (17 June 2026).

Need help applying this?

ComplyPath works with investment and payments firms on financial crime, CASS and safeguarding, Consumer Duty, regulatory remediation and authorisations.

Get in touch

Related Insights