Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

Key takeaways  Introduction: failure to go beyond filing a risk report leads to an AML conviction  In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office.  14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…

Corey Avatar

Key takeaways 

  • In July 2026, a Swiss court fined Lombard Odier CHF 3 million for money-laundering failures, despite the bank flagging concerns back in 2012. 
  • The court found the bank’s compliance function did not adequately investigate or document the origin of tainted funds flowing through a client’s accounts. 
  • This is the latest in a series of fines for banks and fintechs around the world, all with a similar pattern of a gap left unresolved: Monzo in the UK, Revolut in Lithuania and Westpac in Australia. 
  • Filing a report is not the same as managing a risk; regulators increasingly expect organizations to show ongoing action, not a one-off escalation. 
  • GRC teams should build defined escalation pathways with a clear next step, and treat customer and third-party risk monitoring as continuous, not periodic. 

Introduction: failure to go beyond filing a risk report leads to an AML conviction 

In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office. 

14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court has convicted Lombard Odier anyway. On 27 July 2026, the court in Bellinzona fined the bank CHF 3 million (about $3.7 million) for failing to take adequate organizational measures to prevent money laundering, in an investigation now known as the Uzbek case. 

It’s the latest in a series of examples of a risk identified, a report filed, and a gap before anyone asked whether the reporting had changed anything. It’s seen in anti-money laundering (AML) cases around the world and it’s part of a wider pattern that CoreStream GRC has seen, as regulators move from rewarding paperwork to demanding proof that a program actually works

Why “we told them” is neither a defense nor an adequate GRC strategy 

The case centers on Gulnara Karimova, daughter of Uzbekistan’s late president Islam Karimov, and a structure prosecutors called “the Office”, which allegedly channeled proceeds from bribes paid by foreign telecoms companies for access to the Uzbek market. A former Lombard Odier relationship manager, identified in court documents only as C., had prior ties to people connected with the Office before joining the bank in 2008. Over the next 4 years, he opened 9 accounts designed to receive the scheme’s proceeds, using fabricated beneficial ownership information. He was convicted of aggravated money laundering, given a 2-year suspended sentence, and is reported to have managed around $140 million connected to the scheme. The court ordered more than $400 million in related Swiss assets confiscated. 

Lombard Odier’s defense rested on having “proactively reported suspicions to the Swiss authorities” in 2012, and on the fact that the Office of the Attorney General has never alleged the bank knowingly participated in money laundering. The court didn’t dispute either point but found that the bank’s compliance function “did not take sufficient measures to ensure that further enquiries regarding the origin and economic purpose of these funds were conducted and duly documented.” 

Lombard Odier was not accused of intending to launder money. The conviction rests on whether the bank kept asking the right questions – from the time the suspicions were reported (in 2012) until the prosecution was opened in 2016 – rather than treating an early report as the end of its obligation.  

Reporting is not remediation: compliance and risk-monitoring should be a continuous process  

This is the same problem CoreStream GRC has flagged in GRC monitoring more broadly: a static, point-in-time action such as a report filed gets mistaken for an ongoing, managed state.

But a report to a financial intelligence unit is only one data point, what the bank believed at that moment. It does not discharge an ongoing duty to keep asking questions as the relationship continues. 

Under Swiss law, companies can face criminal liability for not doing enough to stop money laundering, regardless of any individual employee’s intent.  

“Did we spot the problem?” is not enough. As Paul Cadwallader, GRC Strategy Director at CoreStream GRC, puts it: 

“A suspicious activity report is a snapshot of what you believed at one moment. Money-laundering risk doesn’t stop when the report is filed, so your scrutiny shouldn’t either. If the evidence trail on a client relationship ends the day you escalated it, you haven’t managed the risk, you’ve only made a note of it.” 

Paul Cadwallader, GRC Strategy Director, CoreStream GRC 

How poor AML process became a global governance, risk and compliance problem 

Lombard Odier isn’t alone. The same gap between AML controls and actual results is at the center of some of the largest recent AML enforcement actions around the world. 

In the UK, the FCA fined Monzo Bank £21.1 million for financial crime control failings between 2018 and 2020, as its customer base grew nearly tenfold. The bank then breached a specific FCA-imposed restriction on opening accounts for high-risk customers, onboarding more than 34,000 of them between 2020 and 2022: a specific, known constraint that the system didn’t adhere to.  

The problem isn’t limited to traditional banks; fintechs face the same challenge. In 2025, the Bank of Lithuania fined Revolut’s local banking entity €3.5 million for breakdowns in transaction monitoring and gaps in detecting suspicious activity. As with Lombard Odier, the regulator didn’t conclude money laundering had occurred, only that the system meant to catch it wasn’t working. 

In Australia in 2020, Westpac agreed to pay A$1.3 billion, the largest civil penalty in Australian corporate history, after admitting to more than 23 million breaches of anti-money laundering law. At the heart of the case was a coding error introduced during a 2013 IT system upgrade, which caused the bank to stop reporting more than 19.5 million international funds transfers, worth over A$11 billion, to AUSTRAC. The error went undetected and uncorrected for nearly five years, a known gap in an established process that nobody closed. 

In each of these examples, the common thread isn’t a failure to notice a risk or to keep an existing reporting system running. It’s that the follow-through didn’t hold: a report not chased, a control left to lapse, a known defect left unfixed for years. 

Illicit financial activity now runs to an estimated $4.4 trillion a year globally with money laundering alone estimated at 2 – 5% of global GDP, or $800 billion – $2 trillion. Set against those figures, and the recent corporate failures, a sharper regulatory focus is understandable. 

Incident Management solution download

Tightening regulation increases pressure on GRC teams 

The move towards principle-based GRC regulation, as previously discussed by CoreStream GRC, is coupled with tighter AML regulation like the EU’s new Anti-Money Laundering Regulation which creates a standalone supervisor, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), and harmonizes AML rules across all 27 member states for the first time.  

AMLA, based in Frankfurt, is expected to begin selecting roughly 40 of the highest-risk cross-border institutions for direct supervision from 2027, in what Deloitte Legal has called “a turning point” for money-laundering prevention across the bloc. 

Switzerland isn’t an EU member state, but as Deloitte’s Swiss practice puts it, Swiss institutions are affected “either directly, if you operate EU subsidiaries or branches, or indirectly”, since Swiss banks “cannot ignore the potential of regulatory arbitrage by customers trying to leverage the differences in the Swiss regime.” Lombard Odier itself operates across France, Belgium, Luxembourg, Italy and Spain, so its EU-facing business falls directly under the new rulebook regardless of Switzerland’s status.  

The UK sits in a comparable position, outside the EU but tightening its own supervision independently through the FCA. And because neither the UK nor Switzerland holds an EU AML “equivalence” decision, cross-border transactions between EU institutions and their UK or Swiss counterparts must satisfy enhanced due diligence on both sides of the border, not just one. 

On the other side of the world, Australia’s reforms are the most significant changes to its anti-money laundering and counter-terrorism financing (AML/CTF) rules in nearly 2 decades. From 1 July 2026, its “Tranche 2” reforms bring almost 100,000 new entities under its remit. These include lawyers, accountants and real estate agents, with customer due diligence, suspicious matter reporting and 7-year record-keeping now required. 

What GRC teams should do now to close the reporting-to-remediation gap 

Lombard Odier’s conviction, along with the Monzo, Revolut and Westpac cases, all point to the same set of practical fixes. 

Build a ‘then what happens’ step into every escalation 

A suspicious activity report or an internal escalation, should never be the last entry in a case file. Define, in writing, what happens next: does the relationship get restricted, does a senior compliance officer review it within a set number of days, does the client get re-underwritten? To effectively manage risk. a process needs to go beyond “we reported it.” 

Treat ongoing monitoring as a live control, not a paper requirement 

Continuous monitoring is the law already. The UK’s Money Laundering Regulations 2017 require “ongoing monitoring of the business relationship” as a standing customer due diligence duty, and FATF’s Recommendation 10 sets the same expectation globally. Failure in cases like this isn’t because of a missing rule. It’s caused by a monitoring duty that exists on paper but isn’t resourced, tested or evidenced as an active control for higher-risk relationships. The same discipline applies to third-party and vendor risk more broadly: check that ongoing monitoring is demonstrably happening, not just documented as a requirement. 

AI tools are here to support this, as VP of Compliance at Pension Bee explains in a recent Spotlight on Women in GRC podcast episode: 

“AI will probably be able to monitor behaviors and track behaviors a lot quicker than a human being can. And although you need that oversight from a human being, when it comes to things like financial crime, and you have a lot of fraudsters out there who are already getting ahead with AI and deepfakes, the only way to stay on top and keep people safe is to learn the system yourself and get ahead of it.”

Jaypee Soule, VP Compliance and MLRO, PensionBee  

Learn about our AI partner’s continuous control monitoring here. 

Diversify how problems reach you 

A clean-looking record is only credible if issues surface through more than one channel: internal audit, external audit, self-identified review and whistleblowing, not just the relationship manager who opened the accounts. 

Make the evidence trail outlive the individual 

In the Lombard Odier case, C. ran the accounts largely under his own oversight for 4 years. Case ownership shouldn’t depend on one person’s continued attention; a monitored relationship needs a documented, reviewable trail that survives staff turnover and departures. 

Conclusion: build the follow-through, not just the report 

Lombard Odier disputes the court’s findings and has confirmed it will appeal. Whatever the outcome, the lesson remains that a report filed once, however proactively, isn’t a substitute for sustained scrutiny over a relationship’s life. Regulators around the world are converging on that expectation. 

If your organization’s AML, third-party or customer risk processes end at the point of escalation rather than continuing through to resolution, that gap should be closed before a regulator finds it for you. 

The cost of getting this wrong is not only the fine. A criminal conviction, a published judgment setting out exactly what a compliance function failed to do, and a bank’s name now permanently attached to a corruption case carry a reputational cost that outlasts the CHF 3 million penalty. Reputation, client trust and investor confidence will still be damaged long after the fine has been paid. 

CoreStream GRC can help you connect risk, escalation and remediation into a single, defensible record rather than a filing cabinet of one-off reports. Book a workshop to review your financial crime escalation model, or request a demo to see how CoreStream GRC turns scattered case files into continuous, audit-ready oversight. 

Frequently asked questions about the Lombard Odier money-laundering case

What did Lombard Odier actually do wrong, according to the Swiss court? 

The court found that the Lombard Odier’s compliance function did not take sufficient measures to investigate and document the origin of suspicious funds once the relationship was already open, which under Swiss law can create corporate criminal liability independent of any individual employee’s intent. The court did not find that the bank intended to launder money, or that its initial 2012 report to Swiss authorities was inadequate. 

Is filing a suspicious activity report enough to protect a company from liability? 

No. This case, alongside the Monzo, Revolut and Westpac enforcement actions, demonstrate that an initial report or escalation is only the start of an ongoing obligation. A defensible anti-money laundering compliance risk assessment needs a documented ‘what happens next’ step, evidence that scrutiny continued, not simply a record that a concern was raised and logged. 

How does individual liability differ from organizational liability in money-laundering cases? 

In the Lombard Odier case, a former relationship manager was convicted of aggravated money laundering and given a 2-year suspended prison sentence for his own conduct in opening and running specific accounts. The bank was separately convicted for organizational failings, whether its systems, escalation processes and oversight did enough to prevent and catch the misconduct, regardless of whether senior management knew about it. 

Does this case affect financial institutions outside Switzerland? 

Yes. The same underlying pattern, a known control gap left unresolved, drove the UK FCA’s £21.1 million fine against Monzo, the Bank of Lithuania’s €3.5 million fine against Revolut, and Australia’s AUSTRAC’s A$1.3 billion penalty against Westpac. The EU’s incoming AML Regulation and its new supervisor, AMLA, will also reach beyond the bloc’s own borders, since Swiss or UK institutions with EU branches, subsidiaries or cross-border clients must meet it directly, regardless of where they are headquartered. 

  • Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Key takeaways  Introduction: failure to go beyond filing a risk report leads to an AML conviction  In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office.  14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…

  • Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questions 

    Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questions 

    In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague sits down with Emma Price, Partner at Brave, former Deloitte partner and one of the UK’s leading voices in risk and resilience.   With more than 25 years of experience helping boards navigate uncertainty, Emma shares:  Curiosity: The skill that launched a 25-year career in GRC and a…

  • CoreStream GRC 3.6 Release Notes

    CoreStream GRC 3.6 Release Notes

    1.0      Document purpose This document provides a summary of the highlights of the CoreStream GRC Release 3.6 release. Major Platform releases are finalized every 2-3 months depending on client and strategic priorities. These release notes are part of CoreStream GRC’s approach to keeping clients and partners informed of the improvements we are delivering. This document…