AML Enforcement Surge: Norton Rose Fulbright Warns Banks
AML Editor•December 24, 2025

The headline reports that the international law firm Norton Rose Fulbright has warned banks of a rise in anti-money-laundering enforcement. Warnings of this kind are a routine feature of the market for legal advice. What follows explains what such publications are, what an enforcement surge normally looks like, and how banks tend to respond to one.
What a law firm's warning is, and is not
Client alerts and horizon-scanning notes published by law firms are awareness and business-development material. They are not regulatory instruments, and they are not legal advice to any particular institution. They are assembled from public sources: enforcement actions and consent orders, supervisory speeches and published annual priorities, consultation papers, thematic reviews and penalty notices. Their value lies in aggregation — noticing that several separate actions share a theme — rather than in disclosing anything confidential. They are best read as one input to a bank's own horizon scanning, checked against the primary sources they cite, and kept distinct from the privileged advice a firm gives once actually instructed.
What an enforcement surge looks like
Enforcement rarely arrives without warning. Supervisors generally escalate along a path: informal feedback, then examination findings, then formal requirements to remediate within a defined period, then public action if remediation fails or the underlying conduct is serious. A perceived surge usually reflects one or more of the following: a change in stated supervisory priorities; the maturing of a cohort of investigations opened years earlier, since large matters take a long time to conclude; a decision to pursue individuals as well as institutions; or the extension of obligations to conduct or sectors previously outside scope.
The powers typically in play
- requirements to commission an independent review of controls, generally at the firm's own expense;
- variation, restriction or withdrawal of permissions, including limits on onboarding or on growth;
- financial penalties, set by reference to the seriousness of the breach and, in many regimes, to revenue;
- undertakings and remediation plans with fixed milestones and periodic reporting to the supervisor;
- action against senior individuals under accountability regimes that attach named responsibilities to named people;
- referral for criminal investigation where the facts warrant it.
How banks generally respond
The response to a credible warning is usually a stocktake rather than a new programme. Boards ask for an honest assessment of where the evidence is thin: due diligence records that cannot be produced on demand, monitoring rules never tested against known outcomes, alert and refresh backlogs, incomplete beneficial ownership data, sanctions screening not tuned for name variation or transliteration. Where a gap is confirmed, the next question is whether a historic look-back is needed and whether past reporting was adequate.
Two themes recur in supervisory commentary. The first is that self-identification counts: an institution that finds, reports and fixes a problem is treated differently from one whose failure is discovered for it. The second is that resourcing and standing matter — compliance functions need the authority to escalate and the budget to act, and supervisors look for evidence that both existed at the time of the failure, not only in the remediation that followed.
