Your Gateway to Understanding AML Made Simple.

When Growth Outpaces Compliance: Wise’s AML Failures Case Study

Posted by:

|

On:

|


By Viktor Ha | July 2026 | AML-CAMS Blog


TL;DR: On 24 July 2026, the US Office of the Comptroller of the Currency rejected Wise’s application for a national trust bank charter, citing longstanding AML/CFT deficiencies. It is the OCC’s first fintech charter denial this year, after approving more than two dozen others. The rejection lands weeks after Belgian prosecutors disclosed a criminal investigation into more than 500 million euros in suspicious transactions moving through Wise’s European operations. Both events sit on top of a UK sanctions breach in 2023, a Belgian customer identification remediation order in 2024, and US state-level AML fines in 2025. This post examines what an AML compliance failure across jurisdictions actually looks like when it plays out at scale, inside one of the world’s largest cross-border payment platforms, and what it means for practitioners assessing global fintech partners.


A Pattern Five Years in the Making

Most enforcement stories on this blog centre on a single institution, a single regulator, and a single moment of reckoning. Wise’s story is different because it is not one event. It is five, spread across three countries and three years, all pointing at the same underlying problem.

On 24 July 2026, the US Office of the Comptroller of the Currency rejected Wise’s application to charter a national trust bank in the United States. The OCC’s letter did not equivocate. It found “significant supervisory and compliance concerns,” including “longstanding deficiencies” in Wise’s anti-money laundering and counter-terrorism financing controls, and concluded that Wise’s proposed management and directors had failed to demonstrate sufficient experience with either fiduciary banking activities or the practical demands of US banking law. The OCC noted plainly that “Wise US has a record of failing to comply with the applicable [money service business] requirements.”

Wise’s shares fell as much as 9% on the news. The rejection lands at a particularly uncomfortable moment. Wise moved its primary stock market listing from London to Nasdaq in May 2026, specifically to pursue deeper growth in its largest and most important market. A rejected US banking charter, attributed explicitly to AML failures, is not a minor setback to that ambition. It is a direct hit to the reason the company moved its listing in the first place.

What makes the rejection more significant still is its context. This is the OCC’s first public denial of a fintech charter application this year, after approving more than two dozen others. Wise did not fail an unusually strict test. It failed a test that dozens of comparable applicants passed.


The Belgian Investigation Running in Parallel

The OCC decision did not arrive in isolation. Weeks earlier, in June 2026, Belgian prosecutors disclosed a criminal investigation into Wise Europe, the company’s Brussels-based subsidiary responsible for its European Economic Area operations.

The Brussels Public Prosecutor’s Office opened the investigation after Wise accounts surfaced repeatedly in hundreds of criminal files submitted to Belgium by more than 30 European countries, through formal cross-border judicial channels including European Investigation Orders and international letters rogatory. The federal police’s organised crime unit, known as DJSOC, is handling the matter. Prosecutors are examining transactions exceeding 500 million euros, roughly $569 million USD at the exchange rate reported at the time, allegedly linked to fraud, drug trafficking, and corruption.

It is important to be precise about what is and is not being alleged. The investigation concerns whether Wise’s AML controls were adequate to detect and report the alleged criminal misuse of its platform. It is not an allegation that Wise defrauded its own customers or that individual customer funds are at risk. The company’s own financial conduct is not what is under scrutiny. Its capacity to detect and report the criminal use of its platform by others is.

Wise’s public response has been notable for what it does not address. The company stated that responding to law enforcement information requests is “a normal part of operations” and “not, in themselves, indicative of non-compliance.” That framing is accurate as a general statement about how AML systems function. But as American Banker’s reporting observed, it sidesteps the prosecutor’s actual allegation, that Wise accounts appeared repeatedly in criminal files across 30 countries because the company failed to properly identify its clients and understand their activity. Answering “we routinely respond to requests” does not answer “why do you appear so often.”

The investigation is reportedly nearing a direct summons to criminal court, a Belgian legal mechanism that allows prosecutors to proceed without an investigating judge. That procedural detail typically signals prosecutors believe they already have sufficient evidence to proceed. Wise’s shares fell as much as 20% when the investigation was first disclosed.


The Pattern That Precedes Both Events

Neither the OCC rejection nor the Belgian investigation emerged from nowhere. Both sit at the end of a trail that stretches back three years.

In 2023, the UK’s Office of Financial Sanctions Implementation found that Wise had breached financial sanctions against Russia. Sanctions screening is one of the most foundational controls in any AML/CTF program. A breach at this level points to a gap not in a peripheral process, but in one of the core pillars of the compliance architecture.

In 2024, the National Bank of Belgium found that Wise lacked proof of address documentation for hundreds of thousands of customers, a basic customer due diligence failure at meaningful scale, and forced the company into a formal remediation plan. That remediation plan predates the current Belgian criminal investigation by two years, meaning Belgian regulators had already identified and acted on foundational CDD gaps well before prosecutors began examining the half-billion-euro transaction pattern now under investigation.

In July 2025, several US state regulators fined Wise a combined $4 million for AML shortcomings, a full year before the OCC’s federal rejection. US regulators at the state level had already flagged compliance concerns before the federal charter application was even decided.

Five events. Three jurisdictions. Three years. One consistent thread: a platform that scaled its customer base, transaction volume, and global licence footprint considerably faster than it scaled the maturity of its AML controls.


Why Scale Doesn’t Explain This

It would be easy to read this pattern as the ordinary growing pains of a fast-expanding fintech. That reading does not survive contact with the actual numbers.

Wise is not a resource-constrained startup. It serves more than 19 million active customers, processes approximately 4.7 million transactions a day, holds more than 80 regulatory licences across the world, and generated roughly $2.5 billion in revenue for its 2026 financial year. In its own regulatory filings, Wise has stated that it assigns roughly a third of its global staff to protecting customers from financial crime.

That is a company with the resources to build a mature, jurisdiction-consistent AML program. The pattern across the UK, Belgium, and the US suggests the resources existed. What appears to have lagged is the discipline to ensure AML maturity kept pace with expansion into new products, new licences, and new jurisdictions at the same rate the business itself was growing.

This is the same failure mode this blog has traced across the fintech sector all year. Airwallex’s transaction monitoring was found not to be calibrated to the platform’s actual cross-border risk, a program that had not evolved at the same pace as the business it was meant to govern. HSBC’s scam controls existed on some payment rails but not the one carrying the highest volume of actual risk. Wise’s pattern adds a further dimension to that lesson: the gap is not confined to a single channel or a single jurisdiction. When a platform operates in dozens of countries, a control that is adequate in one jurisdiction does not automatically transfer to another, and Wise’s history suggests that assumption was tested and found wanting more than once.


What This Means for Practitioners Assessing Global Platforms

For Australian AML practitioners, Wise’s case carries a specific and practical lesson, separate from the international headlines.

Wise Australia Investments Pty Ltd holds an Australian Financial Services Licence and is registered with AUSTRAC as a remittance service provider, placing it under the same category of AML/CTF obligations as any other reporting entity in that sector. There is no publicly disclosed AUSTRAC enforcement action against Wise’s Australian operations specifically, and this post does not suggest one exists. The relevant lesson is structural, not case-specific.

A global platform’s AML maturity in one jurisdiction is not a reliable predictor of its maturity in another. Wise’s controls have been found deficient in the UK, inadequate in Belgium on two separate occasions, and insufficiently mature to satisfy a US federal banking regulator, all while the same company continued operating without equivalent public findings in other markets, including Australia. For practitioners at institutions with correspondent relationships, banking partnerships, or onboarding arrangements involving multinational payment platforms, that unevenness is the operative fact. Global scale and a long list of regulatory licences are not proxies for consistent AML maturity across every jurisdiction a platform operates in.

The practical implication is straightforward. Due diligence on a multinational fintech partner needs to assess the specific jurisdiction’s regulatory history and findings, not the platform’s global reputation or licence count as a whole. A platform can be simultaneously well-regarded, heavily licensed, and materially deficient in the exact jurisdiction that matters to a given relationship.


What Comes Next

Wise says its US business will continue operating normally under its existing money transmitter licences, unaffected by the OCC’s rejection, and intends to submit a new charter application under the framework introduced by the GENIUS Act, the US legislation governing stablecoin and payment stablecoin issuers. Wise has also pointed to compliance investments made since its original application was submitted, stating that “our business and compliance maturity have evolved significantly.”

The Belgian investigation remains ongoing, with a direct summons reportedly being finalised. No charges have been laid at the time of writing, and Wise maintains it is cooperating fully with authorities and denies wrongdoing.

Both matters will take time to resolve. What is already clear, without waiting for either outcome, is the pattern itself. A platform operating at the scale and sophistication of Wise experienced foundational AML control failures in three separate jurisdictions across three years, sanctions screening in the UK, customer identification in Belgium, and now a federal regulator’s assessment of overall AML maturity in the US. That is not a story about one bad audit or one unlucky finding. It is a story about what happens when growth is prioritised as a program in its own right, and AML maturity is treated as something that will eventually catch up.

For a company of Wise’s resources, it should not have needed three jurisdictions and three years to demonstrate otherwise.


Viktor Ha is a Senior Financial Crime Analyst with experience in AML/CTF compliance across the Australian banking sector. The views expressed here are his own.


Links referenced in this post:

External:

Internal:

Posted by

in

Leave a Reply

Your email address will not be published. Required fields are marked *