Twenty Years of Bank Regulation. How the industry was forced to change.
From Basel II's introduction in 2004 through the GFC response, the conduct era, and the current operational resilience and AML enforcement wave — this is a record of the mandates issued, the enforcement actions taken, and the programme burden placed on banks to comply. Sources: OCC, Federal Reserve, FCA, PRA, DOJ — all public registers.
5
Regulatory waves
$200B+
Industry fines 2004–2026
22
Active enforcement actions
2026
Basel III endgame proposed
All enforcement data sourced from public registers: OCC Enforcement Actions Database (apps.occ.gov/EASearch), Federal Reserve Enforcement Actions, FCA Final Notices and Decision Notices, DOJ press releases, and bank annual reports and SEC filings. This page does not contain proprietary Allazo data.
Filter by wave
Wave I
2004 — 2007
The Complacency Era
Basel II arrived in 2004 with sophisticated risk-sensitivity — allowing banks to use internal models to calculate capital requirements. The result was a structural reduction in the capital held against trading books and structured credit. Tier 1 capital ratios at major banks averaged 6–8%, well below what the crisis would reveal as necessary. Enforcement actions were rare at major institutions. Regulatory scrutiny was light. The programme burden was modest — Basel II implementation, yes, but in an environment that treated compliance as administration, not risk management.
Basel II frameworkInternal model approvalLow enforcement intensityPre-crisis capital floors 6–8%Structured credit growth
Wave II
2008 — 2012
The Reckoning
The financial crisis triggered the largest regulatory response in banking history. Dodd-Frank (2010) rewrote the US regulatory architecture. Basel III (2010) doubled capital requirements over a six-year phase-in — Tier 1 ratios would need to reach nearly 13% by 2019 from the pre-crisis 6%. The RMBS enforcement wave produced $75.5B in industry-wide settlements across 21 cases. HSBC's $1.9B AML fine in 2012 signalled that financial crime enforcement was entering a new era. Banks had to build capital programmes, stress testing infrastructure, and resolution planning capabilities that did not previously exist at any meaningful scale.
Dodd-Frank Act 2010Basel III capital doublingCCAR / stress testing introducedRMBS enforcement $75.5BHSBC AML $1.9B 2012Resolution planning mandatory
Wave III
2013 — 2017
Structural Reform and Conduct
Basel III US rules were finalised in 2013–2014. The IHC requirement (Regulation YY) forced foreign banks to consolidate US subsidiaries — a major structural programme for every European bank with a US presence. LIBOR and FX manipulation enforcement produced industry-wide fines across Barclays, RBS, UBS, Citibank and others. The FCA issued its largest-ever fine — £284M against Barclays for FX manipulation. The MRA era intensified: the Fed and OCC issued confidential MRAs liberally across 2013–2017. Wells Fargo's fake accounts scandal (2016) triggered a consent order and a $1.95 trillion asset cap that remains a reference point for conduct risk consequences.
IHC Regulation YYLIBOR / FX manipulation enforcementFCA £284M Barclays FX fineMRA era — confidential supervisionWells Fargo asset capBasel III US implementation
Wave IV
2018 — 2022
Culture, Governance and AML
Regulatory focus shifted from capital adequacy to culture, governance and financial crime. The 1MDB scandal produced Goldman Sachs' $154M Federal Reserve consent order and a total industry-wide penalty of over $5B. Deutsche Bank's long-running consent order saga — seven separate regulatory actions — became the defining symbol of what sustained programme failure looks like under regulatory scrutiny. Operational resilience emerged as a UK priority: PRA PS6/21 (2021) introduced the Important Business Services framework. Citibank's 2020 consent orders from both OCC and Fed — for data governance and risk infrastructure — set the template for the current era of enterprise-wide transformation programmes under regulatory supervision.
1MDB / Goldman SachsDeutsche Bank 7-action sagaCiti 2020 consent ordersPRA Operational Resilience PS6/21Governance-focused enforcementData quality as regulatory risk
Wave V
2023 — 2026
The Convergence Era
The current regulatory environment is defined by convergence: AML enforcement at historic scale, operational resilience mandates maturing into full compliance requirements, and Basel III endgame capital rules proposed in March 2026. TD Bank's $3.09B BSA/AML settlement in October 2024 — the largest in US banking history — combined a DOJ plea, OCC consent order, and a $434B asset cap. Citibank's transformation programme remains the largest active regulatory remediation programme in the industry. The FCA's Consumer Duty is reshaping conduct risk management across UK retail banking. Off-channel communications enforcement (SEC, FINRA) has produced over $1B in aggregate fines. The era of regulatory programmes as episodic events is over — they are now a permanent feature of how major banks operate.
TD Bank $3.09B 2024Citi transformation programmeFCA Consumer DutyOff-channel comms $1B+DORA effective 2025Basel III Endgame proposed Mar 2026APRA CPS 230
The Programme Burden
What banks actually had to build
Every regulatory wave generated a specific set of programme obligations — new infrastructure, new processes, new governance, new technology. These are not one-off projects. They are continuous delivery obligations that run in parallel across multiple jurisdictions, regulators, and business lines.
Wave I · 2004–2007
Basel II Implementation
Internal ratings-based model development and validation
Advanced measurement approach for operational risk
Capital allocation system redesign
Pillar 2 ICAAP framework establishment
Regulatory reporting infrastructure (Pillar 3)
Wave II · 2008–2012
Crisis Response Infrastructure
Capital planning and stress testing programmes (CCAR)
Resolution planning — living wills and IDIs
Volcker Rule trading desk restructuring
OTC derivatives reform (central clearing, margin)
Consumer protection and mortgage servicing remediation
BSA/AML programme rebuilds (post-HSBC era)
Wave III · 2013–2017
Structural and Conduct Reform
IHC formation — US subsidiary consolidation for FBOs
Enhanced Prudential Standards implementation
LIBOR transition programme (early planning)
FX and benchmark rate conduct remediation
Conduct risk framework and front-office surveillance
MiFID II and EMIR compliance programmes
Wave IV · 2018–2022
Culture and Governance Transformation
Enterprise data governance (Citi-template)
Three lines of defence structural reform
LIBOR transition to SOFR/SONIA (active)
Operational resilience IBS mapping and testing
KYC/CDD programme uplift — global re-papering
Senior manager accountability regime (UK SMCR)
Wave V · 2023–2026
Convergence Era Obligations
BSA/AML programme rebuilds at scale (TD, BofA, Wells)
Transaction monitoring and SAR filing infrastructure
Operational resilience — full compliance (PRA, HKMA)
DORA — ICT risk and third-party oversight (EU)
Consumer Duty outcomes framework (FCA)
Basel III endgame capital recalibration
Off-channel communications surveillance and archiving
Industry Penalties 2004–2026 · Verified Public Sources
The cost of non-compliance — by institution
Post-crisis fines through 2026. Sources: DOJ, OCC, FRB, FCA press releases and annual reports. Figures represent total regulatory settlements, not single enforcement actions.
$58B+
Bank of America
Largest total · RMBS / mortgage
$31B+
JPMorgan Chase
RMBS · FX · spoofing · $13B DOJ 2013
$12.8B
Citigroup
RMBS · FX · AML · data governance
$9.7B
Wells Fargo
Consumer · fake accounts · AML
$8.83B
BNP Paribas
Sanctions violations 2015
$3.09B
TD Bank
BSA/AML — largest ever 2024
$2B
Danske Bank
AML — Estonian branch 2023
$1.9B
HSBC
AML / sanctions 2012
£284M
Barclays
FCA FX — largest FCA fine ever 2015
£117M
Lloyds Banking Group
PPI complaints — largest FCA retail fine
£163M
Deutsche Bank
FCA AML fine 2017
£107M
Santander UK
FCA AML — Business Banking 2022
Twenty years of regulatory change. Still being delivered — by banks, right now.
The current enforcement wave — TD Bank, Citibank, Bank of America, Wells Fargo, Barclays — is not a historical footnote. These are active programmes, active monitors, active regulatory obligations. If your bank is managing one of them, Allazo works at this intersection.