Regulatory History · 2004 — 2026

Twenty Years of Bank Regulation.
How the industry was forced to change.

From Basel II's introduction in 2004 through the GFC response, the conduct era, and the current operational resilience and AML enforcement wave — this is a record of the mandates issued, the enforcement actions taken, and the programme burden placed on banks to comply. Sources: OCC, Federal Reserve, FCA, PRA, DOJ — all public registers.

5
Regulatory waves
$200B+
Industry fines 2004–2026
22
Active enforcement actions
2026
Basel III endgame proposed
All enforcement data sourced from public registers: OCC Enforcement Actions Database (apps.occ.gov/EASearch), Federal Reserve Enforcement Actions, FCA Final Notices and Decision Notices, DOJ press releases, and bank annual reports and SEC filings. This page does not contain proprietary Allazo data.
Filter by wave
Wave I
2004 — 2007

The Complacency Era

Basel II arrived in 2004 with sophisticated risk-sensitivity — allowing banks to use internal models to calculate capital requirements. The result was a structural reduction in the capital held against trading books and structured credit. Tier 1 capital ratios at major banks averaged 6–8%, well below what the crisis would reveal as necessary. Enforcement actions were rare at major institutions. Regulatory scrutiny was light. The programme burden was modest — Basel II implementation, yes, but in an environment that treated compliance as administration, not risk management.

Basel II framework Internal model approval Low enforcement intensity Pre-crisis capital floors 6–8% Structured credit growth
Wave II
2008 — 2012

The Reckoning

The financial crisis triggered the largest regulatory response in banking history. Dodd-Frank (2010) rewrote the US regulatory architecture. Basel III (2010) doubled capital requirements over a six-year phase-in — Tier 1 ratios would need to reach nearly 13% by 2019 from the pre-crisis 6%. The RMBS enforcement wave produced $75.5B in industry-wide settlements across 21 cases. HSBC's $1.9B AML fine in 2012 signalled that financial crime enforcement was entering a new era. Banks had to build capital programmes, stress testing infrastructure, and resolution planning capabilities that did not previously exist at any meaningful scale.

Dodd-Frank Act 2010 Basel III capital doubling CCAR / stress testing introduced RMBS enforcement $75.5B HSBC AML $1.9B 2012 Resolution planning mandatory
Wave III
2013 — 2017

Structural Reform and Conduct

Basel III US rules were finalised in 2013–2014. The IHC requirement (Regulation YY) forced foreign banks to consolidate US subsidiaries — a major structural programme for every European bank with a US presence. LIBOR and FX manipulation enforcement produced industry-wide fines across Barclays, RBS, UBS, Citibank and others. The FCA issued its largest-ever fine — £284M against Barclays for FX manipulation. The MRA era intensified: the Fed and OCC issued confidential MRAs liberally across 2013–2017. Wells Fargo's fake accounts scandal (2016) triggered a consent order and a $1.95 trillion asset cap that remains a reference point for conduct risk consequences.

IHC Regulation YY LIBOR / FX manipulation enforcement FCA £284M Barclays FX fine MRA era — confidential supervision Wells Fargo asset cap Basel III US implementation
Wave IV
2018 — 2022

Culture, Governance and AML

Regulatory focus shifted from capital adequacy to culture, governance and financial crime. The 1MDB scandal produced Goldman Sachs' $154M Federal Reserve consent order and a total industry-wide penalty of over $5B. Deutsche Bank's long-running consent order saga — seven separate regulatory actions — became the defining symbol of what sustained programme failure looks like under regulatory scrutiny. Operational resilience emerged as a UK priority: PRA PS6/21 (2021) introduced the Important Business Services framework. Citibank's 2020 consent orders from both OCC and Fed — for data governance and risk infrastructure — set the template for the current era of enterprise-wide transformation programmes under regulatory supervision.

1MDB / Goldman Sachs Deutsche Bank 7-action saga Citi 2020 consent orders PRA Operational Resilience PS6/21 Governance-focused enforcement Data quality as regulatory risk
Wave V
2023 — 2026

The Convergence Era

The current regulatory environment is defined by convergence: AML enforcement at historic scale, operational resilience mandates maturing into full compliance requirements, and Basel III endgame capital rules proposed in March 2026. TD Bank's $3.09B BSA/AML settlement in October 2024 — the largest in US banking history — combined a DOJ plea, OCC consent order, and a $434B asset cap. Citibank's transformation programme remains the largest active regulatory remediation programme in the industry. The FCA's Consumer Duty is reshaping conduct risk management across UK retail banking. Off-channel communications enforcement (SEC, FINRA) has produced over $1B in aggregate fines. The era of regulatory programmes as episodic events is over — they are now a permanent feature of how major banks operate.

TD Bank $3.09B 2024 Citi transformation programme FCA Consumer Duty Off-channel comms $1B+ DORA effective 2025 Basel III Endgame proposed Mar 2026 APRA CPS 230
The Programme Burden

What banks actually had to build

Every regulatory wave generated a specific set of programme obligations — new infrastructure, new processes, new governance, new technology. These are not one-off projects. They are continuous delivery obligations that run in parallel across multiple jurisdictions, regulators, and business lines.

Wave I · 2004–2007
Basel II Implementation
  • Internal ratings-based model development and validation
  • Advanced measurement approach for operational risk
  • Capital allocation system redesign
  • Pillar 2 ICAAP framework establishment
  • Regulatory reporting infrastructure (Pillar 3)
Wave II · 2008–2012
Crisis Response Infrastructure
  • Capital planning and stress testing programmes (CCAR)
  • Resolution planning — living wills and IDIs
  • Volcker Rule trading desk restructuring
  • OTC derivatives reform (central clearing, margin)
  • Consumer protection and mortgage servicing remediation
  • BSA/AML programme rebuilds (post-HSBC era)
Wave III · 2013–2017
Structural and Conduct Reform
  • IHC formation — US subsidiary consolidation for FBOs
  • Enhanced Prudential Standards implementation
  • LIBOR transition programme (early planning)
  • FX and benchmark rate conduct remediation
  • Conduct risk framework and front-office surveillance
  • MiFID II and EMIR compliance programmes
Wave IV · 2018–2022
Culture and Governance Transformation
  • Enterprise data governance (Citi-template)
  • Three lines of defence structural reform
  • LIBOR transition to SOFR/SONIA (active)
  • Operational resilience IBS mapping and testing
  • KYC/CDD programme uplift — global re-papering
  • Senior manager accountability regime (UK SMCR)
Wave V · 2023–2026
Convergence Era Obligations
  • BSA/AML programme rebuilds at scale (TD, BofA, Wells)
  • Transaction monitoring and SAR filing infrastructure
  • Operational resilience — full compliance (PRA, HKMA)
  • DORA — ICT risk and third-party oversight (EU)
  • Consumer Duty outcomes framework (FCA)
  • Basel III endgame capital recalibration
  • Off-channel communications surveillance and archiving
  • CTP regime — critical third-party oversight (UK)
Cross-Wave · Permanent
The Permanent Regulatory Programme
  • Annual CCAR submission and capital plan review
  • Annual resolution plan (living will) refresh
  • Ongoing OTC derivatives reporting (EMIR, CFTC)
  • Continuous AML/KYC monitoring and de-risking
  • Regulatory change management — tracking 150+ annual changes
  • Cross-border coordination — 6+ regulators simultaneously
Industry Penalties 2004–2026 · Verified Public Sources

The cost of non-compliance — by institution

Post-crisis fines through 2026. Sources: DOJ, OCC, FRB, FCA press releases and annual reports. Figures represent total regulatory settlements, not single enforcement actions.

$58B+
Bank of America
Largest total · RMBS / mortgage
$31B+
JPMorgan Chase
RMBS · FX · spoofing · $13B DOJ 2013
$12.8B
Citigroup
RMBS · FX · AML · data governance
$9.7B
Wells Fargo
Consumer · fake accounts · AML
$8.83B
BNP Paribas
Sanctions violations 2015
$3.09B
TD Bank
BSA/AML — largest ever 2024
$2B
Danske Bank
AML — Estonian branch 2023
$1.9B
HSBC
AML / sanctions 2012
£284M
Barclays
FCA FX — largest FCA fine ever 2015
£117M
Lloyds Banking Group
PPI complaints — largest FCA retail fine
£163M
Deutsche Bank
FCA AML fine 2017
£107M
Santander UK
FCA AML — Business Banking 2022

Twenty years of regulatory change.
Still being delivered — by banks, right now.

The current enforcement wave — TD Bank, Citibank, Bank of America, Wells Fargo, Barclays — is not a historical footnote. These are active programmes, active monitors, active regulatory obligations. If your bank is managing one of them, Allazo works at this intersection.

Book a 15-Minute Introduction →