RegTech Reviews

Compliance Monitoring Examples in Financial Services and Healthcare

AML fines have doubled while real-time monitoring failures keep driving enforcement actions.

Staff Writer · · 11 min read · Updated
Cover illustration for “Compliance Monitoring Examples in Financial Services and Healthcare”
Compliance Monitoring · August 29, 2026 · 11 min read · 2,484 words

Compliance monitoring is the ongoing check on whether an organization's people, systems, and money movements actually follow the rules that apply to them, not the once-a-year fire drill everyone dreads and forgets by lunch. Think smoke detector, not fire inspection: one runs constantly in the background, the other shows up with a clipboard twice a year. Financial services and healthcare take this more seriously than almost anyone else, and they've proven it the hard way, through billions in penalties that keep climbing. This piece walks through what monitoring actually looks like in each field, with real cases and real dollar figures, because the job changes shape depending on which regulation and which industry you're standing in.

Both sectors share a basic setup: regulated activity, mandatory reporting, and fines steep enough to change how a board behaves at its next meeting. But what they're watching for splits pretty fast. Financial services monitoring centers on financial crime, trading conduct, and market integrity. Healthcare monitoring centers on patient data, billing accuracy, and care standards. Both keep drifting away from checklist audits toward something closer to a live, running function, because a checklist can get signed off on paper while the system underneath it quietly breaks. That gap, between paper compliance and actual operating compliance, is where most of the fines below come from.

AML transaction monitoring — the most penalized compliance function in global finance

Diagram: AML Fine Escalation: 2023 to 2025. Visualizes: Show the rapid escalation of AML and sanctions enforcement penalties across three reference points: $1.65 billion in fines in 2023, $3.3 billion in 2024 (a doubling), and a 417% year-over-year…

Transaction monitoring means screening payments, wires, and account activity against rule-based thresholds and behavioral models, then generating alerts and filing Suspicious Activity Reports when something crosses a line. The Bank Secrecy Act makes this mandatory, not optional. Customer due diligence, ongoing monitoring, sanctions screening, SAR filing: that's the floor, not a menu to pick from.

The penalty numbers aren't subtle. AML monitoring failures produced roughly $1.65 billion in fines in 2023. In 2024, that number doubled to $3.3 billion. Zoom out further and the Financial Crime News database puts cumulative major AML and sanctions fines above $10 million each at $45.68 billion from 2000 through 2024. Early 2025 data from Fenergo shows penalties up 417% in the first half of the year versus the same stretch in 2024, mostly because EMEA regulators closed a pile of long-running investigations all at once.

The dominant failure pattern in 2024 was a monitoring system that looked fine on paper and fell apart in practice: rule-based engines too slow to catch activity in real time, technical defects that left whole batches of transactions unwatched, and product lines carrying AML risk that controls had never been built to cover. Growth kept outrunning the infrastructure meant to supervise it.

The 2024 enforcement roster reads like a catalog of that exact problem. TD Bank absorbed a combined $3.55 billion across the DOJ ($1.8 billion), FinCEN ($1.3 billion), and OCC ($450 million), tied to weak transaction monitoring and weaker customer due diligence, bad enough that regulators capped the bank's U.S. growth outright. Deutsche Bank paid $186 million for failing to fix monitoring gaps regulators had already flagged once before. Starling Bank got hit with a £28.96 million FCA fine after opening more than 54,000 accounts for high-risk customers, during a stretch when the FCA had explicitly told the bank to slow down. N26 paid €9.2 million to BaFin over SARs that showed up late. And in 2025, Wise US paid $4.2 million across five state regulators for SAR problems and data integrity failures in its own systems.

Regulators want real-time screening, not batch processing that catches a problem a day or a week or a quarter after the fact. A sanctioned party should get stopped at the point of transaction, before the money moves anywhere. The EU's AML package, adopted in May 2024, adds a structural layer on top: it harmonizes enforcement across member states and creates AMLA, a new pan-European AML regulator. The room to shop around for a friendlier jurisdiction keeps shrinking.

Diagram: AML Fines: From $1.65B to $3.3B in One Year. Visualizes: Show the escalating scale of AML monitoring penalties across three time horizons: $1.65 billion in 2023, $3.3 billion in 2024 (a doubling), and $45.68 billion cumulative from…

Market surveillance and insider trading monitoring — how regulators detect what firms don't self-report

This is about catching people who trade on material nonpublic information, or coordinate to move a market, before the firm catches them, or instead of. The SEC's toolkit is worth knowing by name: the Consolidated Audit Trail (CAT) gives regulators cross-market visibility, Electronic Blue Sheets let them pull targeted trade data straight from firms, and the Whistleblower Programme brings in tips that internal compliance teams might never generate on their own.

The detection logic starts out mostly statistical. Unusually well-timed trades, volume spikes clustered right around an earnings call or a merger announcement, patterns too convenient to be luck: that's the anomaly signal that opens an investigation. The SEC reported $8.2 billion in financial remedies for fiscal year 2024, a record, even as the total number of enforcement actions actually fell. Read that combination carefully: fewer cases, bigger dollar signs, which tells you the agency is putting its weight behind fewer, messier cases instead of casting a wide net. FY 2025 pushed further still: 456 enforcement actions, 303 of them standalone, $17.9 billion in orders for monetary relief, and insider trading and market manipulation cases among the areas of continued focus.

One 2025 case makes the abstraction concrete. Ryan Squillante, head of equity trading at an investment firm, traded on nonpublic information about upcoming secondary offerings through his own personal brokerage accounts, across 10 different companies, on at least 11 separate occasions between May 2021 and December 2023. He pocketed about $216,965. The role that exists partly to stop this kind of trading was the exact role he held while doing it.

So what are firms doing about it? Reassessing insider-trading controls, refreshing who actually has access to restricted lists and material nonpublic information, tightening the path from a data-loss-prevention alert to a real human escalation, and extending surveillance out to social media, where a lot of the pre-announcement chatter lives now. None of that changes the basic asymmetry underneath it, though: regulators are building sharper detection tools than plenty of firms have internally. When that gap exists, the firm doesn't catch its own problem first. The SEC does. By then it's an enforcement action, not a quiet internal fix.

Third-party and vendor compliance monitoring — oversight that extends beyond the firm's own perimeter

A large financial firm can easily depend on hundreds of outside vendors, and every one of them is a door the firm doesn't fully control but still answers for. FINRA's 2025 Annual Regulatory Oversight Report calls out rising cyberattacks and outages hitting third-party vendors specifically, the kind of single point of failure that can knock out operations at dozens of firms at once because they all leaned on the same provider.

Regulators expect written supervisory procedures that actually name vendor oversight as a covered activity, due diligence that doesn't stop at the onboarding paperwork, and ongoing monitoring for as long as the relationship runs. FINRA Rule 3110, which governs supervision of associated persons, gets applied here too. A firm that watches its own employees closely but ignores what its vendor does on its behalf is only doing half the job.

Europe raised the bar further. The EU's Digital Operational Resilience Act puts vendor resilience squarely in scope for critical financial firms instead of treating it as someone else's problem. Vendor monitoring needs the same alerting, escalation, and paper trail as watching the firm's own trading desk, not a contract-renewal checkbox tucked inside procurement and forgotten until renewal season.

HIPAA privacy and security monitoring — the compliance backbone of U.S. healthcare

Diagram: HIPAA Enforcement: One Number Explains Most Failures. Visualizes: Visualize a single dominant statistic against its context: inadequate risk analysis appears in roughly 90% of OCR Security Rule enforcement actions, out of a cumulative…

HIPAA monitoring is the ongoing check that protected health information, PHI, gets handled, stored, sent, and disclosed the way the Privacy Rule and Security Rule say it should. The obligation doesn't stop at the hospital or insurer's front door; it reaches business associates too, the vendors and contractors touching that data, the same perimeter problem financial services has with its own vendors.

Civil penalties run from $141 to $71,162 per violation, with more serious violations carrying steeper consequences. The enforcement record since the Privacy Rule took effect is worth sitting with for a second: OCR has fielded more than 371,000 complaints and opened over 1,100 compliance reviews. More than 31,000 investigations forced changes to how organizations handle privacy and security. Total civil penalties and settlements add up to nearly $144 million. In 2024 alone, OCR collected close to $12.8 million across 16 settlements; 2025 brought 21, the second-highest year on record.

Here's the number that should reframe how anyone thinks about HIPAA failures: inadequate risk analysis shows up in roughly 90% of OCR's Security Rule enforcement actions. That points less to clever new hacking techniques outrunning defenses, and more to organizations that never sat down and mapped their own exposure in the first place.

Two cases show the spread. Some settlements have stretched years between the underlying breach and final resolution, a reminder of how long this enforcement tail can run. Phishing campaigns compromising employee mailboxes and exposing large volumes of ePHI have driven several of these settlements. State attorneys general run a parallel track too: $19.56 million across nine actions in 2024, plus one 49-state settlement against Blackbaud worth $49.5 million. OCR isn't the only regulator with teeth here.

Effective HIPAA monitoring in practice means regular risk analyses, access logs, workforce training records, business associate agreement management, and incident response documentation. Each piece does double duty: it's a working control, and it's the evidence an organization would need to hand over if OCR ever came asking.

Diagram: The HIPAA Risk Analysis Gap: 90% of Enforcement Actions. Visualizes: Visualize a single dominant statistic: inadequate risk analysis appears in roughly 90% of OCR Security Rule enforcement actions, set against the backdrop of 371,000+…

Website tracking technology and audit trail monitoring — the emerging HIPAA enforcement frontier

Hospitals and health systems started dropping third-party analytics pixels onto patient-facing websites, and in doing so opened up data flows involving PHI that nobody had disclosed or assessed, until OCR started looking. Nobody meant harm here. Everybody just wanted better site analytics.

Across 2024, the agency collected more than $12.8 million in penalties across 16 settlements — a concentrated wave, not a slow trickle, and tracking technology was among the failure modes under scrutiny. What monitoring now has to cover: a full inventory of every tracking technology sitting on patient portals, appointment booking pages, and other patient-facing web properties, an honest read on what each tool actually collects and whether that counts as PHI given the context, a review of business associate agreements with the analytics vendors themselves, and audit trails documenting how each data flow got found, assessed, and fixed.

That last point loops back to the 90% risk analysis failure rate above. An organization that doesn't know every place PHI moves through its own systems, including through a marketing pixel it forgot was even installed, can't run a complete risk analysis. Full stop. The tracking technology problem traces back to that same old risk analysis gap, just turning up in a corner nobody thought to check.

Context matters here too. 2024 saw a notable surge in exposed medical records, with major ransomware attacks driving breach volumes to significant new highs. Against that backdrop, treating a marketing pixel as a low-priority afterthought starts looking less like an oversight and more like negligence with good intentions.

Healthcare fraud, billing compliance, and the False Claims Act — monitoring for financial integrity in care delivery

This domain swaps the question from "is patient data safe" to "is the money right." It covers monitoring billing codes, claims submissions, medical necessity documentation, and referral relationships against Medicare, Medicaid, and private payer rules. Three statutes draw the perimeter: the False Claims Act, the Anti-Kickback Statute, and the Stark Law.

The mechanisms themselves are fairly plain, once you strip the acronyms away. Claims auditing samples submitted claims and checks whether the billing codes actually match the clinical documentation behind them. Stark Law and AKS monitoring tracks physician referral patterns and financial ties to the providers sending patients their way, hunting for arrangements that look more like kickbacks than medicine. Internal compliance hotlines, required under OIG guidance for organizations running compliance programs, give staff a way to flag problems before they turn into claims data anomalies. And OIG publishes annual Work Plans, telling compliance teams in advance what's getting scrutinized that year.

Here's the structural catch: billing compliance spans three separate stages, what a clinician documents, how a coder turns that into billing codes, and what actually gets sent to the payer. An error, or manipulation, at any single stage creates liability, so monitoring has to run the whole chain rather than spot-check one link. That makes this a genuinely different animal from HIPAA monitoring. HIPAA protects data; billing compliance protects financial accuracy and the honesty of referral relationships. Different failure modes, but the same underlying ask: a documented, continuous oversight program, not a once-a-year audit that samples a pile of claims and calls it a day.

What effective compliance monitoring programs have in common across both sectors

Line up every case in this piece. TD Bank, Starling Bank, Solara Medical Supplies, the hospitals caught by tracking pixels: each had a monitoring program already sitting in place, one that was inadequate, inconsistent, or quietly broken in a way nobody noticed until a regulator did. Most of these organizations were trying. Trying wasn't enough, and that should worry anyone who assumes having a program is the same thing as having a working one.

Real-time detection keeps beating retrospective review, in both sectors, for the same underlying reason: a monthly or annual check leaves a long window where something can go wrong and nobody notices, and long windows are exactly where Ryan Squillante and Metro Bank's unmonitored transactions did their damage. Risk analysis sits underneath both too. The 90% figure from HIPAA enforcement has a real cousin in AML, where firms got penalized for running monitoring systems calibrated against risk profiles that were already stale the day they went live.

The monitoring perimeter has stopped ending at the organization's own walls, too. Financial firms answer for their vendors. Healthcare organizations answer for their business associates, and for the tracking tools those associates quietly installed without telling anyone. Growth keeps being the thing that breaks a monitoring system sized for a smaller version of the organization: Starling opened 54,000 high-risk accounts while under explicit regulatory restriction, and hospitals rolled out tracking tools faster than anyone bothered to assess what data those tools actually touched.

So what actually separates the programs that hold up from the ones that collapse under an OCR letter or an SEC subpoena? Proof, mostly. Regulators in both sectors are asking whether the organization can show, with logs, audit trails, SAR filings, risk analyses, and written procedures, that it was actually watching, not simply whether the right control existed somewhere in a policy binder nobody's opened since the last audit. The control matters. Whether you can prove the control was running matters just as much, maybe more, because in front of an enforcement team, a control you can't document and a control that never existed look exactly the same.

Sources

  1. techuk.org
  2. resources.fenergo.com
  3. finintegrity.org

More in Compliance Monitoring