Welcome again to another issue of the Enforcement Case breakdown at AboutAML
Last week, we came across two AML stories
You may wonder what they have in common
One involved Binance, a big crypto firm, regarding a licensing decision, and the other is traditional banking that involves an enforcement action.
However,
When you look closer, they point to the same AML lesson and question
Does a firm genuinely understand how its products can be used for financial crime?
When a firm does not properly understand how its own products can be misused for money laundering, it risks finding out from the regulators the hard way
Let’s start with Binance.
Binance’s European challenge
Binance is the largest cryptocurrency exchange in the world, serving hundreds of millions of users globally.
On 16 June 2026, Reuters reported that Greece’s regulator is expected to reject Binance’s application for a licence under the EU’s new Markets in Crypto-Assets Regulation (MiCA).
We covered in one of our previous Wednesday breakdowns and discussed what it would mean if the licence gets approved, and what a major milestone for Binance in the EU
Unfortunately, that is taking a not-so-good turn
Binance has said it has not received any formal indication that its application will be refused, and no final decision has been publicly announced.
Still, the development has attracted attention because it could become one of the first major tests of how strictly European regulators intend to apply MiCA.
Why Greece?
Binance reportedly applied through the Hellenic Capital Market Commission (HCMC), Greece’s financial markets regulator.
Greece may have been viewed as a potentially faster route to obtaining a MiCA licence compared with larger jurisdictions such as Germany, France, or the Netherlands.
Well, maybe not.
While the regulator has not publicly explained its concerns, Binance’s regulatory history might have formed part of the bigger picture.
The Binance background
This is not Binance’s first encounter with regulators.
In 2023, Binance reached a $4.3 billion settlement with US authorities over anti-money laundering, sanctions, and compliance failures.
Its founder, Changpeng Zhao (CZ), pleaded guilty to violations relating to anti-money laundering requirements and stepped down as CEO.
Binance has also faced regulatory challenges in several jurisdictions, including the UK, the Netherlands, and Canada.
Regulators look at governance, control, and compliance history
A firm’s track record sure matters.
What then happens if Binance loses EU access?
If the application is ultimately rejected, it would provide an early indication of how European regulators intend to evaluate firms with a history of compliance concerns.
For other crypto firms preparing MiCA applications, it would be a signal that regulators are likely to look beyond policies on paper and focus on whether past weaknesses have been addressed.
Ikano Bank’s €12 million lesson
While Binance dominated crypto headlines, another enforcement action landed in Sweden.
Sweden’s Financial Supervisory Authority (Finansinspektionen) imposed a fine of SEK 140 million (approximately €12 million) on Ikano Bank.
Ikano Bank is part of the Ikano Group, which has historic links to the founders of IKEA.
The bank provides lending, leasing, and financial services across several Nordic and Baltic markets.
What did the regulator find?
According to the Swedish FSA, Ikano failed to adequately assess how some of its corporate products could be exploited for money laundering and terrorist financing.
The regulator also found that
The bank did not fully understand how criminals could misuse some of its products,
It did not properly assess those risks
It did not carry out enough enhanced due diligence on where the risks were higher.
Why this matters
Compared with some of the largest AML penalties issued globally, the fine is relatively modest.
What matters is the message behind it.
The Swedish regulator is saying:
Product risk matters.
Understanding customer risk alone is not enough.
Enhanced due diligence must be applied where higher risks exist.
Mid-sized institutions will be held to the same regulatory expectations as larger firms.
The pattern across both stories
A crypto exchange and a Nordic bank.
A licensing review and an enforcement action.
Two very different situations.
Yet both cases point to the same supervisory expectation.
Regulators want firms to demonstrate that they understand how their products, services, and delivery channels can be misused for financial crime.
Not just on paper but in practice
What does AML regulation say?
Under the EU’s AML framework, firms are expected to identify, assess, understand, and mitigate money laundering and terrorist financing risks associated with their customers, products, services, and delivery channels.
That means looking beyond who the customer is and asking how a product or service could realistically be misused.
Where higher risks are identified, firms are expected to apply enhanced due diligence measures and implement controls proportionate to those risks.
For crypto firms, you need MiCA authorisation from an EU member state to offer crypto-asset services across the European Union.
Regulators reviewing those applications assess governance arrangements, compliance controls, and whether firms are capable of meeting ongoing regulatory obligations.
What does this mean for compliance teams?
The Ikano case shows that product risk assessments should not be treated as a one-off compliance exercise.
As products evolve, customer behaviour changes, and new threats emerge, risk assessments need to evolve as well.
For crypto firms
The Binance shows that regulatory history matters.
A licence application is not limited to what controls exist currently.
It is also about whether regulators are convinced that past failures have been properly addressed.
For people learning AML
These two stories highlight one of the most important lessons in compliance.
Professionals should focus on understanding risk well enough to build controls that actually work.
What to watch out for?
The Greek regulator’s final decision on Binance’s MiCA application
Whether other crypto firms reconsider where they seek MiCA authorisation
Whether the Swedish FSA’s framing of “product misuse risk” will be used by other EU supervisors
Ikano Bank’s response and remediation efforts
Official sources
That’s all for this week. Hope you had a great read!
If you found this useful, feel free to share it with a colleague who works in compliance, risk, fraud, or financial crime.
AboutAML breaks down regulatory developments every Monday and enforcement cases every Wednesday.
Subscribe free here: Substack
Tosin
About AML

