
The $50 Million Silence: What the Swedbank Consent Order Teaches About Scoping a Regulatory Request
The New York State Department of Financial Services imposed a fifty million dollar civil monetary penalty on Swedbank. Read the consent order and one detail frames everything else. It contains no finding of money laundering and no finding of a sanctions breach. The penalty is for a narrower thing: the bank did not produce responsive information when its regulator asked for it.
For anyone who handles supervisory information requests, that is what makes the case worth reading. It turns not on exotic financial crime but on how a regulated firm scoped its response, and on what happened when the reasoning behind that scoping was committed to writing.
1. The question that started it
The matter traces back to the Panama Papers, the 2016 leak of records from the law firm Mossack Fonseca. According to the order, inquiries followed from Swedish and Estonian regulators, and the New York Department opened its own investigation and issued a request for information about the bank's connections to Mossack Fonseca and any related investigations.
Swedbank operates a licensed branch in New York and wholly owned subsidiaries in Estonia, Latvia and Lithuania. The order states that the New York branch responded to the 2016 request as though it applied only to the branch. It reported that it was unaware of responsive connections. It did not consult the Department about that reading, and it did not tell the Department that the response had been limited in that way.
Commentary — a lesson for practitioners, not an NYDFS finding: the first critical decision here was about scope. A broad request was answered as a narrow one, and the narrowing was not disclosed. Scope is where these matters begin.
2. What head office already held
At the time of that first response, the bank's home office already held responsive information. Its compliance leadership had told the board that the leaked records referenced the bank. Swedbank Estonia had identified customers that used Mossack Fonseca as their registered agent, and the order separately records payments to Mossack Fonseca involving certain customers of Swedbank Latvia and Swedbank Lithuania. Supervisors in Sweden and Estonia had already made inquiries.
None of that appeared in the branch's response. The distance between what the organisation held and what it disclosed opened at the first request.
3. The second request, and the carve-out
Two years later the Department asked again. During a call about the scope of that 2018 request, the bank's external U.S. counsel represented that the bank understood the request was not limited to the New York branch and that it covered the bank's global operations, and that the bank would search its head office and global branch network. Counsel did not say the bank intended to leave the Baltic subsidiaries out.
Internally, the bank had already run a search of those subsidiaries, and it produced many matches with Mossack Fonseca. The subsidiaries were then excluded from the response, and the Department was not told.
The internal evidence in the order is direct. Employees stated in correspondence that the request covered the subsidiaries, and a colleague agreed. Those who prepared the responses later said the subsidiaries should have been included. In testimony under oath, a bank officer accepted that the request encompassed the Baltic entities. They were left out anyway.
4. The internal email
The most striking item in the order is an internal email. After a colleague reported that a prior search of the Baltic subsidiaries had produced many matches with Mossack Fonseca, the compliance officer replied: "[t]hat's why I wanted to remove them out of the scope :)." In separate correspondence, she explained that they had limited the description of the bank's business because they did not want regulators focusing on the Baltic subsidiaries. She also said she did not want to draw unnecessary attention to potential issues in the Baltics.
That email appears in the Department's findings and is now part of the regulatory record. The practical point for anyone drafting a response is plain enough. The reasoning behind a scoping decision does not stay private. It lives in email, in chat, in file notes, and when the decision is later questioned, that reasoning is what documents why the firm did what it did.
Commentary — a lesson for practitioners, not an NYDFS finding: if the honest explanation for narrowing a response is that a fuller answer would attract scrutiny, that explanation is the difficulty, not a defence to it. Committing it to writing does not resolve it.
5. How the gap closed
The bank's written responses to the 2018 request omitted the Baltic material. The order also states that the bank described the Swedish supervisor's review as having concluded without adverse findings, while omitting that the same review had produced recommendations for improvement.
According to the order, the Department learned through media reports in early 2019 that information concerning the Baltic subsidiaries had not been provided, and it issued a third request. Swedbank's response in March 2019 contained the first substantive set of documents on the subsidiaries that the Department had received since its initial inquiry in April 2016.
6. The charge, and why it travels
The formal violation is worth stating precisely. As set out in the order, Swedbank and its New York branch failed to produce responsive information when replying to multiple Department requests for special reports, in violation of New York Banking Law section 125(3). The order makes no money-laundering finding and no sanctions finding, and this article draws none.
That precision is what makes the case portable. For firms that respond to supervisory questionnaires, thematic reviews and information requests, the temptation the order illustrates will be familiar: when a complete answer would surface something awkward, read the request narrowly, keep the difficult entity or dataset out of scope, and avoid drawing attention. The Swedbank order shows the regulatory risk that can arise when responsive information is excluded and the regulator is not told how the scope has been limited.
The order also records subsequent leadership change: Swedbank dismissed the compliance officer and its former chief executive, and the majority of the board was replaced. These are recorded as events that followed, not as changes the order attributes, one by one, to this particular matter.
The practitioner's takeaway (commentary, not an NYDFS finding): when a supervisor asks, scope is not a private drafting decision. Where a request is genuinely ambiguous, the safer course is to confirm its scope with the supervisor rather than resolve the ambiguity quietly in the firm's favour.
Know what supervisors are looking for. Handling information requests, supervisory engagement and AML governance is the ground our seminars are built on. If you want your people confident in how they respond when a regulator asks, that is where to start.
Explore the AML/CTF seminars at CPDs.Academy
Source for the enforcement matter: New York State Department of Financial Services, Consent Order in the Matter of Swedbank AB (publ) and Swedbank AB, New York Branch. This article describes what the consent order states; passages marked as commentary are the author's professional reading and not findings of the Department.

Article by Nikolas Demetriades
Published 27 Jul 2026