Irish Central Bank fines Coinbase for "AI" set up failures.
The following is extracted from the Central Bank of Ireland's media statement:
The Central Bank of Ireland (the Central Bank) has fined Coinbase Europe Limited (Coinbase Europe) €21,464,734 for breaching its anti-money laundering (AML) and combatting terrorist financing (CFT) obligations with respect to transaction monitoring as required by the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (the CJA 2010) between 23 April 2021 and 19 March 2025.
As a virtual asset service provider, Coinbase Europe is required to monitor customer transactions on an ongoing basis. Where Coinbase Europe suspects that a transaction is facilitating money laundering or terrorist financing it is required to file a Suspicious Transaction Report (STR) with the national Financial Intelligence Unit (FIU) and Revenue Commissioners as soon as possible.
Coinbase Europe has been fined due to faults in the configuration of their transaction monitoring system, which resulted in more than 30 million transactions not being properly monitored over a 12-month period. The value of these transactions amounted to over €176 billion, and accounted for approximately 31% of all Coinbase Europe transactions conducted in the period when the faults existed.
Further, it took Coinbase Europe almost three years to fully complete the monitoring of the impacted transactions. This subsequent monitoring led to the reporting of 2,708 STRs to the FIU for further analysis and potential investigation.
The STRs submitted in respect of the late monitoring of the transactions contained suspicions associated with serious criminal activities including: money laundering; fraud/scams; drug trafficking; cyber-attacks (malware/ransomware); and child sexual exploitation.
Coinbase Europe has accepted that it breached its transaction monitoring obligations under the CJA 2010 by failing to:
- Fully and properly monitor 30,442,437 transactions;
- Adopt internal policies, controls and procedures to prevent and detect the commission of money laundering and terrorist financing; and
- Conduct additional monitoring in respect of 184,790 transactions.
Comment:
During the investigations into the broad banking sector in Australia, it was discovered that the transaction monitoring system at The Commonwealth Bank of Australia had not been set up properly. Millions of transactions had not been examined by tech intended to do the job. Disproportionate focus was placed on a minuscule number of small value payments in respect of child sexual exploitation. But that focus should have made all in financial services businesses sit up and say "let's just check we turned the thing on" or some such.
This action against Coinbase shows that didn't happen. Perhaps the risk of such a large fine (as it is described by the Banking Regulator at the Central Bank) will give others cause to take a look at what the tech they are using is doing or not doing.


