Spain's anti-money laundering authority, SEPBLAC — the Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias — published a EUR 3,910,000 fine against ING Bank NV's Spanish branch in the Official State Gazette on 6 March 2025. The penalty centres on a fundamental failure of the bank's suspicious transaction reporting obligation: ING Spain's internal detection systems had flagged transactions as potentially related to money laundering or terrorist financing, but those alerts were not converted into reports submitted to SEPBLAC as required under Spanish AML and counter-terrorism financing law.

The violation represents what regulators describe as a systemic breakdown in the reporting chain rather than an isolated oversight. The internal controls performed their detection function correctly, identifying activity that met the threshold for potential concern, but the process by which that internal flag should have triggered a formal suspicious transaction report to the regulator did not operate as required. That distinction — between a detection failure and a reporting failure — is significant because it suggests the bank's compliance architecture contained a structural gap at the point of external notification.

A SYSTEMIC REPORTING FAILURE, NOT A DETECTION GAP

SEPBLAC's finding is notable precisely because ING Spain cannot be said to have been unaware of the transactions in question. The bank's own monitoring systems identified them as warranting scrutiny. The regulatory breach occurred downstream of that identification, in the chain of processes that should have ensured a suspicious transaction report reached the competent authority within the timeframe specified by law.

AML supervisors across Europe have increasingly focused on this category of failure — sometimes called a reporting gap — as distinct from cases where a bank's monitoring systems simply missed the activity entirely. A reporting gap is, in some respects, more concerning to regulators because it implies that compliance functions are screening information but not acting on it in the manner the legal framework prescribes. The result from a financial intelligence perspective is the same: SEPBLAC does not receive the information it needs to assess whether the activity warrants further investigation.

ING's Spanish branch, as a significant retail and digital banking operation in the country, handles a substantial volume of daily transactions, and the question of how many internal flags failed to translate into filed reports is central to the severity assessment underpinning the EUR 3.91 million penalty. The Official State Gazette notice, which provides the formal public record of the fine, sets out SEPBLAC's findings and the legal basis for the sanction.

ENFORCEMENT CONTEXT IN SPANISH FINANCIAL REGULATION

The publication of the ING Spain fine in the Official State Gazette follows SEPBLAC's established practice of making enforcement decisions public as both a transparency measure and a deterrent signal to the broader financial sector. The regulator's willingness to levy seven-figure penalties on the Spanish branches of international banks communicates that cross-border operating structures do not shield institutions from national AML enforcement.

For ING, the Spanish fine adds to a list of compliance-related sanctions the group has faced across multiple jurisdictions in recent years, reinforcing pressure on the bank's leadership to demonstrate that remediation efforts are producing durable improvements rather than temporary adjustments. The Dutch parent will be expected to address the specific reporting chain failure identified by SEPBLAC and to provide assurances to the regulator that equivalent gaps have been closed.

Broader scrutiny of AML compliance quality in the Spanish banking sector has intensified as regulators sharpen their focus on the quality of suspicious transaction reporting rather than simply the volume of reports filed. Institutions operating in Spain are expected to ensure that the full chain from internal alert to external report functions reliably, and the ING case is a concrete illustration of the consequences when it does not.