Taiwan's Financial Supervisory Commission announced on 11 March 2025 that it had imposed a NT$22 million penalty on Bank of Taiwan for anti-money laundering control failures. The fine relates to a combination of employee misconduct and institutional lapses in monitoring a corporate client account that had repeatedly triggered the banking sector's joint defence notification system.
Two former employees of Bank of Taiwan were found to have conducted improper fund transactions with customers and, more seriously, to have executed transactions on behalf of a corporate customer rather than at the customer's independent direction — an arrangement that breaches the fundamental principle that banking staff must not substitute their own judgement or actions for those of account holders. The improper conduct ran from April 2021 to July 2024, spanning more than three years before being addressed.
RED FLAGS UNMONITORED AND ALERTS LEFT UNINVESTIGATED
The FSC's findings highlight a specific monitoring failure relating to a risk indicator added by Taiwan's Bankers Association in December 2022: the pattern of inward remittances being swiftly transferred to offshore virtual currency exchangers. This transaction type has been identified as a high-risk pattern associated with money laundering through cryptocurrency channels, and financial institutions in Taiwan were expected to incorporate it into their transaction monitoring frameworks following the Bankers Association's guidance.
Bank of Taiwan failed to implement adequate monitoring for this indicator, meaning that transactions matching this profile flowing through the relevant corporate account were not appropriately scrutinised. The failure to embed a known and formally communicated red flag into active monitoring protocols is a compliance management weakness that the FSC treats as distinct from — and in addition to — any underlying misconduct by employees.
The same corporate account triggered the joint defence notification system seven times between 2023 and 2024. This system, which allows member banks to share information about accounts displaying suspicious characteristics, is designed to ensure that institutions are alerted when a customer has drawn concern across the network. Bank of Taiwan investigated the first two notifications but took no effective action on the subsequent five, allowing a pattern of suspicious activity to persist without adequate response.
REGULATORY IMPLICATIONS AND INSTITUTIONAL ACCOUNTABILITY
The FSC's decision to fine Bank of Taiwan — a state-owned institution and one of Taiwan's largest banks — demonstrates that government ownership does not confer exemption from AML enforcement. The case combines employee-level misconduct with institutional-level compliance failures, a combination that regulators typically view more seriously than either element in isolation because it suggests weaknesses at multiple layers of the compliance architecture.
The three-year duration of the improper employee conduct also raises questions about the bank's internal audit and supervisory processes. A pattern of transactions executed on behalf of customers, rather than at their direction, should in principle be identifiable through regular transaction review and supervision of staff conduct. The extended period during which this continued without detection or interruption points to gaps in Bank of Taiwan's first and second lines of defence.
For the broader Taiwanese banking sector, the case reinforces the FSC's expectation that institutions respond comprehensively to joint defence notifications rather than treating initial alerts as sufficient and subsequent ones as incremental. The regulator's published enforcement action serves as a public signal that selective or incomplete responses to shared risk intelligence will be treated as regulatory failures carrying material financial consequences.