Taiwan's Financial Supervisory Commission imposed an administrative fine of NT$22 million on Bank of Taiwan in March 2025, with the penalty announced publicly on the FSC's website on 5 May 2025. The action follows a regulatory investigation into serious internal control failures that allowed two former bank employees to participate in improper fund transactions with customers and to conduct transactions on behalf of a corporate client linked to offshore virtual currency exchangers — conduct that persisted from April 2021 through to July 2024, a span of more than three years.
The FSC cited violations of Banking Act Article 45-1 and the Internal Control Implementation Rules, which together impose obligations on financial institutions to maintain effective systems for identifying, escalating, and responding to suspicious customer activity. The corporate account at the centre of the case was flagged seven times by Taiwan's joint defence notification system between 2023 and 2024 — a mechanism designed to share intelligence about suspicious accounts across participating financial institutions. Despite this volume of alerts, Bank of Taiwan failed to conduct the required reviews after the first two notifications had returned no finding of illegal activity.
MULTIPLE ALERTS WENT UNANSWERED
The FSC's findings on the alert response failures represent the most operationally significant aspect of the enforcement action. Internal control frameworks are designed to escalate repeated signals even when initial reviews prove inconclusive — the logic being that multiple alerts on a single account constitute a pattern that warrants deeper scrutiny regardless of the outcome of any individual review. Bank of Taiwan's failure to re-engage the compliance process after the first two alerts found no wrongdoing meant that five subsequent warnings went without adequate investigation, allowing the account's problematic activity to continue largely undisturbed.
The two former employees at the centre of the case engaged in what the FSC characterised as improper fund transactions with customers and facilitated transactions on behalf of a corporate customer involved with offshore virtual currency exchangers. The precise nature of those transactions has not been set out in detail in the public announcement, but the connection to offshore crypto-adjacent activity is consistent with a broader typology of money laundering risk that regulators across the Asia Pacific region have flagged as a growing area of supervisory concern, particularly as the volume and complexity of cross-border virtual asset flows has increased.
FSC SINGLES OUT STATE-BANK COMPLIANCE OBLIGATIONS
The FSC used the enforcement action to make an explicit point about the heightened compliance obligations that attach to state-owned financial institutions. In its announcement, the regulator noted that Bank of Taiwan, as a government-owned bank, should be setting an exemplary standard for the broader financial sector rather than being subject to enforcement action arising from internal control failures of this nature. The FSC also stated that senior management could face accountability measures if similar incidents recur, a warning that signals the regulator's expectation of systemic remediation rather than isolated corrective action.
The case carries implications that extend beyond Bank of Taiwan. For Taiwanese regulators, the ability of employees to collude with external fraud networks over a multi-year period — while repeated system alerts went unactioned — raises questions about the effectiveness of transaction monitoring and alert management frameworks more broadly. Financial institutions operating in Taiwan, and particularly those with state ownership that creates expectations of a higher compliance standard, are likely to face heightened scrutiny of their anti-money laundering governance in subsequent examination cycles.