For compliance teams in London & the UK

The rules got harder. So did the consequences.

Personal liability for compliance failures is no longer theoretical. Kim trains MLROs and compliance teams for the regulatory environment that actually exists now.

Free to evaluate. Licensed deployment for commercial use.
$125m

UBS paid this in August 2026 for what regulators called "willful and repeated" AML failures — its second such penalty in under a decade.

FinCEN · August 2026 · largest-ever penalty against a broker-dealer for BSA violations
The pattern

Every one of these firms had an MLRO, an audit committee and a written policy.

None of it was the failure point. Kim's case library exists to show your team what actually was — the same underlying pattern, dressed differently by sector.

Payments · Germany

Wirecard

Its auditor signed off for ten years. When journalists found the fraud, the regulator investigated them, not the company. Every gatekeeper failed at once, in full public view.

Banking · Credit Suisse

Greensill Capital

$10 billion of client money moved into Greensill's funds on minimal due diligence, against warnings dating back to 2017. No Credit Suisse executive was ever formally held responsible.

Crypto · VASP

Binance

Its founder pleaded guilty personally and paid $50 million. The company paid $4.3 billion — internal messages showed executives knew, and chose market share over compliance anyway.

Wilful blindness. Captured oversight. Risk defined by classification, not by reality. One playbook — banking, government, sport, crypto all run it.

What actually changed — asked to Kim directly

ECCTA 2023 built a converging liability structure.

Not one new rule — three, operating independently and simultaneously. This is Kim's own explanation, asked live rather than written as marketing copy.

  1. s.196
    The identification doctrine, abolished for economic crime.

    Before ECCTA, pinning criminal liability on an MLRO required proving they were the firm's "directing mind and will" — a board-level standard that almost never applied below board level. Section 196 replaced it: a senior manager acting within their authority can now expose the firm directly, and an MLRO fits that definition comfortably.

  2. s.199
    Failure to prevent fraud — in force since September 2025.

    A firm's defence requires reasonable, tested, board-owned fraud prevention procedures — not a policy that exists on paper. When that defence fails, the next question is who was responsible for those procedures, which points straight at the compliance function.

  3. SMF17
    A separate, parallel track under SM&CR.

    The FCA can pursue an MLRO personally — fines, prohibition from working in financial services — entirely independently of whether the criminal case against the firm succeeds. A weak prosecution of the company does not protect the individual.

The protection has not disappeared. What changed is the bar: it now tracks the quality of what an MLRO can demonstrate, not merely what they can point to as having existed.

Who this is built for

Built for the people who carry the risk personally.

Kim is not bulk tick-box training for a headcount return. It is judgement development for the people whose name goes on the SAR — or whose name gets named when the pattern is found too late.

Ongoing training

CPD-aligned, session by session.

Continuing Professional Development is not optional box-ticking for compliance staff — most professional bodies require it to keep a certification or membership current, with real evidence to show for it. Kim is built for that obligation directly: short scenario sessions your team returns to across the year, each one grounded in a real case, not a generic refresher.

  1. Brush up on a topicStructuring, PEP exposure, sanctions, correspondent banking risk — Kim identifies where a refresher is due and works through it properly, not a slide re-read.
  2. Test it with real questionsKim builds questions and answers around the topic, checking the understanding is actually there — not just familiarity with the terms.
  3. Apply it to a hypothetical caseA constructed scenario puts the topic into practice before it ever has to matter for real.
  4. Evaluate a real scenarioBring an actual situation your team is facing, and Kim works through it as a live case, not a training exercise.
Plainly stated

What Kim is not.

  • Kim is not affiliated with, endorsed by or a product of any certifying or examining body.
  • Kim does not guarantee the outcome of any exam, assessment or regulatory review.
  • Kim does not replace an official professional body's own study materials.
  • Kim does not provide compliance advice to firms — it trains the people who give it.
Start now

The next case study is still being written.

Evaluate Kim free. Licensed deployment available for commercial use across your compliance function.