For compliance teams in London & the UK

The rules got harder. So did the consequences.

Personal liability for compliance failures is no longer theoretical. Kim trains MLROs and compliance teams for the regulatory environment that actually exists now.

Free to evaluate. Licensed deployment for commercial use.
$125m

UBS paid this in August 2026 for what regulators called "willful and repeated" AML failures — its second such penalty in under a decade.

FinCEN · August 2026 · largest-ever penalty against a broker-dealer for BSA violations
Just changed · in force 29 June 2026

Section 250 leaves no reasonable procedures defence.

The Crime and Policing Act 2026 came into force on 29 June 2026, replacing ECCTA's section 196 outright. Unlike Failure to Prevent Fraud under section 199 — where a genuine, tested compliance framework is a real defence — section 250 offers none at all. If a senior manager, acting within their actual or apparent authority, commits any criminal offence, the firm is automatically guilty of that offence too. No policy document stands between that finding and the firm's liability — only the conduct itself, documented and independently evidenced at the time, protects you now.

See what else changed →
The pattern

Every one of these firms had an MLRO, an audit committee and a written policy.

None of it was the failure point. Kim's case library exists to show your team what actually was — the same underlying pattern, dressed differently by sector.

Payments · Germany

Wirecard

Its auditor signed off for ten years. When journalists found the fraud, the regulator investigated them, not the company. Every gatekeeper failed at once, in full public view.

Banking · Credit Suisse

Greensill Capital

$10 billion of client money moved into Greensill's funds on minimal due diligence, against warnings dating back to 2017. No Credit Suisse executive was ever formally held responsible.

Crypto · VASP

Binance

Its founder pleaded guilty personally and paid $50 million. The company paid $4.3 billion — internal messages showed executives knew, and chose market share over compliance anyway.

Wilful blindness. Captured oversight. Risk defined by classification, not by reality. One playbook — banking, government, sport, crypto all run it.

What actually changed

In 2016, you could hide behind the institution.

By 2025, you can't — and in 2026, the ground shifted again. Personal accountability has been layered onto firm liability for the better part of a decade: SM&CR built the foundation in 2016, ECCTA escalated it from 2023, and the Crime and Policing Act pushed further still in June 2026.

  1. 2016
    SM&CR names the MLRO personally — SMF17.

    The Senior Managers and Certification Regime, rolled out from 2016 for banks and extended across all FCA-regulated firms by 2019, is the foundation everything since has built on. It named the MLRO individually as an SMF17 holder and gave the FCA power to pursue that person directly — fines, prohibition from working in financial services — independently of whatever happens to the firm.

  2. s.196
    The identification doctrine, lowered for economic crime — now superseded.

    Before ECCTA, pinning criminal liability on the firm required proving a senior enough individual was its "directing mind and will" — a board-level standard that rarely applied in practice. Section 196 lowered that bar for economic crime specifically: a senior manager's conduct, acting within the actual or apparent scope of their authority, could expose the firm directly. It was repealed on 29 June 2026 — the mechanism it introduced didn't disappear, it moved into section 250 below and got considerably wider.

  3. s.199
    Failure to prevent fraud — in force since September 2025.

    Mirroring the Bribery Act's Section 7 architecture, a firm's defence requires reasonable, tested, board-owned fraud prevention procedures. Paper procedures are explicitly not a defence. When that defence fails, the next question is who was responsible for the framework — which points straight at the compliance function.

  4. s.250
    No reasonable procedures defence — and the net just got wider.

    The Crime and Policing Act 2026 received Royal Assent on 29 April 2026 and section 250 came into force on 29 June 2026, replacing section 196 outright. It applies the same senior-manager test to any criminal offence, not just the economic-crime list — and unlike Failure to Prevent Fraud above, there is no defence available at all. A genuine, tested compliance framework protects you against s.199. It does nothing against s.250. The only thing that matters is whether the underlying conduct itself — documented, evidenced, independent — would survive being examined without you in the room to explain it.

SM&CR named you. ECCTA made senior managers the trigger for corporate liability. Section 250 removed the one defence that made that survivable — now only the conduct itself protects you.

Who this is built for

Built for the people who carry the risk personally.

Kim is not bulk tick-box training for a headcount return. It is judgement development for the people whose name goes on the SAR — or whose name comes up when the pattern is found too late.

Ongoing training

CPD-aligned, session by session.

Continuing Professional Development is not optional box-ticking for compliance staff — most professional bodies require it to keep a certification or membership current, with real evidence to show for it. Kim is built for that obligation directly: short scenario sessions your team returns to across the year, each one grounded in a real case, not a generic refresher. On a licensed deployment, Kim produces the evidence record itself — who trained, on what, and for how long.

  1. Brush up on a topicStructuring, PEP exposure, sanctions, correspondent banking risk — Kim identifies where a refresher is due and works through it properly, not a slide re-read.
  2. Test it with real questionsKim builds questions and answers around the topic, checking the understanding is actually there — not just familiarity with the terms.
  3. Apply it to a hypothetical caseA constructed scenario puts the topic into practice before it ever has to matter for real.
  4. Evaluate a real scenarioBring an actual situation your team is facing, and Kim works through it as a live case, not a training exercise.
Licensed deployment

What you actually get, underneath.

Evaluation is free and anonymous. A licensed deployment is a different build underneath it — the same way every Netizen9 deployment is built, for every client, without exception.

Isolation

Your own tenant, not a shared instance

Your own subdomain, your own database, your own document store. No client's data, and no other firm's content, ever touches your deployment — this isn't multi-tenant SaaS with a client filter on top.

Evidence

A CPD roster professional bodies recognise

Who trained, on which topic, for how long — logged as structured evidence, not conversation transcripts. No session content is stored against a person's record. Tracking is opt-in per session; anonymous use stays available alongside it.

Incident support

A mode for a real incident, not a scenario

Direct, structured guidance through containment, escalation and the statutory chain, with a SAR/DAML draft built strictly from what's been said — gaps are flagged for the MLRO to complete, never invented. Every draft carries a review-before-filing notice; it is not legal advice.

Privacy

Opt-in tracking, never blanket surveillance

Zero stored data is the default for every evaluation session. Licensed evidence tracking switches on only for the sessions your firm chooses to log — a request for visibility beyond that is the wrong fit for how Kim is built.

Licensed deployment is a conversation, not a price list. Get in touch to talk through what your team needs — philip@netizen9.uk, Netizen9.

Plainly stated

What Kim is not.

  • Kim is not affiliated with, endorsed by or a product of any certifying or examining body.
  • Kim does not guarantee the outcome of any exam, assessment or regulatory review.
  • Kim does not replace an official professional body's own study materials.
  • Kim does not provide compliance advice to firms — it trains the people who give it.
Start now

The next case study is still being written.

Evaluate Kim free. Licensed deployment available for commercial use across your compliance function.