Personal liability for compliance failures is no longer theoretical. Kim trains MLROs and compliance teams for the regulatory environment that actually exists now.
UBS paid this in August 2026 for what regulators called "willful and repeated" AML failures — its second such penalty in under a decade.
None of it was the failure point. Kim's case library exists to show your team what actually was — the same underlying pattern, dressed differently by sector.
Its auditor signed off for ten years. When journalists found the fraud, the regulator investigated them, not the company. Every gatekeeper failed at once, in full public view.
$10 billion of client money moved into Greensill's funds on minimal due diligence, against warnings dating back to 2017. No Credit Suisse executive was ever formally held responsible.
Its founder pleaded guilty personally and paid $50 million. The company paid $4.3 billion — internal messages showed executives knew, and chose market share over compliance anyway.
Wilful blindness. Captured oversight. Risk defined by classification, not by reality. One playbook — banking, government, sport, crypto all run it.
By 2025, you can't. Personal accountability has been layered onto firm liability for the better part of a decade — SM&CR built the foundation in 2016, and ECCTA escalated it from 2023.
The Senior Managers and Certification Regime, rolled out from 2016 for banks and extended across all FCA-regulated firms by 2019, is the foundation everything since has built on. It named the MLRO individually as an SMF17 holder and gave the FCA power to pursue that person directly — fines, prohibition from working in financial services — independently of whatever happens to the firm.
Before ECCTA, pinning criminal liability on the firm required proving a senior enough individual was its "directing mind and will" — a board-level standard that rarely applied in practice. Section 196 lowers that bar: a senior manager's conduct, acting within the actual or apparent scope of their authority, can now expose the firm directly. It does not create personal liability for the MLRO — that's SMF17, above — but it does mean the firm's exposure now tracks the MLRO's own judgement more closely than before.
Mirroring the Bribery Act's Section 7 architecture, a firm's defence requires reasonable, tested, board-owned fraud prevention procedures. Paper procedures are explicitly not a defence. When that defence fails, the next question is who was responsible for the framework — which points straight at the compliance function.
SM&CR named you. ECCTA makes senior managers the trigger for corporate liability. Failure to Prevent Fraud requires you to prove the framework actually worked.
Kim is not bulk tick-box training for a headcount return. It is judgement development for the people whose name goes on the SAR — or whose name comes up when the pattern is found too late.
Continuing Professional Development is not optional box-ticking for compliance staff — most professional bodies require it to keep a certification or membership current, with real evidence to show for it. Kim is built for that obligation directly: short scenario sessions your team returns to across the year, each one grounded in a real case, not a generic refresher. On a licensed deployment, Kim produces the evidence record itself — who trained, on what, and for how long.
Evaluation is free and anonymous. A licensed deployment is a different build underneath it — the same way every Netizen9 deployment is built, for every client, without exception.
Your own subdomain, your own database, your own document store. No client's data, and no other firm's content, ever touches your deployment — this isn't multi-tenant SaaS with a client filter on top.
Who trained, on which topic, for how long — logged as structured evidence, not conversation transcripts. No session content is stored against a person's record. Tracking is opt-in per session; anonymous use stays available alongside it.
Direct, structured guidance through containment, escalation and the statutory chain, with a SAR/DAML draft built strictly from what's been said — gaps are flagged for the MLRO to complete, never invented. Every draft carries a review-before-filing notice; it is not legal advice.
Zero stored data is the default for every evaluation session. Licensed evidence tracking switches on only for the sessions your firm chooses to log — a request for visibility beyond that is the wrong fit for how Kim is built.
Licensed deployment is a conversation, not a price list. Get in touch to talk through what your team needs — philip@netizen9.uk, Netizen9.
Evaluate Kim free. Licensed deployment available for commercial use across your compliance function.