The cost of not knowing

Ten enforcement actions in thirty months. Not one of them was a cyber breach.

January 2024 to July 2026. Five supervisors, four currencies, and in every single case the finding was about data — how it was classified, whether anyone owned it, whether it was checked, and whether what reached the regulator was true.

What it cost, by what failed

These are the four governance areas supervisors have actually fined.

Grouped not by who was fined, but by the capability that was missing. Each figure is the running total of every published penalty in that area over the period. If your estate is weak in one of these, that is the price of the weakness.

Cumulative penalties · January 2024 – July 2026 · ten actions

$135.6m2 actions

Data-quality monitoring

Controls too weak to monitor data quality in regulatory reporting, and insufficient progress remediating the deficiencies once they were known.

€20.6m + £57.4m4 actions

Classification & ownership

Exposures, instruments and deposits assigned to the wrong category or the wrong party — and ownership left unassigned.

£40.1m3 actions

Reporting controls & accuracy

Control deficiencies across the reporting chain, incorrect figures submitted repeatedly, and information given to a regulator that was not true.

₹6.8m1 action

Completeness of reporting

Required exposures never reported to the central repository at all.

Amounts are shown in the currency each penalty was levied in. We do not publish a converted grand total — choosing an FX rate to manufacture one large number is exactly the sort of thing this audience checks. Per-area subtotals reconcile to the per-regulator subtotals in the public registers.

Read the largest number again. The biggest single area on this page was not levied for a wrong figure. It was levied because the controls could not tell good data from bad, and because the gap stayed open after it was known. That is a penalty for the absence of measurement — not for a mistake.
The record

What the supervisors actually found.

All ten actions, de-identified. We do not publish the institutions’ names — the argument is in the categories and the duration, not in anyone’s embarrassment.

Ten public enforcement actions across five supervisors between January 2024 and July 2026, most recent first. Institutions de-identified by editorial policy.
Date Regulator Area that failed Penalty The finding
Jul 2026 PRA Reporting accuracy £4.17m Incorrect deposit-protection liabilities and fee-tariff data submitted repeatedly across four years
Mar 2026 PRA Reporting accuracy £2.0m Misleading capital information, and fabricated documents given to the regulator
Mar 2026 ECB Classification €6.2m Sovereign-bond options misclassified as model-eligible — wrong market-risk RWA across six reporting periods
Feb 2026 ECB Classification €12.18m Corporate exposures misclassified and given the wrong risk weights — 15 consecutive quarters
Jan 2026 ECB Classification €2.26m Guaranteed receivables assigned to the debtors rather than the guarantors — 13 consecutive quarters
Mar 2025 RBI Completeness ₹6.82m Large-credit borrowers never reported to the central credit repository
Jul 2024 Federal Reserve Data-quality monitoring $60.6m Insufficient progress remediating data-quality management deficiencies
Jul 2024 OCC Data-quality monitoring $75.0m Governance and controls too weak to monitor data quality in regulatory reporting
May 2024 PRA Reporting controls £33.88m Reporting control deficiencies across a data and reporting transformation
Jan 2024 PRA Classification & ownership £57.42m 99% of eligible protected deposits classified “ineligible”, with ownership left unassigned

Sources: the PRA, ECB, OCC, Federal Reserve and RBI public enforcement registers, compiled August 2026. Figures as published. Institutions are deliberately not named.

The part that should worry you

Fifteen consecutive quarters. Thirteen. Four years.

None of these was a bad day. Almost every one ran undetected for quarters or years, inside institutions with the best-resourced data functions in the world.

These were not unprepared organisations

Capable teams, real control frameworks, expensive tooling, and audit functions that had signed things off. The error still ran for years.

An annual control cannot see this

A control tested once a year cannot catch a misclassification that starts quietly, stays perfectly consistent, and never trips an alert.

Duration is the whole argument

The failure mode in every row above is how long it lasted. That is the case for continuous per-product measurement — and it is made here by the supervisors, not by us.

Would FluenBox have caught one of these? We do not claim that. What is true is narrower and more useful: every area on this page is something the platform scores from evidence and re-checks on a cadence — and the failure mode in every row is duration.
Before you scroll past

Which of these could you answer about your last submission?

Not in principle. Today, with something you could put in front of a supervisor.

If any of those took more than a moment, the honest position is not that your data is bad. It is that you do not currently know — and “we did not know” is the finding in three of the ten actions above.

Find out where you stand before a supervisor does.

Thirty days, one slice of your estate, success criteria agreed up front — and you keep the result either way.