Article · FinCrime history

€200 Billion Through a Branch Nobody Watched

Danske Bank’s Estonian non-resident portfolio moved roughly €200 billion while group controls, whistleblower escalation, and U.S. correspondent disclosures failed, then produced a coordinated resolution above $2 billion and a bank-fraud conspiracy plea.

Danske Bank neoclassical facade with gold lettering and a bronze statue in the foreground
Danske Bank facade. Credit: architectural photograph

On 13 December 2022, Danske Bank A/S pleaded guilty in a U.S. federal court to conspiracy to commit bank fraud and agreed to forfeit $2.059 billion. Coordinated resolutions with the U.S. Securities and Exchange Commission and Denmark’s Special Crime Unit brought the package to about $2.06 billion, or roughly DKK 15.3 billion.[1][2]

The conduct sat inside a single branch in Tallinn. From the 2007 acquisition of Sampo Bank through the wind-down of the non-resident book, Danske’s Estonian operation ran a Non-Resident Portfolio (NRP) for customers outside Estonia, including customers in Russia and the wider Commonwealth of Independent States. The bank’s own 2018 investigation put payments through customers with non-resident characteristics at around €200 billion. The U.S. Department of Justice separately stated that between 2008 and 2016 the branch processed $160 billion through U.S. banks on behalf of the NRP. Both figures stand as each source stated them.[1][3][4]

Precision matters. Not every payment through the portfolio was proven criminal. The 2018 Bruun & Hjejle review did not assign a reliable transaction-by-transaction estimate of suspicious flow; it did conclude that a large part of the payments was expected to be suspicious.[3] The U.S. resolution was not an administrative AML penalty alone. Danske admitted it misled U.S. banks about the Estonia branch’s customers and AML controls to obtain and retain dollar access for high-risk customers.[1]

For FinCrime desks the point is direct. A remote branch, legacy system, or lucrative customer segment cannot sit outside group controls. When the group cannot see the customer, beneficial owner, funds, and alerts as one connected risk, a local portfolio can expose the entire institution and the clearing systems that serve it.

An acquisition left outside group sightlines

Danske acquired the Estonian operation in 2007 with Finland’s Sampo Bank. The branch kept its own information-technology platform. Customer documentation was frequently in Estonian or Russian. Group insight into the book was limited for years.[3][4]

According to the factual statement accompanying the U.S. plea, Danske scrapped a project to migrate the branch onto a central technology platform that would have allowed group-level monitoring of customers and transactions. The migration was judged too expensive.[5] The bank’s own investigation later found that the branch operated too independently from the rest of the group, with its own culture and systems and without adequate control or management attention. Control functions lacked sufficient independence from local management.[4]

Shortly after the acquisition, Russia’s central bank wrote to Danske about transactions of doubtful origin that could be connected to criminal activity, including money laundering.[5] The warning arrived early. Integration that would have made the warning visible at group scale was deferred.

The portfolio that bought dollar access

The NRP was the commercial engine. Customers neither lived in nor conducted business from Estonia. Bruun & Hjejle identified about 10,000 NRP customers who made roughly 7.5 million payments. Widening the scope to about 15,000 customers with non-resident characteristics brought the total to about 9.5 million payments worth around €200 billion. Incoming funds came mainly from Estonia, Russia, Latvia, and Cyprus, with the remainder spread across more than 150 countries.[3][4]

Profitability created foreseeable conflict. By 2014, an internal strategy presentation described the NRP as contributing 90 percent of Estonia’s profit before tax, while warning that a material reduction in non-resident business would reduce Baltic profitability.[3] The U.S. factual statement said the NRP generated more than half of the branch’s profits.[5] The SEC alleged these customers generated as much as 99 percent of the branch’s profits from 2009 to 2016.[6] The Danish Financial Supervisory Authority (DFSA) found that in 2012, Russian non-resident portfolios produced 35 percent of the branch’s profits while Russian clients made up only 8 percent of its customers.[7] Those figures describe different frames and years; each stands as the source stated it.

How the business worked is documented in the plea. Branch employees conspired with NRP customers to obscure the true nature of transactions, including through shell companies that hid actual ownership of funds. Some staff helped set up shell companies in exchange for a “consulting fee.” Some customers opened accounts without submitting account-opening documents and with minimal know-your-customer review.[1][5]

Investigative reporting later tied the branch to known laundering schemes, including reporting that $2.9 billion associated with the Azerbaijani Laundromat moved through Danske’s Estonian branch.[8] Association with publicly identified schemes was also among the portfolio-review risk indicators Danske’s investigators later tabulated.[3]

Red flags were structural, not subtle

Danske’s portfolio review examined approximately 6,200 customers and found shared suspicious addresses, email addresses, and phone numbers; large discrepancies between publicly reported revenue and payment activity; associations with publicly identified laundering schemes; rapid pass-through flows; unusual payment chains; unexplained source of funds or wealth; unusual payment descriptions; adverse media; and suspicious counterparties at other banks. Only a few reviewed customers were deemed free of suspicious characteristics or payments.[3]

The review found that 3,500 of the customers were associated with suspicious shared properties, 1,700 showed significant divergence between disclosed revenue and account payment activity, 500 were publicly associated with laundering schemes, and 450 had other suspicious features. The roughly 6,200 customers deemed suspicious represented the majority of the portfolio’s flow. The categories overlap and do not prove criminality for every customer. They show the risk profile was structural.[3]

Those indicators require relationship-level analysis. Shared contact data and common corporate-service addresses point to networks. Differences between turnover and transaction volume call for independent verification of commercial activity. Rapid credits followed by matching debits are a pass-through typology. The appropriate investigation joins related accounts, entities, directors, beneficial owners, signatories, introducers, counterparties, and payment narratives, then tests whether there is a credible legal and economic explanation for the network as a whole.

Due diligence failed at the point of entry

The branch’s problem was not merely weak monitoring of good customers. It had insufficient information to know who many customers actually were. Group Internal Audit’s early 2014 work confirmed deficiencies in account-opening documents, noted the risk of customer tipping-off and possible employee collusion, and found that account managers were assigned so many customers that effective ongoing monitoring was impossible.[3]

Auditors reported that they could not identify actual source of funds or beneficial owners. An employee explained that underlying beneficial owners were not identified because it could cause problems for clients if Russian authorities requested information. The audit work also identified highly profitable agreements with Russian intermediaries where the underlying clients were unknown. Auditors recommended a full independent review of all non-resident customers.[3]

Danske’s subsequent 2014 policy acknowledged the right requirements: understand the customer’s activity and transaction profile, identify ownership and beneficial owners, confirm legitimate business reasons for operating in the Baltics, and establish source of funds. It also foresaw winding down existing non-resident relationships by mid-2015.[3] Those fundamentals should have governed entry from the outset, not been introduced after years of high-risk activity and external warnings. The non-resident business was forced to end in 2015; Estonian supervisors later ordered the branch itself closed.[9]

A whistleblower heard but not fully escalated

In December 2013, an internal report titled “Whistleblowing disclosure: knowingly dealing with criminals in Estonia Branch” was sent to an executive-board member and personnel in Baltic Banking, Group Compliance & AML, and Group Internal Audit. It alleged insufficient customer financial data, false company accounts, continued dealing with a customer after apparent wrongdoing, suspicious payments, insufficient knowledge of beneficial owners, and a high-risk control environment for non-resident clients using U.K. limited-liability partnerships.[3]

Howard Wilkinson, who had led Danske’s trading unit in the Baltics, was the source of that escalation. He had found problems with a U.K. company banking at the branch and emailed senior officials in Copenhagen, including the chief risk officer and the group heads of internal audit and AML.[10][11]

Group Internal Audit investigated with staff outside the branch, but the executive board did not receive a copy of the whistleblower report and the audit committee was not told in its minutes that the investigation resulted from whistleblowing. More reports followed. In 2014, an external inquiry concerning misconduct and irregularities involving senior staff was contemplated, then overturned by two executive-board members. Group Compliance & AML later stated that no further action would be taken on specific allegations beyond listed action points; several allegations had been reduced to broad terms or omitted, including alleged internal collusion.[3]

The U.S. factual statement adds operational detail. Two targeted audits confirmed that some NRP customers were shell companies with false or insufficient information and that the branch had performed no due diligence on them. An outside auditing firm found 17 shortcomings, confirmed the branch had no automated transaction monitoring, and told Danske compliance staff that its gaps were greater than at other Baltic banks. Danske did not disclose the whistleblower’s allegations to authorities or its U.S. correspondent banks, and compliance executives disregarded an internal lawyer’s suggestion to share them with law enforcement.[5]

The lesson is not that every whistleblower claim must be accepted as fact. It is that the full allegation set must reach an independent escalation body, be preserved in its original form, and be investigated against clear scope and evidence standards. Management should not be allowed to substitute a summary that removes the most serious issues.

Misleading the dollar gatekeepers

The Estonia branch was local in legal form and global in settlement reach. U.S. correspondent banks asked for information about AML controls, transaction monitoring, customers, and risk profiles to open and maintain dollar accounts. By at least February 2014, DOJ said Danske knew from internal audits, regulators, and the whistleblower that some NRP customers engaged in highly suspicious and potentially criminal activity, including via U.S. banks, and knew the Estonia AML program was below the bank’s standards and inappropriate for NRP risk. Instead of providing accurate information, it misrepresented the branch’s AML program, transaction-monitoring capability, customers, and risk profile to U.S. banks.[1]

The factual statement describes three U.S. banks without naming them in the public summary used here. One raised concerns as early as 2008; during a compliance visit, branch employees admitted that when the U.S. bank flagged a customer, they would counsel the client to split activity across two or three entities to avoid the correspondent’s monitoring. That bank eventually closed the account after processing $34 billion for NRP customers. A second stopped processing payments for the branch; Danske executives worried internally that the bank might share its concerns with U.S. regulators. A third opened a relationship without being told of the first bank’s concerns, asked the branch to stop routing shell-company payments, was ignored, and processed $3.8 billion for NRP customers. A branch compliance executive falsely stated on the correspondent profile form that the branch had no high-risk customers.[5]

For correspondent teams the point is threshold-level. A respondent’s written attestations about its own AML program were false, and the respondent was coaching customers to defeat the correspondent’s monitoring. Dollar clearing must depend on ongoing, independently testable answers about the customer segment, local monitoring environment, beneficial-ownership framework, high-risk corridors, and the respondent’s ability to provide complete records.

Governance that priced earnings over risk

The DFSA found serious governance deficiencies. It said the bank reacted too late to information about inadequate AML measures and suspicions of customer criminality, including information from the whistleblower. The DFSA issued eight orders and eight reprimands and indicated that the bank’s capital requirement should rise by DKK 5 billion because compliance and reputational risk had become substantially greater than assumed.[7]

Before 2014, the board received scattered information about Estonia, including strong profitability and assurances that due-diligence and monitoring procedures mitigated risk. The internal investigation later concluded that, in 2014, the board and audit committee received a fundamentally different picture: previous reporting had been insufficient and incorrect.[3] After regulators raised concerns, the branch manager and head of AML sent headquarters a memo describing the NRP as prudent and well organized. The plea’s factual statement says the memo misrepresented the onboarding process, and Danske executives repeated its claims to the Danish FSA without verifying them. One executive wrote that the “main thing is how we look in this case, not how it really is.”[5]

Estonia’s Financial Supervision Authority issued a critical report in 2012 and, in 2014, found what it called large-scale, long-lasting systemic violations of anti-money laundering rules at the branch and notified Danish authorities. According to the Danish FSA’s later account of supervision, an EFSA critical report was discussed at a Danske board meeting on 7 October 2014, but its conclusions were toned down in the executive board’s minutes; at a June 2014 meeting, board members focused on earnings and the minutes recorded no comment on significant AML challenges.[7]

On 19 September 2018, Danske published the Bruun & Hjejle report. The review examined about 15,000 customers and 9.5 million payments, searched more than 8 million emails, and conducted more than 70 interviews. Chairman Ole Andersen said the bank had clearly failed to live up to its responsibility. The bank pledged to give away the estimated DKK 1.5 billion in gross income from the customers and said it had implemented the DKK 5 billion capital add-on. The report concluded that the board, chairman, and CEO had not breached their legal obligations.[4] CEO Thomas Borgen resigned in 2018. Estonian authorities arrested ten former branch employees in December 2018 and ordered the branch closed in 2019.[7][9]

The coordinated resolution

The Justice Department obtained a guilty plea to one count of conspiracy to commit bank fraud, with forfeiture of $2.059 billion, and credited about $850 million paid in related domestic and foreign resolutions. It cited the bank’s failure to voluntarily and timely disclose the conduct, but gave full credit for cooperation and remediation.[1] The SEC charged the bank with misleading investors about AML deficiencies in Estonia and failing to disclose their risks, ordering $413 million in disgorgement, interest, and civil penalty ($178.6 million civil penalty, $178.6 million disgorgement, and $55.8 million prejudgment interest), with disgorgement and interest deemed satisfied by parallel forfeiture and confiscation.[6]

Danske accepted a Danish Special Crime Unit resolution for violations of the Danish AML Act and Financial Business Act: a fine of DKK 3.5 billion and confiscation of DKK 1.249 billion, accepted at the City Court of Copenhagen. The bank agreed to three years’ probation under its U.S. plea. An independent expert was already monitoring implementation of its financial-crime plan under DFSA order.[2][12] After credits, the bank’s direct payment to the Justice Department was about $1.21 billion.[5] The Justice Department later transferred $50 million of forfeited funds to Estonia in recognition of its assistance.[13]

Prosecutors charged bank fraud rather than Bank Secrecy Act violations. Commentators noted the likely jurisdictional reasons and that the core of the case was Danske hiding its own AML failures from three U.S. banks, which undermined their compliance programs.[5] On 15 December 2025, Danske announced that its U.S. probation had ended, closing formal regulatory processes tied to the Estonia case.[14]

Individual accountability stayed uneven

Accountability for bank executives remained limited. Danish prosecutors charged Borgen in May 2019, then in 2021 dropped charges against nine former executives, including Borgen, citing a lack of evidence of gross negligence. In November 2022, a Danish court also cleared Borgen of liability in a DKK 2.4 billion lawsuit brought by 155 institutional investors.[15]

Outside facilitators fared differently. In 2022, a Copenhagen court sentenced a Lithuanian woman to a combined eight years after she admitted using the branch to try to launder 29.5 billion kroner.[16] In February 2024, the same court sentenced two more facilitators to nine and seven years in prison.[17] In May 2026, Denmark’s Eastern High Court upheld the nine-year sentence and reduced the other to six years.[18]

The Bruun & Hjejle report’s conclusion that the board, chairman, and CEO had not breached legal obligations, and the later dropped executive charges, sit beside the corporate guilty plea and facilitator convictions. The institutional record is closed; individual culpability for senior bank management was not established in the criminal cases that proceeded.

What investigators still pull from the file

The red flags travel. Non-resident customers with no business nexus to the booking jurisdiction. U.K. limited-liability partnerships, Cypriot companies, and other shells with opaque ownership. Profits concentrated in a narrow high-risk segment. Local staff selling “consulting” services to set up client companies. A respondent bank attesting to strong controls while lacking automated monitoring. Customer activity that splits across new entities soon after a correspondent raises questions. Local IT systems and records inaccessible to group compliance. Shared addresses, emails, and phone numbers across supposedly unrelated customers. Pass-through credits and debits with matching amounts. Beneficial owners left unidentified because disclosure might “cause problems.”[3][5]

For desk practice, six moves still follow. Treat remote high-risk portfolios as group risk: headquarters needs full data access, centralized visibility, and authority to restrict activity; local IT or language must not prevent oversight. Know the real party, not merely the account holder: for intermediaries, limited partnerships, corporate-service addresses, and offshore entities, verify beneficial ownership, source of wealth, source of funds, and commercial purpose before accepting or retaining the relationship. Investigate networks, not alerts in isolation: link accounts by beneficial owner, director, signatory, addresses, contact details, introducers, counterparties, and payment patterns. Preserve and independently escalate whistleblower evidence: full reports must reach the audit committee or equivalent independent authority; case scope cannot be narrowed by commercial management. Price and govern compliance risk honestly: a portfolio’s profit contribution should intensify board challenge, testing, and risk-appetite constraints. Protect correspondent access with transparency: incomplete or misleading AML disclosure by a respondent is a threshold issue.[1][3][5][7]

Ask for the complete relationship record: onboarding files, beneficial-ownership analysis, introducer agreements, alert and case histories, original whistleblower materials and attachments, audit working papers, correspondent questionnaires and profile forms, internal communications about scope and disclosure, and subsequent account and transaction actions. The most probative evidence often sits at the gap between what the institution knew, or should have known, and what it told correspondents, boards, and supervisors.

Danske’s Estonia case shows how AML risk accumulates when a profitable non-resident book runs beyond the parent’s effective sightline. The warning signs were present. The coordinated fines closed the corporate file. If a bank cannot independently explain who is moving money, why the payments make economic sense, and whether its own controls can see the complete relationship, it is not managing risk. It is creating a channel.

Sources

  1. U.S. Department of Justice, “Danske Bank Pleads Guilty to Fraud on U.S. Banks in Multi-Billion Dollar Scheme to Access the U.S. Financial System” (13 December 2022)
  2. Danske Bank, “Danske Bank reaches coordinated resolutions with the U.S. and Danish authorities regarding the Estonia matter” (13 December 2022)
  3. Bruun & Hjejle, Report on the Non-Resident Portfolio at Danske Bank’s Estonian Branch (19 September 2018)
  4. Danske Bank, “Findings of the investigations relating to Danske Bank’s branch in Estonia” (19 September 2018)
  5. Kaley Schafer and Peter D. Hardy, “SDNY Sentences Danske Bank in Massive AML Scandal,” Money Laundering Watch / Ballard Spahr (30 January 2023) (summarizing plea factual statement)
  6. U.S. Securities and Exchange Commission, “SEC Charges Danske Bank with Fraud for Misleading Investors about Its Anti-Money Laundering Compliance Failures in Estonia,” Press Release 2022-220 (13 December 2022)
  7. Danish Financial Supervisory Authority, “Decision Concerning Danske Bank’s Management and Control in the Estonian Money Laundering Case” (3 May 2018); DFSA supervision report (January 2019, archived)
  8. OCCRP, “Azerbaijani Laundromat: The Core Companies” (4 September 2017); Re:Baltica (20 March 2019)
  9. Estonian Financial Supervision Authority, “Finantsinspektsioon Has Issued a Precept Requiring Danske Bank to Terminate Its Activities in Estonia” (19 February 2019)
  10. Association of Certified Fraud Examiners, “Howard Wilkinson,” Fraud Magazine (March/April 2020)
  11. National Whistleblower Center, “Howard Wilkinson”
  12. Danske Bank, “Resolution with SCU accepted at the City Court of Copenhagen” (14 December 2022)
  13. U.S. Department of Justice, “U.S. Transfers $50M in Forfeited Assets to the Republic of Estonia…”
  14. Danske Bank, “Danske Bank confirms conclusion of US Department of Justice probation,” Company Announcement No. 55 (15 December 2025)
  15. Reuters via Euronews, “Danske Bank ex-CEO cleared in $322 million investor lawsuit over Estonia case” (9 November 2022)
  16. Euronews, “Lithuanian woman jailed for laundering €4 billion in Danish kroner through Danske Bank” (23 June 2022)
  17. Bloomberg, “Danish Court Jails Two People for Laundering $4.2 Billion” (2 February 2024)
  18. Global Investigations Review, “Danish appeal court upholds Danske Bank-linked prison sentence” (27 May 2026)

← All articles