Article · FinCrime history
The Gateway That Cost $1.9 Billion
HSBC’s U.S. bank treated group affiliates as trusted correspondents, rated Mexico “standard” risk while cartel cash moved, and paid about $1.9 billion in a 2012 coordinated resolution after willful AML and sanctions failures.
On 11 December 2012, HSBC Holdings plc and HSBC Bank USA, N.A. (HBUS) admitted anti-money-laundering and sanctions violations and entered a landmark U.S. resolution. The package totaled about $1.9 billion: $1.256 billion in Department of Justice forfeiture under a five-year deferred-prosecution agreement, plus $665 million in civil penalties to the Office of the Comptroller of the Currency and the Federal Reserve. The OCC’s $500 million penalty also satisfied a concurrent $500 million FinCEN assessment. The DOJ forfeiture satisfied a $375 million OFAC settlement.[1][2][3]
The dollar figure can hide the more useful finding. Government records describe an enterprise-level breakdown: risk assessment, correspondent due diligence, transaction monitoring, investigations, suspicious-activity reporting, independent testing, staffing, and compliance authority all failed to operate as a coherent defense. HBUS became a gateway through which foreign affiliates and their customers reached the U.S. dollar system without controls matched to the risk.[1][4]
Prosecutors said the failures allowed at least $881 million in drug-trafficking proceeds, including proceeds associated with Mexico’s Sinaloa Cartel and Colombia’s Norte del Valle Cartel, to be laundered through HBUS. Assistant Attorney General Lanny Breuer called the record one of “stunning failures of oversight.”[1][5]
For FinCrime desks the point is direct. An affiliate relationship is not a lower-risk relationship. A shared brand, a common parent, or a long internal history does not replace customer due diligence. It can create an unchallenged assumption of trust precisely where independent skepticism is most necessary.
The U.S. bank as a dollar gateway
HBUS was the U.S. hub for a group with thousands of offices across dozens of countries. The Senate Permanent Subcommittee on Investigations found that HBUS provided correspondent accounts to more than 1,200 banks, including more than 80 HSBC affiliates, giving them access to U.S. dollar clearing, currency services, and payment rails. Senator Carl Levin concluded that the bank’s compliance culture had been “pervasively polluted for a long time.”[6]
Correspondent banking can be legitimate and indispensable. It is also a recognized high-risk channel because the U.S. bank often lacks a direct relationship with the foreign affiliate’s underlying customer. FinCEN found that HBUS had not collected or maintained customer-due-diligence information for any HSBC Group affiliate holding correspondent accounts. Policy exempted affiliates from ordinary due-diligence processes and failed to incorporate their business purposes, anticipated activity, AML supervision, host-country vulnerabilities, and AML compliance history into monitoring. Customers of those affiliates gained indirect U.S. access without appropriate monitoring and alerts.[4]
That is not a risk-based correspondent program. A foreign affiliate should be assessed with at least the rigor applied to an external respondent bank, and often more, because internal commercial and reporting relationships can weaken challenge. The Senate characterized correspondent banking as a potentially major conduit for illicit money when AML requirements are not observed.[6]
Mexico rated “standard” while cash moved daily
HSBC Mexico was central to the case. It was a major HBUS correspondent customer, accepted bulk U.S.-currency deposits, and processed wires. Despite publicly available information about drug-trafficking and money-laundering vulnerabilities, HBUS rated Mexico “standard,” its lowest AML risk category, from 2002 through 2009. FinCEN found that the country-risk process did not systematically incorporate available risk information or ensure consistent internal review.[4]
The consequences were operational. From 2006 through 2009, HBUS failed to monitor more than $670 billion in wire transfers and more than $9.4 billion in physical U.S.-dollar purchases involving HSBC Mexico.[1] The Senate reported that HSBC Mexico transported $7 billion in physical U.S. dollars to HBUS from 2007 to 2008, more than other Mexican banks, including one twice its size. Mexico’s banking regulator later said HSBC had become the main shipper of dollar cash from Mexico to the United States at its peak, handling about half of the total flow despite not being one of the country’s largest banks.[6][7]
The relevant typology included Black Market Peso Exchange activity, a system used to move U.S. drug-sale proceeds to cartels outside the United States. Beginning in 2008, the Homeland Security Investigations El Dorado Task Force and the U.S. Attorney’s Office for the Eastern District of New York identified HSBC Mexico accounts associated with BMPE activity and found that traffickers were depositing hundreds of thousands of dollars in bulk U.S. currency each day into HSBC Mexico accounts. Breuer’s summary was blunt: “These traffickers didn’t have to try very hard.” U.S. Attorney Loretta Lynch told reporters it had been reported to an HSBC official that money launderers regarded HSBC Mexico as the place to launder money.[1][5][8]
HSBC Group admitted it did not tell HBUS about significant AML deficiencies at HSBC Mexico, even though it knew of those problems and their effect on potential illicit flows into the U.S. bank.[1] The Senate also found that HSBC Mexico offered U.S. dollar accounts through a Cayman Islands branch that held about 50,000 client accounts and $2.1 billion with no staff or offices of its own.[9]
A committee that kept the risky clients
Records obtained under Mexico’s public information law by Quinto Elemento Lab and CONNECTAS, and republished by InSight Crime, show how the failures looked at the decision table. HSBC Mexico’s Communication and Control Committee was responsible for money-laundering risk, politically exposed persons, and suspicious transactions. Minutes from June 2006 to March 2008 show the committee repeatedly declining to exit high-risk clients.[10]
In mid-2007, the bank’s AML director proposed closing Casa de Cambio Puebla after U.S. authorities froze its accounts at Wachovia on suspicion of drug proceeds. The commercial banking division objected, and the committee kept the relationship. The exchange house’s dollar sales to HSBC had grown from $18 million in February 2005 to $113 million in March 2007. A DEA investigation later found that from 2003 onward, a network used the exchange house’s HSBC accounts to deposit millions in cash to buy aircraft used to move drugs from South America to Mexico. The committee also rejected a proposal to close accounts of Sigue Corporation, a U.S. money transmitter then negotiating with the Justice Department over undercover DEA transfers of drug money. Those accounts were never closed.[10]
Internal thresholds were weak. The Mexico committee adopted a policy of closing accounts only after four suspicious-activity reports, while group policy set the limit at two. Its chair later acknowledged that one account remained open after 16 such reports. After learning the committee had relied on a client letter to keep Sigue, HSBC’s senior manager of global compliance, John Root, asked, “What is this, the School of Low Expectations Banking?”[10]
Warnings came from inside Mexico too. In September 2007, the AML director briefed the committee on what became known internally as “the Sinaloa Case,” an unusual pattern across 81 clients involving employees at branches in Culiacán and border cities. The accounts were closed, but the matter was effectively shelved within three months. U.S. prosecutors later noted that HSBC branches in Sinaloa continued to accept large dollar deposits, and that HSBC shipped more than $1.1 billion in dollar bills from Sinaloa from 2006 to 2008. The AML director who raised these concerns was dismissed in February 2008 and warned on his way out that he would not be surprised if the bank faced criminal sanctions.[10]
Mexico’s CNBV said it had warned local management in 2007 and 2008 and received little response, then contacted HSBC’s head office because local management had minimized the risks. In July 2012, the CNBV fined HSBC Mexico 379 million pesos, about $28 million. HSBC Mexico acknowledged it failed to report 39 unusual transactions and reported 1,729 others late.[7]
Monitoring built to miss the flows
HBUS’s risk assessment did not reliably drive surveillance. FinCEN found that the bank excluded from review foreign-correspondent wire transactions from countries rated below “cautionary” or “high,” an approach that excluded about $60 trillion a year. When the bank changed one country’s risk rating in 2008, it summarily cleared more than 4,000 unaddressed alerts. Delayed reviews later produced hundreds of SARs filed more than a year after the underlying transactions, involving billions of dollars.[4]
The OCC’s 2010 findings, as summarized in the Senate record, cited failure to monitor $60 trillion in wire transfers and account activity, a backlog of 17,000 unreviewed alerts, and opening accounts for HSBC affiliates without AML due diligence.[6] A risk-rating decision controls which flows the monitoring system sees. Altering that rating, or an automated segmentation rule, must carry documented rationale, independent approval, impact analysis, and retrospective testing. It is not a technical setting change.
Bulk cash was another unprotected channel. From mid-2006 to mid-2009, HBUS took delivery of more than $15 billion in U.S. currency from group affiliates but did not conduct automated, effective monitoring of those banknote transactions, instead relying on manual targeted and quarterly reviews. Absent due-diligence information about affiliate customers in Mexico and other high-risk jurisdictions, the bank could not determine whether actual activity matched a lawful expected purpose. HBUS exited the banknote business in 2010.[4]
The alert-investigation function was severely understaffed. Thousands of alerts remained unprocessed, and staff often cleared alerts without adequate review. HBUS did not acquire an automated system suited to the volume, scope, and nature of its activity until April 2011, and it took another year to validate that system for effective suspicious-activity detection.[1][4] For investigators, an alert backlog is a risk indicator in its own right. It means the institution may hold known leads that have not become SARs, account restrictions, or referrals.
Governance failed before technology did
Technology alone did not cause the HSBC failure. FinCEN found inadequate internal controls, ineffective independent testing, insufficient qualified staffing, and a compliance function that lacked the standing and authority required over business and account-relationship lines. A culture persisted in which compliance officers were effectively denied the authority needed to manage the bank’s risk profile.[4]
Supervisory warnings did not translate into timely durable change. FinCEN stated that from 2005 to 2009, the OCC issued 83 AML Matters Requiring Attention to the HBUS board. The OCC then issued a 2010 consent cease-and-desist order citing deficiencies in suspicious-activity reporting, bulk-cash and international-funds-transfer monitoring, due diligence for foreign affiliates, and risk assessment for politically exposed persons and associates. The 2012 OCC penalty rested in part on failure to fully comply with that order.[2][11]
The Senate report also criticized the OCC. Investigators found the agency had not taken a single enforcement action against HBUS, formal or informal, over the previous six years, despite ample evidence of AML problems. The subcommittee recommended that the OCC treat money laundering as a safety-and-soundness threat rather than a consumer-compliance issue, and that it act firmly once a bank accumulated a threshold number of violations or Matters Requiring Attention.[6] Repeat findings are not merely a remediation-management issue. They are evidence the institution’s governance system cannot reliably identify, own, fund, and close financial-crime risk.
Independent testing also missed its purpose. FinCEN found that the audit program did not effectively evaluate AML vulnerabilities or identify BSA failures promptly; its scope was insufficient to assess the bank’s money-laundering exposure and ability to meet AML and SAR obligations.[4] Effective audit must test whether controls work in the actual high-risk population, tracing selected flows from raw data to alert, case, SAR decision, report quality, and law-enforcement availability.
Sanctions stripping: “Do not mention Iran”
The linked record includes a sanctions-control failure that reinforces the same cultural lesson. From the mid-1990s through September 2006, HSBC Group permitted approximately $660 million in OFAC-prohibited transactions involving Cuba, Iran, Libya, Sudan, and Burma to pass through U.S. financial institutions. Group affiliates followed instructions to omit sanctioned-country names, removed country-identifying information, used less-transparent cover payments, and in at least one case worked with a sanctioned entity to format payment messages to evade filtering.[1]
Payment messages carried notes such as “do not mention Iran.” HSBC Group learned of the practice in 2000. In 2003, its head of compliance acknowledged it could expose the group to sanctions enforcement, yet affiliates received dispensations to continue for three more years. Beginning in 2001, HBUS compliance staff repeatedly told group compliance that cover payments made proper OFAC screening impossible. Prosecutors said those protests were ignored. The Senate found that two affiliates sent nearly 25,000 transactions worth $19.4 billion through HBUS over seven years without disclosing their links to Iran.[1][6]
Sanctions and AML programs have distinct legal requirements, but they share core dependencies: complete and accurate payment data, independent challenge, credible escalation, and a culture that does not allow revenue or relationship pressure to override a control concern.
Travelers cheques, bearer shares, and terror-finance exposure
The Senate investigation identified three further areas of exposure. HBUS provided dollars and services to banks in Saudi Arabia and Bangladesh despite links to terrorist financing. Press coverage of the hearing identified Al Rajhi Bank as one of them, noting HSBC kept the relationship despite reported ties between the bank’s owners and terrorist financing. In under four years, HSBC cleared $290 million in obviously suspicious U.S. travelers cheques for a Japanese bank, benefiting Russians who claimed to be in the used-car business. HSBC also offered more than 2,000 accounts to bearer-share corporations, whose ownership can change hands without a trail.[6][9]
The hearing and the coordinated settlement
At the PSI hearing on 17 July 2012, HSBC’s head of group compliance, David Bagley, announced his resignation from that post.[12] The coordinated resolution followed five months later.[1][2][3]
The Justice Department filed a four-count felony criminal information charging willful failure to maintain an effective AML program, willful failure to conduct due diligence on foreign correspondent affiliates, and violations of the International Emergency Economic Powers Act and the Trading with the Enemy Act. HSBC forfeited $1.256 billion under a five-year DPA. The OCC assessed a $500 million civil money penalty, then the largest the agency had assessed, which also satisfied the concurrent FinCEN penalty. The Federal Reserve assessed a $165 million penalty against HSBC Holdings and HSBC North America Holdings, then the largest the Fed had assessed for BSA, AML, and sanctions compliance failures, plus a cease-and-desist order. Lynch said the agreement carried the largest penalty in any Bank Secrecy Act prosecution to that date.[1][2][3]
The DPA required structural change. HSBC replaced almost all of its senior management, clawed back deferred bonuses from its most senior AML and compliance officers, and agreed to partially defer bonuses for top executives during the agreement. An independent monitor, former prosecutor Michael Cherkasky, was appointed.[1][13]
Too big to jail, and what followed
The decision not to indict drew immediate criticism, and later investigation sharpened it. A July 2016 staff report from the Republican majority of the House Financial Services Committee, based on internal Treasury records, found that senior Justice Department leadership, including Attorney General Eric Holder, overruled a recommendation from the department’s Asset Forfeiture and Money Laundering Section to prosecute HSBC. The report said leadership was concerned that prosecuting the bank “could result in a global financial disaster.” It also described a letter from UK Chancellor George Osborne raising concerns about U.S. enforcement against British banks. The report was not formally adopted by the full committee. A Justice Department spokesman said its handling was consistent with policies that consider collateral consequences to employees, customers, investors, and the public.[14][15]
The monitorship itself was contested. In 2016, the Justice Department reported that Cherkasky found “commendable progress,” with HSBC spending more than $680 million and adding 2,584 compliance staff in 2015, but that he could not yet certify the program. A federal judge ordered a redacted version of the monitor’s report released; the Second Circuit reversed in July 2017, ruling that the report was not a judicial document.[13][16]
On 11 December 2017, HSBC announced that the DPA had expired, that it had met all of its commitments, and that the Justice Department would move to dismiss the deferred charges. Public Citizen called the outcome a travesty of justice. No HSBC executive was criminally prosecuted in the United States for the conduct.[17][18]
The problems did not end in 2012. In December 2021, the UK Financial Conduct Authority fined HSBC Bank plc £63.9 million for serious weaknesses in three key parts of its transaction-monitoring systems from March 2010 to March 2018, a period that overlapped the entire U.S. DPA. The FCA said the matters were separate from the 2012 U.S. action. FCA enforcement director Mark Steward said the systems were “not effective for a prolonged period despite the issue being highlighted on numerous occasions.” InSight Crime also reported in 2020 that HSBC Mexico had received 19 further sanctions from Mexican authorities for AML failures after its historic fine.[10][19]
What investigators still pull from the file
The red flags remain current. Physical currency volumes out of proportion to a bank’s market share. Country risk ratings that ignore well-known narcotics and laundering threats. Currency exchange houses and money transmitters with assets frozen elsewhere. Suspicious-activity report thresholds that allow repeat-flagged accounts to stay open. Payment messages stripped of originator or country information, or routed as cover payments. Sequentially numbered travelers cheques in bulk, and bearer-share entities. Alert backlogs in the tens of thousands. Affiliate correspondents exempted from due diligence. A compliance committee overruled by a business line’s letter.[1][4][6][10]
For desk practice, six moves still follow. Eliminate affiliate exemptions: subject internal correspondent relationships to documented, risk-based due diligence covering customers, products, geographies, regulatory record, and control effectiveness. Make risk ratings operationally consequential and governed: require independent approval and impact testing before a rating change excludes a material transaction population. Control cash at transaction level: bulk-cash activity needs automated surveillance, source-of-cash intelligence, expected-activity profiles, and rapid escalation; periodic manual sampling is not a substitute. Treat backlogs as exposure: set thresholds for alert aging; triage the oldest, highest-value, and highest-risk cases; and test prior closures for quality and SAR timeliness. Give compliance real authority: the second line must be able to challenge onboarding, restrict activity, require an investigation, and elevate disputes without subordination to commercial objectives. Test the whole chain: audit and quality assurance should follow selected transactions from intake through monitoring, investigation, SAR decision, and report narrative.[1][4]
Ask for the complete relationship record: affiliate due-diligence files, country and product risk-rating methodologies and change logs, banknote and wire surveillance coverage maps, alert aging and disposition quality, SAR timing versus transaction dates, committee minutes on high-risk exits, payment-message integrity samples, and communications between group and U.S. compliance. The most probative evidence often sits at the gap between what the institution knew, or should have known, and what its monitoring was designed to see.
HSBC paid, restructured, and kept operating. The controls failed in plain sight, flagged by the bank’s own compliance staff, by a foreign regulator, and by its U.S. examiners, for years before anyone forced a change. Every route into the financial system, especially an affiliate route, must be visible, risk-assessed, monitored, and challengeable. When a bank cannot explain who is using that route, why the flows make sense, and what the data says about risk, it is not carrying a compliance gap. It is creating a channel for illicit finance.
Sources
- U.S. Department of Justice, “HSBC Holdings Plc. and HSBC Bank USA N.A. Admit to Anti-Money Laundering and Sanctions Violations, Forfeit $1.256 Billion in Deferred Prosecution Agreement” (11 December 2012).
- Office of the Comptroller of the Currency, “OCC Assesses $500 Million Civil Money Penalty Against HSBC Bank USA, N.A.,” NR 2012-173 (11 December 2012).
- Board of Governors of the Federal Reserve System, consent cease-and-desist order and civil money penalty against HSBC Holdings PLC and HSBC North America Holdings, Inc. (11 December 2012).
- Financial Crimes Enforcement Network, Assessment of Civil Money Penalty: HSBC Bank USA, N.A. (2012).
- U.S. Department of Justice, “Assistant Attorney General Lanny Breuer Speaks at the HSBC Press Conference” (11 December 2012).
- U.S. Senate Permanent Subcommittee on Investigations, “HSBC Exposed U.S. Financial System to Money Laundering, Drug, Terrorist Financing Risks” (16 July 2012); full report U.S. Vulnerabilities to Money Laundering, Drugs, and Terrorist Financing: HSBC Case History.
- Associated Press via Fox News, “Mexico fines HSBC $28 million in laundering case” (July 2012).
- PBS NewsHour, “British Bank HSBC Makes $2 Billion Settlement” (11 December 2012).
- Raw Story / The Guardian, “HSBC compliance chief resigns at Senate hearing over ‘horrific’ actions” (July 2012).
- Ignacio Rodríguez Reyna, Zorayda Gallegos, and Silber Meza, “HSBC: Dirty Money and White Collars,” InSight Crime (9 October 2020), republished from Quinto Elemento Lab and CONNECTAS.
- Office of the Comptroller of the Currency, “OCC Issues Cease and Desist Order Against HSBC Bank USA, N.A.” (7 October 2010).
- NPR, “HSBC Executive Resigns During Money Laundering Hearing” (17 July 2012).
- Reuters via Malay Mail, “US: HSBC comes up short in money laundering vigilance” (2 April 2016).
- U.S. House Committee on Financial Services, Republican Staff, Too Big to Jail: Inside the Obama Justice Department’s Decision Not to Hold Wall Street Accountable (11 July 2016).
- The Hill, “GOP committee blasts the Justice Department over big bank case” (11 July 2016).
- Corporate Crime Reporter, “Second Circuit Court of Appeals Blocks Release of HSBC Monitor Report” (12 July 2017).
- HSBC Holdings plc, “Expiration of 2012 Deferred Prosecution Agreement” (11 December 2017).
- Public Citizen, “A Travesty of Justice: HSBC Being Released From Deferred Prosecution Agreement” (11 December 2017).
- Financial Conduct Authority, “FCA fines HSBC Bank plc £63.9 million for deficient transaction monitoring controls” (17 December 2021).