Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesNewsletterUpdates by emailGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / No. 126

FCA fines Starling Bank £29m: since 2017, the automated sanctions screening had been matching customers against only a fraction of the list

the screening ran

Incident date
2024-10-02
Published
2026-08-07
Authors
Lemma Critical Team
Related Pack
Pack B · Regulatory

TL;DR

On 2 October 2024, the UK’s Financial Conduct Authority announced a fine of £28,959,426 against Starling Bank for financial crime failings in its financial sanctions screening. At the centre was a failure of matching: until the bank noticed in January 2023, its automated screening had, since 2017, been matching customers against only a fraction of the full sanctions list. Separately, in breach of a requirement it had agreed with the FCA not to open accounts for high-risk customers, it opened over 54,000 accounts for 49,000 such customers between September 2021 and November 2023. The screening layer existed and it ran. What was missing is the layer that establishes, before an account is opened, that the matching covered the whole of the list.

What happened

  • Starling Bank is a UK digital bank that grew from roughly 43,000 customers in 2017 to 3.6 million in 2023. The FCA found that its measures against financial crime did not keep pace with that growth.
  • In 2021, when the FCA reviewed financial crime controls at challenger banks, it identified serious concerns with the anti-money laundering and sanctions framework in place at Starling. The bank agreed to a requirement restricting it from opening new accounts for high-risk customers until this improved.
  • Starling failed to comply, opening over 54,000 accounts for 49,000 high-risk customers between September 2021 and November 2023.
  • In January 2023, Starling became aware that its automated screening system had, since 2017, only been screening customers against a fraction of the full list of those subject to financial sanctions. A subsequent internal review identified systemic issues in its financial sanctions framework. Starling has since reported multiple potential breaches of financial sanctions to the relevant authorities.
  • The fine was £28,959,426. Starling agreed to resolve the matter and so qualified for a 30% discount; without it the figure would have been £40,959,426.

The failure took shape through the following chain.

  1. Automated sanctions screening runs. The machinery is there, and customers are matched every day.
  2. But what they are matched against is a fraction of the source list. A sanctioned party can clear the check.
  3. High-risk customers, too, have accounts opened without those openings being checked against the agreed restriction.
  4. The attribute — sanctioned, or high-risk — surfaces only after the account exists: when the bank notices internally, and when the regulator investigates.

Timeline — disclosure and response

  • 2017: automated screening begins running against a fraction of the full sanctions list rather than the whole (discovered later). The bank has roughly 43,000 customers this year.
  • 2021: the FCA reviews financial crime controls at challenger banks and identifies serious concerns with Starling’s AML and sanctions framework. Starling agrees to a requirement restricting new accounts for high-risk customers.
  • 2021-09 to 2023-11: in breach of that requirement, over 54,000 accounts are opened for 49,000 high-risk customers.
  • 2023-01: Starling becomes aware that its screening covered only a fraction of the full list. A subsequent internal review identifies systemic issues in the sanctions framework.
  • 2024-10-02: the FCA announces a fine of £28,959,426, after a 30% discount for early resolution.

The figures, periods, and account counts in this Brief come from the FCA’s press release. The Final Notice is published as an encrypted PDF and could not be read directly at the time of writing, so findings specific to that notice are not relied on here. Starling has accepted the FCA’s findings and says it has begun remediation — an account from the party involved.

The response and industry movement after disclosure:

  • The FCA’s joint executive director of enforcement and market oversight commented on Starling’s screening controls.

Starling’s financial sanction screening controls were shockingly lax. It left the financial system wide open to criminals and those subject to sanctions. It compounded this by failing to properly comply with FCA requirements it had agreed to, which were put in place to lower the risk of Starling facilitating financial crime.

  • The FCA notes that this case took 14 months from opening to outcome, against an average of 42 months for comparable cases.
  • Starling has reported potential sanctions breaches to the relevant authorities and says it is remediating its screening and related controls.

Why it wasn’t stopped

The failure here is neither that the matching machinery was absent nor that a check was defeated. There was no layer that established, before an account was opened, that the matching covered the whole of the sanctions list.

The screening ran. Customers were matched every day. What was missing sits earlier — a form in which someone could establish, independently, whether what they were matched against was the whole of the source list, and whether that matching bore on the act of opening an account at all. Matching against a fragment does not establish the attribute, however cleanly it clears. And for roughly six years, from 2017 until January 2023, no one inside the bank noticed the state it was in.

Matching means something only when it covers the whole of the source list. Against a fragment, clearing the check establishes nothing, and a sanctioned party surfaces only after the account exists.

The high-risk account openings have the same shape. The agreement not to open them existed; what did not exist was a form in which each opening could be checked against that agreement. As a structure in which a regulated attribute rides into a financial path without being independently checked, this shares a direction with Brief 093 (moving funds under sanctions), and it belongs to the KYC/AML cluster of Brief 013 · Brief 086 · Brief 077, where the layer that verifies identity and attributes thins out.

What proof would have changed

Proof-as-auth inserts one step into the path ahead of the moment an account is opened: it fixes what the customer was matched against. It is not that a machine judges whether the match itself was right. It puts “which version, and which extent, of the list was this customer matched against” into a form in which the person on the receiving end can establish it — before the account exists, and without querying the issuer.

Lemma’s design against this gap:

  • The list it was matched against, fixed. Tie the result to the version and extent of the list actually used, and keep which list it rests on in a form that can be checked before the action.
  • A record of the check. Keep when that binding was made, under whose issuance, and that it has not been altered since — tamper-evident, in a form that cannot be overturned later. The claim that the customer was screened stops being merely a claim.
  • Agreed restrictions, bound to the act. Tie a restriction such as a high-risk designation to each individual account opening, so that compliance with the agreement survives as a verifiable fact rather than a stated policy.
  • Only the result disclosed. Without handing over the list itself or the customer's sensitive data, make just the result — not sanctioned, within the agreed restriction — verifiable.

What this layer does not carry is worth stating as well.

  • It does not vouch for the correctness or completeness of the list. Maintaining the source of record is the issuing authority's job.
  • Whether a result is sound is judged by a person, on the basis of that binding.
  • The gate on opening an account sits with the bank's own process; this layer supplies the material for that decision, no more.

This is also where it differs from an operator’s own screening log. A log is something a party produces for itself; neither the regulator nor the counterparty can check it independently. Through the six years in which the matching covered a fragment, the logs would have accumulated normally.

Lemma does not replace sanctions screening products, nor does it detect financial crime. Screening, human review, and audit are complementary to this layer, not alternatives to it. The first catches known matches; the second closes one point before the account exists.

Sources

“The last layer left for cyber defense in the age of AI”“Proof-as-Auth: sign in without ever sending your key”Pillar 04 — Regulatory Attribute ProofBrief 093 (moving funds under sanctions)Brief 013 (Coinbase insider KYC breach)

This material is a structured analysis of public information; it is not an audit, diagnosis, or recommendation for any specific organization.

Cite this Brief

Lemma Critical Team. (2026).
"FCA fines Starling Bank £29m: since 2017, the automated sanctions screening had been matching customers against only a fraction of the list — the screening ran".
Lemma Critical Brief No.126. Lemma / FRAME00, Inc.
https://lemma.frame00.com/critical/briefs/126-starling-bank-sanctions-screening-partial-list/
Lemma

If it can't be verified,
it doesn't enter your operation.

Lemma attaches cryptographic proofs to data and AI execution, so the receiving side can confirm authenticity without asking the issuer. Detection stays; a proof layer is added in front of it.