Learn more about the latest security and privacy threats
Back

The DNB CCV transaction monitoring fine: a payments firm left 4,200 merchants unmonitored for 23 months

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 15, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "The DNB CCV transaction monitoring fine: a payments firm left 4,200 merchants unmonitored for 23 months".

De Nederlandsche Bank fined payment institution CCV 2.65 million euros after 4,200 merchants sat outside its transaction monitoring system for 23 months.

Table of contents

De Nederlandsche Bank imposed a 2,656,250 euro transaction monitoring fine on payment institution CCV Group on 13 July 2026, after the firm left roughly 4,200 merchants outside its transaction monitoring system for 23 months. The regulator found alerts closed in bulk with no recorded justification, and raised the penalty because CCV had breached the same rule before.

  • DNB fined CCV Group B.V. 2,656,250 euros for failing to monitor transactions adequately and continuously, under Section 3(2) of the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft).
  • For 23 months, transaction profiles for about 4,200 merchants were never loaded into the monitoring system, so their payments ran unscreened.
  • DNB started from a 2.5 million euro basic fine, increased it for repeat offending, then reduced it to reflect a remediation plan CCV is running.
  • The failure was operational, not a policy gap: the rules existed, but the data feeding the system did not.
  • It is the second Dutch KYC enforcement action in a week, following the ABN AMRO customer due diligence fine.

What did DNB actually penalise?

DNB penalised a data and control failure inside a live monitoring system, not a missing policy. On 13 July 2026 the Dutch central bank fined CCV Group B.V., a payment institution that processes card and point-of-sale transactions, 2,656,250 euros for breaching Section 3(2) of the Wwft. The regulator found the firm did not monitor transactions adequately and continuously over a multi-year period.

The core defect was concrete. For 23 months, CCV failed to load the transaction profiles of roughly 4,200 merchants, reported as close to 8 percent of its merchant base, into its transaction monitoring system. A profile tells the system what normal looks like for a given merchant, so without it those merchants generated no meaningful alerts. DNB also found weak follow-up on the alerts that did fire: some were closed in bulk without justification, and some were routed to teams that never reviewed them. The Wwft duty implements Article 13(1)(d) of the EU Anti-Money Laundering Directive, which lists among core due diligence measures "conducting ongoing monitoring of the business relationship".

FactDetail
RegulatorDe Nederlandsche Bank (DNB)
FirmCCV Group B.V., payment institution
Date imposed13 July 2026
Fine2,656,250 euros
Legal basisSection 3(2), Wwft
Duration of gap23 months
Merchants unmonitored~4,200 (reported ~8 percent of base)
Aggravating factorPrior breach of the same provision

How was the transaction monitoring fine calculated?

The transaction monitoring fine was built from a fixed statutory starting point, then moved up for history and down for remediation. DNB set a basic fine of 2.5 million euros, the standard band for a serious Wwft breach of this type. It then raised the amount because CCV had already been penalised for the same failure, and reduced it to account for a recovery plan the firm is implementing. The net result was 2,656,250 euros.

The recidivism point matters. DNB issued CCV a formal instruction in 2019 over customer due diligence and transaction monitoring shortcomings, and confirmed in July 2021 that the firm had restored compliance. Compliance was therefore certified, then lost again. That pattern, a fix that did not hold, is what turns a control gap into an aggravated penalty.

StepEffect on the fine
Statutory basic fine2,500,000 euros
Repeat breach of same ruleIncrease
Remediation plan under wayDecrease
Final penalty2,656,250 euros

DNB published the basic fine and the net penalty, but not the exact euro value of each upward or downward adjustment, so the middle two figures are directional rather than disclosed amounts.

What does this mean for your obligations?

This case maps to ongoing monitoring duties, and it sets the bar at operational evidence, not written policy. Under Section 3(2) of the Wwft, ongoing monitoring is a core due diligence measure: firms must scrutinise transactions across the whole relationship, not only at onboarding. CCV held the framework but could not show it was running.

Three duties come into sharp focus. First, coverage: every customer, or in an acquirer's case every merchant, must be inside the transaction monitoring system, with a current profile, from day one. A silent gap of that size is a breach even if no laundering is proven. Second, alert handling: closing or escalating an alert is a decision that must be evidenced, with a recorded rationale, not a bulk action. Third, reporting integrity depends on both: unscreened flows and unreviewed alerts mean unusual transaction reports to the Financial Intelligence Unit are simply never generated. For payment institutions specifically, the merchant profile is the unit of monitoring, and onboarding data quality decides whether monitoring works at all. Firms preparing for the incoming AMLA single rulebook should expect this evidentiary standard to harden across the EU.

What is still uncertain, and where is the risk?

The open risk is that most firms cannot prove coverage, and this fine makes proof the test. CCV's defect was invisible from the inside for nearly two years, which raises an uncomfortable question for every regulated firm: would your own reconciliation catch 4,200 accounts missing from the monitoring feed? Many institutions monitor the alerts they receive, not the population they are meant to receive alerts about, so a loading failure produces silence that reads as calm.

Liability is the second unresolved area. Payment institutions often argue, as CCV has publicly, that their role differs from a bank's because they sit further from the end customer. DNB's action signals that the ongoing monitoring duty does not bend to that distinction: if you onboard the merchant, you monitor the merchant. Third, remediation risk is now on the record. CCV restored compliance once, in 2021, and the controls degraded again. A recovery plan reduced this fine, but a plan that does not stick invites a larger one next time. The cost of monitoring is not the build; it is sustaining coverage and evidence as systems, staff and merchant books change.

How does this compare with recent Dutch enforcement?

This is the second DNB customer due diligence fine in a single week, and the pattern is deliberate. Days earlier, DNB fined ABN AMRO 8.5 million euros for weak due diligence on high-risk customers. The amounts differ with firm size, but the theme is identical: Dutch supervision is testing whether controls operate in practice, and penalising firms that cannot show their controls actually ran.

CaseFirm typeFineCore failure
CCV (13 Jul 2026)Payment institution2.65 million eurosMerchants left unmonitored; alerts closed without justification
ABN AMRO (Jul 2026)Bank8.5 million eurosWeak due diligence on high-risk customers

How should compliance teams respond?

Start with a coverage reconciliation. Compare the population of active customers or merchants against the population actually loaded into your transaction monitoring system, and treat any delta as an incident, not a backlog item. Then test alert governance: pull a sample of closed and escalated alerts and check that each carries a documented, reviewable rationale. Finally, close the loop between onboarding and monitoring, because a profile that is never created is a customer that is never watched. Clean, structured identity data captured at onboarding is what makes a monitoring profile complete on day one.

This is where a verified, reusable identity layer helps. Zyphe captures customer identity through an NFC chip read to ICAO 9303 and eIDAS standards with two step liveness and no image upload, then produces a reusable credential and an exportable audit trail. That gives monitoring systems complete, consistent onboarding data from the first transaction, and gives supervisors the evidence trail they now demand. To see how it fits an acquirer or fintech stack, book a demo; pricing is usage based with no minimums.

The bottom line

The CCV case is a reminder that transaction monitoring is only as strong as the data feeding it and the evidence behind each decision. A firm can hold a complete rulebook and still fail if customers fall out of scope or alerts are closed without a trace. For teams running KYC and AML, the practical lesson is to prove coverage and prove decisions, continuously, because supervisors are now grading operations rather than intentions, and a control that worked once is not a control that works today.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

DNB fined CCV Group 2,656,250 euros because it did not monitor transactions adequately and continuously. For 23 months the firm failed to load the transaction profiles of about 4,200 merchants into its transaction monitoring system, and it closed alerts in bulk without recorded justification. Both are breaches of the ongoing monitoring duty in Section 3(2) of the Wwft.

Section 3(2) of the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act sets out the customer due diligence measures a firm must take, including ongoing monitoring of the business relationship. It implements Article 13(1)(d) of the EU Anti-Money Laundering Directive, which requires firms to scrutinise transactions throughout a relationship, not only when a customer is first onboarded.

DNB started from a 2.5 million euro basic fine, then increased it because CCV had previously been penalised for breaching the same requirement. It reduced the figure to reflect a remediation plan the firm is running. The repeat nature of the failure was the main aggravating factor, landing the final penalty at 2,656,250 euros.

No. The ongoing monitoring obligation applies to payment institutions in the same way it applies to banks. DNB's action makes clear that if a firm onboards a merchant or customer, it must monitor that relationship. An acquirer cannot treat its distance from the end user as a reason to leave merchants outside the monitoring system.

The overriding lesson is durability. A control certified compliant once, as CCV's was in 2021, still has to hold years later, and DNB treated the relapse as an aggravating factor. Evidence every alert decision with a recorded rationale, and expect the standard to tighten further as the EU AMLA single rulebook takes effect.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo