De Nederlandsche Bank fined payment institution CCV 2.65 million euros after 4,200 merchants sat outside its transaction monitoring system for 23 months.
Table of contents
De Nederlandsche Bank imposed a 2,656,250 euro transaction monitoring fine on payment institution CCV Group on 13 July 2026, after the firm left roughly 4,200 merchants outside its transaction monitoring system for 23 months. The regulator found alerts closed in bulk with no recorded justification, and raised the penalty because CCV had breached the same rule before.
- DNB fined CCV Group B.V. 2,656,250 euros for failing to monitor transactions adequately and continuously, under Section 3(2) of the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft).
- For 23 months, transaction profiles for about 4,200 merchants were never loaded into the monitoring system, so their payments ran unscreened.
- DNB started from a 2.5 million euro basic fine, increased it for repeat offending, then reduced it to reflect a remediation plan CCV is running.
- The failure was operational, not a policy gap: the rules existed, but the data feeding the system did not.
- It is the second Dutch KYC enforcement action in a week, following the ABN AMRO customer due diligence fine.
What did DNB actually penalise?
DNB penalised a data and control failure inside a live monitoring system, not a missing policy. On 13 July 2026 the Dutch central bank fined CCV Group B.V., a payment institution that processes card and point-of-sale transactions, 2,656,250 euros for breaching Section 3(2) of the Wwft. The regulator found the firm did not monitor transactions adequately and continuously over a multi-year period.
The core defect was concrete. For 23 months, CCV failed to load the transaction profiles of roughly 4,200 merchants, reported as close to 8 percent of its merchant base, into its transaction monitoring system. A profile tells the system what normal looks like for a given merchant, so without it those merchants generated no meaningful alerts. DNB also found weak follow-up on the alerts that did fire: some were closed in bulk without justification, and some were routed to teams that never reviewed them. The Wwft duty implements Article 13(1)(d) of the EU Anti-Money Laundering Directive, which lists among core due diligence measures "conducting ongoing monitoring of the business relationship".
| Fact | Detail |
|---|---|
| Regulator | De Nederlandsche Bank (DNB) |
| Firm | CCV Group B.V., payment institution |
| Date imposed | 13 July 2026 |
| Fine | 2,656,250 euros |
| Legal basis | Section 3(2), Wwft |
| Duration of gap | 23 months |
| Merchants unmonitored | ~4,200 (reported ~8 percent of base) |
| Aggravating factor | Prior breach of the same provision |
How was the transaction monitoring fine calculated?
The transaction monitoring fine was built from a fixed statutory starting point, then moved up for history and down for remediation. DNB set a basic fine of 2.5 million euros, the standard band for a serious Wwft breach of this type. It then raised the amount because CCV had already been penalised for the same failure, and reduced it to account for a recovery plan the firm is implementing. The net result was 2,656,250 euros.
The recidivism point matters. DNB issued CCV a formal instruction in 2019 over customer due diligence and transaction monitoring shortcomings, and confirmed in July 2021 that the firm had restored compliance. Compliance was therefore certified, then lost again. That pattern, a fix that did not hold, is what turns a control gap into an aggravated penalty.
| Step | Effect on the fine |
|---|---|
| Statutory basic fine | 2,500,000 euros |
| Repeat breach of same rule | Increase |
| Remediation plan under way | Decrease |
| Final penalty | 2,656,250 euros |
DNB published the basic fine and the net penalty, but not the exact euro value of each upward or downward adjustment, so the middle two figures are directional rather than disclosed amounts.
What does this mean for your obligations?
This case maps to ongoing monitoring duties, and it sets the bar at operational evidence, not written policy. Under Section 3(2) of the Wwft, ongoing monitoring is a core due diligence measure: firms must scrutinise transactions across the whole relationship, not only at onboarding. CCV held the framework but could not show it was running.
Three duties come into sharp focus. First, coverage: every customer, or in an acquirer's case every merchant, must be inside the transaction monitoring system, with a current profile, from day one. A silent gap of that size is a breach even if no laundering is proven. Second, alert handling: closing or escalating an alert is a decision that must be evidenced, with a recorded rationale, not a bulk action. Third, reporting integrity depends on both: unscreened flows and unreviewed alerts mean unusual transaction reports to the Financial Intelligence Unit are simply never generated. For payment institutions specifically, the merchant profile is the unit of monitoring, and onboarding data quality decides whether monitoring works at all. Firms preparing for the incoming AMLA single rulebook should expect this evidentiary standard to harden across the EU.
What is still uncertain, and where is the risk?
The open risk is that most firms cannot prove coverage, and this fine makes proof the test. CCV's defect was invisible from the inside for nearly two years, which raises an uncomfortable question for every regulated firm: would your own reconciliation catch 4,200 accounts missing from the monitoring feed? Many institutions monitor the alerts they receive, not the population they are meant to receive alerts about, so a loading failure produces silence that reads as calm.
Liability is the second unresolved area. Payment institutions often argue, as CCV has publicly, that their role differs from a bank's because they sit further from the end customer. DNB's action signals that the ongoing monitoring duty does not bend to that distinction: if you onboard the merchant, you monitor the merchant. Third, remediation risk is now on the record. CCV restored compliance once, in 2021, and the controls degraded again. A recovery plan reduced this fine, but a plan that does not stick invites a larger one next time. The cost of monitoring is not the build; it is sustaining coverage and evidence as systems, staff and merchant books change.
How does this compare with recent Dutch enforcement?
This is the second DNB customer due diligence fine in a single week, and the pattern is deliberate. Days earlier, DNB fined ABN AMRO 8.5 million euros for weak due diligence on high-risk customers. The amounts differ with firm size, but the theme is identical: Dutch supervision is testing whether controls operate in practice, and penalising firms that cannot show their controls actually ran.
| Case | Firm type | Fine | Core failure |
|---|---|---|---|
| CCV (13 Jul 2026) | Payment institution | 2.65 million euros | Merchants left unmonitored; alerts closed without justification |
| ABN AMRO (Jul 2026) | Bank | 8.5 million euros | Weak due diligence on high-risk customers |
How should compliance teams respond?
Start with a coverage reconciliation. Compare the population of active customers or merchants against the population actually loaded into your transaction monitoring system, and treat any delta as an incident, not a backlog item. Then test alert governance: pull a sample of closed and escalated alerts and check that each carries a documented, reviewable rationale. Finally, close the loop between onboarding and monitoring, because a profile that is never created is a customer that is never watched. Clean, structured identity data captured at onboarding is what makes a monitoring profile complete on day one.
This is where a verified, reusable identity layer helps. Zyphe captures customer identity through an NFC chip read to ICAO 9303 and eIDAS standards with two step liveness and no image upload, then produces a reusable credential and an exportable audit trail. That gives monitoring systems complete, consistent onboarding data from the first transaction, and gives supervisors the evidence trail they now demand. To see how it fits an acquirer or fintech stack, book a demo; pricing is usage based with no minimums.
The bottom line
The CCV case is a reminder that transaction monitoring is only as strong as the data feeding it and the evidence behind each decision. A firm can hold a complete rulebook and still fail if customers fall out of scope or alerts are closed without a trace. For teams running KYC and AML, the practical lesson is to prove coverage and prove decisions, continuously, because supervisors are now grading operations rather than intentions, and a control that worked once is not a control that works today.
Cited sources
- De Nederlandsche Bank, fine imposed on CCV for due diligence shortcomings (13 July 2026)
- Directive (EU) 2015/849, Article 13 (ongoing monitoring of the business relationship), EUR-Lex
- Wet ter voorkoming van witwassen en financieren van terrorisme (Wwft), official consolidated text
- De Nederlandsche Bank, published enforcement record for CCV Group's earlier Wwft instruction, compliance restored July 2021
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.