Coinbase spent 3 years fighting the UK FCA solving the wrong problem. Yes, let them eat cake.

Published by Yetunde Rotinwa on

There is a wonderful compliance case study hidden inside the FCA’s £3.5 million fine against Coinbase’s UK payments entity.

Not because Coinbase broke the law. They clearly did.

This story is a magnificent demonstration of what happens when very intelligent people spend enormous amounts of time and money managing a compliance problem instead of solving it.

A compliance team can be extremely busy, extremely diligent and extremely transparent and still keep working on completely the wrong thing.

What happened?

The FCA decided that some Coinbase customers were too risky for CB Payments. In 2020, the FCA identified weaknesses in the AML framework of CB Payments.

Just so we are clear for the people in the back: CB Payments was essentially the fiat gateway into the wider Coinbase ecosystem. It did not itself execute crypto trades. It was an internal fiat on/off-ramp service.

Coinbase therefore knew the purpose of these accounts and their connection to crypto trading, as well as the customers’ history.

The teams spent about five months in 2020 going back and forth with the FCA, trying to define the exact criteria for who would be considered a high-risk customer and find a workable compromise.

It took multiple meetings, calls and documentation submissions just to define the criteria, according to the FCA’s notice.

Eventually, both sides agreed that CB Payments would enter into the Voluntary Restriction regime with the FCA and develop new rules and flags to prevent existing Coinbase customers who met the criteria from using the internal fiat services.

Coinbase created at least five different committees, working groups and task forces to monitor progress and report the results to the Board.

Important distinction, again, for the people in the back: these prohibited customers were not sanctioned people, customers from Russia or North Korea, terrorists, corrupt PEPs or fraudsters.

They were people who displayed certain risk indicators based on how they answered particular questions.

Most of them were still eligible for general Coinbase services and had been using those services for years.

Coinbase spent three years and considerable money trying to solve this issue.

They could have explored whether a partner PSP in another country could process some of these transactions, or whether they could build an alternative payments solution elsewhere.

But no.

Big serious companies don’t always want to solve problems. Sometimes they want to manage problems as long and as thoroughly as possible.

Proposed solution: build the compliance flag, but make sure the requirements are complex and fuzzy

Coinbase decided to implement the restriction by building a new flag called VREQ.

I really want to meet the person who thought this was a good name.

VREQ sounds like the noise a printer makes before it dies.

Unlike Coinbase, I recently built a flag with a team for newly onboarded customers and we called it Rookie. I feel it is a much more inspiring name.

Nobody has ever been motivated to fix a control called VREQ.

Over the following two years, the CB Payments team sent multiple notifications and explanations to the FCA, describing problems such as:

  • Engineers implementing the flag were using an outdated set of requirements, meaning some criteria that should have triggered the restriction did not.
  • Some people on the global support team did not know about the requirement and were crediting customer accounts with “sorry bonuses.”
  • The new Simple Trade Service introduced in 2022 did not properly inherit the restriction.
  • Some customers changed their onboarding information during their relationship with Coinbase, and it was unclear whether they should have been restricted and from when.
  • The Coinbase Pro migration did not fully incorporate the relevant tag.

By December 2020, Coinbase had already discovered that 4,471 high-risk customers had been onboarded contrary to the VREQ.

Fixes were implemented.

In January 2021, Coinbase told the FCA that the VREQ had been fully implemented.

Excellent.

But…

For almost two years, Coinbase did not perform proper ongoing testing to determine whether the VREQ flag actually prevented flagged customers from accessing the relevant services.

Of course, they had dashboards.

Every modern compliance disaster needs a dashboard.

I am pretty sure Credit Suisse and FTX had even more dashboards.

This is my favourite part.

Customer-service employees had manually credited money to 199 flagged customers, including compensation for poor customer experiences.

That last category is particularly beautiful.

Imagine the conversation:

“Here is £20 compensation because we are terribly sorry you had a bad experience.”

“Wait. The FCA says we cannot put £20 into your wallet because this would be a prohibited transaction involving a high-risk customer.”

And somewhere, a compliance officer opens Incident Register.xlsx.

Line 345.

From January 2023, somebody in Compliance was required every working day to check whether flagged customers had nevertheless conducted transactions and escalate exceptions.

And once you build a system specifically designed to discover every tiny breach, something remarkable happens.

You discover every tiny breach.

One flagged customer had a pending e-money order that executed after the flag was applied.

Value: £11.35.

Coinbase notified the FCA the next day.

That is less than the hourly rate of literally every person who touched that notification, and I count at least six.

Then came another notification.

This time, 145 customers had received approximately £74,000 in refunds from previous Coinbase Card purchases. Seven more received about £4,000 through things such as fee rebates or compensation for complaints.

For Coinbase, this was peanuts.

Another notification followed.

Two customers had managed to transact through a third-party payment platform during the short period before the restriction was applied.

Total value: £50.

Yes, I am not kidding.

At this point, even Kafka in his most utopian state of mind might have stopped writing, because the plot had become too crazy.

The outcome

Over three years, 13,416 customers falling within the VREQ definition accessed CB Payments services.

They made deposits totaling approximately $24.9 million.

Those funds subsequently generated approximately $226 million of crypto transactions through other Coinbase Group entities.

Coinbase as a group made decent money.

These customers generated just 62 SARs.

Sixty-two SARs out of 13,416 customers is a rather compelling number, and nobody appears to have put it in front of the regulator as an argument.

Instead, the numbers became part of the evidence of the compliance problem.

The FCA fined CB Payments £3.503 million.

Just think about it.

Coinbase spent three years discovering, investigating, documenting, escalating, remediating and reporting breaches, including £11.35 and £50 transactions.

Eventually, they paid a £3.5 million fine.

Could they have approached the issue differently from the beginning instead of agreeing to a complex set of rules they struggled to implement for

>