Why Reasonable FinTech Companies Making Reasonable Efforts Still Get Fined

Published by Yetunde Rotinwa on

FinTech audit should NOT be an emergency in your business. It should be a routine process where you feel 100% in control and well prepared.

I just reviewed the formal findings from the regulatory audits of Bunq, Coinbase, N26, Chime, Robinhood, Klarna, and a few other prominent FinTech companies.

They have much more resources and bigger budgets than many smaller startups. They’re obviously trying their best to follow the law.

They still get fined.

Consider this example:
Bunq was audited by the Dutch National Bank and was given over a year to provide various explanations and additional documentation in relation to just about 30 sample customer files.

One of their “worst” and “riskiest” customers from the sample was selling flowers.

Bunq went above and beyond their regulatory obligations (in my opinion) by collecting various invoices, declarations, and verifications about the counterparties of this flower business, who were not even Bunq’s direct customers.

The payments appeared to be for actual flowers, as confirmed by shipping documents, invoices, and customs declarations.

DNB refused multiple explanations, accused Bunq of weak controls and processes, and fined them 2 million euros.

Coinbase, N26, Wise, and many other cases I reviewed are VERY similar.

Why do reasonable companies making reasonable efforts get fined?
There are 3 main mistake patterns:

Their documentation and policies are disconnected from what they actually do.
What they themselves view as risky often isn’t risky at all, while what regulators view as risky goes unaddressed.
They don’t know (or didn’t take the time to think about) how to explain operational limitations, legitimate inconsistencies, and summarise why their efforts were actually sufficient.

When these audits and inspections are over, companies are often left with a long list of audit findings, 99% of which you will find ridiculous, formalistic, and completely irrelevant.

Nevertheless, your company will have to spend time figuring out what to do about these findings and how to rectify the issues before the next audit.

Another waste of your management efforts.

What if I told you it doesn’t have to be this way?
It is possible to prepare for any regulator audit within a few days.

It is possible to know exactly what your audit outcome will be.

It is entirely possible for the audit findings list to be very short, sensible, and for you to rectify most issues during the audit and never think about it again.

In short, if you know how to prepare for the audit and focus on the right things, it will not be a paralysing emergency.

What Went Wrong at These Companies, and How You Can Easily Avoid the Same Issues
Here’s what I learned from reviewing the audit findings of Revolut, N26, Wise, Coinbase, Klarna, Bunq, and several others:

The 3 Patterns That Get FinTech Companies Fined
Pattern 1: Documentation and policies are disconnected from reality.

Most FinTech companies have beautiful compliance policies. They just don’t follow them.

Not because they’re reckless, but because the policies were written for an imaginary version of the business that doesn’t exist.

The result? Auditors compare what you wrote to what you actually do, and every gap becomes a finding.

Pattern 2: Risk perception mismatch.

What you think is risky often isn’t what regulators think is risky.

You might be obsessing over transaction monitoring thresholds while ignoring the fact that your customer risk assessment methodology has no documentation trail.

Auditors don’t care that you’re “doing your best.” They care whether you’re addressing the risks they care about.

Pattern 3: Inability to explain operational constraints and trade-offs.

Most compliance teams can’t articulate why their approach was sufficient given the circumstances.

They can’t explain why they prioritised X over Y.

They can’t defend the legitimate inconsistencies that exist in any fast-moving business.

When auditors ask, “Why didn’t you do [thing]?” the answer is usually some version of “we didn’t have time” or “we didn’t think of it.”

Neither of those answers works.

Why CEOs Should Stay Out of the Audit Process (Mostly)
Let’s say you, as a FinTech CEO, would like to get a favourable audit opinion in the shortest amount of time possible.

After receiving some initial questions and reviewing draft answers prepared by your team, you feel like the audit process is not going to go well. Everything looks disturbing, and you have an uncontrollable urge to jump in and start driving the conversation.

What’s a better strategy?
→ Let your compliance person lead the conversation and be a single point of contact for all audit communications.

Regardless of what you think of them, most likely they have completed more audits in their professional lives compared to you and have a better understanding of how satisfactory answers look.

→ Ask your compliance team about the typical audit process and its milestones.

Understand the role and purpose of the engagement letter and audit scope, the difference between findings and recommendations, how the exchange of information will look, and what needs to be prepared in advance.

→ You CAN assist your team by managing down the cost (or ask your CFO to get involved).

Here’s how you make a difference:

Get a clear understanding of who is going to be involved in the audit team and how many hours they plan to spend. If you see that a senior manager is going to spend 50 hours doing fieldwork analysis, ask to assign a more junior person to do these tasks (because it costs less).
Ask for a breakdown of the fees based on the activities performed and the seniority of the person performing the activity. For example, understand how many hours a person expects to spend reviewing one sample case, how many hours they expect to write a report or review your policies.
If you see that your auditors are planning to take 20 samples and review each sample account for 2 hours, you have a negotiation opportunity.

As soon as you get those estimates, you’ll be able to understand where your auditors plan to spend the majority of their time, how long things may take, and which sample sizes they’re planning to review.

This gives you ample material to challenge the underlying pricing assumptions in a much more constructive way, backed by data and logic.

You can potentially reduce your costs by up to 20%.

→ When your audit reaches the phase of discussing initial findings, you can help by pushing back and understanding whether the auditors’ requests are really well grounded.

Auditors make up stuff all the time. They need to see you defending your past choices, your policies, and your processes, and then they will pull back.

Sometimes (well, most of the time), when auditors make up stuff, the CEO can help by playing the dumbest person in the room and asking “naïve” questions and making innocent comments, such as:

“Is it really required? Why don’t our competitors do it?”
“Why do you think this is required? It makes no sense.”

By doing so, you as a CEO protect the professional standing of your team while effectively challenging the auditors without making them defensive.

Since you’re not a compliance professional, you’re “just” being curious and asking questions for your personal education only, which is non-threatening for the auditors.

→ Agree with your compliance team in advance which mistakes and omissions you will let your auditors find quickly.

You absolutely need to let them find small and easy mistakes (such as some policies not being updated or some dates missing), or they will keep digging.

The Bottom Line
If you know how to prepare for an audit and focus on the right things, it will not be a paralysing emergency.

Most FinTech companies approach audits reactively: scrambling when the auditor letter arrives, pulling together documentation that should have been ready months ago, and hoping for the best.

The companies that do well treat audits as a routine operational milestone, not a crisis.

They know what questions will be asked. They know how to answer them. They know how to defend their choices with logic, not excuses.

That’s the difference between a 2-million-euro fine and a clean audit report. is this blogpost evergreen?

Categories: FinTech

>