us

216.73.217.135

Back
News

New York State Department Fines Robinhood $30m for Inadequate AML Compliance Measures

New York State Department Fines Robinhood $30m for Inadequate AML Compliance Measures
R Richard M. AUGUST 3, 2022 1 minute read

New York’s top financial regulator has fined Robinhood $30 million for failures and shortcomings in the company’s oversight of its AML compliance programs.

The New York State Department of Financial Services has taken action against the cryptocurrency trading unit of online brokerage Robinhood for alleged violations of Anti-Money Laundering (AML) and cybersecurity regulations in the department’s first crypto enforcement action.

The New York State financial regulator stated on 2 August that Robinhood has inadequate maintenance measures to ensure Anti-Money Laundering and cybersecurity compliance.

According to the consent order, Robinhood is required to retain an independent consultant to evaluate its compliance with NYDFS’s regulations and its remediation efforts. NYDFS reportedly found significant failures after a supervisory exam followed by an enforcement investigation of Robinhood. 

The failures, the regulator said, resulted from shortcomings in the company’s management and oversight of its compliance programs. These include failures to ensure compliance and to assign adequate resources to the AML and cybersecurity programs, particularly as the company grew quickly.

Robinhood stated that in its latest quarterly filing, it had a total of 15.9 million monthly active users at the end of March. 

This was first publicly disclosed in the investigation and settlement with the NYDFS a year ago in the paperwork filed with the Securities and Exchange Commission. The company initially expected a monetary penalty of at least $10m and later increased it to $30m.

NYDFS said Robinhood’s Bank Secrecy Act and anti-money-laundering compliance program was insufficiently staffed and failed to transition in a timely manner from a manual transaction monitoring system that was appropriate for the company’s size, transaction volumes and customer profiles. 

Robinhood’s cybersecurity program also failed to address the company’s operational risks, and its policies weren’t in compliance with the regulator’s cybersecurity and virtual currency regulations, NYDFS said.

Suggested read: New York Financial Department Releases Guidelines On Dollar-Backed Stable Coins

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.