The Danske Bank scandal — €200 billion in suspicious flows through a single Estonian branch over eight years — is often discussed as an AML compliance failure. It was that. But it was also a whistleblower failure, and in some ways that failure is the more instructive one.

Howard Wilkinson was a British banker who headed the trading unit at Danske Bank’s Estonian branch. In 2013 and 2014, he observed transactions that he believed were suspicious — large-volume flows from non-resident customers through structures that had no apparent commercial purpose. He reported his concerns to Danske Bank’s compliance function in Copenhagen.

The bank conducted an internal review. The review identified some problems and recommended some changes. But it did not trigger the kind of systemic response that the scale of the problem demanded. The branch continued to process suspicious transactions. Wilkinson eventually left Danske Bank. The flows continued until 2016. The scandal did not become public until 2018, when media reporting — first by the Danish newspaper Berlingske, then by a succession of international outlets — exposed the scale of what had happened.

Why internal whistleblowing failed

Wilkinson did what compliance training tells employees to do. He identified suspicious activity and reported it through internal channels. The system then failed him — and, more importantly, failed the public.

The reasons are structural, not personal. Internal whistleblower mechanisms face a fundamental conflict of interest: the institution being reported on is also the institution responsible for investigating the report. When the suspicious activity is generating significant revenue — as Danske’s Estonian non-resident business was — the institutional incentive to investigate thoroughly is directly opposed by the institutional incentive to preserve a profitable business line.

This does not require conscious corruption. It requires only that the people responsible for investigating the report are operating within an institutional culture where the default assumption is that the business is legitimate and the burden of proof falls on the whistleblower to demonstrate otherwise. In that environment, an internal review can acknowledge “areas for improvement” without confronting the fundamental question: is this business line a money laundering conduit?

What external whistleblowing achieves

The Danske scandal was ultimately exposed not by internal compliance, not by the regulator, and not by the correspondent banks whose systems were being used to clear the transactions. It was exposed by journalists and, later, by Wilkinson’s testimony to the Danish parliament and the European Parliament.

External whistleblowing — reporting to regulators, law enforcement, or the public — bypasses the institutional conflict of interest. It puts the information in the hands of people whose incentives are aligned with investigating rather than containing the problem.

The challenge is that external whistleblowing carries significant personal risk. Whistleblowers face retaliation, career damage, legal threats, and social isolation. Wilkinson’s willingness to testify publicly was unusual and courageous. Many potential whistleblowers in similar positions choose silence — not because they are indifferent, but because the personal cost of speaking up is real and the institutional support for doing so is inadequate.

What has changed — and what hasn’t

Since the Danske scandal, both the European Union and the United States have strengthened whistleblower protections. The EU Whistleblower Directive, adopted in 2019 and required to be transposed by EU member states by December 2021, establishes minimum protections for people who report breaches of EU law — including AML violations — through internal or external channels. It prohibits retaliation and requires institutions to establish secure reporting channels.

In the United States, the SEC and CFTC whistleblower programmes offer financial incentives — a percentage of sanctions exceeding $1 million — that have produced significant results. The SEC’s programme has awarded over $1.5 billion to whistleblowers since its inception. FinCEN established its own whistleblower programme under the AML Act of 2020, offering awards of 10–30% of monetary sanctions exceeding $1 million.

These are meaningful improvements. But they do not solve the fundamental problem: most whistleblower reports are first made internally, and internal mechanisms remain subject to the same institutional conflicts that failed at Danske Bank. Until organisations develop cultures where internal reporting of uncomfortable truths is genuinely valued — not just tolerated — the pattern will repeat.

For anyone in a financial institution who sees something that does not look right, the practical advice remains what it has always been: report internally, but document everything. If the internal response is inadequate, know your options — external regulators, whistleblower programmes, and legal protections exist for exactly this situation. And understand that the information you hold may be the difference between a problem that is contained and a problem that costs billions.

Previous articleCrown Resorts Pays AU$450M in AML Crackdown
Next articleOneCoin Co-Founder Gets 20 Years for $4B Scam