On 27 July 2026, Switzerland’s Federal Criminal Court fined the Swiss Private Bank, Lombard Odier, CHF 3 million (around $3.6M) for failing to prevent aggravated money laundering by a former employee.
The former employee, a Lombard relationship manager, was given a 24-month custodial sentence, fully suspended. Additionally, the Swiss court ordered the confiscation of more than CHF 400 million in assets connected with the illicit scheme.
What did the Court Find Against the Geneva-Based Bank Lombard?
According to the court, the case can be traced back to a network called “the Office.” This network is connected to Gulnara Karimova, the daughter of Uzbekistan’s former president, Islam Karimov. Allegedly, the Office was moving funds from corruption involving foreign telecommunications companies seeking favorable treatment in the Uzbek market.
Lombard Odier’s former relationship manager managed the relevant accounts linked to the network. Swiss authorities found that he knew of indications that some assets might have originated from corruption in Uzbekistan’s telecommunications sector. Despite this, he conducted superficial checks, failing to adequately verify the money’s origin and economic purpose.

Under Article 102 of the Swiss Criminal Code, Lombard’s AML program was not sufficient to prevent the offense. In particular, its AML program failed to ensure that the source and economic purpose of the funds were investigated and documented.
Lombard has disputed the court’s decision, stating it never knowingly or wilfully participated in money laundering. Additionally, the bank emphasized that it had proactively submitted a suspicious-activity report in 2012 and had subsequently cooperated with the authorities.
As such, the ruling is not final. This case is critical because it concerned whether the bank had the right governance, escalation and investigative arrangements in place to sufficiently prevent employees from facilitating criminal proceeds.
Employee Risk Hiding in Plain Sight
One of the less-discussed elements of the backstory is the former employee’s connection to the customers before joining the bank. Allegedly, the relationship manager already knew Karimova and some members of the Office before he joined Lombard.
This creates a blind spot. While a banker’s existing network can prove commercial value, it can create significant risk and conflicts, especially when tied to an influential network such as the Office. Compliance teams should therefore treat pre-existing relationships as a distinct risk factor.
Relevant questions can include:
- Does the employee have a financial or reputational interest in maintaining the relationship?
- Is customer information being independently verified or largely supplied through the banker?
- Has the employee discouraged escalation or characterized high-risk alerts as normal for the client?
- Are compliance challenges documented and resolved independently of revenue ownership?
The Full Impact of the Case is Understated
The Swiss court has ordered the seizure of over CHF 400 million ($487 M) connected to the laundering offense or under the Office’s control. The Lombard case forms part of the broader Karimova investigation, whereby Swiss authorities froze almost CHF 800 million across the relevant proceedings beginning in 2012.
Regulatory penalties fall short of the overall costs of non-compliance.
Switzerland and Uzbekistan agreed that the confiscated Karimova-related assets would be returned through a United Nations trust-fund structure. Harry Varatharasan, Chief Product Officer at ComplyCube, mentions, “Regulatory penalties fall short of the overall costs of non-compliance. Asset restraints, remediation, and reputational effects far outweigh the headline fines.”
Compliance Takeaway and What to Expect Next
The next step in this case will be Lombard’s appeal. Compliance teams should expect closer scrutiny of whether controls are effective in practice. This is especially true as the Swiss Financial Market Supervisory Authority (FINMA) identifies private wealth management as a sector with elevated money laundering risks.
Despite submitting a suspicious-activity report, this case shows how regulators may reconstruct and challenge businesses on whether compliance controls could effectively challenge and prevent illicit funds. The lesson is that detection does not automatically prove that the AML framework is effective.
1. Review the Purpose of Transactions
Despite a customer having genuine source-of-wealth evidence, individual transactions may still appear suspicious. Thus, compliance teams should understand whether a transaction has a clear purpose, not whether a client can afford the transaction. For example, this can include alerts on transactions that are unusually large or inconsistent with the customer’s expected activity.
Learn how transaction screening can support identifying and detecting risk in real time.
2. Documented Escalation
Businesses should maintain clear audit trails and provide real judgment on how challenges are resolved. For instance, this can include what concern was identified, what questions were asked, and what evidence was used to resolve it. Reports do not need to be lengthy. Instead, it needs to show more than the fact that a customer or transaction was approved.
Learn how case management tools can help teams maintain a consistent audit trail.
3. Treat Employee Relationships as a Risk Factor
In situations where an employee might know or have worked with a customer, that relationship should be disclosed. This is particularly true if the relationship holds high commercial value, as it can create unconscious bias or make it hard to challenge a customer’s explanation. An independent review of the relationship can help ensure the relationship does not replace due diligence.
Learn how KYC questionnaires can help you identify and manage these relationship risks.

Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally.



