The UK’s Financial Conduct Authority (FCA) has cracked down on three former senior Dolfin Financial figures over a £35.5 million scheme to help clients avoid investor visa rules. Notably, the FCA found that the firm ran an illicit scheme that enabled clients to obtain UK Tier 1 investor visas without investing £2 million of their own money.
Dolfin’s Former Chief Executive, Denisz Nagy, was fined £324,800, while Former Finance Director, Sanjay Maraj, was fined £122,000. They have both also been banned from working in UK financial services. Enforcement action against the firm’s co-founder, Roman Joukovski, remains provisional.
How the Dolfin Scheme Remained Hidden for Years
The UK’s Tier 1 Investor Visa route was introduced in 2008, offering a viable residency route for high-net-worth individuals who made a substantial financial investment of at least £2 million in the economy. By 2022, the route was closed to new applications due to security concerns, including corrupted elites.

The FCA investigation found that a majority of the customers under the Dolfin scheme only paid fees of roughly £400,000 between 2016 and 2019. At least 99 people had received investor visas under the scheme, while Dolfin-linked businesses and immigration agents earned at least £35.5 million in fees.
In essence, the scheme was able to bypass authorities due to several factors:
- The Illusion of Compliance: The arrangement was deliberately designed to create the impression that customers had met the $2 million investment requirement via false paper trails.
- Concealed Networks: The visibility of millions of transactions was obscured across multiple fragmented layers through third-party channels, including immigration agents.
- Acting as an Authorized Firm: Because Dolfin Financial (UK) Ltd operated as a regulated wealth management firm, it avoided heightened regulatory scrutiny.
Reports indicated that Mr Nagy and Mr Joukovski played leading roles in creating and operating the scheme. At the same time, Mr Maraj was responsible for the financial aspects of the illicit scheme.
The FCA also found that Mr Joukovski deliberately hid his involvement and role within the scheme. However, investigations are still ongoing, as Mr Joukovski referred his Decision Notice to the Upper Tribunal, where his case will be presented.
The Timeline of the Dolfin Scheme, from 2019 to 2026
Scrutiny only caught up when the FCA identified broader red flags regarding Dolfin’s financial crime and Anti-Money Laundering (AML) controls, leading to initial voluntary restrictions in late 2019. Here is the full timeline of the Dolfin Scheme:
- 2019: The FCA imposed voluntary restrictions on Dolfin after identifying concerns, including around its Tier 1 investor-visa business and financial-crime controls. An independent review of the company was launched under section 166.
- 2021: The review uncovered material deficiencies in Dolfin’s onboarding and financial-crime controls. The FCA then stopped the firm from carrying out regulated activities. Months after, Dolfin entered Special Administration and became insolvent.
- 2022: The Home Office officially closed the UK Tier 1 Investor Visa route.
- 2026: The FCA announced the individual enforcement outcomes.
The Compliance Controls Dolfin Financial Ltd Needed in Place
Traditional Know Your Customer (KYC) processes pose an important first question: Who is this client? However, the Dolfin case underscores a crucial problem for compliance teams, that identity verification alone is not sufficient enough in managing financial crime risk.
This is particularly true in cases involving high-value relationships, such as the UK Tier 1 Investor Visa route. In a compliant framework, Dolfin would need to do more than verify identity. The firm should demonstrate a clear understanding of its clients, including the source of their funds, the purpose of the visa, and the nature of their relationship.
Compliance Lesson 1: Enhanced Due Diligence Is More Than a Box to Check
The Dolfin case shows why high-value transactions require scrutiny beyond the mere presence of supporting documents. Firms must have sufficient controls in place to understand where millions of pounds are allegedly being invested and whether the activity made any sense.
This includes understanding the funds origins, whether the customer truly owns or controls the funds, whether any third parties are involved, and whether the transaction aligns with its stated purpose. This makes abnormal behavior easier to identify later. As such, for higher-risk relationships, Enhanced Due Diligence (EDD), Source of Funds (SoF), and Source of Wealth (SoW) checks are especially critical.
Compliance Lesson 2: Strong Governance is Part of Financial Crime Prevention
The most important lesson from the case relates to governance. Compliance systems are only as good as the people who operate and respect them. A strong compliance infrastructure cannot compensate for a culture whereby senior decision-makers can ignore critical controls without being questioned.
Strong governance should therefore enforce clear escalation processes. This includes documented decision-making, appropriate segregation of duties, and an audit trail capable of showing not simply what decision was made, but who made it and why.
Compliance Lesson 3: Continuous Customer Risk Assessment as a Non-negotiable
A customer can have a legitimate passport, pass biometric verification, and successfully clear sanctions or Politically Exposed Person (PEP) screening, yet still carry significant risks. That is why KYC today increasingly needs to be an ongoing risk assessment rather than a one-off check.
Identity verification needs to operate alongside customer due diligence, Source of Funds checks, and ongoing monitoring. Ultimately, effective compliance is not just about confirming the customer’s identity. It is about understanding where their money comes from, why they are transacting, and whether their behavior continues to make sense over time.

Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally.



