Compliance Takeaways from The FCA’s £35.5M Dolfin Scheme Probe

Image of passport in the middle with uk flag on top left | complycube

The UK’s Financial Conduct Authority (FCA) has cracked down on three former senior Dolfin Financial figures over a £35.5 million scheme to help clients avoid investor visa rules. Notably, the FCA found that the firm ran an illicit scheme that enabled clients to obtain UK Tier 1 investor visas without investing £2 million of their own money.

Dolfin’s Former Chief Executive, Denisz Nagy, was fined £324,800, while Former Finance Director, Sanjay Maraj, was fined £122,000. They have both also been banned from working in UK financial services. Enforcement action against the firm’s co-founder, Roman Joukovski, remains provisional. 

How the Dolfin Scheme Remained Hidden for Years

The UK’s Tier 1 Investor Visa route was introduced in 2008, offering a viable residency route for high-net-worth individuals who made a substantial financial investment of at least £2 million in the economy. By 2022, the route was closed to new applications due to security concerns, including corrupted elites.

Header announcing fca bans three dolfin financial executives over investor visa scandal with the trust edition banner and a  | complycube'Visa Approved' stamp visually present.

The FCA investigation found that a majority of the customers under the Dolfin scheme only paid fees of roughly £400,000 between 2016 and 2019. At least 99 people had received investor visas under the scheme, while Dolfin-linked businesses and immigration agents earned at least £35.5 million in fees.

In essence, the scheme was able to bypass authorities due to several factors:

  • The Illusion of Compliance: The arrangement was deliberately designed to create the impression that customers had met the $2 million investment requirement via false paper trails.
  • Concealed Networks: The visibility of millions of transactions was obscured across multiple fragmented layers through third-party channels, including immigration agents.
  • Acting as an Authorized Firm: Because Dolfin Financial (UK) Ltd operated as a regulated wealth management firm, it avoided heightened regulatory scrutiny.

Reports indicated that Mr Nagy and Mr Joukovski played leading roles in creating and operating the scheme. At the same time, Mr Maraj was responsible for the financial aspects of the illicit scheme.

The FCA also found that Mr Joukovski deliberately hid his involvement and role within the scheme. However, investigations are still ongoing, as Mr Joukovski referred his Decision Notice to the Upper Tribunal, where his case will be presented.

The Timeline of the Dolfin Scheme, from 2019 to 2026

Scrutiny only caught up when the FCA identified broader red flags regarding Dolfin’s financial crime and Anti-Money Laundering (AML) controls, leading to initial voluntary restrictions in late 2019. Here is the full timeline of the Dolfin Scheme:

  • 2019: The FCA imposed voluntary restrictions on Dolfin after identifying concerns, including around its Tier 1 investor-visa business and financial-crime controls. An independent review of the company was launched under section 166.
  • 2021: The review uncovered material deficiencies in Dolfin’s onboarding and financial-crime controls. The FCA then stopped the firm from carrying out regulated activities. Months after, Dolfin entered Special Administration and became insolvent.
  • 2022: The Home Office officially closed the UK Tier 1 Investor Visa route.
  • 2026: The FCA announced the individual enforcement outcomes.

The Compliance Controls Dolfin Financial Ltd Needed in Place

Traditional Know Your Customer (KYC) processes pose an important first question: Who is this client? However, the Dolfin case underscores a crucial problem for compliance teams, that identity verification alone is not sufficient enough in managing financial crime risk.

This is particularly true in cases involving high-value relationships, such as the UK Tier 1 Investor Visa route. In a compliant framework, Dolfin would need to do more than verify identity. The firm should demonstrate a clear understanding of its clients, including the source of their funds, the purpose of the visa, and the nature of their relationship.

Compliance Lesson 1: Enhanced Due Diligence Is More Than a Box to Check

The Dolfin case shows why high-value transactions require scrutiny beyond the mere presence of supporting documents. Firms must have sufficient controls in place to understand where millions of pounds are allegedly being invested and whether the activity made any sense.

This includes understanding the funds origins, whether the customer truly owns or controls the funds, whether any third parties are involved, and whether the transaction aligns with its stated purpose. This makes abnormal behavior easier to identify later. As such, for higher-risk relationships, Enhanced Due Diligence (EDD), Source of Funds (SoF), and Source of Wealth (SoW) checks are especially critical.

Compliance Lesson 2: Strong Governance is Part of Financial Crime Prevention

The most important lesson from the case relates to governance. Compliance systems are only as good as the people who operate and respect them. A strong compliance infrastructure cannot compensate for a culture whereby senior decision-makers can ignore critical controls without being questioned.

Strong governance should therefore enforce clear escalation processes. This includes documented decision-making, appropriate segregation of duties, and an audit trail capable of showing not simply what decision was made, but who made it and why.

Compliance Lesson 3: Continuous Customer Risk Assessment as a Non-negotiable

A customer can have a legitimate passport, pass biometric verification, and successfully clear sanctions or Politically Exposed Person (PEP) screening, yet still carry significant risks. That is why KYC today increasingly needs to be an ongoing risk assessment rather than a one-off check.

Identity verification needs to operate alongside customer due diligence, Source of Funds checks, and ongoing monitoring. Ultimately, effective compliance is not just about confirming the customer’s identity. It is about understanding where their money comes from, why they are transacting, and whether their behavior continues to make sense over time.

Fortify your fraud prevention and identity verification solutions with complycube | complycube

Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally. 

Table of Contents

More posts

Dark blue verification card showing a man with glasses orange badge reads no fraud detected and green badge says check complete for an article on closing the aml gap in risk based monitoring  | complycube

Closing the AML Gap in Risk-Based Monitoring

Risk-based AML frameworks can become difficult to execute, especially across different spreadsheets and workflows. Discover how custom risk engines can transform documented methodologies into consistent, auditable risk decisions....
Two gig workers connected to one platform account illustrating the identity challenge behind gig economy right to work compliance | complycube

Changes In Right to Work Digital Identity Checks for Gig Platforms

With October 2026 right to work reforms, gig platforms face new responsibilities. Learn how identity, access, substitutes, and proportionate re-verification can help reduce huge compliance gaps to protect against illegal working....
Logo of india flag with bitcoin icon on the bottom right and exclaimation icon on bottom left | complycube

India Blocks 15 Crypto Exchanges for AML Violations

15 crypto exchanges are under India's FIU scrutiny as the country aims to step up AML enforcement. The case shows what offshore crypto firms risk if they serve customers in India without meeting local AML and CDD compliance rules....