<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "JATS-journalpublishing1.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="other" dtd-version="1.1" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">J_Bus_Account_Financ_Perspect</journal-id>
      <journal-title-group>
        <journal-title>Journal of Business Accounting and Finance Perspectives</journal-title>
        <abbrev-journal-title abbrev-type="publisher">J_Bus_Account_Financ_Perspect</abbrev-journal-title>
        <abbrev-journal-title abbrev-type="pubmed">Journal of Business Accounting and Finance Perspectives</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="epub">2603-7475</issn>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.35995/jbafp2030017</article-id>
      <article-id pub-id-type="publisher-id">J_Bus_Account_Financ_Perspect-2-17</article-id>
      <article-categories>
        <subj-group>
          <subject>&#xA0;</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Danske Bank&#x2014;A Smorgasbord of Risks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>McConnell</surname>
            <given-names>Patrick</given-names>
          </name>
        </contrib>
      </contrib-group>
      <aff id="af1-J_Bus_Account_Financ_Perspect-2-17">Affiliation Recently Macquarie University, Sydney, Australia; <email>pjmcconnell@gmail.com</email></aff>
      <pub-date pub-type="epub">
        <day>09</day>
        <month>06</month>
        <year>2020</year>
      </pub-date>
      <volume>2</volume>
      <issue>3</issue>
      <elocation-id>17</elocation-id>
      <history>
        <date date-type="received">
          <day>20</day>
          <month>02</month>
          <year>2020</year>
        </date>
        <date date-type="accepted">
          <day>30</day>
          <month>04</month>
          <year>2020</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>&#xA9; 2020 Copyright by the authors.</copyright-statement>
        <copyright-year>2020</copyright-year>
        <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
          <license-p>Licensed as an open access article using a CC BY 4.0 license.</license-p>
        </license>
      </permissions>
      <abstract>
        <p>In September 2018, Danske Bank, the largest bank in Denmark and one of the largest in the Nordic region, published a report which detailed that the bank&#x2019;s board had fallen into lapses in Anti-Money Laundering/Counter Terrorism Financing (AML/CTF) policies at the bank, in particular, within its Estonian subsidiary. The report was devastating in its criticism of AML processes in the Estonian branch, stating that, over a period of several years, &#x201C;all lines of defence failed&#x201D; to manage money laundering risks. Soon after the publication of this report, the CEO of Danske resigned, causing the details of the underlying scandal to become public knowledge (although some the issues involved had been aired publicly on a number of occasions previously). It was also revealed that the bank had become the subject of criminal investigations by US authorities. While the events that are covered in the initial report related to failures to manage AML risks, the situation is more complex than merely deficient AML controls in a remote branch. There was a failure to manage a smorgasbord of different types of risks at both the local and group (i.e., headquarters) level, including: strategic risks; technology risks; and especially operational risks. As befits a sophisticated modern financial institution, Danske Bank operates a group-wide enterprise risk management (ERM) framework covering multiple types of risk (credit, market operational, etc.). The fact that the failure to manage the AML risks took several years to come to light casts doubts on the efficacy of their ERM framework and its implementation. Using Turner&#x2019;s case study approach, this paper considers the Danske Bank case from the perspective of operational risk management with a view to identifying lessons that can be learned from the scandal that can be applied to future, large-scale operational risk events.</p>
      </abstract>
      <kwd-group>
        <kwd>strategic technology risk</kwd>
        <kwd>Danske Bank</kwd>
        <kwd>Russian Laundromat</kwd>
        <kwd>operational risk management</kwd>
        <kwd>Turner&#x2019;s Six Stages Model</kwd>
      </kwd-group>
	   <custom-meta-group>
        <custom-meta>
          <meta-name>How to cite</meta-name>
          <meta-value>Patrick McConnell. Danske Bank&#x2014;A Smorgasbord of Risks. <italic>J. Bus. Account. Financ. Perspect.</italic>, 2020, 2(3): 17; doi:<ext-link ext-link-type="uri" xlink:href="https://doi.org/10.35995/jbafp2030017">10.35995/jbafp2030017</ext-link>.</meta-value>
        </custom-meta>
      </custom-meta-group>
    </article-meta>
  </front>
  <body>
   <p><bold>Foreword to Danske Bank Annual Report 2018 (<xref rid="B7-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2018</xref>)</bold></p>
      <disp-quote>
        <p>&#x201C;Danske Bank is one of the largest financial services providers in Denmark and one of the largest financial institutions in the Nordics. As such, <bold>we have a particular responsibility and an obligation to positively impact the Nordic economies and societies by creating long-term value for all our stakeholders.</bold></p>
      </disp-quote>
      <disp-quote>
        <p><bold>Through our shortcomings and failures in Estonia, including our late and inadequate handling of the issues, we have failed to live up to this responsibility.</bold> Not only have we disappointed our customers and our employees but also our shareholders and society at large.</p>
      </disp-quote>
      <disp-quote>
        <p><bold>This has changed the way the world sees us and has shaken the trust our stakeholders have in us.</bold> Many people are asking themselves if we can be trusted to act responsibly, ethically and lawfully. </p>
      </disp-quote>
      <disp-quote>
        <p>No issue can be of greater importance than restoring the trust we have lost. [Emphasis added]&#x201D;</p>
      </disp-quote>
    <sec id="sec1-J_Bus_Account_Financ_Perspect-2-17" sec-type="intro">
      <title>1. Introduction</title>
      <p>Danske Bank, the largest bank in Denmark and one of the largest in the Nordic region, is the very model of a successful, modern universal banking corporation, with a solid record of profitability in its chosen markets in Northern Europe. Given its history of prudent, staid banking, it came as a surprise to investors and customers that the bank had been involved in a massive money-laundering scandal. </p>
      <p>In September 2018, the Danske board released a report of an inquiry, by an independent legal firm, into the &#x2018;Non-Resident Portfolio at Danske Bank&#x2019;s Estonian branch&#x2019; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>). This report concluded that, for a period between 2007 and 2015, some 7.5 million payment transactions involving around 10,000 &#x2018;non-resident&#x2019; customers that had been handled through the bank&#x2019;s Estonian branch, located in Tallinn, should have been deemed &#x2018;suspicious&#x2019;, according to the bank&#x2019;s Anti-Money Laundering (AML) procedures. The report estimated that these transactions involved some EUR 200 billion in value.</p>
      <p>On receiving such an adverse report, the board estimated the bank&#x2019;s gross income from these suspicious pavements totalled some DKK 1.5 (EUR 0.2) billion and this was to &#x201C;be donated to an independent foundation supporting initiatives to combat international financial crime&#x201D; (<xref rid="B11-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018b</xref>). This &#x2018;donation&#x2019; was a substantial hit to the bank&#x2019;s annual profit when combined with an order from the Danish Financial Services Authority (DFSA) to increase capital with a DKK 10 billion Pillar II add-on (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2018</xref>).</p>
      <p>Before describing the Danske case in detail, the &#x201C;six stages&#x201D; of Turner&#x2019;s Framework for analysing &#x201C;organisational disasters&#x201D; (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner, 1976</xref>) are described. This is believed to be the first paper that addresses the Danske scandal using Turner&#x2019;s case study approach. One of the key insights provided by <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) is that large organisational disasters, and consequential financial and non-financial losses, emerge, or are &#x201C;incubated&#x201D;, over a long period of time, and it is difficult for those closest to the action to see the disaster emerging.</p>
      <p>The paper then describes the background to the case and, using Turner&#x2019;s Framework, describes the sequence of major events that took place over more than a decade that led to the exposure of the AML scandal. </p>
      <p>The paper concludes by identifying some lessons that can be learned from the Danske scandal, specifically the role of risk management functions in assisting business managers to identify and mitigate the myriad of issues that give rise to such events.</p>
      <p>Before describing the events, however, Turner&#x2019;s Framework for analysing organisational &#x2018;disasters&#x2019; is briefly described.</p>
    </sec>
    <sec id="sec2-J_Bus_Account_Financ_Perspect-2-17">
      <title>2. Turner&#x2019;s Framework</title>
      <p>In an often-cited work in decision literature, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) examined the official reports of a number of &#x2018;disasters&#x2019; from an organisational perspective. Some of the disasters analysed by Turner resulted in considerable loss of life and so cannot be compared to the failures of management that occurred at Danske Bank. However, Turner considered that discussion of such disasters offers &#x201C;a paradigm for discussion of less tragic but equally important organisational and inter-organisational failures of foresight&#x201D;, such as significant financial losses in major public companies.</p>
      <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) identified a number of &#x201C;stages&#x201D; in the &#x201C;development of a disaster&#x201D; and &#x201C;features&#x201D; that appear to be common to them, which are summarised in <xref ref-type="table" rid="J_Bus_Account_Financ_Perspect-2-17-t001">Table 1</xref>.</p>
      <p>In his framework, Turner concentrates on the stages of &#x201C;initial beliefs&#x201D; and &#x201C;incubation period&#x201D; because he argued that it was before the &#x201C;onset&#x201D; of disasters that the most significant organisational failures tended to occur. In an observation that is important for banking regulators and management, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) pointed out that:
      <disp-quote>
        <p>&#x201C;<bold>Disasters, other than those arising from natural forces, are not created overnight</bold>. It is rare that an individual, by virtue of a single error, can create a disastrous outcome in an area believed to be relatively secure. <bold>To achieve such a transformation he or she needs the unwitting assistance offered by access to the resources.... of large organisations, and time</bold> [Emphasis added]&#x201D;.</p>
      </disp-quote></p>
      <p>It should be noted that, whereas organisational disasters may appear suddenly and unexpectedly, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) found that often, they were &#x201C;incubated&#x201D; over a long period of time, during which the unacceptable gradually became acceptable. <xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Fitzsimmons and Atkins</xref> (<xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2017</xref>) found that &#x201C;most major accidents incubate for more than three years, with <bold>more than 25 per cent taking longer than eight years to emerge</bold> [Emphasis added]&#x201D;. </p>
      <p>In an important observation, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) noted that &#x201C;large organisations&#x201D; can create large disasters as the &#x201C;failure to comply with existing regulations&#x201D; becomes commonplace across the organisation, over a long period. Because of &#x201C;information difficulties and noise&#x201D; in very large organisations, critical information gets diluted and ignored as it moves through various organisational levels.</p>
      <p>It should be noted that the events described here took over a decade to fully emerge, but along the way, there were, as documented in <xref ref-type="app" rid="app1-J_Bus_Account_Financ_Perspect-2-17">Appendix A</xref>, many &#x2018;red flags&#x2019; that should have been apparent <italic>if managers had been watching carefully enough</italic>.</p>
      <p>As shown in <xref ref-type="table" rid="J_Bus_Account_Financ_Perspect-2-17-t001">Table 1</xref>, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) identified several &#x2018;features&#x2019; that he found were common to disasters, from organisational rigidity to individuals&#x2019; failure to appreciate danger. He argued that disasters tend to occur not as a result of some sudden event, but as a consequence of an accumulation of organisational and individual faults that cause a problem, which could have been contained, to grow into a catastrophe. Turner argues that &#x201C;small scale disasters can be produced rapidly, but <bold>large-scale disasters can only be produced if time and resources are devoted to them</bold> [Emphasis added]&#x201D;. </p>
      <p>During the prolonged incubation period of any large disaster, Turner points out that there is a steady accumulation of events that are at odds with the norms of the organisation(s) but which go unnoticed because their importance is not fully appreciated. It is the gradual acceptance of such events that blinds management and regulators to potential problems. </p>
      <p>An important aspect of Turner&#x2019;s methodology is the focus on gathering information from official sources, typically independent inquiries and annual reports. Such reports will have some degree of objectivity and, in particular, will not be reliant on the subjective recollections of managers and staff under pressure at the time that the event surfaces. This means, for example, that newspaper articles published as the scandal emerges are not good sources of information, although they do provide some colour for the narrative.</p>
      <p>Turner&#x2019;s framework has been used to investigate cases of operational risk events, such as ANZ Bank (<xref rid="B25-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2010</xref>) and JPMorgan (<xref rid="B27-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2014</xref>), and <xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Fitzsimmons and Atkins</xref> (<xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2017</xref>) used Turner&#x2019;s approach to analyse several cases of organisational disasters in large corporations that caused considerable &#x201C;reputational damage&#x201D;. </p>
    </sec>
    <sec id="sec3-J_Bus_Account_Financ_Perspect-2-17">
      <title>3. Background to the Scandal</title>
      <sec id="sec3dot1-J_Bus_Account_Financ_Perspect-2-17">
        <title>3.1. Danske Bank</title>
        <p>Danske Bank is the largest bank in Denmark and one of the largest in the Nordic region, with a presence in 15 countries, mostly in Northern Europe. In 2018, the bank serviced some three million customers, mostly personal, i.e., retail, but also business customers (<xref rid="B7-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2018</xref>). Danske Bank is regulated by the Danish Financial Supervisory Authority (DFSA) and considered to be one of six systemically important financial institutions in Denmark, and hence &#x201C;deemed essential to the financial system&#x201D;.</p>
        <p>In 2017, Danske Bank posted gross income of some DKK 76 billion (Net Income DKK 48 billion (approx. Eur 6.3 billion)). Over 93% of gross income was generated in the Nordic countries (Denmark, Sweden, Finland and Norway). Another 4% of gross income was generated in the UK (Northern Ireland), where Danske had previously acquired the Northern Bank and the National Irish Bank (which has Danske-branded branches in Ireland). Of particular note here is that Baltic branches (i.e., Estonia, Latvia and Lithuania) contributed only 0.5% of gross income (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>). </p>
        <p>As with many large international banks, the Danske Board organised its risk functions in the so-called &#x2018;Three Lines of Defence&#x2019; model (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The first line of defence is the business itself, which must ensure correct, legal and expedient operations. The second line of defence is a risk management function that is to identify and mitigate risks and a compliance function that is to check compliance with rules. Finally, the third line of defence is the internal audit department, which monitors whether the first and second lines of defence identify the problems. Management [and the Board] receives reporting from the three lines of defence on an ongoing basis.&#x201D;</p>
        </disp-quote></p>
        <p>Given the prevalence of this &#x2018;lines of defence&#x2019; model in modern banking, it is disconcerting to find that &#x201C;all lines of defence failed&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>).</p>
      </sec>
      <sec id="sec3dot2-J_Bus_Account_Financ_Perspect-2-17">
        <title>3.2. Estonian Branch and the Non-Resident Portfolio</title>
        <p>In November 2006, Danske Bank announced its acquisition of Finnish-based Sampo Pank and completed the acquisition in February 2007 (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>). Later, in 2008, Sampo Pank in Estonia was formally turned into a branch of Danske Bank.</p>
        <p>During the 1990s, there had been &#x201C;strong economic ties between the Baltic countries and Russia&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>), and as a result, the Estonian branch had built up a sizeable portfolio of customers who resided outside Estonia, the so-called &#x2018;Non-Resident Portfolio&#x2019;. This portfolio, which over time numbered roughly some 10,000 firms and individuals, was dominated by customers from &#x201C;the Russian Federation and the larger Commonwealth of Independent States (&#x201C;CIS&#x201D;), including countries such as Azerbaijan and Ukraine&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>).</p>
        <p>Organisationally, the Non-Resident Portfolio, consisting of some 3000 to 4000 customers at any one time, was managed by a separate unit, called the International Banking Division (IBD). Until the end of 2015, when it was closed and the Non-Resident Portfolio terminated, this division held a significant share of this overseas business in the local banking system (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;By the end of 2013, the Non-Resident Portfolio within Danske Bank&#x2019;s Estonian branch held 44 per cent of the total deposits from non-resident customers in Estonian banks (up from 27 per cent in 2007) and nine per cent of the total deposits from non-resident customers in Baltic banks (up from five per cent in 2007)&#x201D;</p>
        </disp-quote></p>
        <p>The International Banking Division was profitable (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The [Estonian] branch had high earnings on Russian and other non-Baltic customers (non-resident customers), whose total volume of payments through the branch was very considerable. For example, 35% of the profit in the branch in 2012 was generated by Russian customers, who made up 8% of the customer base. &#x2026;</p>
        </disp-quote>
        <disp-quote>
          <p>Over the nine years from 2007 through 2015, the flow [of payments] converted into EUR for both the approximately 10,000 customers in the Non-Resident Portfolio and the 15,000 customers subject to investigation was approximately EUR 200 billion.&#x201D;</p>
        </disp-quote></p>
        <p>Up until June 2013, employees at the bank had considered initiating similar businesses with non-resident customers in the branch in Lithuania, but the Executive Board rejected these plans.</p>
        <p>At this point, it is important to note that payment income dominated IBD profitability (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;<bold>As regards the Non-Resident Portfolio, the branch took no credit risks of any significance. For the same reason, little capital was allocated to the Non-Resident Portfolio</bold> [Original Emphasis]&#x201D;</p>
        </disp-quote></p>
        <p>This meant that, <italic>provided operational risks were being managed</italic>, the Non-Resident Portfolio was an almost perfect banking business, with little or no credit risk, and significant fee income, especially from Foreign Exchange (FX) and Payments transactions. As there is &#x2018;no such thing as a free lunch&#x2019;, such excessive profits <italic>should</italic> have raised red flags for business, risk and audit managers but appeared not to have done so.</p>
        <p>The problem with this financial &#x2018;golden goose&#x2019; (<xref rid="B26-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2013</xref>) was that operational risks, in particular money laundering risks, were not being managed properly, and there was a disaster waiting to happen.</p>
      </sec>
      <sec id="sec3dot3-J_Bus_Account_Financ_Perspect-2-17">
        <title>3.3. The Russian Laundromat</title>
        <p>Before considering the Danske case in detail, it is worth describing the business environment in which misconduct first emerged and then thrived. The term &#x2018;Russian Laundromat&#x2019; has passed into popular folklore to describe various schemes used by rich people to launder money from Russia and other ex-Soviet republics (especially, in this context, Azerbaijan and Moldova) to the UK and other western countries, often via tax havens.</p>
        <p>In 2014, the Organized Crime and Corruption Reporting Project (OCCRP), a non-profit media organisation providing an &#x201C;investigative reporting platform&#x201D;, produced a report titled the &#x201C;Russian Laundromat&#x201D; (<xref rid="B33-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2014</xref>) which claimed:
        <disp-quote>
          <p>&#x201C;Between 2010 and early 2014, organized criminals and corrupt politicians in Russia moved US$ 20 billion in dirty funds through this laundromat&#x2019;s complex cleanse-and-spin cycle made up of dozens of offshore companies, banks, fake loans, and proxy agents. The process was then certified as clean by judges in the tiny Republic of Moldova. The newly cleaned funds were then spread across Europe.&#x201D;</p>
        </disp-quote></p>
        <p>In 2017, the OCCRP followed up on this initial report with another which gave details of how the &#x2018;Laundromat&#x2019; worked and the people and businesses involved (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2017</xref>):
        <disp-quote>
          <p>&#x201C;Money entered the Laundromat via a set of shell companies in Russia that exist only on paper and whose ownership cannot be traced. Some of the funds may have been diverted from the Russian treasury through fraud, rigging of state contracts, or customs and tax evasion. &#x2026; At the other end of the Laundromat, money flowed out for luxuries, for rock bands touring Russia, and on a small Polish non-governmental organization that pushed Russia&#x2019;s agenda in the European Union.&#x201D;</p>
        </disp-quote></p>
        <p>The Laundromat scheme was &#x201C;ingenious&#x201D; (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2017</xref>):
        <disp-quote>
          <p>&#x201C;Organizers created a core of 21 companies based in the United Kingdom (UK), Cyprus and New Zealand and run by hidden owners. A number of Russian companies then used these companies to move their money out of Russia. &#x2026; All of the core-group companies appeared to be owned by proxies standing in for hidden owners. Even directors and shareholders of the companies were fake&#x201D;.</p>
        </disp-quote></p>
        <p>And the criminals often used &#x2018;fake debt&#x2019; to allow money to be moved from Russia (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2017</xref>):
        <disp-quote>
          <p>&#x201C;To get the money out, the scheme&#x2019;s organizers devised a clever misdirection. They created a fake debt among some of these core shell companies and then got a Moldovan judge to order the Russian company seeking to launder funds to pay that [fake] debt to a court-controlled account&#x201D;.</p>
        </disp-quote></p>
        <p>Having &#x2018;cleaned&#x2019; the money through Moldova, it was a small step to release the money into the international financial system, through respected international banks, such as Danske Bank (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2017</xref>):
        <disp-quote>
          <p>&#x201C;Between 2011 and 2014, the 21 shell companies fired out 26,746 payments from their various [Moldovan bank] accounts. The payments went to 96 countries, <bold>passing almost without obstacle</bold> into some of the world&#x2019;s biggest banks. &#x2026; Finally, <bold>payments of laundered money slid easily</bold> into the world&#x2019;s biggest international banks. [Emphasis added]&#x201D;</p>
        </disp-quote></p>
        <p>The <xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP</xref> (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2017</xref>) report showed for the first time that Danske Bank was one of the leading conduits for the flow of illicit funds&#x2014;but other banks were also involved, including other Nordic banks:
        <disp-quote>
          <p>&#x201C;The Laundromat illustrates that the world&#x2019;s banking system has been impotent, unable to stanch massive flows of illicit money.&#x201D;</p>
        </disp-quote></p>
        <p>After Danske Bank had been forced to launch its own investigation in 2017, the <xref rid="B35-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP</xref> (<xref rid="B35-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018</xref>) reported on the flow of illicit funds through the Estonian branch.</p>
        <disp-quote>
          <p>&#x201C;While Danske began its own investigation last September, its senior management is currently facing outrage from Danish politicians as to why the bank did not act more quickly in addressing long-standing concerns over the operations of its Estonian branch.&#x201D;</p>
        </disp-quote>
      </sec>
      <sec id="sec3dot4-J_Bus_Account_Financ_Perspect-2-17">
        <title>3.4. AML Regulations</title>
        <p>Both Danish and Estonian banking industries are covered by European Union (EU) law, in this case (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;EU Directive 2005/60 (&#x201C;Third AML Directive&#x201D;) was implemented into Estonian law on 28 January 2008 in the form of the Money Laundering and Terrorist Financing Prevention Act (&#x201C;MLTFPA&#x201D;)&#x201D;</p>
        </disp-quote></p>
        <p>Under this comprehensive directive, financial institutions in the EU are required to (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):<list list-type="order">
          <list-item>
            <label>(1)</label>
            <p>Perform &#x201C;customer due diligence&#x201D; or &#x2018;Know Your Customer; when establishing a business relationship with a customer, including &#x201C;<bold>an obligation to establish the customer&#x2019;s identity</bold> (and, where applicable, the beneficial owner) and to obtain information on the purpose and intended nature of the business relationship&#x201D;;</p>
          </list-item>
          <list-item>
            <label>(2)</label>
            <p>Conduct ongoing monitoring of the <bold>business relationship with every customer, including scrutiny of transactions</bold>, &#x201C;to ensure that the transactions conducted were consistent with the institution&#x2019;s knowledge of the customer, the customer&#x2019;s business and risk profile, including, where necessary, the source of funds&#x201D;; and</p>
          </list-item>
          <list-item><label>(3)</label>
            <p>Monitor transactions and if there are &#x201C;reasonable grounds to suspect a customer of engaging in money laundering (or terrorist financing), <bold>this had to be reported to the Financial Intelligence Unit</bold> (&#x201C;FIU&#x201D;), that is a public law enforcement agency &#x2026; in the form of a suspicious activity report (SAR) [Emphasis added]&#x201D;</p>
          </list-item>
        </list></p>
        <p>Obviously, to fully comply with the EU AML Directive, a financial institution would have to create and properly staff the organisations needed to perform and monitor <italic>all</italic> transactions for potential AML activity and to train their staff in doing so. In addition, a financial institution would have to develop the IT systems necessary to identify (and track) potential Suspicious Activity Reports (SARs). This is a non-trivial undertaking for any financial institution, especially an international bank.</p>
        <p>While the Estonian branch did make a large number of SARs to the FIU (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>), the information was neither comprehensive nor complete, as described in the following sections. </p>
      </sec>
    </sec>
    <sec id="sec4-J_Bus_Account_Financ_Perspect-2-17">
      <title>4. The Danske Money Laundering Scandal </title>
      <sec id="sec4dot1-J_Bus_Account_Financ_Perspect-2-17">
        <title>4.1. Before the Event </title>
        <p><xref ref-type="fig" rid="J_Bus_Account_Financ_Perspect-2-17-f001">Figure 1</xref> (here called the Danske Laundromat) summarises the flow of money through Danske Bank that had given rise to the scandal (from top right to bottom left).</p>
        <p>As noted above, after the acquisition of Sampo Pank, the Sampo branch in Tallinn, Estonia, serviced a large number of &#x2018;Non-Resident&#x2019; customers residing in ex-Soviet Union countries including Russia, Azerbaijan and Moldova. Periodically, those customers would transmit money to their accounts in the Danske Estonian branch and then send instructions to make transfers to individuals and businesses overseas (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>).</p>
        <p>Typically, the transfer instructions from Non-Residents would be merged with instructions from Estonian customers and passed onto the Danske Bank headquarters in Copenhagen. Here, the transfers would be merged with additional instructions from Danish and other European customers and passed onto partner, so-called &#x2018;correspondent&#x2019;, banks (<xref rid="B21-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McAndrews, 2010</xref>) for delivery to the bank accounts of the final recipients, often businesses registered in London, Paris or New York. </p>
        <p>However, what if the businesses were not real but in fact merely &#x2018;front&#x2019; companies created to pay and/or receive money, i.e., to money launder?</p>
        <p>In some cases, when the money was paid by a fake &#x2018;front company&#x2019; in, say, London, that business would pass the payment (minus a significant fee) along to accounts in tax havens, such as Cyprus or the British Virgin Islands, where, suitably cleansed, the funds would disappear into the global financial system&#x2014;and with automation through the SWIFT network, the full set of transfers through the different &#x2018;hops&#x2019; could be executed &#x2018;end-to-end&#x2019; in hours, even minutes.</p>
        <p>It should be noted that almost all of the payments made through these different &#x2018;hops&#x2019; would be totally automated, especially if a Non-Resident customer (even if located outside of the ex-Soviet Union) had used an Internet-banking connection to Danske Bank. This means that staff would have little or no opportunity to catch an invalid transmission as it flows through the system, unless there is an automated AML system for reviewing all transfers and diverting those that look &#x2018;suspicious&#x2019; for further investigation. In addition, good AML practice would also investigate all transfers on a daily, weekly and monthly basis looking for suspicious transactions, patterns and trends. Of course, this can only be done using appropriate computer software that is developed, tested, operated and monitored for compliance according to company policies and regulatory rules.</p>
        <p>At this point, it should be recognised that collecting information about the sources and uses of illicit funds is very difficult, as banks, such as Danske, only see part of the overall picture and hence are often unable to verify key information, such as the ultimate owner of a company in a different jurisdiction. </p>
        <p>Many international transfers will originate from business customers on a regular basis. For example, an automobile dealer in Russia or Moldova will pay for shipments of vehicles on a regular basis, often using a third-party broker in the West. Thus, assuming that the automobile dealer and third-party broker are bona fide businesses, there would be little need to flag any transfer as suspicious. It would be extremely difficult, for example, to detect if one or more of such payments were suspicious.</p>
        <p>However, detailed investigation is <italic>not</italic> what banks are required to do. Under AML legislation, they are required to file a Suspicious Activity Report (SAR) with the appropriate financial intelligence agency&#x2014;in this case, the Estonian Financial Intelligence Unit (EFIU).</p>
        <p>The failure to comprehensively identify suspicious behaviour was highlighted in the analysis of the Non-Resident Portfolio (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The SARs filed on the approximately 10,000 customers in the Non-Resident Portfolio <bold>accounted for</bold> approximately <bold>13 per cent</bold> of the total number of SARs filed in the period. [but &#x2026;] the Non-Resident Portfolio accounted for <bold>approximately 30 per cent of the total number of FIU inquiries received by the branch</bold> in the period from 2007 through 2015. <bold>Only few of the customers examined have been deemed not suspicious, that is without suspicious characteristics and not having been involved in payments deemed suspicious</bold>. [Emphasis added]&#x201D;</p>
        </disp-quote></p>
        <p>In short, almost all activity in the Non-Resident Portfolio, inherited from Sampo Pank and expanded by Danske Bank, should have been considered &#x2018;suspicious&#x2019; <italic>but was not</italic>.</p>
      </sec>
      <sec id="sec4dot2-J_Bus_Account_Financ_Perspect-2-17">
        <title>4.2 The Precipitating Event</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) identifies two distinct stages that bring a disaster to the public&#x2019;s attention: the &#x201C;precipitating event&#x201D;, which grabs the attention of the public; and the &#x201C;onset&#x201D;, or immediate consequences of the event. </p>
        <p>In September 2018, the Board of Danske released a report of an inquiry into the &#x2018;Non-Resident Portfolio at Danske Bank&#x2019;s Estonian branch&#x2019;, undertaken by an independent legal firm, Bruun &amp; Hjejle (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>). The Board had initiated this inquiry after public and regulatory pressure following publication of details of the Russian Laundromat (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2017</xref>).</p>
        <p>In a conference call to publish the report, Chairman of the Board of Directors Ole Andersen highlighted the severity of the inquiry&#x2019;s findings (<xref rid="B12-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018c</xref>):
        <disp-quote>
          <p>&#x201C;Finally, our investigation shows that the bank has failed to live up to its obligations and responsibility. We, of course, take this very seriously and we regret these events deeply. They do not reflect the kind of bank that we want to be and we&#x2019;ll do everything we can to learn from these events going forward, so that something like this can never happen again&#x201D;.</p>
        </disp-quote></p>
        <p>The remainder of this paper summarises the findings of this and other official reports concerning this scandal.</p>
      </sec>
      <sec id="sec4dot3-J_Bus_Account_Financ_Perspect-2-17">
        <title>4.3. The Onset</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) identifies a short period after the Precipitating Event, the Onset, during which the &#x201C;immediate consequences of the collapse of &#x201C;cultural precautions&#x201D; become apparent&#x201D; and in many ways set the scene for what follows.</p>
        <p>In the Danske case, the initial reaction was for the CEO, Thomas F. Borgen, to resign, and this was followed pretty quickly by a &#x2018;spill&#x2019; of a number of Board positions, including the Chairman and Chair of the Audit Committee. An internal manager, Jacob Aarup-Andersen, who was not directly involved in the scandal, was proposed as the new interim CEO (<xref rid="B13-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018d</xref>).</p>
      </sec>
      <sec id="sec4dot4-J_Bus_Account_Financ_Perspect-2-17">
        <title>4.4. After the Event</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) identifies two final stages that are common in an organisational disaster. In the immediate aftermath, there is the &#x201C;rescue and salvage&#x201D; of anything of value left from the disaster, and finally, there is the &#x201C;cultural adjustment&#x201D;, which attempts to learn lessons from the unhappy events. Again, these stages were apparent in the Danske case.</p>
      </sec>
      <sec id="sec4dot5-J_Bus_Account_Financ_Perspect-2-17">
        <title>4.5. Rescue and Salvage</title>
        <p>Shortly after the new interim CEO was installed, Danske announced the bank&#x2019;s financial results for the first nine months of 2018, which showed a slight fall in operating income compared to the same period in 2017, but in addition, the Board announced that income was down (<xref rid="B11-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018b</xref>):
        <disp-quote>
          <p>&#x201C;as a result of our decision to donate DKK 1.5 billion, corresponding to the gross income from the Estonian non-resident portfolio, to initiatives aimed at combating financial crime.&#x201D;</p>
        </disp-quote></p>
        <p>Interestingly, the Board had attempted to wipe the slate clean by taking a substantial hit to its profits, counteracting any charges that the bank had profited from its mistakes.</p>
        <p>However, the bank announced that it had become the subject of criminal investigations by US authorities, which lays the ground for further possibly large regulatory fines in the future (<xref rid="B28-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2015</xref>).</p>
        <p>In considering the case, the bank&#x2019;s main regulator, the Danish Financial Services Authority, considered action under Danish law against staff and management but demurred (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2018</xref>).</p>
        <p>&#x201C;The Danish FSA has assessed whether there are grounds for bringing actions under the fit and proper rules against the bank&#x2019;s current members of management and staff. On the available basis, the Danish FSA does not consider that there are sufficient grounds for bringing such actions.&#x201D;</p>
        <p>However, the DFSA noted that (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
        <disp-quote>
          <p>&#x201C;In Danske Bank&#x2019;s Estonian branch, there have been significant violations of the European and Estonian money laundering rules. In December 2018, ten former employees in the branch were arrested in Estonia. By all accounts, for a number of years employees in the Estonian branch actively carried out and covered up the violations both to the bank&#x2019;s senior management in Copenhagen and to the Estonian Financial Supervisory Authority (EFSA).&#x201D;</p>
        </disp-quote></p>
        <p>At the time of writing, in late 2019, there are several legal investigations taking place in a number of jurisdictions, and doubtless, further actions will be taken by regulators and other authorities in the future. </p>
      </sec>
      <sec id="sec4dot6-J_Bus_Account_Financ_Perspect-2-17">
        <title>4.6. Cultural Adjustment</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) points out that after the dust settles, it is possible to carry out a &#x201C;more leisurely and less superficial assessment&#x201D; of the events leading up to a disaster, with the goal of learning lessons from it and ultimately closing the circle by adjusting the erroneous beliefs and norms that lead to the failure. </p>
        <p>In the Danske case, this included making significant improvements to its operational risk management (ORM) processes, in particular working on AML (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>).
        <disp-quote>
          <p>&#x201C;The bank has stated that it has increased the number of employees working with AML in the first and second lines of defence from less than 200 to 550 last year and nearly 900 today. Among other things, the bank has also expanded and updated internal AML training, worked to strengthen the compliance culture and made considerable investments in IT in the area.&#x201D;</p>
        </disp-quote></p>
      </sec>
    </sec>
    <sec id="sec5-J_Bus_Account_Financ_Perspect-2-17">
      <title>5. Before the Event</title>
      <sec id="sec5dot1-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.1. The Incubation Period</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) considered the &#x201C;incubation period&#x201D; to be of utmost importance when analysing corporate disasters, as it is actions prior to the &#x201C;onset of the event&#x201D; that ultimately determine the &#x201C;scale&#x201D; of the organisational disaster. During the incubation period, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) points out that there is a steady accumulation of events that are at odds with the norms of the organisation but go unnoticed because their importance is not fully appreciated. Turner identifies the &#x201C;incubation period&#x201D; as the stage where the &#x201C;failures of foresight&#x201D; that lead to the eventual disaster occur and he describes a number of key features, summarised in <xref ref-type="table" rid="J_Bus_Account_Financ_Perspect-2-17-t001">Table 1</xref> above, which are common to the disasters that he studied. </p>
        <p>Describing Turner&#x2019;s approach, <xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Fitzsimmons and Atkins</xref> (<xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2017</xref>) noted that:
        <disp-quote>
          <p>&#x201C;Analysing these long incubations, Turner found steady accumulations of tell-tale events that were not acted upon. Some were overlooked or misunderstood for reasons ranging from wrong assumptions to a failure to understand the complexity of the system. Others were ignored because people refused to accept just how bad the consequences could have been if the mishap had not been a &#x2018;near miss&#x2019;&#x201D;.</p>
        </disp-quote></p>
        <p>The events that led to the Danske scandal coming to the public&#x2019;s attention took place over 12 years during a period of enormous changes in the financial system, most notably the Global Financial Crisis (GFC) of 2007/2008, the impact of which has not completely worked its way out of the global financial system in 2019 (<xref rid="B22-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell and Blacker, 2011</xref>).</p>
        <p>During this prolonged period, there were very many events, actions and inactions by Danske Bank directors, management and staff and also external banking regulators and other financial institutions. <xref ref-type="table" rid="J_Bus_Account_Financ_Perspect-2-17-t002">Table A1</xref> in <xref ref-type="app" rid="app1-J_Bus_Account_Financ_Perspect-2-17">Appendix A</xref> lists a timeline of some of these events and activities, organised by date, which is broken down in the table by seven distinct phases. </p>
        <list list-type="order">
          <list-item>
            <label>(1)</label>
            <p><bold>Strategic Euphoria</bold>: a period of euphoria as the bank&#x2019;s growth strategy in the Baltic countries was implemented (roughly 2006&#x2013;2008);</p>
          </list-item>
          <list-item>
            <label>(2)</label>
            <p><bold>Regulatory Unease</bold>: a period during which banking regulators expressed unease about the implementation of Danske&#x2019;s growth strategy (roughly 2009&#x2013;2013);</p>
          </list-item>
          <list-item>
            <label>(3)</label>
            <p><bold>Management Myopia</bold>: a period during which management appeared to ignore the increasing signs of problems with the growth strategy (roughly 2013&#x2013;2014);</p>
          </list-item>
          <list-item>
            <label>(4)</label>
            <p><bold>Management Tinkering</bold>: a period during which management took steps to ameliorate (some of) the symptoms without really addressing the serious problems emerging (roughly 2014&#x2013;2016);</p>
          </list-item>
          <list-item>
            <label>(5)</label>
            <p><bold>Management Investigations</bold>: a period during which management initiated multiple investigations but did not directly address the problems (roughly 2016&#x2013;2017);</p>
          </list-item>
          <list-item>
            <label>(6)</label>
            <p><bold>Scandal Emerges</bold>: a period during which the full import of the scandal emerged and corrective actions began to be taken (roughly 2017&#x2013;2018); and</p>
          </list-item>
          <list-item>
            <label>(7)</label>
            <p><bold>Aftermath</bold>: a period during which the firm and its regulators began to take actions to attempt to correct the problems that arose during the scandal, also called &#x201C;Cultural Adjustment&#x201D; by <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>).</p>
          </list-item>
        </list>
        <p>The remainder of this section considers some of the more important events that went unnoticed or were given insufficient attention by management. However, at this point, it should be noted that the events described here were selected, from a vast amount of information, by the author as being important. It is not infeasible that another researcher might select different, even contradictory, events when analysing the events from another perspective. </p>
      </sec>
      <sec id="sec5dot2-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.2. Initial Beliefs and Norms</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) argues that a disaster or &#x201C;cultural collapse&#x201D; takes place because of &#x201C;some inaccuracy or inadequacy in the accepted norms and beliefs&#x201D; of a firm or, here, a group of semi-independent branches. Organisational disasters build up gradually over time, and the signs should be apparent to management and regulators. Instead, the warning signs go unnoticed or ignored because of &#x201C;cultural rigidity&#x201D; which manifests itself in erroneous assumptions and reluctance to face unpalatable outcomes (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner, 1976</xref>). </p>
        <p>In 2006, as it was about to acquire Sampo and its Estonian subsidiary, Danske Bank was very clear in its vision and mission and its strategic positioning (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>).
        <disp-quote>
          <p>&#x201C;Danske Bank Group focuses on conducting conventional banking business in the northern European markets based on state-of-the-art technology. The Group is a leading player in the Nordic markets.&#x201D;</p>
        </disp-quote></p>
        <p>The Board had developed an overall vision of &#x2018;One platform&#x2014;exceptional brands&#x2019; based on shared technology (<xref rid="B4-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2006</xref>):
        <disp-quote>
          <p>&#x201C;We have developed a <bold>solid and scalable platform</bold> to support our core business. The platform consists of systems to manage IT, product development, communications, branding, credits, risk, HR development and finances. <bold>This platform allows all our units across borders to base their work on the same business model.</bold> We continually develop our business model through best practice activities and an active pursuit of new business opportunities. Our ambition is to build and maintain unique brands that respect our core values. [Emphasis added]&#x201D;.</p>
        </disp-quote></p>
        <p>It was very much a vision of a global organisation directed from the centre in the bank&#x2019;s headquarters in Copenhagen, Denmark with:
        <disp-quote>
          <p>&#x201C;Group standards for risk management, financial planning and control, credit approval, HR development, compliance and the shared IT platform ensure a well-structured management of all activities.&#x201D;</p>
        </disp-quote></p>
        <p>While there is nothing intrinsically wrong with such a vision and aspirations, the difficulties of actually implementing common standards across diverse markets and cultures must be recognised. Such a vision is replete with strategic implementation risks (<xref rid="B29-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2016</xref>).</p>
      </sec>
      <sec id="sec5dot3-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.3. Rigidities of Belief</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) points out that all organisations develop a culture that relates the tasks that individuals perform to the goals of the firm and that success stems from the effectiveness of that culture. The other side of this coin, however, is that in attempting to create an all-pervasive culture, managers may well become blind to potential problems outside of the perceived norms. <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) describes how, in the development of a disaster, important events go &#x201C;unnoticed or misunderstood because of erroneous assumptions&#x201D;. </p>
        <p>In the case of Danske Bank, an erroneous assumption was that whenever a policy was agreed at board and headquarter level, it would be implemented throughout the bank organisation as &#x2018;one platform&#x2019;. While such an assumption <italic>may have been</italic> valid when Danske was based mainly in Denmark and was staffed primarily by Danes, it does not necessarily hold as the bank acquired new staff in countries with different cultures, and existing work practices. </p>
        <p>This is not a judgement on non-Nordic countries, but merely that distinct differences in organisational cultures have been observed between countries (<xref rid="B18-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Hofstede, 1991</xref>). Even without delving too deeply into Hofstede&#x2019;s six dimensions of national culture, it should be apparent that approaches to organisational compliance would almost certainly differ between a Western European democracy and a country and people still emerging from Soviet dominance. There is no evidence that Danske considered that different approaches to compliance might be needed, if only in communicating policies, in their recently acquired ex-Soviet subsidiaries. </p>
      </sec>
      <sec id="sec5dot4-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.4. Decoy Phenomena</title>
        <p>In describing the &#x2018;decoy phenomenon&#x2019;, <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) noted that:
        <disp-quote>
          <p>&#x201C;A recurrent feature of the reports analyzed is that in many instances, when some hazard or problem was perceived, action taken to deal with that problem distracted attention from the problems which eventually caused trouble&#x201D;.</p>
        </disp-quote></p>
        <p>In the case of Danske, there was a huge &#x2018;decoy phenomenon&#x2019;, that of the Global Financial crisis (GFC), which occurred just a few years into the acquisition of Sampo Pank and, in particular, it was not surprising, given the problems in the Irish economy at the time (<xref rid="B31-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Nyberg, 2011</xref>), that the bank&#x2019;s board focussed on its Irish and UK investments. In the great scheme of things, the relatively &#x2018;minor&#x2019; operational issues in the Estonian branch would not reach the top of the pile of important problems that needed to be resolved quickly.</p>
      </sec>
      <sec id="sec5dot5-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.5. Disregard of Complaints from Outsiders</title>
        <p>Perhaps one of the most surprising findings in the disasters reported by <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>), <xref rid="B17-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Gleick</xref> (<xref rid="B17-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1992</xref>) and <xref rid="B1-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Augustine</xref> (<xref rid="B1-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1995</xref>) was that often there were clear warnings of potential danger before a disaster occurs. However, warnings from outsiders were routinely dismissed by management with the assumption that the firm knows better than outsiders as to how to run its business. </p>
        <p>The same &#x201C;organizational exclusivity&#x201D;<sup>1</sup> was apparent within Danske Bank, especially in respect of warnings from external parties:<list list-type="order">
          <list-item>
            <label>(1)</label>
            <p>Warnings from financial regulators;</p>
          </list-item>
          <list-item>
            <label>(2)</label>
            <p>The termination of major &#x2018;correspondent&#x2019; banks from their long-standing business relationship with Danske Bank; and</p>
          </list-item>
          <list-item>
            <label>(3)</label>
            <p>The failure to take seriously a &#x2018;whistle-blower complaint&#x2019; from a senior staff member working in the Estonian branch.</p>
          </list-item>
        </list></p>
        <sec id="sec5dot5dot1-J_Bus_Account_Financ_Perspect-2-17">
          <title>5.5.1. Warnings from Financial Regulators</title>
          <p>Given the international emphasis on banking regulation (<xref rid="B2-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Bank for International Settlements, 2004</xref>), it is hard to believe that any major bank would not take their regulators&#x2019; concerns seriously. However, as shown in the timeline in <xref ref-type="app" rid="app1-J_Bus_Account_Financ_Perspect-2-17">Appendix A</xref>, Danske Bank&#x2019;s management appeared to play down concerns from a number of financial regulators over the decade, during which the AML problems were documented, but not properly addressed.</p>
          <p>First, and in hindsight most surprisingly, the bank appears not to have taken seriously warnings from the Russian Central bank in 2007 when Sampo Pank was acquired (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;The Russian central bank warned the Danish FSA about AML risks related to a number of Russian customers in Danske Bank&#x2019;s newly acquired Estonian subsidiary.&#x201D; </p>
          </disp-quote></p>
          <p>This warning was obviously passed onto Danske, where an investigation was undertaken (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;The feedback received from both [heads of Legal and Audit] was that <bold>there were no problems in relation to AML risks in the Estonian subsidiary</bold> [Emphasis added].&#x201D; </p>
          </disp-quote></p>
          <p>Additionally, in 2007, as the Estonian branch was being acquired, the local regulator, the Estonian Financial Services Authority (EFSA), also warned the Danish regulator and the bank (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;The EFSA found deficiencies in relation to the subsidiary&#x2019;s management of AML risks and on that basis issued an order for the subsidiary on further measures to investigate new non-Baltic customers (non-resident customers) and to strengthen internal AML procedures&#x201D;. </p>
          </disp-quote></p>
          <p>However, investigations appeared not to have uncovered the full extent of the problem (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;However, neither Danske Bank nor the EFSA identified problems on a scale anywhere near what was later identified.&#x201D; </p>
          </disp-quote></p>
          <p>Obviously, a golden opportunity to nip the AML problem in the bud had been missed not only by Danske Bank but also their regulators in Denmark and Estonia. Although regulators may have missed the full import of the problem, the ultimate responsibility, of course, resided with the Board of Danske Bank.</p>
          <p>In 2009, the Estonian financial regulator again conducted an AML inspection which gave a modicum of comfort to Danske Bank directors (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;EFSA also concluded that EFSA had found some weaknesses, but did not find serious shortcomings or problems, and that the problems identified in 2007 appeared to have been handled.&#x201D;</p>
          </disp-quote></p>
          <p>Again, another opportunity to delve into and resolve &#x2018;weaknesses&#x2019; was missed and, instead, over the next 3 years or so, the number of Non-Resident customers grew, as did the number of &#x2018;suspicious transactions&#x2019;</p>
          <p>In 2012, the Danish regulator (DFSA) undertook an inspection of processes at Danske Bank and concluded that &#x201C;<bold>Danske Bank has historically not lived up to its obligations in the AML area</bold> [Emphasis added]&#x201D; (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2018</xref>).</p>
          <p>In 2013, the Estonian FSA contacted the Danish FSA about possible AML issues at the branch, alleging that &#x201C;<bold>detailed information</bold> from 2012 and 2013 to the Danish FSA and the Estonian FSA therefore <bold>was misleading</bold> [Emphasis added]&#x201D;.</p>
          <p>On inspection, the Danish regulator discovered that (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2018</xref>):
          <disp-quote>
            <p>&#x201C;From the end of 2012 to November 2013, Danske Bank did not have a person responsible for AML activities as required by the Danish Anti-Money Laundering Act.&#x201D;</p>
            </disp-quote></p>
          <p>Technically, this meant that Danske Bank was in violation of Danish law at that point and had been so for some time. </p>
          <p>In 2013, regulatory investigations began to heat up (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
          <disp-quote>
            <p>&#x201C;The EFSA contacted the Danish FSA again regarding AML risks in the Estonian branch. The inquiry was based on a warning from the Russian central bank which included a list with a number of the branch&#x2019;s Russian customers, which the Russian central bank considered to be suspicious, and on the EFSA&#x2019;s own analysis of the branch&#x2019;s customer mix.&#x201D;</p>
            </disp-quote></p>
          <p>However, Danske Bank management again appeared to downplay the problems (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;The Danish FSA asked Danske Bank to address EFSA&#x2019;s request. The bank&#x2019;s acting Head of the Legal Department replied that the Estonian branch had a special setup in the light of the elevated AML risk in the branch.&#x201D; </p>
            </disp-quote></p>
          <p>Additionally, the bank appears to not have been thorough and diligent in its response (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;However, the evidence shows that the <bold>bank did not always provide the FSA with accurate information,</bold> and that in several cases this was due to <bold>the bank not being sufficiently thorough in its</bold> investigation of the facts before replying to the Danish FSA [Emphasis added].&#x201D; </p>
            </disp-quote></p>
          <p>Towards the end of 2013, the bank&#x2019;s management received a report from a whistle-blower, as described in the next section, which seemed to confirm regulators&#x2019; concerns. In 2014, the Estonian regulator (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;conducted two AML inspections in 2014. The Danish FSA was not asked to attend. The inspections <bold>showed significant weaknesses in the branch&#x2019;s AML procedures</bold> and led to orders from the EFSA and <bold>the</bold> replacement <bold>of the branch&#x2019;s local management.</bold> [Emphasis added]&#x201D; </p>
            </disp-quote></p>
          <p>A senior employee emailed colleagues concerning the EFSA report (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;The executive summary of the Estonian FSA letter is brutal to say the least and is close to the worst I have ever read within the AML/CTF area (<bold><italic>and I have read some harsh letters</italic></bold>). [Emphasis added]&#x201D;.</p>
            </disp-quote></p>
          <p>However, the Danske Board and management appeared still not to be fully aware of the seriousness of the situation, failing to take seriously the regulator&#x2019;s warnings (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
          <disp-quote>
            <p>&#x201C;the Estonian FSA&#x2019;s critical conclusions were thus still toned down in the minuted discussions of the Executive Board and in written internal reporting to the Board of Directors.&#x201D;</p>
            </disp-quote></p>
          <p>In 2015, after further warnings from the Estonian regulator, the Danske Board eventually began to act, ordering that the Non-Resident portfolio be closed down, but &#x201C;another year passed before, in January 2016, the close down was completed&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>).</p>
          <p>In March 2017, the Russian Laundromat investigation was reported in the press (<xref rid="B34-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2017</xref>), implicating Danske Bank in money laundering activities. At that point, stung by media pressure, the Danish regulator began an investigation and asked &#x201C;the bank&#x2019;s Board of Directors and Executive Board for a written statement about this case and more generally about AML handling at the branch&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>).</p>
          <p>The Danish regulator was not, however, completely satisfied with the information supplied by the bank (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>):
          <disp-quote>
            <p>&#x201C;<bold>As a result of inadequate information being provided to the Danish FSA</bold>, the Danish FSA has found it necessary to enquire more than once regarding the same issues in order to receive an adequate reply and to enquire about the bank&#x2019;s knowledge of further cases. [Emphasis added]&#x201D;</p>
            </disp-quote></p>
          <p>Finally, in September 2017, <italic>a full decade after the first warnings from the Russian Central Bank</italic>, the Danske Bank Board acknowledged that (<xref rid="B9-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2017</xref>):
          <disp-quote>
            <p>&#x201C;<bold>major deficiencies in controls and governance</bold> that made it possible to use Danske Bank&#x2019;s branch in Estonia <bold>for</bold> criminal <bold>activities such as money laundering</bold> [Emphasis added]&#x201D;.</p>
            </disp-quote></p>
          <p>At that point, the external investigation (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>) was initiated which led to the events that resulted in the resignation of the CEO and Chairman and the reorganisation of the organisation, as described above.</p>
          <p>When the interactions are laid out in the sequence above and documented in <xref ref-type="app" rid="app1-J_Bus_Account_Financ_Perspect-2-17">Appendix A</xref>, it is difficult to believe that the warnings from the bank&#x2019;s senior regulators were ignored and/or downplayed. That is hindsight, though. </p>
          <p>As <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) observes, prior to many organisational disasters, there was a &#x201C;failure to comply with existing regulations&#x201D;, with those closest to an impending disaster unable to see the looming crisis because of &#x201C;cultural rigidity&#x201D;. Danske Bank&#x2019;s Board and management had a &#x201C;blind spot&#x201D; (<xref rid="B3-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Blacker and McConnell, 2015</xref>) as regards money laundering, obviously not fully aware of the importance placed upon the crime by overseas authorities. </p>
        </sec>
        <sec id="sec5dot5dot2-J_Bus_Account_Financ_Perspect-2-17">
          <title>5.5.2. Termination of Correspondent Bank Relationships</title>
          <p>Because the costs of setting up a fully-fledged overseas banking operation to support their largest clients are so enormous, banks often enter into what is called a &#x2018;correspondent banking&#x2019; relationship with overseas banks (<xref rid="B21-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McAndrews, 2010</xref>). For example, in order to process payments in US dollars for a client, such as Maersk, i.e., one of the world&#x2019;s largest shipping companies, Danske Bank would typically set up a legal arrangement with a local US bank, such as JP Morgan. For a fee, JPMorgan then would accept and make payments on behalf of Danske Bank, and Danske Bank would agree to do the same for clients of JP Morgan with business in Denmark.</p>
          <p>Today, international commerce is driven through complex networks of mutually beneficial correspondent banking relationships between the largest banks in each country/jurisdiction. These correspondent networks are, in turn, aided by highly automated global communications networks, such as SWIFT (<xref rid="B21-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McAndrews, 2010</xref>). </p>
          <p>Although driven by opportunities for profit, any particular correspondent relationship between two banks is based on &#x2018;<bold>trust&#x2019;</bold>; trust that the receiving bank will execute a banking transaction to the best of its capabilities; and trust that the sending bank will only request legal transactions, as the receiving bank will have legal liability for illegal transactions in their home jurisdiction.</p>
          <p>This is particularly important for any payments transactions that are subject to Anti-Money Laundering controls in that the receiving bank may be judged as being liable for any transgression of AML laws <italic>in their local jurisdiction.</italic></p>
          <p>In a somewhat anomalous situation, the Danske branch in Estonia had its own direct correspondent banking relationship for making USD payments. However, in June 2013 (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>): 
          <disp-quote>
            <p>&#x201C;a member of the Executive Board was contacted by one of the bank&#x2019;s correspondent banks with a view to terminating the correspondent banking relationship on grounds of AML.&#x201D;</p>
            </disp-quote></p>
          <p>Despite this serious matter being raised with the highest level of the bank, the warning appeared not to have rung alarm bells sufficiently and, after an internal review, the relationship was terminated <italic>but</italic> immediately replaced by another, different relationship (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>).</p>
          <p>In 2015, two separate correspondent banks in the USA approached Danske at &#x2018;group level&#x2019; with warnings concerning transactions emanating from the Estonian branch, and one bank is reported as stating (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>) that they:
          <disp-quote>
            <p>&#x201C;did not want to go into detail, but made it clear that they had found some payments that they were not comfortable with&#x201D;.</p>
            </disp-quote></p>
          <p>A review at the time, by the bank&#x2019;s Group Compliance and AML team, warned (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>) that &#x201C;we should be mindful that we <bold>have a really bad case in Estonia</bold>, where &#x2026; <bold>all lines of defence failed</bold> [Emphasis added]&#x201D;. However, these warnings and the terminations of major banking correspondent banking relationships with the Estonian branch were not reported to the Board.</p>
          <p>At the very least, the termination of major correspondent banking relationships should have raised &#x2018;red flags&#x2019; in all management, risk and compliance forums. However, it appears that while some unease was felt, no significant actions appear to have been taken to get to the bottom of the reasons such important relationships were terminated.</p>
        </sec>
        <sec id="sec5dot5dot3-J_Bus_Account_Financ_Perspect-2-17">
          <title>5.5.3. The Danske Whistle-Blower</title>
          <p>In 2012, a senior employee in the Estonian branch felt that &#x201C;he had no option but to approach senior group employees directly&#x201D; because (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
          <disp-quote>
            <p>&#x201C;It is not appropriate to raise these issues within the branch due to their serious nature, that it is unclear at what level in the branch there was knowledge of the incident and because of a general problem regarding confidentiality in the branch.&#x201D; </p>
            </disp-quote></p>
          <p>After doing some basic research (at the UK Companies House), the whistle-blower discovered that a particular UK company, which was receiving large payments, was in effect a dormant company with little business activity other than receiving and then disbursing payments from accounts of &#x2018;non-residents&#x2019;. In a damning report, he concluded that (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
          <disp-quote>
            <p>&#x201C;<bold>The bank may itself have committed a criminal offence;</bold> The bank can be seen as having aided a company that turned out to be doing suspicious transactions (helping to launder money?); <bold>The bank has likely</bold> breached <bold>numerous regulatory requirements.</bold> The bank has behaved unethically; and <bold>There has been a near total process failure.</bold> [Emphasis added]&#x201D;</p>
            </disp-quote></p>
          <p>Reaction to the whistle-blower&#x2019;s report was slow, taking more than a year for the suspicious customer relationship to be terminated. This was because the whistle-blower was initially viewed with suspicion, as he decided to bypass the normal branch-based whistle-blowing process, voicing his concerns directly to headquarters where, of course, he was considered an &#x2018;outsider&#x2019; who was circumventing standard procedures. </p>
          <p>In 2014, the Danske Bank Group&#x2019;s internal audit department (GIA) conducted several AML audits at the branch, which &#x201C;<bold>confirmed significant AML deficiencies as pointed out by the whistle-blower</bold> [Emphasis added]&#x201D;, especially that companies were being set up, with complicated opaque ownership corporate structures specifically &#x201C;to avoid submitting financial statements&#x201D; and with beneficial owners that were not &#x201C;known by the bank, or were known but not registered in the relevant systems of the branch&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>)&#x2014;all clear contraventions of the EU AML regulations.</p>
          <p>In a damning analysis of the bank&#x2019;s failure to address the extremely serious issues raised, the independent review stated (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
          <disp-quote>
            <p>&#x201C;In the period after the whistle-blower report, there were several indications that members of the management and/or employees of the branch <bold>were colluding with non-resident customers in criminal activities or, at least, knew of such activities</bold>. The bank did not, however, investigate this, and there were <bold>no managers or employees who were dismissed or relocated because of such a suspicion</bold>. [Emphasis added]&#x201D;</p>
            </disp-quote></p>
          <p>The failure of senior management and group control functions to act on the serious issues raised by reputable correspondent banks and the senior whistle-blower illustrates that bank management disregarded complaints from those not in the &#x2018;inner circle&#x2019; because &#x201C;it was automatically assumed that the organizations knew better than outsiders about the hazards of the situations with which they were dealing&#x201D; (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner, 1976</xref>).</p>
        </sec>
      </sec>
      <sec id="sec5dot6-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.6. Information Difficulties and Noise</title>
        <p>Banking is an information-intensive industry (<xref rid="B30-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2017</xref>). Every day, in any large financial institution, such as Danske Bank, millions of pieces of information are captured from banking transactions, such as payments, deposits, mortgage repayments, Foreign Exchange trades and so on. These captured data are stored, processed, aggregated and reported to customers (as statements), regulators (as regulatory repots) and to management as information of many different types (operating volumes, profitability, risks, future liabilities etc.) While the vast majority of this information will be &#x2018;correct&#x2019;, an unknown proportion will be incorrect&#x2014;the result of genuine mistakes, delays and even fraud.</p>
        <p>Finding these errors, however, is like finding the proverbial needle in a very large haystack, and even harder as the haystack is continually growing and shifting shape. Furthermore, after anomalies are found, selecting the errors in order of importance is also very difficult.</p>
        <p>Of course, modern banks use Information Technology (IT) to perform the vast bulk of the job of searching for, and reporting, potential errors. Banking and most other businesses today are driven by &#x2018;exception reporting&#x2019; or the highlighting of possible exceptions in a vast mass of data. If IT systems have not been programmed to pick up exceptions, then management and ultimately a board will be making decisions on the basis of incorrect, out-of-date or incomplete information.</p>
        <p>As noted earlier, Danske Bank Management were very proud of their &#x2018;One Platform&#x2019; strategy (<xref rid="B5-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2007</xref>):
        <disp-quote>
          <p>&#x201C;We have developed a solid and scalable platform to support our core business. The platform consists of systems to manage IT, product development, communications, branding, credits, risk, HR development and finances. <bold>This platform allows all our units across borders to base their work on the same business model</bold> [Emphasis added]&#x201D;.</p>
          </disp-quote></p>
        <p>By having a single and shared IT platform across all (or almost all) business units, management information can be produced that is &#x2018;consistent&#x2019;, providing the basis for identifying exceptions that management needs to address.</p>
        <p>In late 2006, announced the acquisition of Sampo Pank and noted (<xref rid="B4-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2006</xref>):
        <disp-quote>
          <p>&#x201C;Danske Bank expects to complete the integration of Sampo Pank&#x2019;s Finnish activities on its IT platform at Easter 2008. It has not yet been decided when to integrate the still relatively small operations in Estonia, Latvia, Lithuania and Russia.&#x201D;</p>
          </disp-quote></p>
        <p>It should be noted that the announcement stated &#x201C;<italic>when</italic>&#x201D; not &#x201C;<italic>if</italic>&#x201D; the Estonian branch would be integrated into the &#x2018;One Platform&#x2019;, and as a measure of whether this was achievable, and indeed what had been achieved, the report added:
        <disp-quote>
          <p>&#x201C;The Group vision of creating &#x201C;one platform&#x2014;exceptional brands&#x201D; was clearly reflected in the successful migration of the systems of National Irish Bank and Northern Bank to the Group&#x2019;s shared IT platform during Easter 2006.&#x201D; </p>
          </disp-quote></p>
        <p>However, unlike the situation in the Irish banks, the integration of the Baltic branches of Sampo, especially Estonia, did not go well for reasons that were not expanded upon (<xref rid="B6-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2008</xref>):
        <disp-quote>
          <p>&#x201C;In the third quarter of 2008, on the basis of a cost analysis, the Group <bold>decided to discontinue the migration of Banking Activities Baltics to its shared IT platform</bold>. But this will not stop future investments in the Baltic banks and their IT departments and local IT systems. The Group will also continue the business integration of the banks and will market Danske Bank products where relevant. [Emphasis added]&#x201D;.</p>
          </disp-quote></p>
        <p>In other words, the IT systems used to capture and, more importantly, to report to Group management and the Board were not consistent across the bank, giving rise to considerable &#x201C;difficulties and noise&#x201D; (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner, 1976</xref>). In particular, in the context of this case, the identification of &#x2018;suspicious&#x2019; money laundering transactions was not consistent and indeed may have been downplayed, or even removed, in the alternative Estonian systems.</p>
        <p>With hindsight, the decision not to complete the integration of the Baltic branches, ostensibly for cost reasons, cost the bank very dearly.</p>
      </sec>
      <sec id="sec5dot7-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.7. The Involvement of Strangers</title>
        <p>Turner refers to &#x201C;strangers&#x201D; as members of the general public who may behave unpredictably in a disaster. In Turner&#x2019;s framework, &#x2018;strangers&#x2019; may not necessarily contribute directly to the causes of disasters but become part of the &#x2018;noise&#x2019; that distracts the attention of the participants and hinders the detection of potential problems. In the Allied Irish Bank (AIB) and National Australia Bank (NAB) cases, <xref rid="B23-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell</xref> (<xref rid="B23-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2003</xref>, <xref rid="B24-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2005</xref>) identified examples of &#x2018;strangers&#x2019; in the banking industry, in particular brokers, who had an impact on those events.</p>
        <p>In the Danske case, the &#x2018;strangers&#x2019; are obvious&#x2014;they are the firms and individuals who were classified as the &#x2018;Non-Resident Portfolio&#x2019;. It was the failure of the bank&#x2019;s employees and managers to get to &#x2018;Know Your Customers&#x2019; (KYC) that led to the scandal and considerable cost to Danske Bank, not only in money but also in reputation.</p>
        <p>The number of these strangers is significant, estimated at &#x201C;approximately 10,000 in the period from 2007 through 2015&#x201D;, including some customers that were &#x201C;passive&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>). At any one time, <xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank</xref> (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018a</xref>) documents that there just under 3900 active customers with customers coming and going from different jurisdictions (even a small number from Estonia itself):
        <disp-quote>
          <p>&#x201C;Over time, the geographical distribution of the customers in the Non-Resident Portfolio changed. In total, customers came from 90 countries based on their registered or recorded residency status (for example, postal address for private persons and country of incorporation for corporate entities), the three main countries being Russia, the UK and the British Virgin Islands.&#x201D;</p>
          </disp-quote></p>
        <p>It should be noted that changes in the numbers and origins of customers would be expected in a money laundering situation, as criminals attempt to stay ahead of their pursuers&#x2014;here, the financial crime authorities. <xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank</xref> (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018a</xref>) provides copious statistics on the make-up of the Non-Resident Portfolio over time, and it should also be noted that there were approximately 5000 customers who resided outside of Estonia, such as in other Nordic countries, who were not considered to be part of the Portfolio.</p>
        <p>These strangers/customers were very active in making significant payments (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;In the period from 2007 through 2015, the approximately 10,000 customers in the Non-Resident Portfolio had approximately 7.5 million incoming and outgoing payments. &#x2026;. The flow as converted into EUR was approximately EUR 200 billion.&#x201D;</p>
          </disp-quote></p>
        <p>It was the failure to comply with AML regulations for many of these payments that created the scandal and cost Danske dearly.</p>
      </sec>
      <sec id="sec5dot8-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.8. Failure to Comply with Discredited or Out-of-Date Regulations</title>
        <p><xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) documents how, prior to many organisational disasters, there was often a &#x201C;failure to comply with existing regulations&#x201D;, with those closest to an impending disaster unable to see the looming chaos because of so-called &#x201C;cultural rigidity&#x201D;. In this case, the &#x201C;existing regulations&#x201D; ignored were those of regulators who had developed rules as to how AML activities should be identified and reported to financial crime authorities.</p>
        <p>It should be noted that the term &#x2018;discredited or out-of-date regulations&#x2019; refers to the perceptions of management <italic>not</italic> regulators, as there is no evidence that the various regulators for Danske downplayed the importance of AML as illustrated above when discussing complaints from regulators. The independent report found that (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;AML procedures at the Estonian branch in relation to the Non-Resident Portfolio were manifestly insufficient and inadequate and in breach of international standards as well as Estonian law. This was so even though the <bold>non-resident customers were categorised as high risk.</bold> [Emphasis added]&#x201D;</p>
          </disp-quote></p>
        <p>The report listed, in great detail, some very clear examples of non-compliance and failures of due diligence, including clear breaches of AML regulations (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):<list list-type="bullet">
          <list-item>
            <p>&#x201C;Lacking knowledge of customers;</p>
          </list-item>
          <list-item>
            <p>Lacking identification of (ultimate) beneficial owners and &#x201C;controlling interests&#x201D;;</p>
          </list-item>
          <list-item>
            <p>Customers included so-called intermediaries, which were unregulated and represented; .</p>
          </list-item>
          <list-item>
            <p>Insufficient attention to customer activities;</p>
          </list-item>
          <list-item>
            <p>Lacking identification of the source and origin of funds used in transactions;</p>
          </list-item>
          <list-item>
            <p>No screening of customers against lists of politically exposed persons;</p>
          </list-item>
          <list-item>
            <p>No screening of incoming payments against sanctions or terror lists&#x201D;; and</p>
          </list-item>
          <list-item>
            <p>Several other clear failures of AML monitoring and reporting.</p>
          </list-item>
        </list></p>
        <p>There were also serious organizational failings:
        <disp-quote>
          <p>&#x201C;Other shortcomings have been identified, such as the <bold>lack of independence between the AML function</bold> at the Estonian branch and the business and <bold>insufficient training of the staff</bold> of the Estonian branch and <bold>lack of formal procedures</bold>. [Emphasis added]&#x201D;</p>
          </disp-quote></p>
        <p>Furthermore, in addition to the manifest failures as regards AML compliance, the firm appeared to be in breach of its obligations with the Danish regulator (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;From the end of 2012 to November 2013, Danske Bank did not have a person responsible for AML activities as required by the Danish Anti-Money Laundering Act. The Danish FSA was not notified of this until February 2018 and then as a result of the Danish FSA&#x2019;s supplementary questions. The Board of Directors and the Executive Board have stated that in practice, the head of Group Compliance &amp; AML, who reported to the bank&#x2019;s CFO, was the person responsible for AML activities.&#x201D;</p>
          </disp-quote></p>
        <p>There were also obvious organisational failures that undermined the independence of risk management function particularly in the Estonian branch, making compliance with regulations &#x201C;ineffective&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;In addition, the branch&#x2019;s second and third lines of defence were organised in such a way that in practice, they reported to the branch CEO and thus were not sufficiently independent.&#x201D;</p>
          </disp-quote></p>
      </sec>
      <sec id="sec5dot9-J_Bus_Account_Financ_Perspect-2-17">
        <title>5.9. Minimising Emergent Danger</title>
        <p>A common feature of organisational disasters is that those who are closest to the problem &#x201C;fail to call for help&#x201D;, which has been attributed to fears of causing unnecessary alarm, psychological denial of the danger or the assertion of the individual&#x2019;s invulnerability (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner, 1976</xref>). Turner points out that individuals consistently underestimate the scale of the problems that they face because of ambiguity or disagreement about the evidence regarding the danger. He also notes that when the danger becomes impossible to ignore, rather than addressing the causes of the problem, individuals often look to shift the blame to others. </p>
        <p>This was apparent in the Danske case, where unpalatable truths were ignored or downplayed (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;For a long time, it was believed within Group that the high risk represented by non-resident customers in the Estonian branch was mitigated by appropriate anti-money laundering (&#x201C;AML&#x201D;) procedures.&#x201D;</p>
          </disp-quote></p>
        <p>As an example, in 2012, in correspondence with the Danish FSA, the AML programme was referred to as &#x201C;Best in Class&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>)&#x2014;and indeed, it may well have been so in most areas of the Danske group, but clearly not in the Estonian branch, and the harsh criticism from regulators, over a significant time, showed:
        <disp-quote>
          <p>&#x201C;AML procedures also became subject to harsh criticism from the FSA in Estonia, and Danske Bank was met with regulatory sanctions from both the Estonian FSA in July 2015 and the Danish FSA in March 2016&#x201D;.</p>
          </disp-quote></p>
        <p>Danger was routinely minimised in Board reports and minutes (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The head of Business Banking, who was responsible for the Estonian branch on the Executive Board, informed the Executive Board and Board of Directors of the observations made by GIA and the consultancy firm. The slides he had had prepared for the Board of Directors meetings <bold>significantly toned down the AML issues</bold>, but the Board of Directors and the Executive Board have stated that it should be taken into account that <bold>the slides were neither shared nor used.</bold> [And &#x2026;]</p>
          </disp-quote>
         <disp-quote><p>According to minutes from meetings of the Board of Directors and the Board of Directors&#x2019; Audit Committee as well as the Executive Board, there were <bold>no comments of significance to his presentation nor to the more critical assessments</bold> of AML in the Baltic countries in the audit report and reporting from Group Compliance &amp; AML [Emphasis added]&#x201D;.</p></disp-quote></p>
        <p>It appears that, despite the mounting evidence, the Board and management did not &#x2018;join the dots&#x2019; and did not fully recognise the dangers they were facing (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The bank&#x2019;s Board of Directors and Executive Board argue in their reply to the Danish FSA that such a simultaneous breakdown of all three lines of defence is a risk that must be considered to have <bold>low probability from a management perspective</bold>. [Emphasis added]&#x201D;</p>
          </disp-quote></p>
        <p>The Board appeared to have blamed this on their workload (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The Board of Directors and the Executive Board have stated that when assessing the Board of Directors&#x2019; and the Executive Board&#x2019;s work and the volume of written material that the members of the two boards receive, it should be taken into consideration that the branch in Estonia accounts <bold>for only a small part of the total business and total risks</bold>. [Emphasis added]&#x201D;</p>
          </disp-quote></p>
        <p>This section looked at each of Turner&#x2019;s &#x2018;stages&#x2019; of a disaster and related the events that occurred over the decade that it took the scandal to emerge to these stages. The next section looks at the risks that emerged but were not managed properly.</p>
      </sec>
    </sec>
    <sec id="sec6-J_Bus_Account_Financ_Perspect-2-17">
      <title>6. Risks Apparent in the Danske Bank Scandal</title>
      <p>In all large financial institutions, there are a myriad of risks that must be managed, proactively and carefully. First among these risks in banks are the full range of credit and market-related risks. However, this paper does not consider these major risks, as they were not raised in independent investigation, but rather other so-called non-financial risks. </p>
      <sec id="sec6dot1-J_Bus_Account_Financ_Perspect-2-17">
        <title>6.1. Strategic Risks</title>
        <p>A member of the US Federal Reserve Board, <xref rid="B19-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Randall Kroszner</xref> (<xref rid="B19-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2008</xref>) noted that financial firms do not always recognise and manage risks to their corporate strategy:
        <disp-quote>
          <p>&#x201C;An effective overall corporate strategy combines a set of activities a firm plans to undertake with an adequate assessment of the risks included in those activities. Unfortunately, many firms have forgotten the second part of that definition. In other words, <bold>there can be no real strategic management in financial services without risk management</bold> [Emphasis added].&#x201D;</p>
          </disp-quote></p>
        <p>As with the term &#x2018;strategy&#x2019;, there is no generally agreed definition of &#x2018;strategic risk&#x2019; nor of Strategic Risk Management (SRM). <xref rid="B20-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">MacLennan</xref> (<xref rid="B20-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2010</xref>) points out:
        <disp-quote>
          <p>&#x201C;It is relatively recently that strategic risk management has emerged as a distinct concern. Recognition that isolated risk management in specific areas is inadequate and that many risks are &#x201C;strategic&#x201D; in their nature and impact has led to the emergence of the field.&#x201D;</p>
          </disp-quote></p>
        <p><xref rid="B29-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell</xref> (<xref rid="B29-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2016</xref>) collected a number of definitions of strategy and strategic risk. For example, for the purposes of examining banks, the US Federal Reserve and the Office of the Comptroller of the Currency (OCC) define &#x201C;strategic risk&#x201D; as (<xref rid="B32-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCC, 2010</xref>):
        <disp-quote>
          <p>&#x201C;The current and prospective impact on earnings or capital <bold>arising from adverse business decisions, improper implementation of decisions, or lack of responsiveness to industry changes</bold>. This risk is a function of the compatibility of an organisation&#x2019;s strategic goals, the business strategies developed to achieve those goals, the resources deployed against these goals, and the quality of implementation [Emphasis added].&#x201D;</p>
          </disp-quote></p>
        <p>In the Danske case, the negative impact of earnings arises from the AML scandal, which involves both &#x201C;adverse business decisions&#x201D;, &#x201C;improper implementation of decisions&#x201D;, in particular, the acquisition of Sampo Pank.</p>
        <p>In the early 2000s, Danske was following an aggressive strategy of &#x201C;growth by acquisition&#x201D;, acquiring smaller banks in Northern Europe, such as Sampo. <xref rid="B29-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell</xref> (<xref rid="B29-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2016</xref>) notes that growth strategies are risky, and acquisition strategies are particularly risky because of the &#x201C;difficulty/inability of performing sufficient &#x2018;due diligence&#x2019; on the firm being acquired&#x201D;.</p>
        <p>In documenting many instances of commercial acquisitions that have failed, <xref rid="B36-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Rankine and Howson</xref> (<xref rid="B36-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2014</xref>) warn that &#x201C;most acquisitions fail&#x201D; to achieve their stated objectives and point out the importance of conducting good commercial due diligence. They note, however, that it is often very difficult to perform sufficient due diligence on the company being acquired not only in the cases where the board of the firm being pursued perceives the approach to be &#x2018;hostile&#x2019; but, even when it is welcomed, in cases when secrecy, such as keeping the news of a potential takeover from employees, must be preserved.</p>
        <p>In the case of Danske, it is apparent that the board and management did not do sufficient due diligence on Sampo Pank, since, as noted earlier, the Russian central bank had already warned that there was evidence of significant money laundering at the Estonian branch (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>). Not that such a discovery should have stopped the acquisition, merely that additional work would be needed to resolve the problems that were later unearthed. </p>
        <p>In short, while the overall growth through the acquisition strategy of acquiring smaller banks in Northern Europe may be considered somewhat successful, or at least not unsuccessful, the Danske Board did not identify nor did they manage the complete set of the risks in their strategy. </p>
      </sec>
      <sec id="sec6dot2-J_Bus_Account_Financ_Perspect-2-17">
        <title>6.2. Strategic Technology Risk</title>
        <p>While an opportunity was missed to identify AML issues when Sampo Pank was first acquired, later decisions turned that initial problem into a much bigger one. When in 2006, Danske announced the acquisition of Sampo Pank (<xref rid="B4-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2006</xref>), it clearly stated that:
        <disp-quote>
          <p>&#x201C;Danske Bank expects to complete the integration of Sampo Bank&#x2019;s Finnish activities on its IT platform at Easter 2008. It has not yet been decided when to integrate the still relatively small operations in Estonia, Latvia, Lithuania and Russia.&#x201D;</p>
          </disp-quote></p>
        <p>However, in 2008, the Board stated that &#x201C;on the basis of a cost analysis, the Group decided to discontinue the migration of Banking Activities Baltics to its shared IT platform.&#x201D; (<xref rid="B6-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2008</xref>). This meant that as time went on (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;The Estonian branch had its own IT platform. This meant that the branch <bold>was not covered by the same customer systems and transaction and risk monitoring as Danske Bank Group</bold> headquartered in Copenhagen (also referred to as &#x201C;Group&#x201D;), and it also meant that Group <bold>did not have the same insight into the branch as other parts of Group.</bold> [Emphasis added]&#x201D;.</p>
          </disp-quote></p>
        <p>This anomaly proved a serious shortcoming for the bank&#x2019;s risk monitoring functions, compounded by the fact that many of the documents were written in Estonian or Russian and thus difficult for foreigners to read.</p>
        <p>In the Danske case, the board and management had a clear strategy of &#x2018;one platform&#x2019;, based on shared state-of-the-art technology. However, the board chose not to follow that strategy for the Baltic branches for cost reasons. In this, they failed to fully understand and manage the risks in the overall technology strategy (<xref rid="B30-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">McConnell, 2017</xref>)</p>
      </sec>
      <sec id="sec6dot3-J_Bus_Account_Financ_Perspect-2-17">
        <title>6.3. Operational Risks</title>
        <p>In 2004, the Basel Committee of the Bank for International Settlements, the world&#x2019;s senior banking regulator, finalised proposals to bring the management of Operational Risk in line with the standards already adopted for Market and Credit risks (<xref rid="B2-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Bank for International Settlements, 2004</xref>). These so-called Basel II proposals are designed to strengthen operational controls in international banks and to ensure that they have set aside sufficient capital to cover large losses, such as those at Danske Bank. The Basel Committee defines operational risk as (<xref rid="B2-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Bank for International Settlements, 2004</xref>):
        <disp-quote>
          <p>&#x201C;the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This definition includes legal risk but not strategic or reputational risk&#x201D;.</p>
          </disp-quote></p>
        <p>In the 2004 Basel II regulations, &#x2018;Money Laundering&#x2019; is identified as an Operational Risk Loss Event Type in the category of &#x201C;Clients, Products &amp; Business Practices&#x201D;, in the Level 2 Category &#x201C;Improper Business or Market Practices&#x201D; (<xref rid="B2-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Bank for International Settlements, 2004</xref>, Annex 7). The Danske case would seem to fit this classification, and hence, the losses are clearly an Operational Risk Loss Event (ORLE). </p>
        <p>It is also obvious that all of the factors identified by the Basel Committee as giving rise to operational risk were present in the Danske case, including:<list list-type="bullet">
          <list-item>
            <p>Processes&#x2014;failure of basic processes designed to identify money laundering;</p>
          </list-item>
          <list-item>
            <p>People&#x2014;failure to follow board level policies, in particular reporting suspicious activities with regard to &#x2018;non-residents&#x2019;;</p>
          </list-item>
          <list-item>
            <p>Systems&#x2014;failure to integrate IT systems in the Estonian branch into the &#x2018;one platform&#x2019; technology model; and</p>
          </list-item>
          <list-item>
            <p>External&#x2014;illegal money laundering activity by non-residents.</p>
          </list-item>
        </list></p>
        <p>It is apparent from the evidence provided in the independent report (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>) and others that, at least for management of the operational risks of money laundering, the &#x2018;Group operational risk management framework of policies&#x2019; and IT systems were woefully deficient.</p>
      </sec>
    </sec>
    <sec id="sec7-J_Bus_Account_Financ_Perspect-2-17">
      <title>7. Failure of Risk Management</title>
      <p>It should be noted that this study did not consider all aspects of risk management at Danske Bank, only those areas relating to failures of Anti-Money Laundering policies, and even then, only with regard to the firm&#x2019;s Estonian branch. In the absence of any other information that shows wider failures of risk management elsewhere in the firm, which has <italic>not</italic> emerged following the revelations in the independent report (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>), it may be assumed for now that this scandal is an outlier, albeit a very serious one.</p>
      <sec id="sec7dot1-J_Bus_Account_Financ_Perspect-2-17">
        <title>7.1. Operational Risk Management</title>
        <p>In its 2008 Annual Report, as Sampo Pank was being acquired, the Danske Board reported that as regards operational risk management (ORM) (<xref rid="B6-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2008</xref>):
        <disp-quote>
          <p>&#x201C;<bold>Group operational risk management relies on a framework of policies</bold>. Each individual business unit is responsible for the day-to-day monitoring of operational risk and for mitigating losses. The relevant support functions place resources at the disposal of the business units. The measurement and control framework comprises four <bold>qualitative</bold> elements:</p>
          </disp-quote>
        <list list-type="bullet">
          <list-item>
             <p>Risk identification and assessment ensure that all key risks are <bold>effectively highlighted</bold> for group-wide transparency and management. This enables the Group to focus on fewer but more fundamental risks.</p>
          </list-item>
          <list-item>
            <p>Monitoring of key risks is an ongoing process ensuring that <bold>an increase in such risks is highlighted on a consistent and a group-wide basis</bold>.</p>
          </list-item>
          <list-item>
            <p>Risk mitigation strategies and implementation processes ensure <bold>that key risks are reduced and establish transparency in these strategies and processes</bold>.</p>
          </list-item>
          <list-item>
            <p>Follow-up on loss data and events. [Emphasis added]&#x201D;</p>
          </list-item>
        </list></p>
        <p>In its initial &#x2018;Risk Management Report&#x2019; to its Danish regulator (<xref rid="B8-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2010</xref>), it was noted that the &#x201C;Executive Board&#x201D; had a dedicated &#x201C;Operational Risk Committee&#x201D; which &#x201C;includes managers of all major support functions and resource areas, including IT, and the Group Business Development department&#x201D; and which:
        <disp-quote>
          <p>&#x201C;[...] reviews trends in the Group&#x2019;s key operational risks on an ongoing basis and <bold>follows up on the progress of</bold> concrete <bold>action plans regarding these risks</bold>. The committee also receives reports and recommendations on key risk indicators.&#x201D; [And &#x2026;]</p>
          </disp-quote>
        <disp-quote>
          <p>The Group&#x2019;s operational risk losses are registered in the Operational Risk Information System (ORIS). Losses are categorised according to the Basel II event categories for operational risk, and both direct losses and direct gains are registered. [Emphasis added]&#x201D;</p>
          </disp-quote></p>
        <p>Thus, Danske Bank appeared to have &#x2018;ticked all the boxes&#x2019; as regards regulatory required policies, organisations and frameworks for operational risk management but, as noted by the independent inquiry, &#x201C;all three lines of defence failed&#x201D;, and the much-vaunted risk management framework did not work.</p>
      </sec>
      <sec id="sec7dot2-J_Bus_Account_Financ_Perspect-2-17">
        <title>7.2. Failures of Operational Risk Management </title>
        <p>The independent investigation summarised the failures of operational risk management in the Estonian Branch (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;In respect of the Estonian branch, <bold>there were deficiencies in all three lines of defence</bold>. The first line of defence at the branc<bold>h did not focus on efficiently combating money laundering despite the significan</bold>t number <bold>of high-risk, non-resident customer</bold>s. This was not identified by the first line of defence at Business Banking in Copenhagen, which received a number of reports stating that the branch complied with the rules. <bold>The second-line integration of the Baltic units into the Group&#x2019;s risk managemen</bold>t, including monitoring and reporting, was weak. AML at the branches in the Baltic countries was not mentioned as a compliance risk in the bank&#x2019;s management reporting. The third line internal audit formed part of Group Internal Audit (GIA<bold>). The integration of the branch&#x2019;s internal audit department with GIA was also inadequate</bold>. [Emphasis added]&#x201D;</p>
          </disp-quote></p>
        <p>The core problem in this case is that, despite the many red flags raised by regulators, correspondent banks and a whistle-blower, the issue was not raised to a level that the Board and senior management would take the warnings seriously. Despite what management considered to be a world-class risk management framework, the right information did not flow to the right people (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>):
        <disp-quote>
          <p>&#x201C;Several documents show how management in Copenhagen did not integrate the Estonian branch in the bank&#x2019;s risk management and control systems, but instead allowed the branch to operate with significantly different risk exposure and to a large extent, the branch itself conducted controls.&#x201D;</p>
          </disp-quote></p>
        <p>Such a situation is clearly a serious failure of ORM processes in the bank, which was long-lived (over a decade) and catastrophic, causing serious economic and reputational damage to the company.</p>
        <p>How could such a failure happen, though?</p>
        <p>Documenting a large number of ORM failures, <xref rid="B3-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Blacker and McConnell</xref> (<xref rid="B3-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2015</xref>) identified similar operational risk management failures including in Barings, Allied Irish Bank (AIB), National Australia Bank (NAB), Soci&#xE9;t&#xE9; G&#xE9;n&#xE9;rale (SocGen), Union Bank of Switzerland (UBS) and JPMorgan. Several of these cases are often categorised as &#x2018;rogue trading&#x2019;, but in all these cases, breakdowns in operational risk management processes enabled the people responsible to precipitate serious losses.</p>
        <p>A key point about many of these cases, and also obvious in the Danske case, is the &#x2018;remote&#x2019; nature of the staff and business units involved in the risk management failures. Before these scandals erupted, the offices and business units involved were considered to be small and reasonably profitable, and the small size of the business was wrongly considered not to be risky.</p>
        <p>This, however, is a flawed analysis. Whereas the level of credit risk may reasonably be tied to business unit size, this is not true of operational risk, as failures in ORM in even a small business unit can bring about very large regulatory fines. Operational risk is no respecter of size or profitability.</p>
      </sec>
      <sec id="sec7dot3-J_Bus_Account_Financ_Perspect-2-17">
        <title>7.3. Key Lesson of Danske Scandal</title>
        <p>The key lesson of the Danske Bank scandal is that operational risk management (ORM) processes failed, not across the whole firm but, disastrously, in a small, remote business unit that was considered by HQ as hardly worth worrying about. <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) showed that once such an incorrect belief takes hold, it becomes accepted wisdom and very hard to dislodge.</p>
        <p>In some respects, <bold>the solution is obvious and simple</bold>&#x2014;apply the most rigorous risk management analysis and management to <italic>every</italic> business unit in the firm, even if, at first glance, the effort may not appear to be justified. </p>
        <p>In terms of the Basel II regulations (<xref rid="B2-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Bank for International Settlements, 2004</xref>), this means that every business unit should, each year, conduct a formal and rigorous risk and control self-assessment (RCSA) exercise, in which all operational risk issues pertaining to the business unit would be documented, considered and improvements canvassed. </p>
        <p>As a <italic>separate and independent</italic> exercise, this business line RCSA exercise should be reviewed and audited independently by the firm&#x2019;s central risk management organisation and also the internal audit function. At this stage, any whistle-blowing reports related to the business unit would be considered and used to validate the business unit&#x2019;s self-assessment.</p>
        <p>The results of these reviews should then be presented to senior business line and executive risk committees for formal analysis, monitoring and sign-off. Any requests for additional information or for process changes should be formally made to business unit management and monitored during execution by the central risk management function. Additionally, in order to pick up systematic problems across business lines, formal assessments of RCSAs by independent experts should be commissioned on a regular basis.</p>
        <p>To many business unit managers, such recommendations might appear to be bureaucratic overkill&#x2014;ticking even more boxes&#x2014;and to an extent, they are. However, as <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) observes and Danske Bank shows, barriers to the free flow of information down and up the organisation need to be minimised, regulations need to be respected, warnings, especially from well-positioned whistle-blowers, need to be heeded and risks must be treated seriously.</p>
        <p>In short, boards and senior executives must endure that their risk management policies and frameworks are effective, <italic>everywhere in the organisation</italic>.</p>
      </sec>
    </sec>
    <sec id="sec8-J_Bus_Account_Financ_Perspect-2-17">
      <title>8. Further Research</title>
      <p>This paper was an historical case study and so, except for references, is not compared in detail here to other significant cases of risk management failures. Additional research could prove useful by studying:<list list-type="bullet">
        <list-item>
          <p>Similarities and differences between the Danske case and other scandals in which failure of AML processes were apparent;</p>
        </list-item>
        <list-item>
          <p>Mechanisms for identifying, describing and mitigating money laundering risks that may lead to misconduct and large operational risk losses; and</p>
        </list-item>
        <list-item>
          <p>The success, or otherwise, of regulators&#x2019; actions in the Danske and in other cases, identifying, if possible, factors that are likely to impact successful implementation of regulatory policies.</p>
        </list-item>
      </list></p>
      <p>It should be noted that such research efforts are necessarily multi-disciplinary, for example, involving not only ORM experts but also Human Resources, Compliance and Payments functions.</p>
      <p>Another potentially useful area of research is that of formal methodologies for studying operational risk case studies, especially those that have involved large-scale operational risk losses. Turner&#x2019;s method is useful because it is based on a structured approach to analysis that attempts to dig down to the root causes of an organisational disaster. <xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Fitzsimmons and Atkins</xref> (<xref rid="B16-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2017</xref>) highlight some of the benefits of Turner&#x2019;s approach in taking a big-picture, longitudinal perspective of an event that has had major ramifications for a firm or the industry: 
      <disp-quote>
        <p>&#x201C;When time separates causes from effects, feedback is likely to be poor and more distorted by bias. This makes it much harder for people and organizations to learn and to identify the roots of future crises. Festering root causes can incubate and accumulate for years before emerging; so unless someone deliberately sets out to find and deal with them, they will stay that way until they materialize to cause a crisis. Even when they emerge in a crisis, these deeper risks often remain unrecognized because, &#x2026;, the investigation is superficial and does not dig to root causes&#x201D;.</p>
      </disp-quote></p>
      <p>In this study, Turner&#x2019;s well-established framework is employed, and doubtless, there are others. Research to identify and compare other potentially useful methods could prove beneficial to regulators, the industry and academics.</p>
    </sec>
    <sec id="sec9-J_Bus_Account_Financ_Perspect-2-17">
      <title>9. Summary</title>
      <p>This paper presents an historical case study of what has become known as the Danske Anti-Money Laundering (AML) scandal in which for more than a decade, until brought to light in 2018 by an independent report, some 7.5 million payment transactions involving around 10,000 &#x2018;non-resident&#x2019; customers had been handled through the bank&#x2019;s Estonian branch, located in Tallinn. These transactions should have been deemed &#x2018;suspicious&#x2019; according to the bank&#x2019;s AML procedures but were not. </p>
      <p>On receiving the extremely adverse report of the investigators, the board deemed that the gross income from these suspicious pavements totalling some EUR 0.2 billion should &#x201C;be donated to an independent foundation supporting initiatives to combat international financial crime&#x201D;.</p>
      <p>The events leading up to the scandal are described in this paper using Turner&#x2019;s &#x2018;Six Stages&#x2019; Framework for analysing &#x201C;organisational disasters&#x201D;. One of Turner&#x2019;s key insights is that large organisational disasters, and consequential financial and non-financial losses, emerge, or are &#x201C;incubated&#x201D;, over a long period of time, and it is difficult for those closest to the action to see the disaster emerging. </p>
      <p>After describing Turner&#x2019;s methodology, the paper then describes the background to the case and, using Turner&#x2019;s Framework, describes the sequence of major events that took place over more than a decade that led to the exposure of the AML scandal. </p>
      <p>The paper concluded by identifying some of the key risks that were apparent in the evolution of the Danske scandal and some lessons that can be learned, specifically the role of risk management functions in assisting business managers to identify and mitigate the myriad of issues that give rise to such events. The paper concluded by identifying further research that could help to identify similar cases of corporate misconduct in future.</p>
    </sec>
  </body>
  <back>
   <notes notes-type="COI-statement">
      <title>Declaration of Interest</title>
      <p>The author reports no conflicts of interest. The author alone is responsible for the content and writing of the paper.</p>
    </notes>
    <app-group>
      <app id="app1-J_Bus_Account_Financ_Perspect-2-17">
        <title>Appendix A. Timeline of Events</title>
        <p>The events listed in <xref ref-type="table" rid="J_Bus_Account_Financ_Perspect-2-17-t002">Table A1</xref> are an historical timeline of the events in the Danske Bank scandal, extracted from <xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank</xref> (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018a</xref>) and <xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA</xref> (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018</xref>, <xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2019</xref>) which document the same events from a different perspective and in a different order. The table contains:<list list-type="bullet">
          <list-item>
            <p><bold>Date(s)</bold>: the date or dates on, or between, which the event(s) occurred;</p>
          </list-item>
          <list-item>
            <p><bold>Event/Activity</bold>: the event or activity being described, as referenced in <xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA</xref> (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018</xref>) or <xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank</xref> (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018a</xref>), unless noted otherwise;</p>
          </list-item>
          <list-item>
            <p><bold>Danske Bank Reaction/Action</bold>: how Danske Bank management, executive and/or Board reacted (or did not react) to the event or activity;</p>
          </list-item>
          <list-item>
            <p><bold>Red Flag</bold>: whether the event <italic>should have been</italic> noticed and actions taken;</p>
          </list-item>
          <list-item>
            <p><bold>Features common to Disasters</bold>: the &#x201C;features&#x201D; (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner, 1976</xref>) obvious in the bank&#x2019;s actions/inactions, specifically:<list list-type="alpha-lower">
            <list-item><label>(a)</label><p>Rigidities of belief;</p>
          </list-item>
          <list-item>
            <label>(b)</label><p>Decoy phenomena;</p>
          </list-item>
          <list-item>
            <label>(c)</label><p>Disregard of complaints from outsiders;</p>
          </list-item>
          <list-item>
            <label>(d)</label><p>Information difficulties and noise;</p>
          </list-item>
          <list-item>
            <label>(e)</label><p>The involvement of strangers;</p>
          </list-item>
          <list-item>
            <label>(f)</label><p>Failure to comply with discredited or out-of-date regulations;</p>
          </list-item>
          <list-item>
            <label>(g)</label><p>Minimising emergent danger.</p>
          </list-item>
        </list></p></list-item>
        </list></p>
        <p>The timeline in <xref ref-type="table" rid="J_Bus_Account_Financ_Perspect-2-17-t002">Table A1</xref> emerges over a number of distinctive, but overlapping, &#x2018;Phases&#x2019; as described earlier:<list list-type="order">
          <list-item>
            <label>(1)</label>
            <p><bold>Strategic Euphoria</bold>: a period of euphoria as the Nordic growth strategy was implemented (roughly 2006&#x2013;2008);</p>
          </list-item>
          <list-item>
            <label>(2)</label>
            <p><bold>Regulatory Unease</bold>: a period during which banking regulators expressed unease about the implementation of Danske&#x2019;s growth strategy (roughly 2009&#x2013;2013);</p>
          </list-item>
          <list-item>
            <label>(3)</label>
            <p><bold>Management Myopia</bold>: a period during which management appeared to ignore the increasing signs of problems with the growth strategy (roughly 2013&#x2013;2014);</p>
          </list-item>
          <list-item>
            <label>(4)</label>
            <p><bold>Management Tinkering</bold>: a period during which management took steps to ameliorate (some of) the symptoms without really addressing the serious problems emerging (roughly 2014&#x2013;2016);</p>
          </list-item>
          <list-item>
            <label>(5)</label>
            <p><bold>Management Investigations</bold>: a period during which management initiated multiple investigations but did not directly address the problems (roughly 2016&#x2013;2017);</p>
          </list-item>
          <list-item>
            <label>(6)</label>
            <p><bold>Scandal Emerges</bold>: a period during which the full import of the scandal emerged and corrective actions began to be taken (roughly 2017&#x2013;2018); and</p>
          </list-item>
          <list-item>
            <label>(7)</label>
            <p><bold>Aftermath</bold>: a period during which the firm and its regulators began to take actions to attempt to correct the problems that arose during the scandal, also called &#x201C;Cultural Adjustment&#x201D; by <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>).</p>
          </list-item>
        </list></p>
        <table-wrap id="J_Bus_Account_Financ_Perspect-2-17-t002" position="float">
          <object-id pub-id-type="pii">J_Bus_Account_Financ_Perspect-2-17-t002_Table A1</object-id>
          <label>Table A1</label>
          <caption>
            <p>Timeline of significant events in the Danske Bank scandal.</p>
          </caption>
          <table>
            <thead>
              <tr>
                <th align="center" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Date(s)</th>
                <th align="left" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Event/Activity<break/><italic><xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA</xref> (<xref rid="B14-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018</xref>, <xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2019</xref>), <xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank</xref> (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">2018a</xref>) Unless Noted</italic></th>
                <th align="left" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Danske Bank&#x2014;Reaction/Action</th>
                <th align="center" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Red Flag</th>
                <th align="left" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Turner&#x2014;Features Common to Disasters</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2006&#x2013;2008</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>Phase 1&#x2014;Strategic Euphoria</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Nov. 2006</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danske Bank acquires Sampo Pank, acquisition completed February 2007</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Strategic acquisition &#x201C;integration of Sampo Pank into Danske Bank&#x2019;s IT platform and organisation&#x201D; (<xref rid="B4-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Annual, 2006</xref>)</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2007</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Estonian FSA conducted AML inspection</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;not aware of the extent to which the conclusions of these reports have reached management in Copenhagen&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2007</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The Russian central bank warned the Danish FSA about AML risks related to a number of Russian customers in Danske Bank&#x2019;s newly acquired Estonian subsidiary.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The feedback received from both [heads of Legal and Audit] was that there were no problems in relation to AML risks in the Estonian subsidiary.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders<break/>(e) The involvement of strangers</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2007</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the EFSA found deficiencies in relation to the subsidiary&#x2019;s management of AML risks and on that basis issued an order for the subsidiary on further measures to investigate new non-Baltic customers (non-resident customers) and to strengthen internal AML procedures&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;However, neither Danske Bank nor the EFSA identified problems on a scale anywhere near what was later identified.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders<break/>(e) The involvement of strangers<break/>(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2008</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Sampo Pank Estonia turned into Danske branch</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2009&#x2013;2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>Phase 2&#x2014;Regulatory Unease</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2009</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Estonian FSA conducted AML inspections</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;EFSA also concluded that EFSA had found some weaknesses, but did not find serious shortcomings or problems, and that the problems identified in 2007 appeared to have been handled.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref> <uri>https://www.dfsa.dk/en/News/Press-releases/2019/Corresspondance_EFSA_200219</uri>)</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders<break/>(d) Information difficulties and noise<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2011&#x2013;2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Majority of new &#x201C;non-resident&#x201D; customers are accepted by Estonian branch</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to identify AML risks</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2012</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danish FSA&#x2019;s inspection </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;Danske Bank has historically not lived up to its obligations in the AML area&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2012&#x2013;2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Estonian FSA contacted the Danish FSA about <bold>possible AML issues</bold> at the branch</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;detailed information from 2012 and 2013 to the Danish FSA and the Estonian FSA therefore was misleading&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(d) Information difficulties and noise</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2012&#x2013;2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;From the end of 2012 to November 2013, Danske Bank <bold>did not have a person responsible for AML activities</bold> as required by the Danish Anti-Money Laundering Act.&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to hire senior staff, as required by law</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the EFSA contacted the Danish FSA again regarding AML risks in the Estonian branch. The inquiry was based on a warning from the Russian central bank which included a list with a number of the branch&#x2019;s Russian customers, which the Russian central bank considered to be suspicious, and on the EFSA&#x2019;s own analysis of the branch&#x2019;s customer mix.&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The Danish FSA asked Danske Bank to address EFSA&#x2019;s request. The bank&#x2019;s acting Head of the Legal Department replied that the Estonian branch had a special setup in the light of the elevated AML risk in the branch.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders<break/>(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>May 2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">New Group Credit Policy removing exception &#x201C;to grant FX lines to non-residents solely on cash collateral&#x201D;, i.e., to end &#x2018;non-resident&#x2019; accounts</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Assumption that Group Policy would be implemented as dictated</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>July 2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;following a dialogue with the bank, one of the Estonian branch&#x2019;s two correspondent banks for USD payments <bold>terminated its cooperation with the branch due to concerns about the branch&#x2019;s non-resident customers</bold>&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to recognise significance of this event</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2010&#x2013;2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The Danish FSA requested additional detailed documentation, depending on the quality of the information, and compared it with the information from the EFSA&#x2019;s AML supervision of the branch, [&#x2026;.] Thus, the Danish FSA did not uncritically trust the information from the bank&#x2014;neither information on AML in the branch in Estonia or on the Danish activities.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;However, the evidence shows that the bank did not always provide the FSA with accurate information, and that in several cases this was due to the bank not being sufficiently thorough in its investigation of the facts before replying to the Danish FSA.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">c) Disregard of complaints from outsiders<break/>(d) Information difficulties and noise <break/>(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">New CEO (Thomas Borgen) appointed, previously Head of Baltic Banking, including Estonian branch</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2013&#x2013;2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"><bold>Phase 3&#x2014;Management Myopia</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Dec. 2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;senior employees at the bank <bold>received a whistle-blower report</bold> about AML issues in relation to a customer in the Estonian branch&#x2019;s non-resident portfolio&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to recognise significance of the whistle-blower&#x2019;s report</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>End 2013</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Accounting Goodwill for Estonian branch written down</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>March 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">GIA (Group Internal Audit) reported that new Group Credit Policy <bold>has not been fully implemented</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to process failure</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Jan 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">The whistle-blower made additional accusations in relation to <bold>three other customers of the branch</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Feb. 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">GIA &#x201C;confirmed significant AML deficiencies as pointed out by the whistleblower&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>April 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;an investigation by an external third party. &#x2026;. identified 14 critical deviations and 9 significant deviations between branch practice and applicable rules/best practice&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>May 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">In an investigation of &#x201C;a general nature&#x201D;. &#x201C;There was thus significant information from the whistleblower that the person responsible for AML activities or others <bold>failed to follow up on or did not sufficiently follow up on</bold>&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to whistle-blower&#x2019;s information</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>May 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;At the request of the bank&#x2019;s CEO, the person responsible for AML activities in May 2014 prepared a plan to give the AML area a lift at the Baltic units. &#x2026;. The <bold>plan and the branch&#x2019;s own review did not solve the significant problems at the branch</bold>.&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to act on agreed changes</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2014&#x2013;2016</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"><bold>Phase 4&#x2014;Management Tinkering</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the EFSA conducted two AML inspections in 2014. The Danish FSA was not asked to attend. The inspections showed significant weaknesses in the branch&#x2019;s AML procedures and led to orders from the EFSA and the replacement of the branch&#x2019;s local management.&#x201D; (<xref rid="B15-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">DFSA, 2019</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders<break/>(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>June 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;At a new audit found a number of customers who &#x201C;should not have been accepted as continuing customers of the branch&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to implement Group Credit Policy </td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>End 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;According to the bank&#x2019;s Board of Directors and Executive Board, the branch&#x2019;s review, completed towards the end of 2014, led to the termination of 853 customer relationships&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to expedite termination policy</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(d) Information difficulties and noise</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Mid 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the Estonian FSA conducted AML inspections at the branch and <bold>was very critical in its reporting</bold>&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings<break/>&#x201C;the Estonian FSA&#x2019;s <bold>critical conclusions were thus still toned down in</bold> the minuted discussions of the Executive Board and in written internal reporting to the Board of Directors.&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Aug. 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Russian Laundromat exposed (<xref rid="B33-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">OCCRP, 2014</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to recognise implications of reporting</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(e) The involvement of strangers<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;a senior employee sent an e-mail to other senior employees at Group Legal and Group Compliance &amp; AML &#x2026; &#x201C;The executive summary of the Estonian FSA letter <bold>is brutal to say the least and is close to the worst I have ever read within the AML/CTF area</bold> (and I have read some harsh letters).&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to internal warnings<break/>&#x201C;According to [omitted], there <bold>was no cause for panic as the findings have been addressed in the ongoing process improvement</bold>. [Omitted] will travel to Estonia and assist the Estonian organisation.&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(c) Disregard of complaints from outsiders <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Oct. 2014</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;In the bank&#x2019;s annual AML report for the period from October 2013 to September 2014, Group Compliance &amp; AML <bold>underlined the AML challenges faced by the</bold> bank, for example in Estonia&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Jan. 2015</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the Board of Directors <bold>did not make a decision</bold>, but noted the Executive Board&#x2019;s <bold>expected close down</bold> of the part of the non-resident portfolio &#x2026;&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to follow-up implementation <break/>&#x201C;<bold>Another year passed before</bold>, in January 2016, the close down was completed&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>May 2015</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;one of the branch&#x2019;s <bold>two correspondent banks informed the bank that it no longer wanted to assist in transactions</bold> with British companies controlled by the branch&#x2019;s Russian customers&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>July 2015</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Estonian FSA &#x2018;harshly&#x2019; criticised AML procedures</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Continued running down Non-Resident Portfolio</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>2015</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Non-Resident Portfolio terminated</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Finally closed early 2016</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2015</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The <bold>other of the two correspondent banks terminated its cooperation</bold> with the branch in &#x2026; due to concerns over the branch&#x2019;s non-resident customers&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2016&#x2013;2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"><bold>Phase 5&#x2014;Management Investigations</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Jan. 2016</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the close down [of non-resident portfolio] was completed &#x2026; as a result [inter alia] of pressure from the Estonian FSA&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>April 2016</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">At the hearing on the Panama Papers in the Danish Parliament&#x2019;s Fiscal Affairs Committee in April 2016, the bank&#x2019;s preliminary investigations <bold>had uncovered only seven customers with companies registered by the Panamanian law firm Mossack Fonseca</bold>&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;<bold>The bank later had to state that the Estonian branch had had more than ten times as many customers with companies established by Mossack Fonseca.</bold>&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(d) Information difficulties and noise <break/>(e) The involvement of strangers<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>April 2016</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danske Bank publicly announced that the bank would scale down its Baltic banking activities, focusing &#x201C;exclusively on supporting subsidiaries of Nordic customers and global corporates with a significant Nordic footprint&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>March 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Reporting of the Russian Laundromat, in the Danish media</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(c) Disregard of complaints from outsiders <break/>(d) Information difficulties and noise <break/>(e) The involvement of strangers<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>April 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the bank hired [external party] to investigate why the bank&#x2019;s controls had failed.&#x201D; </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;However, <bold>the investigation did not cover the extent of suspicious transactions</bold> and customer relations&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(d) Information difficulties and noise <break/>(e) The involvement of strangers</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;A [Danish FSA] inspection was begun following stories in the media about the Azerbaijani case in September 2017&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;As a result of the media coverage of the Azerbaijani case &#x2026; the Danish FSA asked the bank&#x2019;s Board of Directors and Executive Board <bold>for a written statement about this case and more generally about AML handling at the branch</bold>&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The Danish FSA received a statement from the bank on 16 October 2017.&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(d) Information difficulties and noise <break/>(e) The involvement of strangers<break/>(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2017&#x2013;2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"><bold>Phase 6&#x2014;Scandal Emerges</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danske Bank acknowledged that it was &#x201C;major<break/>deficiencies in controls and governance that made it possible to use Danske Bank&#x2019;s branch in Estonia for criminal activities such as money laundering&#x201D; (<xref rid="B9-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2017</xref> )</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Not all information shared &#x2018;for legal reasons&#x2019; related to regulators</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(d) Information difficulties and noise <break/>(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The bank did not initiate an investigation into the transactions until September 2017&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Oct 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;During 2017, the bank has several times provided information or material about the case to the Danish FSA. </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;As a result of <bold>inadequate information being provided to the Danish FSA</bold>, the Danish FSA has found it necessary to <bold>enquire more than once regarding the same issues</bold> in order to receive an adequate reply and to enquire about the bank&#x2019;s knowledge of further cases.&#x201D; </td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(d) Information difficulties and noise <break/>(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Oct. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danske Bank has been placed under investigation by French Authorities</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Subsequently, investigation changed the status of Danske Bank to that of an assisted witness.</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(c) Disregard of complaints from outsiders <break/>(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Nov. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;not until November 2017 [did the bank] initiate an investigation into the course of events and into whether managers or staff had sufficiently lived up to their responsibilities&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Failure to react to warnings</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Dec. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the bank hired a law firm to handle and supervise the investigations.&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Dec. 2017</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;the Danish FSA sent a memorandum entitled &#x201C;Preliminary assessments of the involvement of Danske Bank&#x2019;s management in the AML case at the bank&#x2019;s Estonian branch to Danske Bank&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Feb. 2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The Chief Audit Executive replied on 6 February 2018, and the Board of Directors and the Executive Board replied on 7 February 2018. The reply from the Board of Directors and the Executive Board <bold>included more than 200 pages of annexes</bold>&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;&#x2026; <bold>the bank&#x2019;s investigations of what had happened in the AML area in Estonia were in the initial stages and that the replies to specific questions therefore necessarily were incomplete</bold>&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief <break/>(d) Information difficulties and noise <break/>(e) The involvement of strangers<break/>(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>March 2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The Danish FSA received a reply with a number of general comments on 26 March 2018.<break/>The reply from the Board of Directors and the Executive Board also included more than 600 pages of annexes&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;Danske Bank has <bold>chosen to let the law firm handling the bank&#x2019;s investigations represent the Board of Directors in the case in relation to the Danish FSA</bold>.&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief<break/>(c) Disregard of complaints from outsiders<break/>(d) Information difficulties and noise<break/>(g) Minimising emergent danger</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>April 2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;The process [of answering questions] has thus been rather long&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(f) Failure to comply with discredited or out-of-date regulations</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>May 2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Publication of Danish FSA &#x201C;Danske Bank&#x2019;s management and governance in relation to the AML case at the Estonian branch&#x201D;</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;Danske Bank earlier concluded that, in the period from 2007 to 2015, <bold>it was not sufficiently effective in preventing the branch in Estonia from potentially being used for money laundering</bold> and that this was due to critical deficiencies in governance and controls.&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Publication of Danske internal &#x201C;Report on the Non-Resident Portfolio at Danske Bank&#x2019;s Estonian branch&#x201D; (<xref rid="B10-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Danske Bank, 2018a</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin">&#x201C;According to assessments made, the Board of Directors, the Chairman and the CEO <bold>have not breached their legal obligations</bold> towards the bank&#x201D;</td>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Yes</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief<break/>(c) Disregard of complaints from outsiders</td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Sept. 2018</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">CEO (Thomas Borgen) resigns</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6">
                  <bold>2019&#x2013;&#x2026;</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"><bold>Phase 7&#x2014;Aftermath</bold></td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin;background:#E7E6E6"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Feb. 2019</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Estonian FSA orders Danske Bank to close Estonian branch </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Feb. 2019</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danske Bank in dialogue with US securities industry regulator (SEC)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
              <tr>
                <td align="center" valign="middle" style="border-bottom:solid thin">
                  <bold>Oct. 2019</bold>
                </td>
                <td align="left" valign="middle" style="border-bottom:solid thin">Danske Bank closes Estonian branch (<xref rid="B37-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Reuters, 2019</xref>)</td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="center" valign="middle" style="border-bottom:solid thin"> </td>
                <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
              </tr>
            </tbody>
          </table>
</table-wrap>
      </app>
    </app-group>
    <ref-list>
      <title>References</title>
      <ref id="B1-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Augustine</surname>
              <given-names>N. R.</given-names>
            </name>
          </person-group>
          <article-title>Managing the Crisis you tried to Prevent</article-title>
          <source>Harvard Business Review</source>
          <year>1995</year>
          <volume>73</volume>
          <issue>6</issue>
          <fpage>147</fpage>
          <lpage>158</lpage>
        </element-citation>
      </ref>
      <ref id="B2-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Bank for International Settlements</collab>
          </person-group>
          <source>International Convergence of Capital Measurement and Capital Standards&#x2014;A Revised Framework</source>
          <publisher-name>Bank for International Settlements, Basel Committee on Banking Supervision</publisher-name>
          <publisher-loc>Basel</publisher-loc>
          <year>2004</year>
          <comment>Retrieved from <uri>http://www.bis.org/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B3-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>Blacker</surname>
              <given-names>K.</given-names>
            </name>
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <source>People Risk Management</source>
          <publisher-name>Kogan Page</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>2015</year>
        </element-citation>
      </ref>
      <ref id="B4-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Annual</collab>
          </person-group>
          <source>Annual Report 2006</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <year>2006</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B5-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Annual</collab>
          </person-group>
          <source>Annual Report 2007</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <year>2007</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B6-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Annual</collab>
          </person-group>
          <source>Annual Report 2008</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <year>2008</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B7-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Annual</collab>
          </person-group>
          <source>Annual Report 2018</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <year>2018</year>
<comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B8-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Bank</collab>
          </person-group>
          <source>Risk Management Report 2010</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <year>2010</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B9-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Bank</collab>
          </person-group>
          <source>Danske Bank Expands Investigation of Estonia Branch</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <day>21</day>
          <month>September</month>
 <year>2017</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B10-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Bank</collab>
          </person-group>
          <source>Report on the Non-Resident Portfolio at Danske Bank&#x2019;s Estonian Branch</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <day>19</day>
          <month>September</month>
<year>2018a</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B11-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Bank</collab>
          </person-group>
          <source>Interim Report&#x2014;First Nine Months 2018</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <year>2018b</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B12-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Bank</collab>
          </person-group>
          <source>Conference Call Findings of the Estonia Investigations</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <day>19</day>
          <month>September</month>
<year>2018c</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B13-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>Danske Bank</collab>
          </person-group>
          <source>Danske Bank Appoints Interim CEO</source>
          <publisher-name>Danske Bank</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <day>1</day>
          <month>October</month>
<year>2018d</year>
          <comment>Retrieved from <uri>https://danskebank.com/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B14-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <collab>DFSA</collab>
          </person-group>
          <source>Danske Bank&#x2019;s Management and Governance in Relation to the AML Case at the Estonian Branch</source>
          <publisher-name>Danish Financial Supervisory Authority</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
          <day>3</day>
          <month>May</month>
  <year>2018</year>
          <comment>Retrieved from <uri>https://www.dfsa.dk/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B15-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
<person-group person-group-type="author">
            <collab>DFSA</collab>
          </person-group>
          <source>Report on the Danish FSA&#x2019;s Supervision of Danske Bank as Regards the Estonia Case</source>
         <publisher-name>Danish Financial Supervisory Authority</publisher-name>
          <publisher-loc>Copenhagen</publisher-loc>
 <day>29</day>
          <month>January</month>
  <year>2019</year>
<comment>Retrieved from <uri>https://www.dfsa.dk/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B16-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>Fitzsimmons</surname>
              <given-names>A.</given-names>
            </name>
            <name>
              <surname>Atkins</surname>
              <given-names>D.</given-names>
            </name>
          </person-group>
          <source>Rethinking Reputational Risk: How to Manage the Risks That Can Ruin Your Business, Your Reputation and You</source>
          <publisher-name>Kogan Page</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>2017</year>
        </element-citation>
      </ref>
      <ref id="B17-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>Gleick</surname>
              <given-names>J.</given-names>
            </name>
          </person-group>
          <source>Genius: Richard Feynman and Modern Physics</source>
          <publisher-name>Abacus</publisher-name>
          <year>1992</year>
        </element-citation>
      </ref>
      <ref id="B18-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>Hofstede</surname>
              <given-names>G.</given-names>
            </name>
          </person-group>
          <source>Cultures and Organizations</source>
          <publisher-name>McGraw-Hill</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>1991</year>
        </element-citation>
      </ref>
      <ref id="B19-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="gov">
          <person-group person-group-type="author">
            <name>
              <surname>Kroszner</surname>
              <given-names>R.</given-names>
            </name>
          </person-group>
          <source>Strategic Risk Management in an Interconnected World</source>
          <publisher-name>Federal Reserve Board</publisher-name>
          <publisher-loc>Washington</publisher-loc>
          <month>October</month>
          <year>2008</year>
          <comment><ext-link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.federalreserve.gov/newsevents/speech/kroszner20081020a.htm" ext-link-type="uri">http://www.federalreserve.gov/newsevents/speech/kroszner20081020a.htm</ext-link>
          </comment>
        </element-citation>
      </ref>
      <ref id="B20-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>MacLennan</surname>
              <given-names>A.</given-names>
            </name>
          </person-group>
          <source>Strategy Execution: Translating Strategy into Action in Complex Organizations</source>
          <publisher-name>T &amp; F Books UK</publisher-name>
          <year>2010</year>
        </element-citation>
      </ref>
      <ref id="B21-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>McAndrews</surname>
              <given-names>D. H.</given-names>
            </name>
          </person-group>
          <article-title>Payments Systems</article-title>
          <source>The Oxford Handbook of Banking. Oxford Handbooks in Finance</source>
          <person-group person-group-type="editor">
            <name>
              <surname>Berger</surname>
              <given-names>A. N.</given-names>
            </name>
            <name>
              <surname>Molyneux</surname>
              <given-names>P.</given-names>
            </name>
            <name>
              <surname>Wilson</surname>
              <given-names>J. O. S.</given-names>
            </name>
          </person-group>
          <publisher-name>Oxford University Press</publisher-name>
<edition>Kindle Edition</edition>
          <year>2010</year>
        </element-citation>
      </ref>
      <ref id="B22-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
            <name>
              <surname>Blacker</surname>
              <given-names>K.</given-names>
            </name>
          </person-group>
          <article-title>The role of Systemic People Risk in the Global Financial Crisis</article-title>
          <source>Journal of Operational Risk</source>
          <year>2011</year>
          <volume>6</volume>
          <issue>3</issue>
          <fpage>65</fpage>
          <lpage>123</lpage>
          <pub-id pub-id-type="doi">10.21314/JOP.2011.095</pub-id>
        </element-citation>
      </ref>
      <ref id="B23-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <source>AIB/Allfirst&#x2014;Development of another Disaster</source>
          <series>Henley Working Paper Series</series>
          <publisher-name>Henley Management College</publisher-name>
          <year>2003</year>
        </element-citation>
      </ref>
      <ref id="B24-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <source>NAB&#x2014;Learning from Disaster</source>
          <series>Henley Working Paper Series</series>
          <publisher-name>Henley Management College</publisher-name>
          <year>2005</year>
        </element-citation>
      </ref>
      <ref id="B25-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <article-title>Prime Loss: A Case Study in Operational Risk</article-title>
          <source>Journal of Risk Management in Financial Institutions</source>
          <year>2010</year>
          <volume>3</volume>
          <issue>1</issue>
          <fpage>84</fpage>
          <lpage>104</lpage>
        </element-citation>
      </ref>
      <ref id="B26-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <article-title>Strategic Risk&#x2014;The Beanstalk Syndrome</article-title>
          <source>Journal of Risk Management in Financial Institutions</source>
          <year>2013</year>
          <volume>6</volume>
          <issue>3</issue>
          <fpage>229</fpage>
          <lpage>252</lpage>
        </element-citation>
      </ref>
      <ref id="B27-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <article-title>Dissecting the JPMorgan Whale: A post-mortem</article-title>
          <source>Journal of Operational Risk</source>
          <year>2014</year>
          <volume>9</volume>
          <issue>2</issue>
          <fpage>59</fpage>
          <lpage>100</lpage>
          <pub-id pub-id-type="doi">10.21314/JOP.2014.144</pub-id>
        </element-citation>
      </ref>
      <ref id="B28-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <source>Systemic Operational Risk</source>
          <publisher-name>Risk Books</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>2015</year>
        </element-citation>
      </ref>
      <ref id="B29-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <source>Strategic Risk Management</source>
          <publisher-name>Risk Books</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>2016</year>
        </element-citation>
      </ref>
      <ref id="B30-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>McConnell</surname>
              <given-names>P. J.</given-names>
            </name>
          </person-group>
          <source>Strategic Technology Risk</source>
          <publisher-name>Risk Books</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>2017</year>
        </element-citation>
      </ref>
      <ref id="B31-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="gov">
          <person-group person-group-type="author">
            <name>
              <surname>Nyberg</surname>
              <given-names>L.</given-names>
            </name>
          </person-group>
          <source>Misjudging Risk: Causes of the Systemic Banking Crisis in Ireland</source>
          <publisher-name>Ministry of Finance</publisher-name>
          <publisher-loc>Dublin</publisher-loc>
          <month>March</month>
 <year>2011</year>
          <comment>Retrieved from <uri>http://www.bankinginquiry.gov.ie/Documents/Misjuding%20Risk%20-%20Causes%20of%20the%20Systemic%20Banking%20Crisis%20in%20Ireland.pdf</uri></comment>
        </element-citation>
      </ref>
      <ref id="B32-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="gov">
          <person-group person-group-type="author">
            <collab>OCC</collab>
          </person-group>
          <source>Large Bank Supervision&#x2014;Comptrollers Handbook</source>
          <publisher-name>Office of the Comptroller of the Currency</publisher-name>
          <publisher-loc>Washington, DC</publisher-loc>
          <year>2010</year>
          <comment>Retrieved from <uri>https://www.occ.gov/publications-and-resources/publications/comptrollers-handbook/files/large-bank-supervision/index-large-bank-supervision.html</uri></comment>
        </element-citation>
      </ref>
      <ref id="B33-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <collab>OCCRP</collab>
          </person-group>
          <article-title>The Russian Laundromat. Organized Crime and Corruption Reporting Project</article-title>
          <year>2014</year>
          <comment>Retrieved from <uri>https://www.occrp.org/en/laundromat/russian-laundromat/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B34-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <collab>OCCRP</collab>
          </person-group>
          <article-title>The Russian Laundromat Exposed. Organized Crime and Corruption Reporting Project</article-title>
          <year>2017</year>
          <comment>Retrieved from <uri>https://www.occrp.org/en/laundromat/the-russian-laundromat-exposed/</uri></comment>
        </element-citation>
      </ref>
      <ref id="B35-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <collab>OCCRP</collab>
          </person-group>
          <article-title>Russia Laundered Millions via Danske Bank Estonia. Organized Crime and Corruption Reporting Project</article-title>
          <year>2018</year>
          <comment>Retrieved from <ext-link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://www.occrp.org/en/investigations/7698-report-russia-laundered-billions-via-danske-bank-estonia" ext-link-type="uri">https://www.occrp.org/en/investigations/7698-report-russia-laundered-billions-via-danske-bank-estonia</ext-link></comment>
        </element-citation>
      </ref>
      <ref id="B36-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="book">
          <person-group person-group-type="author">
            <name>
              <surname>Rankine</surname>
              <given-names>D.</given-names>
            </name>
            <name>
              <surname>Howson</surname>
              <given-names>P.</given-names>
            </name>
          </person-group>
          <source>Acquisition Essentials: A Step-by-Step Guide to Smarter Deals</source>
          <edition>2nd ed.</edition>
          <publisher-name>Pearson Educational</publisher-name>
          <publisher-loc>London</publisher-loc>
          <year>2014</year>
        </element-citation>
      </ref>
      <ref id="B37-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <collab>Reuters</collab>
          </person-group>
          <article-title>Danske Bank Has Exited Its Banking Activities in Estonia</article-title>
          <day>1</day>
          <month>October</month>
 <year>2019</year>
          <comment>Retrieved from <uri>https://www.reuters.com/article/brief-danske-bank-has-exited-its-banking/brief-danske-bank-has-exited-its-banking-activities-in-estonia-idUSC7N1V001S</uri></comment>
        </element-citation>
      </ref>
      <ref id="B38-J_Bus_Account_Financ_Perspect-2-17">
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Turner</surname>
              <given-names>B.</given-names>
            </name>
          </person-group>
          <article-title>The Organisational and Interorganisational Development of Disasters</article-title>
          <source>Administrative Science Quarterly</source>
          <year>1976</year>
          <volume>21</volume>
          <fpage>387</fpage>
          <lpage>397</lpage>
          <pub-id pub-id-type="doi">10.2307/2391850</pub-id>
        </element-citation>
      </ref>
    </ref-list>
    <sec sec-type="display-objects">
      <title>Figure and Table</title>
      <fig id="J_Bus_Account_Financ_Perspect-2-17-f001" position="float">
        <label>Figure 1</label>
        <caption>
          <p>The Danske Laundromat.</p>
        </caption>
        <graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="image001.jpg"/>
      </fig>
      <table-wrap id="J_Bus_Account_Financ_Perspect-2-17-t001" position="float">
        <object-id pub-id-type="pii">J_Bus_Account_Financ_Perspect-2-17-t001_Table 1</object-id>
        <label>Table 1</label>
        <caption>
          <p>Common features in the development of a disaster.</p>
        </caption>
        <table>
          <thead>
            <tr>
              <th align="left" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Stage</th>
              <th align="left" valign="middle" style="border-top:solid thin;border-bottom:solid thin">Features Common to Disasters</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left" valign="middle" style="border-bottom:solid thin"><bold>1. Initial Beliefs and Norms</bold><break/>Culturally accepted beliefs and precautionary norms and procedures</td>
              <td align="left" valign="middle" style="border-bottom:solid thin">Failure to comply with existing regulations</td>
            </tr>
            <tr>
              <td align="left" valign="middle" style="border-bottom:solid thin"><bold>2. Incubation Period</bold><break/>The accumulation of an unnoticed set of events which are at odds with the accepted beliefs </td>
              <td align="left" valign="middle" style="border-bottom:solid thin">(a) Rigidities of belief<break/>(b) Decoy phenomena<break/>(c) Disregard of complaints from outsiders<break/>(d) Information difficulties and noise<break/>(e) The involvement of strangers<break/>(f) Failure to comply with discredited or out-of-date regulations<break/>(g) Minimising emergent danger</td>
            </tr>
            <tr>
              <td align="left" valign="middle" style="border-bottom:solid thin"><bold>3. Precipitating Event</bold><break/>The event that forces itself to public attention </td>
              <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
            </tr>
            <tr>
              <td align="left" valign="middle" style="border-bottom:solid thin"><bold>4. Onset</bold><break/>The immediate consequences of the collapse of &#x201C;cultural precautions&#x201D; becomes apparent</td>
              <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
            </tr>
            <tr>
              <td align="left" valign="middle" style="border-bottom:solid thin"><bold>5. Rescue and Salvage</bold><break/>The immediate post collapse situation when rescue attempts begin</td>
              <td align="left" valign="middle" style="border-bottom:solid thin"> </td>
            </tr>
            <tr>
              <td align="left" valign="middle" style="border-bottom:solid thin"><bold>6. Full Cultural Adjustmen</bold>t<break/>An inquiry is carried out and beliefs are adjusted.</td>
              <td align="left" valign="middle" style="border-bottom:solid thin">The establishment of a new level of precautions</td>
            </tr>
          </tbody>
        </table>
        <table-wrap-foot>
          <fn>
            <p>Source: <xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">Turner</xref> (<xref rid="B38-J_Bus_Account_Financ_Perspect-2-17" ref-type="bibr">1976</xref>) Tables 1 and 2, pages 381 and 391.</p>
          </fn>
        </table-wrap-foot>
      </table-wrap>
    </sec>
  </back>
  </article>
