A shop owner receives a request from a payment provider for fresh company details. Turnover has risen, foreign orders are more common, and the provider wants to understand the change. To the owner, it may feel like another administrative interruption. Inside the payment firm, that same information may decide whether thousands of payments are measured against the right risk profile.
That connection matters after De Nederlandsche Bank published its enforcement decision concerning CCV Group on 13 July 2026. DNB imposed an administrative fine of €2,656,250 for shortcomings in ongoing transaction monitoring under Article 3(2) of the Wwft. CCV filed an objection on 6 March 2026. The case remains in that process.
The failure before the alert
The striking part is not the size of the fine. It is where the control chain broke.
DNB found that CCV’s monitoring system was not fully and promptly supplied with all merchant transactions for more than two years. For 23 months, transaction profiles for 4,200 merchants, around 8 per cent of its merchant base, were not correctly loaded. A monitoring engine cannot assess payment activity properly when transactions or customer profiles are missing from its view.
This makes the decision a story about data and responsibility before it becomes an alert story. Compliance staff can review only what reaches them. When the merchant profile is stale, incomplete or absent, the system compares real payments with an unreliable picture of the customer.
An alert may work exactly as designed and still rest on the wrong foundation. The problem starts earlier, in the connection between customer records, transaction feeds and the risk profile that gives those payments meaning.
DNB also identified weaknesses after alerts had been generated. Its decision describes insufficient closure reasoning, referrals that were not subsequently assessed, and bulk closures without transaction-specific analysis.
That creates a second break in the chain. A firm may have activity, an alert and a closed case, yet still lack a clear record of who examined the risk and why the conclusion was reasonable.
Software does not own the judgement
The Wwft requires ongoing monitoring of the business relationship and its transactions. The institution must assess whether transactions fit what it knows about the client and the client’s risk profile. Where necessary, it must also investigate the source of funds.
The law leaves room for different systems and alert thresholds. That flexibility is sensible, but it places responsibility squarely with the firm. Installed software does not settle the matter. Someone must own the completeness of the inputs, the quality of the profile, the treatment of exceptions and the final judgement.
DNB’s wider sector findings, published in March 2026, give the CCV decision a broader context. The supervisor found shortcomings at a substantial number of payment and electronic-money institutions, particularly in transaction monitoring, risk assessment and customer due diligence. DNB said that basic processes were not in order at many payment institutions, despite earlier supervisory signals.
Growth adds pressure. Payment services increasingly run through platforms, distributors and partner relationships. Every handoff can widen the distance between the customer relationship and the licensed institution that carries the legal responsibility.
A partner may collect documents or manage daily customer contact. Yet where the end user is the licensed institution’s customer, DNB expects that institution to remain responsible for acceptance, risk profiles and client review. Outsourcing a workflow does not outsource the judgement.
The record behind the decision
Large reporting numbers can create a false sense of control. FIU-Nederland received 3,055,362 unusual-transaction reports in 2025. Payment service providers were the largest reporting group, with 1,386,790 reports.
Those figures reflect international payment flows, reporting methods and retrospective reports after supervisory directions. For payment providers, 90 per cent of reported unusual transactions had no direct Dutch link through the sender or beneficiary. Dutch payment infrastructure reaches far beyond the domestic market.
Volume therefore tells only part of the story. A firm can produce many alerts or reports while its staff still struggle to explain whether each decision followed from complete data and current customer knowledge.
The stronger question is quieter. Can the firm reconstruct the route from transaction to profile, from profile to alert, and from alert to a named decision? If that route crosses several systems, partner teams or manual transfers, the board should know where information can disappear.
Compliance cannot restore a missing transaction feed at the end of the process. Nor can a well-written procedure repair a customer record that was never updated when the business changed.
What the merchant sees
Return to the shop owner asked for updated information. The request may be clumsy or repetitive, but its purpose is clear. A payment provider needs to understand whether changed turnover, new countries, different products or unusual payment patterns still fit the known business.
Merchants make that work easier when ownership details, business activities and explanations for major trading changes remain coherent across their records. It saves time when the provider asks questions. It also reduces the chance that ordinary growth starts looking like unexplained activity.
For founders inside regulated payment firms, the lesson is sharper. Remediation cannot end with clearing an alert backlog or rewriting procedures. The real test sits in daily operations: do transaction feeds reconcile, do merchant profiles stay current, do referrals reach an accountable reviewer, and can closure reasons withstand later examination?
Earlier enforcement raises the standard for proving that repair will last. A board needs more than a project plan. It needs evidence that the customer picture, payment data and human judgement now meet each other in the same working process.
The CCV decision remains under objection. Its business lesson is already clear. Transaction monitoring does not begin when a warning flashes on a screen. It begins when a firm decides who owns the customer picture, who checks that the data arrived, and who is willing to put a reasoned name behind the final decision.
Need a practical review of payment controls, customer files or partner handoffs? Speak with our team
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
