The £3.84 million ENEX forfeiture by the National Crime Agency highlights a critical issue: many compliance teams still rely on outdated assumptions about sanctions evasion and money laundering. When ENEX Premium Trading Limited opened UK accounts in mid-2024, the funds seemed legitimate. However, the NCA later traced these funds back through Chinese accounts to suspected front companies involved in Iranian oil sales, by which time the money had already passed through multiple jurisdictions and converted into cryptocurrency.
These myths persist because they once reflected simpler compliance environments. A name-match system caught most sanctioned parties, and source-of-funds verification was straightforward. Cryptocurrency was often ignored. But as the ENEX investigation shows, these assumptions now create dangerous blind spots.
Myth 1: If the sanctions screening comes back clean, the customer is clear
Reality: Sanctions lists change daily, and the riskiest connections often emerge after onboarding.
The companies that paid into ENEX's Chinese accounts were designated under US sanctions after the transactions occurred. A screening system that checked names at account opening would have produced clean results, but that didn't mean the risk was absent.
Effective sanctions controls require continuous re-screening against updated lists. Even then, a US designation doesn't automatically create a UK asset freeze obligation, yet it provides significant financial crime intelligence. When OFAC designates a counterparty for illicit activities, that information should immediately feed back into your AML risk assessment and transaction monitoring, regardless of direct legal obligations.
Myth 2: Recording source of funds equals verifying source of funds
Reality: There's a critical difference between documenting what a customer tells you and establishing whether it's credible.
When ENEX opened its UK accounts, the stated source of funds was personal wealth and retained earnings from previous trading structures, including a UAE-registered entity. For compliance teams, "personal wealth" provides almost no meaningful information about a specific multi-million-pound transfer. "Retained earnings" offers slightly more, but a higher-risk situation requires you to establish which company generated those earnings, through what activity, during which period, and how the money subsequently traveled to the account being funded.
This can require financial statements, contracts, invoices, tax records, or banking documentation depending on the risk profile. The NCA ultimately traced the UK funds back to Chinese accounts that had received tens of millions of pounds from suspected front companies. A plausible description at onboarding cannot substitute for understanding the actual provenance of money moving through an account.
Myth 3: Your customer relationship is with the account holder, not their funding sources
Reality: Sanctions evasion typically occurs several steps removed from the customer facing your institution.
The immediate account holder may appear entirely legitimate. The direct payer may be another seemingly ordinary commercial company. The sanctioned connection often sits two or three entities further back in the transaction chain.
This is exactly what the Financial Conduct Authority identified in its May 2025 review of sanctions controls across more than 150 firms. Among the evasion techniques: using third parties and intermediaries to obscure sanctioned connections and routing funds through cryptoasset or e-money wallets. For higher-risk relationships, you need to understand not only who your customer is, but who is funding them, where that money originated, and whether the transaction pattern makes sense against their stated business model.
Myth 4: Individual red flags need to be serious before you escalate
Reality: Money laundering risk emerges from cumulative patterns, not single decisive indicators.
Consider the ENEX profile: substantial sums arriving in recently opened accounts over a short period, a corporate structure spanning St Kitts and Nevis, the UAE, China, and the UK, funds deriving from "previous trading structures" rather than straightforward operating revenue, payments originating through suspected front companies, transaction flows involving electronic money institutions followed by cryptocurrency conversion, and adverse media concerning associated businesses.
None of those factors alone proves criminality. Their cumulative effect should trigger enhanced scrutiny. UK AML regulations require enhanced due diligence where transactions are unusually large or complex relative to context, where there's an unusual pattern, or where activity lacks apparent economic purpose. Enhanced measures include obtaining additional source-of-funds information and increasing ongoing monitoring frequency.
Myth 5: Cryptocurrency is a separate compliance domain
Reality: Crypto conversion is often the stage where traditional transaction monitoring loses visibility into the highest-risk activity.
The ENEX investigation identified a network of suspected front companies and bank accounts moving transactions through UK electronic money institutions before converting funds into cryptocurrency. The FCA and other UK authorities have specifically warned that cryptoassets can be used to circumvent sanctions, identifying transactions involving high-risk wallets, obfuscation techniques, and activity inconsistent with customer profiles as warning signs.
An AML system monitoring fiat payments without understanding what happens when funds move into crypto can miss the very stage that presents the greatest laundering or sanctions-evasion risk. This isn't theoretical. In 2024, CB Payments Limited was fined more than £3.5 million after control failures resulted in thousands of high-risk customers conducting hundreds of millions of dollars of cryptoasset transactions through related entities.
Myth 6: Sophisticated screening technology eliminates the need for human judgment
Reality: Automation solves one problem while creating another.
In January 2025, the Office of Financial Sanctions Implementation imposed a £160,000 penalty on Bank of Scotland after automated screening failed to identify a spelling variation of a designated individual's name. OFSI highlighted weaknesses in screening, escalation, and training, urging firms to consider whether systems could handle transliteration variants.
The ENEX case presents the opposite challenge. A sophisticated screening system may have worked exactly as designed and still not identified companies that hadn't yet been designated. Sanctions programs need both list-matching technology and broader risk intelligence that considers transaction patterns, geographic pathways, business model coherence, and emerging typologies.
What to do instead
Build a compliance program that treats risk as dynamic rather than static. Re-screen customers against updated sanctions lists regularly, not just at onboarding. Establish actual source of funds through documentation, not just customer statements. For higher-risk relationships, trace transaction chains backward beyond your immediate customer. Monitor for patterns that collectively signal risk, even when individual indicators seem minor. Understand where customer funds go after they leave your visibility, particularly into cryptocurrency. And ensure your screening technology includes human review protocols that can identify risks the algorithm wasn't designed to catch.
The ENEX forfeiture represents suspected money laundering and sanctions evasion, not a proven case. But it illustrates exactly why your compliance controls need to evolve beyond the myths that once seemed sufficient.



