<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>5.2  Activity: Danske Bank case study by Gia Instructor</title>
      <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph</link>
      <description>Systems Thinking &amp; Viability</description>
      <language>en-us</language>
      <pubDate>2024-10-14 04:08:46 UTC</pubDate>
      <lastBuildDate>2026-08-10 21:58:38 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Question 1</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3377895613</link>
         <description><![CDATA[<p>The Danske Bank money laundering scandal and the lack of oversight and internal controls demonstrates failure relating to the following ASX principles: </p><p>• Principle 3: Instill a culture of acting lawfully, ethically and responsibly – criminal behaviour went undetected by staff at all levels, with negligence and possible collusion reported. </p><p>• Principle 4: Safeguard the integrity of corporate reports – the Estonian branch was reporting far greater profits than any other European branch, but this was in reality not the case. </p><p>• Principle 7: Recognise and manage risk – the risk of money laundering was not adequately addressed by internal controls, such as a separate and less secure IT system for the Estonian branch as opposed to the rest of Danske Bank, failure to effectively monitor and screen transactions to ensure they matched information on customer and business profiles, and failure to provide the Board with information from a whistleblower.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-03-23 08:07:58 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3377895613</guid>
      </item>
      <item>
         <title>Question 2</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3377899897</link>
         <description><![CDATA[<p>This case is a clear example of the <strong>Swiss cheese model</strong>, where the levels of defence failed to hold up to prevent, detect or correct the risk of money laundering within this particular branch of Danske Bank.</p><p><br/></p><p>There appeared to also be a <strong>lack of appropriate feedback</strong> within the control system, demonstrated by a lack of ability or willingness to provide assurance at any level of the activities which were being undertaken by the branch. For a financial institution, performance metrics which appear to be too good to be true should ideally be subjected to audit and assurance activities to provide confidence to the Board and senior management that they are performing as intended.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-03-23 08:17:30 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3377899897</guid>
      </item>
      <item>
         <title>Q1</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3504896439</link>
         <description><![CDATA[<p>The Danske Bank failure could most sensibly be described as a failure of the organisation to adhere to sufficient risk management controls in alignment with the ASX Principle 7 - Recognise and Manage Risk. </p>]]></description>
         <enclosure url="" />
         <pubDate>2025-06-29 03:23:30 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3504896439</guid>
      </item>
      <item>
         <title>Q2</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3504898158</link>
         <description><![CDATA[<p>The failure of multiple layers of risk management controls can be viewed through the Swiss Cheese model, where controls were not adequate and subsequently the fraudulent activity continued undetected.</p><p><br/></p><p>In addition, the archetype of drifting goals can be applied as the bank clearly did not detect that the ethical standards of the organisation had been compromised (presumably in favour of short term financial gain), allowing behaviours that contributed to the fraudulent activity.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-06-29 03:32:05 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3504898158</guid>
      </item>
      <item>
         <title>Q1</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3529763654</link>
         <description><![CDATA[<p>The failures relate to Principles 1 (foundations for management and oversight), 3 (lawful, ethical and responsible culture) and 7 (recognise and manage risk). Taking the swiss cheese model, failures against all of these three principles enabled criminal money-laundering to continue unabated.</p><p><br/></p><p>From a systems perspective, a control systems diagram could be applied to Danske Bank's acquisitions process, with analysis of the customer portfolio - desired output being 'customer profile complies to DB's expectation, and regular measurement of deviations from that. Another desired output response would be ' acquired bank onboarded into DB's IT architecture and reporting systems'. These systems tools as part of management practice would have guided a more appropriate and risk-focused acquisitions process.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-07-28 02:54:24 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3529763654</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3529768825</link>
         <description><![CDATA[<p>The Swiss Cheese Model shows the cumulative effect of flaws in the risk management approach to this acquisition.</p><p>The financial performance of Sampo Bank, which was outperforming the rest of the banking sector in Europe at the time should have been a red flag for Danske Bank's board and management, but instead the 'shifting the burden' archetype seems to have been in play - they looked only at the surface results and did not look at this anomalous result as indicative of a problem symptom</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-07-28 03:00:57 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3529768825</guid>
      </item>
      <item>
         <title>Q1</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3636981944</link>
         <description><![CDATA[<p>The Principle 3 of having a Culture to Act Lawfully, ethically and responsibly was not followed by the bank. It would appear that unethical practices were encouraged and rewarded, and probably was done by way of collusion by key staff members.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-17 04:00:52 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3636981944</guid>
      </item>
      <item>
         <title>Q2</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3636985035</link>
         <description><![CDATA[<p>It would appear that a type of Swiss Cheese scenario took place with multiple failures in multiple systems, which were either undetected or ignored for personal gain.</p><p>A good risk management system would be robust enough to have checks and balances in place to make sure money laundering could not and would not take place, particularly if risk mitigation systems are in place and there is a culture of ethics and responsibility.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-17 04:03:30 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3636985035</guid>
      </item>
      <item>
         <title>There are 3 principles here the bank did not adhere to and the result was serious.  Lay solid foundations for management there was a lack of oversight and internal controls. Principle 3 instil a culture of acting lawfully, ethically and responsibly it was clear there had been a violation of the law here. Principle 4 corporate reporting again lack of oversight led to poor or fraudulent reporting. </title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3737814484</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2026-01-05 03:16:05 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3737814484</guid>
      </item>
      <item>
         <title>I would start by reinforcing the interconnectedness of all systems such as the simple action of opening and international account if not checked properly leads to fraud.  Then systems mapping / Context diagram for visualising boundaries and elements of the system also introduce feedback loops to encourage staff transparency </title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3737818913</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2026-01-05 03:20:37 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3737818913</guid>
      </item>
      <item>
         <title>4 Principles</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3980634135</link>
         <description><![CDATA[<p>The scandal highlights failures in Principle 7 (Recognise and Manage Risk) due to inadequate risk management and internal controls, and Principles 1 (Lay Solid Foundations for Management and Oversight), 2 (Structure the Board to Add Value) and 3 (Instil a Culture of Acting Lawfully, Ethically and Responsibly) due to weak governance oversight, accountability, escalation processes and ethical culture. These failures allowed significant money laundering activity to go undetected.</p>]]></description>
         <enclosure url="" />
         <pubDate>2026-07-13 03:29:18 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3980634135</guid>
      </item>
      <item>
         <title>Swiss cheese + Reinforcing loop</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3980637680</link>
         <description><![CDATA[<ul><li><p><strong>Swiss Cheese Model</strong> – failures in governance, risk management, internal controls and regulatory oversight all aligned, allowing ongoing money laundering over an extended period.</p></li><li><p><strong>Reinforcing Loop</strong> – the continued acceptance of high-risk transactions reinforced lack of controls and unlawful conduct and allowed the problem to grow over time.</p></li></ul>]]></description>
         <enclosure url="" />
         <pubDate>2026-07-13 03:31:59 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/3980637680</guid>
      </item>
      <item>
         <title>Q1</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/4002348670</link>
         <description><![CDATA[<p>Principle 7 (Risk Management) failed because governance structures did not identify, escalate and manage known risks. Failure indicators:</p><ul><li><p>Ineffective risk identification and monitoring.</p></li><li><p>Weak AML control environment.</p></li><li><p>Poor due diligence and customer screening.</p></li><li><p>Failure to act on known risk information. </p></li></ul><p><br/></p><p>Principle 3 (Culture and Ethics) explains why those failures were allowed to persist. Failure indicators:</p><ul><li><p>Compliance concerns were overridden by business objectives.</p></li><li><p>Ethical obligations were not embedded into decision-making.</p></li><li><p>Warning signs were repeatedly ignored.</p></li></ul>]]></description>
         <enclosure url="" />
         <pubDate>2026-08-10 00:20:54 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/4002348670</guid>
      </item>
      <item>
         <title>Q2</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/4002353297</link>
         <description><![CDATA[<p>The Swiss Cheese Model explains how multiple control failures aligned to allow the money laundering activities to occur. Weaknesses existed across governance, risk management, compliance, internal audit and regulatory oversight, creating a pathway for suspicious transactions to go undetected.</p><p>The shifting the burden archetype is evident in the focus on financial performance over underlying control weaknesses. Strong profits masked emerging risks, causing management attention to remain on short-term results rather than addressing root causes such as poor AML controls and governance failures.</p><p>The case demonstrates ineffective feedback loops, with warning signs from whistleblowers, compliance teams and external parties either not escalated or not acted upon. As a result, the Board and senior management lacked accurate visibility of the risks within the Estonian branch.</p>]]></description>
         <enclosure url="" />
         <pubDate>2026-08-10 00:31:59 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/pcc9yqgiekxcz8ph/wish/4002353297</guid>
      </item>
   </channel>
</rss>
