Corporate Compliance Rules Every Business Must Follow

Corporate Compliance Rules Every Business Must Follow

According to data analyzed by Protecht US businesses paid $345 billion in corporate fines between 2020 and 2024. That’s 180,000+ enforcement actions in five years.

And the companies that got hit the hardest? Most of them already had compliance programs. Written policies. Legal teams. Internal audits. The problem was never awareness — it was that nobody was actually doing what the policy said.

TD Bank? $3.09 billion gone because their anti-money laundering system hadn’t been updated since 2014. Cummins? $1.675 billion — largest Clean Air Act fine ever — for rigging emissions software on nearly a million trucks. Meta? €1.2 billion from EU regulators for moving European user data into the US without proper protections.

Combined bill for those three: over $6 billion.

Same story each time. Leadership knew about the gaps. Chose not to fix them.

That doesn’t fly anymore.

Which Compliance Failures Actually Cost the Most?

Not all violations hit equally. Some get you a warning letter. Others end careers and drain billion-dollar reserves. Here’s what regulators have been going after hardest:

AreaFineCompanyWhat Happened
Anti-Money Laundering$3.09B (2024)TD Bank92% of transactions unmonitored for a decade
Environmental$1.675B (2024)CumminsDefeat devices on 630,000+ diesel trucks
Data Privacy~$1.3B (2023)MetaEU user data shipped to US without GDPR protections
Workplace Safety$50M (2024)American AirlinesRepeated violations of disabled passengers’ rights
Financial ReportingOngoingMultipleWeak SOX controls, AI audit risks climbing

Every company on this list had a compliance department. Didn’t matter.

TD Bank Ignored Its Own AML Systems for a Decade — Here’s What That Cost

This one’s worth understanding in detail because the failure pattern is so common.

TD Bank’s automated monitoring was supposed to catch suspicious transactions. Instead, between 2018 and 2024, it missed 92% of total transaction volume. That’s $18.3 trillion in activity — just… unwatched. Three criminal networks moved $670 million through the bank during that period. Five bank employees actively helped one network launder $39 million to Colombia.

Why? TD’s leadership ran what they called a “flat cost paradigm.” Compliance budget stays the same every year. Doesn’t matter that the bank is growing, adding Zelle, expanding its customer base, entering new markets. The AML spending cap doesn’t move.

Their own internal auditors flagged this. Repeatedly. Management’s response? Gradually reduce the backlog. Not fix the system — just chip away at the pile of alerts nobody was looking at.

Attorney General Merrick Garland put it bluntly: “By making its services convenient for criminals, TD Bank became one.”

The damage went beyond fines:

  • $1.43 billion criminal penalty to the DOJ
  • $452 million in forfeitures
  • $1.3 billion civil penalty to FinCEN
  • $434 billion asset cap from the OCC — the bank literally can’t grow its US operations until regulators approve the fix
  • Five years of probation. Three years of independent monitoring.

TD originally set aside $450 million for this. The final number was nearly seven times higher.

The takeaway is uncomfortable but simple. When the compliance budget stays flat while the business grows, the gap isn’t theoretical. It’s guaranteed. And regulators will find it.

Cummins Put Defeat Devices on 630,000 Trucks — The EPA Noticed

Cummins makes the diesel engines in RAM 2500 and 3500 pickup trucks. From 2013 to 2023, those engines had software that dialed back emissions controls during normal driving but performed perfectly during EPA testing.

The catch? After the Volkswagen diesel scandal in 2015, the EPA started running non-standard driving tests at its National Vehicle and Fuel Emissions Laboratory. Not the predictable lab simulations manufacturers prep for — actual real-world driving conditions. That’s how the defeat devices got caught.

Total bill: over $2 billion.

  • $1.675 billion in civil penalties (largest Clean Air Act fine in history)
  • $326 million+ for recall programs and emissions mitigation
  • Must repair 85% of affected vehicles within three years
  • Fund replacement of 27 old diesel locomotive engines
  • Complete 50 locomotive idle-reduction projects

Cummins said it found no evidence employees acted in bad faith. The EPA’s view? The software was designed to behave differently during testing than during real use. That’s the definition of a defeat device.

Bottom line: Environmental compliance isn’t a one-time certification. Regulators are testing smarter now. The space between “passing the test” and “actually meeting the standard” is exactly where billion-dollar fines sit.

Meta’s €1.2 Billion GDPR Fine Started With a 2020 Court Ruling They Didn’t React To

In 2020, the EU’s highest court struck down the Privacy Shield framework in the Schrems II decision. That ruling said US surveillance practices made standard data transfer agreements inadequate for protecting European citizens’ data.

Meta kept transferring data anyway, relying on Standard Contractual Clauses (SCCs) that regulators had already flagged as insufficient.

Three years later — €1.2 billion fine. Largest GDPR penalty ever imposed.

The European Data Protection Board described the violation as “systematic, repetitive and continuous.” Millions of Facebook users affected. Massive data volumes involved.

Meta’s appealing. They’ve also adopted the new EU-US Data Privacy Framework introduced in July 2023. But that framework’s survival is shaky — privacy advocate Max Schrems is preparing a “Schrems III” challenge, and the US surveillance law supporting the agreement expires in April 2026.

What matters for every other business: A company headquartered in the US can face European enforcement if it handles EU data. PwC’s 2025 survey found 51% of executives now rank data privacy as their top compliance risk. Treating international data transfers as purely an IT decision is the same bet Meta made. We know how that turned out.

Data Protection Rules That Actually Apply to Your Business

Skip the theory. Here’s what regulators enforce:

  • Get real consent. Not buried-in-terms-of-service consent. Informed, clear, opt-in consent before collecting personal data.
  • Give people control. GDPR and CCPA both require you to let individuals access, correct, and delete their information. This has to actually work — not just exist as a form on your website.
  • Report breaches fast. GDPR gives you 72 hours from discovery. Miss that window and you’re looking at a separate penalty on top of whatever caused the breach.
  • Run privacy audits. Document your data processing. Know where personal data lives, who has access, and what security protects it.
  • Watch the AI angle. Automated decision-making, AI-powered tools processing personal data, and cross-border data sharing all create new regulatory exposure that barely existed five years ago.

What SOX and Tax Compliance Actually Require

Public companies follow GAAP or IFRS depending on jurisdiction. The Sarbanes-Oxley Act adds teeth — executives are personally liable for the accuracy of financial statements. Not the company. The individual.

That distinction matters more than most people realise. A corporate fine hits the balance sheet. SOX liability can hit the CFO’s personal freedom.

KPMG flagged a growing risk here: AI in financial reporting. Companies are adopting AI tools for calculations, risk modeling, and audit support. That creates efficiency — and also introduces bias, algorithmic errors, and fraud vectors that SOX internal controls now need to cover. If your AI produces an inaccurate number and it ends up in a filing, someone’s still signing off on it.

Tax compliance spans federal, state, and local. Multi-state operations create nexus issues — you might owe taxes in a state where you have no office but hit a revenue threshold. Miss that and the interest alone compounds fast.

OSHA, Wages, and Worker Classification — Where Employment Law Bites

OSHA handles physical safety — safe conditions, proper training, protective equipment. That’s the obvious part.

The less obvious part is where most penalties actually come from:

  • Worker misclassification. Calling employees “independent contractors” to dodge benefits and tax obligations. The IRS, DOL, and state agencies all investigate this, and penalties compound across every misclassified worker and every pay period.
  • Wage and hour violations. Overtime miscalculations, meal break violations, off-the-clock work. These get expensive fast in class action suits.
  • Recordkeeping gaps. Payroll records, time tracking, safety logs, training documentation, harassment complaints — all need to be maintained and accessible. Missing records are treated as evidence of the violation, not ignorance of it.

For compliance professionals who want deeper legal grounding, online Juris Doctor program sharpens the ability to interpret regulations and manage legal risk. Programs like Cleveland State University’s online J.D. combine flexibility with rigorous training — their curriculum includes six residential weekends alongside online coursework, lawyering skills intensives, and alumni networking.

AML and Anti-Corruption After the TD Bank Fallout

The TD Bank case made the business argument for AML investment painfully clear. But the obligations go beyond banking.

The Bank Secrecy Act, USA PATRIOT Act, and FCPA apply to financial services, manufacturing, healthcare, and any company with international operations. The practical requirements:

  • Know Your Customer (KYC) during onboarding — verify identities, assess risk profiles
  • Transaction monitoring for suspicious patterns — not a static system set up once and ignored for eight years
  • Suspicious Activity Reports (SARs) filed when red flags appear
  • Anti-bribery policies covering kickbacks, conflicts of interest, and third-party vendor relationships
  • Regular risk assessments that actually change what the company does, not just produce a report

US regulators issued $4.3 billion in financial penalties in 2024 alone. Bank-specific penalties surged 522% year over year. Transaction monitoring fines doubled. That trajectory isn’t slowing down.

Environmental Compliance Is Shifting — But EPA Enforcement Isn’t

Two things happening at once here, and they point in opposite directions.

  • On one side: The EPA settled the largest Clean Air Act penalty in history with Cummins. Air permits, discharge limits, hazardous materials handling — all actively enforced with real financial consequences.
  • On the other: In March 2025, the SEC voted to stop defending rules that would’ve required companies to disclose climate-related emissions and risks. Industrial lobbying groups and Republican state attorneys general argued the rules overstepped the SEC’s authority. The case is pending in the US Court of Appeals.

So mandatory climate disclosure? Uncertain. EPA enforcement of existing environmental law? Unchanged and, if anything, escalating.

Many companies are hedging by adopting voluntary sustainability goals — driven by investors, supply chain partners, and customers rather than regulation. That approach works regardless of how the SEC case resolves.

How to Build a Compliance Program That Doesn’t Just Exist on Paper

Every company in the case studies above had compliance on paper. The gap was between the document and the reality. Based on the 2024 enforcement patterns, the programs that actually survive regulatory scrutiny share a few things:

Budget that grows with the business. TD Bank’s compliance budget stayed flat for years while everything else grew. That’s the single most cited failure in the DOJ’s findings.

Systems that get updated. Cummins used software that behaved differently in tests. TD Bank’s transaction monitoring was frozen since 2014. Old technology creates risk faster than old policies do.

Cross-border legal awareness. Meta got hit by EU regulators enforcing European law against a US company. If you handle international data or transactions, single-jurisdiction compliance isn’t enough.

Personal accountability at the top. SOX makes executives liable. The DOJ clawed back TD Bank’s CEO bonuses. Individual consequences change behaviour faster than corporate fines.

Reviews triggered by events, not just calendars. Annual audits are a floor. New products, market expansions, regulatory changes, and acquisitions all need immediate compliance assessment.

The compliance training market itself tells this story. According to Mordor Intelligence, global spending hit $6.15 billion in 2025, projected to reach $9.02 billion by 2030 at a 7.96% CAGR. Companies aren’t spending more because compliance got easier. They’re spending more because they’ve watched what happens to companies that don’t.

Frequently Asked Questions

What are the real consequences beyond fines?

Fines are actually the easier part. TD Bank’s $434 billion asset cap means they can’t grow US operations until regulators approve — that potentially costs more than the $3 billion penalty over time. Beyond financial hits: lawsuits, lost licenses, criminal charges against individual executives, reputational damage, investor flight, and increased regulatory surveillance going forward. Repeat violators get watched much more closely.

How often should compliance programs get reviewed?

Once a year at minimum. But the real answer is: every time something significant changes. New product launch? Review. Entering a new market? Review. Regulatory change in any jurisdiction you operate in? Review. TD Bank’s monitoring sat untouched for eight years while they added Zelle and peer-to-peer payments. That’s the exact gap enforcement targets.

Small businesses don’t need enterprise-level compliance… right?

The scope is different. The legal obligation isn’t. Small businesses face the same core requirements around taxes, employment law, workplace safety, and data protection. Some simplified reporting exists, but wage laws, anti-discrimination rules, and breach notification requirements apply regardless of size. Professional compliance guidance almost always costs less than the violation it prevents.

References

  • Fenergo — 2024 Global Financial Institution Enforcement Actions Analysis: fenergo.com
  • FinCEN — Record $1.3 Billion Penalty Against TD Bank: fincen.gov
  • US EPA — 2024 Cummins Inc. Vehicle Emission Control Violations Settlement: epa.gov
  • European Data Protection Board — €1.2 Billion Fine for Meta/Facebook: edpb.europa.eu
  • Protecht USA — Analysis of 180,000+ US Corporate Fines 2020–2024: protechtgroup.com
  • Mordor Intelligence — Global Corporate Compliance Training Market Size and Forecast
  • PwC — 2025 Global Risk Survey: Technology Compliance Risks
  • KPMG — AI in Financial Reporting and SOX Compliance
  • Cleveland State University — Online Juris Doctor Program Details

Aarthy Venkat Head - Strategy at SignDesk

SignDesk is a workflow automation and documentation product aimed at assisting businesses in digitizing and automating their documentation processes.

Hit and Run OCGA Charges in Georgia_ What Actually Happens
Previous Story

Hit and Run OCGA Charges in Georgia: What Actually Happens

5 Specific Cases Where You Should Not Take Advice from AI for a Divorce
Next Story

5 Specific Cases Where You Should Not Take Advice from AI for a Divorce

Latest from Business & Employment

Hit and Run OCGA Charges in Georgia_ What Actually Happens
Previous Story

Hit and Run OCGA Charges in Georgia: What Actually Happens

5 Specific Cases Where You Should Not Take Advice from AI for a Divorce
Next Story

5 Specific Cases Where You Should Not Take Advice from AI for a Divorce

Don't Miss

New Jersey's Permissive Use Law for Stolen Vehicles: N.J.S.A. 2C:20-10.2

New Jersey’s Permissive Use Law for Stolen Vehicles: N.J.S.A. 2C:20-10.2

Picture this – a client walks into my office, visibly