NFR-0041
2024 Evidence-controlled
CrowdStrike / Delta Air Lines
Microsoft estimated that CrowdStrike's 19 July 2024 update affected 8.5 million Windows devices. CrowdStrike's technical RCA identified a 21-versus-20 input mismatch and an out-of-bounds read; Delta later reported approximately 7,000 flight cancellations over five days, a $380 million revenue impact and $170 million of additional operating expense.
Technology & Change Risk
Third-Party & Concentration Risk
Operational Resilience
Third-party concentration
Open NFR-0041
NFR-0059
2023 Evidence-controlled
New York Stock Exchange
An SEC order found that NYSE staff manually marked a failed disaster-recovery health check as successfully resolved without full investigation, escalation or approval. The next morning, 2,824 securities opened without their required auctions and more than 4,000 trades were later busted.
Operational Resilience
Data & Control Integrity
Technology & Change Risk
Disaster recovery
Open NFR-0059
NFR-0104
2020 Evidence-controlled
Silicon Valley Bank
The Federal Reserve found management failure, supervisory delay and 31 open safety-and-soundness findings when the bank failed.
Conduct & Governance Risk
Data & Control Integrity
Governance & escalation
Open NFR-0104
NFR-0106
2019 Evidence-controlled
Luckin Coffee Inc.
The SEC alleged that fabricated sales were reinforced through a false operations database and altered accounting and bank records.
Data & Control Integrity
Conduct & Governance Risk
Data integrity
Open NFR-0106
NFR-0037
2019 Evidence-controlled
Vastaamo
Finland's Data Protection Ombudsman reported at least two unauthorised logins to Vastaamo's patient database and said insufficient logs prevented investigators from determining the exact breach timing, network addresses or methods. The regulator imposed a EUR 608,000 sanction in a decision it stated was not yet final.
Data & Control Integrity
Operational Resilience
Conduct & Governance Risk
Sensitive data
Open NFR-0037
NFR-0073
2018 Evidence-controlled
Boeing 737 MAX
After two 737 MAX crashes killed 346 people, the FAA identified the original MCAS reliance on one angle-of-attack sensor among the safety issues that had to be addressed. The revised design uses both sensor inputs and disables MCAS for the flight when their difference exceeds a threshold.
Data & Control Integrity
Technology & Change Risk
Conduct & Governance Risk
Automated decisioning
Open NFR-0073
NFR-0051
2018 Evidence-controlled
TSB Bank plc
The FCA and PRA found that TSB's data migrated successfully in April 2018, but the new platform failed immediately; disruption affected all branches and a significant proportion of 5.2 million customers, with £48.65 million in combined penalties.
Technology & Change Risk
Operational Resilience
Third-Party & Concentration Risk
Change & release management
Open NFR-0051
NFR-0038
2017 Evidence-controlled
National Health Service in England
WannaCry affected at least 80 of 236 NHS trusts in England and exposed gaps in patching, preparedness and national response coordination.
Operational Resilience
Technology & Change Risk
Cyber security
Open NFR-0038
NFR-0105
2017 Evidence-controlled
Carillion plc
Within ten months of publishing its 2016 accounts, Carillion entered liquidation with nearly £7 billion of liabilities and £29 million cash.
Data & Control Integrity
Conduct & Governance Risk
Independent challenge
Open NFR-0105
NFR-0052
2012 Approved reference case
Royal Bank of Scotland, NatWest and Ulster Bank
A 2012 software compatibility failure disrupted core banking processes, affected at least 6.5 million UK customers and resulted in £56 million of combined FCA and PRA penalties.
Technology & Change Risk
Operational Resilience
Data & Control Integrity
Payments Risk
Open NFR-0052
NFR-0102
2011 Evidence-controlled
JPMorgan Chase Bank, N.A.
The CFTC found reckless concentrated swaps trading—not the valuation process itself—to be manipulative conduct.
Conduct & Governance Risk
Data & Control Integrity
Conduct risk
Open NFR-0102
NFR-0001
2006 Evidence-controlled
HSBC
The OCC found that HSBC Bank USA excluded wire transfers from 'standard' and 'medium' risk countries from automated BSA/AML monitoring, representing two-thirds of dollar volume for its payments business. The DOJ resolution included $1.256 billion of forfeiture and $665 million of civil penalties.
Financial Crime & Control Integrity
Data & Control Integrity
Conduct & Governance Risk
Anti-money laundering
Open NFR-0001
NFR-0085
2006 Evidence-controlled
Volkswagen AG
Volkswagen pleaded guilty in 2017 to three federal felonies after software distinguished emissions testing from normal driving; the US federal resolution totalled $4.3 billion and concerned approximately 590,000 diesel vehicles.
Conduct & Governance Risk
Data & Control Integrity
Physical, Safety & Environmental Risk
System & back-out testing
Open NFR-0085
NFR-0003
2004 Evidence-controlled
BNP Paribas S.A.
BNP Paribas pleaded guilty in 2014 to conspiring to violate US sanctions law after moving more than $8.8 billion through the US financial system for sanctioned entities; the plea agreement imposed $8.9736 billion in total financial penalties.
Financial Crime & Control Integrity
Data & Control Integrity
Conduct & Governance Risk
Sanctions
Open NFR-0003
NFR-0002
2002 Evidence-controlled
Wells Fargo
Wells Fargo agreed to a $3 billion 2020 resolution over sales practices between 2002 and 2016. The DOJ statement of facts says leadership knew as early as 2002 that unlawful and unethical practices were increasing because of onerous goals and management pressure, while more than 23,000 employees were referred for investigation between 2011 and 2016.
Conduct & Governance Risk
Data & Control Integrity
Financial Crime & Control Integrity
Conduct risk
Open NFR-0002
NFR-0014
2001 Evidence-controlled
Siemens AG
Siemens AG and three subsidiaries pleaded guilty to FCPA-related offences in 2008; coordinated US and German resolutions exceeded $1.6 billion and included a four-year independent compliance monitor.
Financial Crime & Control Integrity
Conduct & Governance Risk
Data & Control Integrity
Bribery & corruption
Open NFR-0014
NFR-0044
1999 Evidence-controlled
Post Office Limited - Horizon
The Court of Appeal found a material risk that apparent branch shortfalls were caused by Horizon bugs, errors or defects and quashed 39 appellants' convictions in 2021; legislation in 2024 then quashed qualifying convictions more broadly.
Data & Control Integrity
Conduct & Governance Risk
Data integrity
Control assurance
Open NFR-0044
NFR-0015
1989 Evidence-controlled
Rolls-Royce plc
The court-approved DPA documented bribery-related conduct spanning three business divisions, seven jurisdictions and more than two decades.
Financial Crime & Control Integrity
Conduct & Governance Risk
Bribery & corruption
Open NFR-0015