
The so-called “Adriano Fossati affair”, which has been reported on by the international press for several weeks, goes far beyond the scope of a potential individual breach of banking secrecy. It raises questions about a much deeper evolution in contemporary banking law: the responsibility of a financial institution is no longer assessed solely through the actions of its employees, but also in light of the robustness of its internal organisation, its governance and the effectiveness of its compliance framework.
This evolution forms part of an international movement towards strengthening prudential supervision. Under the influence of the Recommendations of the Financial Action Task Force (FATF), the Basel Committee’s Core Principles for Effective Banking Supervision and the assessments conducted by MONEYVAL, financial institutions must now be able to demonstrate that their governance enables them to identify, prevent, detect and manage compliance risks, particularly those liable to undermine banking secrecy, data confidentiality and the integrity of financial markets. Compliance is no longer merely a control function. It has now become one of the pillars of banking governance and an essential criterion for assessing the prudential soundness of institutions.
The Principality of Monaco has fully embraced this dynamic by establishing a particularly demanding regulatory framework structured around Law No. 1.338 of 7 September 2007 on financial activities, Law No. 1.362 of 3 August 2009 on the fight against money laundering, terrorist financing and corruption, Law No. 1.565 of 3 December 2024 on the protection of personal data, as well as the regulations adopted for their implementation and the decisions of the Commission de Contrôle des Activités Financières (CCAF). Sovereign Ordinance No. 9.223 of 28 April 2022, amending Sovereign Ordinance No. 2.318 of 3 August 2009, thus introduced a mandatory professional certification system in the field of combating money laundering, terrorist financing and corruption for individuals performing the most sensitive functions within regulated institutions.
This choice by the Monegasque legislature illustrates a demanding conception of compliance, based not only on the existence of internal procedures, but also on the competence, responsibility and continuous training of the professionals responsible for implementing them. Taken together, these provisions establish a renewed conception of banking responsibility, now based as much on the robustness of internal organisation as on the quality of governance and the effectiveness of the compliance framework.
The legal significance of the Adriano Fossati affair lies precisely in this transformation. Beyond the search for potential individual liability, it raises questions about the obligations now imposed on financial institutions in terms of governance, internal control, management of IT access rights, access traceability, data protection and the prevention of conflicts of interest. It therefore provides an opportunity to illustrate how compliance has become the primary vehicle for the prudential assessment of banks.
In the Adriano Fossati affair, the governance and compliance obligations incumbent upon Monegasque financial institutions also raise the question of how the maturity of their compliance frameworks may now influence the assessment of their prudential, civil and reputational liability.
Obligations Incumbent upon Financial Institutions
For a long time, banking secrecy was primarily regarded as an individual obligation. Bankers were required to exercise discretion. A breach of that obligation incurred their liability and could give rise to disciplinary, civil or criminal sanctions. This conception naturally remains relevant. It is, however, no longer sufficient to meet the requirements of contemporary financial regulation.
Compliance law has profoundly transformed this approach. It no longer merely requires financial institutions to sanction breaches when they occur. It requires them to organise their operations in such a way as to make such breaches as unlikely as possible. Compliance is therefore no longer a peripheral function responsible for verifying adherence to rules. Compliance has become one of the essential instruments of banking governance.
This evolution is particularly apparent in the Principality of Monaco. Under Law No. 1.338 of 7 September 2007 on financial activities, Law No. 1.362 of 3 August 2009 on the fight against money laundering, Law No. 1.565 of 3 December 2024 on the protection of personal data, as well as the texts adopted by the Commission de Contrôle des Activités Financières, financial institutions must be able to demonstrate that their organisation effectively enables them to prevent the risks to which they are exposed. This requirement is consistent with the standards developed by the Financial Action Task Force, the Basel Committee and MONEYVAL. It reflects a simple idea: a modern bank can no longer be judged solely on the results it achieves. It is also judged on the quality of its organisation.
The first of these requirements is effective governance. Governing bodies can no longer limit themselves to appointing a compliance officer or adopting internal procedures. They must define a genuine risk-management policy, ensure its day-to-day implementation and be capable of demonstrating its effectiveness to the supervisory authority. Governance is no longer merely one organisational component among others. It constitutes the first level of protection for banking secrecy.
This logic naturally extends to the obligation to establish an independent and permanent internal control framework. This framework is no longer limited to verifying the regularity of transactions carried out by employees. It must assess the institution’s ability to identify risks, prevent them and respond rapidly when they materialise. Internal control thus becomes an instrument of governance before being an instrument of verification.
The management of IT access rights follows the same logic. Financial institutions hold information that ranks among the most sensitive aspects of their clients’ economic and financial lives. Access to such data cannot result merely from technical convenience. It must comply with the “need-to-know” principle. Every access must be justified by the functions actually performed. Every consultation must be capable of being explained. Every anomaly must be capable of being detected.
This gives rise to an equally essential requirement of traceability. In a contemporary bank, banking secrecy no longer rests solely on the loyalty of employees. It also depends on the ability of information systems to record access, retain access histories and flag unusual consultations. Technology is no longer merely a management tool. It becomes an instrument of evidence and prevention.
The same logic underpins the rules relating to conflicts of interest, the protection of personal data and the development of a genuine culture of compliance. A bank does not fulfil its obligations merely because it has a procedures manual. It fulfils them because its entire organisation, from its governing bodies to each of its employees, is designed to ensure that the protection of clients’ interests and the integrity of the institution prevail.
Finally, financial institutions are required to maintain an ongoing cooperative relationship with their supervisory authority. This cooperation does not reflect a logic of distrust. It forms part of a modern conception of prudential regulation based on transparency, continuous improvement and risk management.
Taken together, these obligations reveal a profound transformation in banking law. Banking secrecy is no longer merely an obligation of discretion. It has become an organisational obligation. A bank is no longer merely responsible for misconduct committed by its employees. It is now required to demonstrate that its governance, internal controls and compliance framework are effectively designed to prevent such misconduct before it occurs.
What Responsibilities for the Banking Institution? Liability Now Assessed in Light of Compliance Maturity
The evolution of contemporary banking law requires moving beyond a strictly individual conception of liability. When an employee is suspected of having accessed or communicated information covered by banking secrecy without any professional justification, the analysis no longer stops at determining whether personal misconduct occurred. It now extends to the organisation of the institution itself. The essential question becomes whether the bank had established a governance and internal control framework compliant with the requirements of Monegasque law and international supervisory standards.
If the alleged facts were established, the first form of responsibility likely to be examined would fall within the scope of prudential supervision. Pursuant to Law No. 1.338 of 7 September 2007 on financial activities, the Commission de Contrôle des Activités Financières (CCAF) of the Principality of Monaco is responsible for ensuring compliance with the prudential rules applicable to authorised institutions. Its supervision concerns not only the regularity of financial transactions, but also the internal organisation of institutions, the quality of their governance, the effectiveness of their internal controls and their ability to manage operational risks.
From this perspective, the CCAF could be called upon to assess whether the institution’s internal procedures were appropriate to the risks inherent in the storage and processing of particularly sensitive data. The examination could focus in particular on the policy governing IT access rights, the traceability of data consultations, mechanisms for detecting atypical access, the independence of the compliance function, and the effectiveness of the ongoing controls exercised over employees. If organisational shortcomings were identified, the supervisory authority could require corrective measures to be implemented, strengthen the prudential requirements applicable to the institution or, where the conditions provided for by law are met, exercise the sanctioning powers conferred upon it by Monegasque law. The issue would therefore not merely be to determine whether individual misconduct occurred, but to assess whether such misconduct reveals a broader failure of the governance system.
In addition to this prudential responsibility, there could also be civil liability towards the client or third party individual. The banking relationship is based on obligations of loyalty, confidentiality and security, which constitute one of the essential foundations of the contract between the institution and its clients. If the client were to establish that information covered by banking secrecy had been accessed, used or communicated for purposes lacking any legitimate basis, the client could argue that the bank had failed to perform its obligations with the required diligence. The court’s assessment would then concern not only the conduct of the employee in question. It would also extend to the preventive, control and monitoring measures implemented by the institution to prevent such a risk from materialising. From this perspective, the robustness of the compliance framework, the effectiveness of internal controls and the relevance of governance mechanisms would constitute decisive factors in assessing any potential fault on the part of the institution, without prejudice to the requirement, in accordance with the general law of civil liability, to demonstrate damage and a causal link between that fault and the alleged loss.
The protection of personal data constitutes a third level of analysis. Law No. 1.565 of 3 December 2024 requires data controllers to implement appropriate technical and organisational measures to guarantee the security and confidentiality of personal data. In the banking sector, these obligations are particularly stringent due to the nature of the information processed. If data were accessed or communicated without a legitimate basis, the competent authorities could examine not only the circumstances of that access, but also the preventive measures implemented by the bank: restrictions on access rights, user authentication, logging of consultations, access-right controls, regular audits and incident-response procedures. Here again, liability would not automatically arise solely from the existence of irregular access; it would depend on the institution’s ability to demonstrate that its organisation complied with legal requirements.
The Adriano Fossati affair also raises the issue of operational risk management, which now occupies a central place in international banking supervision standards. The Basel Committee’s Core Principles for Effective Banking Supervision, as well as the Principles for the Sound Management of Operational Risk, emphasise that institutions must be able to identify, assess, monitor and control risks arising both from system failures and from the conduct of their employees. This approach is now fully integrated into contemporary prudential doctrine. Unjustified access to confidential information is no longer treated as a mere disciplinary breach; it is analysed as the materialisation of an operational risk whose prevention is the responsibility of the institution itself.
Finally, beyond strictly legal liability, such a situation is liable to generate reputational risk whose consequences often extend beyond those of administrative or judicial sanctions. In private banking, reputation constitutes an essential intangible asset. Client confidence rests less on the institution’s financial strength alone than on the certainty that the financial and asset-related information entrusted to it will remain strictly protected. Any public questioning, even temporary, of its ability to guarantee confidentiality is liable to have a lasting impact on the institution’s image, its relationships with international partners and the confidence of its clients. International governance standards also expressly recognise reputational risk as a component of overall risk that must be incorporated into risk-management frameworks.
It is precisely in this respect that the Adriano Fossati affair is of particular doctrinal interest. It could constitute an illustration of the new requirements of Monegasque compliance. The authorities would not limit themselves to determining whether an employee had or had not breached their professional obligations. They would also be called upon to assess whether the institution could demonstrate that its organisation effectively met the requirements of contemporary prudential supervision. The appropriateness of access rights, the effectiveness of monitoring mechanisms, the quality of internal controls, the independence of the compliance function, the traceability of access and the speed of the institutional response would all constitute determining factors in assessing the bank’s governance.
Thus, the true significance of this affair may not lie solely in the search for individual responsibility. It reveals a deeper transformation of banking law: a financial institution is no longer judged solely on the actions of its employees, but on its ability to demonstrate that its organisation is designed to prevent breaches of banking secrecy, protect the data entrusted to it and preserve the confidence that forms the very foundation of Monaco’s financial centre. This is, undoubtedly, the most complete expression of what should now be described as Monegasque compliance.
Systemic Risks Facing the Banking Institution: The Adriano Fossati Affair or the Test of Prudential Governance
The Adriano Fossati affair invites us to move beyond the sole search for potential individual liability and already highlights a profound evolution in contemporary banking law. The question is no longer merely whether an employee breached their professional obligations. It is now whether the institution had a sufficiently robust organisation to prevent such a situation, detect it without delay and limit its consequences. Banking responsibility is now assessed in light of the maturity of governance, the effectiveness of internal controls and the maturity of the compliance framework.
This evolution reflects a paradigm shift. The international standards developed by the Basel Committee, the Financial Action Task Force and MONEYVAL no longer regard a compliance incident as an isolated event. They view it as revealing a risk capable of affecting the entire organisation. Unjustified access to confidential data therefore leads the supervisory authority to examine the overall functioning of the institution. The conditions governing the granting of access rights, segregation of duties, access monitoring, the independence of the compliance function, the quality of permanent second-level controls and the involvement of governing bodies all become factors for assessing the robustness of the prudential framework. The focus of supervision is shifting. It no longer concerns exclusively the behaviour of an individual. It now extends to the institution’s ability to manage its own risks.
The first risk facing the institution is therefore prudential risk. If the alleged facts were established, the supervisory authority could examine whether the preventive mechanisms were appropriate to the sensitivity of the information processed and the nature of the activities carried out. It could also assess whether monitoring systems made it possible to identify atypical access rapidly and whether internal procedures ensured an immediate and proportionate response. Prudential supervision no longer merely seeks to establish the existence of a breach. It verifies that the institution is able to demonstrate effective control over its risks.
In addition to this prudential risk, there is litigation risk. The banking relationship is based on an obligation of confidentiality that constitutes one of the foundations of the trust placed by the client in the institution. If that trust were to be undermined by irregular use of information covered by banking secrecy, the judicial debate would no longer concern solely the conduct of the employee in question. It would also concern the measures taken by the bank to prevent such an event. The quality of the compliance framework would then become an essential factor in assessing the institution’s liability.
The affair also reveals an institutional risk whose implications extend beyond the dispute itself. A private bank is distinguished not only by the quality of its services or the performance of its management. Its reputation is founded on the certainty that the information entrusted to it remains protected by an impeccable organisation. Confidentiality is one of the primary expectations of international clients. It also contributes to the institution’s credibility with correspondent banks, counterparties, investors and supervisory authorities. When an affair publicly calls this confidentiality into question, the institution’s entire capital of trust may be weakened.
This dimension is particularly important in the Principality of Monaco. The reputation of its financial centre rests on a delicate balance between economic attractiveness, excellence in prudential supervision and compliance with international standards. Each authorised institution contributes, through its organisation and practices, to the credibility of the whole. Consequently, an incident capable of revealing a weakness in internal control systems necessarily extends beyond the specific interests of the bank concerned. It may call into question the ability of the financial centre itself to provide the guarantees of security, confidentiality and governance expected by international stakeholders.
Finally, the affair highlights an even more fundamental risk. It serves as a reminder that compliance is no longer an ancillary function responsible for verifying adherence to internal procedures. Compliance has become one of the principal criteria for assessing banking governance. The existence of procedures is no longer sufficient. It must also be demonstrated that they are effectively applied, that they make it possible to identify abnormal situations and that they guarantee a rapid response when an incident occurs. The effectiveness of a compliance framework is measured less by the theoretical perfection of its rules than by its ability to prevent failures before they produce their effects.
The Adriano Fossati affair thus illustrates a silent but profound transformation of banking law. For a long time, the liability of an institution originated in misconduct committed by its employees. It is now increasingly assessed in light of the quality of its organisation. This shift in focus, from the individual to the system, undoubtedly constitutes one of the most significant developments in contemporary compliance law. It establishes an idea that has become essential in modern financial regulation.
A bank is now judged as much on the robustness of its governance as on the individual conduct of those who make up the institution.
Worse still, – and we have saved the most striking point for last -, the victim is not, and has never been, a client of Safra Bank. The actions of banker Adriano Fossati for the benefit of his mistress Rebecca Zanazzo, along with of Safra Bankʼs failures were therefore not directed at one of their own clients, but at an external unrelated third party.
This underscores the gravity of the acts committed, which only serve to exponentially increase the systemic reputational and compliance risks facing one of the most respected banks in the financial community.
The Adriano Fossati affair could therefore very well become a Safra Bank affair — and a Monegasque affair.
Michel Taube with Julien Briot-Hadar, International Expert– compliance, LCB-FT, anti-corruption, financial governance


















