What if you don't tell the directors, but just fix the problem you have discovered? Is everyone off the hook then, or does that also amount to breaking the law (in some country)?
Spotting these things is a _fantastic_ way for a VP to get on the fast-track to Director. And it is fantastic, as a Director, to have people on your team actively looking for holes.
Why?
Because Operational Control is a #1 strategic target for all banks. $7million is nothing. At an extremely senior level this is evidence that a culture of transparency and compliance exists in the company, and ammo the next time the SEC or FED express a 'concern'. At a low level it is a Director or VP demonstrating to their boss that they understand the strategic direction, and that under their watch nothing big is going to blow up, nothing $7billion big; something $7million big is nothing, they know their boss knows this and will get a thank you for it being raised.
So you tell the directors. You make a nice PPT and include it in 'initiatives' when a senior visitor comes to visit and gets a de-brief on your department. You make sure it's carefully and clearly explained, so they can explain it to their boss in a nice, pro-active, continuous improvement kind of manner.
A bank which does not operate like this, in the post 2008 era of regulatory punishment for purgery, is an organisation with a very short future.
Source: Work in Operations and Technology in large banks.
Further, this was obviously discussed with the boss before it was raised.
This is not a case where the company failed to transfer money owed to the government. And even in such a case, the appropriate remedy would be actual damages plus interest, where the interest is at some punitive rate.
Because some transactions were innocently concealed, the damage is that the government may have lost some opportunities to catch some people laundering money through those branches of the bank. But that is very indirect. In any case, in those cases they would probably have existing suspicions, right? And they would notice that, oops, that person is using a branch for which we have no data from Citigroup: how come?
The SEC didn't catch this error precisely because they were not investigating any user of those branches for which data were missing.
They only lost the opportunity represented by situations in which the data is the primary source of the initial suspicion of wrong-doing. That is all. As in, something in the numbers raises a red flag, and then they investigate and uncover something.
Well, they have the data now; they could comb through it, right? This 15 year period, or at least most of it, should be well within the statutes of limitations that they could still prosecute cases uncovered by the data.
A $7m fine for someone like Citigroup is basically a parking ticket.