The quietest data point in the Deutsche Bank–Monte Paschi litigation is not the €440 million compensation order handed down by a Milan court. It is not the €70 million the bank paid to Italian prosecutors in 2021 to close a chapter of criminal exposure. The quietest data point is the settlement. After naming four former employees as defendants in the London Commercial Court — among them Michele Faissola, once the global head of rates trading — Deutsche Bank settled with at least two of them and agreed to pay their legal fees. Read that again: the plaintiff is paying the defendants' legal bills. That is not how a party behaves when its theory of liability is intact. That is how a party behaves when it has decided that the litigation no longer serves the story it wants to tell. In governance terms, it is a reverted transaction: the slashing threat was issued, partially executed, and then reversed, with the cost absorbed by the initiator. If this were a protocol, forensic analysts would be studying the revert data. In the London Commercial Court, it will take years and tens of millions of pounds to reach the same conclusion.
The Trade That Would Not Die
Let me establish the facts, because the governance argument depends on them. Between 2006 and 2012, Deutsche Bank structured a series of complex derivatives for Banca Monte dei Paschi di Siena, Italy's oldest surviving bank. Trades internally code-named Alexandria and Santorini were long-dated structured products that, according to Italian prosecutors, were used to conceal mounting losses and distort the bank's financial statements. The structure was labyrinthine: swaps, options, reverse convertible bonds, and notional amounts that dwarfed the tiny Sienese lender's capital base. When the dust settled, the Milan court found Deutsche Bank and Nomura jointly liable for roughly €440 million in compensation to BMPS. Deutsche Bank settled its Italian proceedings in 2021, paying €70 million to BMPS as part of approximately €110 million in total settlements with Italian authorities.
Before that settlement, in 2018, the bank had launched a separate claim in London against four former employees: Faissola, Ivor Dunbar, a senior manager in the structured credit business, Michele Foresti, who oversaw structured rates trading, and a fourth former manager whose role has been less widely reported. The legal theories are familiar to anyone who has read a City employment dispute: fraudulent misrepresentation, conspiracy to injure, breach of fiduciary duty, and claims rooted in the duty of fidelity. The bank's narrative is simple: these individuals defrauded their employer by concealing the true nature and risk of the BMPS trades, and the bank, as a victim, is entitled to recover its losses from them.
The timing is instructive. Ivey v Genting Casinos, decided by the UK Supreme Court in 2017, had just redefined the test for dishonesty in civil claims as a purely objective standard. The Senior Managers and Certification Regime had been live since 2016, transforming the FCA's approach from institution-centered oversight to individual accountability. In 2018, Deutsche Bank filed suit, using the grammar of a new accountability era to describe conduct from the old one. That recency is not an accident. It is a signal about how the bank wanted the claim to be read.
The Passing-On Circuit
The first concept to name is the passing-on circuit. When a liability is confirmed downstream, an institution has two options: absorb it, or route it upstream to the individuals whose signatures sit on the trade tickets. The London claim is precisely that circuit. The Milan judgment provides the quantum. The London trial provides the theatre. The employees provide the balance sheet. This is not a search for truth; it is a search for a payer.
Passing-on is a term of art in competition law, where defendants argue that an overcharge was passed on to customers and therefore no loss was suffered. I am using it more broadly, to name the institutionalization of blame transference. The bank accepted a penalty in one jurisdiction, and then turned around to pass the economic substance of that penalty to four named individuals in another. The legal vehicle is fraud; the economic substance is allocation. What matters in a governance reading is not whether Faissola or Foresti were dishonest in some abstract moral sense. What matters is that the bank's own accountability architecture failed to detect, prevent, or fairly attribute the risk for years, and the litigation now compensates for that failure by concentrating liability on a narrow set of actors who were the most visible, not necessarily the most responsible.
I have seen this pattern before, in a smaller and far less expensive theatre. During my years auditing smart contracts for a Lagos-based fintech in the ICO years, I found an integer overflow vulnerability in a vesting schedule that management wanted to ship regardless. I refused to sign off on the whitepaper until it was patched. That refusal cost me my job. Weeks later, similar integer overflow exploits hit three other projects that had not patched, draining user funds. The lesson was not that my colleagues were dishonest. It was that the accountability system was a checklist, not a protocol. The startup's governance was a promise on paper — a set of policies, an org chart, a risk register. It failed structurally before any individual acted badly. Trust is a protocol, not a promise. The bank's promise to shareholders, regulators, and the public was elaborate: codes of conduct, compliance training, board-level risk committees. But the protocol beneath the promise was an incentive system that rewarded revenue acceleration, a review process that normalized complexity, and a risk function that was consulted but not empowered. That protocol failed years before any trade was booked.
The Retroactive Upgrade
The second governance concept is the retroactive upgrade. English courts, when evaluating conduct from before 2017, now apply Ivey's objective standard of dishonesty. The test says: given what the defendant actually knew, would an ordinary honest person have regarded the conduct as dishonest? Notice the structure. The evaluator applies an external standard, but the information set is internal. The defendant's actual knowledge defines the universe of the inquiry; the standard of judgment comes from outside. This epistemic posture is almost identical to a smart contract. A contract does not ask whether a user intended to violate a rule. It checks whether the submitted inputs fail the encoded conditions. What matters is the state transition. In that sense, Ivey is law's version of a compiled boolean check.
The problem is that retroactive objective standards are precise about behavior and blind to context. In a smart contract, such blindness is a deliberate design choice, intended to prevent human bias and the corruption of discretion. In a courtroom, the same blindness becomes a selection device. It selects for the visible actor, the person whose signature appears on the trade ticket, while rendering invisible the surrounding system that made the trade rational, profitable, and normal. The head of structured rates trades a product that his desk has traded for years, with the bank's own risk infrastructure clearing it, its accounting department booking it, its auditors signing off on it. Then, eight years and one regulatory cycle later, a court is asked to evaluate whether that trader was dishonest by a standard that did not exist when the trade was executed.
In a DAO, this would be the governance crisis of the year. If a protocol changed its slashing parameters after a loss and applied the new rules to an old incident, the community would rightly call it a state-actor-style power grab. The bank did exactly that, at the scale of the state. The lesson is not that the bank is uniquely predatory. It is that retroactive rule-making is a governance failure whichever institution attempts it. My own moment of clarity came in the DeFi Summer of 2020, when I retreated to a quiet estate in Ogun State after watching the industry burn itself out with yield churning. The relentless velocity of incentives had eroded the philosophical core of decentralization. Speed had become a virtue in itself, and nobody was asking what the speed was for. The BMPS trades were approved quickly, unwound slowly, and examined too late. Speed is a liability, not an asset. We govern the gray areas between blocks — and nobody governs them well at market velocity.
A Ledger Written in Evidence
The third concept is what I call the slow ledger. The English Commercial Court's disclosure regime requires parties to produce documents that adversely affect their own case. Emails, board minutes, risk committee sign-offs, internal audit findings, instant messages — all must be disgorged and reviewed. This is the closest thing traditional finance has to an immutable record. But it is a ledger written in hindsight, under threat of sanction, at a ruinous cost. Litigation of this scale consumes years and tens of millions of pounds in legal fees. The court's disclosure process is post-hoc transparency. A blockchain is pre-hoc transparency. That difference is the difference between an autopsy and a vaccination.
The BMPS trades were visible. They were recorded in trade tickets, booked in accounting systems, reported to risk committees, subject to regulatory filings. They were seen. They were never verified. Vision without verification is just hallucination. A ledger that records everything but is never queried is a diary, not a governance mechanism. English litigation is a procedure for forcing actors to query their diaries under oath. It works, but it works badly, slowly, and asymmetrically. A former employee defending a fraud claim against a global systemic bank does not have the resources of a global systemic bank. The disclosure regime may aspire to honesty, but the weapons are not shared equally. In a DAO, if a contributor needs a legal defense fund to survive an enforcement action, that is a design failure in the protocol's accountability layer. The infrastructure of fairness must be built before the dispute, not discovered during it.
The bank's case also reveals a technology gap. If its internal surveillance systems had been adequate, the trades would have triggered alerts years earlier. If the systems were not adequate, the question becomes: why did the bank's governance tolerate an inadequate surveillance layer? Either way, the bank is before the court because its own technical infrastructure failed its oversight function. This is the RegTech lesson hidden in the lawsuit: monitoring is not a compliance checkbox; it is a governance primitive. And like any primitive, it must itself be audited. The watcher must be watched. The DAO that deploys a risk monitor must test the monitor. The bank apparently did not, or the test did not matter.
The Unclean Hands Paradox
The fourth concept is the paradox of unclean hands. Deutsche Bank settled with Italian prosecutors in 2021, paid approximately €70 million to BMPS, and accepted a measure of institutional responsibility. It then turned around and sued four individuals, alleging that their dishonesty caused the loss. The contradictions are glaring. If the institution was the victim of four bad actors, why did it settle a criminal investigation into its own conduct? The defensible answers — vicarious liability, cost of closure, commercial pragmatism — all concede the same point: an institution can be liable without any individual being at fault, and an institution can be victimized only by itself. The legal doctrine of ex turpi causa and the equitable maxims attached to clean hands will be invoked by defense counsel, and the bank's own settlement record is a gift to their argument.
More damaging is the cumulative record. Deutsche Bank's decade includes the LIBOR manipulation scandal, the role in the 1MDB affair, sanctions violations, and the long saga of Postbank litigation. Whether or not these episodes indicate systemic corruption, they certainly indicate systemic normalization — a culture in which the boundaries of acceptable conduct drift. Culture compiles where logic fails. No single trader invented the bonus structure that rewarded arranging complex derivatives with minimal disclosure. No single manager designed the risk appetite that treated counterparty opacity as a source of yield rather than a source of danger. The lone bad actor narrative is a comforting governance fiction. It allows boards to sacrifice a few visible individuals while leaving intact the structures that produced them.
I encountered this pattern during the 2022 bear market, when the treasury of the DAO I worked with dropped by sixty percent and the community began searching for a villain. The impulse to slash the proposer, to punish the multisig signer, to name and shame the visible executor — it was overwhelming. But the structural failure was the absence of crisis management protocols, the lack of independent review, the incentive design that rewarded deployment over diligence. Blaming the individual was the cheapest governance action and the least valuable. I withdrew from that conversation for months, reading foundational cryptographic literature and asking myself what decentralization is actually for. I came back with a conviction: crisis management is not about identifying the guilty. It is about understanding why the structure permitted the failure. Accountability that begins with a blame hunt and ends with a settlement is not accountability; it is ritual.
The Slashing That Reverted
The settlements with Faissola and Dunbar, with the bank covering their legal costs, are the most significant governance datum in the entire dispute. A plaintiff who pays a defendant's fees has stopped arguing that the defendant is dishonest. A plaintiff who settles two of four claims has conceded the story is more complex than it alleged. The litigation's continuation against the remaining defendants is a shadow of what was designed: the case's original architecture was a comprehensive narrative of individual corruption; the settlement deletes two pillars while the third and fourth stand increasingly exposed.

In blockchain terms, the DAO slashed, then discovered new evidence, then reverted the slash and compensated the victim. Reverts are information. They tell the community that the initial enforcement action was premature, or materially incomplete, or strategically self-serving. Silence in the chain speaks louder than noise: the absence of a judgment on the settled claims says more about the bank's confidence than any grand pronouncement about accountability. The market headlines that celebrated a crackdown on individual wrongdoing should be re-read against the settlement ledger. The bank did not deliver accountability. It delivered a negotiated exit.
The strategic reading is darker. By pursuing the employees, the bank generated a public record of internal discipline — exactly the kind of record the FCA, the BaFin, and the European Central Bank expect to see from a systemically important institution. Lawsuits of this kind are a regulated company's way of saying to its supervisors: we hold individuals responsible. Whether that signal is genuine or performative is beside the point. It is a signal designed for the regulator's desk. Trust is a protocol, not a promise — and the protocol here was a litigation strategy, not a governance improvement.
What This Teaches DAOs
The Deutsche Bank case is, for those willing to look, a compressed case study in accountability architecture. Its lessons belong not to the London Commercial Court but to the design rooms where DAOs are building their own governance. There are six.
First, accountability must be ex ante, not ex post. The bank's accountability layer was a promise written in employment contracts and compliance manuals. It was not a protocol enforced by the structure of the institution. DAOs have the rare privilege of writing the rules before the funds move. Slashing rules, veto rights, independent review requirements, and defined escalation paths can all be encoded in advance. If they are, the post-mortem is short.
Second, attribution requires pre-committed data models. The bank spent years reconstructing who knew what and when. DAOs that bind identities to keys, require role-based signing, and log sub-delegations are building attribution into the flow of work itself. The data model is the governance model. If the records are complete, the inquiry is cheap. If the records are incomplete, the inquiry becomes law.

Third, individual accountability without structural accountability is blame laundering. The sm&cr regime in the UK and the objective dishonesty test in Ivey have pushed financial institutions to name responsible individuals. Crypto has always preached personal responsibility. The convergence is real, but it is dangerous. In both domains, the visible executor absorbs the penalty while the invisible architect — the compensation design, the board approval, the cultural normalization — continues unexamined. DAOs should design their enforcement actions to evaluate the system as much as the person.
Fourth, enforcement symmetry matters. The four employees faced the litigation budget of a global systemic bank. D&O insurance policies often exclude fraud, leaving individuals exposed. DAOs should fund legal defense pools for contributors, made available regardless of guilt, conditioned on cooperation rather than admission. A governance system that can bankrupt a contributor through enforcement is a governance system that has confused power with justice.

Fifth, settlements are data. The DAO should treat its own governance actions as a dataset and mine it for patterns. Which enforcement actions succeed? Which are reverted? Why? The reversal of a slashing proposal is not a failure of the system; it is the system being honest. The bank's settlements reveal its confidence level; a DAO's reverted votes reveal its own.
Sixth, design for the average human, not the exceptional hero or villain. My experience distributing governance tokens to 500 artists and collectors in the Lagos NFT community taught me that inclusive design is a security parameter. When a diverse group holds review power, the concentration of contextual blind spots is reduced. The bank's committees were diverse in job titles and homogeneous in incentives: everyone was paid to make the trade work, not to question it. We are building cathedrals in the bear market — the discipline of constructing accountable systems in the quiet years is what prevents expensive autopsies in the crisis years.
The Contrarian Reading
The contrarian position is this: the objective dishonesty standard in Ivey and the English disclosure regime are, in a strange way, convergent with the crypto ethos. Both presume that external rules applied to internal knowledge can generate fair judgments without requiring the evaluator to know the defendant's heart. A smart contract does the same. Yet I would not celebrate any of this as accountability. Accountability extracted by threat is compliance, not virtue. An institution that becomes transparent only when subpoenaed will resist transparency when no subpoena is coming. The blockchain's gift is not transparency on demand; it is transparency as a permanent state. The bank's gift to the world is a warning about what happens when transparency arrives too late, through force, at great cost.
We should also resist the temptation to read this lawsuit as validation of the crypto premise. The bank is pursuing individuals not because it has discovered the value of personal responsibility, but because its institutional governance failed so thoroughly that no other actor was left to blame. The DAO community should not copy the legalistic response to failure. It should study the governance failure that preceded it — the years of risk blindness, the normalized complexity, the surveillance that did not surveil. And it should notice the design bias shared by the courtroom and the smart contract: both punish the visible executor and tend to absolve the invisible architect.
The deeper blindness is in the litigation itself. The case asks whether four individuals were dishonest. It does not ask whether a compensation system that paid enormous bonuses for opaque revenue-enhancing trades was honest. It does not ask whether a risk architecture that cleared those trades was honest. It does not ask whether an audit process that missed them was honest. The courtroom narrows the aperture to four faces. The governance problem is that ordinary life is exactly the opposite: the faces are many, the signals are diffuse, and the failure is distributed. That is where accountability belongs, and it is where we are not looking.
The Verification Is on Us
The next five years will determine whether accountability can be built before damage is done, rather than reconstructed after it. The protocol of accountability is not merely a set of encoded rules; it is the culture, incentives, and review practices that make the rules live. The bank had policies — thousands of pages of them. Its promise was elaborate. Its protocol was the problem. Trust is a protocol, not a promise. Culture compiles where logic fails. We govern the gray areas between blocks. Vision without verification is just hallucination — and this time, the verification is on us. It must be written before the promise is spoken, before the trade is booked, before the next Milan court is born.