On a Tuesday morning in February 2026, BaFin investigators walked into Deutsche Bank's Frankfurt headquarters for the third time. The public statement from the regulator was clinical. The number attached to it was not. 54 banks. €7 billion in exposure. A scandal from 2012, still bleeding cash into the balance sheets of 2026. Every commentary I have read on this frames it as a legal story. Compliance failure. Aggressive tax planning that crossed a line. Prosecutors finally catching up. That framing is wrong. Cum-Ex is a legacy technology story wearing a legal costume. The exposure is not live because the trades happened. The exposure is live because the systems that processed those trades were never built to answer the questions regulators are now asking.
The Uncomfortable Split In The Investigation
Look at which banks settled early and which are still under investigation. The pattern is not about which firm had cleaner intentions. It is about which firm had the technical capacity to reconstruct what actually happened. BaFin can name 54 institutions with precision because the paper trail is recoverable at their end. Settlement records, tax reclaim filings, counterparty declarations. All of it sits in structured, queryable form inside the regulator's systems. Ask the banks themselves the same question and the answer changes. Most cannot produce an unbroken audit trail linking a specific trade to a specific settlement to a specific dividend claim to a specific counterparty position at a specific microsecond. They have the trades. They have the settlements. What they do not have is the queryable linkage between them. That is the exposure. Not the trading behaviour. The inability to prove, one way or the other, what the trading behaviour actually was.
What The Original Systems Recorded, And What They Did Not
The platforms that executed cum-ex trades between 2005 and 2012 were built for a different regulatory world. They logged transactions. They stored prices, volumes, timestamps, and counterparties. They did their job. What they did not log was context. Counterparty intent. Timing precision below the second. Settlement linkage across custodians. The relationship between one leg of a trade and the offsetting leg at another firm. The chain that connects a share sale on Tuesday to a dividend claim on Wednesday to a tax reclaim filed six weeks later. Regulators now require exactly that context. And the systems that would need to produce it were never designed to hold it. So the banks are doing something extraordinary. They are hiring forensic accountants, legal teams, and consulting firms to reconstruct computationally what the technology should have recorded automatically. A single institution can spend €50 million to €200 million on this reconstruction work. Some are spending more. Every euro of that reconstruction cost is a payment against technical debt that was invisible on the balance sheet fifteen years ago.
The Argument That Makes People Uncomfortable
Here is the part senior executives at these institutions do not want to hear. This is not a 2012 problem that has been fixed. The same architectural failure exists inside these firms today, in a different shape. The trading systems are newer. The compliance overlays are more sophisticated. The regulatory reporting is more frequent. None of that addresses the underlying issue. The underlying issue is this: the systems that execute the trades and the systems that record the context of those trades are still separate systems. They talk to each other overnight, in batches, through reconciliation processes that were designed for end-of-day settlement in the 1990s. Fragmented data lakes. Siloed order management systems. Post-trade reconciliation that runs after the fact rather than at the moment of execution. Custodial reporting that lives in one place, tax reporting in another, counterparty positions in a third, all stitched together by scheduled jobs and human reconciliation. When a regulator arrives in 2031 and asks a question about a trade executed today, the answer will require the same forensic reconstruction that Cum-Ex requires now. The cost will be the same. The exposure will be the same. Only the specific scandal will have a different name.
Why Compliance Training Cannot Solve This
The response inside affected institutions has been predictable. More compliance training. More attestations. More policy documents. More governance layers on top of the same technical foundation. None of that fixes what is broken. Compliance training assumes the people executing trades know something they are hiding. In practice, the people executing trades know exactly what they are doing. The system just does not record it in a form that survives fifteen years of technological and regulatory change. You cannot train your way out of an architecture problem. You cannot govern your way out of an architecture problem. You can only rebuild your way out of it.
What A Firm Should Actually Do Differently
The answer is not glamorous. It is architectural, and it is expensive, and it takes years. Trading platforms need to produce an unbroken, queryable audit trail at the point of execution. Not overnight. Not through reconciliation. At execution. That means every trade carries, from the moment it is created, the full context of why it happened, who agreed to it, how it links to related trades at other institutions, and how it flows through to settlement, custody, tax treatment, and regulatory reporting. The context is not attached later. It is native to the transaction. That means retiring the assumption that post-trade systems will clean up what pre-trade systems failed to capture. Post-trade cleanup is the origin of the problem, not the solution. That means integrated data models rather than stitched-together data lakes. Trade, position, settlement, and regulatory reporting sitting on the same substrate, queryable in real time, with a single version of the truth that persists. I have built these systems. Not commented on them. Not consulted on them from the outside. Built them, inside the firms that face this exposure, for the desks that generate it. The technical work is well understood. The engineering is available. What is missing at most institutions is the executive willingness to fund a multi-year rebuild when the current systems appear, quarter over quarter, to still work. They work until they do not. Cum-Ex is the demonstration of what "do not" looks like.
The Question On The Table
Every senior executive at a European or global financial institution should be asking one question this week. If a regulator arrived tomorrow and asked for the full context around a trade executed by your firm five years ago, could you answer in software, or would you answer in consulting fees? The 54 banks named by BaFin already know their answer. €7 billion is the price of that answer. The firms that will face the next version of this exposure are running the same categories of infrastructure that produced the current one. The specific scandal will be different. The mechanism will be identical. The rebuild takes three to five years. The exposure builds in real time. That maths only works in one direction.