Alibaba’s $600 Million Compliance Failure

The Risks Were Visible—But Nobody Managed to Manage them

Enforcement activity may be quieter than it has been in previous years, but quieter does not mean totally dead. The Department of Justice’s (DOJ) recent $600 million resolution with Alibaba Group and AUS Merchant Services gives compliance officers plenty to consider.

The case contains several of the fact patterns that continue to appear across industries and enforcement: high-risk third parties, employees raising concerns about inadequate controls, business migrating to less-visible messaging channels, and monitoring systems that did not identify illegal transactions before law enforcement did.

What Happened?

Thumbnail illustration representing Alibaba's $600 million compliance failure with imagery of money, a barrel, and a businessperson.

Alibaba Group and its U.S.-based payment processor, AUS Merchant Services, entered into non-prosecution agreements and agreed to pay a combined $600 million to resolve allegations that they failed to prevent merchants from selling and importing illegal pharmaceuticals, controlled substances, listed chemicals, pill presses, and other prohibited products into the United States through Alibaba.com and AliExpress.com.

Alibaba admitted that, between January 2016 and December 2024, merchants using its platforms completed approximately 80,000 (wow!) unlawful sales involving imports into the United States.

Those transactions had a combined gross merchandise value exceeding $200 million (wow again). During the investigation, federal law enforcement successfully completed more than 40 undercover purchases of pharmaceuticals and counterfeiting equipment that could not lawfully be imported into the United States.

Alibaba’s Compliance Problems

The resolution is particularly notable because Alibaba had policies restricting prohibited products, and employees had reportedly raised concerns that the company’s compliance controls were inadequate.

In some cases, merchants used Alibaba’s private messaging service to direct buyers to third-party encrypted messaging platforms, where the unlawful transactions could continue with less visibility. Alibaba also earned fees connected to sellers’ activities through membership, advertising, marketing, shipping, and payment-processing services.

The DOJ also identified weaknesses in AUS’s transaction monitoring. According to the resolution, AUS did not fully incorporate certain wire-transfer data into its monitoring system, limiting its ability to identify transactions involving high-risk jurisdictions or multiple payors using a single invoice.

In at least one instance, a merchant continued selling prohibited products after AUS had investigated and reported the merchant to Alibaba.

There are four significant lessons for compliance officers.

1. Third Parties Remain a Persistent Source of Risk

This case is another reminder that third-party risk does not end when a company completes onboarding, conducts screening, or includes the correct contractual language.

Alibaba operated the platforms, but thousands of independent merchants used those platforms to reach buyers. AUS processed payments. Other service providers supported advertising, shipping, communications, and settlement. The misconduct occurred within an ecosystem in which different parties controlled different pieces of the transaction.

That fragmentation can create dangerous gaps. Each organization may have some information, but no organization has a complete view. A merchant may appear acceptable during onboarding, generate concerning messages on the platform, receive payments with unusual characteristics, and ship products that trigger customs concerns. Unless those data points are connected, each control operates with only part of the picture.

Compliance teams should examine whether their third-party programs are designed to detect changes in behavior after onboarding. Screening tells you who the third party appeared to be when the relationship began. Monitoring should tell you what the third party is actually doing now.

2. Listen to Your Whistleblowers—and Understand What They Are Telling You

The DOJ stated that employees raised concerns that Alibaba’s controls were inadequate and failed to prevent illegal products from being sold and imported.

That fact should receive significant attention.

When employees repeatedly identify weaknesses in a compliance program, the issue is no longer simply whether the company has a reporting channel. The issue is whether management understands the significance of what is being reported and responds with appropriate urgency.

Compliance officers should consider how control-related concerns are categorized, escalated, aggregated, and reported. A complaint that a particular control is ineffective may look operational when viewed in isolation. Multiple reports concerning the same control, business line, product category, or customer behavior may indicate a systemic problem.

The investigation process must therefore look beyond whether an individual allegation can be substantiated. It should also ask whether the report exposes a broader weakness that could allow similar conduct to continue elsewhere.

3. Misconduct Migrates to the Channels with the Least Visibility

Shipping boxes, globe, airplane, and trend lines illustrating international trade, logistics, and global supply chain performance.

The use of third-party encrypted messaging platforms is one of the most important aspects of the resolution.

Merchants allegedly used Alibaba’s own messaging service to direct buyers to outside platforms, where the illegal sales could be facilitated away from Alibaba’s direct oversight.

This is a familiar pattern. When bad actors believe that a monitored channel creates risk, they move the meaningful part of the conversation somewhere else.

Organizations may not be able to monitor every external messaging service used by every third party. They can, however, monitor for the point at which business is being redirected outside approved channels.

Language such as “contact me privately,” “continue on WhatsApp,” “move to Telegram,” or “complete the transaction elsewhere” may be a meaningful risk indicator, particularly when combined with high-risk products, jurisdictions, counterparties, or payment behavior.

The objective is not perfect visibility. It is identifying the behavioral signals that suggest the organization is intentionally losing visibility.

4. Monitoring Must Find Illegal Transactions Before Law Enforcement Does

Federal agents successfully completed more than 40 undercover purchases through the platforms.

That creates a difficult but necessary question: if law enforcement could identify the sellers, communicate with them, purchase the products, and arrange shipment into the United States, why did the company’s controls fail to stop the same transactions?

Monitoring programs should be tested against realistic misconduct scenarios, not simply reviewed for technical operation. A system can function exactly as designed and still fail because it does not ingest the right data, connect activity across platforms, identify circumvention language, or escalate repeat sellers effectively.

Compliance teams should consider conducting their own controlled testing, including test purchases, mystery-shopping exercises, targeted message reviews, and transaction lookbacks. Monitoring effectiveness should be measured by what the program finds—not merely whether alerts are generated and closed.

Oh – and Another Thing

You may notice that there aren’t any individual prosecutions or named individuals here. You’re right. All the talk about individual responsibility didn’t show up here. Frustrating – especially given how many facts point to a failure of tone from the top and taking whistleblower complaints seriously.

The Bottom Line

The Alibaba resolution is not a story about the absence of compliance infrastructure. The company had policies, internal messaging, employee concerns, and monitoring systems.

The problem was that those components did not prevent approximately 80,000 illegal sales.

For compliance officers, the central lesson is that a program must be evaluated as an interconnected system. Third-party oversight, whistleblower reporting, messaging controls, payment monitoring, and remediation cannot operate independently. The misconduct will move through the gaps between them.

And, as this resolution demonstrates, regulators and law enforcement may eventually find what the company’s own systems did not.