Deutsche Bank's Monte Paschi Suit: A Legal Engineering Failure in Plain Sight
CryptoLion
Predictability is a myth; only volatility is real. Deutsche Bank just turned a seven-year-old Italian scandal into a fresh volatility event. The bank is suing four former employees in London's High Court over the Monte Paschi derivatives collapse. Not for whistleblowing. Not for disloyalty to a competitor. For executing trades the bank itself already paid to bury. The claims: fraudulent misrepresentation, conspiracy to injure, breach of fiduciary duty, unjust enrichment. The subtext: we paid; now you pay.
Look past the plaintiff and defendant labels. This is a case about who owns the memory of a bank. Monte Paschi is not a current asset. It is a liability that refuses to age.
The case reads like a binary echo of 2008. Between 2008 and 2012, Deutsche Bank structured two complex derivative transactions, code-named Alexandria and Santorini, for Banca Monte dei Paschi di Siena. BMPS, Italy's oldest lender, was hiding losses. Deutsche Bank was the counterparty and, according to Milan prosecutors, the architect of the concealment. In 2018, a Milan court ruled that Deutsche Bank and Nomura must compensate BMPS by roughly €440 million. Deutsche Bank later paid around €70 million to settle Italian criminal proceedings. Now, in London, the bank wants Michele Faissola, Ivor Dunbar, Michele Foresti, and a fourth former employee to bear the cost.
These were not junior clerks. Faissola ran global rates. Dunbar headed OMB. Foresti led structured rates. They were the control layer for complex products. That is the legal problem.
The case was filed in London's Commercial Court around 2018. That timing matters. It came after Ivey, after SM&CR, and after the Milan judgment. The bank waited until the legal weather changed.
Deutsche Bank's English claims rest on employment law, tort law, and restitution. The core allegation is that the four men breached the duty of fidelity, made fraudulent misrepresentations, conspired to injure the bank, and were unjustly enriched. This is not a negligence claim. The bank must prove dishonesty. That threshold changed in 2017.
In Ivey v Genting Casinos, the UK Supreme Court collapsed the old subjective/objective test into a single objective standard. The court asks what the defendant actually knew, then judges that knowledge against ordinary standards of honest behavior. The bank no longer needs to prove the employees knew they were doing wrong. It needs to prove that a decent, honest person would have known. That is a lower bar. It is also why this case exists.
Ivey is not just a definition. It is a weapon. The old test required the claimant to prove what was going on in the defendant's mind. The new test compares the defendant's actual knowledge with an external standard of honesty. That external standard works in the bank's favor because complex derivatives are judged by simple norms. If a trader structures a transaction to hide risk from a counterparty, a jury of honest people does not need to know the difference between a swap and an option to call it fraud.
Why London? Three answers. First, England's disclosure regime favors claimants. Deutsche Bank can force the former employees to produce internal emails, trade tickets, and compliance sign-offs that would be much harder to reach in Italy. Second, Ivey lowers the dishonesty bar. Third, Milan is not a friendly forum for the bank. In the Italian narrative, Deutsche Bank is a co-conspirator, not a victim. A Rome-based claim would invite scrutiny of the bank's own approvals, board minutes, and risk committees. London allows the bank to frame a systemic failure as four rogue individuals.
The Italian judgment is the load-bearing wall. Under Italian law, Deutsche Bank and Nomura were ordered to compensate BMPS for losses from the Alexandria and Santorini structures. The London case does not relitigate that. It treats the Italian judgment as a given fact and then asks: who inside Deutsche Bank caused the bank to incur that liability? That is the architecture of blame transfer.
Here is the contradiction. The bank's legal theory is built on a fiction: that the employees exceeded their authority. But the derivative books were large, long-dated, and highly profitable. The board approved the relationship with BMPS. The risk committee set the limits. Compliance cleared the trades. If a global head of rates executed a transaction the bank later admitted was fraudulent, the first question is not who signed the ticket. It is why the control framework did not stop him.
Based on my audit experience, I recognize the pattern. In 2017, I spent weeks auditing the Parity multisig contract source code. I identified a critical reentrancy vulnerability and published a technical pre-mortem three days before the exploit. The vulnerability was always in the codebase. The question was who was allowed to see it. In this case, the codebase is the bank's internal control architecture. The vulnerability is the Alexandria and Santorini structures. The lawsuit is an attempt to re-classify a systemic bug as user error.
Now map the legal dependencies. The bank's claim is a passing-on exercise. Milan established the loss. Deutsche Bank wants to transfer it to individuals through English tort and contract law. But the causal chain is fragile. Under Rome I, the employment contracts may be governed by German law, not English law. Under Rome II, the tort's place of damage may be Italy. The bank must persuade an English court to apply English law to conduct that occurred in Milan, executed by employees of a German bank, using contracts drafted under Italian law. Stability is an illusion maintained by ignoring latency.
Then there is the unclean hands problem. English equity does not reward claimants who arrive with dirty hands. Deutsche Bank has already paid €70 million to Italian prosecutors. That settlement is, in effect, an admission of organizational failure. The former employees will cite it as evidence that responsibility was institutional, not personal. They will argue ratification: the bank's subsequent conduct, paying fines, restructuring the desk, keeping the revenue, ratified the very transactions it now calls fraudulent.
One hidden layer is technological. Inside the bank's surveillance systems, there should be records of every trade, every limit check, every compliance approval. If those records show that senior management saw red flags, the case becomes a corporate governance trial. If the records show nothing, the bank must explain why its own systems failed to catch a decade-old scam. Either way, the disclosure phase is the real battlefield.
D&O insurance complicates the picture. Standard directors-and-officers policies exclude deliberate fraud. Ivey's objective standard creates a path around that exclusion. If the court finds the employees dishonest, their insurers may refuse to fund the defense. That is a powerful settlement lever and probably one reason the bank chose this framework. But it also means former employees must spend personal capital on legal defense. That creates an incentive to fight, not settle.
Here is the unreported angle. This lawsuit is not principally a legal remedy. It is a regulatory signal. Deutsche Bank faces ongoing scrutiny from the FCA, which since SM&CR has pushed individual accountability; from BaFin; from the ECB; and, through New York operations, from the DOJ and NYDFS. By suing its own former employees, the bank demonstrates internal accountability. It tells regulators: "we do not protect our people." But the signal is ambiguous.
Deutsche Bank has already shown it can settle. Reports indicate it reached agreements with some original defendants, including Faissola and Dunbar, and agreed to pay legal costs. That is not the behavior of a bank that expects a clean sweep. It is the behavior of a bank managing legal risk in tranches. It settles with the strongest defendants and proceeds against the weakest. The public story of accountability is, in practice, a portfolio optimization exercise.
History does not repeat, but it rhymes in binary. Deutsche Bank has paid for LIBOR manipulation, sanctions violations, and 1MDB. Each time, the institution settled; the individuals walked away. This suit is different only in direction. The bank wants to reverse the flow. In doing so, it exposes itself. The disclosure phase will force the bank to produce its own internal reviews of the BMPS relationship. The court will see whether senior management knew. If they did, the bank becomes the defendant in its own trial.
Then there is the malicious prosecution counterclaim. English law sets a high bar. But if the former employees can show the bank pressed claims it knew were weak, while simultaneously settling with other defendants, the reputational fallout will exceed any judgment. This is the volatility the bank is trying to contain.
The real value at stake is not €70 million or €440 million. It is infrastructure: the evidentiary chain, the decision log, the audit trail. A bank that cannot demonstrate where a decision was made cannot assign blame. A bank that cannot assign blame cannot govern its risk. In that sense, this suit is an infrastructure audit conducted in public.
The next 12 to 18 months will define the new geography of individual accountability. Watch three signals: any FCA guidance citing this case; court rulings on the illegality defense in D&O insurance; and whether Deutsche Bank expands settlements or pushes to judgment. If the bank wins, every institution gets a template for blaming its own code. If it loses, the template becomes a boomerang. Either way, the question is no longer whether Deutsche Bank is a victim. It is whether a bank can sue its own past without indicting its present.