Baker & Hostetler LLP

08/14/2026 | Press release | Distributed by Public on 08/14/2026 09:16

FinCEN Ups Ante on Broker-Dealer AML Obligations by Imposing Another Historic BSA Penalty

08/14/2026|6 minute read
Share

Key Takeaways

  • The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) assessed a $125 million civil money penalty against UBS Financial Services Inc. (UBSFS), a broker-dealer and futures commission merchant, for willful violations of the Bank Secrecy Act (BSA), marking what FinCEN described as the largest penalty ever assessed against a broker-dealer for BSA violations, eclipsing the penalty assessed against Canaccord Genuity LLC in March.
  • FinCEN emphasized UBSFS' status as a repeat offender and found that, after a 2018 FinCEN consent order addressing foreign currency wire monitoring deficiencies, UBSFS failed to address the deficiencies, which allowed a monitoring gap to persist into 2023, during which time UBSFS failed to appropriately monitor more than 61,500 foreign currency wires totaling more than $10.5 billion.
  • FinCEN also found customer due diligence (CDD) deficiencies involving certain customers with ties to Russia and Latin America, including shortcomings in assessing and documenting source-of-wealth information, analyzing adverse media, evaluating politically exposed person (PEP) risk, updating customer risk profiles, and applying account restrictions and enhanced monitoring.
  • FinCEN agreed to credit $48 million against the $125 million penalty for payments to the U.S. Securities and Exchange Commission (SEC), the U.S. Commodity Futures Trading Commission and the Financial Industry Regulatory Authority (FINRA) in related matters, leaving UBSFS with a $62 million payment due to the Treasury; the remaining $15 million may be waived, in FinCEN's sole discretion, based on qualifying expenditures and full compliance with the order, which includes a mandatory suspicious activity report (SAR) look-back investigation and an anti-money laundering (AML) program review to be undertaken by qualified independent consultants.
  • This marks the second major fine imposed this year by FinCEN against a broker-dealer for BSA violations, following the March consent order with Canaccord Genuity LLC - sending a clear message to broker-dealers and other covered financial institutions that BSA enforcement remains a high priority for FinCEN.

Background

On Aug. 3, FinCEN announced its second enforcement action against UBSFS (the Order).[1] The action stems from deficiencies FinCEN alleged persisted after its earlier 2018 settlement with UBSFS.[2] In that prior action, FinCEN assessed a $14.5 million civil money penalty and identified significant weaknesses involving the firm's monitoring of foreign currency wire transfers. According to FinCEN, the 2018 consent order recognized UBSFS' stated commitment and ability to correct the identified issues, including an upgrade to its AML surveillance monitoring system.

In the 2018 matter, UBSFS represented that it expected to implement a new automated monitoring system by mid-2019. FinCEN found that UBSFS did not deploy the system until March 2021 and failures persisted into the second quarter of 2023.

The Order concluded that UBSFS's conduct during the relevant period involved willful AML program and SAR-reporting violations despite representations that corrective actions would be implemented, resulting in substantial gaps in transaction monitoring and suspicious activity detection.

The Order characterized UBSFS as a repeat violator, and FinCEN Director Andrea Gacki stated that the enforcement action should serve as a warning to "recidivist financial institutions" that repeated violations of the BSA may result in severe regulatory consequences.

The Alleged Misconduct

The Order identifies several categories of alleged violations, including failures involving transaction monitoring, customer due diligence, suspicious activity reporting, and AML program governance.

Failure To Effectively Monitor Foreign Currency Wire Activity

The Order describes a sustained failure to monitor foreign currency wires through commodities, retail brokerage, and securities-backed loan accounts. Before March 2021, UBSFS relied in part on manual reporting that FinCEN found to be deficient for multiple reasons. FinCEN found that the new automated monitoring system did not resolve the deficiencies. According to the Order, during the relevant period UBSFS failed to appropriately monitor more than 61,500 foreign currency wires with an aggregate value exceeding $10.5 billion.

FinCEN found that UBSFS selected an incomplete data feed, resulting in foreign currency wire transactions being excluded from monitoring; other transactions lacked counterparty information needed for meaningful review. The system also lacked an exception queue or error-reporting process to identify transactions that failed to enter the monitoring environment.

The Order places particular weight on the prior regulatory history. FinCEN found that management was aware of delays in implementing the replacement system, yet UBSFS did not notify FinCEN that the promised remediation had not been completed and did not meaningfully implement mitigating controls. According to the Order, FinCEN learned of the failures through a later investigation rather than through disclosures from UBSFS.

Deficiencies in High-Risk Customer Due Diligence

FinCEN also identified failures in UBSFS' risk-based CDD processes for certain high-risk customers, particularly customers with ties to Russia and Latin America. The Order describes instances in which UBSFS did not adequately evaluate or update customer risk profiles, analyze source-of-wealth information, address adverse media, assess PEP-related risks, investigate deviations from expected account activity, or apply tailored restrictions and enhanced monitoring.

The Order illustrates FinCEN's expectation that CDD be dynamic. For example, FinCEN found that UBSFS did not respond adequately when information indicated changes in a customer's nexus to Russia, source-of-wealth, or risk profile. It also criticized UBSFS' handling of adverse media and high-risk relationships involving PEPs and Russian oligarchs.

Failure To Timely File SARs and Maintain an Effective AML Program

FinCEN identified hundreds of suspicious transactions involving tens of millions of dollars for which UBSFS failed to timely and accurately file SARs. FinCEN concluded that the delays and incomplete information deprived law enforcement of important financial intelligence.

Taken together, FinCEN concluded that UBSFS failed to implement and maintain an AML program meeting the BSA's minimum requirements. As part of the settlement, UBSFS admitted that it willfully violated the BSA, including failing to maintain an effective AML program meeting those requirements and failing to accurately and timely file SARs.

Why This Enforcement Action Matters

The UBSFS matter is notable not merely because of the size of the penalty but also because of the circumstances that led to it.

Focus on Recidivist Institutions. FinCEN treated UBSFS' prior consent order, the length of the monitoring failures, the scale of the unmonitored activity, and the absence of timely disclosure as significant enforcement factors. It found that the monitoring gap originated as early as 2004, continued after the 2018 order and remained unresolved until late 2023.

Expectation of Operational Success. The Order reflects increasingly sophisticated regulatory expectations concerning transaction monitoring, sanctions screening, CDD, and investigative procedures. FinCEN's findings address the completeness and reliability of data inputs, the adequacy of monitoring coverage, the handling of alerts and investigations, the escalation of identified problems, and the testing and validation of remedial measures.

Source-of-Wealth and Adverse Media. The Order highlights FinCEN's focus on source-of-wealth analyses and adverse media reviews involving high-risk customers - such as those with links to Iran, Russia, Venezuela, or possible narcotics trafficking - and underscores the importance of evaluating CDD risk on a continuing basis. The Order makes clear FinCEN's expectation that financial institutions ensure that their CDD programs incorporate effective procedures for evaluating potentially adverse information, escalating material concerns, and reassessing risk when new information becomes available.

Compliance Lessons for Financial Institutions

For broker-dealers, banks, fintech companies, digital asset businesses, and other regulated financial institutions, the UBSFS settlement serves as a reminder that AML compliance programs remain a significant enforcement priority and will continue to receive intense regulatory scrutiny. Institutions should proactively assess whether their controls, governance frameworks, monitoring capabilities, and remediation efforts are capable of meeting evolving regulatory expectations.

Outside counsel can help guide BSA programs on a path of continuous improvement by assisting with AML risk assessments, compliance program design and enhancements, targeted training, and regulatory engagement. Independent compliance counsel can perform privileged evaluations of whether surveillance, staffing, transaction-monitoring, and escalation frameworks are appropriately calibrated to business risk and can advise on remediation strategies before deficiencies become examination findings or enforcement matters. Early engagement of counsel can also be critical in managing issues that could trigger interactions with FinCEN, the SEC, and other regulatory organizations, particularly where parallel investigations or cumulative penalties may arise.

Ultimately, the UBSFS enforcement action provides the following practical lessons for financial institutions and compliance professionals.

Remediation must be timely, transparent, and validated. The Order demonstrates that a remediation commitment is not a one-time exercise. Institutions should maintain documented remediation plans, clear accountable owners, defined milestones, escalation protocols for missed dates, and risk-appropriate interim controls. Material implementation delays and control failures should receive appropriate internal escalation and be evaluated for regulatory disclosure.

Transaction monitoring requires effective data governance. FinCEN's findings link monitoring effectiveness to complete and accurate data feeds, tested data lineage, reliable matching of counterparties and transactions, and exception-management processes. Institutions should test monitoring tools not only for scenario logic and alert performance, but also for whether the underlying in-scope population and related data is actually entering the system and contains information necessary for meaningful review.

CDD cannot be a static, check-the-box process. FinCEN focused on whether UBSFS identified and acted upon new information concerning source-of-wealth, adverse media, customer geography, sanctions-related risk, PEP considerations, and deviations between expected and actual activity. Firms should reassess customer risk profiles periodically, ensuring information is shared appropriately across different functions in the enterprise, and apply enhanced due diligence procedures where appropriate.

SAR processes require end-to-end assurance. Institutions should periodically test whether alerts and red flags are identified, triaged, investigated, escalated, documented, quality-assured, and - when appropriate - reported accurately and on time. Alert backlogs continue to be a common finding in AML consent orders. Monitoring or CDD failures can have a compounding effect if they prevent the institution from detecting activity in time to investigate and file a meaningful SAR.

Prior matters create heightened enforcement risk. FinCEN's recidivism analysis indicates that an institution operating under or following a consent order, examination finding, or remediation commitment should expect increased scrutiny of both the implementation and the sustainability of its corrective actions. Senior management and boards should understand this and take steps to ensure that remediation is functioning in practice and that known deficiencies have been fully addressed.

Independent review should be designed to test effectiveness. The UBSFS undertaking reflects an expectation that independent reviews assess not only whether corrective actions have been adopted, but also whether they meaningfully mitigate the relevant risks. Financial institutions should routinely evaluate their transaction-monitoring systems to identify potential gaps in scenario coverage, data integrity, model performance, and alert generation. Effective independent testing should identify issues before regulators do.

Maintaining transparency with regulators is critical. The Order illustrates the risks associated with failing to disclose significant compliance deficiencies. Regulators expect institutions to identify problems, escalate issues, and communicate material compliance concerns promptly.

[1] https://www.fincen.gov/system/files/2026-07/UBS-Consent-Order.pdf

[2] https://www.fincen.gov/system/files/enforcement_action/2023-04-05/UBS_Assessment_12.17.2018_FINAL_508_Revised_0.pdf

Related Services

Plus
Baker & Hostetler LLP published this content on August 14, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 14, 2026 at 15:16 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]