U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

By
Key Takeaways
  • Coordinated Enforcement: FinCEN, the SEC, the CFTC, and FINRA announced coordinated enforcement actions imposing a combined $173 million in penalties against UBS Financial Services over persistent anti-money laundering compliance failures.
  • Record FinCEN Penalty: FinCEN assessed a $125 million civil money penalty, which is the largest ever imposed against a broker-dealer for Bank Secrecy Act violations, after concluding UBSFS failed to remediate deficiencies identified in a 2018 enforcement action.
  • Years of Monitoring Failures: Regulators found UBSFS continued to operate with significant weaknesses in its transaction monitoring systems, leaving more than 50,000 foreign currency wire transfers unmonitored according to FinCEN, while FINRA identified more than 60,000 inadequately monitored transactions totaling over $10 billion.
  • Customer Due Diligence Breakdowns: Multiple regulators cited failures in UBSFS's risk-based customer due diligence program, including inadequate oversight of higher-risk customers and delayed filing of suspicious activity reports tied to potential money laundering risks.
  • Independent Remediation Required: FinCEN's settlement requires UBSFS to conduct an independent AML review and transaction lookback, with up to $15 million of the penalty eligible for waiver if the firm successfully implements the review's recommendations.
Deep Dive

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish. Four regulators announced coordinated enforcement actions Monday imposing a combined $173 million in penalties against the firm, concluding that deficiencies identified years earlier continued to undermine transaction monitoring, customer due diligence, and suspicious activity reporting. The actions were brought by the Treasury Department's Financial Crimes Enforcement Network (FinCEN), the Securities and Exchange Commission, the Commodity Futures Trading Commission, and the Financial Industry Regulatory Authority.

FinCEN imposed the largest sanction, a $125 million civil money penalty, the largest ever assessed against a broker-dealer for violations of the Bank Secrecy Act. The SEC ordered UBSFS to pay $20 million for failing to timely file suspicious activity reports, FINRA fined the firm $20 million for repeat anti-money laundering failures, and the CFTC imposed an $8 million penalty over supervision failures affecting the firm's AML transaction monitoring systems.

This was not a case built around a newly discovered flaw or a fast-moving criminal scheme that outpaced compliance systems. Regulators say the underlying problems were already known. They had already been cited, and the institution had already committed to fixing them. Instead, FinCEN concluded that UBSFS continued to operate with critical gaps in its anti-money laundering program, leaving more than 50,000 foreign currency wire transfers with an aggregate value exceeding $10 billion outside appropriate monitoring because of weaknesses in its automated surveillance systems. Worse still, according to the agency, the firm never told FinCEN the problems persisted. Regulators learned of them only after launching another investigation following a regulatory examination.

"Today's historic action against UBSFS should send a clear message that recidivist financial institutions will face severe repercussions," FinCEN Director Andrea Gacki said in announcing the enforcement action.

The agency's findings reached well beyond transaction monitoring. FinCEN said UBSFS also fell short in conducting meaningful customer due diligence for higher-risk wealth management clients, particularly individuals with ties to Russia and Latin America. Investigators found instances where the firm inadequately assessed the risks posed by customers whose reported sources of wealth or public histories included allegations of corruption, fraud, or money laundering. In some cases, FinCEN noted, concerns raised by one of UBS's own affiliates did not translate into stronger scrutiny.

Those failures carried practical consequences. FinCEN said UBSFS did not timely file hundreds of Suspicious Activity Reports, depriving law enforcement of information it relies upon to identify and investigate illicit financial activity. The settlement leaves little room for ambiguity. UBSFS admitted it willfully violated the Bank Secrecy Act, including failing to implement and maintain an effective anti-money laundering program and failing to file required suspicious activity reports.

The remedial measures are almost as revealing as the penalty itself. UBSFS must retain an independent third party to conduct a lookback review aimed at identifying suspicious transactions that its systems failed to detect. It must also undergo an independent assessment of its AML program, one focused specifically on risks FinCEN considers national priorities: activity connected to the U.S. Southwest border and narcotics trafficking organizations, Iran, Russia, and Venezuela.

FINRA's findings largely tracked FinCEN's investigation but focused on the firm's obligations as a broker-dealer. The self-regulatory organization concluded UBS Financial failed to remediate deficiencies identified in a 2018 disciplinary action and continued using inadequate systems to monitor foreign currency wire activity. Between January 2019 and June 2023, FINRA said the firm failed to reasonably monitor more than 60,000 foreign currency wire transfers totaling more than $10 billion, including transactions involving high-risk jurisdictions, unusually large transfers, and activity lacking an apparent business purpose.

The SEC's order focused on the consequences of those failures, concluding that weaknesses in transaction monitoring and customer due diligence caused UBSFS to file certain Suspicious Activity Reports late, in violation of federal securities laws governing broker-dealers.

Four Regulators, One Conclusion

Although each regulator focused on different legal obligations, the factual findings were remarkably consistent. FinCEN concluded UBSFS failed to remediate deficiencies identified in its 2018 Bank Secrecy Act enforcement action, allowing more than 50,000 foreign currency wire transfers worth over $10 billion to escape appropriate monitoring. FINRA similarly found the firm failed to reasonably monitor more than 60,000 foreign currency wire transactions totaling more than $10 billion between 2019 and 2023, describing the case as an example of repeat misconduct warranting progressively stronger sanctions.

The CFTC approached the case through a supervisory lens, finding deficiencies in how UBS configured and governed its AML transaction monitoring systems for foreign-currency wire transfers within futures commission merchant accounts. According to the agency, both legacy manual processes and later problems configuring automated surveillance tools left thousands of transactions either omitted from monitoring or insufficiently reviewed.

The SEC, meanwhile, concluded that the monitoring failures and weaknesses in customer due diligence caused UBSFS to file certain Suspicious Activity Reports late, violating federal securities laws requiring broker-dealers to comply with Bank Secrecy Act reporting obligations. The Commission also cited failures to maintain accurate customer risk profiles and identify red flags associated with customers connected to higher-risk jurisdictions.

FinCEN also built an unusual incentive into the resolution. If UBSFS successfully completes the independent review and implements the resulting recommendations to the agency's satisfaction, FinCEN will waive up to $15 million of the penalty to offset the firm's remediation costs.

That provision says something about how AML enforcement has evolved. Regulators increasingly appear less interested in simply collecting penalties than in forcing institutions to prove that expensive compliance transformations actually happened. The fine punishes the past. The independent review is designed to test whether the future looks any different.

FinCEN emphasized that institutions serving clients connected to higher-risk jurisdictions cannot satisfy customer due diligence obligations by documenting concerns and moving on. Risk-based due diligence, the agency said, requires firms to continually reassess customer relationships and respond proportionately as new information emerges.

Perhaps the most consequential lesson is the simplest one. Financial institutions regularly discover weaknesses in their compliance programs. Regulators understand that, but what appears to draw increasingly severe responses is not the existence of those weaknesses but the decision to leave them unresolved after promising they would be fixed. In FinCEN's telling, that distinction is what turned a multimillion-dollar enforcement action in 2018 into a record-setting one in 2026.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong