INTELLIGENCE BRIEF
firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session
vol VII . ISSUE 24 . 24 JUN 2026
U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action
Breaking . AML

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

Insight . Intelligence . Accountability

32 Views
0 Comments
News & Analysis 04 Aug, 2026

A new wave of professionals is transforming Governance, Risk, and Compliance from a rigid framework into a dynamic force for trust, innovation, and resilience. Governance, Risk, and Compliance (GRC) has long been associated with boardrooms and bureaucracy—a domain reserved for executives and auditors. But that image is changing fast.

By GRC Report Staff

Key Takeaways
  • Coordinated Enforcement: FinCEN, the SEC, the CFTC, and FINRA announced coordinated enforcement actions imposing a combined $173 million in penalties against UBS Financial Services over persistent anti-money laundering compliance failures.

  • Record FinCEN Penalty: FinCEN assessed a $125 million civil money penalty, which is the largest ever imposed against a broker-dealer for Bank Secrecy Act violations, after concluding UBSFS failed to remediate deficiencies identified in a 2018 enforcement action.

  • Years of Monitoring Failures: Regulators found UBSFS continued to operate with significant weaknesses in its transaction monitoring systems, leaving more than 50,000 foreign currency wire transfers unmonitored according to FinCEN, while FINRA identified more than 60,000 inadequately monitored transactions totaling over $10 billion.

  • Customer Due Diligence Breakdowns: Multiple regulators cited failures in UBSFS's risk-based customer due diligence program, including inadequate oversight of higher-risk customers and delayed filing of suspicious activity reports tied to potential money laundering risks.

  • Independent Remediation Required: FinCEN's settlement requires UBSFS to conduct an independent AML review and transaction lookback, with up to $15 million of the penalty eligible for waiver if the firm successfully implements the review's recommendations.

Deep Dive

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish. Four regulators announced coordinated enforcement actions Monday imposing a combined $173 million in penalties against the firm, concluding that deficiencies identified years earlier continued to undermine transaction monitoring, customer due diligence, and suspicious activity reporting. The actions were brought by the Treasury Department's Financial Crimes Enforcement Network (FinCEN), the Securities and Exchange Commission, the Commodity Futures Trading Commission, and the Financial Industry Regulatory Authority.

FinCEN imposed the largest sanction, a $125 million civil money penalty, the largest ever assessed against a broker-dealer for violations of the Bank Secrecy Act. The SEC ordered UBSFS to pay $20 million for failing to timely file suspicious activity reports, FINRA fined the firm $20 million for repeat anti-money laundering failures, and the CFTC imposed an $8 million penalty over supervision failures affecting the firm's AML transaction monitoring systems.

This was not a case built around a newly discovered flaw or a fast-moving criminal scheme that outpaced compliance systems. Regulators say the underlying problems were already known. They had already been cited, and the institution had already committed to fixing them. Instead, FinCEN concluded that UBSFS continued to operate with critical gaps in its anti-money laundering program, leaving more than 50,000 foreign currency wire transfers with an aggregate value exceeding $10 billion outside appropriate monitoring because of weaknesses in its automated surveillance systems. Worse still, according to the agency, the firm never told FinCEN the problems persisted. Regulators learned of them only after launching another investigation following a regulatory examination.

"Today's historic action against UBSFS should send a clear message that recidivist financial institutions will face severe repercussions," FinCEN Director Andrea Gacki said in announcing the enforcement action.

The agency's findings reached well beyond transaction monitoring. FinCEN said UBSFS also fell short in conducting meaningful customer due diligence for higher-risk wealth management clients, particularly individuals with ties to Russia and Latin America. Investigators found instances where the firm inadequately assessed the risks posed by customers whose reported sources of wealth or public histories included allegations of corruption, fraud, or money laundering. In some cases, FinCEN noted, concerns raised by one of UBS's own affiliates did not translate into stronger scrutiny.

Those failures carried practical consequences. FinCEN said UBSFS did not timely file hundreds of Suspicious Activity Reports, depriving law enforcement of information it relies upon to identify and investigate illicit financial activity. The settlement leaves little room for ambiguity. UBSFS admitted it willfully violated the Bank Secrecy Act, including failing to implement and maintain an effective anti-money laundering program and failing to file required suspicious activity reports.

The remedial measures are almost as revealing as the penalty itself. UBSFS must retain an independent third party to conduct a lookback review aimed at identifying suspicious transactions that its systems failed to detect. It must also undergo an independent assessment of its AML program, one focused specifically on risks FinCEN considers national priorities: activity connected to the U.S. Southwest border and narcotics trafficking organizations, Iran, Russia, and Venezuela.

FINRA's findings largely tracked FinCEN's investigation but focused on the firm's obligations as a broker-dealer. The self-regulatory organization concluded UBS Financial failed to remediate deficiencies identified in a 2018 disciplinary action and continued using inadequate systems to monitor foreign currency wire activity. Between January 2019 and June 2023, FINRA said the firm failed to reasonably monitor more than 60,000 foreign currency wire transfers totaling more than $10 billion, including transactions involving high-risk jurisdictions, unusually large transfers, and activity lacking an apparent business purpose.

The SEC's order focused on the consequences of those failures, concluding that weaknesses in transaction monitoring and customer due diligence caused UBSFS to file certain Suspicious Activity Reports late, in violation of federal securities laws governing broker-dealers.

Four Regulators, One Conclusion

Although each regulator focused on different legal obligations, the factual findings were remarkably consistent. FinCEN concluded UBSFS failed to remediate deficiencies identified in its 2018 Bank Secrecy Act enforcement action, allowing more than 50,000 foreign currency wire transfers worth over $10 billion to escape appropriate monitoring. FINRA similarly found the firm failed to reasonably monitor more than 60,000 foreign currency wire transactions totaling more than $10 billion between 2019 and 2023, describing the case as an example of repeat misconduct warranting progressively stronger sanctions.

The CFTC approached the case through a supervisory lens, finding deficiencies in how UBS configured and governed its AML transaction monitoring systems for foreign-currency wire transfers within futures commission merchant accounts. According to the agency, both legacy manual processes and later problems configuring automated surveillance tools left thousands of transactions either omitted from monitoring or insufficiently reviewed.

The SEC, meanwhile, concluded that the monitoring failures and weaknesses in customer due diligence caused UBSFS to file certain Suspicious Activity Reports late, violating federal securities laws requiring broker-dealers to comply with Bank Secrecy Act reporting obligations. The Commission also cited failures to maintain accurate customer risk profiles and identify red flags associated with customers connected to higher-risk jurisdictions.

FinCEN also built an unusual incentive into the resolution. If UBSFS successfully completes the independent review and implements the resulting recommendations to the agency's satisfaction, FinCEN will waive up to $15 million of the penalty to offset the firm's remediation costs.

That provision says something about how AML enforcement has evolved. Regulators increasingly appear less interested in simply collecting penalties than in forcing institutions to prove that expensive compliance transformations actually happened. The fine punishes the past. The independent review is designed to test whether the future looks any different.

FinCEN emphasized that institutions serving clients connected to higher-risk jurisdictions cannot satisfy customer due diligence obligations by documenting concerns and moving on. Risk-based due diligence, the agency said, requires firms to continually reassess customer relationships and respond proportionately as new information emerges.

Perhaps the most consequential lesson is the simplest one. Financial institutions regularly discover weaknesses in their compliance programs. Regulators understand that, but what appears to draw increasingly severe responses is not the existence of those weaknesses but the decision to leave them unresolved after promising they would be fixed. In FinCEN's telling, that distinction is what turned a multimillion-dollar enforcement action in 2018 into a record-setting one in 2026.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Leave a comment

Your email address will not be published. Required fields are marked with *

Similar Articles
A network that laundered more than four million euros from scams by sending the money to Nigeria falls

A network that laundered more than four million euros from scams by sending the money to Nigeria falls

Spanish Police Bust €4 Million International Money Laundering Ring Bound for Nigeria. The Spanish Civil Guard has dismantled a criminal network responsible for laundering over €4 million generated through cyber fraud, CEO scams, and identity theft across Europe. The organization utilized "smurfing"—splitting large illicit funds into more than 9,200 small-wire transfers using falsified passports and stolen identities—to bypass anti-money laundering controls and funnel cash into Nigeria. The two-phase operation led to 20 arrests, investigations into 11 others, and raids targeting key leaders in Bilbao as well as several complicit money transfer agencies.

Read Full Brief
07 Aug 2026
U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish.

Read Full Brief
04 Aug 2026
FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

The Financial Action Task Force closed its June 2026 plenary by removing Algeria and Namibia from its list of jurisdictions under increased monitoring, while adding Bosnia and Herzegovina and Iraq. For African compliance functions, the headline delisting matters less than what it confirms about the direction of travel.

Read Full Brief
04 Aug 2026
RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Every compliance leader I meet is being asked, in some form, what their AI strategy is. Almost none of them are being asked the more important question first: what is your governance model for the AI you already have?

Read Full Brief
04 Aug 2026
The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

High-risk AI obligations for financial services have been pushed back sixteen months. Transparency rules for chatbots and synthetic media have not moved at all — and enforcement power against general-purpose AI providers switches on this week.

Read Full Brief
04 Aug 2026
Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Outsourcing does not outsource accountability. Regulators have said this for years. Boards are only now starting to act as though they believe it.

Read Full Brief
04 Aug 2026
Recommended Articles
See all

No recommended articles found.