Welcome to the Wednesday edition of AboutAML
What’s a week without enforcement breakdown? Let’s dive in…
In 2018, UBS Financial Services was penalised for weaknesses in its anti-money laundering controls. It told the US Financial Crimes Enforcement Network, FinCEN, that it would fix them.
On 3 August 2026, FinCEN assessed a $125 million civil penalty against the firm for willful violations of the Bank Secrecy Act. It is said to be the largest BSA penalty imposed on a broker-dealer to date.
As shocking as the size of the fine is, FinCEN’s announced it to be recidivist, meaning a repeat offender.
This was the continuation of weaknesses the firm had already been required to address.
The earlier warning
In December 2018, FinCEN assessed a $14.5 million penalty against UBS Financial Services. Among other deficiencies, the regulator found that the firm’s automated system did not adequately monitor foreign-currency wires.
Before that settlement, UBS told FinCEN it expected to introduce a new monitoring system by mid-2019.
The system was not deployed until March 2021. FinCEN found that weaknesses in its planning, testing and implementation allowed monitoring failures to continue into the second quarter of 2023.
During the relevant period, UBS failed to monitor appropriately more than 61,500 foreign-currency wires worth over $10.5 billion. FinCEN’s public announcement describes this more as over 50,000 wires worth more than $10 billion.
The firm also failed to disclose the continuing deficiencies to FinCEN. The regulator said it discovered them through an investigation following a regulatory examination.
This combination made the case more serious.
Think of it this way: a known problem, an assurance that it would be fixed, years of delay and an inadequate implementation.
What happen if controls don’t work?
The enforcement order describes failures involving both technology and people.
For part of the period, UBS relied on a complicated manual report to monitor certain foreign-currency wires. Staff had to query four systems and copy information into an Excel document through a process involving around a dozen steps. The data was sometimes incomplete, the report was not sufficiently tailored to the risk and it was run too infrequently.
A coding problem also caused the firm to undercount the value of some wires for roughly two years, preventing hundreds of transactions from generating alerts.
When a new automated system was eventually introduced, weaknesses in its implementation meant that many foreign-currency wires were still not covered by the relevant monitoring scenarios.
AML control can be more effective when its design, data, implementation, testing, governance and human response work together.
The high-risk customer problem
FinCEN also identified customer due diligence failures involving customers connected to Russia and Latin America.
One example involved entities beneficially owned by a Russian oligarch reportedly among the world’s wealthiest individuals and described as having close ties to President Vladimir Putin.
UBS’s screening produced thousands of hits across more than 300 articles at onboarding. A later review returned more than 150 articles, but only the first 25 were reviewed. FinCEN found that the firm did not appropriately explain or justify how it resolved the negative news it considered.
The firm assigned the accounts a higher-risk rating, but FinCEN concluded that it accepted the heightened money-laundering risk without sufficient justification or adequate mitigating controls.
We can learn from here that giving a customer a high-risk rating is not enough if the controls attached to that rating do not operate effectively.
What are the reporting consequences?
FinCEN identified hundreds of suspicious transactions, involving tens of millions of dollars, for which UBS failed to file timely and accurate suspicious activity reports.
As part of the settlement, UBS admitted that it willfully violated the BSA. In US civil BSA enforcement, willfulness can include reckless disregard or willful blindness.
The firm must now work with a third party to look back at transactions that may have escaped detection and report suspicious activity that was missed. It must also undergo an independent review of its AML programme.
FinCEN assessed the $125 million penalty and will credit $48 million for related penalties imposed by the SEC, CFTC and FINRA. It may also waive up to $15 million if UBS satisfactorily completes the independent review and implements the reviewer’s recommendations.
For compliance teams
Don’t treat remediation as a promise on a spreadsheet.
Assign an owner, set realistic deadlines, test whether the fix works and preserve evidence of completion.
If delivery slips or the solution fails, escalate and communicate appropriately with the regulator.
For businesses navigating AML obligations
Buying a screening or monitoring tool does not complete the obligation. The data entering the tool must be reliable, the scenarios must reflect the firm’s risks, alerts must be investigated properly and decisions must be documented.
A risk rating without effective follow-up controls offers little protection.
For people learning AML
These are differences to take note of:
Identify: recognise what is wrong.
Remediate: design and implement the correction.
Validate: test independently whether the correction actually works.
Official sources
FinCEN: Historic $125 million penalty against UBS Financial Services for recidivist BSA violations
FinCEN’s 2018 enforcement action against UBS Financial Services
If you found this useful, feel free to share it with a colleague who works in compliance, risk, fraud, or financial crime to stay informed between meetings or over a cup of coffee.
AboutAML covers regulatory developments like this every Monday and enforcement actions every Wednesday.
Subscribe for free: Substack
Don’t miss a read.
See you next Monday!
Tosin
AboutAML


The remediation point raises another useful distinction: once a firm commits to fix a known weakness, the commitment itself becomes something worth monitoring.
The question is no longer just whether remediation was completed, but whether subsequent evidence shows the underlying exposure actually changed.
The gap between what was promised, what was implemented, and what proved effective can itself become an early warning signal.