The U.S. Treasury Department’s Financial Crimes Enforcement Network (FinCEN) has imposed a $125 million civil money penalty on UBS Financial Services Inc. (UBSFS) for what the agency described as willful violations of the Bank Secrecy Act, marking the largest penalty FinCEN has imposed on a broker-dealer for BSA violations.
The enforcement action puts renewed attention on a central expectation of financial-crime compliance: once an institution identifies an anti-money laundering weakness — particularly one that has already resulted in regulatory enforcement — it is expected to remediate the problem effectively rather than simply commit to doing so.
In UBSFS’s case, FinCEN said the company continued to experience significant deficiencies years after entering into an earlier enforcement agreement concerning similar monitoring failures.
FinCEN Director Andrea Gacki described the action as a warning to institutions that repeatedly fail to address AML deficiencies, particularly when those shortcomings expose the financial system to high-risk customers and activities.
A second FinCEN enforcement action against UBSFS
The latest penalty is not UBSFS’s first encounter with FinCEN over its BSA compliance program.
In December 2018, UBSFS entered into a consent order with FinCEN that imposed a $14.5 million civil money penalty for BSA violations.
Among the deficiencies identified at the time were weaknesses in the firm’s automated monitoring system that resulted in inadequate monitoring of foreign-currency wire transfers.
UBSFS represented that it would address the underlying problems.
According to FinCEN’s latest findings, however, the problems were not adequately resolved.
The agency said UBSFS subsequently failed to appropriately monitor more than 50,000 foreign-currency wires with an aggregate value exceeding $10 billion.
The regulator also said UBSFS did not disclose these continuing deficiencies to FinCEN. Instead, FinCEN discovered them through a subsequent investigation following a regulatory examination.
That history was central to the latest enforcement action.
The issue was therefore not simply that UBSFS had an AML control weakness. From FinCEN’s perspective, the more serious concern was that the institution had previously been warned about similar deficiencies, committed to remediation and nevertheless continued to operate with significant gaps.
High-risk customers came under scrutiny
The enforcement action also focuses on customer due diligence, particularly UBSFS’s relationships with high-risk customers with ties to Russia and Latin America.
FinCEN said its investigation identified cases in which UBSFS failed to appropriately assess and mitigate money-laundering and other illicit-finance risks associated with customers’ sources of wealth.
The regulator also identified instances involving adverse information concerning customers and alleged connections to corruption, fraud and money laundering.
In some cases, FinCEN said, even negative information that raised concerns within a UBSFS affiliate was not adequately incorporated into the firm’s customer-risk assessment and response.
The deficiencies had consequences beyond the internal compliance function.
According to FinCEN, UBSFS failed to file hundreds of suspicious activity reports in a timely manner, depriving law enforcement of information that could have been relevant to investigations of potential illicit financial activity.
The findings underscore the role of customer due diligence as an ongoing process rather than a one-time onboarding exercise.
A customer’s source of wealth, geographic exposure and adverse-media profile can change over time. FinCEN’s action makes clear that institutions are expected to reassess those risks as relationships develop rather than simply document them at the beginning of the relationship.
FinCEN says UBSFS admits to willful BSA violations
As part of the settlement, UBSFS admitted that it willfully violated the Bank Secrecy Act.
The violations included failures to implement and maintain an AML program meeting the minimum requirements of the BSA and failures relating to the filing of suspicious activity reports.
The consent order requires UBSFS to undertake a significant remediation programme.
One of the most consequential requirements is a third-party lookback designed to identify suspicious transactions that may have gone undetected because of the deficiencies identified by FinCEN.
Where previously unidentified suspicious activity is discovered, the third party will assist in determining which transactions should be reported to FinCEN.
This retrospective review effectively extends the consequences of the control failures beyond the period during which regulators originally identified them.
The institution must also undergo an independent review of its AML programme.
Four priority illicit-finance risks
FinCEN’s required independent review will focus specifically on deficiencies that contributed to the violations and their relationship to several priority illicit-finance risks.
The agency identified four areas:
- The U.S. Southwest border, cartels and possible narcotics trafficking
- Iran
- Russia
- Venezuela
The scope is notable because it connects UBSFS’s remediation not only to generic AML controls but to specific areas of illicit-finance risk identified by U.S. authorities.
The review will assess whether UBSFS’s AML programme is effectively addressing those risks and whether the institution has implemented appropriate controls to manage them.
FinCEN has also created a financial incentive around the remediation process.
If UBSFS satisfactorily completes the independent review and implements the recommendations produced through the exercise, FinCEN said it will waive up to $15 million of expenses incurred by UBSFS in connection with the undertaking.
The arrangement reflects an enforcement philosophy in which remediation is treated as an important component of the regulatory outcome, rather than the monetary penalty being the sole measure of accountability.
The message for financial institutions: remediation cannot remain on paper
Perhaps the most significant compliance lesson from the UBSFS case is FinCEN’s emphasis on effective remediation.
Financial institutions regularly identify control weaknesses through regulatory examinations, internal audits, compliance testing and employee reports.
The regulator’s expectation is that those findings result in substantive changes.
In UBSFS’s case, FinCEN said the institution continued to fail to monitor foreign-currency transactions effectively after entering into an earlier settlement with FinCEN, the Securities and Exchange Commission and the Financial Industry Regulatory Authority concerning similar failures.
The agency said significant aspects of remediation were not undertaken until its subsequent investigation was already underway.
For financial institutions, the distinction is important.
A documented remediation plan does not necessarily demonstrate that a risk has been addressed. Regulators can assess whether controls actually work in practice — whether alerts are generated, whether investigators review them, whether suspicious activity is reported and whether identified deficiencies remain present in live operations.
The case therefore places considerable emphasis on the gap between policy implementation and control effectiveness.
Risk-based CDD goes beyond “papering” a file
FinCEN also used the enforcement action to reinforce its expectations around risk-based customer due diligence.
Financial institutions subject to the agency’s 2016 CDD Rule are expected to conduct meaningful, risk-based due diligence at onboarding and throughout the customer relationship.
That obligation becomes particularly important when institutions provide wealth-management services to customers who may present elevated money-laundering or illicit-finance risks.
FinCEN cautioned against an approach in which institutions merely document apparent risks without genuinely assessing them.
In practical terms, that means a customer file should not simply contain an adverse-media report, a source-of-wealth document or an internal risk assessment. The institution must determine what those facts mean for the customer’s actual risk and respond with controls proportionate to that risk.
For a high-risk customer, that could mean enhanced monitoring, additional source-of-wealth or source-of-funds investigation, closer review of transactions, escalation to senior compliance personnel or other measures appropriate to the circumstances.
The key principle is that CDD must be dynamic.
Why wealth management faces particular scrutiny
The case is particularly relevant to wealth-management businesses because private and institutional clients can present complex ownership structures, international connections and substantial financial flows.
A customer’s wealth may originate from multiple jurisdictions and businesses, making it more difficult to establish a clear economic narrative.
Cross-border relationships can also create exposure to jurisdictions associated with corruption, sanctions evasion, organised crime or other forms of financial crime.
That does not mean that customers from higher-risk jurisdictions are inherently illicit.
Rather, FinCEN’s expectations require institutions to understand the specific risks associated with individual customers and apply proportionate controls.
The UBSFS case illustrates the consequences when regulators conclude that those risks were not adequately identified or addressed.
Suspicious activity reporting remains a critical control
Another major component of the enforcement action concerns suspicious activity reports (SARs).
SARs are an important mechanism through which financial institutions provide information about potentially suspicious transactions to U.S. authorities.
FinCEN said UBSFS failed to timely report hundreds of suspicious transactions as a result of its AML deficiencies.
The issue highlights the interconnected nature of an AML programme.
Weak transaction monitoring can lead to missed alerts. Missed alerts can result in inadequate investigations. Inadequate investigations can result in missed SAR filings. And missed SARs can deprive law enforcement of intelligence about potentially illicit activity.
A weakness in one component of the compliance framework can therefore propagate through the entire system.
Multiple regulators involved
FinCEN also acknowledged cooperation with the Commodity Futures Trading Commission, the SEC and FINRA in connection with the matter.
The multi-regulator involvement reflects the increasingly interconnected regulatory environment surrounding financial-crime compliance in the United States.
Broker-dealers and wealth-management firms can face overlapping obligations across different regulatory regimes. Deficiencies identified by one regulator may also become relevant to other supervisory or enforcement authorities.
For compliance departments, this increases the importance of maintaining a consistent understanding of AML risks across regulatory, operational and business functions.
The broader compliance lesson
The UBSFS enforcement action is ultimately about more than the size of the penalty.
The $125 million figure is significant because it represents the largest BSA penalty imposed against a broker-dealer by FinCEN to date. But the regulator’s findings point to several broader lessons for financial institutions.
First, repeat violations matter.
A weakness that has already been the subject of regulatory enforcement receives heightened scrutiny if the institution subsequently fails to resolve it.
Second, remediation must be demonstrable.
Regulators can look beyond written policies and commitments to determine whether controls actually operate effectively.
Third, CDD must be risk-based and continuous.
Customer risk does not remain static after onboarding, particularly for customers with complex international relationships or exposure to higher-risk jurisdictions.
Fourth, source-of-wealth analysis matters.
For wealth-management businesses, understanding how a customer accumulated wealth can be as important as establishing the customer’s identity.
Fifth, adverse information needs to inform the risk assessment.
Simply recording negative news in a customer file may not be sufficient if the information raises substantive concerns about corruption, fraud, money laundering or other illicit activity.
Finally, transaction monitoring and CDD cannot operate in isolation.
Customer risk assessments, transaction behaviour, adverse information and suspicious-activity reporting need to feed into one another.
A warning for the wider financial sector
The UBSFS case sends a broader message to banks, broker-dealers and other financial institutions operating sophisticated AML programmes: regulatory compliance is measured by outcomes, not assurances.
An institution may have policies, procedures, monitoring systems and remediation plans on paper. If those controls fail to identify high-risk transactions or customers in practice, regulators can treat the underlying programme as deficient.
The case is particularly consequential because UBSFS had already been subject to enforcement over related monitoring weaknesses.
The latest action demonstrates that the regulatory consequences can become substantially more severe when previously identified deficiencies persist.
For financial institutions, the immediate priority is therefore not simply to confirm that an AML programme exists. It is to establish whether the programme is working, producing meaningful risk identification, generating appropriate alerts, supporting effective investigations and resulting in timely regulatory reporting.
The UBSFS settlement makes that distinction unmistakable: in the eyes of regulators, an unresolved AML weakness does not become less serious because an institution has previously promised to fix it.
And when the same weakness survives an earlier enforcement action, the consequences can become considerably more severe.
By FCCT Editorial Team

