FinCEN Imposes Record $125 Million BSA Penalty on UBS Financial Services

FinCEN has imposed a $125 million civil money penalty on UBS Financial Services Inc. for willful violations of the Bank Secrecy Act.
The penalty is the largest FinCEN has imposed on a securities broker-dealer for BSA violations.
UBS Financial Services, or UBSFS, admitted that it failed to maintain an AML program meeting minimum BSA requirements and did not file suspicious activity reports on time.
The case is particularly significant because it is FinCEN’s second enforcement action against the firm. UBSFS paid $14.5 million in 2018 after regulators identified deficiencies in its monitoring of foreign currency wires and other AML controls.
FinCEN said the firm did not adequately correct those weaknesses and did not promptly disclose that the problems had continued.
More Than $10.5 Billion in Wires Were Not Properly Monitored
From January 2019 through June 2023, UBSFS failed to appropriately monitor more than 61,500 foreign currency wire transfers with a combined value exceeding $10.5 billion.
The problem affected commodities accounts, retail brokerage accounts and securities-backed lending accounts.
FinCEN found that the interim manual process used for some transactions was unreliable, poorly documented and too infrequent. It required employees to extract and combine information from several systems, while important records were sometimes incomplete or incorrectly matched to customer accounts.
A replacement automated monitoring system was introduced later than promised. Its implementation was also flawed, leaving some foreign currency wires outside the intended monitoring scenarios until 2023.
As a result, the firm failed to identify and report hundreds of suspicious transactions within the required timeframe.
Earlier Regulatory Findings Were Not Fully Remediated
The repeat nature of the violations was central to FinCEN’s action.
In the 2018 settlement, UBSFS represented that it expected to introduce an improved monitoring system by mid-2019. The system was not deployed until March 2021, and material gaps remained after implementation.
FinCEN also found that UBSFS did not voluntarily disclose the continuing violations. The regulator became aware of the unresolved issues through a later investigation following a regulatory examination.
This distinguishes the case from an isolated system failure. The underlying monitoring risk had already been identified, formally documented and made subject to remediation commitments.
For regulated institutions, closing an audit or regulatory finding on paper is not sufficient. Management must confirm that the corrective control has been properly designed, tested and implemented across the full transaction population.
High-Risk Wealth Management Customers Were Not Properly Assessed
The enforcement action also identified weaknesses in customer due diligence involving high-risk wealth management customers with connections to Russia and Latin America.
FinCEN said UBSFS did not always give appropriate weight to:
- The customer’s source of wealth;
- Connections with high-risk jurisdictions;
- Significant adverse media;
- Alleged links to corruption, fraud or money laundering;
- Information held by other UBS affiliates; and
- Transaction activity that differed from the customer’s expected profile.
In one example, a customer originally rated low risk later moved to Russia, obtained a Russia-based telephone number and received funds from a Russian account. The customer’s risk profile was not appropriately updated for several years.
In other cases, the firm accepted customers linked to Russian oligarchs or politically exposed wealth without sufficient justification or controls proportionate to the identified risk.
FinCEN stressed that customer due diligence should not be reduced to documenting an explanation for apparent risks. Institutions must objectively assess those risks and take meaningful steps to address them.
Customer Risk Must Be Updated During the Relationship
The case reinforces that customer risk assessment is not limited to onboarding.
A customer’s circumstances can change through:
- A new country of residence;
- A change in occupation or business activity;
- New sources of wealth;
- Connections with high-risk persons or jurisdictions;
- Adverse media;
- Significant changes in transaction volume; or
- Activity inconsistent with the original customer profile.
These events should be capable of triggering an update to the customer’s information and risk rating.
A customer classified as low risk should not remain outside periodic or event-driven review when the institution already holds information showing that the original assessment is no longer accurate.
The same principle applies to high-risk customers. Accepting the relationship requires more than senior approval at onboarding. The institution must maintain controls that continue to address the identified risk throughout the relationship.
What UBSFS Must Do Next
Under the settlement, UBSFS must engage independent third parties to conduct:
- A retrospective review of previously unmonitored transactions and potential missed SARs; and
- An independent review of the effectiveness of its current AML program.
The program review will examine areas including customer identification, high-risk jurisdictions, transaction monitoring, data governance, issue remediation, SAR reporting and the influence of revenue-generating business units on customer acceptance and exit decisions.
FinCEN assessed a total penalty of $125 million. UBSFS will receive credit for $48 million paid in parallel settlements with the SEC, FINRA and the Commodity Futures Trading Commission.
A further amount of up to $15 million may be waived if UBSFS satisfactorily completes the required AML review and incurs qualifying costs implementing the resulting improvements.
The structure of the settlement gives the firm a financial incentive to invest in measurable remediation rather than treating the penalty as the end of the matter.
Compliance Significance
The UBSFS action points to three issues relevant to other financial institutions.
First, transaction monitoring must cover the full transaction. Monitoring only the U.S. dollar debit or credit is inadequate where the system omits the foreign currency, counterparty, jurisdiction or third-party information needed to assess risk.
Second, a new monitoring platform does not resolve a deficiency unless data mapping, transaction coverage and scenarios are properly tested. A technically deployed system may still leave material activity unmonitored.
Third, remediation following enforcement requires greater urgency and transparency. If an institution cannot meet an agreed timetable or discovers that a corrective control is not working, the issue should be escalated and discussed with the relevant regulator.
The size of the penalty reflects not only the monitoring and CDD failures, but also their duration and recurrence after an earlier enforcement action.
Main Sources
FinCEN — FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations
FinCEN — Consent Order Imposing Civil Money Penalty: UBS Financial Services Inc.
https://www.fincen.gov/system/files/2026-07/UBS-Consent-Order.pdf



