Compliance PracticeEnforcement & CasesNorth America

FinCEN Imposes Record $80 Million BSA Penalty on Canaccord Genuity

Date: 6 March 2026
Category: Enforcement / Compliance
Region: United States

The U.S. Financial Crimes Enforcement Network has imposed an $80 million civil money penalty on Canaccord Genuity LLC for willful violations of the Bank Secrecy Act.

It is the largest BSA penalty FinCEN has ever imposed on a securities broker-dealer.

According to FinCEN, Canaccord failed to maintain an AML program appropriate to the risks of its business, conduct adequate risk-based customer due diligence and establish effective controls for identifying and reporting suspicious trading activity.

The violations covered conduct from March 2018 through June 2024. FinCEN said the failures allowed high-risk customers and potentially fraudulent securities activity to access the U.S. financial system without appropriate scrutiny.

A High-Risk Business Without Matching AML Controls

Canaccord operated two business lines central to the enforcement action:

  • A wholesale market-making business covering over-the-counter securities; and
  • A trade-execution business serving institutional customers, including money managers, hedge funds, financial institutions and other legal entities.

The firm was one of the most active market makers in low-volume and low-priced OTC securities.

Between 2018 and 2022, it executed nearly $70 billion in transactions involving securities trading below $5 per share.

Low-priced securities can present elevated fraud and market-manipulation risks because they may have:

  • Limited publicly available information;
  • Low trading liquidity;
  • High price volatility;
  • No minimum exchange-listing standards; and
  • Concentrated ownership or trading activity.

These characteristics can make the securities vulnerable to pump-and-dump schemes, wash trading and other forms of manipulation.

FinCEN’s central concern was not that Canaccord participated in a high-risk market. It was that the firm’s AML controls did not adequately reflect the scale and nature of that risk.

Surveillance Reports Were Not Properly Used

Canaccord relied heavily on automated trade-surveillance reports to identify suspicious activity.

The reports were intended to detect patterns involving:

  • Low-priced and low-volume securities;
  • Pump-and-dump activity;
  • Wash sales;
  • Self-trading;
  • Abnormal price movements; and
  • Other potentially manipulative transactions.

However, some reports went unreviewed for periods ranging from months to several years.

Until late 2021, only four employees—each with other responsibilities—were assigned to review more than 100 different surveillance reports. Some of those reports generated thousands or millions of data entries each year.

FinCEN also found that certain monitoring parameters were adjusted to reduce the number of transactions requiring review rather than to capture activity based on its actual risk.

For example, employees manually filtered low-priced and low-volume reports to make the review workload more manageable. Some thresholds were selected without sufficient testing or a documented risk rationale.

A monitoring system is therefore not effective merely because alerts or reports are being generated.

The institution must also ensure that:

  • The scenarios reflect the risks of the business;
  • The data is complete and accurate;
  • Thresholds have a defensible methodology;
  • Reports are reviewed on time;
  • Investigators understand the activity being assessed; and
  • Adequate staff are available to complete the work.

Institutional Customers Still Require Meaningful CDD

The enforcement action also highlights weaknesses in Canaccord’s due diligence on institutional and legal-entity customers.

Institutional status should not be treated as a substitute for customer understanding.

A customer described as a hedge fund, investment business, financial institution or professional trading firm may still present higher risk because of its:

  • Ownership structure;
  • Jurisdiction;
  • Regulatory status;
  • Trading strategy;
  • Sources and uses of funds;
  • Underlying counterparties; or
  • Exposure to low-priced securities.

FinCEN found that Canaccord often applied the same basic level of due diligence to customers without adequately differentiating between their risk profiles.

Its processes did not consistently identify or resolve beneficial ownership issues, and higher-risk indicators did not always lead to additional investigation.

For broker-dealers, appropriate institutional customer due diligence may require an understanding of:

  • The nature and purpose of the account;
  • The customer’s ownership and control;
  • Its principal business and markets;
  • Expected trading activity;
  • Source of funds and source of wealth where relevant;
  • Related parties and counterparties;
  • Regulatory and disciplinary history; and
  • Why the customer requires access to particular markets or services.

The relevant question is not simply whether an institution can provide corporate documents.

It is whether the broker-dealer understands who controls the customer, how the account is expected to operate and what activity would be inconsistent with that profile.

Customer Information Must Be Updated When Risk Changes

FinCEN found that Canaccord lacked a consistent process for updating customer due diligence and risk profiles for much of the relevant period.

Updates were often limited or conducted on an ad hoc basis.

CDD is not completed permanently when an account is opened. The information collected during onboarding establishes a baseline against which later activity can be assessed.

A review may be needed when:

  • Trading activity differs materially from the stated purpose of the account;
  • The customer begins trading higher-risk securities;
  • Transaction volumes increase significantly;
  • New jurisdictions or counterparties appear;
  • Ownership or control changes;
  • Adverse regulatory or law-enforcement information emerges;
  • The customer becomes associated with unusual market activity; or
  • Existing information becomes inconsistent, unreliable or incomplete.

A fixed periodic review schedule can support ongoing CDD, but it should not be the only mechanism.

Where material risk events occur, customer information and risk ratings may need to be updated before the next scheduled review.

Low-Priced Securities Require Contextual Monitoring

Monitoring low-priced securities cannot rely solely on a single transaction threshold.

Suspicious patterns may develop over several days, weeks or related accounts.

Relevant indicators can include:

  • Rapid increases in price or trading volume;
  • Trading that dominates the market for a security;
  • Matched or prearranged transactions;
  • Repeated buying and selling without a clear economic purpose;
  • Wash trading involving no genuine change in beneficial ownership;
  • Promotional activity followed by concentrated selling;
  • Deposits followed by rapid liquidation;
  • Trading inconsistent with the customer’s stated strategy; and
  • Connections between customers, issuers, promoters or beneficial owners.

Effective monitoring should combine trading data with customer and ownership information.

A price increase may not be suspicious on its own. The risk becomes clearer when it is connected with promotional campaigns, coordinated trading, related accounts or customers whose activity is inconsistent with their known profile.

At Least 160 SARs Were Not Filed

Based on the preliminary results of a retrospective review, FinCEN found that Canaccord failed to file at least 160 suspicious activity reports involving dozens of OTC securities.

The underlying activity involved thousands of potentially suspicious transactions.

FinCEN also identified weaknesses in the timeliness and quality of the firm’s investigations and reporting.

For broker-dealers, the obligation to file a SAR does not depend on proving that securities fraud or market manipulation has occurred.

A SAR may be required where the firm knows, suspects or has reason to suspect that a transaction or pattern:

  • Involves proceeds of illegal activity;
  • Is intended to disguise illicit funds;
  • Is designed to evade BSA requirements;
  • Has no apparent lawful or business purpose; or
  • Uses the broker-dealer to facilitate criminal activity.

The regulatory threshold is suspicion based on the available facts—not the conclusion of a law-enforcement investigation.

Where surveillance reviews are delayed, suspicious activity reporting will also be delayed. By the time a regulator or enforcement agency confirms the scheme, the broker-dealer may already have missed its reporting obligation.

Compliance Capacity Must Match Business Risk

FinCEN attributed many of Canaccord’s failures to insufficient AML resources, training and oversight.

Employees responsible for surveillance reviews lacked appropriate experience and guidance. Independent testing also failed to identify or adequately test important weaknesses in the firm’s monitoring processes.

The case demonstrates that staffing should be assessed against:

  • The volume of transactions;
  • The number and complexity of surveillance reports;
  • The risk level of the products;
  • The size and nature of the customer population;
  • Alert-review deadlines;
  • The experience of investigators; and
  • The time required for proper escalation and SAR decisions.

Reducing alert volumes to fit available staffing is not the same as applying a risk-based approach.

Where the monitoring workload exceeds operational capacity, institutions may need to improve data quality, refine scenarios, automate appropriate processes or increase experienced compliance resources.

They should not simply exclude potentially relevant activity from review.

What Broker-Dealers Should Review

The Canaccord action provides several practical questions for securities firms:

  1. Does the AML risk assessment accurately reflect higher-risk products and business lines?
  2. Are institutional customers risk-rated individually rather than treated as a low-risk category?
  3. Is beneficial ownership information complete and internally consistent?
  4. Can changes in customer activity trigger an update to the CDD file and risk rating?
  5. Are low-priced securities monitored using scenarios designed for their specific risks?
  6. Are surveillance thresholds supported by testing and documented reasoning?
  7. Are all critical reports reviewed within defined timeframes?
  8. Do investigators have sufficient training to distinguish legitimate trading from manipulation?
  9. Are related alerts, customers and securities reviewed together?
  10. Are SAR decisions timely, consistent and adequately documented?
  11. Does independent testing examine how controls operate in practice?
  12. Are AML resources sufficient for the volume and complexity of the business?

These questions apply beyond broker-dealers active in low-priced securities.

The wider principle is that an AML program must be designed around the institution’s actual customers, products and transaction risks.

The Compliance Takeaway

FinCEN’s record penalty reflects more than a series of missed alerts.

The action describes a broader failure to connect customer due diligence, customer-risk updates, trade surveillance and suspicious activity reporting.

A broker-dealer may identify its products as high-risk, but that recognition has limited value unless it leads to:

  • Stronger customer due diligence;
  • Appropriate monitoring scenarios;
  • Timely investigations;
  • Adequate staffing;
  • Updated customer information; and
  • Effective suspicious activity reporting.

Institutional customers should not receive reduced scrutiny simply because they are professional market participants.

Likewise, surveillance systems should not be judged by how many reports they generate, but by whether the institution can identify, investigate and report the risks those reports were designed to detect.

The Canaccord action sends a clear message to the securities sector:

AML controls must be proportionate not only to the size of the business, but also to the risks created by the markets and customers it chooses to serve.

Main Sources

FinCEN — FinCEN Assesses Historic $80 Million Penalty Against Canaccord Genuity LLC for Securities Fraud-Related Bank Secrecy Act Violations

https://www.fincen.gov/news/news-releases/fincen-assesses-historic-80-million-penalty-against-canaccord-genuity-llc

FinCEN — Consent Order Imposing Civil Money Penalty: Canaccord Genuity LLC

https://www.fincen.gov/system/files/2026-03/Canaccord-Consent-Order-No-2026-01.pdf

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button