Learn more about the latest security and privacy threats
Back

The UBS AML penalty: FinCEN's record action against UBS Financial Services

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published August 4, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "The UBS AML penalty: FinCEN's record action against UBS Financial Services".

FinCEN fined UBS Financial Services 125 million dollars for repeat AML failures. What the consent order says and what it changes for your CDD and SAR duties.

Table of contents

The UBS AML penalty announced on 3 August 2026 is 125 million dollars ($125 million), the largest civil money penalty FinCEN has ever imposed on a broker-dealer for Bank Secrecy Act violations. UBS Financial Services admitted willful failures and conceded it never closed the wire monitoring gaps a 2018 consent order required it to fix.

  • The UBS AML penalty covers more than 61,500 foreign currency wires worth over 10.5 billion dollars left unmonitored between January 2019 and June 2023.
  • The firm admitted willful Bank Secrecy Act violations, including failing to maintain an AML program and to file suspicious activity reports.
  • The SEC, FINRA and the CFTC resolved in parallel for 20 million, 20 million and 8 million dollars, all credited against the FinCEN figure.
  • Customer due diligence failures centred on high-risk clients with ties to Russia and Latin America, including source of wealth and negative news dispositions.
  • A third-party SAR lookback is due within 180 days, and an independent AML program review must cover cartels, Iran, Russia and Venezuela.

What did FinCEN find in the UBS AML penalty?

The UBS AML penalty rests on findings that UBS Financial Services Inc willfully violated the Bank Secrecy Act between 1 January 2019 and 30 June 2023. The firm failed to monitor foreign currency wires, failed to perform adequate customer due diligence on high-risk clients, and failed to file hundreds of suspicious activity reports on time.

UBS Financial Services is the US brokerage arm of UBS Group AG, and the decisive fact here is recidivism. UBS Financial Services signed a consent order with FinCEN in December 2018 that carried a 14.5 million dollar penalty and identified the same weakness: automated systems that did not properly capture foreign currency wires. The firm told FinCEN it would deploy a replacement by mid-2019. It did not deploy one until March 2021, and the monitoring gap ran into the second quarter of 2023.

FinCEN Director Andrea Gacki said the action should signal that "recidivist financial institutions will face severe repercussions". The consent order records that the firm did not disclose the slippage, and that FinCEN found out only through an investigation it opened after a regulatory examination.

RegulatorPenaltyCore findingDate
FinCEN125 million dollarsWillful AML program and SAR reporting violations3 August 2026
SEC20 million dollarsLate suspicious activity report filings3 August 2026
FINRA20 million dollarsAML program and customer due diligence failures3 August 2026
CFTC8 million dollarsFailure to supervise AML transaction monitoring systems3 August 2026

The headline figure in the UBS AML penalty is not all new money. FinCEN credited the 48 million dollars going to the other three regulators, so 62 million dollars goes to the Treasury on execution and 15 million dollars falls due by 31 May 2028. That final tranche can be waived if the firm spends an equivalent amount on qualifying remediation work.

How did the monitoring failure last more than four years?

The conduct behind the UBS AML penalty was operational rather than exotic. While the replacement system was delayed, UBS Financial Services relied on an interim control: a manual report built by querying four systems, copying results by hand and running code inside a spreadsheet. FinCEN found the report was untailored, error-prone and run too rarely to mitigate a known risk.

A UBS Financial Services slide deck from January 2019, weeks after the first consent order and quoted in the new order, recorded that the report was "still not effective". One parameter flagged households moving more than the equivalent of 300,000 US dollars in foreign currency wires within a month. A quality-control gap meant the firm systematically undercounted those wire values for roughly two years, so hundreds of transactions never alerted. Staff who found the defect in late 2020 did not immediately escalate it or size the miss.

An internal lookback began in December 2020, after a FINRA examination prompted the firm to revisit the issue. It completed in 2021 and produced no suspicious activity reports at all. FinCEN also noted that group internal audit reports in 2019 and 2020 concluded the legacy compensating controls had been adequately implemented, which they had not.

When the automated system finally arrived in March 2021, it enabled scenarios that peers had run for years: high-risk geographies, suspicious payment instructions, deviation from expected behaviour, velocity of funds across products, dormant-account activity and round-dollar transactions. Even then, a flawed implementation left many foreign currency wires outside those scenarios until FinCEN's investigation raised questions about coverage.

What does the UBS AML penalty change for your obligations?

Nothing in the law changed on 3 August, but the evidentiary bar moved. The UBS AML penalty shows how FinCEN now tests four specific duties, and every regulated firm running wire monitoring or wealth-management onboarding should read its own controls against them rather than against the headline figure.

AML program adequacy (31 U.S.C. 5318(h)). Coverage is now a data question. The consent order requires data lineage mapping and testing to establish whether other products suffered gaps with the same root cause as the wire failure. Being able to show which transaction populations reach your monitoring engine, and which silently do not, is the artefact examiners want.

Suspicious activity reporting (31 U.S.C. 5318(g)). Timeliness is judged against when the activity should have alerted, not when a human eventually saw it. A lookback that returns zero filings after a known alerting defect is treated as evidence of a weak review, not proof of a clean book.

Customer due diligence under the 2016 CDD Rule. FinCEN was explicit that risk-based diligence is not "papering" a disposition. Negative news screening that returns hundreds of articles and is reviewed only in part, a source of wealth accepted from an affiliate's assessment, or a domicile change missed for years are all named failures. Ongoing diligence means refreshing the customer record when facts move.

Sanctions and PEP exposure. The firm adopted another UBS entity's conclusion that a client was not a politically exposed person, while its own searches surfaced reporting on close ties to the Russian president. Inherited classifications carry inherited risk, and OFAC exposure attaches on strict liability regardless of who made the original call. Our note on the Merrill SAR monitoring penalty covers the calibration side of the same problem.

What is still uncertain about this case?

Several things remain open, and the most consequential is scope. The independent lookback set out in the FinCEN order covers foreign currency wires plus any other product where similar data gaps appear, so the firm does not yet know how many late suspicious activity reports it will end up filing or what those filings will surface.

The timetable is tight. The lookback consultant must deliver a report within 180 days of the consent order, and the filings follow within 90 days of that, with one 60-day extension available. Firms that have run remediation lookbacks know how often those windows slip once transaction populations turn out to be larger than assumed.

The waiver design also invites debate. Up to 15 million dollars of the penalty can be extinguished by qualifying spend on the AML program review, with FinCEN deciding at its sole discretion what counts. It rewards real investment over cheque-writing, but it makes the effective cost of the resolution unknowable until 2028.

Two more caveats matter for anyone quoting the UBS AML penalty. The willfulness admission is the civil standard under 31 U.S.C. 5321(a)(1), meaning reckless disregard or willful blindness, not a criminal finding. And the failure that ran longest was human: staff spotted a coding defect and did not escalate it, which no monitoring upgrade would have caught.

How does the UBS AML penalty compare with earlier actions?

The UBS AML penalty is the second record broker-dealer resolution in five months, and the structure is identical both times: FinCEN sets the headline number, the SEC and FINRA resolve in parallel, and their payments are credited. That pattern is now the template for securities-sector AML enforcement in the United States.

ActionDateFinCEN penaltyParallel penaltiesConduct period
UBS Financial Services3 August 2026125 million dollarsSEC 20m, FINRA 20m, CFTC 8mJan 2019 to Jun 2023
Canaccord Genuity6 March 202680 million dollarsSEC 20m, FINRA 20mMar 2018 to Jun 2024
UBS Financial Services11 December 201814.5 million dollarsFINRA 4.5m2004 to Apr 2017

The multiplier is the story. UBS Financial Services paid 14.5 million dollars in 2018 for weak foreign currency wire monitoring and roughly nine times that in 2026 for not fixing it. Our earlier piece on the Canaccord FinCEN penalty set out the previous record, which stood for less than half a year.

The two agencies also sized the same window differently. FINRA cited more than 60,000 wires exceeding 10 billion dollars where FinCEN counted 61,500 worth 10.5 billion, so treat the FinCEN number as the outer bound of one population, not a second set of transactions. Bill St. Louis, FINRA's head of enforcement, said member firms must build AML programs "tailored to their business model", which is the test an inherited global template tends to fail. FinCEN's enforcement factors go further back, finding the firm failed to monitor these wires effectively for nearly twenty years in total.

How should compliance teams respond?

Start with coverage rather than tuning, because coverage is what the UBS AML penalty punished. Map every transaction population to the monitoring scenario that should see it, then test the lineage end to end and document which populations are excluded and why.

Second, treat any discovered alerting defect as an escalation event with a named owner and a fixed clock, because the delay in escalating cost more here than the defect itself. Third, re-read your negative news and source of wealth dispositions for the top decile of customer risk. Ask whether each one explains a decision or merely records that a search ran. Fourth, stop inheriting classifications from affiliates without your own evidence, especially politically exposed person calls. Fifth, tell your regulator when remediation slips, because concealment was an aggravating factor in this order.

Where Zyphe fits. Zyphe was built for the identity half of that problem. Verification runs from an NFC chip read to ICAO 9303 and eIDAS standards with two-step liveness and no image upload, personal data is split into shards across separate nodes so no single node holds a complete record, and the reusable credential lets a customer re-present a verified identity without your firm accumulating another copy of it. If you want to see how that changes your customer due diligence evidence trail, book a demo or read how our AML software and KYC software fit an existing stack.

The bottom line

The UBS AML penalty shows that regulators are no longer pricing the original control failure. They are pricing the gap between what a firm promised its supervisor and what it delivered, and this order shows that gap being measured in years, in undisclosed slippage and in a lookback that produced nothing. For teams running KYC and AML, the practical lesson is that coverage evidence and escalation discipline now sit alongside model tuning as first-order controls, and that a customer file which was accurate at onboarding is not the same as one that is accurate today.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

FinCEN assessed 125 million dollars against UBS Financial Services Inc, the US broker-dealer subsidiary of UBS Group AG, on 3 August 2026. FinCEN credited 48 million dollars of parallel payments to the SEC, FINRA and the CFTC. The firm pays 62 million dollars to the Treasury on execution and 15 million dollars by 31 May 2028, subject to a waiver for qualifying remediation spend.

FinCEN describes it as the largest penalty ever imposed against a broker-dealer for Bank Secrecy Act violations. The previous record was the 80 million dollar penalty against Canaccord Genuity in March 2026. Broker-dealer figures remain far below the largest bank cases, but the gap has narrowed sharply in 2026.

It admitted willful violations of the Bank Secrecy Act, including failing to implement and maintain an AML program and failing to file suspicious activity reports. Willfulness here is the civil standard of reckless disregard or willful blindness under 31 U.S.C. 5321(a)(1), not a criminal finding, and the firm admitted it only in that sense.

FinCEN focused on high-risk wealth-management clients with ties to Russia and Latin America. It cited unreviewed negative news, unexamined source of wealth, a missed change of domicile and a politically exposed person assessment adopted from an affiliate. After the invasion of Ukraine, the firm identified about 100 customers domiciled in or deriving wealth from Russia.

It must engage an independent consultant to run a suspicious activity report lookback across the relevant period, report to FinCEN within 180 days, and file the resulting reports within 90 days after that. A separate independent review of its AML program must address cartel and southwest border risk, Iran, Russia and Venezuela.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo