Feature Compliance Strategy
FINRA's Low-Priced Securities AML Trap: What the Pictet and Blue Ocean Fines Mean for Your Surveillance Program
FINRA fined Pictet Overseas ($610K) and Blue Ocean ATS ($550K) for AML failures on low-priced securities in 2026. One firm missed $300M in transactions routed through an affiliate's omnibus account. The other had one employee reviewing two reports. Here's the five-part compliance trap these cases expose.
Table of Contents
TL;DR
- FINRA fined Pictet Overseas $610,000 and Blue Ocean ATS $550,000 for AML and supervisory failures on low-priced securities in 2026
- Pictet processed $300 million in low-priced securities transactions, more than 70% through an affiliate’s omnibus account that was outside its effective surveillance scope
- Blue Ocean had one employee manually reviewing two reports for what the firm describes as 95% of all overnight U.S. equity trading volume—no automated pattern detection, no spoofing or layering surveillance
- FINRA’s enforcement position: the risks in low-priced securities are “well-established,” meaning manual review is not a surveillance program, and affiliates’ omnibus accounts don’t exempt underlying transactions from your AML obligations
- Five compliance traps these cases expose—each one a gap your program might have right now
Most broker-dealer AML programs are designed around what the firm can see. The Pictet and Blue Ocean enforcement actions are a reminder that what you can’t see—or chose not to look at—is where FINRA is looking.
In May 2026, FINRA announced joint enforcement actions against Pictet Overseas Inc. and Blue Ocean ATS totaling more than $1.1 million. The violations weren’t exotic. They weren’t sophisticated financial crimes the firm had no way to detect. They were failures to monitor transactions the firms knew they had, in a risk category the regulator has been warning about for more than a decade.
Pictet’s core problem was routing: most of the firm’s low-priced securities activity moved through an affiliate’s omnibus account, making it invisible to Pictet’s internal surveillance. Blue Ocean’s core problem was scale: the firm had built a trading platform that processes the majority of overnight U.S. equity trading, and staffed its AML surveillance with one person running two manual reports.
Both firms resolved these actions without admitting or denying the charges. But the findings document what FINRA considers a compliant program for these risks—and neither firm was close.
What FINRA Actually Found
The Pictet Problem: The Affiliate’s Omnibus Account Is Still Your Problem
Between February 2022 and March 2023, Pictet Overseas executed approximately $300 million in low-priced securities transactions, involving more than 150 million shares. That’s a meaningful volume. The problem wasn’t the volume—it was where it sat.
More than 70% of those transactions flowed through an omnibus account held by Pictet’s own foreign financial institution affiliate. In structure, that account appeared to Pictet’s monitoring systems as a counterparty account, not as a collection of transactions by underlying customers. The firm’s surveillance treated the account as a foreign financial institution relationship and applied FFI-level monitoring to it—which meant no transaction-level surveillance on the $200-plus million of low-priced activity behind it.
FINRA found two related failures:
First, Pictet failed to apply AML monitoring reasonably designed to detect suspicious transactions in low-priced securities that occurred through the affiliate omnibus account. The monitoring that existed was not calibrated to the actual risk: customers whose trading represented more than 20% of daily market volume on individual days were not being flagged, investigated, or evaluated for potential suspicious activity.
Second, Pictet failed to implement a reasonably designed due diligence program for its FFI correspondent accounts. FINRA’s rules require broker-dealers to conduct periodic reviews of FFI account activity—not just at onboarding, but on an ongoing basis. Pictet’s FFI due diligence program did not meet that standard for the affiliate relationship that was generating the low-priced activity.
The enforcement message is direct: running your transactions through an affiliate’s account doesn’t remove your AML obligation to monitor those transactions. If the economic activity is yours—in the sense that it’s your customers, your platform, your firm’s relationship—the AML obligation follows the substance, not the account structure.
The Blue Ocean Problem: One Employee Is Not a Surveillance Program
Blue Ocean ATS occupies a distinctive position in U.S. equity markets. The firm describes itself as handling approximately 95% of all overnight trading volume in U.S. equities. That’s an extraordinary concentration of trading activity for a single ATS. It also means that whatever Blue Ocean is doing in overnight markets, it’s doing at scale.
The problem FINRA documented is that Blue Ocean’s AML surveillance for low-priced securities consisted primarily of one employee manually reviewing two reports: a wash sale report and a low-priced securities report. The employee did not have automated tools for pattern detection. The firm’s surveillance did not cover spoofing, layering, or other manipulative order entry patterns that are standard concerns in low-priced securities markets.
FINRA ordered Blue Ocean to certify that it has remediated the deficiencies in its AML compliance program. The fine is the fine, but the remediation requirement is the real cost: building out an actual surveillance infrastructure rather than continuing to rely on a single reviewer running periodic reports.
The enforcement message here is about proportionality. A firm that processes that volume of trading activity—including a substantial volume of low-priced securities—cannot staff its AML surveillance in the same way a small introducing broker-dealer might. The level of monitoring must be commensurate with the volume and risk profile of the activity being processed.
The Five Compliance Traps These Cases Expose
These two enforcement actions aren’t isolated oddities. They document failure patterns that FINRA has been warning about for years, and that appear in AML programs far beyond the two firms named.
Trap 1: The Affiliate’s Omnibus Account Is Outside Your Surveillance Scope
If a significant portion of your firm’s transactions flow through an affiliated entity’s account—a holding company affiliate, a parent’s correspondent account, a related entity—and your surveillance is calibrated to that account rather than to the underlying transactions, you have the Pictet problem.
The question to ask: when you look at your highest-volume counterparty accounts, do you understand what’s behind them? Are those accounts transparent to your transaction monitoring, or are they treated as pre-screened counterparties whose underlying activity you’re not seeing?
This is particularly acute for broker-dealers that are part of larger financial groups. The affiliate relationship can create a structural blind spot in surveillance if the AML monitoring design doesn’t account for it.
Trap 2: FFI Correspondent Due Diligence Without Ongoing Review
FINRA Rule 3310 requires that AML programs include “ongoing customer due diligence.” For FFI correspondent accounts, that means periodic reviews of account activity—not just due diligence at account opening.
Both firms in this enforcement action had FFI relationships. The pattern FINRA documented is that onboarding due diligence was completed, but ongoing activity monitoring was either absent or insufficient relative to the volume and risk profile of the activity.
The question to ask: for every FFI correspondent account, when was the last time you reviewed the account’s activity against what you expected at onboarding? When transaction volume, trading patterns, or customer composition changed in that account, did your due diligence update?
Trap 3: Manual Review Is Not Automated Surveillance
This is the Blue Ocean lesson, and it appears in AML programs across firm sizes. A compliance team that assigns a reviewer to check a report periodically is doing something—but FINRA does not treat that as surveillance when it comes to pattern detection.
Surveillance means automated tools that look for patterns across transactions: volume concentration, wash trading indicators, spoofing and layering signals, anomalous trading sequences. A human reviewer looking at a transaction-level report can catch individual suspicious transactions, but will miss patterns that emerge across thousands of transactions or across multiple accounts coordinating their activity.
The question to ask: for each category of risk your AML program is supposed to cover, what’s the detection mechanism? If the answer is “a reviewer checks a report,” ask whether that reviewer has the analytical capacity—and the analytical tools—to detect coordinated patterns at the volume the firm is processing.
Trap 4: Proportionality—Surveillance Must Match Risk Profile
Regulators evaluate AML programs against the risk profile of the activity being monitored, not against an abstract compliance standard. A program that would be adequate for a small introducing broker-dealer processing $50 million per year in low-priced securities is not adequate for an ATS processing hundreds of millions of dollars per year in the same category.
FINRA’s explicit language in the Blue Ocean finding is instructive: “Blue Ocean’s and Pictet’s monitoring systems were inadequate given their customers’ low-priced securities trading.” The inadequacy wasn’t measured against a static standard—it was measured against the volume and risk characteristics of what the firms were actually doing.
The question to ask: has your AML program been reviewed against your current transaction volumes, not the volumes you had when the program was designed? For firms that have grown rapidly—or where a particular business line has grown rapidly—program proportionality can fall behind business growth without anyone making an affirmative decision to reduce monitoring.
Trap 5: Low-Priced Securities Require Tailored Surveillance, Not Generic AML Coverage
FINRA has published specific guidance on low-priced securities (Regulatory Notice 19-18 and earlier guidance). The regulator’s enforcement history going back well over a decade treats pump-and-dump schemes, coordinated trading, and money laundering through low-priced securities as well-established risks. When FINRA says a risk is “well-established,” that language signals that failing to address it will be treated as willful inadequacy rather than mere oversight.
Tailored surveillance means: detection logic specific to the manipulation patterns common in low-priced securities (matched trades, circular trading, high-volume price movement without fundamental news), concentration monitoring (identifying when a customer’s trading represents a significant share of market volume), and specific customer due diligence for customers who are actively trading low-priced securities at meaningful volume.
Generic transaction monitoring—designed around dollar thresholds and structured for CTR-relevant activity—does not catch these patterns. If your AML program’s low-priced securities coverage is generic transaction monitoring plus a periodic report, you have the Blue Ocean fact pattern.
What to Test in Your Own Program
The Pictet and Blue Ocean findings map to specific questions your compliance team can answer now, before FINRA asks them.
Account structure review: Map your highest-volume accounts. For each account that represents more than 5% of your transaction volume, identify whether the account is transparent to surveillance or whether the underlying transactions are not individually monitored. Flag any affiliate, omnibus, or correspondent account structures where transaction-level data isn’t flowing into your AML monitoring.
FFI correspondent account due diligence calendar: List every FFI correspondent account and the date of its most recent activity review. Flag accounts where the review is more than 12 months old, or where transaction volume has increased materially since the last review.
Surveillance coverage gap analysis: For each major risk category in your AML program (low-priced securities, wire transfers, structured deposits, crypto on/off-ramps), document the detection mechanism. Distinguish between manual review, automated transaction-level monitoring, and pattern-based surveillance. For categories where the coverage is manual review only, assess whether that’s proportionate to the volume and risk.
Pattern detection inventory: List the manipulative trading patterns your surveillance is designed to detect. If spoofing, layering, wash trading, and coordinated activity are not on that list—and your firm processes any meaningful volume of low-priced securities—document that gap.
The escalation from Canaccord Genuity’s record broker-dealer BSA penalty in March 2026 to UBS’s $125 million record-breaking penalty in August 2026 to FINRA’s coordinated actions in between reflects an enforcement environment where broker-dealer AML is under continuous scrutiny. FINRA’s independent testing requirements exist partly because regulators know internal compliance teams often overestimate their program’s effectiveness—especially in categories where the testing is manual and the risk patterns require pattern-matching to detect.
So What?
The Pictet and Blue Ocean enforcement actions don’t introduce new legal obligations. They document existing obligations—FINRA Rule 3310, FFI correspondent account due diligence, proportionate surveillance—applied to fact patterns where firms either didn’t design their programs to see the risk, or didn’t build the analytical capacity to detect it.
Neither firm got fined for a novel legal theory. Both got fined for doing exactly what FINRA said would result in a fine: having surveillance that wasn’t designed for the actual risk profile of their low-priced securities activity.
The gap between “we have an AML program” and “our AML program covers the risk our business actually creates” is where enforcement lives. These two cases are a very specific description of what that gap looks like—and what it costs when FINRA finds it before you do.
External references:
- FINRA Fines Pictet Overseas and Blue Ocean ATS for AML and Supervisory Violations
- FINRA enforcement release via BusinessWire (May 2026)
- FINRA Anti-Money Laundering Rules Guidance
- FINRA Regulatory Notice 19-18 on Low-Priced Securities
- Pictet Overseas and Blue Ocean ATS Fined $1.1 Million for AML Violations
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did FINRA find in the Pictet Overseas enforcement action?
What did FINRA find in the Blue Ocean ATS enforcement action?
Why is monitoring low-priced securities a specific AML obligation for broker-dealers?
Do AML obligations apply to transactions routed through an affiliate's omnibus account?
What is the minimum surveillance standard FINRA expects for low-priced securities?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Compliance Strategy
Three Bosses, One Compliance Team: How Nonbank Fintechs Navigate FTC, State, and Sponsor Bank Oversight in 2026
Nonbank fintechs answer to at least three distinct oversight relationships simultaneously—FTC, state regulators, and their sponsor bank. Each has different priorities, evidence standards, and enforcement timelines. Here's how to build a compliance program that holds up across all three.
Aug 24, 2026
Compliance Strategy
Conduct Risk KRIs: Indicators, Thresholds, and Incentive Blind Spots
Build conduct risk key risk indicators that expose sales pressure, weak overrides, complaints, cancellations, and customer harm before they become findings.
Aug 21, 2026
Compliance Strategy
Five Statutes Generated 75% of All FDIC Compliance Violations in 2025. Here's What They Are.
The FDIC's 2026 Consumer Compliance Supervisory Highlights identified 1,155 violations in 2025 exams. Five statutes — TILA, EFTA, the Flood Act, TISA, and HMDA — drove three-quarters of them. Here is what examiners actually cited and what your compliance program needs to test.
Aug 18, 2026