Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Operational Risk

FinCEN Hit UBS With a Record $125 Million 'Willful' BSA Fine — and FINRA Added $20 Million More. What the Double-Barrel Enforcement Action Means for Your AML Program.

FinCEN's $125 million penalty against UBS Financial Services — the largest BSA fine ever imposed on a broker-dealer — combined with FINRA's simultaneous $20 million fine creates a $145 million enforcement landmark. Both actions trace back to the same root cause: UBS knew its transaction monitoring had gaps, promised to fix them after a 2018 settlement, and didn't. Here's what 'reasonably designed' AML monitoring actually requires.

By Rebecca Leung · September 8, 2026 ·
Table of Contents

TL;DR

  • FinCEN assessed a record $125 million civil penalty against UBS Financial Services in August 2026 — the largest BSA fine ever imposed on a broker-dealer — for “willful” violations of the Bank Secrecy Act. FINRA separately fined UBS $20 million on August 3, 2026. Total: $145 million.
  • The same institution had settled with FinCEN in December 2018 for $14.5 million for similar AML program failures. UBS acknowledged the gaps, promised to fix them, and then failed to monitor 60,000+ foreign currency wires totaling $10 billion over the next four years.
  • FinCEN’s “willful” designation — the worst characterization available — reflects that UBS knew of the deficiencies, was told by regulators, and chose not to remediate adequately.
  • The three enforcement lessons: (1) known gaps that aren’t fixed become “willful” violations; (2) transaction monitoring scope — not just the existence of a program — is what examiners evaluate; (3) CDD failures for high-risk customers are examined independently from monitoring failures.

The worst word in a FinCEN enforcement action isn’t “violation.” It’s “willful.”

Violation means you failed to comply. Willful means you knew you were failing to comply — regulators told you, you agreed to fix it, and you didn’t. That’s the story FinCEN told in August 2026 when it imposed a $125 million civil penalty against UBS Financial Services Inc. — the largest BSA penalty ever assessed against a broker-dealer. FINRA piled on $20 million more on August 3, 2026.

The same institution had settled with FinCEN in December 2018 for $14.5 million for substantially similar AML program deficiencies. That settlement included a promise to fix the underlying gaps. What followed, according to FinCEN’s consent order: four more years of the same failures, applied to 60,000+ transactions totaling $10 billion.

That trajectory — settlement, promise, continued failure — is what produced the “willful” designation. And the record fine.

The Double-Barrel Action: What FinCEN and FINRA Each Found

The two enforcement actions are parallel but distinct.

FinCEN’s civil money penalty, filed under FinCEN’s BSA enforcement authority, found that UBS Financial Services willfully violated the BSA by:

  • Failing to implement and maintain an AML program reasonably designed to detect and report suspicious transactions involving foreign currency wires
  • Failing to reasonably implement its customer due diligence program for high-risk retail customers — particularly those with ties to Russia and Latin America
  • Failing to file hundreds of suspicious activity reports in a timely manner

FinCEN’s consent order characterizes the violations as willful based on the institution’s prior settlement, the knowledge of gaps documented in internal records, and the continued operation with known deficiencies for more than four years after the 2018 settlement.

FINRA’s action, brought under FINRA’s AML supervision rules, found that UBS Financial failed to establish and implement an AML compliance program reasonably expected to detect and cause the reporting of suspicious transactions. FINRA’s jurisdiction is supervision of FINRA member firms; FinCEN’s is BSA compliance by financial institutions. Both came to the same underlying conclusion: the monitoring program wasn’t adequate for what it was supposed to cover.

Total penalty: $125 million (FinCEN) + $20 million (FINRA) = $145 million, plus the cost of the mandatory third-party transaction lookback that FinCEN required.

Eight Years of Known Deficiencies

The timeline is important because it’s what made the “willful” finding possible.

December 2018: FinCEN and FINRA settled with UBS Financial Services for $14.5 million covering AML program failures in its foreign currency wire business. The settlement was explicit: UBS acknowledged the deficiencies and committed to remediation.

January 2019 – June 2023: In the four-plus years after that settlement, UBS failed to monitor more than 60,000 foreign currency wires totaling more than $10 billion. The monitoring gaps weren’t new — they were substantially the same gaps that the 2018 settlement had identified.

August 2026: FinCEN’s consent order documents that “UBSFS knew its transaction-monitoring arrangements were inadequate, promised regulators that the problems would be corrected, and nevertheless allowed material gaps to remain for more than four years.”

That sentence is the basis for the “willful” designation. It’s also the clearest articulation of what regulators mean when they say willfulness: not malice, but awareness of a legal obligation, awareness of your own failure to meet it, and a choice not to fix it.

The 2018 settlement changed the evidentiary landscape. Before it, UBS could potentially argue that its monitoring program was a good-faith attempt to comply with ambiguous regulatory expectations. After the settlement, that argument was foreclosed. Regulators had already told them what was insufficient. What followed was indefensible.

What “Reasonably Designed” Actually Means

Both actions center on the “reasonably designed” standard under the BSA. That standard is the core requirement for every AML program: the program must be reasonably designed to detect and report suspicious activity. The word “designed” implies that the program’s structure, scope, and methodology must match your actual risk profile.

UBS had a transaction monitoring program. The violation wasn’t that monitoring didn’t exist — it was that the program’s scope failed to cover a high-risk transaction type that ran through UBS’s actual business.

Foreign currency wires are not obscure transactions. For broker-dealers with retail clients in high-risk jurisdictions, they are among the most significant AML risk vectors: international transfers, often large dollar amounts, often crossing into jurisdictions with elevated sanctions and money laundering risk. The fact that UBS’s monitoring didn’t adequately cover them — despite a prior settlement specifically about that gap — is what produced the “knew and didn’t fix” narrative.

What this means for every AML compliance program:

DimensionWhat Examiners Look ForCommon Gap
Transaction monitoring scopeCoverage of all meaningful transaction types, calibrated to actual transaction activityMonitoring rules that cover “standard” transactions but miss high-volume, high-risk transaction types specific to the institution’s business
CDD implementationActual application of enhanced due diligence criteria to high-risk customer segmentsPolicies that describe EDD requirements without documented evidence of implementation
SAR filing timelinessSARs filed within 30 days of determination; delays documented with justificationBacklogs created by monitoring gaps; suspicious transactions identified late because monitoring rules missed them
Geographic riskSpecific protocols for customers with nexus to high-risk jurisdictionsGeneric country risk ratings not translated into account-level controls

The “reasonably designed” standard doesn’t set a bright-line rule for how many monitoring rules you need or what thresholds to use. It requires that your program be designed to detect the suspicious activity that flows through your specific business — which means your monitoring scope has to match your transaction activity, and your monitoring thresholds have to be calibrated to your risk profile.

The CDD Failure: Where Monitoring Meets Customer Risk

The CDD findings are separate from the monitoring findings but closely related. FinCEN found that UBS failed to conduct adequate due diligence on high-risk retail customers — particularly those with ties to Russia and Latin America.

CDD failure in this context isn’t “we didn’t collect KYC documents.” It’s a failure to reasonably implement the enhanced due diligence framework for customers who warranted it. The distinction matters: FinCEN’s scam center alert earlier this month reinforced that regulators expect CDD to be ongoing, not a one-time onboarding exercise. Customers’ risk profiles change. CDD programs have to keep pace.

The connection to monitoring is direct: if your CDD program isn’t identifying which customers warrant enhanced scrutiny, your transaction monitoring thresholds can’t be calibrated to reflect that risk. The two failures reinforce each other. A customer flagged as high-risk should trigger enhanced monitoring rules. If CDD didn’t flag them, enhanced monitoring rules don’t apply, and the monitoring gap expands.

The SAR Filing Failures

The third category of findings — failure to file SARs timely — flows directly from the first two. If monitoring doesn’t detect a transaction, you can’t file a SAR on it. If CDD doesn’t identify a customer as high-risk, monitoring thresholds that depend on risk tier won’t trigger on their activity.

FinCEN’s consent order required a third-party transaction lookback focused on the same geographies and risk categories where the monitoring and CDD failures were concentrated: U.S. Southwest border, narcotics trafficking networks, Iran, Russia, and Venezuela. The lookback firm must identify any suspicious transactions that went undetected and ensure SARs are filed retroactively.

This creates a secondary exposure problem. Every SAR identified in the lookback is evidence that a SAR should have been filed and wasn’t. Every one of those is an additional BSA violation in the historical record. The mandatory lookback isn’t just expensive — it’s self-documenting additional violations that FinCEN can reference in any future enforcement action.

FINRA’s Reg BI enforcement wave this year demonstrated a similar pattern in the supervision context: when regulators identify a systemic failure through enforcement, the subsequent monitoring of that firm intensifies. After the 2018 settlement, UBS was on a shorter leash. The 2026 action reflects how short that leash had become.

The Compliance Program Lessons

The UBS enforcement action teaches three things that apply to every broker-dealer and financial institution with an AML program.

1. Known gaps that aren’t remediated become willful violations. If your compliance team has documented monitoring gaps, CDD weaknesses, or SAR filing delays — and those findings haven’t been remediated — you have a “known and not fixed” problem. The 2018 UBS settlement is an extreme example, but the underlying principle applies to any documented finding that isn’t addressed: you’ve created evidence of awareness without evidence of action. Document the gap, escalate it, and drive it to closure — the way a mature issues management process requires.

2. Transaction monitoring scope is the first thing examiners evaluate. The question isn’t “do you have a transaction monitoring system?” It’s “does your transaction monitoring cover the transaction types that carry meaningful AML risk for your specific customer base and business model?” For a broker-dealer with international clients, foreign currency wires should be an obvious answer. Map your transaction activity against your monitoring coverage. The gaps are your exposure.

3. CDD failure creates monitoring failure. An EDD policy that isn’t implemented — meaning there’s no documentation that customers who meet high-risk criteria actually received enhanced scrutiny — will show up as a separate finding alongside monitoring failures, not instead of them. Regulators examine both. The AML/BSA Risk Assessment Template includes a risk-tiered CDD implementation framework with documentation requirements that map to examiner expectations — specifically the documentation gap that lets EDD policies sit on paper without evidence of implementation.

So What?

The UBS action is notable for the size of the fine and the “willful” designation, but the underlying violations — inadequate monitoring scope, insufficient CDD for high-risk customers, SAR filing delays — are among the most common BSA exam findings for broker-dealers and money service businesses.

The difference between UBS’s $145 million outcome and a more typical enforcement result is the 2018 settlement. The settlement created a documented record of awareness that foreclosed every good-faith argument. Most compliance programs don’t have a prior consent order as a complicating factor — but they often have documented findings that are weeks or months overdue for remediation.

Run this exercise before your next exam: pull every open AML-related finding in your issues tracker. For each one, check when it was identified and what the documented remediation status is. If there are findings more than 90 days old without a remediation action or an approved extension with documented rationale, you have a potential “knew and didn’t fix” problem — even without a prior consent order.

The 132-indicator KRI Library includes 10 BSA/AML-specific KRIs covering SAR filing rates, transaction monitoring false positive rates, high-risk customer CDD completion, and geographic exposure metrics — the indicators that would have flagged UBS’s trajectory before it became a $145 million problem.

“Willful” is an outcome, not a character judgment. It’s what happens when a compliance program treats documented gaps as acceptable operating conditions instead of problems to fix. The UBS timeline makes that trajectory visible in a way that should reframe how every BSA officer thinks about their open findings list.


Sources: FinCEN: Record $125M Penalty Against UBS Financial Services | FINRA: $20M Fine Against UBS Financial (FINRA.org) | BusinessWire: FINRA UBS Announcement | Miller & Chevalier: FinCEN $125M Penalty Analysis | AML Intelligence: UBS Record Fine Coverage

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What makes a BSA violation 'willful' under FinCEN's standard?
FinCEN's willful designation requires showing that the institution knew of a legal obligation, was aware of its existing violation, and deliberately chose not to comply. In UBS's case, the 2018 consent order provided direct evidence of awareness — FinCEN had already told UBS that its transaction monitoring was inadequate, and UBS had agreed in writing to fix it. The subsequent four years of the same failures met FinCEN's willful standard because UBS couldn't claim ignorance of the obligation or the gap.
What did UBS's transaction monitoring program actually fail to cover?
UBS's monitoring program failed to adequately cover foreign currency wires, a specific and high-risk transaction type. Between January 2019 and June 2023, UBS failed to monitor more than 60,000 foreign currency wires totaling more than $10 billion. This wasn't a case of no monitoring system — UBS had AML controls. The failure was incomplete scope: a high-risk transaction category wasn't covered adequately by the existing monitoring rules.
What does 'reasonably designed' mean for an AML program under the BSA?
The BSA requires financial institutions to establish and implement an AML compliance program 'reasonably designed to prevent the financial institution from being used to facilitate money laundering or the financing of terrorist activities.' The word 'designed' is key: it's not enough to have a program on paper. The program must be designed to detect the suspicious activity that flows through your specific business — which means your transaction monitoring rules and thresholds must cover the transaction types, geographies, and customer segments that carry the highest risk for your institution.
What was the specific CDD failure in the UBS enforcement action?
FinCEN and FINRA found that UBS failed to conduct adequate customer due diligence for high-risk retail customers, particularly those with ties to Russia and Latin America. CDD failure in this context means the program existed but wasn't 'reasonably implemented' for a specific high-risk segment — UBS wasn't applying enhanced due diligence protocols appropriately where the risk profile warranted them. The CDD gaps compounded the monitoring gaps: if you don't know your customer's risk profile, your monitoring thresholds can't be calibrated to their actual risk.
What does the FinCEN-required transaction lookback mean for UBS going forward?
FinCEN's consent order requires UBS to hire a third-party firm to conduct a transaction lookback — a retrospective review of historical transactions to identify suspicious activity that should have been reported via SAR but wasn't. The lookback focuses on the geographic and customer risk categories where UBS's monitoring and CDD failures were concentrated: U.S. Southwest border, narcotics trafficking, Iran, Russia, and Venezuela. Any SARs identified must be filed. The lookback is both remediation and additional exposure: every identified SAR is evidence of a prior BSA violation.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.