Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Operational Risk

Two Employees Falsified Compliance Records. 160 SARs Went Unfiled. FinCEN's $80 Million Fine Against Canaccord Genuity Shows Exactly How an AML Program Collapses.

On March 6, 2026, FinCEN, the SEC, and FINRA imposed an $80 million penalty on broker-dealer Canaccord Genuity for willful Bank Secrecy Act violations — including surveillance reports that went unreviewed for four years, falsified compliance records, and 160+ unfiled SARs tied to OTC securities fraud. Here's what the consent order reveals about AML program failure.

By Rebecca Leung · October 4, 2026 ·
Table of Contents

TL;DR

  • On March 6, 2026, FinCEN, the SEC, and FINRA imposed an $80 million civil penalty on Canaccord Genuity for willful BSA violations — at the time of issuance, the largest penalty ever assessed against a broker-dealer
  • Surveillance reports went unreviewed for up to four years; two compliance employees then falsified records to conceal the backlog
  • At least 160 SARs went unfiled, tied to thousands of suspicious OTC securities transactions
  • Canaccord’s high-risk OTC market-making business was under-supported by an under-resourced AML program that was never redesigned to match the business it was supposed to cover
  • The cascading failure pattern — inadequate program design → review backlog → falsified records → unfiled SARs — appears in enforcement actions repeatedly; the case is a template for what regulators treat as willful

The compliance team was running surveillance. The system was generating alerts. The reports were being logged.

They just weren’t being reviewed.

By the time FinCEN examined Canaccord Genuity’s AML program, surveillance reports had been sitting unreviewed for up to four years. Thousands of OTC securities transactions had triggered alerts. At least 160 of them should have generated suspicious activity reports filed with FinCEN. They didn’t.

When examiners started asking questions, they found something worse than neglect: two compliance employees had falsified records to make the backlog disappear on paper.

The result, announced March 6, 2026: an $80 million civil money penalty assessed jointly by FinCEN, the SEC, and FINRA — the largest BSA fine ever assessed against a broker-dealer at that point. The CCO and deputy were separately charged by FINRA.

This wasn’t a case of a firm that ignored AML entirely. It was a firm with an AML program that was designed for a different business than the one it was trying to cover, staffed below the level required to keep up with alert volume, and ultimately papered over rather than fixed. That sequence — wrong design, inadequate resources, concealment — is the specific pattern FinCEN treats as willful.


The Business That Created the Risk: OTC Market-Making

Canaccord Genuity ran a significant OTC market-making operation. OTC securities — penny stocks, small caps, shell companies, and thinly traded issues outside major exchanges — carry substantially elevated BSA risk. FinCEN’s own guidance and a generation of enforcement actions have established that OTC securities markets are routinely used for pump-and-dump schemes, layering, wash trading, and other manipulation techniques that generate illicit profits and obscure their source.

A firm with a major OTC market-making desk is, by definition, handling a product line that FinCEN views as high-risk. The regulatory expectation that follows from that is straightforward: the AML program must be designed and resourced to match. The surveillance scenarios, the SAR filing thresholds, the customer due diligence depth, and the staff capacity for review all need to be calibrated to OTC securities risk — not imported from a lower-risk business segment and applied unchanged.

What FinCEN found at Canaccord was an AML program that had not made that adjustment. The program’s structure and resources reflected a different level of risk than the OTC business actually presented. Alerts were generated — the system was working — but the human review layer that was supposed to convert those alerts into SAR decisions was chronically under-capacity.

That gap between alert volume and review capacity is where the failure began.


The Surveillance Backlog: Four Years of Unreviewed Reports

When a surveillance system flags a transaction, the output is a report that gets routed to a compliance analyst for review. The analyst evaluates the transaction against the alert criteria, looks at account history and context, makes a SAR/no-SAR determination, and documents the decision.

That review process takes time. It requires judgment. It requires personnel who understand the specific risk profile of OTC securities, can recognize manipulation patterns, and know when to escalate.

Canaccord didn’t have enough of those people to keep up with report volume. The result: reports piled up. Weeks of backlog became months. Months became years. By the time FinCEN began its review, some surveillance reports were four years old — still unreviewed, still unresolved, still sitting in a queue.

The transactions those reports covered had continued. Some had involved multiple follow-on trades in the same accounts. Some had continued patterns that, if someone had looked, would have resulted in SAR filings well before the accounts grew into significant problems.

At least 160 SARs were never filed that should have been. Each unfiled SAR is a statutory violation of the Bank Secrecy Act. FinCEN treated each category of SAR-filing failure as a separate violation category, and the combination of volume, pattern, and duration supported a willfulness finding.


The Falsified Records: Where Negligence Became Criminal Exposure

The surveillance backlog by itself might have been treated as negligence — a resource failure, inadequate program design, a remediable gap. What converted it to willful violation territory was what happened next.

Two compliance employees falsified records to show that the delinquent surveillance reports had been completed. The documentation that would have appeared in an audit trail — the review log, the completion timestamps, the sign-off records — was fabricated to show work that hadn’t been done.

This didn’t resolve the backlog. It hid it. When examiners examined the AML program records, they found documentation that appeared to show completed reviews. When they went a level deeper and examined whether the reviews had actually been performed — whether the outputs were consistent with genuine analysis, whether related SAR filings had followed — the fabrication became apparent.

Falsifying BSA compliance records is not a compliance gap. It’s a federal crime. The two individuals involved faced FINRA disciplinary proceedings in connection with the action.

For the firm, the falsification was evidence of knowledge: the employees knew the reviews hadn’t been done, knew the program was deficient, and chose to conceal it rather than escalate. That’s exactly the fact pattern FinCEN points to when it makes willfulness findings — not carelessness, but awareness of a known deficiency followed by a decision not to fix it.


The CDD Failure: Foreign Correspondent Accounts

Alongside the SAR failures, FinCEN cited inadequate customer due diligence for foreign correspondent accounts. Foreign correspondent relationships — where a domestic broker-dealer processes transactions on behalf of foreign financial institutions or their customers — are among the highest-risk relationships in the BSA framework.

FinCEN’s Foreign Correspondent Account Recordkeeping and Due Diligence rule (31 CFR 1010.610-611, implementing Section 312 of the USA PATRIOT Act) requires institutions to develop a due diligence program specific to foreign correspondent accounts, with enhanced scrutiny for accounts from jurisdictions with elevated money laundering risk, political exposure, or weak AML regimes.

Canaccord’s CDD program for these accounts was insufficient. The depth of review, the documentation of the correspondent’s AML controls, and the ongoing monitoring calibrated to the correspondent’s risk profile did not meet the regulatory standard. That failure compounded the SAR-filing violations: if you don’t know who your correspondent’s underlying customers are, you can’t make an informed SAR-filing decision.


What the Pattern Reveals: Four Sequential Failures

The Canaccord enforcement action follows a pattern that appears consistently in large BSA enforcement actions:

StageWhat Happened
1. Wrong program designAML program not calibrated to the risk profile of the OTC market-making business
2. Inadequate resourcingAlert volume exceeded review capacity; reports queued without resolution
3. Backlog not escalatedKnown backlog not surfaced to senior management or the board
4. ConcealmentTwo employees falsified records rather than escalating the unreviewed reports

Each stage made the next one worse. A wrong program design created excess alert volume. Inadequate resources made that volume unmanageable. Failure to escalate allowed the backlog to compound over years. Falsification converted the program failure into willful violation territory and added individual criminal exposure for the employees involved.

The enforcement action didn’t require FinCEN to prove intent at stage one. It required only that someone in the firm knew the program was deficient — which the falsification established — and that the deficiency was not remedied. That’s the willfulness standard.


So What? Four Compliance Program Questions This Case Raises

1. Does your SAR queue have a maximum age?
Surveillance alerts that generate reports should be reviewed and closed within a defined timeframe — typically 30-45 days from alert generation to SAR/no-SAR determination. If your program doesn’t set a maximum age for open surveillance reports and trigger escalation when that age is exceeded, you don’t have a control on queue depth. Canaccord’s queue aged to four years without triggering any escalation or management review.

2. How does your program handle alert volume that exceeds capacity?
If alert volume exceeds the capacity of your review team, what happens? The right answer is: escalation to management, review of alert parameters, additional resourcing, or all three. The wrong answer is: reports go unreviewed. If your answer to “what do we do when the queue grows?” is unclear or doesn’t include escalation to compliance leadership, that gap needs addressing before an examiner asks the same question.

3. Is your AML program designed for the business you actually run?
Product-line risk is the BSA risk assessment’s core job. If your firm has added a high-risk product line — OTC trading, cross-border payments, crypto-linked activity, correspondent banking — and your AML program was designed before that product line existed or without explicit adjustment for it, the program is not fit for purpose. The business changed; the program needs to reflect that. The FFIEC BSA/AML Examination Manual’s structure — products and services, customer types, geographies, delivery channels — is the framework for that review.

4. Does your surveillance system’s output have ownership?
Someone in your organization needs to be accountable for surveillance report disposition. That means: a designated owner, a completion standard, a queue aging report that goes to compliance leadership, and a documented process for what happens when reviews don’t happen on time. If surveillance is automated but the output is unowned, the automation gives you a false sense of coverage.


The CCO and Deputy: What FINRA Did

Separate from the institutional penalty, FINRA brought disciplinary proceedings against Canaccord’s Chief Compliance Officer and the CCO’s direct report. The proceedings focused on supervisory failures — specifically, failure to adequately supervise the AML staff responsible for surveillance reviews and failure to escalate the growing review backlog to firm management.

Personal liability in BSA enforcement follows a three-part pattern that regulators have articulated: affirmative misconduct, obstruction of the examination, or wholesale failure of supervisory responsibility. The Canaccord CCO case fell into the third category — the individuals with compliance oversight responsibilities were aware or should have been aware of the surveillance backlog and did not act to remediate or escalate it.

For compliance program leaders, this case reinforces what the August 2026 CCO liability analysis covered: documentation of what you knew, when you knew it, and what you did about it is not just good practice. It’s how you distinguish between a program that failed and one that was deliberately concealed.


How This Compares to the UBS Action Six Months Later

In August 2026, FinCEN assessed a $125 million penalty against UBS Financial Services — surpassing Canaccord to become the new record BSA fine for a broker-dealer. The UBS case focused heavily on the recidivist angle: UBS had already settled similar failures in 2018 and had not fixed the underlying program.

The two cases in sequence define what BSA enforcement in the broker-dealer space looks like in 2026:

  • Both cases: Willful violation findings, multi-regulator coordination (FinCEN + SEC + FINRA), undersized AML programs for high-risk business lines
  • Canaccord specifically: Falsified compliance records, OTC market-making risk, foreign correspondent CDD
  • UBS specifically: Recidivist pattern (same failure resurfacing after a prior action), foreign currency wire monitoring, high-risk CDD

FinCEN’s message across both cases is consistent: an AML program that doesn’t match the risk profile of the business it covers will eventually be found, and if personnel knew it was deficient, the penalty will be sized accordingly.


Building the SAR Program That Survives Examination

The specific failures in the Canaccord case translate into concrete program design elements:

Surveillance system governance: Define maximum alert ages. Create automated queue aging reports. Establish escalation triggers. Assign a named owner to the surveillance output process.

SAR committee cadence: If your SAR filing decisions go through a committee, ensure the committee meets frequently enough to handle volume. For a high-risk product line, that may mean weekly reviews, not monthly.

AML program risk assessment refresh: When your firm adds a new product line or customer segment with elevated risk, the BSA risk assessment should be updated to reflect that change — not when you get an MRA, but when the business changes.

Independent testing scope: Your AML independent testing (the fourth pillar of a compliant BSA program) should specifically test SAR completeness — comparing the transactions that triggered alerts to the SARs that were actually filed. If your independent testing doesn’t include SAR completeness testing, you have a gap.

Record integrity: Compliance records are legal documents. Falsification of compliance records is not a procedural violation — it’s criminal. A compliance culture in which employees falsify records is one that has never received the message that accurate documentation of what happened is the point, not documentation of what management wants to have happened.

The FINRA Reg BI enforcement wave and the Canaccord case together illustrate a theme in broker-dealer regulation in 2026: the supervisory failures that create the biggest enforcement exposure are the ones that were known internally and not addressed.


Key Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did FinCEN cite in the Canaccord Genuity consent order?
The March 6, 2026 consent order cited three core violation categories: (1) failure to implement and maintain an AML program that adequately managed the risks from its high-risk OTC market-making business line, (2) failure to conduct sufficient customer due diligence on foreign correspondent accounts, and (3) willful failure to file at least 160 suspicious activity reports tied to thousands of OTC securities transactions. The action also uncovered that two compliance employees had falsified records to make it appear they had completed required surveillance reviews that had gone unreviewed for up to four years.
What is a 'willful' BSA violation and why does it matter?
A willful violation finding means FinCEN concluded the firm knew — or had reason to know — that its AML program was deficient and did not remedy it. For Canaccord, willfulness was evidenced by: the firm's AML personnel acknowledging internally that the program was under-resourced; surveillance reports piling up unreviewed for years; and two employees actively falsifying records to conceal the backlog rather than escalating. Willful findings can be referred to the DOJ for criminal prosecution and signal that any subsequent action will be significantly more expensive.
What is the surveillance review failure pattern FinCEN identified?
Canaccord's automated surveillance system generated alerts on OTC securities transactions. Those alerts fed into surveillance reports that compliance staff were responsible for reviewing and resolving. The problem: the program was so under-resourced that reports sat in queues for months or years with no action. Two employees then falsified records to show completed reviews. This allowed suspicious activity — including potential securities fraud and pump-and-dump schemes in OTC markets — to continue without SAR filings or escalation. FinCEN cited at least 160 instances where SARs were required but not filed.
Why did Canaccord's OTC market-making business create elevated BSA risk?
OTC securities markets — penny stocks, shell companies, and thinly traded securities outside major exchanges — are historically high-risk for manipulation schemes, including pump-and-dump fraud, layering, and wash trading used to move illicit funds. A broker-dealer with significant market-making activity in OTC securities is handling a product line that FinCEN and the SEC have flagged as inherently high-risk. The expectation is that the AML program's surveillance, CDD, and SAR-filing resources are calibrated to that higher risk — not designed for a lower-risk institutional book and then applied to OTC trading without adjustment.
What does this case mean for AML programs that use automated surveillance systems?
Automated surveillance generates alerts; human review closes or escalates them. When alert volume exceeds review capacity, reports age. When reports age without escalation, SARs don't get filed. When SARs don't get filed, you have a willful BSA violation — even if your system was running. FinCEN has consistently held that having an automated system is not sufficient if the outputs are not adequately resourced for review. The Canaccord case makes clear that a surveillance backlog is itself a material compliance failure, and falsifying records to conceal it compounds both the BSA violation and potential criminal exposure for the individuals involved.
How does this case compare to the August 2026 UBS Financial Services action?
Both cases involved large BSA penalties for broker-dealers in 2026 — Canaccord at $80 million in March, UBS at $125 million in August. The common thread is willful violation findings driven by AML programs that failed to match the risk profile of the underlying business. The UBS case was a recidivist action — the firm had been penalized for similar failures in 2018. Canaccord's case is notable for the falsification of compliance records, which shifts the risk from a programmatic failure to potential individual criminal liability. In both cases, the specific business line creating elevated risk was the same type of problem: a high-risk activity (wire transfers for UBS, OTC market-making for Canaccord) was not adequately supported by the AML program.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

◆ Keep reading

Related posts.

Operational Risk

40 States Just Made Credit Acceptance Corporation Pay $700 Million for Loans It Knew Borrowers Couldn't Repay. Here's What Consumer Lenders Need to Lock In Now.

On September 17, 2026, a 40-state coalition secured a $700 million settlement against Credit Acceptance Corporation for predatory subprime auto loans—including $634M in debt relief for 55,000 consumers. The smoking gun was CAC's own internal predictive model showing expected defaults. Here's what every consumer lender needs to do before November.

Oct 2, 2026

Operational Risk

The Fed's 2026 Risk Officer Survey Is Out. No Major Fraud Category Is Getting Better. Here's What Your Controls Are Flagging Late.

The Federal Reserve's 2026 Risk Officer Survey of 400+ financial institutions shows fraud rising or persisting in every payment channel. Debit card fraud is near-universal. Money mule accounts are discovered after funds disappear. Synthetic identities are defeating KYC. Here's the diagnostic checklist your program needs.

Oct 1, 2026

Operational Risk

FTC Just Fined a Payment Processor $12 Million for Sham Merchants. Here's What 'Knowingly Facilitating Fraud' Actually Looks Like.

On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services for processing payments for 1,000+ sham merchant accounts running chargebacks at 10x card network thresholds. This is what payment processor liability looks like—and why it matters for every fintech that routes transactions.

Sep 28, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.