Feature Operational Risk
FinCEN Hit UBS With a Record $125 Million 'Willful' BSA Fine — and FINRA Added $20 Million More. What the Double-Barrel Enforcement Action Means for Your AML Program.
FinCEN's $125 million penalty against UBS Financial Services — the largest BSA fine ever imposed on a broker-dealer — combined with FINRA's simultaneous $20 million fine creates a $145 million enforcement landmark. Both actions trace back to the same root cause: UBS knew its transaction monitoring had gaps, promised to fix them after a 2018 settlement, and didn't. Here's what 'reasonably designed' AML monitoring actually requires.
Table of Contents
TL;DR
- FinCEN assessed a record $125 million civil penalty against UBS Financial Services in August 2026 — the largest BSA fine ever imposed on a broker-dealer — for “willful” violations of the Bank Secrecy Act. FINRA separately fined UBS $20 million on August 3, 2026. Total: $145 million.
- The same institution had settled with FinCEN in December 2018 for $14.5 million for similar AML program failures. UBS acknowledged the gaps, promised to fix them, and then failed to monitor 60,000+ foreign currency wires totaling $10 billion over the next four years.
- FinCEN’s “willful” designation — the worst characterization available — reflects that UBS knew of the deficiencies, was told by regulators, and chose not to remediate adequately.
- The three enforcement lessons: (1) known gaps that aren’t fixed become “willful” violations; (2) transaction monitoring scope — not just the existence of a program — is what examiners evaluate; (3) CDD failures for high-risk customers are examined independently from monitoring failures.
The worst word in a FinCEN enforcement action isn’t “violation.” It’s “willful.”
Violation means you failed to comply. Willful means you knew you were failing to comply — regulators told you, you agreed to fix it, and you didn’t. That’s the story FinCEN told in August 2026 when it imposed a $125 million civil penalty against UBS Financial Services Inc. — the largest BSA penalty ever assessed against a broker-dealer. FINRA piled on $20 million more on August 3, 2026.
The same institution had settled with FinCEN in December 2018 for $14.5 million for substantially similar AML program deficiencies. That settlement included a promise to fix the underlying gaps. What followed, according to FinCEN’s consent order: four more years of the same failures, applied to 60,000+ transactions totaling $10 billion.
That trajectory — settlement, promise, continued failure — is what produced the “willful” designation. And the record fine.
The Double-Barrel Action: What FinCEN and FINRA Each Found
The two enforcement actions are parallel but distinct.
FinCEN’s civil money penalty, filed under FinCEN’s BSA enforcement authority, found that UBS Financial Services willfully violated the BSA by:
- Failing to implement and maintain an AML program reasonably designed to detect and report suspicious transactions involving foreign currency wires
- Failing to reasonably implement its customer due diligence program for high-risk retail customers — particularly those with ties to Russia and Latin America
- Failing to file hundreds of suspicious activity reports in a timely manner
FinCEN’s consent order characterizes the violations as willful based on the institution’s prior settlement, the knowledge of gaps documented in internal records, and the continued operation with known deficiencies for more than four years after the 2018 settlement.
FINRA’s action, brought under FINRA’s AML supervision rules, found that UBS Financial failed to establish and implement an AML compliance program reasonably expected to detect and cause the reporting of suspicious transactions. FINRA’s jurisdiction is supervision of FINRA member firms; FinCEN’s is BSA compliance by financial institutions. Both came to the same underlying conclusion: the monitoring program wasn’t adequate for what it was supposed to cover.
Total penalty: $125 million (FinCEN) + $20 million (FINRA) = $145 million, plus the cost of the mandatory third-party transaction lookback that FinCEN required.
Eight Years of Known Deficiencies
The timeline is important because it’s what made the “willful” finding possible.
December 2018: FinCEN and FINRA settled with UBS Financial Services for $14.5 million covering AML program failures in its foreign currency wire business. The settlement was explicit: UBS acknowledged the deficiencies and committed to remediation.
January 2019 – June 2023: In the four-plus years after that settlement, UBS failed to monitor more than 60,000 foreign currency wires totaling more than $10 billion. The monitoring gaps weren’t new — they were substantially the same gaps that the 2018 settlement had identified.
August 2026: FinCEN’s consent order documents that “UBSFS knew its transaction-monitoring arrangements were inadequate, promised regulators that the problems would be corrected, and nevertheless allowed material gaps to remain for more than four years.”
That sentence is the basis for the “willful” designation. It’s also the clearest articulation of what regulators mean when they say willfulness: not malice, but awareness of a legal obligation, awareness of your own failure to meet it, and a choice not to fix it.
The 2018 settlement changed the evidentiary landscape. Before it, UBS could potentially argue that its monitoring program was a good-faith attempt to comply with ambiguous regulatory expectations. After the settlement, that argument was foreclosed. Regulators had already told them what was insufficient. What followed was indefensible.
What “Reasonably Designed” Actually Means
Both actions center on the “reasonably designed” standard under the BSA. That standard is the core requirement for every AML program: the program must be reasonably designed to detect and report suspicious activity. The word “designed” implies that the program’s structure, scope, and methodology must match your actual risk profile.
UBS had a transaction monitoring program. The violation wasn’t that monitoring didn’t exist — it was that the program’s scope failed to cover a high-risk transaction type that ran through UBS’s actual business.
Foreign currency wires are not obscure transactions. For broker-dealers with retail clients in high-risk jurisdictions, they are among the most significant AML risk vectors: international transfers, often large dollar amounts, often crossing into jurisdictions with elevated sanctions and money laundering risk. The fact that UBS’s monitoring didn’t adequately cover them — despite a prior settlement specifically about that gap — is what produced the “knew and didn’t fix” narrative.
What this means for every AML compliance program:
| Dimension | What Examiners Look For | Common Gap |
|---|---|---|
| Transaction monitoring scope | Coverage of all meaningful transaction types, calibrated to actual transaction activity | Monitoring rules that cover “standard” transactions but miss high-volume, high-risk transaction types specific to the institution’s business |
| CDD implementation | Actual application of enhanced due diligence criteria to high-risk customer segments | Policies that describe EDD requirements without documented evidence of implementation |
| SAR filing timeliness | SARs filed within 30 days of determination; delays documented with justification | Backlogs created by monitoring gaps; suspicious transactions identified late because monitoring rules missed them |
| Geographic risk | Specific protocols for customers with nexus to high-risk jurisdictions | Generic country risk ratings not translated into account-level controls |
The “reasonably designed” standard doesn’t set a bright-line rule for how many monitoring rules you need or what thresholds to use. It requires that your program be designed to detect the suspicious activity that flows through your specific business — which means your monitoring scope has to match your transaction activity, and your monitoring thresholds have to be calibrated to your risk profile.
The CDD Failure: Where Monitoring Meets Customer Risk
The CDD findings are separate from the monitoring findings but closely related. FinCEN found that UBS failed to conduct adequate due diligence on high-risk retail customers — particularly those with ties to Russia and Latin America.
CDD failure in this context isn’t “we didn’t collect KYC documents.” It’s a failure to reasonably implement the enhanced due diligence framework for customers who warranted it. The distinction matters: FinCEN’s scam center alert earlier this month reinforced that regulators expect CDD to be ongoing, not a one-time onboarding exercise. Customers’ risk profiles change. CDD programs have to keep pace.
The connection to monitoring is direct: if your CDD program isn’t identifying which customers warrant enhanced scrutiny, your transaction monitoring thresholds can’t be calibrated to reflect that risk. The two failures reinforce each other. A customer flagged as high-risk should trigger enhanced monitoring rules. If CDD didn’t flag them, enhanced monitoring rules don’t apply, and the monitoring gap expands.
The SAR Filing Failures
The third category of findings — failure to file SARs timely — flows directly from the first two. If monitoring doesn’t detect a transaction, you can’t file a SAR on it. If CDD doesn’t identify a customer as high-risk, monitoring thresholds that depend on risk tier won’t trigger on their activity.
FinCEN’s consent order required a third-party transaction lookback focused on the same geographies and risk categories where the monitoring and CDD failures were concentrated: U.S. Southwest border, narcotics trafficking networks, Iran, Russia, and Venezuela. The lookback firm must identify any suspicious transactions that went undetected and ensure SARs are filed retroactively.
This creates a secondary exposure problem. Every SAR identified in the lookback is evidence that a SAR should have been filed and wasn’t. Every one of those is an additional BSA violation in the historical record. The mandatory lookback isn’t just expensive — it’s self-documenting additional violations that FinCEN can reference in any future enforcement action.
FINRA’s Reg BI enforcement wave this year demonstrated a similar pattern in the supervision context: when regulators identify a systemic failure through enforcement, the subsequent monitoring of that firm intensifies. After the 2018 settlement, UBS was on a shorter leash. The 2026 action reflects how short that leash had become.
The Compliance Program Lessons
The UBS enforcement action teaches three things that apply to every broker-dealer and financial institution with an AML program.
1. Known gaps that aren’t remediated become willful violations. If your compliance team has documented monitoring gaps, CDD weaknesses, or SAR filing delays — and those findings haven’t been remediated — you have a “known and not fixed” problem. The 2018 UBS settlement is an extreme example, but the underlying principle applies to any documented finding that isn’t addressed: you’ve created evidence of awareness without evidence of action. Document the gap, escalate it, and drive it to closure — the way a mature issues management process requires.
2. Transaction monitoring scope is the first thing examiners evaluate. The question isn’t “do you have a transaction monitoring system?” It’s “does your transaction monitoring cover the transaction types that carry meaningful AML risk for your specific customer base and business model?” For a broker-dealer with international clients, foreign currency wires should be an obvious answer. Map your transaction activity against your monitoring coverage. The gaps are your exposure.
3. CDD failure creates monitoring failure. An EDD policy that isn’t implemented — meaning there’s no documentation that customers who meet high-risk criteria actually received enhanced scrutiny — will show up as a separate finding alongside monitoring failures, not instead of them. Regulators examine both. The AML/BSA Risk Assessment Template includes a risk-tiered CDD implementation framework with documentation requirements that map to examiner expectations — specifically the documentation gap that lets EDD policies sit on paper without evidence of implementation.
So What?
The UBS action is notable for the size of the fine and the “willful” designation, but the underlying violations — inadequate monitoring scope, insufficient CDD for high-risk customers, SAR filing delays — are among the most common BSA exam findings for broker-dealers and money service businesses.
The difference between UBS’s $145 million outcome and a more typical enforcement result is the 2018 settlement. The settlement created a documented record of awareness that foreclosed every good-faith argument. Most compliance programs don’t have a prior consent order as a complicating factor — but they often have documented findings that are weeks or months overdue for remediation.
Run this exercise before your next exam: pull every open AML-related finding in your issues tracker. For each one, check when it was identified and what the documented remediation status is. If there are findings more than 90 days old without a remediation action or an approved extension with documented rationale, you have a potential “knew and didn’t fix” problem — even without a prior consent order.
The 132-indicator KRI Library includes 10 BSA/AML-specific KRIs covering SAR filing rates, transaction monitoring false positive rates, high-risk customer CDD completion, and geographic exposure metrics — the indicators that would have flagged UBS’s trajectory before it became a $145 million problem.
“Willful” is an outcome, not a character judgment. It’s what happens when a compliance program treats documented gaps as acceptable operating conditions instead of problems to fix. The UBS timeline makes that trajectory visible in a way that should reframe how every BSA officer thinks about their open findings list.
Sources: FinCEN: Record $125M Penalty Against UBS Financial Services | FINRA: $20M Fine Against UBS Financial (FINRA.org) | BusinessWire: FINRA UBS Announcement | Miller & Chevalier: FinCEN $125M Penalty Analysis | AML Intelligence: UBS Record Fine Coverage
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What makes a BSA violation 'willful' under FinCEN's standard?
What did UBS's transaction monitoring program actually fail to cover?
What does 'reasonably designed' mean for an AML program under the BSA?
What was the specific CDD failure in the UBS enforcement action?
What does the FinCEN-required transaction lookback mean for UBS going forward?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Operational Risk
FinCEN's Southwest Border GTO Just Expired. Here's What MSBs in Four States Need to Know Now.
FinCEN's expanded Southwest Border Geographic Targeting Order expired September 2, 2026, ending enhanced $1,000 CTR requirements for MSBs in border counties of AZ, CA, NM, and TX. The enforcement operation behind it hasn't stopped. Here's what MSBs should do now and what to expect next.
Sep 7, 2026
Operational Risk
The OCC's Spring 2026 Risk Perspective Named Three Operational Threats. Here's What Your Program Needs to Fix.
The OCC's Spring 2026 Semiannual Risk Perspective shifted focus from credit risk to operational resilience—flagging legacy technology, rising fraud, and sophisticated cyber threats as the top concerns. Here's what that means for your risk program.
Aug 31, 2026
Operational Risk
FDIC Reciprocal Deposits Rule: The New $30 Billion Cap Is Not a Liquidity Free Pass
The FDIC reciprocal deposits rule raises the nonbrokered cap and expands agent-institution eligibility. Here is the treasury control plan.
Aug 29, 2026