ru

95.108.213.80

Back
News

FinCEN Fines UBS $125M in Record Broker-Dealer AML Penalty

FinCEN Fines UBS $125M in Record Broker-Dealer AML Penalty
Amir Rizwan Amir Rizwan SEPTEMBER 1, 2026 1 minute read

The Financial Crimes Enforcement Network (FinCEN) assessed a $125 million civil money penalty against UBS Financial Services on August 3, 2026, for willful Bank Secrecy Act violations, the largest penalty the bureau has issued against a broker-dealer. The firm admitted it had failed to fix deficiencies FinCEN identified in a 2018 consent order and had not disclosed those failures to the regulator.

UBS Financial Services, the US brokerage subsidiary of the Swiss bank, admitted in its consent order that it did not implement an adequate anti-money laundering programme and did not file suspicious activity reports as required. The consent order records that for four years the firm failed to appropriately monitor more than 61,500 foreign-currency wires with an aggregate value above $10.5 billion, and applied insufficient customer due diligence to high-risk clients with ties to Russia and Latin America. UBS did not implement changes to its foreign-currency transaction monitoring controls until 2021, leaving monitoring that FinCEN describes as manual, untailored, error prone and at times absent altogether. Hundreds of suspicious transactions went unreported on time. The same inadequate wire monitoring had drawn a $14.5 million penalty under a December 2018 consent order, making this FinCEN’s second action against the firm on overlapping conduct.

The headline figure overstates the cash cost. FinCEN agreed to credit $48 million against the total for parallel payments UBS made to the Commodity Futures Trading Commission, the Securities and Exchange Commission and the Financial Industry Regulatory Authority, bringing the net penalty to $77 million. A further $15 million will be waived if the firm completes a mandated review and adopts its recommendations. UBS must retain an outside consultant to assess its AML programme against risks tied to the US southwest border, cartels, narcotics trafficking, Iran, Russia and Venezuela, and run a retrospective look-back for transactions it previously failed to flag.

FinCEN Director Andrea Gacki said repeat violators of the Bank Secrecy Act “jeopardize the integrity of our financial system, especially those that expose it to high-risk customers” without effective controls. The recidivism framing is the operative part of the order. The penalty is calibrated not to the 2026 conduct in isolation but to the eight-year gap between a regulator naming a control weakness and the firm closing it, and the structure of the settlement, with credits for parallel payments and a waiver tied to future remediation, prices compliance work directly into the outcome.

That is the shift worth reading closely. A 2018 consent order presumes the firm will remediate and report honestly on its progress, and this one establishes what happens when the remediation exists on paper while the underlying monitoring gap stays open. Wire monitoring that misses 61,500 transactions is not a policy failure but a detection failure, and the distinction matters because policy documents are what most institutions produce when a supervisor asks for evidence of remediation. Screening high-risk clients against sanctions and adverse-media data is only as good as the transaction layer feeding it, and a static onboarding check cannot surface a counterparty whose risk profile changed after the account opened.

Institutions carrying open remediation commitments need monitoring that produces evidence of detection, not just documented procedure. Shufti supports that through continuous transaction screening against 1,000+ global watchlists with ongoing customer risk assessment, so sanctions, PEP and adverse-media exposure is re-evaluated as counterparty behaviour changes rather than only at onboarding, across 240+ countries and territories. Compliance teams reviewing their own look-back exposure can see how transaction screening solution performs against live data in a short demo.

Disclaimer: The information provided here is for general informational purposes only and should not be treated as legal, regulatory, or business advice. Shufti Pro Limited accepts no liability for decisions or actions taken in reliance on this information.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.