UBS Hit with Record $125 Million FinCEN Penalty Over Repeat AML and Bank Secrecy Act Violations
UBS Financial Services Inc. (UBSFS) has been hit with a record $125 million civil money penalty by the U.S. Financial Crimes Enforcement Network (FinCEN) for willfully violating the Bank Secrecy Act...
UBS Financial Services Inc. (UBSFS) has been hit with a record $125 million civil money penalty by the U.S. Financial Crimes Enforcement Network (FinCEN) for willfully violating the Bank Secrecy Act (BSA), marking one of the most significant anti-money laundering (AML) enforcement actions against a broker-dealer in recent years. The penalty underscores U.S. regulators’ growing intolerance for firms that fail to correct long-standing compliance deficiencies despite previous enforcement actions.
The FinCEN action was accompanied by a separate $20 million fine imposed by the Financial Industry Regulatory Authority (FINRA), which found that UBS repeatedly failed to maintain an AML programme reasonably designed to detect and report suspicious activity. According to regulators, the firm’s compliance framework contained persistent weaknesses in transaction monitoring, customer due diligence, and the identification and reporting of suspicious transactions.
Regulatory findings show that between January 2019 and June 2023, UBSFS failed to adequately monitor more than 60,000 foreign currency wire transfers with a combined value exceeding $10 billion. The transactions included activity involving higher-risk jurisdictions, unusually large transfers, and payments lacking an apparent economic or business purpose. Regulators concluded that the firm’s surveillance systems failed to identify transactions that warranted additional scrutiny and, where appropriate, the filing of Suspicious Activity Reports (SARs).
The investigations also identified shortcomings in UBS’s customer risk assessment processes. According to FINRA, the firm assigned inadequate risk ratings to certain customers despite the presence of multiple risk indicators, including adverse media, political exposure, changes in domicile, and links to jurisdictions associated with elevated financial crime risks. These weaknesses, regulators said, reduced the effectiveness of the firm’s AML controls and delayed the detection of potentially suspicious activity.
The latest enforcement action is particularly significant because it follows an earlier regulatory settlement. In 2018, UBS agreed to pay $14.5 million to resolve similar deficiencies relating to foreign currency transaction monitoring and committed to strengthening its AML controls. FinCEN determined that the firm failed to fully implement those remediation measures, allowing many of the same weaknesses to persist for several years. The agency cited the firm’s failure to address known deficiencies as a key factor in determining the size of the record civil penalty.
The coordinated regulatory response extended beyond FinCEN and FINRA, with the U.S. Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) also participating in related settlements arising from the firm’s compliance failures. The multi-agency action reflects increasing cooperation among U.S. financial regulators in addressing systemic weaknesses in anti-money laundering controls across the financial sector.
The record penalties send a clear message that regulators will continue to impose increasingly severe sanctions on institutions that fail to maintain effective AML programmes or neglect to remediate previously identified weaknesses. Beyond the financial cost, such enforcement actions carry significant reputational consequences and demonstrate that repeat compliance failures remain a key priority for U.S. enforcement authorities.
Compliance Takeaway
The UBS enforcement action highlights a recurring regulatory theme: institutions are judged not only on the existence of AML controls but on their effectiveness and sustainability. Firms that fail to remediate previously identified deficiencies face heightened enforcement risk and substantially larger penalties. Compliance officers should ensure that transaction monitoring systems are independently validated, customer risk-rating methodologies are regularly reviewed, governance committees receive timely escalation of AML issues, and remediation plans are tracked to completion with documented evidence of effectiveness. Regulators increasingly expect firms to demonstrate continuous improvement rather than one-time corrective actions, making robust governance, independent testing, and board oversight essential components of an effective financial crime compliance programme.
Editor’s Compliance Insight
The UBS enforcement action reinforces a lesson that regulators have consistently emphasized over the past decade: remediation is not complete when a corrective action plan is approved—it is complete only when the identified risks have been effectively mitigated and the controls are demonstrably operating as intended. Institutions that repeatedly fail to address known deficiencies face not only escalating financial penalties but also increased regulatory scrutiny, reputational damage, and heightened expectations from boards and senior management.
For compliance leaders, this case illustrates the importance of treating regulatory findings as enterprise-wide governance issues rather than isolated compliance gaps. Effective AML programmes require continuous tuning of transaction monitoring systems, periodic validation of customer risk models, robust quality assurance, and independent testing to confirm that remediation efforts remain effective over time. Boards should receive regular reporting on outstanding regulatory commitments, while internal audit and compliance functions should verify that corrective actions are sustainable and supported by measurable outcomes.
Ultimately, regulators are signalling that repeat failures will attract increasingly severe consequences. Financial institutions should therefore view every enforcement action—whether their own or that of a peer—as an opportunity to benchmark their controls, reassess remediation programmes, and strengthen their overall financial crime risk management framework before regulators do it for them.



No Comment! Be the first one.