UBS’s $125 Million BSA Penalty: What “Recidivist” Violations Mean for Your Program

Share

On August 3, 2026, the Financial Crimes Enforcement Network (FinCEN) assessed a $125 million Bank Secrecy Act (BSA) penalty against UBS Financial Services Inc. (UBSFS). It is the largest BSA penalty ever imposed on a broker-dealer, and it is FinCEN’s second enforcement action against the firm.

FinCEN’s announcement shows how regulators treat institutions that promise to fix known problems and then fail to follow through. This article covers what happened, what recidivist status means, and how compliance teams can strengthen their anti-money laundering (AML) programs.

Key Highlights

  • FinCEN assessed a $125 million civil money penalty against UBSFS on August 3, 2026, the largest BSA penalty ever imposed on a broker-dealer.
  • The action follows a $14.5 million consent order in December 2018 that cited inadequate monitoring of foreign currency wires.
  • After the 2018 order, UBSFS failed to monitor more than 50,000 foreign currency wires worth over $10 billion and did not disclose the gap to FinCEN.
  • Weak customer due diligence (CDD) on high-risk clients tied to Russia and Latin America led to hundreds of late suspicious transaction reports.
  • FinCEN expects prompt remediation of findings raised by regulators, auditors, and employees, and encourages early dialogue with regulators.

What Happened in the UBSFS BSA Penalty Case

The 2018 consent order found that UBSFS failed to adequately monitor foreign currency wires because of weaknesses in its automated monitoring system. UBSFS assured FinCEN it would remediate the problem. According to FinCEN, it did not. The firm went on to miss monitoring for more than 50,000 foreign currency wires with an aggregate value above $10 billion.

UBSFS also did not disclose these gaps. FinCEN learned of them through an investigation it opened after a regulatory examination. Separately, due diligence on high-risk customers tied to Russia and Latin America fell short. UBSFS did not adequately weigh source of wealth or negative news alleging corruption, fraud, and money laundering, even after an affiliate raised concerns.

The result was hundreds of suspicious transactions that the firm failed to report on time. UBSFS admitted it willfully violated the BSA, including by failing to maintain an AML program that met minimum requirements and failing to file suspicious activity reports (SARs).

December 2018 actionAugust 2026 action
Civil money penalty$14.5 million$125 million
Central findingsInadequate monitoring of foreign currency wiresContinued monitoring failures, weak CDD on high-risk customers, late reporting
OutcomeConsent order with FinCENConsent order, admission of willful violations, lookback, independent review

The consent order requires UBSFS to work with a third party on a lookback that identifies and reports suspicious transactions that went undetected. The firm must also undergo an independent review of its AML program, focused on priority risks including the U.S. Southwest border, Iran, Russia, and Venezuela. FinCEN will waive up to $15 million of remediation expenses once the review and its recommendations are completed, a sign that it credits genuine investment.

What “Recidivist” Means in FinCEN Enforcement

FinCEN Director Andrea Gacki said the action should send a clear message that recidivist financial institutions will face severe repercussions. The penalty supports that statement: it is more than eight times the 2018 amount. FinCEN’s findings point to three aggravating factors:

  • Known deficiencies persisted for years after a prior enforcement action.
  • The firm did not disclose continued failures to FinCEN.
  • Significant remediation began only after FinCEN’s investigation was already underway.

FinCEN expects institutions to remediate failures uncovered by regulators, auditors, and employees promptly, and to take full accountability when violations surface.

Customer Due Diligence Expectations After UBSFS

FinCEN reminded institutions covered by its 2016 CDD Rule that risk-based due diligence applies at onboarding and throughout the customer relationship, with information updated on a risk basis. It also cautioned against simply “papering” dispositions of apparent risks. Reviewers should objectively assess each risk and apply proportionate controls. A customer due diligence checklist can help standardize source of wealth reviews, adverse media escalation, and periodic updates.

Steps to Strengthen Your AML Program

Compliance teams can apply the lessons from this case with five practical steps:

  1. Close findings with evidence. Assign an owner, deadline, and validation step to every exam, audit, and employee-raised finding. An independent AML audit can confirm that fixes hold up.
  2. Test monitoring coverage. Confirm that every product and payment channel, including foreign currency wires, feeds your automated transaction monitoring system, and reconcile data completeness on a regular schedule.
  3. Escalate adverse media. Route negative news and affiliate concerns to documented review with a clear rationale.
  4. Refresh customer risk. Update customer information on a risk basis, prioritizing clients with ties to high-risk jurisdictions or complex source of wealth.
  5. Engage your regulator early. FinCEN encourages institutions to discuss issues tied to prior enforcement actions before they surface elsewhere.

Turning Remediation Commitments Into Results

The UBSFS penalty shows that regulators judge remediation by outcomes and timing. A firm that documents a problem, promises a fix, and leaves the gap open faces escalating consequences, as the move from $14.5 million to $125 million demonstrates. Compliance teams that track findings to verified closure, test monitoring coverage, and apply meaningful due diligence to high-risk customers put themselves in the strongest position to avoid the same path.

Schedule a free demo

See how Alessa can help your organization

100% Commitment Free

Recent Posts

legal documents being signed

You Know You Work in Compliance When…

Spend enough time working in compliance and something starts to happen: you begin seeing red flags everywhere. The unusual transaction. The oddly worded email. The

X

chatbot-alessa Alessa

Hello, I'm Allie! I'm here to help if you have questions about Alessa and our products.

Please fill out the form to access the webinar: