You are currently viewing 61,500 Unmonitored Wire Transactions worth $10.5 Billion. FinCEN Just Issued the Largest BSA Fine Ever Against a Broker-Dealer.

61,500 Unmonitored Wire Transactions worth $10.5 Billion. FinCEN Just Issued the Largest BSA Fine Ever Against a Broker-Dealer.

  • Post category:AML
UBS Financial Services Just Received the Largest BSA Fine Ever Imposed on a Broker-Dealer. FinCEN Had Already Fined It Once. | Truth Technologies

On August 3, 2026, FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc. for willful violations of the Bank Secrecy Act. It is the largest BSA penalty ever imposed on a broker-dealer in US history. It is also FinCEN's second enforcement action against the same firm. The first was in 2018. The 2018 consent order specifically identified the failures that would generate the 2026 penalty. UBSFS admitted to remediation that never happened.

The consent order is 55 pages and covers two distinct categories of failure: a transaction monitoring system for foreign currency wires that remained broken for nearly twenty years despite explicit regulatory notice, and a customer due diligence program that onboarded and retained ultra-high net worth customers with documented ties to Russia, Latin America, and the Troika Laundromat while systematically discounting the risk those customers presented. Together, those failures resulted in more than 61,500 foreign currency wire transactions worth $10.5 billion going unmonitored, and hundreds of suspicious transactions going unreported to law enforcement.

$125M
FinCEN Civil Penalty
61,500+
Unmonitored Wire Transactions
$10.5B
Aggregate Value Unmonitored
~20 yrs
Duration of Monitoring Failures

What the 2018 Consent Order Found and What Happened Next

In December 2018, FinCEN fined UBSFS $14.5 million for failing to monitor foreign currency wires in its commodities and retail brokerage accounts. At the time, UBSFS told FinCEN it expected to implement a new automated monitoring system by mid-2019 that would remediate these deficiencies. FinCEN acknowledged that commitment in the 2018 consent order and referenced UBSFS's ability to correct the identified issues.

Within weeks of signing that consent order, UBSFS's own senior executives became aware it would not meet the mid-2019 deadline. The implementation date slipped to late 2019, then into 2020, then into 2021. UBSFS did not inform FinCEN of any of these delays. When the new automated system was finally deployed in March 2021, it was flawed in three material ways: it selected an incorrect partial data feed rather than a complete end-of-day feed, it failed to match counterparty information to transactions, and it contained no exception queue or error-reporting mechanism to catch transactions that fell through. Consequently, UBSFS did not discover the scope of these implementation failures until FinCEN's subsequent investigation raised questions about the new system's coverage in 2022.

"Today's historic action against UBSFS should send a clear message that recidivist financial institutions will face severe repercussions. Financial institutions that continue to violate the BSA jeopardize the integrity of our financial system, especially those that expose it to high-risk customers and activities without effective controls."

Andrea Gacki, Director, Financial Crimes Enforcement Network, August 3, 2026

The total monitoring gap spans from at least 2004 through June 2023, nearly twenty years. The relevant time period for the 2026 consent order alone covers January 2019 through June 2023, during which more than 61,500 foreign currency wire transactions with an aggregate value of over $10.5 billion went unmonitored.


The CDD Failures: What the Consent Order Found

Beyond the monitoring failures, FinCEN identified pervasive weaknesses in UBSFS's customer due diligence program, particularly in connection with its provision of wealth management services to high-risk customers with ties to Russia and Latin America. The consent order details specific customers whose cases illustrate the systemic nature of the failures.

In one case, UBSFS onboarded a customer rated low-risk whose source of wealth was described as consulting income. Enhanced due diligence would have identified that this customer had earned income through a project associated with a Russian oligarch who had been designated by OFAC. That connection had been publicly reported since 2018. UBSFS did not identify it until the customer was indicted for US sanctions violations in March 2022.

In another case, a customer who relocated from the United States to Russia in 2013 and joined the faculty of a Russian government-supported technical university did not have his risk profile updated for more than eight years. During that period, he added a Russian phone number to his UBSFS profile, accessed the account from Russia on fourteen occasions in a single year, and received more than $2 million in wires from a Russian bank. UBSFS generated alerts on two of those transactions but closed them without meaningful investigation.

In a third case, UBSFS onboarded a Cypriot investment company whose ultimate beneficial owner's brother was a high-profile figure with documented connections to the Troika Laundromat. UBSFS's review identified those connections but an internal memorandum concluded there was "no formal negative news" because no legal proceedings had been filed. The account later received inbound wires totaling roughly ten times the expected amount. UBSFS failed to escalate or investigate the discrepancy.

Perhaps most significantly, UBSFS onboarded two entities beneficially owned by a Russian oligarch with close ties to President Putin. Negative news screening generated more than 300 articles at onboarding. UBSFS reviewed only 25 of them. When a financial advisor recommended dismissing concerns about an alleged money laundering scheme connecting the oligarch to OFAC-designated nationals, UBSFS accepted the assessment without scrutiny. UBSFS imposed account restrictions to bring the relationship within its own risk threshold, including a restriction on third-party wires. Of more than $60 million in outgoing wires from those accounts, approximately three-quarters were third-party wires in apparent violation of the restriction UBSFS had itself set.


Four Compliance Failures FinCEN Explicitly Called Out

Failure 1

Remediation promises made to regulators must be kept and delays must be disclosed.

UBSFS represented to FinCEN in 2018 that its monitoring failures would be remediated by mid-2019. When that deadline became impossible, UBSFS did not disclose the delay. FinCEN found out through its own subsequent investigation in 2022. The consent order treats the non-disclosure of implementation delays as an independent aggravating factor. When a financial institution makes a remediation commitment to a regulator, that commitment is a condition of settlement and failure to meet it, without proactive disclosure, converts a compliance failure into a recidivism finding.

Failure 2

New automated monitoring systems require complete data lineage mapping and exception queue controls before deployment.

UBSFS's new automated system failed because it selected a partial rather than complete data feed, could not reliably match counterparty information to transactions, and had no exception queue to catch transactions the system could not process. These are not edge case technical failures. They are basic system design requirements. FinCEN specifically cited the absence of data lineage mapping and testing, and the lack of an exception-handling control, as root causes of the continued monitoring gap. A monitoring system that cannot identify what it is not seeing provides no more assurance than a manual control.

Failure 3

Negative news review must be substantive, not a process of documenting reasons to proceed.

FinCEN specifically called out UBSFS's approach to negative news as a focus on "papering" dispositions rather than conducting objective risk assessments. In one case, a financial advisor recommended dismissing hundreds of negative news articles because the customer had "never been arrested or charged." In another, UBSFS concluded there was "no formal negative news" despite documented connections to a known money laundering network, on the basis that no legal proceedings had been filed. Reviewing negative news for purposes of finding a reason to proceed is not CDD. It is a documentation exercise that will not withstand regulatory scrutiny.

Failure 4

Account restrictions set by compliance must be enforced, not overridden by revenue considerations.

UBSFS imposed third-party wire restrictions on accounts associated with a Russian oligarch to bring the relationship within its own risk threshold. Three-quarters of the outgoing wires from those accounts were subsequently processed in apparent violation of that restriction. The consent order also notes that UBSFS branch management and financial advisors repeatedly pushed to proceed with high-risk customer onboarding because of existing assets under management at UBS affiliates. When revenue considerations influence the enforcement of compliance-imposed restrictions, the restrictions cease to function as controls.


What This Means for Wealth Management Compliance Programs

The UBSFS case is particularly significant for broker-dealers, wealth managers, and any institution providing financial services to ultra-high net worth customers from high-risk jurisdictions. FinCEN's consent order is explicit: risk-based CDD for wealth management customers includes understanding source of wealth, assessing PEP connections, reviewing negative news substantively, and maintaining customer risk profiles that reflect actual information rather than onboarding assumptions.

Customer risk profiles must be updated when new information becomes available, not only at scheduled reviews. UBSFS failed to update a customer's low-risk profile for eight years despite his adding a Russian phone number, relocating to Russia, and receiving wires exclusively from a Russian bank account. Continuous customer monitoring that generates alerts when customer behavior or publicly available information changes materially is precisely the control designed to prevent an eight-year gap between profile and reality.

Negative news screening must review the full results, not a sample selected for convenience. UBSFS reviewed 25 of more than 150 negative news articles generated for one customer during periodic review. FinCEN's finding that this was inadequate is a direct signal to compliance teams: a negative news process that is structurally limited by the volume of results it will actually review is not functioning as designed. Review processes should be calibrated to the risk level of the customer, not to what is administratively convenient.

Monitoring system implementations require independent data lineage testing before go-live. UBSFS's new system was deployed without confirming that the correct, complete data was flowing into it. The absence of data lineage mapping meant that the system's model performance monitoring reports showed no problems, because the reports themselves did not have visibility into what the system was not receiving. Independent testing of data flows, including confirmation that the system is receiving what it is supposed to receive, is a prerequisite for any monitoring system deployment.

Compliance restrictions on high-risk accounts require a monitoring process to verify they are being enforced. A restriction that is documented but not monitored for compliance is a control in name only. UBSFS's third-party wire restrictions were violated at scale, evidently without generating meaningful compliance intervention. For high-risk accounts with specific conditions attached, those conditions need to be actively monitored, not simply recorded and assumed to be followed.


The Sentinel Perspective

The UBSFS case illustrates a customer due diligence failure at scale: customer risk profiles that did not reflect the information the institution had already collected about its own customers, negative news reviews that were structurally limited in scope, and PEP assessments that accepted affiliate conclusions without independent verification.

Sentinel's continuous customer monitoring platform addresses exactly this layer. Ongoing screening against adverse media, PEP databases, and sanctions lists generates alerts when new information changes the risk profile of an existing customer, so that an eight-year gap between profile and reality becomes architecturally implausible. When a customer adds a foreign phone number, receives wires exclusively from a high-risk jurisdiction, or appears in new negative news, Sentinel surfaces that information rather than waiting for the next scheduled periodic review.

For wealth management firms and broker-dealers providing services to customers with international source of wealth, the UBSFS consent order is a detailed audit checklist. The central question it raises is whether your customer risk profiles reflect the information you actually have, and whether your ongoing screening will catch changes before a regulator does.

See How Sentinel Supports KYC and CDD Compliance for Wealth Management and Broker-Dealer Programs

Request a demonstration tailored to your institution's PEP screening, adverse media monitoring, and ongoing customer due diligence requirements.

Truth Technologies provides AML, KYC, OFAC, and sanctions screening compliance solutions through the Sentinel platform. This post is published for informational purposes only and does not constitute legal advice. All facts are sourced from the official FinCEN press release and consent order linked above.