The UBS AML Settlements: Broker-Dealer Lessons From a Four-Regulator Resolution

AUG 27, 2026 | PRACTUS LLP

The UBS AML Settlements: Broker-Dealer Lessons From a Four-Regulator Resolution

Authored by Robert Moreiro

One Resolution, Four Regulators

Executive Summary: Why the UBS AML Settlements Matter for Broker-Dealers

On August 3, 2026, FINRA announced a $20 million fine against UBS Financial Services Inc. for anti-money laundering failures involving foreign-currency wires and customer due diligence. The FINRA action did not arrive alone. It was one piece of a coordinated resolution announced the same day by four regulators. FinCEN assessed a $125 million civil money penalty, the largest it has ever imposed on a broker-dealer for Bank Secrecy Act violations, and UBS Financial admitted that it willfully violated the BSA. The SEC ordered a $20 million penalty for suspicious activity reporting failures under Exchange Act Section 17(a) and Rule 17a-8. The CFTC imposed $8 million for failing to diligently supervise the same AML transaction-monitoring systems. FinCEN credited the $48 million paid to the three market regulators against its own assessment and agreed to waive up to $15 million of the remainder if the firm satisfactorily completes the required remediation.

Beyond the Numbers: What Regulators Were Really Testing

The size of the combined sanctions is only part of the story. FINRA and FinCEN each characterized the conduct as repeat misconduct following 2018 settlements that had already required UBS Financial to fix its monitoring of foreign-currency wires. The 2026 actions are therefore a working answer to a question every compliance officer should be asking: how do regulators decide whether an AML program actually operates as designed, rather than existing on paper?

Risk Ratings, CDD and Missed Red Flags

According to FINRA’s Letter of Acceptance, Waiver and Consent (AWC), from January 2019 through June 2023 UBS Financial failed to reasonably monitor more than 60,000 foreign-currency wires totaling more than $10.4 billion. FINRA found that the activity included transfers involving high-risk geographic locations, excessive or unusually large transfers, transactions with no apparent business purpose, and activity similar to transactions for which the firm had previously filed suspicious activity reports (SARs). FINRA also found customer due diligence deficiencies that caused certain higher-risk customers to be assigned or kept at lower risk ratings and, in turn, subjected to less scrutiny.

FinCEN, the SEC and FINRA Target the Same Underlying Failures

The case should be read against the regulatory framework governing broker-dealer AML programs. FinCEN’s rules under the Bank Secrecy Act require broker-dealers to maintain AML programs, customer identification procedures and suspicious activity reporting processes. The SEC examines and enforces broker-dealer compliance with BSA requirements, including through Exchange Act Rule 17a-8. FINRA Rule 3310 requires each member to maintain a written AML program reasonably designed to achieve and monitor compliance with the BSA and its implementing regulations, including policies reasonably expected to detect and cause the reporting of suspicious transactions and risk-based procedures for ongoing customer due diligence. The UBS resolution shows all three regimes, plus the CFTC’s supervision expectations, applied to the same underlying control failures.

Where AML Controls Break Down

For broker-dealers, the central lesson is that AML effectiveness depends on the integrity of the entire control chain: risk assessment, customer information, transaction data, scenario design, alert generation, investigation, escalation, SAR decisioning, remediation and testing. A failure at any one point can undermine the rest of the program. And when a regulator has already identified the same control weakness, a delayed or incomplete remediation can transform an ordinary supervisory deficiency into a recidivist enforcement matter with far higher sanctions.

Key Takeaways for Broker-Dealer AML Compliance

The UBS matter raises questions that broker-dealers should be asking now, particularly firms with significant wire activity, international customers, complex data architecture or prior AML findings:

  • Repeat findings materially increase enforcement risk. FINRA expressly cited progressive discipline and the firm’s 2018 settlement, and FinCEN obtained an admission that the violations were willful. An AML remediation commitment is itself a regulatory risk event: missed deadlines, partial implementations and recurring gaps should receive senior-management and board-level attention.
  • Transaction monitoring is only as good as the data feeding it. UBS implemented a new automated monitoring tool, but FINRA found that incomplete data and a labeling change caused the tool to omit a significant portion of foreign-currency wire activity. Model sophistication cannot cure missing, misclassified or incomplete source data.
  • Customer risk ratings must change when the facts change. FINRA’s findings focus on failures to incorporate changes in domicile, employment, adverse media, political exposure and connections to higher-risk jurisdictions into customer risk profiles. Static risk ratings are not consistent with risk-based ongoing CDD.
  • AML and sanctions-related information must flow across functions. Information identified by registered representatives, surveillance analysts, investigations teams, onboarding personnel and adverse-media screening should be reconciled. Material information cannot remain trapped in one function while another relies on an outdated profile.
  • SAR reporting is the end of a process, not the beginning. The obligation is not satisfied by having a SAR policy. Firms need monitoring and investigation systems reasonably capable of surfacing activity that should be reviewed for potential reporting, with escalation and documentation sufficient to support the ultimate SAR decision.
  • Remediation must be validated independently. The FINRA AWC requires a third-party lookback, detailed reporting, implementation of recommendations and senior-management certification, and FinCEN made up to $15 million of its penalty contingent on satisfactory completion of an independent program review. Firms should assume that regulators will expect evidence that fixes have been tested and are operating effectively, not simply deployed.
  • Broker-dealer AML obligations overlap, and the overlap is now concrete. FinCEN establishes the BSA requirements, the SEC examines and enforces compliance with applicable BSA obligations, FINRA imposes its own AML program rule, and the CFTC expects diligent supervision of futures-related activity. In the UBS resolution, one set of control failures produced four separate actions.

Background: FINRA’s 2026 UBS AML Enforcement Action

UBS Financial has been a FINRA member since 1936 and operates a large full-service brokerage business. The 2026 AWC follows a December 2018 FINRA settlement in which the firm was censured and fined $4.5 million for AML deficiencies involving foreign-currency wire monitoring. The 2018 matter also included a parallel FinCEN consent order addressing the same monitoring weaknesses. FINRA’s 2026 AWC states that UBS Financial represented in connection with the earlier matter that it would implement a new third-party automated transaction-monitoring system by mid-2019.

Legacy Systems, Delayed Fixes and Monitoring Gaps

FINRA found that the implementation did not occur until February 2021. In the interim, the firm continued to use legacy monitoring systems that FINRA had already found deficient. Those systems did not capture information FINRA viewed as necessary to reasonably detect suspicious activity, including beneficiary and originator information, countries of destination and origin, and foreign-currency denomination. FINRA also described limitations in a quarterly manual report used for certain accounts, including the volume of wires included, limited parameters, incomplete geographic information, a coding error that excluded more than 16% of relevant wire activity for a period, and review delays that often exceeded several months.

Automation Did Not Eliminate the Monitoring Gap

When the automated system was implemented in February 2021, the monitoring problem changed rather than disappeared. FINRA found that an incomplete data file and a labeling change prevented the system from reviewing a significant percentage of foreign-currency wire activity. The omitted activity included approximately 33% of foreign-currency wires in retail customer accounts approved for foreign-currency spot activity. FINRA also found that hundreds of wires totaling more than $110 million had incomplete or missing counterparty information, impairing monitoring of potentially higher-risk geographic activity.

The Scope of the Monitoring Failure

Across the January 2019 through June 2023 period, FINRA found that the firm failed to reasonably monitor more than 60,000 foreign-currency wires totaling more than $10.4 billion. The FINRA settlement includes a censure, a $20 million fine, extensive undertakings, a third-party lookback and remediation review, and senior-management certification. UBS Financial accepted FINRA’s findings without admitting or denying them.

Parallel FinCEN, SEC and CFTC AML Actions Against UBS

The companion actions materially change the risk picture, and any assessment of the matter that stops at the FINRA fine understates it. FinCEN assessed a $125 million civil money penalty, which it described as the largest it has ever imposed on a broker-dealer for BSA violations. Unlike the FINRA AWC, the FinCEN resolution includes an admission: UBS Financial admits that it willfully violated the BSA, including by failing to implement and maintain an AML program meeting the statute’s minimum requirements and by failing to file SARs. FinCEN credited the $48 million UBS Financial paid to the SEC, FINRA and the CFTC against its assessment and agreed to waive up to $15 million of the remainder upon satisfactory completion of an independent review of the AML program and implementation of the reviewer’s recommendations.

FinCEN Flags Priority Risks for Remediation

The FinCEN consent order also signals where remediation attention is expected. The required independent review must evaluate the program’s effectiveness against specified priority illicit-finance risks: the U.S. Southwest border, cartels and possible narcotics trafficking; Iran; Russia; and Venezuela. Broker-dealers designing risk assessments and scenario coverage should take note. The government has told this respondent, in an enforcement document, which typologies it cares about most.

One Control Failure, Four Enforcement Theories

The SEC’s settled order imposed a $20 million penalty for SAR-related failures under Exchange Act Section 17(a) and Rule 17a-8, and the CFTC imposed $8 million for failing to diligently supervise the transaction-monitoring systems on which its registrant relied. Neither theory is novel. Together with the FINRA and FinCEN actions, they demonstrate how a single monitoring and CDD breakdown can be charged four different ways.

Customer Due Diligence Failures and Risk-Rating Lessons

The case is equally important for its customer due diligence findings. FINRA found that, between January 2019 and December 2022, UBS Financial did not reasonably implement its CDD program with respect to certain retail customers. The firm collected information such as name, address, citizenship, occupation, source of wealth and source of funds and used an automated client risk-rating tool. Higher-risk customers were subject to additional diligence. The failure, according to FINRA, was not the absence of a CDD framework; it was the failure to timely detect and incorporate material risk information into that framework.

Risk Indicators That Should Trigger a CDD Refresh

The AWC identifies risk indicators such as connections to higher-risk jurisdictions, unexplained changes in domicile and employment, adverse media, negative news and potential political exposure. In some instances, those indicators did not result in timely changes to customer profiles or risk ratings. The resulting lower ratings meant less scrutiny and less information available to reviewers assessing transaction activity.

Risk Ratings Are Not One-and-Done

A customer risk rating is not a static onboarding artifact. It should reflect current information and should be refreshed when triggering events or new information materially change the customer’s risk. Firms should evaluate whether information generated in other parts of the organization (surveillance alerts, sanctions screening, adverse-media reviews, account servicing, registered-representative communications, credit activity and investigations) can trigger a CDD reassessment when warranted.

Broker-Dealer AML Regulatory Framework: FinCEN, SEC and FINRA

FinCEN and Bank Secrecy Act AML Requirements for Broker-Dealers

Broker-dealers are financial institutions under the Bank Secrecy Act and are subject to FinCEN’s implementing regulations. The principal requirements include the following:

  • AML program (31 C.F.R. § 1023.210). A broker-dealer must maintain a written AML program reasonably designed to achieve and monitor compliance with the BSA and applicable implementing regulations. The program must be approved by senior management and include the core elements required by the BSA and applicable SRO rules.
  • Suspicious activity reporting (31 C.F.R. § 1023.320). A broker-dealer must file a SAR when a transaction conducted or attempted by, at or through the broker-dealer involves or aggregates at least $5,000 and the firm knows, suspects or has reason to suspect that the transaction involves illicit funds, is designed to evade BSA requirements, lacks an apparent lawful purpose or is not the type of activity in which the customer would normally be expected to engage and no reasonable explanation is known after examining the available facts.
  • Customer Identification Program (31 C.F.R. § 1023.220). Broker-dealers must maintain a written CIP appropriate to their size and business, including procedures to obtain and verify identifying information and form a reasonable belief that the firm knows the true identity of each customer, subject to the rule’s definitions and exceptions.
  • Customer due diligence and beneficial ownership (31 C.F.R. § 1010.230 and ongoing CDD obligations). Covered financial institutions must maintain risk-based CDD procedures. FinCEN’s exceptive relief of February 13, 2026 (FIN-2026-R001) permits covered financial institutions to limit beneficial-owner identification and verification for a legal-entity customer to the first account opening, circumstances in which facts call prior information into question, and circumstances required by the institution’s risk-based ongoing CDD procedures.
  • Foreign correspondent and private banking due diligence (31 C.F.R. §§ 1010.610 and 1010.620). Where applicable, broker-dealers must implement due diligence or enhanced due diligence for certain foreign correspondent accounts and private banking accounts for non-U.S. persons, including heightened scrutiny for designated higher-risk relationships.
  • Recordkeeping and reporting. Broker-dealers also remain subject to applicable BSA recordkeeping and reporting requirements, including preservation of SAR supporting documentation and confidentiality restrictions governing SARs and information that would reveal their existence.

SEC Oversight and Exchange Act Rule 17a-8

The SEC’s role is not merely derivative of FINRA supervision. Exchange Act Rule 17a-8 requires registered broker-dealers to comply with the reporting, recordkeeping and record-retention requirements of the BSA that apply to brokers or dealers in securities. FinCEN also has delegated authority to the SEC to examine broker-dealers for compliance with FinCEN regulations. The SEC therefore may bring its own enforcement actions when a broker-dealer fails to satisfy applicable SAR, recordkeeping or related BSA obligations.

SEC Enforcement Confirms Broker-Dealer Accountability

That authority is in active use. The SEC’s own UBS order in the August 2026 resolution imposed a $20 million penalty for SAR-related failures. And on June 29, 2026, the Commission announced a settled action against Merrill Lynch, Pierce, Fenner & Smith Incorporated, which paid a $7.5 million civil penalty for failing to file numerous SARs, in violation of Exchange Act Section 17(a) and Rule 17a-8. The Merrill order is a caution for firms that rely on an enterprise-wide bank AML platform: reliance on a parent’s or affiliate’s systems does not eliminate the broker-dealer’s separate obligations. The registered broker-dealer remains responsible for satisfying the regulatory requirements applicable to it.

FINRA Rule 3310 AML Compliance Program Requirements

FINRA Rule 3310 requires each member to develop and implement a written AML program approved in writing by senior management and reasonably designed to achieve and monitor the member’s compliance with the BSA and its implementing regulations. Among other things, the rule requires:

  • Rule 3310(a): policies and procedures that can be reasonably expected to detect and cause the reporting of suspicious transactions;
  • Rule 3310(b): policies, procedures and internal controls reasonably designed to achieve compliance with the BSA and implementing regulations, including applicable CIP and beneficial-ownership requirements;
  • Rule 3310(c): independent testing for compliance, generally each calendar year, subject to the rule’s limited two-year testing provision for certain firms;
  • Rule 3310(d): designation of one or more individuals responsible for implementing and monitoring the day-to-day AML program;
  • Rule 3310(e): ongoing AML training for appropriate personnel; and
  • Rule 3310(f): risk-based procedures for ongoing CDD, including understanding the nature and purpose of customer relationships for purposes of developing customer risk profiles, conducting ongoing monitoring to identify and report suspicious transactions, and maintaining and updating customer information on a risk basis.

FINRA also commonly charges Rule 2010 where AML program failures violate the standards of commercial honor and just and equitable principles of trade. In the UBS AWC, FINRA found violations of Rules 3310(a), 3310(f) and 2010.

Five AML Compliance Lessons Beyond Foreign-Currency Wires

  1. Data Lineage Is an AML Control

The clearest technical lesson from the case: transaction monitoring cannot be evaluated separately from data governance. A transaction-monitoring platform may be well designed at the scenario level and still fail if the source systems do not deliver complete, accurate and properly labeled data. Firms should be able to trace critical AML data from source systems through transformations, interfaces and staging layers into the monitoring engine and finally into alerts and cases.

  • Testing should confirm that:
  • The population entering the monitoring system reconciles to the population that should be monitored.
  • Critical fields are populated and reliable.
  • Transaction types are classified correctly.
  • Upstream system changes do not unintentionally alter downstream monitoring.
  • Exception reports identify unexpected drops, gaps or data-quality problems.
  1. Remediation Deadlines Must Be Governed Like Regulatory Commitments

Even where delays stem from legitimate technology challenges, firms should treat regulatory remediation commitments as enterprise obligations with:

  • Formal governance and accountable ownership.
  • Milestone tracking and escalation thresholds.
  • Independent validation of completed fixes.
  • Documented decisions when timelines change.
  • Senior-management visibility into repeat or overdue findings.

The FinCEN credit-and-waiver structure makes the same point in dollars: remediation completed and validated is worth up to $15 million; remediation promised is worth nothing.

  1. Alert Volume Is Not a Substitute for Reasonable Coverage

A monitoring program should be calibrated to the firm’s actual business and risk. Excessive alert volume can be evidence of poor scenario design just as readily as insufficient alert volume. The quarterly manual report described by FINRA generated thousands of wires, yet FINRA found it did not reasonably permit reviewers to identify suspicious or unusual patterns and often lacked important geographic information. The relevant question is not how many alerts or transactions were reviewed; it is whether the system reasonably identifies the risk typologies the firm faces and provides analysts with sufficient context to investigate them.

  1. CDD and Transaction Monitoring Must Work Together

Because CDD and transaction surveillance are interdependent, firms should test whether:

  • Customer-risk scoring receives complete and current inputs.
  • Risk-rating overrides are documented and reviewed.
  • Material changes trigger recalculation or reassessment.
  • Downstream monitoring logic uses the current customer risk rating.
  • Investigators have enough customer context to evaluate activity effectively.
  1. Prior SARs Should Inform Subsequent Monitoring

FINRA specifically identified unreviewed transactions involving accounts for which the firm had previously filed SARs for similar activity. A prior SAR does not automatically require a subsequent SAR, and SAR filing determinations remain fact specific. But a pattern of recurring conduct should inform the customer’s risk profile, monitoring strategy and investigative context. Firms should assess whether prior SARs, internal investigations and law-enforcement requests are incorporated into future monitoring in a manner consistent with SAR confidentiality requirements.

Practical AML Compliance Checklist for Broker-Dealers

  • Reconcile monitoring populations. Compare source transaction populations to the populations actually received by AML monitoring systems. Test by transaction type, product, channel, legal entity, geography and customer segment.
  • Perform end-to-end data lineage testing. Identify critical data elements used by scenarios and risk-rating engines, trace them through all transformations, and establish controls to detect dropped, null, stale or mislabeled values.
  • Govern system changes. Require AML impact assessments for changes to source systems, data labels, interfaces, transaction codes and vendor platforms. Significant changes should trigger regression testing before and after deployment.
  • Test scenario coverage against the firm’s risk assessment. The AML risk assessment should map identified risks to monitoring controls. Gaps between business risk and scenario coverage should be documented, remediated and escalated. Consider whether coverage addresses the priority illicit-finance risks FinCEN identified in the UBS consent order.
  • Review customer-risk triggers. Confirm that changes in domicile, occupation, source of wealth, beneficial ownership, political exposure, adverse media, sanctions nexus, transaction behavior and other material facts can trigger CDD refreshes and risk-rating reassessment.
  • Build a formal investigations feedback loop. Information identified by alert analysts and investigations teams should feed back into customer profiles, risk ratings, enhanced-diligence decisions and surveillance when appropriate.
  • Validate SAR governance. Review alert-to-case conversion, investigative documentation, escalation thresholds, SAR decisioning, timeliness, continuing-activity reviews, confidentiality controls and supporting-document retention.
  • Treat regulatory remediation as a controlled program. Establish accountable owners, milestones, issue validation, senior escalation, independent testing and closure evidence. Where deadlines slip, document why and assess whether regulators should be informed.
  • Use independent testing to challenge effectiveness, not merely policy compliance. Independent testing should include transaction sampling, data completeness, scenario validation, CDD trigger testing, SAR timeliness and issue-remediation validation.
  • Assess third-party and enterprise dependencies. Introducing firms, clearing firms and affiliates may allocate operational functions, but each broker-dealer retains its own regulatory obligations. Reliance arrangements should be documented and periodically tested.
  • Escalate repeat findings. A recurring AML issue should be treated as a significant compliance event. Repeat findings can materially alter the sanctions analysis and may prompt regulator demands for independent consultants, lookbacks and senior certifications.

Broker-Dealer AML Compliance FAQs

Does a broker-dealer have to file a SAR for every unusual transaction?

No. The SAR rule applies when the regulatory threshold and suspicious-activity criteria are met. Firms should investigate relevant facts and document the basis for filing or not filing. The absence of a filing obligation for a particular transaction does not eliminate the need for reasonable monitoring.

What is the SAR dollar threshold for broker-dealers?

Under 31 C.F.R. § 1023.320, the broker-dealer SAR rule generally applies to transactions conducted or attempted by, at or through the broker-dealer that involve or aggregate at least $5,000 and satisfy one or more specified suspicion criteria.

How quickly must a broker-dealer file a SAR?

The rule generally requires filing no later than 30 calendar days after initial detection of facts that may constitute a basis for filing. Where no suspect is identified on the date of initial detection, the rule permits a delay of up to an additional 30 calendar days to identify a suspect, but in no case may filing be delayed more than 60 calendar days after initial detection. Firms should have escalation procedures for matters requiring immediate law-enforcement attention.

Can a broker-dealer rely on an affiliate’s or parent bank’s AML system?

A broker-dealer may use enterprise systems and shared services, but it retains responsibility for meeting its own regulatory obligations. The SEC’s June 2026 Merrill Lynch action and the SEC’s own order against UBS Financial in the August 2026 resolution both reinforce that point.

What is the significance of the 2026 FinCEN beneficial-ownership relief?

FinCEN’s exceptive relief of February 13, 2026 (FIN-2026-R001) permits covered financial institutions to identify and verify beneficial owners of a legal-entity customer at the first account opening rather than at each subsequent account opening, subject to risk-based ongoing CDD and circumstances that call prior information into question. Firms should confirm that procedures reflect the relief accurately and continue to respond to material risk changes.

Does a prior SAR change the customer’s risk rating automatically?

Not necessarily. Risk-rating methodologies differ, and SAR confidentiality must be preserved. But the underlying activity and facts that gave rise to a SAR may be highly relevant to ongoing CDD, monitoring and future investigations.

What should a firm do if it discovers a historical monitoring gap?

The response should be risk based and promptly escalated. Firms should define the affected population, stop the ongoing control failure, assess data integrity, determine whether a lookback is warranted, evaluate SAR obligations, preserve evidence, consider regulatory reporting obligations and independently validate remediation.

Conclusion: What Broker-Dealers Should Do After the UBS AML Settlements

The UBS resolution shows where AML enforcement now concentrates: on whether the control environment works at scale. Policies, procedures and sophisticated monitoring technology are not enough if the firm cannot demonstrate complete data, appropriate risk calibration, current customer profiles, timely investigations and reliable escalation. The same is true of remediation. A promised fix that is late, incomplete or not independently validated can become the centerpiece of the next enforcement action; here it became the centerpiece of four.

Use the UBS Matter as a Testing Agenda

Broker-dealers should use the UBS matter as a testing agenda. Firms should ask whether they can reconcile the transaction population subject to monitoring, trace critical data from source to alert, explain why each material risk is covered, demonstrate that customer risk ratings respond to new information, and prove that prior findings were remediated and tested. Where the answer is incomplete, the issue should be treated as a compliance control gap rather than a documentation exercise.

Overlapping Regulators Raise the Compliance Stakes

The overlapping structure raises the stakes. FinCEN establishes the core BSA requirements; the SEC examines for and enforces applicable broker-dealer BSA reporting and recordkeeping obligations; FINRA Rule 3310 requires a written AML program reasonably designed to achieve and monitor compliance with those requirements; and, for firms with futures business, the CFTC expects diligent supervision of the same systems. A material weakness can create simultaneous exposure under all of them. The most defensible response is a program that is risk based, data driven, independently tested and capable of producing evidence that the firm’s controls operate as designed.

Authorities and Source Materials

About Robert Moreiro

Robert Moreiro is a Securities Regulation Partner with Practus, LLP. He has more than 20 years of experience advising broker-dealers, registered investment advisers, financial institutions and associated persons on securities regulation, compliance, regulatory examinations, investigations and enforcement matters. He previously served as Senior Counsel in FINRA’s Enforcement Department and has served as Chief Compliance Officer and AML Compliance Officer for regulated financial-services firms. He is recognized in the 2025 and 2026 editions of The Best Lawyers in America for Securities Regulation and holds the Investment Adviser Certified Compliance Professional and Certified Securities Compliance Professional designations.

The Authors
Robert Moreiro
Read Full Bio

Practus, LLP provides this information as a service to clients and others for educational purposes only. It should not be construed or relied on as legal advice or to create an attorney-client relationship. Readers should not act upon this information without seeking advice from professional advisers.

Search Icon