The Financial Crimes Enforcement Network (FinCEN) assessed a $125 million civil money penalty against UBS Financial Services Inc. (UBSFS) on August 3, 2026 for willful Bank Secrecy Act (BSA) violations, and the remedy attached to it — a lookback across foreign currency wire transactions plus an independent programme review — moves the supervisory question from “did you investigate the alert?” to “can you prove the transaction ever reached the monitoring system?”
The consent order finds that UBSFS failed to appropriately monitor more than 61,500 foreign currency wires with an aggregate value of more than $10.5 billion between January 1, 2019 and June 30, 2023, in violation of 31 U.S.C. § 5318(h) and 31 U.S.C. § 5318(g) (FinCEN Consent Order). None of that turned on a compliance officer misreading a red flag. It turned on data: an incorrect partial feed, missing counterparty fields, and no exception queue to flag what never arrived. This analysis walks through the mechanics of that failure, the credit structure behind the headline number, how five jurisdictions define the same monitoring duty, and what the 180-day lookback clock requires of firms carrying similar architecture.
Key facts
- $125,000,000 civil money penalty assessed August 3, 2026 — the largest BSA penalty imposed on a broker-dealer to date (FinCEN news release).
- Credit structure: $48 million credited for parallel payments — $20 million each to FINRA and the SEC, $8 million to the CFTC. UBSFS pays $62 million to the U.S. Department of the Treasury on execution; a $15 million Remaining Amount falls due on or before May 31, 2028, waivable in full against Qualifying Expenses (Consent Order, Section V).
- Scale: more than 61,500 foreign currency wires worth more than $10.5 billion went unmonitored during the Relevant Time Period of January 1, 2019 to June 30, 2023 (Consent Order, Section II.H).
- The data defect: FINRA found that the automated tool deployed in February 2021 omitted roughly 33% of foreign currency wires in retail accounts approved for foreign currency spot activity, because of an incomplete data file and a labelling change (FINRA news release).
- What the gap concealed: the SEC found the firm’s own remedial lookback suspicious activity reports (SARs), filed from October 2023, were untimely and concerned thousands of transactions totalling approximately $250 million (Administrative Proceeding File No. 3-22665).
- The clock: the SAR Lookback Report is due to FinCEN within 180 days of the consent order date; SARs on identified Covered Transactions must be filed within 90 days of that report, with one 60-day extension available as of right (Consent Order, Section VI.A).
- Recidivism: UBSFS entered a December 2018 consent order with FinCEN carrying a $14.5 million penalty for the same monitoring deficiency, and told FinCEN it expected a replacement system by mid-2019. It deployed one in March 2021.
Methodology and sources
This analysis rests on primary documents. The core text is the FinCEN consent order in In the Matter of UBS Financial Services Inc., published August 3, 2026, read in full alongside FinCEN’s news release of the same date. The parallel actions are read from their issuing authorities: the SEC’s settled administrative order (File No. 3-22665), the CFTC’s release 9277-26, and FINRA’s news release. Comparative material comes from the FCA’s Final Notice against Metro Bank PLC, the Monetary Authority of Singapore’s July 2025 enforcement statement, AUSTRAC’s Westpac penalty record, and the published text of the EU anti-money laundering package. One Tier 2 source is used for market interpretation: the Willkie Farr & Gallagher client alert of August 5, 2026. Jurisdictional scope is the United States, United Kingdom, European Union, Singapore and Australia. Figures are as stated in the source documents.
What the consent order actually finds: a data-lineage failure, not a missed alert
Read the statement of facts and a specific engineering story emerges. Retail brokerage and securities-backed loan accounts at UBSFS carried balances only in U.S. dollars, so the dollar debits and credits were surveilled while the foreign-currency leg — the denomination, the counterparty, the jurisdiction of the sender or recipient — was not. The monitoring system saw a domestic-looking dollar movement where a cross-border conversion had occurred.
The 2018 consent order had already said this. UBSFS represented that a new automated system covering foreign currency wires would be in place by mid-2019. Within weeks of signing, the consent order records, UBSFS and UBS Head Office knew the date would slip, and did not tell FinCEN. Deployment came in March 2021, and the replacement carried its own defects.
The root cause FinCEN identifies is data governance, not surveillance logic. UBSFS selected an incorrect, partial data feed of foreign currency wires rather than the complete end-of-day feed. A one-month sample taken in early 2022 found that more than 5% of foreign currency wires were excluded from the automated system entirely and a further 12% or so arrived missing counterparty information. There was no exception queue and no error-reporting mechanism, so nothing surfaced the absence. Monthly model performance monitoring reports never flagged a problem, because no group inside the organisation — not Group Internal Audit, not Model Risk Management and Control — owned full data lineage mapping and testing back to the source of the foreign exchange wire data. UBSFS did not apply a coherent data management framework to the process until April 2023, four years into the Relevant Time Period.
That distinction matters for anyone benchmarking their own controls. A model can be well calibrated and an independent test can pass while a defined slice of cross-border activity is absent from the population being tested. FinCEN treats that absence as a failure to implement and maintain an AML program under 31 U.S.C. § 5318(h) and 31 C.F.R. §§ 1023.210 and 1026.210, and the unfiled reports as violations of 31 U.S.C. § 5318(g).
How five jurisdictions frame the same monitoring duty
| Jurisdiction / Regulator | Instrument and date | Scope | Key requirement | Penalty benchmark |
|---|---|---|---|---|
| US (FinCEN, SEC, CFTC, FINRA) | 31 U.S.C. § 5318(h) and § 5318(g); 31 C.F.R. §§ 1023.210, 1026.210; CDD Rule applicable May 11, 2018 | Broker-dealers and futures commission merchants | Implement and maintain an AML program with internal controls sufficient to detect and report suspicious activity; file SARs | Up to $71,545 per day per willful program violation (31 C.F.R. § 1010.821); UBSFS assessed $125 million, August 3, 2026 |
| UK (FCA) | Money Laundering Regulations 2017 (SI 2017/692), in force June 26, 2017; FCA Principle 3 | FCA-authorised firms, including investment firms | Regulation 28 ongoing monitoring, including scrutiny of transactions across the business relationship | Metro Bank PLC fined £16,675,200 on November 12, 2024 for failing to monitor 60 million transactions worth over £51 billion |
| EU (AMLA and national supervisors) | Regulation (EU) 2024/1624 applies July 10, 2027; Directive (EU) 2024/1640 transposition July 10, 2027 | Obliged entities, including investment firms and crypto-asset service providers | Uniform customer due diligence and ongoing transaction monitoring under the single rulebook, supervised centrally for selected entities | Maximum pecuniary sanction of at least €10 million or 10% of total annual turnover for serious, repeated or systematic breaches (Article 53, Directive (EU) 2024/1640) |
| Singapore (MAS) | MAS Notice SFA04-N02, revised text effective July 1, 2025, issued under section 27B of the Monetary Authority of Singapore Act | Capital markets intermediaries | Ongoing monitoring, corroboration of source of wealth, and adequate review of transactions the firm’s own systems flag as suspicious | Composition penalties of S$27.45 million across nine institutions, July 4, 2025; UBS AG Singapore Branch S$3 million |
| Australia (AUSTRAC) | Anti-Money Laundering and Counter-Terrorism Financing Act 2006, section 45(2) | Reporting entities sending or receiving international funds transfer instructions | Report every international funds transfer instruction to the AUSTRAC CEO within the statutory timeframe | A$1.3 billion ordered by the Federal Court on October 21, 2020 for 19,502,841 reporting failures — the largest civil penalty in Australian history |
Sources: FinCEN consent order; FCA; EUR-Lex; MAS; AUSTRAC. Last updated: August 19, 2026.
Ongoing monitoring is defined almost identically across these five regimes, and enforced through different mechanics. Each requires a firm to scrutinise transactions across the life of a relationship, not only at onboarding. The divergence is in what the regulator can reach. Australia converts the duty into a per-instruction reporting obligation under section 45(2) of the AML/CTF Act 2006, which is why Westpac’s 19,502,841 unreported international funds transfer instructions produced a A$1.3 billion penalty: each omission is a countable contravention. The United States prices the program failure by the day and the report, but layers four authorities over the same conduct. The United Kingdom fined Metro Bank £16,675,200 for a data-feed defect structurally identical to the one at UBSFS — transactions on the day an account opened were never fed into the monitoring system. The EU, from July 10, 2027, applies a maximum sanction of at least 10% of turnover, a number that scales with the firm rather than the breach count. AMLA’s single rulebook makes that shift explicit.
Regulatory arbitrage on this control is therefore narrowing. A firm running one global monitoring stack cannot pass in one jurisdiction and fail in another on the same data defect; whichever supervisor examines first finds it, and the others follow. UBS demonstrates the point: cross-border data completeness is the same problem the Financial Action Task Force has been chasing through the Travel Rule, and MAS penalised UBS AG’s Singapore branch S$3 million in July 2025 for transaction-monitoring and source-of-wealth shortcomings while the FinCEN investigation was already under way.
“Today’s historic action against UBSFS should send a clear message that recidivist financial institutions will face severe repercussions. Repeat violators of the Bank Secrecy Act jeopardize the integrity of our financial system, especially those that expose it to high-risk customers and activities without effective controls.”
— Andrea Gacki, Director, Financial Crimes Enforcement Network (FinCEN)
Enforcement context: the second record broker-dealer penalty in five months
The UBSFS order is not an outlier in a quiet year. On March 6, 2026, FinCEN assessed an $80 million penalty against Canaccord Genuity LLC for securities-fraud-related BSA violations, including a failure to file at least 160 SARs relating to dozens of over-the-counter securities. That action itself set the broker-dealer record. Five months later it was surpassed.
The recidivism finding drove the number. FinCEN’s December 2018 consent order carried a $14.5 million penalty and identified the foreign currency wire gap by name; FINRA fined the firm $4.5 million in the same settlement, which this publication covered at the time. UBS Group Internal Audit reviewed the transaction monitoring programme in 2019 and 2020; the later report concluded that UBSFS had “adequately implemented compensating controls over the legacy” applications — a finding the consent order describes as inaccurate. The firm’s own investigators, working the manual commodities report, repeatedly encountered foreign currency wires from non-commodities accounts and closed them as “generated in error” or “not in scope of the manual control” without confirming those wires were monitored anywhere else.
The pattern extends beyond AML. FINRA fined UBS $2.98 million in December 2024 over supervisory failures producing unsuitable recommendations, and $1.1 million in January 2025 for a decade of misleading trade confirmations. Each is distinct, but the common thread — controls that operate on paper while a defined slice of activity escapes them — is what supervisors are now pricing.
“Member firms operating in global markets bear a responsibility to design and implement AML programs that are tailored to their business model and capable of reasonably monitoring transactions for potentially suspicious activity. This action underscores FINRA’s approach to progressive discipline, which includes escalating sanctions for recidivist misconduct.”
— Bill St. Louis, Executive Vice President and Head of Enforcement, FINRA (FINRA)
What this means for brokers, FCMs, CASPs and compliance teams
For broker-dealers and FCMs. The examinable artefact is now data lineage documentation: a mapped, tested path from each source system that originates a cross-border or multi-currency instruction to the record the monitoring engine consumes, with reconciliation counts at every hop. UBSFS failed on feed selection, not model design. Firms should be able to answer, in writing, which feed the monitoring system consumes, whether it is complete or partial, who tests that, and how often. An exception queue for records that arrive incomplete or not at all is the specific control whose absence the consent order names.
For dual registrants. UBSFS is a registered broker-dealer, investment adviser and futures commission merchant, and paid four authorities for one control failure. The SEC–CFTC memorandum of understanding coordinates process, not liability. Remediation plans should be scoped across every registration the same data feed touches.
For crypto-asset service providers and payments firms. The same architecture recurs wherever a customer-facing balance is held in one unit of account and the underlying instruction settles in another. Where a conversion strips counterparty or jurisdiction fields before monitoring, the monitored record is materially incomplete. FinCEN’s payment stablecoin rules extend that expectation to issuers now inside the BSA perimeter.
For legal and compliance teams. Two obligations sit alongside the technical work. The first is disclosure: the consent order treats the failure to tell FinCEN that a committed remediation date had slipped as an aggravating fact in its own right. The second is scope. The AML Program Consultant must prioritise customers and transactions connected to the U.S. Southwest border, cartels and possible narcotics trafficking, Iran, Venezuela and Russia — FinCEN’s designated Priority Illicit Finance Risks. Firms should expect examiners to ask how those four risks are represented in their own customer risk models.
“While both penalties remain dwarfed by FinCEN’s headline-grabbing enforcement actions against Binance ($3.4 billion) and TD Bank ($1.3 billion), the rapid succession of record-setting broker-dealer penalties signals a clear escalation in regulatory scrutiny of anti-money laundering (‘AML’) compliance across the securities industry.”
— David Mortlock, Britt Mosman and Joshua Nelson, authors of the client alert, Willkie Farr & Gallagher LLP (Willkie)
What’s next: the 180-day clock and the $15 million that is still in play
Three dates now govern the matter. The SAR Lookback Consultant must deliver its report to FinCEN and UBSFS within 180 days of the consent order — a deadline falling around late January 2027. Within 90 days of that report, UBSFS must complete filing SARs on every Covered Transaction the consultant identifies, with one 60-day extension available as of right. Separately, the Remaining Amount of $15 million falls due on or before May 31, 2028.
The lookback is broader than the headline suggests. Beyond foreign currency wires in the Relevant Time Period, it requires data lineage mapping and testing to determine whether monitoring of other products suffered material gaps from similar root causes; where it did, the review period extends to however long that gap persisted. The eventual SAR volume is not bounded by the 61,500 figure in the order.
The $15 million waiver is an incentive and a constraint. FinCEN will credit only Qualifying Expenses — third-party fees for the AML Program Review and internal costs of implementing its recommendations — and explicitly excludes anything UBSFS would have spent maintaining an adequate programme anyway, including routine independent testing. Eligibility is determined quarter by quarter, in FinCEN’s sole discretion. The design rewards incremental remediation spend while refusing to subsidise business as usual, and it is the mechanism most likely to be replicated in future orders.
TL;DR
FinCEN assessed $125 million against UBS Financial Services on August 3, 2026 — the largest BSA penalty against a broker-dealer — after finding that more than 61,500 foreign currency wires worth over $10.5 billion escaped transaction monitoring between January 2019 and June 2023, four years after a 2018 consent order flagged the same defect. The cause was data governance: a partial feed, missing counterparty fields, and no exception queue. Of the total, $48 million is credited against payments to FINRA, the SEC and the CFTC; $62 million goes to Treasury now; $15 million is waivable against remediation spend. A SAR lookback report is due within 180 days, and the parallel programme review must prioritise the U.S. Southwest border, cartels and narcotics, Iran, Venezuela and Russia.
FAQ
Is the $125 million on top of the SEC, CFTC and FINRA penalties?
No. FinCEN imposed a $125 million civil money penalty and agreed to credit $48 million against it for payments UBSFS makes to the CFTC ($8 million), the SEC ($20 million) and FINRA ($20 million). UBSFS pays $62 million directly to the U.S. Department of the Treasury, with a Remaining Amount of $15 million due on or before May 31, 2028 that FinCEN may waive against qualifying remediation spend. The all-in cash figure is therefore $125 million at most, not $173 million.
What exactly is a SAR lookback review?
It is a retrospective examination, conducted by an independent consultant at the firm’s expense, of transactions that were not properly surveilled at the time, to determine which of them would have required a suspicious activity report. Here the consultant must review foreign currency wire transactions across the January 2019 to June 2023 period and test whether other products suffered similar monitoring gaps. Any transactions identified must then be reported to FinCEN as SARs within 90 days of the report.
Why did FinCEN call UBSFS a recidivist?
Because the December 2018 consent order, which carried a $14.5 million penalty, had already identified inadequate monitoring of foreign currency wires. UBSFS told FinCEN it expected a replacement automated system by mid-2019, learned within weeks that the date would slip, did not disclose that, and deployed a system only in March 2021 — which then carried its own data defects through the second quarter of 2023.
Does this apply to firms outside the United States?
The consent order binds UBSFS only. The control expectation is not US-specific. The FCA fined Metro Bank £16,675,200 in November 2024 for a structurally similar data-feed defect, MAS penalised nine institutions S$27.45 million in July 2025 partly for transaction-monitoring shortcomings, and the EU anti-money laundering package applies a single rulebook from July 10, 2027 with sanctions of up to 10% of annual turnover.
What are FinCEN’s Priority Illicit Finance Risks in this order?
Four risk areas the AML Program Consultant must prioritise when selecting customers and transactions for risk-based testing: the U.S. Southwest border, cartels and possible narcotics trafficking; Iran; Venezuela; and Russia. The consultant may draw its sample primarily from customers UBSFS rated high or higher risk, but must supplement it with customers rated medium and low risk — a design intended to test the risk rating itself, not only the monitoring downstream of it.
What is the single control most firms should check first?
Whether an exception queue and error-reporting mechanism exists for records that fail to reach the transaction monitoring system or arrive without required fields. FinCEN named its absence as one of three categories of error at UBSFS. Without it, a monitoring stack cannot distinguish “no suspicious activity found” from “the transaction was never examined”, and neither model performance reporting nor internal audit will surface the difference.
This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.