August 17, 2026 By FinCheck
FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc. — the largest BSA penalty ever imposed on a broker-dealer. The headline number will get the attention. The word that should get your attention is the one FinCEN put in the title of its own press release: recidivist.
This was not a firm that failed to spot an emerging typology. It was a firm that was told exactly what was broken in 2018, said it would fix it, and did not. For compliance leaders at money service businesses, FinTechs, crypto platforms, payroll processors and gaming operators, that is the transferable lesson — and it has nothing to do with being a $10 billion broker-dealer.
What Actually Happened
FinCEN’s 2018 consent order with UBSFS carried a $14.5 million penalty and identified a specific defect: the firm’s automated monitoring system was not adequately surveilling foreign currency wires. UBSFS assured FinCEN it would remediate.
It did not. Over the following years, more than 50,000 foreign currency wires with an aggregate value exceeding $10 billion went without appropriate monitoring. UBSFS also did not disclose the ongoing failure to FinCEN — the regulator learned of it only through an investigation opened after a routine examination.
Layered on top were customer due diligence failures, particularly for high-risk customers with ties to Russia and Latin America. FinCEN found instances where the firm did not meaningfully assess source of wealth or act on adverse media alleging corruption, fraud and money laundering — in at least one case, even after a UBS affiliate raised its own concerns. Hundreds of suspicious transactions went unreported. UBSFS admitted willful violation of the BSA, including failure to maintain a compliant AML program and failure to file SARs.
The Real Violation Was the Broken Promise
Read FinCEN’s Compliance Considerations section closely and the message is unambiguous. Financial institutions are expected to promptly remediate AML compliance failures uncovered by regulators, auditors and employees. FinCEN specifically noted that significant portions of UBSFS’s remediation were not undertaken until its investigation was already underway.
That is a shift worth internalizing. Historically, the finding was the exposure. In this action, the finding was survivable — the failure to close it, and the failure to tell the regulator it remained open, is what converted a $14.5 million matter into a $125 million one. Nearly a nine-fold escalation for the same underlying defect.
Every compliance program carries open items. Independent audit findings, exam matters requiring attention, self-identified gaps in a risk assessment. None of those are, by themselves, an enforcement event. An open finding that has quietly aged for three renewal cycles, with a management action plan nobody has updated, absolutely is.
“Papering” Risk Is Not Managing Risk
The CDD language in this order deserves to be printed and pinned above every onboarding desk. FinCEN wrote that meaningful risk-based CDD does not include a focus on simply “papering” dispositions of apparent risks. It requires objective identification of the risks presented — at onboarding and as they emerge over the life of the relationship — and a proportionate response with commensurate controls.
In practice, that is the difference between an EDD file that documents why an alert was cleared and one that demonstrates the risk was actually reduced. Adverse media dismissed with a template rationale is documentation. Adverse media that triggers source-of-wealth verification, a relationship-level risk re-rating and a tightened monitoring threshold is control. Examiners have become good at telling the two apart.
Why This Lands on Smaller Institutions Too
It is tempting to file a broker-dealer wealth management case under “not my sector.” That would be a mistake, for three reasons.
- Scope of the mandated review. FinCEN’s independent AML program review requires UBSFS to be assessed against four priority illicit finance risks: the U.S. Southwest border, cartels and narcotics trafficking; Iran; Russia; and Venezuela. That is a clear statement of national priorities, and those same four themes are exactly what examiners are probing in MSB, crypto and payments programs right now.
- Automated monitoring is where the gap opens. The original 2018 defect was a rules engine that did not cover a transaction type. Any institution that has migrated platforms, added a payment rail, launched a new corridor or onboarded a new product without re-validating scenario coverage is exposed to the same failure mode.
- Recidivism scales down. A state examiner returning for a second look at a repeat finding at an MSB will apply the same logic on a smaller balance sheet. Repeat findings signal governance failure, not technical failure — and governance failure is what regulators price most aggressively.
The $15 Million Signal
There is a constructive element that has been largely overlooked. FinCEN will waive up to $15 million of the penalty for expenses UBSFS incurs completing the third-party lookback and independent AML program review — explicitly framed as recognition of “meaningful remediation” and “consequential investments” in the program.
That is a regulator telling the industry it will credit real money spent on real fixes. Read alongside the recidivism framing, the incentive structure is coherent: fix it properly and the cost is partially returned; defer it and the cost multiplies.
FinCheck’s Perspective & The Way Forward
Our view is that this action redefines what an AML program has to be able to prove. It is no longer sufficient to show that findings were identified. Institutions must show that findings were closed, that closure was validated by someone independent of the owner, and that the regulator was kept informed where prior enforcement is involved.
Five practical steps we recommend to clients this quarter:
- Run a findings-age report. Pull every open item from independent audits, exam reports, internal QA and self-identified gaps over the last 36 months. Age each one. Any finding older than two review cycles is your highest-priority risk, regardless of its original severity rating.
- Validate closure, don’t accept assertion. A finding is not closed because an owner marked it closed. Require evidence testing — re-run the sample, re-check the rule logic, re-read the SAR narratives. Independent validation of remediation is now a core audit deliverable, not a nice-to-have.
- Re-validate monitoring scenario coverage. Map every product, channel, rail and corridor against your live rule set and confirm each is covered by at least one tuned scenario. Document the mapping. Wire, FX and cross-border flows deserve first attention.
- Upgrade EDD from documentation to disposition. For every high-risk relationship, ask whether the file shows a risk that was mitigated or a risk that was merely explained. Source of wealth and adverse media are where this test is failed most often.
- Escalate repeat findings to the board. Any finding recurring across two consecutive audits should be a standing board or governing-body agenda item with a named owner and a hard date. Recidivism is a governance metric now — treat it as one.
The institutions that will come through the next examination cycle cleanly are not the ones with zero findings. They are the ones that can put a documented, independently validated remediation trail in front of an examiner and let it speak for itself.
Work With FinCheck
FinCheck LLC provides independent AML audits, BSA/AML risk assessments, fractional Chief Compliance Officer support, policy and procedure development, and remediation and management action plan execution for FinTechs, MSBs, crypto and digital asset platforms, payroll processors, e-commerce businesses and gaming and sweepstakes operators — with 25+ years of compliance experience across 30+ countries.
If you have open audit or examination findings that have outlived their remediation dates, now is the moment to close them properly. Connect with FinCheck LLC to schedule an independent AML program review or remediation validation.
Source: FinCEN news release and Consent Order, “FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations,” August 3, 2026.