About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UBS AML Enforcement Exposes Underlying Data Weaknesses

Subscribe to our newsletter

A coordinated US enforcement action against UBS Financial Services has exposed how incomplete data feeds, faulty system configuration and weak customer-risk controls can undermine an automated anti-money laundering (AML) programme.

FINRA found that UBS failed to monitor adequately more than 60,000 foreign-currency wires worth over $10 billion between January 2019 and June 2023. The deficiencies continued after the firm replaced a manual review process with automated monitoring.

The Financial Crimes Enforcement Network (FinCEN), the Financial Industry Regulatory Authority (FINRA), the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) addressed the failures through separate but coordinated actions. Transaction-monitoring software can assess only the activity and risk classifications supplied to it, a dependency reflected across the four actions.

Four Regulators, Connected Control Failures

FinCEN imposed a $125 million civil penalty, which it described as the largest penalty imposed against a broker-dealer for Bank Secrecy Act violations. It treated UBS as a repeat offender and required the firm to complete a third-party transaction lookback and submit its AML programme to independent review. FinCEN may waive up to $15 million for expenses associated with the undertaking if UBS satisfactorily completes the independent review and implements the third party’s recommendations.

The SEC imposed a further $20 million penalty after finding that UBS wilfully violated Exchange Act requirements governing broker-dealer compliance with the Bank Secrecy Act. The regulator also found that suspicious activity reports (SARs) arising from the subsequent lookback were filed late and covered thousands of transactions worth approximately $250 million. 

FINRA imposed a $20 million fine for failures in AML monitoring and customer due diligence. The CFTC imposed an $8 million penalty for failures to supervise the configuration and operation of systems monitoring foreign-currency wires.

Each regulator examined the breakdown through a different legal mandate. Together, the actions show how connected AML failures can engage broker-dealer, futures and Bank Secrecy Act requirements at the same time.

Automation Inherited Data Gaps

UBS initially monitored foreign-currency wires through a manually generated quarterly report containing thousands of transactions. Regulators found that the report was poorly suited to identifying suspicious patterns and omitted relevant geographic information.

The firm introduced an automated monitoring system in 2021. The new platform did not resolve the problem because it received an incomplete data file and was affected by a change in how transaction data was labelled. FINRA said about 33% of foreign-currency wires in retail customer accounts approved to engage in foreign-currency spot activity were omitted from monitoring.

The sequence illustrates a control-migration risk. Installing a new analytical engine does not prove that the source population is complete. Firms must reconcile transactions from the originating systems through each transformation and into the monitoring platform. They also need to test field mappings, classification rules and exclusions after configuration changes.

A monitoring system may process every record it receives correctly while still missing material activity. Without an independent control that compares the source population with the monitored population, compliance teams may have no clear view of what has dropped out.

Customer Risk and Transaction Data Diverged

The findings extended beyond transaction ingestion. Regulators also identified weaknesses in the customer due-diligence process, including the treatment of connections to higher-risk jurisdictions such as Russia, unexplained changes in domicile or employment, adverse media and potential political exposure.

Some customers retained risk ratings that generated less scrutiny than their circumstances warranted. That weakened the monitoring process even where transaction data reached the system.

Customer-risk data determines how firms classify activity, set alert thresholds and decide which behaviour needs review. Stale or inaccurate profiles can therefore reduce the sensitivity of transaction-monitoring scenarios. Effective AML surveillance requires customer and transaction data to operate within the same control framework.

Remediation Needs Its Own Controls

The repeat-offender finding shifts attention to UBS’s remediation. UBS had already faced regulatory action over its monitoring of foreign-currency wires in 2018. Related weaknesses continued for several years, and the later system deployment did not correct the affected data flow.

Remediation programmes need defined ownership, measurable completion criteria and testing independent of the implementation team. Closing a project or deploying a system does not establish that the original risk has been removed. Firms need evidence that previously omitted transactions have been identified, reviewed and reported where required.

Lessons Learned

The UBS action highlights three forms of evidence firms relying on automated surveillance should be able to produce: which transactions entered the system, how the system treated them and whether resulting cases reached investigation and reporting within the required time.

Bill St. Louis, FINRA’s head of enforcement, said member firms were responsible for designing and implementing AML programmes “tailored to their business model and capable of reasonably monitoring transactions for potentially suspicious activity.”

That requires end-to-end reconciliation, ownership of data fields and mappings, and regression testing after migrations or labelling changes. Known exclusions and data-quality problems need formal approval, time limits and escalation. Customer-risk attributes must also reach the monitoring system accurately and on time.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Managing Off-Channel Communications Compliance

The compliance challenge around off-channel communications has moved beyond the familiar narrative of WhatsApp messages on personal phones. Today, the real issue confronting firms has become communication sprawl: conversations occurring across messaging apps, collaboration platforms, social media direct messages, personal email, and even messaging tools embedded within trading and workflow applications. Regulators’ expectations focus on...

BLOG

Democratising Surveillance: Why Culture Is the Real Compliance Challenge

Institutional culture has always been the defining constraint for effective compliance across capital markets and treasury. Boards may approve ever-larger budgets for surveillance technology and artificial intelligence, and regulators may intensify scrutiny of governance, risk, and compliance frameworks, yet the hardest variable to control remains behavioural norms and internal incentives. For many organisations, the question...

EVENT

AI in Capital Markets Summit London

Now in its 3rd year, the AI in Capital Markets Summit returns with a focus on the practicalities of onboarding AI enterprise wide for business value creation. Whilst AI offers huge potential to revolutionise capital markets operations many are struggling to move beyond pilot phase to generate substantial value from AI.

GUIDE

Regulatory Data Handbook – Fourth Edition

Need to know all the essentials about the regulations impacting data management? Welcome to the Fourth edition of our A-Team Regulatory Data Handbook which provides all the essentials about regulations impacting data management. A-Team’s series of Regulatory Data Handbooks are a great way to see at-a-glance: All the regulations that are impacting data management today A...