About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UBS AML Enforcement Exposes Underlying Data Weaknesses

Subscribe to our newsletter

A coordinated US enforcement action against UBS Financial Services has exposed how incomplete data feeds, faulty system configuration and weak customer-risk controls can undermine an automated anti-money laundering (AML) programme.

FINRA found that UBS failed to monitor adequately more than 60,000 foreign-currency wires worth over $10 billion between January 2019 and June 2023. The deficiencies continued after the firm replaced a manual review process with automated monitoring.

The Financial Crimes Enforcement Network (FinCEN), the Financial Industry Regulatory Authority (FINRA), the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) addressed the failures through separate but coordinated actions. Transaction-monitoring software can assess only the activity and risk classifications supplied to it, a dependency reflected across the four actions.

Four Regulators, Connected Control Failures

FinCEN imposed a $125 million civil penalty, which it described as the largest penalty imposed against a broker-dealer for Bank Secrecy Act violations. It treated UBS as a repeat offender and required the firm to complete a third-party transaction lookback and submit its AML programme to independent review. FinCEN may waive up to $15 million for expenses associated with the undertaking if UBS satisfactorily completes the independent review and implements the third party’s recommendations.

The SEC imposed a further $20 million penalty after finding that UBS wilfully violated Exchange Act requirements governing broker-dealer compliance with the Bank Secrecy Act. The regulator also found that suspicious activity reports (SARs) arising from the subsequent lookback were filed late and covered thousands of transactions worth approximately $250 million. 

FINRA imposed a $20 million fine for failures in AML monitoring and customer due diligence. The CFTC imposed an $8 million penalty for failures to supervise the configuration and operation of systems monitoring foreign-currency wires.

Each regulator examined the breakdown through a different legal mandate. Together, the actions show how connected AML failures can engage broker-dealer, futures and Bank Secrecy Act requirements at the same time.

Automation Inherited Data Gaps

UBS initially monitored foreign-currency wires through a manually generated quarterly report containing thousands of transactions. Regulators found that the report was poorly suited to identifying suspicious patterns and omitted relevant geographic information.

The firm introduced an automated monitoring system in 2021. The new platform did not resolve the problem because it received an incomplete data file and was affected by a change in how transaction data was labelled. FINRA said about 33% of foreign-currency wires in retail customer accounts approved to engage in foreign-currency spot activity were omitted from monitoring.

The sequence illustrates a control-migration risk. Installing a new analytical engine does not prove that the source population is complete. Firms must reconcile transactions from the originating systems through each transformation and into the monitoring platform. They also need to test field mappings, classification rules and exclusions after configuration changes.

A monitoring system may process every record it receives correctly while still missing material activity. Without an independent control that compares the source population with the monitored population, compliance teams may have no clear view of what has dropped out.

Customer Risk and Transaction Data Diverged

The findings extended beyond transaction ingestion. Regulators also identified weaknesses in the customer due-diligence process, including the treatment of connections to higher-risk jurisdictions such as Russia, unexplained changes in domicile or employment, adverse media and potential political exposure.

Some customers retained risk ratings that generated less scrutiny than their circumstances warranted. That weakened the monitoring process even where transaction data reached the system.

Customer-risk data determines how firms classify activity, set alert thresholds and decide which behaviour needs review. Stale or inaccurate profiles can therefore reduce the sensitivity of transaction-monitoring scenarios. Effective AML surveillance requires customer and transaction data to operate within the same control framework.

Remediation Needs Its Own Controls

The repeat-offender finding shifts attention to UBS’s remediation. UBS had already faced regulatory action over its monitoring of foreign-currency wires in 2018. Related weaknesses continued for several years, and the later system deployment did not correct the affected data flow.

Remediation programmes need defined ownership, measurable completion criteria and testing independent of the implementation team. Closing a project or deploying a system does not establish that the original risk has been removed. Firms need evidence that previously omitted transactions have been identified, reviewed and reported where required.

Lessons Learned

The UBS action highlights three forms of evidence firms relying on automated surveillance should be able to produce: which transactions entered the system, how the system treated them and whether resulting cases reached investigation and reporting within the required time.

Bill St. Louis, FINRA’s head of enforcement, said member firms were responsible for designing and implementing AML programmes “tailored to their business model and capable of reasonably monitoring transactions for potentially suspicious activity.”

That requires end-to-end reconciliation, ownership of data fields and mappings, and regression testing after migrations or labelling changes. Known exclusions and data-quality problems need formal approval, time limits and escalation. Customer-risk attributes must also reach the monitoring system accurately and on time.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: The Next Compliance Frontier: Monitoring GenAI and Unstructured Comms Data

Date: 16 September 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes Generative AI is rapidly transforming how employees create, share, and interpret information. From internal copilots drafting client messages to AI tools summarising trading conversations or generating research notes, large language models are increasingly embedded in daily workflows across capital...

BLOG

Sumsub and ComplyAdvantage Deepen AML Screening Partnership as Compliance Demands Rise

ComplyAdvantage and Sumsub have partnered to tighten AML screening by combining Sumsub’s verification and monitoring environment with ComplyAdvantage’s Mesh intelligence layer. The result is a more integrated compliance workflow that brings together customer and business verification and screening within a single platform. For Sumsub users, the partnership adds ComplyAdvantage’s screening intelligence directly into existing workflows,...

EVENT

Data Management Summit New York City

Now in its 15th year the Data Management Summit NYC brings together the North American data management community to explore how data strategy is evolving to drive business outcomes and speed to market in changing times.

GUIDE

Regulatory Data Handbook 2026 – Fourteenth Edition

Welcome to the fourteenth edition of A-Team Group’s Regulatory Data Handbook. Supervisors increasingly expect firms to demonstrate which rules apply, which data supports each obligation, who owns the control and how exceptions are identified and resolved. Policies and implementation programmes must now be supported by records that can withstand regulatory scrutiny. This edition examines material...