
A coordinated US enforcement action against UBS Financial Services has exposed how incomplete data feeds, faulty system configuration and weak customer-risk controls can undermine an automated anti-money laundering (AML) programme.
FINRA found that UBS failed to monitor adequately more than 60,000 foreign-currency wires worth over $10 billion between January 2019 and June 2023. The deficiencies continued after the firm replaced a manual review process with automated monitoring.
The Financial Crimes Enforcement Network (FinCEN), the Financial Industry Regulatory Authority (FINRA), the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) addressed the failures through separate but coordinated actions. Transaction-monitoring software can assess only the activity and risk classifications supplied to it, a dependency reflected across the four actions.
Four Regulators, Connected Control Failures
FinCEN imposed a $125 million civil penalty, which it described as the largest penalty imposed against a broker-dealer for Bank Secrecy Act violations. It treated UBS as a repeat offender and required the firm to complete a third-party transaction lookback and submit its AML programme to independent review. FinCEN may waive up to $15 million for expenses associated with the undertaking if UBS satisfactorily completes the independent review and implements the third party’s recommendations.
The SEC imposed a further $20 million penalty after finding that UBS wilfully violated Exchange Act requirements governing broker-dealer compliance with the Bank Secrecy Act. The regulator also found that suspicious activity reports (SARs) arising from the subsequent lookback were filed late and covered thousands of transactions worth approximately $250 million.
FINRA imposed a $20 million fine for failures in AML monitoring and customer due diligence. The CFTC imposed an $8 million penalty for failures to supervise the configuration and operation of systems monitoring foreign-currency wires.
Each regulator examined the breakdown through a different legal mandate. Together, the actions show how connected AML failures can engage broker-dealer, futures and Bank Secrecy Act requirements at the same time.
Automation Inherited Data Gaps
UBS initially monitored foreign-currency wires through a manually generated quarterly report containing thousands of transactions. Regulators found that the report was poorly suited to identifying suspicious patterns and omitted relevant geographic information.
The firm introduced an automated monitoring system in 2021. The new platform did not resolve the problem because it received an incomplete data file and was affected by a change in how transaction data was labelled. FINRA said about 33% of foreign-currency wires in retail customer accounts approved to engage in foreign-currency spot activity were omitted from monitoring.
The sequence illustrates a control-migration risk. Installing a new analytical engine does not prove that the source population is complete. Firms must reconcile transactions from the originating systems through each transformation and into the monitoring platform. They also need to test field mappings, classification rules and exclusions after configuration changes.
A monitoring system may process every record it receives correctly while still missing material activity. Without an independent control that compares the source population with the monitored population, compliance teams may have no clear view of what has dropped out.
Customer Risk and Transaction Data Diverged
The findings extended beyond transaction ingestion. Regulators also identified weaknesses in the customer due-diligence process, including the treatment of connections to higher-risk jurisdictions such as Russia, unexplained changes in domicile or employment, adverse media and potential political exposure.
Some customers retained risk ratings that generated less scrutiny than their circumstances warranted. That weakened the monitoring process even where transaction data reached the system.
Customer-risk data determines how firms classify activity, set alert thresholds and decide which behaviour needs review. Stale or inaccurate profiles can therefore reduce the sensitivity of transaction-monitoring scenarios. Effective AML surveillance requires customer and transaction data to operate within the same control framework.
Remediation Needs Its Own Controls
The repeat-offender finding shifts attention to UBS’s remediation. UBS had already faced regulatory action over its monitoring of foreign-currency wires in 2018. Related weaknesses continued for several years, and the later system deployment did not correct the affected data flow.
Remediation programmes need defined ownership, measurable completion criteria and testing independent of the implementation team. Closing a project or deploying a system does not establish that the original risk has been removed. Firms need evidence that previously omitted transactions have been identified, reviewed and reported where required.
Lessons Learned
The UBS action highlights three forms of evidence firms relying on automated surveillance should be able to produce: which transactions entered the system, how the system treated them and whether resulting cases reached investigation and reporting within the required time.
Bill St. Louis, FINRA’s head of enforcement, said member firms were responsible for designing and implementing AML programmes “tailored to their business model and capable of reasonably monitoring transactions for potentially suspicious activity.”
That requires end-to-end reconciliation, ownership of data fields and mappings, and regression testing after migrations or labelling changes. Known exclusions and data-quality problems need formal approval, time limits and escalation. Customer-risk attributes must also reach the monitoring system accurately and on time.
Subscribe to our newsletter


