About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

UBS AML Enforcement Exposes Underlying Data Weaknesses

Subscribe to our newsletter

A coordinated US enforcement action against UBS Financial Services has exposed how incomplete data feeds, faulty system configuration and weak customer-risk controls can undermine an automated anti-money laundering (AML) programme.

FINRA found that UBS failed to monitor adequately more than 60,000 foreign-currency wires worth over $10 billion between January 2019 and June 2023. The deficiencies continued after the firm replaced a manual review process with automated monitoring.

The Financial Crimes Enforcement Network (FinCEN), the Financial Industry Regulatory Authority (FINRA), the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) addressed the failures through separate but coordinated actions. Transaction-monitoring software can assess only the activity and risk classifications supplied to it, a dependency reflected across the four actions.

Four Regulators, Connected Control Failures

FinCEN imposed a $125 million civil penalty, which it described as the largest penalty imposed against a broker-dealer for Bank Secrecy Act violations. It treated UBS as a repeat offender and required the firm to complete a third-party transaction lookback and submit its AML programme to independent review. FinCEN may waive up to $15 million for expenses associated with the undertaking if UBS satisfactorily completes the independent review and implements the third party’s recommendations.

The SEC imposed a further $20 million penalty after finding that UBS wilfully violated Exchange Act requirements governing broker-dealer compliance with the Bank Secrecy Act. The regulator also found that suspicious activity reports (SARs) arising from the subsequent lookback were filed late and covered thousands of transactions worth approximately $250 million. 

FINRA imposed a $20 million fine for failures in AML monitoring and customer due diligence. The CFTC imposed an $8 million penalty for failures to supervise the configuration and operation of systems monitoring foreign-currency wires.

Each regulator examined the breakdown through a different legal mandate. Together, the actions show how connected AML failures can engage broker-dealer, futures and Bank Secrecy Act requirements at the same time.

Automation Inherited Data Gaps

UBS initially monitored foreign-currency wires through a manually generated quarterly report containing thousands of transactions. Regulators found that the report was poorly suited to identifying suspicious patterns and omitted relevant geographic information.

The firm introduced an automated monitoring system in 2021. The new platform did not resolve the problem because it received an incomplete data file and was affected by a change in how transaction data was labelled. FINRA said about 33% of foreign-currency wires in retail customer accounts approved to engage in foreign-currency spot activity were omitted from monitoring.

The sequence illustrates a control-migration risk. Installing a new analytical engine does not prove that the source population is complete. Firms must reconcile transactions from the originating systems through each transformation and into the monitoring platform. They also need to test field mappings, classification rules and exclusions after configuration changes.

A monitoring system may process every record it receives correctly while still missing material activity. Without an independent control that compares the source population with the monitored population, compliance teams may have no clear view of what has dropped out.

Customer Risk and Transaction Data Diverged

The findings extended beyond transaction ingestion. Regulators also identified weaknesses in the customer due-diligence process, including the treatment of connections to higher-risk jurisdictions such as Russia, unexplained changes in domicile or employment, adverse media and potential political exposure.

Some customers retained risk ratings that generated less scrutiny than their circumstances warranted. That weakened the monitoring process even where transaction data reached the system.

Customer-risk data determines how firms classify activity, set alert thresholds and decide which behaviour needs review. Stale or inaccurate profiles can therefore reduce the sensitivity of transaction-monitoring scenarios. Effective AML surveillance requires customer and transaction data to operate within the same control framework.

Remediation Needs Its Own Controls

The repeat-offender finding shifts attention to UBS’s remediation. UBS had already faced regulatory action over its monitoring of foreign-currency wires in 2018. Related weaknesses continued for several years, and the later system deployment did not correct the affected data flow.

Remediation programmes need defined ownership, measurable completion criteria and testing independent of the implementation team. Closing a project or deploying a system does not establish that the original risk has been removed. Firms need evidence that previously omitted transactions have been identified, reviewed and reported where required.

Lessons Learned

The UBS action highlights three forms of evidence firms relying on automated surveillance should be able to produce: which transactions entered the system, how the system treated them and whether resulting cases reached investigation and reporting within the required time.

Bill St. Louis, FINRA’s head of enforcement, said member firms were responsible for designing and implementing AML programmes “tailored to their business model and capable of reasonably monitoring transactions for potentially suspicious activity.”

That requires end-to-end reconciliation, ownership of data fields and mappings, and regression testing after migrations or labelling changes. Known exclusions and data-quality problems need formal approval, time limits and escalation. Customer-risk attributes must also reach the monitoring system accurately and on time.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Post-Trade Transformation: Automating Clearing & Settlement

Date: 1 December 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes The UK, EU and Swiss markets move to T+1 settlement on 11 October 2027, but the first binding compression arrives almost a year earlier. ESMA’s amended settlement discipline RTS expects allocation and confirmation completed by 23:00 CET on trade...

BLOG

FCA Misconduct Rules Put Surveillance Evidence and HR–Compliance Workflows to the Test

The Financial Conduct Authority’s expanded non-financial misconduct rules took effect on 1 September, bringing around 37,000 non-bank firms within a broader conduct regime. Firms now need to show how complaints, communications evidence and employment investigations inform regulatory decisions. New rule COCON 1.1.7FR covers serious work-related bullying, harassment and violence towards colleagues. It brings non-bank firms...

EVENT

AI in Capital Markets Summit London

Now in its 3rd year, the AI in Capital Markets Summit returns with a focus on the practicalities of onboarding AI enterprise wide for business value creation. Whilst AI offers huge potential to revolutionise capital markets operations many are struggling to move beyond pilot phase to generate substantial value from AI.

GUIDE

Regulatory Data Handbook 2026 – Fourteenth Edition

Welcome to the fourteenth edition of A-Team Group’s Regulatory Data Handbook. Supervisors increasingly expect firms to demonstrate which rules apply, which data supports each obligation, who owns the control and how exceptions are identified and resolved. Policies and implementation programmes must now be supported by records that can withstand regulatory scrutiny. This edition examines material...