UBS has been hit with a $125 million fine by the US Financial Crimes Enforcement Network (FinCEN) for what regulators described as willful violations of the Bank Secrecy Act. It is the largest civil penalty ever imposed on a broker-dealer for violations of the US’s AML law.
But the size of the fine is not as significant as why UBS was fined.
The case involves high-risk customers, inadequate source-of-wealth investigations, hundreds of suspicious transactions that were not reported in a timely manner, more than 60,000 foreign-currency wires worth over $10 billion that were not appropriately monitored, and, critically, weaknesses that UBS had already promised regulators it would fix.
This is a story about what happens when AML controls exist but fail to operate effectively.
A repeat offender, a broken promise
UBS had already been fined $14.5 million by FinCEN in 2018 for deficiencies in its AML programme, including inadequate monitoring of foreign-currency wires.
At the time, UBS committed to upgrading its automated AML surveillance system. But that did not happen as promised.
The replacement system was delayed until March 2021, nearly two years after the commitment. Worse, FinCEN concluded that the new system was still inadequate.
Between January 2019 and June 2023, UBS failed to appropriately monitor more than 50,000 foreign-currency wires worth approximately $10.5 billion, with other regulatory findings putting the total at more than 60,000 transactions.
A remediation plan does not protect a business if the underlying problem remains. And a second failure following a previous enforcement action can dramatically change the regulatory response.
FinCEN Director Andrea Gacki described the action as a warning that repeat violations will result in severe repercussions.
The source of wealth problem
Perhaps the most important part of the UBS case concerns customer due diligence.
FinCEN found that UBS failed to appropriately assess and mitigate money laundering and illicit finance risks associated with high-risk customers, particularly customers with ties to Russia and Latin America.
The issue was not simply whether these customers had money. It was whether UBS adequately understood where that money came from. That distinction is fundamental to effective AML compliance.
A wealthy customer can provide bank statements, corporate records, property documents and other evidence demonstrating that they possess substantial assets. But that does not necessarily establish how the wealth was originally accumulated.
For high-risk customers, firms need to understand the underlying story of the wealth and then they can determine whether criminal proceeds enter the legitimate financial system.
Thousands of negative news hits but not enough investigation
The case involving one Russian oligarch illustrates the problem particularly clearly.
According to FinCEN, the customer had close ties to Russian President Vladimir Putin and had been the subject of extensive negative media coverage questioning the origins of his wealth and alleging possible money laundering.
At onboarding, UBS’s negative-news screening reportedly generated thousands of hits across more than 300 articles. A subsequent periodic KYC review generated more than 150 articles. But UBS reviewed only the first 25.
FinCEN concluded that the firm failed to adequately explain or justify how it dealt with the negative news it had identified. That is a crucial distinction because screening is not investigation.
A screening system can produce an alert. It cannot, by itself, determine whether the information is relevant, credible or material to the customer’s risk.
The compliance obligation does not end when the software produces a result. Someone has to assess the result. Someone has to determine whether it changes the customer’s risk profile. And where the information raises genuine concerns, someone needs to decide what action is required.
The UBS findings become even more striking because FinCEN identified a case where one of UBS’s own affiliates had raised concerns about allegations involving a customer. Yet those concerns were not adequately acted upon.
This raises a broader governance issue for multinational organisations. Information about a customer can exist in different parts of a group. One business may identify a risk that another part of the organisation does not fully appreciate.
Effective AML governance requires more than having separate compliance teams operating within separate entities. Firms need mechanisms to ensure that material risk information travels across the organisation and is acted upon.
The sanctions warning hidden inside the UBS case
Although the FinCEN action is an AML enforcement case, there is also a significant sanctions compliance lesson. The UBS customer at the centre of some of the findings was reported to have links to a company actively invested in Iranian digital assets.
That matters because AML and sanctions risks frequently overlap. A customer who presents heightened money laundering risk may also present sanctions risk because of their connections to sanctioned jurisdictions, individuals, companies or sectors.
This is particularly important when dealing with Russian and Iranian exposure. A sanctions programme cannot operate entirely separately from customer due diligence.
Understanding ownership, control, source of wealth, business activities, counterparties and geographic exposure can provide critical information for sanctions risk assessment.
A customer who does not generate a direct sanctions screening match can still present a meaningful sanctions risk if the underlying ownership or transaction structure has not been properly understood.
The $60m warning
The UBS case also demonstrates why restrictions imposed on high-risk accounts need to be monitored in practice. FinCEN found that UBS had placed restrictions on several accounts belonging to the Russian customer, including limits on third-party wires and enhanced monitoring.
Yet approximately $60 million in outgoing wires from one account were third-party payments that appeared to violate those restrictions. This is an important distinction between designing a control and operating a control.
It is one thing to document that a high-risk customer is subject to enhanced monitoring. It is another to demonstrate that transactions were actually monitored and that breaches of restrictions triggered appropriate intervention.
FinCEN also found that UBS failed to file hundreds of suspicious activity reports in a timely manner. SARs provide law enforcement with information that can help connect apparently unrelated transactions, customers and networks. When reports are delayed or not filed, investigators can lose access to information at the point when it may be most useful.
For businesses, this reinforces the importance of having a clear escalation process. Front-line employees need to know what constitutes a concern, where to report it and what happens next. Compliance teams need sufficient information and authority to investigate. And the organisation needs to be able to demonstrate why a particular decision was made.
What should companies do now?
The UBS case should not be dismissed as a problem unique to a global financial institution. The underlying compliance principles apply much more broadly.
Companies need to be able to demonstrate that their AML controls are risk-based, operational and capable of responding to changing information. That starts with customer due diligence.
Where a customer presents elevated risk, businesses need to go beyond collecting standard identification documents. They need to understand the source of funds and, where appropriate, the source of wealth. They need to investigate information that does not fit the customer’s story and document how significant concerns were resolved.
It also means treating negative media seriously.
A search producing hundreds of articles does not automatically mean a customer is a money launderer. But neither can a firm simply tick a box saying “negative media reviewed” and move on.
The key is demonstrating meaningful assessment and judgment.
The same applies to transaction monitoring. Controls need to be calibrated to the actual risks facing the business, tested regularly and updated when weaknesses are identified.
And when a regulator or internal review identifies a problem, remediation needs to be demonstrably effective.
The UBS case demonstrates how regulators can connect the dots between known weaknesses, ineffective remediation, inadequate customer due diligence, missed suspicious activity and failures to respond to red flags. It’s time to test whether your AML and sanctions controls actually work.
Our AML courses will help you stay protected
Try them here →