UBS’s $125 Million Lesson: Why Ignoring a Prior Enforcement Action Is the Costliest Compliance Mistake

FinCEN’s $125 million penalty against UBS is notable for more than its size, though it is the largest fine ever imposed on a broker-dealer under the Bank Secrecy Act. What makes this case a critical study for compliance officers is that it is a recidivism case. UBS was fined for Bank Secrecy Act violations in 2018, and according to FinCEN’s August 3 announcement, the bank never actually fixed the underlying problem. It simply kept operating with the same gap for years afterward, until it grew large enough to become a $125 million admission of willful misconduct.

A Second Fine for the Same Unresolved Problem

FinCEN’s order describes a bank that had already been told exactly where its controls were weak and chose not to close the gap. Following its 2018 enforcement action, UBS was expected to strengthen its monitoring of foreign currency wire transfers. According to FinCEN, it did not. That unaddressed monitoring gap allowed more than $10 billion in transactions to move through the bank without adequate scrutiny in the years that followed.

FinCEN Director Andrea Gacki did not mince words about what this pattern means for how the agency will treat repeat offenders going forward, framing the action as a message that institutions who fail to correct known deficiencies, particularly when that failure exposes the financial system to high-risk customers and activity, will face significantly harsher consequences the second time around. That is the central lesson of this case: a known, previously cited control weakness that goes unremediated does not stay a static risk. It compounds, and by the time it resurfaces in a subsequent examination, regulators treat it not as an oversight but as a willful choice.

High-Risk Customers, Ignored Internal Warnings

The wire transfer monitoring gap was not the only failure FinCEN identified. The agency also found that UBS failed to conduct adequate due diligence on high-risk customers connected to Russia and Latin America, two geographies that have long sat at the center of global money laundering and sanctions risk. What makes this part of the order particularly damaging is that the warning did not have to come from an external examiner. According to FinCEN, one of UBS’s own affiliate businesses had already raised internal concerns about negative reporting tied to these customers, specifically flagging worries about the legitimacy of their sources of wealth and their potential ties to corruption, fraud, and money laundering.

That detail should stop every compliance officer reading this case in their tracks. This was not a situation where the risk was invisible until a regulator found it. The bank’s own internal apparatus surfaced the concern, and the concern did not translate into the kind of enhanced due diligence or account-level action that should have followed. A red flag raised internally and not acted upon is, from an enforcement perspective, functionally equivalent to no controls existing at all, and in some respects it is worse, because it establishes that the institution had actual notice of the risk.

Admission and Remediation

UBS admitted that it willfully violated the Bank Secrecy Act, a significant concession that removes any ambiguity about whether the conduct was negligent or something more serious. As part of its remediation, the bank is now working with an independent third party to conduct a retrospective review of past transactions, identifying which ones should have generated suspicious activity reports that were never filed. This look-back and delayed-filing process has become a familiar remediation pattern across recent Bank Secrecy Act enforcement actions, and it reflects a consistent expectation from regulators: once a monitoring gap is identified, the institution’s obligation extends backward, not just forward. Fixing the system prospectively is not sufficient if the historical gap in reporting was never closed.

Part of a Broader Global Push

This action lands within a wider international trend of regulators tightening scrutiny of how money moves through the financial system, regardless of an institution’s jurisdiction or reputation. In the UK, the Financial Conduct Authority has been pressing asset managers and alternative investment firms with detailed inquiries into their own anti-money laundering processes. And even Switzerland, long associated with a culture of banking secrecy and discretion, is reportedly considering tighter domestic rules in response to mounting international pressure for cooperation on financial crime. The days when a bank’s jurisdiction or brand reputation offered any insulation from aggressive AML enforcement are clearly over.

Compliance Takeaways

A few lessons from this case deserve particular attention from compliance and AML officers at any financial institution.

A prior enforcement action is not the end of the story; it is the beginning of a heightened scrutiny period. Regulators will look specifically at whether the deficiencies cited in an earlier action were actually remediated, and evidence that they were not treated as a genuine priority will be read as willfulness, not oversight, the second time around.

Internal red flags carry independent evidentiary weight. When a firm’s own affiliate, business unit, or compliance function raises a concern about a customer’s source of wealth or potential ties to financial crime, that concern needs a documented resolution. An unaddressed internal warning is one of the most damaging pieces of evidence a regulator can find in an investigation, because it forecloses any argument that the risk was unknown.

High-risk geographic exposure demands proportionate, sustained due diligence, not a one-time onboarding check. Customers connected to jurisdictions with elevated money laundering, corruption, or sanctions risk require monitoring that scales with that risk over the life of the relationship, not just at account opening.

Remediation has to include a genuine look-back, not just a forward-looking fix. Regulators increasingly expect institutions to identify and report the suspicious activity that should have been caught during the period a control was deficient, not simply to correct the control and move on.

Finally, no institution’s size, jurisdiction, or reputation provides durable protection against aggressive enforcement. UBS is one of the most prominent private banking institutions in the world, and Switzerland has long cultivated an image of discretion and stability. Neither insulated the bank from a record-setting penalty once regulators determined that a previously identified weakness had been allowed to persist.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *