The Commodity Futures Trading Commission has ordered UBS Financial Services Inc. to pay an $8 million civil penalty after finding that weaknesses in the broker-dealer’s anti-money laundering controls left thousands of foreign-currency wire transfers inadequately monitored or outside its transaction-monitoring process.
The settlement concerns UBS Financial Services, a registered futures commission merchant, rather than every UBS entity. It covers control failures from January 2019 through June 2023. The CFTC said deficiencies in system configuration and data governance affected wires sent or received through retail customer commodity accounts.
The order does not establish that every affected transfer was illicit. It shows a more fundamental control problem: UBS could not consistently subject the relevant activity to the surveillance designed to identify suspicious patterns. For payments and compliance teams, that distinction matters. Transaction monitoring is not effective merely because a tool is running; the data entering it must be complete, correctly labeled and tested against the activity the institution actually processes.
Manual monitoring missed the risk
According to the CFTC, UBS used a manually generated report during part of the period that failed to capture all relevant foreign-currency wires and was not designed to identify suspicious patterns across those transactions.
FINRA, in a related action announced the same day, provided additional detail. It said the legacy process involved a quarterly manual review of a report containing thousands of foreign-currency wires. The report did not reasonably support detection of suspicious or unusual patterns and often lacked material information about the geographic locations involved.
The failure was not confined to a small number of edge cases. FINRA said UBS failed to reasonably monitor more than 60,000 foreign-currency wires totaling more than $10 billion between January 2019 and June 2023. The activity included wires involving high-risk locations, unusually large amounts, excessive transfers, transactions with no apparent business purpose and accounts for which similar activity had previously prompted suspicious activity reports.
Those figures describe activity that should have been monitored; they are not a finding that $10 billion was laundered. FINRA fined UBS Financial Services $20 million in its separate settlement. The firm accepted FINRA’s findings without admitting or denying them.
Automation did not solve the data problem
UBS moved to an automated monitoring system in 2021, but the change did not close the control gap. The CFTC said the firm failed to configure properly the data flowing into the new system, weakening the effectiveness of suspicious-activity monitoring.
FINRA said an incomplete data file and a labeling change caused the automated tool to omit a significant share of the firm’s activity. That included about 33% of foreign-currency wires in retail accounts approved for foreign-currency spot activity.
This is a recurring implementation risk for financial institutions replacing manual controls with automated platforms. A new rules engine or monitoring vendor cannot compensate for missing source records, changed field labels or incomplete mappings. Effective migration requires reconciliations between source systems and the monitoring platform, exception reporting, volume comparisons and testing that proves all in-scope transaction types are being ingested.
Regulators emphasized repeat failures
The CFTC said UBS knew about vulnerabilities because they had been addressed in prior proceedings by other government agencies and a self-regulatory organization. FINRA said it had fined UBS Financial Services $4.5 million in December 2018 over failures to monitor foreign-currency wires, and that the firm continued using the legacy process involved in that settlement until January 2021.
FINRA also found weaknesses in customer due diligence for certain retail customers. According to the regulator, UBS did not promptly identify and investigate factors including links to higher-risk jurisdictions, unexplained changes in domicile and employment, adverse media and potential political exposure. FINRA said some customers consequently retained lower risk ratings and received less scrutiny.
The CFTC ordered UBS to cease and desist from further violations and said it recognized the firm’s representations about remediation. FinCEN, the Securities and Exchange Commission and FINRA announced related actions on August 3, underscoring how one control breakdown can create overlapping exposure across Bank Secrecy Act, securities and derivatives supervision regimes.
What compliance teams should take from the case
The practical lesson is not simply to replace spreadsheets or manual reports. Institutions need evidence that their monitoring population is complete before and after any technology change. That means inventorying transaction types, reconciling wire counts and values, validating jurisdiction and customer-risk fields, testing alerts with known scenarios, and escalating unexplained drops in monitored activity.
Responsibility also extends beyond the monitoring team. Product, data engineering, operations and compliance functions must share ownership of schema changes and feed quality. A field-label change that appears technical can become a regulatory failure when it removes transactions from surveillance.
The UBS actions put particular weight on recurrence. When a regulator has already identified a weakness, remediation should be measured against the original failure mode and independently validated. A nominally automated replacement is not remediation if relevant transactions still fail to reach the control.