A record penalty for recurring failures
On 3 August 2026, the Financial Crimes Enforcement Network (FinCEN) assessed a $125 million civil money penalty against UBS Financial Services Inc. (UBSFS) for willful violations of the Bank Secrecy Act (BSA). FinCEN described UBSFS as a recidivist and said the penalty was the largest it had imposed on a broker-dealer for BSA violations.
The action followed a 2018 consent order in which FinCEN assessed a $14.5 million penalty and identified weaknesses in UBSFS’s anti-money laundering (AML) programme, including inadequate monitoring of foreign-currency wires. Before that order, UBSFS represented that a new automated monitoring system was expected to address the deficiencies by mid-2019.
According to the 2026 order, deployment did not occur until March 2021, and weaknesses in planning, data, testing and implementation allowed monitoring failures to persist into 2023. FinCEN found that more than 61,500 foreign-currency wires, with an aggregate value exceeding $10.5 billion, were not appropriately monitored. It also identified customer due-diligence failures involving certain high-risk customers and failures to file hundreds of suspicious activity reports on time.
THE CENTRAL QUESTION: How can an institution know that a material deficiency exists, commit to remediate it, invest in a replacement system—and still fail to achieve the required outcome?
FinCEN’s order does not assess UBSFS’s regulatory change management framework, and the public record does not establish the absence of such a framework as the legal cause of the violations. The facts do, however, expose governance breakdowns that a mature regulatory change management process is specifically designed to help prevent.
The deeper lesson: knowing is not implementing
Regulatory obligations become effective only when they are converted into changes in policies, processes, controls, data, technology, training and oversight. The UBSFS order illustrates the distance that can open between recognizing a requirement and proving that it works in practice.
The obligation was known, but the response was not completed on time.
The 2018 order identified deficiencies in monitoring foreign-currency wires, and UBSFS represented that automation would remediate them. Yet the new system was deployed materially later than expected. A mature change process treats such a commitment as a governed obligation with milestones, owners, dependencies, escalation thresholds and evidence—not as a general intention attached to a technology project.
Interim controls remained in place without sufficient challenge.
For commodities accounts, UBSFS relied on a manual report that FinCEN described as flawed in design and execution. The process required personnel to query multiple systems, copy and clean data manually and review reports too infrequently. Known limitations in an interim control should trigger recurring risk acceptance, heightened oversight and a defined expiry date—not quiet normalisation.
System deployment was mistaken for control effectiveness.
The eventual implementation of an automated monitoring system did not resolve the problem. FinCEN attributed continued gaps partly to flawed planning and testing. This distinction matters: a system can be delivered on schedule and still fail the regulatory obligation if data feeds are incomplete, scenarios do not cover the relevant risk, or testing does not trace results back to the original requirement.
Signals were identified but did not consistently produce enterprise action.
The order describes coding issues, incomplete data, alerts involving transactions outside the assumed scope and concerns raised within the organisation. A robust governance process should aggregate such signals, assess whether they invalidate prior conclusions and escalate them to people with authority to act across business, compliance, technology and operations.
Closure was not anchored to demonstrated readiness.
Remediation should not close because tasks are marked complete or a new system has gone live. Closure should require evidence that affected obligations have been implemented across the full population, material limitations have been resolved or accepted at the proper level, and independent challenge has tested whether the intended regulatory outcome is being achieved.
THE GOVERNANCE GAP: The recurring theme is not a lack of awareness. It is the failure to maintain an unbroken line from regulatory expectation to implementation, verification, escalation and sustainable closure.
How robust regulatory change management could have helped
Regulatory change management is often treated as a monitoring function: identify a new rule, circulate an alert and record that it was reviewed. That is only the beginning. For material findings, consent orders and supervisory commitments, the same discipline should govern the entire response lifecycle.
01 Translate findings into a controlled obligation register
Each requirement and commitment should be recorded at a level that can be assigned, assessed and tested. The register should connect the 2018 findings to affected products, account types, transactions, systems, data fields, policies and control owners. This would reduce the risk that remediation addresses one part of the problem while leaving adjacent populations outside scope.
02 Perform an enterprise impact and gap assessment
The assessment should examine not only what needs to change, but also how long remediation will take and what protects the institution in the meantime. Manual reports, incomplete data, delayed technology, and account populations without compensating controls should be visible as active gaps with explicit risk treatment.
03 Convert gaps into accountable action plans
Every gap should cascade into actions with an accountable owner, collaborators, milestones, dependencies, due dates and escalation rules. A commitment to implement a new monitoring system is not one action; it is a program of data mapping, scenario design, configuration, testing, deployment, back-testing, documentation, training and validation.
04 Test implementation against the original obligation
Readiness validation should ask whether all required transactions and customer populations are captured, whether data is complete and accurate, whether scenarios address identified risks, and whether exceptions generate timely investigation and reporting. Testing should be performed by people sufficiently independent from delivery and should include credible challenge of management’s closure evidence.
05 Maintain oversight after go-live
Regulatory change does not end at implementation. Dashboards should keep overdue actions, unresolved limitations, missed milestones and residual risks visible to senior management. Material deviations from regulatory commitments should prompt escalation, reassessment and—where appropriate—timely engagement with regulators.
A CRITICAL DISTINCTION: Technology can support this discipline, but technology is not the discipline. Effective regulatory change management depends on governance, accountable decision-making and an institutional willingness to surface bad news early.
Questions compliance leaders should ask now
The UBSFS action provides a useful stress test for any regulated institution. Boards, executives and compliance leaders should ask:
Can we trace every material regulatory finding and commitment to specific obligations, impacted areas, controls and accountable owners?
When remediation is delayed, who is notified, who accepts the interim risk and what compensating controls are required?
Do implementation plans cover data, technology, policy, process, training and operational adoption—or only the most visible workstream?
Who independently verifies that a new control covers the complete population and achieves the intended regulatory outcome?
What evidence must exist before remediation can be approved for closure?
Can senior management see recurring issues, missed milestones, unresolved limitations and related findings across the enterprise?
Are employees empowered and required to escalate evidence that prior assumptions, testing or closure decisions may be wrong?
Would we know when a regulatory commitment is technically “complete” but operationally ineffective?
From regulatory response to regulatory resilience
The most consequential part of the UBSFS action is not the size of the penalty. It is the allegation that known deficiencies persisted after a prior enforcement action and stated remediation commitments. That is the point at which a control weakness becomes a governance failure.
A robust regulatory change management program cannot guarantee that violations will never occur, and it does not replace an effective AML program, sound data governance or strong compliance culture. What it can do is create the connective tissue between regulatory expectations and operational reality: clear obligations, structured impact assessment, accountable action, independent challenge, transparent escalation and evidence-based closure.
For compliance leaders, the lesson is straightforward. Regulatory findings do not become less risky with time. If the organisation cannot demonstrate that an obligation has been implemented, tested and sustained, remediation is not finished—regardless of how many tasks have been closed.
This article provides general information and does not constitute legal or regulatory advice.
