Select your language

Blog

Blog description

AML Compliance Failures: KYC, Transaction Monitoring, SAR Reporting, and FinCEN Enforcement

AML Compliance Failures: KYC, Transaction Monitoring, SAR Reporting, and FinCEN Enforcement

An anti-money laundering program may appear comprehensive on paper while failing in practice. An institution may collect identification documents without understanding its customers, install monitoring software without confirming that relevant transactions reach the system, or generate alerts without ensuring timely review. The central question is whether its controls function, not merely whether policies exist.

The Financial Crimes Enforcement Network’s enforcement action against UBS Financial Services Inc. illustrates these risks. On August 3, 2026, FinCEN assessed a $125 million civil monetary penalty for willful Bank Secrecy Act violations involving the firm’s AML program and suspicious activity reporting. The resolution also required a transaction lookback and an independent AML program review.

Customer due diligence, monitoring, reporting, and remediation must operate as an interconnected process. Accurate onboarding information has limited value if investigators cannot access it. Monitoring cannot identify patterns in excluded transactions. Corrective measures cannot resolve deficiencies unless they are implemented and tested.

For compliance officers, executives, and legal departments, the challenge is to connect these functions while distinguishing binding requirements from supervisory guidance, internal practices, and proposed regulatory changes.

Understanding the Applicable AML Obligations

The Bank Secrecy Act does not impose an identical framework on every business that handles money. Requirements depend on regulatory classification, activities, and applicable exemptions. FinCEN’s Customer Due Diligence Rule, for example, applies to specified institutions, including banks, securities broker-dealers, mutual funds, futures commission merchants, and introducing brokers in commodities, not every financial or commercial business.

541

For banks, these include understanding customer relationships, monitoring for suspicious activity, and updating customer information on a risk basis.

“Know Your Customer,” or KYC, is commonly used as an umbrella term, but identity verification, beneficial ownership identification, and ongoing due diligence address different questions. Securities firms must also consider FINRA Rule 2090, which requires reasonable diligence concerning essential customer information and the authority of persons acting for customers.

542

KYC Failures: Documents Are Not a Substitute for Understanding

Identity verification does not, by itself, establish that an institution understands the customer relationship. A valid identification document or incorporation certificate does not explain the purpose of an account or whether subsequent activity is consistent with that purpose. Ongoing due diligence addresses the relationship’s nature, purpose, and risk profile.

A meaningful assessment should connect:

543

The review should reflect actual risk rather than a universal enhanced-documentation checklist.

Source of funds concerns the origin of money involved in a transaction or relationship; source of wealth concerns how the customer accumulated wealth more broadly. Identifying the bank from which funds arrived may explain the transfer route without explaining the underlying economic source. Whether further inquiry is appropriate depends on the circumstances and applicable due diligence obligations.

Consider a hypothetical domestic equipment distributor that begins receiving payments from unrelated overseas entities and rapidly transferring the proceeds to beneficiaries unconnected to its stated business. Its incorporation documents may remain valid, but its original profile no longer explains the activity.

The appropriate response is a risk-based inquiry, not an automatic conclusion that money laundering occurred. Investigators should assess whether the business changed, whether explanations are credible, and whether the facts meet the applicable reporting standard.

Beneficial Ownership: Less Repetition Does Not Eliminate Due Diligence

544

Exclusions and special rules apply, and identity verification should not be confused with a universal requirement to independently prove every ownership representation.

FinCEN’s February 13, 2026, exceptive relief reduced repetitive beneficial ownership identification and verification. Institutions relying on the relief generally conduct these procedures when the customer first opens an account, when facts reasonably call existing information’s reliability into question, and when risk-based ongoing due diligence otherwise requires action. Other applicable AML obligations remain in place.

Eliminating unnecessary recollection does not justify retaining information known to be unreliable. Institutions should ensure that contradictory ownership information and material changes reach the personnel responsible for evaluating whether updates are necessary.

These obligations remain separate from Corporate Transparency Act reporting directly to FinCEN. Treasury’s August 2026 final rule removed BOI reporting requirements for U.S. companies and U.S. persons; it did not eliminate financial institutions’ separate customer due diligence obligations.

The relevant question is therefore not simply whether a company must submit a BOI report, but what information the institution must obtain, maintain, and update about its customer.

Transaction Monitoring Must Reflect the Actual Business

Monitoring should be assessed from the underlying data through the final disposition of an alert. A practical review should determine whether relevant products, accounts, currencies, and payment channels are included; whether data transfers are complete; and whether transactions are associated with the correct customers. Testing should also consider changes introduced by acquisitions, new products, and system migrations. FFIEC guidance includes supporting technology, systems, and processes within risk-based independent testing.

Monitoring criteria must also reflect the institution’s risks. A scenario suitable for one business line may be ineffective for another. Thresholds should not be changed solely to reduce workloads without assessing the consequences for detection. FFIEC guidance calls for management to understand filtering criteria and review their continuing appropriateness.

One useful test is to trace selected transactions through the process: 

545

This can reveal an important distinction: a system may be operational while a particular control remains ineffective.

Outsourcing does not transfer regulatory accountability. Federal banking guidance states that engaging a third party does not remove a bank’s responsibility to comply with applicable requirements. Vendor oversight should therefore examine data access, performance, escalation procedures, and contingency arrangements—not merely the description of services in a contract.

Automation should be judged by the same standard: whether it supports the institution’s compliance responsibilities, not how sophisticated the technology appears.

SAR Reporting: Standards, Deadlines, and Useful Information

Suspicion Does Not Require Proof of a Crime

Suspicious Activity Reports are governed by specific criteria and thresholds. For broker-dealers, reporting generally applies to transactions involving or aggregating at least $5,000 that meet specified suspicious-activity criteria, subject to applicable exceptions. The MSB framework generally uses a $2,000 threshold for covered activity, with special provisions for certain transactions.

A SAR does not require a criminal conviction or conclusive proof of money laundering. Conversely, unusual activity does not automatically require reporting. Investigators must apply the relevant standard to available facts, evaluate customer explanations, and distinguish substantiated information from assumptions.

Filing Deadlines Depend on Initial Detection

For banks, 31 C.F.R. § 1020.320 generally requires filing within 30 calendar days after initially detecting facts that may support a SAR. When no suspect is identified at that point, an additional 30 days may be used to identify one, subject to a 60-day maximum. Situations requiring immediate attention also require prompt law-enforcement notification.

An automated alert does not necessarily start the filing period. Review may be needed to determine whether the activity is suspicious, but that review must occur within a reasonable time. Investigation backlogs are not an unlimited extension of the deadline. Procedures should make case ownership, progress, and relevant deadlines visible.

Narrative Quality Matters

A SAR should explain why the activity is suspicious, not merely reproduce a transaction list. FFIEC guidance emphasizes identifying the parties, activity, timing, location, reasons for concern, and methods involved.

A useful narrative connects expected activity with observed conduct, explains relevant relationships, and separates verified facts from unresolved concerns. For example, it may explain that payments came from entities whose relationship to the customer could not be established and that the available explanation did not resolve the inconsistency. Labels such as “unusual wires” add little without supporting context.

 

Guidance Also Limits Unnecessary Procedures

FinCEN’s October 9, 2025, FAQs clarify that proximity to the currency transaction reporting threshold alone does not require a SAR. They also explain that institutions need not conduct a separate post-SAR review solely to determine whether activity continued, provided appropriately designed risk-based controls identify and report suspicious activity. The historical continuing-activity filing approach is not universally mandatory.

The FAQs further state that the BSA and its implementing regulations do not generally require or expect documentation of nonfiling decisions. Institutions choosing to document them may use a proportionate approach. Internal procedures should distinguish preferred practices from legal requirements and account for any specific applicable rules.

SAR Confidentiality Requires Separate Controls

SARs and information revealing their existence are confidential, subject to authorized exceptions. Banks must retain filed SARs and supporting documentation for five years. These obligations require appropriate controls over access, customer communications, litigation requests, and internal distribution.

Confidentiality does not prohibit all sharing of information about the underlying activity. FinCEN’s September 2025 cross-border guidance distinguishes protected SAR information from underlying facts, transactions, and documents. Such material does not automatically become confidential under the SAR rules merely because it supports a filing, although other restrictions may apply.

Information-sharing procedures should therefore address the: 

  • recipient
  • purpose
  • applicable restrictions, and 
  • whether the communication improperly discloses a SAR. 

This is particularly important for cross-border institutions: access to relevant information is essential, but membership in the same corporate group does not provide unlimited permission to circulate SARs.

Lessons From the UBS Enforcement Action

The UBS action demonstrates why an institution’s response to a known deficiency matters. According to FinCEN, a 2018 resolution had already addressed weaknesses in foreign-currency wire monitoring. Despite assurances of remediation, the firm subsequently failed to appropriately monitor more than 50,000 foreign-currency wires totaling over $10 billion. FinCEN also identified customer due diligence deficiencies and untimely suspicious activity reporting.

The required lookback and independent program review serve different purposes: examining past transactions for missed reporting and evaluating controls intended to prevent recurrence.

546

Adding staff does not necessarily correct inadequate investigation procedures. Closing an audit finding does not establish that a control works.

A defensible closure process should identify the deficiency, explain the correction, specify the testing performed, and record remaining limitations. Reports to regulators should accurately distinguish completed work from measures still being implemented.

How FinCEN Evaluates Enforcement Risk

FinCEN’s published enforcement framework identifies responses ranging from no action and warning letters to civil penalties, remedial commitments, and criminal referrals. Relevant considerations include:

547

An isolated failure addressed promptly presents a different factual record from a recurring problem left unresolved after internal warnings. Nevertheless, remediation and cooperation do not guarantee immunity or a particular penalty reduction.

Civil enforcement must also be distinguished from criminal prosecution. In October 2024, the Department of Justice announced guilty pleas by TD Bank, N.A., and its U.S. holding company involving AML program and related failures. The bank’s conspiracy plea also included money laundering. Those outcomes depended on the specific conduct and charges, not merely the existence of a compliance finding.

An exposure assessment should therefore identify the applicable legal standard, relevant conduct and period, and evidence concerning knowledge or intent. Treating all deficiencies as equivalent can obscure important differences.

Governance and Remediation: From Findings to Verified Corrections

AML compliance requires support beyond the compliance department. FinCEN’s culture-of-compliance advisory emphasizes leadership engagement, sufficient resources, information sharing, independent testing, and protection of compliance decisions from conflicting revenue interests.

A practical response should begin by establishing 

  • what failed and whether the failure remains active. 
  • Relevant customer records, transaction data, alert histories, system configurations, testing results, and communications should be preserved. 
  • The record should distinguish original actions from subsequent corrective work.

Next, the institution should define the affected population and period. A missing payment channel may require a different review from an isolated incomplete customer file. A flawed risk methodology may affect multiple business lines. The scope should follow the identified cause and risk rather than an assumption that every deficiency requires either a comprehensive lookback or no retrospective review.

Current and historical exposure should be addressed separately. Temporary controls may be appropriate while a permanent solution is developed. At the same time, the institution should assess whether past activity requires review for missed reporting.

Management should assign accountable owners, milestones, dependencies, and escalation procedures. A direction to “enhance monitoring” is difficult to verify. A workable plan 

  • identifies the excluded transactions, 
  • explains the repair, 
  • assigns testing responsibility, and 
  • defines closure evidence. 

FFIEC guidance addresses responsibility allocation and management reporting concerning deficiencies and corrective action.

Validation should test results rather than rely on completion statements. Reviewers should possess appropriate expertise and independence, and testing should determine whether the correction addresses the identified risk and whether significant limitations remain.

Regulatory communications should also be coordinated and accurate. Voluntary disclosure and cooperation are relevant enforcement considerations, but discussions about program deficiencies do not replace required transaction reporting.

The objective is a reliable account of what happened, what remains unresolved, and what the institution has actually corrected.

Regulatory Change Requires Careful Implementation

Institutions should not confuse regulatory reform with the immediate removal of existing duties.

In April 2026, FinCEN proposed AML/CFT program changes emphasizing risk-based effectiveness and distinguishing program establishment from implementation. The proposal superseded its earlier 2024 proposal. A notice of proposed rulemaking does not itself create an effective final rule.

A compliance inventory should distinguish binding regulations, effective relief, interpretive guidance, and proposed amendments. The February 2026 CDD relief, October 2025 SAR FAQs, and April 2026 proposal perform different legal functions. Institutions should neither preserve unnecessary procedures under the mistaken belief that they remain mandatory nor discontinue required controls before an applicable change takes effect.

Frequently Asked Questions

1. Which businesses are subject to AML requirements?

Requirements apply to specified financial institutions, including banks, broker-dealers, MSBs, and casinos, among others. Obligations vary by classification and activities. Certain BSA duties also reach nonfinancial businesses, but accepting payments does not automatically require maintaining a bank-style AML program.

2. Can AML violations occur without a customer being convicted of money laundering?

Yes. AML program obligations are independent compliance duties. Failure to maintain required controls, training, testing, or customer due diligence can create regulatory exposure without a customer’s criminal conviction. A compliance violation and participation in money laundering are distinct issues.

3. Is verifying identity enough to satisfy customer due diligence requirements?

No. Due diligence also addresses the relationship’s purpose, expected activity, and risks. Depending on the circumstances, further information about ownership, business operations, counterparties, or sources of funds and wealth may be appropriate. The review should be risk-based.

4. Has FinCEN eliminated beneficial ownership verification?

No. The February 2026 relief reduced repetitive collection and verification. Institutions relying on it generally perform these procedures at the first account opening, when existing information becomes reasonably questionable, and when risk-based ongoing due diligence requires action.

5. What makes transaction monitoring ineffective?

Potential weaknesses include incomplete data, poorly calibrated scenarios, insufficient review capacity, inadequate escalation, and investigators lacking customer information. Evaluation should examine the entire detection and reporting process, not simply alert volumes or closure rates.

6. Does every alert require a SAR?

No. An alert requires evaluation against applicable reporting criteria and thresholds. Unusual activity may have a legitimate explanation. Conversely, reporting does not require conclusive proof of a crime when the regulatory suspicion standard is met.

7. How long does a bank have to file a SAR?

Generally, 30 calendar days after initially detecting facts that may support filing. When no suspect is initially identified, an additional 30 days may be used to identify one, subject to a 60-day maximum. Urgent circumstances also require prompt law-enforcement notification.

8. Must every decision not to file a SAR be documented?

Not as a general BSA requirement. FinCEN’s October 2025 FAQs permit proportionate documentation where institutions choose to maintain it. Institutions should still account for specific applicable rules and their own risk-based procedures.

9. Must another SAR be filed every 90 days?

Not automatically. Institutions may rely on appropriately designed risk-based monitoring rather than a separate post-SAR review. They must nevertheless report newly identified reportable activity within applicable deadlines.

10. Can a bank tell a customer that it filed a SAR?

No. A bank must not notify a customer involved in the reported activity that a SAR was filed. Sharing underlying transaction information may be permissible, but it must not improperly reveal the filing.

11. Does a SAR require freezing or closing an account?

No. A SAR does not automatically require account closure; the decision depends on the institution’s risk-based assessment. OFAC blocking obligations are separate. Where applicable sanctions require blocking, affected property generally cannot be transferred or otherwise dealt in without authorization.

12. Can a bank outsource its AML responsibilities?

It may outsource functions, but not its regulatory accountability. The bank remains responsible for applicable requirements and should oversee the provider’s performance, access to information, escalation arrangements, and corrective measures.

13. Can executives or compliance officers face personal liability?

Potentially. Under 31 U.S.C. § 5321(a)(1), civil liability can extend to directors, officers, partners, and employees who willfully violate covered BSA provisions, regulations, or orders. Liability depends on the person’s conduct and applicable legal standard—not their title alone.

14. What should an institution do after discovering a deficiency?

Determine its cause and scope, assess ongoing exposure, assign corrective measures, and establish evidence for closure. Depending on the findings, retrospective review may be appropriate. Management should track progress and verify that the correction addresses the problem.

15. Can disclosure and remediation prevent penalties?

They may influence the outcome but do not guarantee immunity. FinCEN weighs corrective action, voluntary disclosure, and cooperation alongside the seriousness, duration, systemic nature, and history of violations. Each matter depends on its facts and applicable law.

Conclusion

AML weaknesses become especially consequential when they reinforce one another. Incomplete customer information can undermine monitoring; monitoring gaps can prevent investigation; weak investigation can delay reporting; and inadequate governance can allow known problems to persist.

The appropriate response is not simply more documentation or more alerts. It is a coherent process grounded in the institution’s actual obligations and risks.

Customer due diligence should provide meaningful context. Monitoring should cover relevant activity. SAR decisions should apply the correct standard and communicate concerns clearly. Remediation should address both a failure’s cause and its consequences.

For boards, executives, and compliance leaders, the central question is practical: 

548

A complete policy manual is a starting point, not the measure of an effective AML program.

Select your language