The Institution That Already Knew
When a Regulatory Finding Survives the Remediation Designed to Eliminate It

Calvert Steele Jr., CAMS
11 min
Somewhere inside UBS, the notification arrives.
Perhaps it appears first on a legal monitor, an executive’s phone, or the screen of a compliance professional who already understands what the numbers will mean. The document opens. The institution’s name sits near the top. Beneath it is a figure large enough to travel quickly across financial newsrooms:
$125 million.
For a few moments, the office may remain exactly as it was. Calls continue. Screens glow. Meetings remain on calendars. The institution does not physically change when an enforcement action becomes public.
But the story inside the document is not new.
Foreign-currency wires. High-risk customers. Incomplete monitoring. Suspicious activity reporting. Weaknesses involving risks the institution had already been required to confront.
Someone reading the order may remember December 2018.
That was when regulators imposed a $14.5 million penalty and described failures involving many of the same areas. UBS announced investments, expanded staffing, upgraded systems, strengthened oversight, and began the work institutions call remediation.
Then January 2019 arrived.
According to the latest regulatory action, the period behind the new violations began the following month.
Not years after the original warning had faded into institutional memory. Not after an entirely new threat emerged. One month later, while the first penalty was still recent enough to remain in inboxes, meeting materials, remediation plans, and conversations across the control environment.
The institution did not need another warning to know where the weakness lived.
It had already paid to be told.
A first failure may expose a weakness. A repeated failure reveals what the institution learned to tolerate.
— Risk Ready Intelligence
The Finding Was Already Specific
Regulatory findings do not always provide institutions with perfect answers. Some identify broad governance weaknesses that require significant internal investigation before the true cause becomes visible.
The 2018 action was not that vague.
It identified insufficient resources, alert backlogs, delayed suspicious activity reporting, shell-company indicators, banking-like activity moving through brokerage accounts, and foreign-currency wires that were not being monitored with enough information to assess geography and politically exposed person risk. The finding did not merely say the AML program needed improvement. It described where the architecture was failing.
The 2026 action returned to disturbingly familiar territory.
Regulators said UBS failed to appropriately monitor more than 60,000 foreign-currency wires totaling over $10 billion. They also identified due-diligence deficiencies involving high-risk customers connected to Russia and Latin America. The settlement requires an independent consultant to review the AML program, with attention directed toward risks involving cartels, narcotics trafficking, the Southwest border, Iran, Russia, and Venezuela.
This is what separates a repeat finding from an unrelated control failure.
The institution was not encountering an entirely new threat produced by an unforeseeable change in criminal behavior. It was again confronting risk in areas regulators had already told it to examine: foreign-currency movement, high-risk customers, incomplete monitoring, suspicious activity reporting, and the consequences of providing banking-like services through a broker-dealer environment.
The weakness had not returned from somewhere outside the institution.
It had survived inside it.

Remediation Activity Is Not Remediation Effectiveness
Institutions know how to demonstrate activity.
They establish remediation offices. They assign issue owners, hire consultants, revise procedures, develop training, install new systems, form committees, update dashboards, and produce evidence showing that action items have been completed. Each step may be necessary. None of them, standing alone, proves that the underlying risk has been eliminated.
A system can be upgraded while incomplete data continues flowing into it. Training can be delivered while the incentives shaping daily decisions remain unchanged. Oversight can be expanded while ownership remains distributed across teams that never see the full customer relationship. An issue can be marked closed because required tasks were performed even though the original vulnerability remains operationally possible.
That is the distinction between remediation activity and remediation effectiveness.
Activity asks whether the institution completed the work it promised to complete.
Effectiveness asks whether the institution can still produce the same failure.
The second question is harder because it cannot be answered by documentation alone. It requires sustained testing under real conditions. It requires an institution to examine whether customer risk ratings are changing when circumstances change, whether monitoring systems receive complete information, whether alerts are generated as designed, whether investigators possess the context necessary to make sound decisions, and whether governance responds when results contradict the remediation narrative.
Remediation is not proven by what the institution completed. It is proven by what the institution can no longer repeat.
— Risk Ready Intelligence
The reported UBS timeline makes this distinction unavoidable. The fact that the subsequent violation period began in January 2019 does not prove that every remediation measure had already been implemented by that date or that every later failure occurred immediately. It does establish that the period of exposure began directly after the original enforcement action and continued for more than four years.
There was no meaningful period in which the institution could plausibly claim it had forgotten the original warning.
The warning was still fresh.
When Wealth Begins to Reassure the Control
UBS Financial Services operates in an environment where wealth itself can influence perception.
FinCEN reportedly observed that the firm sought wealthy and ultra-high-net-worth customers, including people who lived in or derived wealth from jurisdictions carrying heightened illicit-finance risk. Wealth does not establish criminality. A connection to a high-risk jurisdiction does not establish wrongdoing. Adverse media is not proof, and proximity to political power does not automatically make every customer illicit.
Those factors do, however, increase the burden of understanding.
Reporting on the new action described a Russian oligarch with close ties to Vladimir Putin who allegedly opened and maintained UBS accounts despite public reporting questioning the origins of his wealth and linking him to possible money laundering and a company invested in Iranian digital assets. Regulators also cited broader due-diligence deficiencies involving high-risk relationships connected to Russia and Latin America.
The institutional danger appears when characteristics that should produce greater scrutiny begin producing greater comfort.
A large relationship can feel too established to be questioned. Significant assets can make a customer appear institutionally important. Prior acceptance by an affiliate can be interpreted as evidence that someone else has already completed the difficult work. The absence of an arrest or conviction can quietly become a substitute for understanding source of wealth, source of funds, beneficial ownership, political exposure, close-associate risk, and the purpose of activity.
That is not risk-based decision-making.
It is reassurance built from status.
Financial crime controls are not designed to determine whether a customer appears respectable enough to retain. They are designed to determine whether the institution understands the relationship well enough to carry its risk responsibly.
The more complicated the wealth, the more politically connected the network, and the more opaque the movement of funds, the less an institution can afford to let familiarity perform the work of verification.
The Spreadsheet Is Never Just a Spreadsheet
The Financial Times reported that UBS relied on a complex monitoring process that included an Excel spreadsheet and that errors in the process contributed to hundreds of alerts being missed.
The immediate lesson may appear technological: spreadsheets are fragile, manual processes create operational risk, and complex monitoring should not depend on tools unable to carry the scale of the environment.
But technology is only the visible layer.
A spreadsheet becomes institutionally dangerous when too much responsibility has been placed inside it without sufficient challenge. Someone designed the process. Someone accepted its limitations. Someone determined how exceptions would be identified. Someone reviewed the results, received management information, assessed the remaining risk, and decided whether the process was functioning well enough to continue.
The spreadsheet did not decide that its own errors were tolerable.
The institution did.
This is why technological remediation often falls short when it is separated from governance. Replacing a tool may correct a technical defect, but it does not automatically correct the decision architecture that allowed the defect to persist. The same institution can purchase better technology while preserving fragmented ownership, weak challenge, incomplete data, poorly calibrated scenarios, or incentives that reward closure more than accuracy.
Control failures are rarely contained inside the tool where they become visible.
They travel through the people, assumptions, handoffs, and governance decisions surrounding it.

The Danger of Closing the Finding
Every remediation program eventually approaches a moment of closure.
Evidence has been collected. Testing has been completed. Senior committees have received updates. The issue is presented as sufficiently addressed, and the institution is ready to move forward.
Closure carries psychological weight. Once a finding has been closed, future concerns are no longer assessed against an open weakness. They are assessed against the belief that the weakness was already corrected.
That changes how new information is interpreted.
An anomaly may be treated as an isolated exception because the broader system was recently approved. A control failure may be framed as an implementation issue rather than evidence that the original diagnosis was incomplete. Professionals may hesitate to reopen a finding that required significant investment and executive attention to close. The institution becomes invested not only in the control, but in the story that the control now works.
This is how remediation can become defensive.
Instead of asking whether the system is producing reliable outcomes, the organization begins protecting the conclusion that the system has been fixed.
Repeated enforcement actions expose the cost of that posture. They demonstrate that a finding was managed administratively without being eliminated structurally. Policies existed. Oversight existed. Remediation artifacts existed. Yet the risk retained enough space to continue.
The institution survived the first penalty.
Survival may have been mistaken for recovery.
Independent Review Cannot Replace Internal Ownership
The new settlement requires UBS Financial Services to retain an outside consultant to review its AML program and focus on priority illicit-finance risks. Independent review can introduce necessary challenge, especially when an institution’s own confidence has become part of the problem.
But independence cannot become another layer of distance.
A consultant can test systems, identify gaps, review governance, and recommend redesign. A consultant cannot permanently own the institution’s judgment. Once the reports are delivered and the engagements end, someone inside the organization must remain accountable for whether the architecture continues to work.
That responsibility cannot be diffused across project teams.
Strong remediation must operate across three connected levels. The technical level must establish that data is complete, monitoring logic is appropriate, and defects are detected before they create silent gaps. The operational level must establish that investigators have sufficient time, context, training, and authority to act on what the systems produce. The governance level must establish that leaders receive information capable of revealing weakness rather than dashboards designed primarily to demonstrate progress.
Most importantly, the institution must preserve the original finding as active memory.
The lesson cannot remain trapped inside an enforcement order, a closed project folder, or the recollections of employees who may eventually leave. It must continue shaping customer acceptance, monitoring design, quality assurance, escalation, audit, and executive challenge long after the public attention disappears.
A regulatory action should not become something the institution once experienced.
It should become something the institution is structurally incapable of forgetting.
When Knowledge Never Becomes Architecture
On December 17, 2018, UBS Financial Services was not handed a mystery.
The institution was told that its AML program had failed to address the risks created when brokerage accounts began functioning like bank accounts. It was told that staffing was insufficient, alerts had accumulated, suspicious activity reporting had been delayed, and foreign-currency monitoring lacked information necessary to recognize jurisdictional and politically exposed person risk. Regulators also acknowledged the investments UBS said it had made to correct those weaknesses.
Then January 2019 arrived.
Years later, another regulatory action returned to many of the same rooms: foreign-currency wires, high-risk customers, monitoring weaknesses, due diligence, and suspicious activity reporting.
The question now is not whether UBS can begin another remediation program. It undoubtedly can. The question is whether the institution can redesign itself deeply enough that the next warning does not resemble the last one.
A first enforcement action identifies what failed.
A second asks whether the institution ever truly changed.
Because when the same weakness survives the systems, investments, training, oversight, and assurances designed to eliminate it, the failure is no longer a lack of awareness.
It is knowledge that never became architecture.

Calvert Steele Jr., CAMS
Founder, Risk Ready
Financial crime and institutional risk professional focused on governance, judgment, and emerging threat environments.
Learn moreSources
- •FinCEN — Financial Crimes Enforcement Network. Although multiple agencies announced coordinated penalties, FinCEN assessed the record $125 million civil money penalty against UBS Financial Services and credited the SEC, FINRA, and CFTC penalties against its assessment as part of the coordinated resolution.
- •U.S. Securities and Exchange Commission (SEC) — Press Releases
- •Financial Industry Regulatory Authority (FINRA) — News Releases
- •Commodity Futures Trading Commission (CFTC) — Press Releases
- •Reuters — Legal & Regulatory
- •Financial Times
Related Briefings
When Small Bribes Open Large Doors
Sometimes the threat is not on the other side of the transaction. It is closer than anyone wants to admit. A recent TD Bank insider case shows how little money may be required to bend the right access point inside a financial institution.
AMLWhy Institutions Miss Signals Before Enforcement
The warning signs were visible. The escalation pathways existed. Yet the organization failed to act until external pressure forced recognition. This pattern repeats across sectors.