Regulatory Commentary
A New System Is Not a Closed Finding: What Institutions Must Prove Before Calling Remediation Done
By Thomas DiGiovanni, Partner and Founder
August 5, 20266 min read
On August 3, 2026, four authorities penalized the same firm a combined $125 million over a monitoring system that replaced its predecessor and missed roughly a third of the wires it was meant to watch. A new system is not a closed finding. Closure is what someone can prove after the project ships, not the go-live itself.
On August 3, 2026, four authorities acted against the same firm, on the same conduct, on the same day. The Financial Crimes Enforcement Network (FinCEN) assessed a $125 million civil penalty against UBS Financial Services Inc. and called it historic. The Securities and Exchange Commission (SEC) added $20 million for willful violations of Section 17(a) of the Securities Exchange Act of 1934 and Rule 17a-8. The Financial Industry Regulatory Authority (FINRA) added $20 million under its Rule 3310. The Commodity Futures Trading Commission (CFTC) added $8 million for supervision failures in the same systems. The four numbers do not add the way they look. FinCEN's $125 million is the total, and the $48 million going to the other three counts toward it, not on top.
The last $15 million is the part worth pausing on. FinCEN will waive it, in whole or in part, matching whatever the firm documents in spending on an independent review of its anti-money laundering program. The agency was willing to forgo $15 million to see the program independently verified. The firm had been here before. In December 2018 it settled with FinCEN, the SEC, and FINRA on the same day over inadequate monitoring of foreign currency wires, $14.5 million all in. It committed to remediate. In February 2021 it replaced the old process with an automated transaction monitoring tool. FinCEN found the firm then failed to appropriately monitor over 50,000 foreign currency wires with an aggregate value of more than $10 billion. The failure mechanism is not securities-specific. Nearly every institution running an automated suspicious activity monitoring system replaced a predecessor at some point. Confirming the new one saw everything the old one did is a separate exercise, and a rarer one.
The replacement was the remediation, and nobody reconciled it
In the SEC's finding, foreign currency wires were booked outside the customer's brokerage account, so the legacy monitoring system did not consider certain transaction information. The manual control around it was, in FINRA's description, a quarterly review of a report containing thousands of foreign currency wires, and the review did not reasonably allow for identifying suspicious patterns. The replacement deserves the attention. The tool implemented in February 2021 pulled from 4:00 p.m. feeds rather than complete end-of-day files. A transaction labeling change kept it from recognizing certain foreign currency wires. The matching logic tying wire postings to counterparty details broke down because many wires carried no unique reference number. In the SEC's words, the new system had no exception or repair queue. In FINRA's finding, the incomplete data file and the labeling change together omitted approximately 33% of the foreign currency wires in retail customer accounts approved for foreign currency spot activity.
A system without a repair queue cannot tell you what it failed to process. It produces silence, and silence reads exactly like a clean run. Most institutions can show a signed project plan, a cutover date, and a decommissioning notice. Far fewer can show a reconciliation of transaction counts and dollar volumes through the new feed against the source of record for a defined period after go-live. Make the reconciliation the deliverable, not the go-live. Pick a window, tie the population entering the monitoring system back to the source of record, name every exclusion and the reason for it, and keep it as the evidence of closure.
The Federal Financial Institutions Examination Council (FFIEC) Bank Secrecy Act and Anti-Money Laundering Examination Manual already sets the bar. The monitoring system's programming methodology and effectiveness should be independently validated to ensure the models are detecting potentially suspicious activity, and management should document and be able to explain filtering criteria, thresholds used, and how both are appropriate for the institution's risks. That is examiner guidance, and it reaches every institution the federal banking agencies and the National Credit Union Administration (NCUA) examine, credit unions included. It was written for all of them, not a segment.
Closure is a supervisory claim, not a project milestone
The through-line in all four 2026 orders is the 2018 action. FinCEN and FINRA say so outright, citing recidivist violations and escalating the sanctions accordingly. Seven years, one system replacement, and the same category of failure. The failure mode is common. The people delivering a remediation project are almost never the people bearing the risk it was meant to retire. They measure themselves on scope, budget, and date, and they treat cutover as the finish line. For the project, it is. In most institutions cutover is also when the finding gets marked closed. Here the SEC found the firm could not confirm a complete remediation until June 2023.
The question is not whether the institution remediated. It is what the institution accepted as proof it had. Separate the delivery owner from the closure owner. Nothing closes until someone with no stake in the delivery date runs a test on production data after the change and shows the exposure is gone. This is ownership language at its most expensive. The words assign the work, and no one notices the proof obligation went with it.
The model-risk overlay came off in April, and the validation expectation did not
On April 17, 2026, the Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC) issued revised Model Risk Management guidance as Supervisory Letter SR 26-2 and OCC Bulletin 2026-13. The revised guidance supersedes SR 11-7, the 2011 foundation, and SR 21-8, and the OCC rescinded SR 21-8's companion, Bulletin 2021-19. Those two were the interagency statement on model risk management for bank systems supporting Bank Secrecy Act and anti-money laundering compliance, the bridge that pointed model-risk discipline at monitoring systems. The reach is narrower than the issuance suggests. The guidance is expected to be most relevant to banking organizations above $30 billion in total assets, though it may reach smaller ones with significant model-risk exposure. For most mid-sized institutions the overlay was never the binding constraint. The FFIEC manual is, and it did not move.
If your transaction monitoring system quietly left the model inventory in April, it did not leave the examination. Keep the independent validation, the data lineage test, and the tuning documentation where an examiner can find them. FinCEN's own direction sharpens the point. Its proposed rule on anti-money laundering and countering the financing of terrorism programs, published April 10, 2026, separates establishing a program from maintaining one, and defines maintenance as implementing the established program in all material respects. The same proposal states institutions will not incur additional risk of a significant supervisory or enforcement action solely from responsibly experimenting with innovative technologies, machine learning and generative artificial intelligence among them.
The April invitation and the August penalty are not in tension. FinCEN invited institutions to modernize, then assessed $125 million against a firm whose modern tool, on FINRA's finding, missed about a third of the wires in the retail accounts approved for foreign currency spot activity. The invitation covers the technology choice. It does not cover not knowing what the tool sees.
The pattern underneath
Supervision keeps handing work back. Reputation risk left the rating sheet while the exposure stayed. The banking agencies then committed to protecting highly sensitive information in examinations, and made the institution responsible for identifying it. This is the third, and the quietest. The model-risk overlay on anti-money laundering systems came off, and the obligation to prove the system works stayed put.
A finding is not closed when the project ships. It is closed when someone can prove the exposure is gone. Name what the system covers. Name who is allowed to say it works. Keep the evidence closure required.
Questions this raises
Who should sign off that a remediation is complete?
Someone with no stake in the delivery date. The people running a remediation project measure themselves on scope, budget, and cutover, and for the project those are the right measures. They are not proof the exposure is gone. Separating the delivery owner from the closure owner means the person certifying the finding is resolved is not the person whose project is being certified. That closure owner should be running a test on production data after the change, not reviewing the project's own status reporting.
What does a post-implementation reconciliation need to contain?
Four things. A defined window after go-live rather than a spot check at cutover. The population entering the new system tied back to the source of record, by transaction count and by dollar volume. Every exclusion named, with the reason it was excluded. And the whole thing retained as the evidence of closure rather than as a project artifact that gets archived with the plan. A system with no exception or repair queue cannot tell you what it failed to process, so the reconciliation is the only thing that will.
Back to all insights