A $125m wake-up call: This month’s record $125 million FinCEN penalty against UBS Financial Services is more than just another enforcement action. It is a clear reminder that regulators expect firms to operate customer due diligence programmes that are effective in practice, particularly in understanding and addressing the specific risk profiles of their customer base.
According to FinCEN, the failures extended beyond isolated process gaps. The findings included weaknesses in customer due diligence, failures to remediate previously identified issues, insufficient monitoring of international wire activity and shortcomings in identifying and reporting suspicious activity, particularly involving higher-risk customers with links to jurisdictions including Latin America and Russia that present elevated money laundering and corruption risks.
Of particular relevance is FinCEN’s focus on the effectiveness of UBSFS’s AML programme in practice. The regulator highlighted failures to appropriately assess and mitigate risks associated with customers’ source of wealth, negative news indicators and potential links to corruption, fraud and money laundering.
Similar weaknesses are emerging across private markets
The themes highlighted by FinCEN are not unique to UBSFS or the US.
In the UK, the FCA has highlighted similar weaknesses across asset managers and alternative investment firms. Its review of asset management and alternative firms’ financial crime controls found:
- Deficiencies in understanding source of wealth for higher-risk customers, with 10% of firms failing to adequately verify higher-risk customers’ source of wealth.
- Inconsistent risk assessments.
- Weaknesses in ongoing monitoring and oversight of higher-risk relationships.
The message from both regulators, whether through guidance or enforcement, is consistent: AML programmes need to be effective in both design and application and aligned with a firm’s exposure to financial crime risk.
Customer due diligence is not a one-time exercise
FinCEN’s compliance considerations in relation to the UBSFS enforcement action reinforce a point regulators have been making consistently – effective customer due diligence is not a one-time onboarding exercise.
Firms need to conduct meaningful, risk-based CDD at the start of the relationship and continue to maintain and update customer information throughout the investor lifecycle, ensuring controls evolve as risk profiles change.
As regulators continue to scrutinise the effectiveness of AML controls, the question is no longer whether firms have a KYC policy. It is whether they can demonstrate that their programme is operating effectively, consistently and throughout the entire customer relationship.
What does an effective KYC programme look like?
For firms, this means having accurate, current customer data that is maintained throughout the investor lifecycle, with ongoing screening, risk assessment and monitoring capable of identifying changes in behaviour, circumstances or risk profile as they happen.
An effective KYC programme should provide:
- A complete and centrally maintained customer profile.
- Appropriate identification and verification of beneficial ownership.
- Risk ratings based on factors such as jurisdiction, PEP status, ownership structure and source of wealth.
- Continuous screening against sanctions, PEPs, enforcement actions and adverse media.
- Ongoing monitoring of customer activity and material changes in risk.
- The effective application of enhanced customer due diligence for higher risk relationships.
- Clear governance, reporting and evidence that higher-risk relationships receive enhanced oversight.
From regulatory expectation to operational reality
At Sonata One, this is exactly what we’ve built our Investor Passport around: creating a single, continually maintained investor profile that supports ongoing due diligence, live screening, risk monitoring and oversight across multiple funds.
Every investor profile is verified and approved by our team of compliance specialists at onboarding, then continually monitored and kept up to date across the fund lifecycle. Moreover, with ongoing MLRO support delivered by experienced AML officers, we help fund managers strengthen governance and demonstrate effective oversight, ensuring their KYC and AML programmes are aligned with the evolving risk profile of their funds and investors.
If you’d like to discuss your AML framework or investor due diligence programme, we’d be happy to share our experience and insights. Contact Louis Dodd or book a demo to find out more.
