Spotlight

FinCEN’s $80M Penalty Names a Training Failure

FinCEN's $80 million penalty against Canaccord Genuity names poorly trained monitoring staff among the causes — and what it does not mean for your program.

Michael Cosgrove

On 6 March 2026, the Financial Crimes Enforcement Network assessed an $80,000,000 civil money penalty against Canaccord Genuity LLC, a US broker-dealer, for willful violations of the Bank Secrecy Act.[1] The figure is not the most useful part of the order. The explanation is.

Buried in the Compliance Considerations section is something regulators almost never put in writing: a plain statement of what was wrong with the people doing the monitoring. Not the policy. Not the system. The reviewers themselves, and what they had been equipped to do. It is quoted in full below, because paraphrasing it would soften it.

What FinCEN said

FinCEN attributed Canaccord’s transaction monitoring failure in part to staff it described as inexperienced, poorly trained and overwhelmed, working from surveillance reports it called unreasonably designed. Training was one of several named causes. It was not the only one, and not a new regulatory standard.

What FinCEN Found

Transaction monitoring alert reports and regulatory notices on a desk beside a laptop

As part of its resolution, Canaccord admitted that it willfully violated the BSA by failing to develop, implement and maintain an effective AML program; to conduct required due diligence on correspondent accounts for foreign financial institutions; and to file suspicious activity reports.[1]

The reporting gap was substantial. FinCEN found that Canaccord failed to file at least 160 SARs relating to dozens of different over-the-counter securities, the trading of which involved underlying suspicious transactions the agency estimates to be in the thousands.[1] The schemes that went unreported included penny stock and microcap fraud that FinCEN said caused significant economic harm to investors.

These are findings about one firm’s admitted conduct. They are not a sector-wide obligation, and nothing below should be read as a rule that now applies to every broker-dealer.

The Sentence Worth Reading Twice

Canaccord’s transaction monitoring policies, procedures, and internal controls relied on an insufficient number of inexperienced staff who were poorly trained and overwhelmed by the number of transactions Canaccord tasked them with reviewing through unreasonably designed surveillance reports.

Regulators rarely locate a failure this precisely in the capability of the people doing the work. FinCEN’s point is that Canaccord was structurally well placed to catch what it missed: as a market maker, it was, in the agency’s words, well-positioned to detect and investigate red flags in the securities for which it provided trading services.[1] The information was in front of it. The capacity to act on it was not.

It would be a distortion to read this as a penalty for bad training alone. FinCEN named four contributing conditions, and they compound one another:

  1. An under-resourced program: FinCEN described the AML program as significantly under-resourced and not proportional to the risks of Canaccord’s business model.
  2. Inexperienced staff: an insufficient number of reviewers, and the ones present were new to the work.
  3. Poor training: named explicitly, in those words, in the enforcement order.
  4. Volume and tooling: reviewers overwhelmed by transaction counts, working from surveillance reports FinCEN called unreasonably designed.

Each of those is fixable on its own. Together they describe a monitoring function that could not have worked no matter how many alerts it generated.

The Second Warning: Remediation That Never Landed

Three financial compliance analysts reviewing reports together in a boardroom

There is a second finding in the order that deserves as much attention as the first. Canaccord’s regulator had repeatedly found weaknesses in its AML program, including in its monitoring of suspicious transactions. The firm committed in writing to remediate them. It then failed to meaningfully address those concerns for years, with significant aspects of the remediation not undertaken until FinCEN’s investigation was already underway.[1]

Five months later, the same pattern produced a larger number. On 3 August 2026, FinCEN assessed a $125,000,000 penalty against UBS Financial Services Inc., now the largest imposed on a broker-dealer for BSA violations, after finding that the firm had not remediated a monitoring weakness identified in a December 2018 consent order, and had subsequently failed to appropriately monitor over 50,000 foreign currency wires with an aggregate value of more than $10 billion.[2]

Two enforcement actions, five months apart, both turning on remediation that was promised and never reached the people doing the reviewing.

What This Is, and What It Isn’t

FinCEN has not introduced a training standard. There is no new frequency, no mandated curriculum, no hours requirement anywhere in either order. Anyone telling a board that FinCEN now requires a particular kind of AML training is overstating the record.

What the agency does state, as general guidance, is that AML programs should be risk-based and commensurate with the risks posed by the nature and volume of the financial products and services provided by the institution, including fraud-related risks that can arise in the securities markets.[1] It also reminded broker-dealers acting as market makers of their obligation to identify and report suspicious activity, including scams involving penny stocks and other securities fraud.[1]

Read against that guidance, the training question is not whether a program exists. It is whether the people reviewing alerts can do the thing the program is supposed to have equipped them to do.

Canadian reporting entities face the same question under a different regime. We looked at what FINTRAC actually examines when it reviews a training program in a separate piece, and at the broader obligation in our guide to FINTRAC compliance training.

Questions for your compliance team

  • Can the people reviewing your alerts explain why a pattern is suspicious, or only that the system flagged it?
  • Is your training measured by completion rates, or by demonstrated recognition?
  • When a weakness was last identified by an examiner, an auditor, or your own staff, did the fix reach the reviewers’ desks, or stop at the policy document?
  • Are your surveillance reports designed for the people who actually read them?

How TAMLO can help

How Tamlo Can Help

Tamlo International provides AML/ATF compliance training for financial institutions, MSBs, credit unions, securities firms and fintech companies across Canada and the United States. Whether your team needs foundational AML awareness training, CAMLO-level advanced modules, or a custom compliance program aligned to FINTRAC requirements, we can help. Reach out to Tamlo International to discuss your training needs.

Sources and regulatory references
  1. FinCEN — FinCEN Assesses Historic $80 Million Penalty Against Canaccord Genuity LLC for Securities Fraud-Related Bank Secrecy Act Violations, 6 March 2026 (enforcement notice)
  2. FinCEN — FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations, 3 August 2026 (enforcement notice)