Issue #24 | October 6, 2026 | 7 min read

The Brief

On March 6, 2026, FinCEN announced an $80 million civil money penalty against Canaccord Genuity, the largest Bank Secrecy Act penalty ever imposed on a broker-dealer. The violations ran from March 2018 to June 2024, and the firm's own surveillance system was the centerpiece of the failure.

This issue covers how a broker-dealer built a trade-surveillance program that generated alerts faster than anyone could clear them, what a SAR lookback found in the activity those alerts never reached, and why the correspondent account findings are the part most programs should read twice.

Main Feature

Canaccord Had the Alerts. It Didn't Have Anyone Who Could Clear Them.

A record broker-dealer penalty for a surveillance program that existed on paper and failed in the queue.

Canaccord's exposure sat in its wholesale market-making business for over-the-counter, low-price securities, the corner of the market where pump-and-dump schemes do most of their work. From 2018 through 2022 the firm ranked among the top five market makers for OTC low-priced stocks, executing nearly $70 billion in trades on stocks trading under five dollars. FinCEN found the firm willfully failed to maintain an effective AML program, to conduct required due diligence on foreign correspondent accounts, and to file suspicious activity reports. The $80 million figure is the headline. Inside it, FinCEN credited $20 million each for penalties the SEC and FINRA imposed separately, suspended $5 million pending a SAR lookback, and left Canaccord paying $35 million to the Treasury.

The surveillance program was not missing. Canaccord had trade-surveillance reports, and FinCEN's findings are about how those reports were built, staffed, and reviewed. The reports carried fundamental design flaws and longstanding data problems. One report's thresholds were set at "arbitrary numbers," chosen by trial and error without regard to the risk of the transactions it captured. A wash-sale report often ran more than 50 pages a day and was described as too long to review. Until late 2021, four employees, all with other responsibilities, were tasked with reviewing more than 100 unique reports, many of them daily. Some reports went unreviewed for stretches of months to four years.

When FINRA began asking for proof that the reports had been reviewed, two compliance employees falsified records to make it look as though they had been. One of them falsified nearly 400 documents. Canaccord later terminated those employees. The falsification is the detail an auditor should pull first, because it means the review evidence itself can't be trusted without independent testing.

A SAR lookback produced preliminary results showing at least 160 SARs that should have been filed, covering dozens of OTC securities where FinCEN estimates the underlying suspicious transactions run into the thousands. The red flags were the standard microcap set: matched trades, prearranged trades, wash trades, rapid deposit-and-liquidation, one account dominating a security's volume, and marking the close. In one stock, the SEC suspended trading over unusual market activity. Canaccord resumed trading when the suspension ended and conducted no review of its own activity in the stock. The reports that would have surfaced those patterns were sitting in the same unreviewed queue.

The correspondent banking findings are quieter, and they're worse for anyone who has to defend the program to an examiner. Canaccord ran foreign financial institution correspondent accounts without confirming that customer information met regulatory requirements. Onboarding staff didn't consistently collect the nature of the foreign bank's business or the markets it serves, and the firm had no procedure for periodic review of account activity against its expected use. A broker-dealer that doesn't know what its correspondent customers are supposed to be doing can't tell when they start doing something else.

Red flags in This Case

  • Surveillance thresholds set by trial and error, with no documented link to customer or product risk and no testing against known suspicious activity

  • Surveillance reports too long for a reviewer to work through in a day, with a reviewer who had no training on what the report was for

  • Low-price securities where trading volume is dominated by a small number of accounts, with rapid deposit-and-liquidation sequences

  • Continued trading in a stock after the SEC suspended it, with no review of the firm's own activity

  • Foreign correspondent accounts with no consistently collected business purpose, expected activity, or market information, and no periodic activity review

The question for a program running trade surveillance isn't whether the reports exist. It's who set the thresholds, when anyone last checked them against known suspicious activity, how many reports each reviewer is expected to clear, and who checks that the reviews happened. If the answer to the last question is the same people who run the reviews, the review evidence is only as good as their integrity. A threshold nobody can justify is a control nobody can defend in an exam.

Canaccord had the alerts. What it lacked was anyone with the time, the training, and a defensible reason to close them, and a supervisor checking whether they did.

Controls & Testing

Risk & Control Matrix

Risk

Control

Trade-surveillance thresholds set without reference to customer or product risk, and never validated against known suspicious activity

Documented threshold rationale for each surveillance report, with periodic back-testing against confirmed suspicious activity and sign-off by the BSA officer

Reports too large for reviewers to complete, so alerts age out unreviewed

Reviewer capacity model tying report volume to available analyst hours, with aged alerts escalated once they pass a defined review window

Review evidence falsified or backdated when a regulator asks for proof of review

Independent quality-control re-performance of a sample of closed reviews, with system-generated timestamps and reviewer log-ins retained for each review

Foreign correspondent accounts opened without documented business purpose, expected activity, or jurisdictional risk, and never re-reviewed

Correspondent onboarding checklist requiring those fields before activation, with periodic review of account activity against expected use

Audit Test Steps

An audit program built around this typology could test for it by:

  1. Obtaining the full inventory of trade-surveillance reports in force during the period and, for each one, the documented threshold rationale and the date of its last validation. Flagging any report with neither.

  2. Selecting a sample of alerts from the period and tracing each to a review date and reviewer, then measuring the share unreviewed after the program's stated review window, by report.

  3. Comparing reviewer headcount against the number and frequency of reports assigned, and testing whether those assignments were achievable within working hours for each period.

  4. Re-performing a sample of closed reviews and comparing system timestamps and reviewer records against the review documentation, flagging any review dated before the alert was generated or any documentation without a matching system record.

  5. Pulling the foreign correspondent account population and testing a sample for documented business purpose, expected activity, jurisdictional risk rating, and evidence of periodic activity review.

Intelligence Briefing

FinCEN targets the A7 Network's sub-agents. On October 1, FinCEN issued Alert FIN-2026-Alert007 on the A7 Network, a Russia-linked wholesale sanctions-evasion and money laundering service that the alert says is used by a wide range of illicit actors, including Iran and its terrorist proxies. The same day, FinCEN proposed a rule under the Combating Russian Money Laundering Act that would prohibit covered US institutions from sending or receiving funds in transactions involving the network's sub-agents. The docket is FINCEN-2026-0265. The alert and the proposal bring the network's sub-agents into scope before any final rule exists.
Source: FinCEN Alert FIN-2026-Alert007, Oct. 1, 2026

Vietnamese national charged with laundering crypto pig-butchering proceeds. Trung Nguyen Van faces a two-count criminal complaint for money laundering, announced by the US Attorney's Office for the Western District of Missouri on September 25 after his initial appearance in federal court in Los Angeles. An affidavit traces one victim's roughly $16 million in cryptocurrency transfers during mid-2024 to a fake "Triangle" platform, and says more than $569,000 of it reached Van's wallet within days. DOJ says about $568,000 of that moved through four transactions into a privately controlled, unhosted wallet outside any regulated exchange. Wallets linked to Van received about $53.3 million in crypto tied to wire-fraud schemes targeting US citizens between February 2018 and December 2024. The step into an unhosted wallet is where a program's visibility usually ends.
Source: US Attorney's Office, W.D. Mo., Sept. 25, 2026

Career Intel

The BLS projects 4 percent employment growth for compliance officers from 2025 to 2035, which it calls as fast as average. That's about 32,700 openings a year against 436,400 jobs today, and the typical entry requirement is a bachelor's degree with no work experience. The degree isn't the hard part. Employers set the experience bar, so the bottleneck is landing a first seat on a review desk, whether in KYC, fraud, or alert investigation. The median wage was $80,730 in May 2025. Expect steady demand and a competitive market, not a hiring wave.
Source: BLS Occupational Outlook Handbook, Compliance Officers

AI in Financial Crimes Compliance

On May 4, FIS announced a Financial Crimes AI Agent built with Anthropic, aimed at the part of AML work analysts dread most: assembling the evidence. Per FIS, the agent pulls a case's records across a bank's core systems, evaluates the activity against known typologies, and surfaces the highest-risk cases for an investigator. BMO and Amalgamated Bank are named as early customers still in development, with general availability planned for the second half of 2026.

The design choice is the interesting part. The agent doesn't close alerts. It builds the evidence package and hands an investigator a ranked case, and FIS says investigators "will remain in control of every decision" and that every agent decision is traceable and auditable.

The catch is that the speed claims are targets, not results. FIS says investigations compress "from hours to minutes" and that false positives fall, but the announcement gives no measured figures. And the agent only sorts what the upstream rules hand it. If the thresholds generating alerts were set arbitrarily, as FinCEN found at Canaccord, the agent will prioritize the wrong queue very efficiently. The question for an auditor is what happens to the alerts the agent ranks low, and whether anyone tests that decision.
Source: FIS press release, May 4, 2026

Tip Line

Got any idea for something you'd want to see covered here? Doesn't have to fit neatly into a category. If you think it's interesting, we probably will too.

Send it to [email protected].

If someone forwarded this to you, welcome.

The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:

[BUTTON: Subscribe → theamlbrief.com]

Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.

The AML Brief | theamlbrief.com

Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.