Skip to main content

Author: Angela Brunelle

Top Five AML Testing Failures – The Penny Stock Edition

Business professionals engaging in meeting.

Findings related to penny stocks—more commonly referred to as low‑priced securities—are not new. Regulators have consistently highlighted the elevated risk these securities present, particularly in the context of market manipulation and money laundering. However, recent enforcement activity suggests that these issues are not only persisting, but may be increasing in frequency and severity, particularly where firms’ AML programs are not adequately aligned with the underlying risk.

For purposes of regulatory analysis, a “penny stock” generally refers to equity securities trading at low prices, typically over‑the‑counter and often lacking robust public disclosure. These securities are also commonly referred to as low‑priced securities, microcap securities, OTC securities, or thinly traded securities. Regardless of terminology, they share common characteristics—limited liquidity, price volatility, and reduced transparency—that make them particularly susceptible to manipulative or illicit activity. Against that backdrop, recent AML testing and enforcement observations reveal several recurring failure points.

1. Surveillance That Doesn’t Capture the Risk

A consistent issue is the presence of surveillance systems that technically exist, but are not designed to capture the firm’s actual risk exposure.

In many cases, firms relied on reports or exception monitoring that:

  • Excluded key account types (e.g., omnibus, DVP/RVP, or certain institutional accounts)
  • Filtered out lower‑value or segmented transactions
  • Failed to aggregate activity across accounts or time periods

The result is a control environment where the highest‑risk activity is effectively outside the scope of monitoring. From a testing perspective, this is not a gap in execution—it is a design failure. Surveillance that cannot identify relevant activity cannot be considered “reasonably designed” under Rule 3310.

2. Lack of Risk Alignment with the Firm’s Business Model

Another recurring theme is the failure to tailor AML programs to the firm’s specific business activities involving low‑priced securities.

This commonly arises where firms:

  • Facilitate trading through correspondent, omnibus, or foreign financial institution accounts
  • Operate in execution‑only environments with limited insight into underlying customers
  • Engage in high‑velocity or high‑volume trading in thinly traded securities

Despite these risk factors, AML programs often remain generic and do not reflect the firm’s actual operational exposure.

From a testing perspective, the key question is not whether a firm has an AML program—it is whether the program reflects the actual risks presented by the firm’s activities. Where low‑priced securities are a meaningful part of the business, regulators expect enhanced, targeted controls.

3. Red Flags Identified—But Not Operationalized

Many firms appropriately identify red flags associated with low‑priced securities in their written procedures. However, a common failure is the absence of operational guidance around those red flags.

Specifically:

  • Red flags are listed, but not linked to specific surveillance scenarios
  • There is no defined process for how alerts are generated or identified
  • Escalation thresholds and investigative expectations are unclear or undefined

In practice, this creates a disconnect between policy and execution. Staff may recognize that certain activity is risky in theory, but lack the tools or direction to detect and act on that risk.

Effective AML programs require that red flags are not only documented—but translated into actionable surveillance, investigation, and escalation procedures.

4. Failure to Investigate and Escalate Suspicious Activity

Even where potentially suspicious activity is identified, firms frequently fail to conduct reasonable investigations or escalate concerns appropriately.

Testing observations often include:

  • Acceptance of customer explanations without independent verification
  • Lack of documented investigative steps or conclusions
  • Failure to consider whether activity warrants SAR filing

This issue is particularly pronounced in low‑priced securities activity involving:

  • Significant liquidations relative to market volume
  • One‑sided trading patterns (e.g., repeated sell orders with no corresponding buys)
  • Rapid movement of proceeds following transactions

From a regulatory perspective, detecting activity is only the first step. Firms must demonstrate a structured, documented, and defensible investigative process, including clear rationale for escalation or non‑escalation decisions.

4. Failure to Investigate and Escalate Suspicious Activity

Even where potentially suspicious activity is identified, firms frequently fail to conduct reasonable investigations or escalate concerns appropriately.

Testing observations often include:

  • Acceptance of customer explanations without independent verification
  • Lack of documented investigative steps or conclusions
  • Failure to consider whether activity warrants SAR filing

This issue is particularly pronounced in low‑priced securities activity involving:

  • Significant liquidations relative to market volume
  • One‑sided trading patterns (e.g., repeated sell orders with no corresponding buys)
  • Rapid movement of proceeds following transactions

From a regulatory perspective, detecting activity is only the first step. Firms must demonstrate a structured, documented, and defensible investigative process, including clear rationale for escalation or non‑escalation decisions.

The common thread across these findings is not the absence of AML programs—but the absence of operational, risk‑aligned controls that reflect the realities of low‑priced securities trading.

For firms that engage in or facilitate this activity, the regulatory expectation is clear: AML programs must move beyond generic frameworks and demonstrate a practical, working ability to detect, investigate, and escalate suspicious activity in higher‑risk areas of the business.

Firms that proactively address these gaps through targeted AML program testing, surveillance design reviews, and risk‑based control enhancements are better positioned to identify vulnerabilities before regulators do.

Renaissance Regulatory Services works with broker-dealers and other financial institutions to operationalize these expectations—supporting firms through independent AML testing, control framework assessments, and tailored remediation strategies designed to align programs with real-world regulatory scrutiny.