← Broker database 2026-03-20
Stash Capital Fined $450,000 for Customer Identification and AML Compliance Failures
According to FINRA, Stash Capital LLC (CRD #287728) of New York, New York, was censured and fined $450,000 after FINRA found the firm failed to establish a reasonable Customer Identification Program (CIP), maintain an adequate AML compliance program, and develop a written Identity Theft Prevention Program (ITPP) compliant with federal securities law.
With respect to the CIP, the firm's written procedures did not adequately describe how it verified customer identities, which databases it searched, when it would manually review customer information, or how it would respond to red flags during account opening. The firm's automated system classified applications as approved, rejected (identity could not be verified), or indeterminate (identity verified but with an alert for potential identity theft). Applications flagged as rejected or indeterminate were passed through additional automated reviews, but those secondary reviews failed to address the specific reasons the initial verification had raised concerns. As a result, the firm approved numerous customer accounts without forming a reasonable belief that it knew the true identity of its customers.
The firm's AML program also lacked policies and procedures reasonably expected to cause the reporting of suspicious transactions in accounts exhibiting red flags of potential new account fraud. AML-specific red flags were not identified, automated alerts only flagged large or unusually frequent deposits and withdrawals, and there was no comprehensive system linking red flags observed during account opening with suspicious activity that emerged after an account was opened. With millions of customer accounts, the firm relied solely on manual review — an approach wholly inadequate to the scale of its business.
With respect to identity theft, the firm's ITPP relied primarily on customers self-reporting stolen identity and on its clearing firm notifying it of undeliverable mail. Even when alerted to potential identity theft methods, the firm failed to take timely corrective action.
For retail investors, these failures matter directly: inadequate CIP procedures and weak identity theft protections may allow fraudsters to open accounts in another person's name and misuse their identity. Investors should monitor their brokerage accounts closely and report any suspicious activity promptly.