AML Requirements for Financial Institutions - Pain or Gain?

Across the globe nations are enacting new anti money laundering (AML) laws or amending existing legislation. Why all this activity and why now? After all money laundering is hardly new. Criminals have always sought to hide the link between the crime and the money it generated so they could enjoy the benefits of their criminal activity. To understand what is happening now we need to look back to developments almost two decades ago and to more recent events which are shaping the international agenda.

Initial Reponses to Money Laundering

A criminal’s need to launder money will depend on the effectiveness of law enforcement. If the criminal perceives no threat there is no need to launder funds. The extent and sophistication of the laundering will respond to the perceived threat. The Mafia developed a number of techniques which included the use of front businesses with no legitimate business activity at all, the clandestine transfer of funds off shore and subsequent repatriation from apparently legitimate sources and the corruption of public officials and bank staff to hide the origin of funds. These funds were then used to finance ongoing criminal activity and the purchase of legitimate businesses, which generated legitimate profits but also had the potential to provide further laundering opportunities.

Until the 1980s however, law enforcement did not seem intent on finding or recovering criminal proceeds. The political pressure on western governments to deal with the burgeoning drug trade in the 1980s brought about a rethink in law enforcement. The best way to deal with the super profits available through drug trafficking was thought to be a focus on the organisers. The idea was to target the ‘Mr Bigs’ of organised crime by following the money trail. Given that criminals try to disguise the source of their funds, the activity of hiding the link between the money and the crime, the laundering process, should itself be a criminal offence. Money laundering always involves an offence (the predicate offence), which generates the money which is subsequently laundered. These ideas were reflected in the 1988 UN Convention Against Illicit Traffic In Narcotic Drugs and Psychotropic Substances (the Vienna Convention). Money laundering was still seen as primarily linked to the drug trade.

The Paradigm Shift – It’s about the Financial Sector

At the end of the 1980s a major paradigm shift occurred in the way the major economies viewed money laundering. The G7 leaders determined in 1989 that money laundering provided a major threat to global financial systems. Money laundering distorted financial markets, provided unfair competitor (a business supported by illicit funds could compete unfairly against legitimate businesses), could undermine small economies and lead to political instability and encourage and support corruption in government and financial institutions. In short the G7 had decided that money laundering was a serious problem and something had to be done about it. They created the Financial Action Task Force (FATF), made up of officials from OECD economies and some other bodies such as the European Commission, to identify international best practice in identifying, combating and preventing money laundering. These standards, referred to as the FATF Forty Recommendations were published in 1990.

By 1996 most, but not all, member countries had enacted laws to reflect the FATF Forty Recommendations. In that year the FATF reviewed and substantially strengthened the Forty Recommendations. New and tougher AML obligations were imposed most notably that predicate offences should now cover all serious crime not just drug offences. Thus money laundering could involve proceeds derived from fraud, insider trading, tax evasion, investment scams and corruption.

The Second Paradigm Shift – Protection from Terrorism

When the terrorists attacked New York and Washington on 11 September 2001 many governments turned their attention to terrorism and its financing. The FATF drew up eight special recommendations, which it bravely claimed would effectively attack terrorist financing. A key element of the special recommendations was the association of money laundering and terrorist financing. The FATF required that ‘countries should ensure that such offences are designated as money laundering predicate offences’ (see FATF SR II). Yet often terrorism is financed by legitimate funds. How could the use of legitimate funds to finance a subsequent criminal act amount to a predicate offence? This was the result of an attempt to apply existing AML regimes as a basis for responding to terrorism. While the purpose was laudable the lack of rigorous analysis and the desire to be seen to act immediately papered over poor analysis of both the problem and the best way to respond to it. That legacy remains and partly explains why the focus on terrorist financing has had little effect in combating terrorist activity. Subsequently FATF added a new recommendation dealing with cross border movement of negotiable instruments including cash.

The FATF special recommendations, a number of resolutions of the Security Council of the United Nations and the various anti terrorism proposals prepared by governments all required a legislative response. The result was new legal obligations to identify suspicious transactions that might be related to terrorism and extensive powers to freeze suspect transactions.

The New Rules – Money Laundering is Everyone’s Responsibility

In 2003 the FATF again reviewed the Forty Recommendations. Both the scope and content of the recommendations changed. The definition of a financial institution, previously limited to banks, insurance companies and those involved in the securities markets was now expanded to include many businesses that no one would regard as a financial institution. Casinos, gem dealers, real estate agents and bullion dealers were all so defined. So too were ‘gatekeepers’ such as accountants, lawyers and financial advisers who could facilitate the placement of illicit proceeds into the financial system. These businesses were often used by money launderers and the FATF was recognising this reality.

In addition the obligations previously imposed on financial institutions to ‘know their customer’, report suspicious transactions, verify identities, avoid shell banks and anonymous accounts, institute AML policies, scrutinise high risk customer activity and train staff were toughened and expanded. Furthermore, these obligations were imposed on all of the newly defined ‘financial institutions’. Finally, the obligations to identify and report possible money laundering also extended to possible terrorist financing. If the former was difficult the latter was nigh on impossible. In short the responsibility to help identify and combat money laundering has been placed on a wide range of businesses and professions. Hence the need to amend domestic laws to ensure compliance with the international standards.

In order to ensure compliance, regulators had to enhance their response to non-compliance. This had always been the case in relation to the AML standards but prior to September 2001 little real attention was paid to effective enforcement in the western economies. This was even less so in other parts of the globe. But 2001 changed that. The threat of terrorism saw governments spend large amounts of political energy and real dollars in responding to, and being seen to respond to, the ‘terrorist threat’. We saw regulators and financial sector supervisors such as central banks (who don’t like being referred to as ‘regulators’) take action where poor AML performance was identified.

What Must Financial Institutions Do?

What does this mean for financial institutions? They must have in place effective policies and procedures to meet these expanded obligations. It means

  • staff awareness across the organisation;
  • training tailored to the role of individual staff members and their roles. Not a half day ‘Money Laundering 101’ course given to everyone but specific training designed for account managers, tellers, back office staff, senior management, compliance officers and those who develop new products;
  • being prepared to really know the customer and to conduct extensive and expensive due diligence when appropriate;
  • ensuring that those with whom the institution does business (not just customers) such as the providers of outsourced services apply equally rigorous procedures;
  • the use of sophisticated and effective software which can assist in identifying unusual transactions;
  • developing an effective relationship with regulators and a willingness to tell them about problems before they discover them;
  • support for expenditure on training and software;
  • recognition that there is business we simply do not want because it could cause catastrophic damage to the institution (as Riggs Bank found out when it dealt with a variety of international despots and dictators); and
  • the full commitment of the Board to the AML policy.

None of this comes cheap. But it can and should be based on risk analysis so that effort and expenditure relate to identified risk.

The Changed Regulatory Environment

US regulators, partly driven by genuine post September 11 concerns and partly by increased congressional scrutiny of their past failures, began to impose serious penalties on non-compliant financial institutions. Fines of $50m were imposed on Riggs Bank and Am South Bank for example. Their British counterparts at the FAS followed suit. Fines of more than £8m were imposed. In Japan, financial regulators withdrew Citigroup’s licence for its private banking operation because of inadequate AML practices. Most of these penalties relate to failures to apply the 1996 FATF rules not the 2003 iteration. This is because many countries have not yet translated the new requirements into their domestic law and regulatory systems. All of which suggest that the vigour of the regulators will not diminish when the new rules are enforceable.

Governments know that compliance is expensive. Yet the politics driving government activity has drowned out the complaints of the business community. In the United States few if any in the business community have openly complained about the huge increase in compliance costs, which have flowed from September 11. In the United Kingdom, where one estimate suggests AML related compliance costs have reached £90m while government expenditure responding to money laundering and terrorist financing using the information gathered from the private sector is in the order of £11 million, questions are being asked about costs and benefits. In Australia rumours suggest the government’s initial commitment to fully implementing the FATF 40 plus nine may be weakening in response to business sector concern about cost. The recent London bombings may well change the political dynamic yet again.

Notwithstanding the growing enthusiasm and effectiveness of the regulators in some major economies, that is not the global experience. In the developing economies in the Asia Pacific region a number of observations can be made about the regulation of the financial sector, most of which are less than flattering. Regulators are seriously under resourced, lack genuine independence and are subject to external pressure, often perceived to be ineffective, sometimes seen as corrupt or at least corruptible and operate under legislation that is often dated and inadequate. The penalties in the insurance industry law in one Asian jurisdiction have not changed for 19 years. Of course these comments do not apply to all regulators and supervisory agencies. There are exceptions, particularly in the developed economies. But the track record of the regulators in Japan and Australia for example is not without its spectacular failures.

Given this situation it is hardly surprising that financial institutions do not take regulators seriously. There is no real likelihood of effective regulatory action and even if serious problems were encountered, large penalties are uncommon if not unknown. In addition many of the financial regulators have specific policies not to publicise breaches of laws and regulations for fear this will undermine confidence in the financial sector. It does not seem to occur to these regulators that the obvious lack of effective regulation is a greater threat to public confidence.

So why should financial institutions in this region take their AML obligations seriously? First, governments are coming under increasing pressure to take effective action in relation to AML and terrorist financing issues. Action will be taken because influential governments and donor organisations such as the ADB, EC and the IMF are pressing for action on given terrorist threats. Secondly, financial institutions, particularly the larger ones, operate globally. They are subject to financial regulators in every jurisdiction in which they operate so they must be able to meet the standards and expectations in each of those jurisdictions. A Thai bank with a branch office in the United States has to meet US standards both in the US and at home (as it may have its home operations examined by the US authorities). Under the US Patriot Act US authorities can require US banks that have correspondent relationships with other banks to cease those relationships if the correspondent bank does not meet US AML standards. If the relationship is stopped it will have major implications for the bank. Fourthy compliance failures can be expensive both in monetary and reputation terms. Do you really want to be the bank used by corrupt politicians, failed businessmen who may also defraud you as well as their shareholders, organised criminals or terrorists? Finally think about the potential litigation your institution might face if it has been used by money launderers. Reputation is important and reputational risk a major threat to financial institutions.

All of these are good reasons to commit the expenditure and resources to comply wit the AML requirements. But they are essentially based on the need to prevent adverse consequences.

But effective AML activities have beneficial consequences for financial institutions. Effective AML requires that institutions know their customer. Every bank should know its customers. How else can you identify new marketing opportunities? Every bank wants to prevent fraud. Isn’t it sensible to find out as much as you can about a customer when they deposit their money as you would want to know about them when you lend them your money? In many cases the volume of funds lent will be greater than any deposit. Identifying changes in account activities such as changes in the volume of funds can identify emerging business opportunities for the institution. High quality record keeping is not just required for AML purposes but is sound business practice. Much of the software that is available to identify unusual transactions and account holders whose names appear on international watch lists can be easily adapted to meet business needs including fraud prevention and detection. If an institution is known to have effective compliance systems in place and to work effectively with regulators and other government entities an occasional failure will almost certainly attract less criticism and penalty because regulators will take these issues into account. Finally, taking effective action against money laundering and terrorist financing makes a positive contribution to the well being and safety of the institution and its employees and shareholders.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y