How to Make the Most of AML Investments
In the past, banks considered investment in anti-money laundering (AML) compliance technology as purely a cost of complying with various regulations to protect them from operational, financial and reputational risks. These investments enabled banks to continue business as usual and avoid the high penalties of non-compliance, the threat of reputational damage and closure of business; there was never any strategic intent to derive additional business benefits. There are, however, opportunities to derive benefits from investment in AML technology, i.e. extending the use of this technology for other purposes as well as effective compliance, thereby enhancing business performance. This article analyses the costs of AML compliance and suggests how banks can derive value from these investments.
The dynamic nature of AML regulation along with a stringent enforcement environment has caused a complete overhaul in the strategy towards investment in tools and technologies to counter money laundering. The focus of the regulations has changed from mere monitoring of transactions to detecting suspicious customer activity indicating money laundering, which requires banks to adopt an enterprise-wide approach to tackle money laundering rather than a piecemeal approach to compliance. With increased technology spend on compliance related issues, to the extent that banks may find themselves unable to function, it is essential that banks derive full value from their investments in AML technology.
AML related spending has increased significantly since the 9/11 events in the US and banks have established financial and human resources to get their AML programs in place. In the next few years, increased information technology requirements and human resource costs for compliance and risk management initiatives and training will increase the momentum of spending.
A report on technology spends by independent market analyst, Datamonitor, shows that compliance and risk management projects are going to be the major drivers of investment in analytics and business intelligence software by financial services institutions (FSIs). Datamonitor predicts that investment by European FSIs in business intelligence and analytics will hit $4.8bn by 2006 out of which, for compliance and risk management combined, investment will amount to $1.7bn in 2006. The report splits business intelligence and analytics solutions into six solution areas: customer intelligence, risk management, fraud, performance management, financial analysis and compliance.
Fuelled by AML and Basel II initiatives, Datamonitor says that compliance and risk management solutions in particular will experience the strongest growth in terms of FSI investments. The report predicts that, while overall European FSI spends on business intelligence and analytics will grow at a compound annual growth rate (CAGR) of almost 7 per cent between 2002 and 2006, the combined FSI spend on compliance and risk management solutions are predicted to grow at a CAGR of 9.5 per cent between 2002 and 2006, showing the fastest growth of all solution areas.
Besides information technology expenditure on analytics and business intelligence software to monitor and detect suspicious money laundering transactions, banks face several other costs when putting in an effective AML readiness program in place:
The table below provides a list of banks fined over the past four years by regulatory authorities, on account and KYC and AML violations.
| Date | Institution | Regulatory Violation | Fine/Penatly |
|---|---|---|---|
| August 2005 | Arab Bank, New York branch | Bank Secrecy Act failures | US$24m civil penalty |
| February 2005 | City National Bank | Bank Secrecy Act and other money laundering law violations. | US$750,000 fine |
| January 2005 | Riggs Bank | Failure in reporting suspicious activity | US$41m fine |
| December 2004 | Anchorbank Madison, Wisconsin | Filing suspicious activity reports (SARs) and currency transaction reports (CTRs) late. Failure to implement a customer identification program. | US$100,000 civil fine |
| October 2004 | AmSouth Bank Birmingham, Alabama | AML program had deficient internal controls, staff lacked sufficient training, and the independent audits were inadequate. It also had numerous reporting violations and was ‘willfully blind’ to its lack of internal controls. | US$10m civil money penalty, US$40m civil forfeiture and deferred prosecution |
| September 2004 | Citibank, N.A. Japan | Lax control over money laundering, contraventions of the Securities and Exchange Law. | Licences withdrawn for four offices engaged in private banking |
| September 2004 | Bank of Ireland | Failure to comply with money laundering rules, failure to have adequate systems and controls in place to detect a series high risk cash transactions and lack of employee understanding of AML responsibilities. | US$672,000 fine |
| May 2004 | Riggs Bank | Violations of AML laws. | US$25m civil penalty |
| March 2004 | Hudson United Bank | Inadequate AML compliance program. | US$5m fine |
| January 2004 | Bank of Scotland | Failure to keep proper customer identification. | GBP£1.25m fine |
| December 2003 | Abbey National Bank | Inadequate money laundering controls. | US$3.5m fine |
| August 2003 | Northern Bank ( Northern Ireland-based unit of National Australia Bank) | Failed to comply with regulations that compel banks to take steps to identify customers. | GBP£1.25m |
| August 2003 | Western Union | Inadequate money laundering control procedures and failure to file CTRs. | US$5m fine |
| March 2003 | Western Union | Failure to file CTRs. | US$3m fine |
| January 2003 | Banco Popular de Puerto Rico | Failure to file SARs. | US$21.6 forfeiture and deferred prosecution |
| December 2002 | Broadway National Bank, of New York | Failure to file SARs and failure to maintain an AML program. | US$4m fine |
| December 2002 | Western Union | Inadequate compliance program and failure to file SARs and CTRs. | US$8m fine |
The chart below gives an estimate of the amounts being spent by US financial institutions on different components of AML programs in 2005.

Though the primary objective of AML related-investments has been to comply with the regulatory risks in order to protect the bank against financial, operational, legal and reputational risks, banks can leverage investments in AML solutions to derive business value extending beyond regulatory compliance. In the past, AML solutions were specific to meeting the immediate regulatory requirements and consisted of monitoring and alert-generation tools implemented in the high-risk areas of the bank, and as such were not expensive. This was a time when banks considered compliance as a cost centre, requiring investments only in basic technology to meet the regulatory requirements. They were not scalable and adaptable to the changing regulatory environment and over time required banks to make more investments in this area to constantly upgrade the AML technological capabilities.
The AML products which are now gaining popularity come at a higher price as the basic requirement currently is the need to provide transaction monitoring tools that are able to detect potentially suspicious activity indicating money laundering and terrorist financing. The technologies used in these solutions provide banks with opportunities to derive quantifiable value beyond basic regulatory compliance.
Banks can derive business value from AML solutions in the following ways:
Customer relationship management (CRM) requires aggregation and reporting of customer transaction data in a manner that is possible to ascertain the customer behavior, preferences and transaction patterns. It requires an up-to-date and real-time analysis of the vast amounts of customer transaction data that is flowing through various applications in the bank. An enterprise-wide AML solution with the ability to pull data from all systems and applications would mean that it is closely integrated with all the channels and data points through which customer transactions flow in the bank. This kind of solution will have the ability to analyze customer transaction and profile data and then extract, store and aggregate data to understand customer behavior, thereby enabling banks to use this for CRM constituents such as customer profitability analysis, data mining and marketing.
The ultimate objective of any CRM initiative is to have a single view of all customer activity so that the bank can understand customer’s business habits and preferences and enrich customer analysis therefore enabling them to serve them better. The new-generation AML solutions with their advanced data management capabilities can help banks in realizing this aim, thus enabling banks to derive business value from regulatory prompted investments.
Investing in an AML solution is no longer a simple cost consideration and banks need to consider the flexibility and adaptability to changing regulatory requirements as well as deriving business value in the form of better and comprehensive regulatory compliance and improved customer relationships.