Month: November 2021

Adverse Media And The Importance Of Risk Categorization

Adverse media is an important tool in the fight against financial crime. News stories can reveal important information about a customer’s involvement in crime long before that information is officially confirmed by government or law enforcement sources. However, the scope of the adverse media landscape means that organizations must screen against a vast amount of information in order to ensure their customer risk profiles are as up-to-date and accurate as possible.

Managing adverse media is a significant administrative challenge. The incoming information may be incorrect, irrelevant, confusing, and contradictory, and organizations may expend significant effort attempting to scrutinize it effectively for actionable financial crime data. By contrast, screening solutions that are deployed with too narrow an adverse media focus may miss important stories, and develop potentially costly risk blindspots.

The power of categorization

Ideally, an organization should be able to categorize the adverse media information that they collect in order to cut down on administrative noise and to better gauge the significance of each story as part of the risk-based approach to regulatory compliance recommended by the Financial Action Task Force (FATF). Under a risk-based approach, organizations must assess their customers individually, and then deploy compliance measures commensurate with the risk that those customers present. Adverse media should inform that process, adding depth to customer profiles and serving to alert organizations of meaningful changes to the risk they present. 

It is important to remember that categorization isn’t a one-size-fits-all solution: the accuracy and recall capabilities of the technology that an organization uses will have a significant effect on the outcomes of adverse media searches. A platform that uses sophisticated money laundering classifiers, for example, may be able to capture adverse media data with greater nuance and depth than a platform that uses more simplistic keyword searches.   

Individual organizations will inevitably approach adverse media categorization differently, and in a manner that reflects their risk landscape. Similarly, organizations should understand how different categories of adverse media relate to their unique compliance concerns. With those factors in mind, an adverse media screening solution may organize stories into the following categories:

Criminal and non-criminal

While many adverse media stories denote explicit criminal liability, non-criminal adverse media stories may still be useful as a way of informing customer risk profiles or highlighting potential criminal liabilities that may emerge in the future. Similarly, the legal status of certain behaviors may change in the future or be classified as illegal in other jurisdictions.

Anti-Money Laundering risk

Adverse media may be sourced from the conventional screen and print media sources, or from a diverse landscape of online media sources. The categorization of analogue and online sources may inform the credibility of adverse A broad spectrum of news stories may be relevant to anti-money laundering (AML) risk, reflecting the number of predicate crimes that generate illegal funds. Grouping those stories together enables firms to quickly identify the criminal behavior involved, and to gauge the level of risk in relation to their customer or client.

Financial crimes

Financial crime covers a range of offences, including both civil and criminal risk. Some financial activities are explicitly illegal but may also reveal a customers’ involvement in other types of criminal behavior: bribery, for example, is often committed in connection to other crimes such as environmental crime.

Terrorist activities

A range of adverse media stories may reveal customer involvement in the financing of terrorist activities. Stories relating to terrorism may generate significant adverse attention and cover a spectrum of criminal offences – from reading or distributing extremist publications to perpetrating acts of terror.

Regulatory compliance violations

Serious regulatory compliance violations may generate adverse media and may even constitution criminal offences. The categorization of compliance violations, by seriousness or by type, is useful because news stories often feature connections to other criminal activities: reporting violations, for example, may indicate financial misconduct.

Predicate offences

Money laundering and terrorism-related crimes involve a range of predicate offences that have been criminalized in jurisdictions around the world. Predicate offences may generate significant adverse media and vary greatly in terms of seriousness. Sex crimes, for example, may include prostitution, trafficking, and the production of illegal material – all of which generate illegal funds and confer a range of criminal punishments. Similarly, offences such as drug trafficking, theft, cybercrime, and fraud also constitute common predicate offences for money laundering and terrorism.


WANT TO LEARN HOW RIPJAR CAN HELP WITH ADVERSE MEDIA SCREENING? PLEASE GET IN TOUCH.

Ripjar recognised by Chartis in RiskTech100 Ranking

Ripjar is absolutely thrilled to have been recognised by Chartis in their latest RiskTech ranking of the 100 most important global players in Risk and Compliance Management. 

Ripjar’s commitment to innovation in compliance has led us to re-imagine all components in the screening journey. Demanding top tier banks and corporates are recognising our industry-beating performance.

Phil Mackenzie, Research Principal at Chartis commented, “We have been impressed by Ripjar’s approach to complex challenges in counter-party monitoring and beyond, and are delighted to welcome Ripjar to the Chartis RiskTech100.”

Jeremy Annis commented, “I’m delighted to see the hard work and dedication of our engineers and data scientists recognised by Chartis. We look forward to continuing to work closely with Chartis while we continue to invest in innovations which provide our customers with the next generation of compliance solutions.”

6AMLD: 5 Changes Every Compliance Officer Should Know About

The European Union’s Anti-Money Laundering Directives (AMLD) are issued periodically to adjust the bloc’s collective regulatory response to the threat of money laundering and terrorism financing. When the European Parliament hands down a new money laundering directive, EU member-states have an implementation period in which to transcribe the legislation into domestic law and ensure that all domestic banks and financial institutions are compliant. 

Each AMLD broadly reflects changes to the global financial risk landscape, often requiring firms to expand anti-money laundering and counter-financing of terrorism (AML/CFT) measures to new types of service or customer or to adjust to new criminal methodologies. The most recent AMLD was the Sixth Anti-Money Laundering Directive (6AMLD) which was issued on 3 December 2020, with an implementation date of 3 June 2021. 6AMLD broadly strengthened measures introduced in 5AMLD, while adjusting other AML/CFT compliance measures to reflect changing criminal threats. 

With 6AMLD now in legal effect in every EU member state, compliance officers should understand how their organization’s regulatory landscape has changed, and how to manage the new compliance responsibilities that it entails. Although it has left the EU and has opted not to implement 6AMLD, the UK has effectively already implemented the directive’s regulatory requirements in its domestic legislation. Similarly, EEA member states, such as Liechtenstein, or Switzerland (which is a member of the single market) must broadly implement the directive’s terms.

1. Regulatory Harmonization

6AMLD introduced a harmonized definition of the crime of money laundering to be used by each EU member state. The harmonization is intended to remove loopholes and inconsistencies in domestic legislation and address emerging money laundering methodologies that exploit new technologies or regulatory blindspots. 
As part of the regulatory harmonization, the EU set out a list of 22 money laundering offences, including crimes such as tax evasion, insider trading, drug trafficking, and human trafficking. The list of 22 predicate offences included 2 new predicate offences: cybercrime and environmental crime, both of which reflect the EU’s desire to focus on emerging criminal threats and the shifting legislative focus of its member states.

2. Regulatory Scope

In addition to the new predicate offences, 6AMLD expanded the criminal definition of money laundering to include “aiding and abetting”. Accordingly, under 6AMLD, persons that help or enable money launderers to transform illegal money will also be considered guilty of the crime of money laundering – and be charged in the same way. Aiding and abetting takes in persons that attempt to launder money, or that encourage or incite others to launder money. 

The expanded list of predicate offences and the expanded scope of the money laundering offence means that compliance officers should examine their own understanding of the law as it applies within their jurisdiction. Similarly, they should ensure that their internal AML programs are capable of capturing the new risk exposures that the adjusted definitions create. 

3. Criminal Liability

6AMLD expanded the scope of criminal behaviour associated with money laundering but also changed the way that criminal liability applies to the offence. Prior to 6AMLD, only individual criminals could be held liable for money laundering offences: under the new regulations, criminal liability is extended to legal persons, which means that organizations can be punished for offences committed by the people that work for them. Organizations that are found guilty of money laundering face a range of penalties, including supervision orders or operational bans. 
The change means that responsibility for corporate criminal conduct falls on management personnel in addition to individual employees. By expanding criminal liability, the EU is signaling that larger companies will be held to account under their regulatory regime and be expected to actively contribute to the global effort to combat financial crime.

4. Money Laundering Punishments

Under 6AMLD, the EU moved to address inconsistencies in money laundering punishments across member-states by increasing the minimum prison sentence for money laundering. Prior to the directive, the minimum prison sentence for individuals found guilty of money laundering was 1 year: under the new rules, the minimum sentence has increased to 4 years. 

The increased sentences may not represent a significant change for many member states since they already mandate 4-year minimums (or longer) but will serve to bring outliers with lower sentences into alignment with the rest of the bloc. While it has not implemented 6AMLD, the UK’s money laundering punishments are harsh, with maximum prison terms of between 2 to 14 years depending on the severity of the crime for those found guilty of offences. 
6AMLD’s sentencing changes also include discretion for judges to impose fines on individuals found guilty of money laundering and to prevent corporate entities found guilty of money laundering from accessing EU public funding programmes.

5. Dual Criminality

In another important step, 6AMLD has introduced changes to the way member states address dual criminality as it applies to the crime of money laundering. Dual criminality refers to crimes that span international borders – in the context of money laundering, it involves illegal funds that are laundered in a country other than the one in which they were acquired. 

Under 6AMLD, member-states have specific information sharing and cooperation requirements to facilitate dual criminality money laundering prosecutions. In order to implement those changes effectively, some member-states may need to treat certain predicate offences as criminal offences regardless of whether they are illegal. These offences are: 

  • Involvement in organized crime
  • Human trafficking and smuggling
  • Sexual exploitation
  • Drug trafficking
  • Corruption

6AMLD also sets out guidance for authorities to determine where a dual-criminality money laundering prosecution should take place. That guidance suggests that member states should consider the location of the original victim of the predicate offence, the nationality of the offender, and where the money laundering offence took place.

Adapting to 6AMLD

Since it is now in effect, all banks and financial service providers in the EU must ensure that they are compliant with 6AMLD. In practice this means that compliance officers should review their internal compliance solutions to account for the adjustments to predicate offences and criminal liability. The following measures may be particularly important: 

  • Ensuring organization-wide understanding of 6AMLD’s new definition of money laundering and the 22 money laundering predicate offences. 
  • Reviewing criminal liability for potential money laundering offences, including the conduct of senior and management employees. 
  • Adjusting risk assessment procedures for alignment with the new risk landscape. 
  • Training compliance employees to meet their new obligations.
  • Implementing suitable technology solutions to ensure ongoing compliance with 6AMLD. 

Screening obligations: 6AMLD’s expanded regulatory scope includes a requirement for firms to adjust their compliance screening solutions, including implementing enhanced customer due diligence for higher risk customers. In practice this means that firms must conduct “open source or adverse media searches” for occasional transactions and periodically throughout business relationships, in order to be aware of any emerging risk exposure.


GET IN TOUCH TO LEARN HOW RIPJAR CAN HELP YOU To Comply With 6AMLD

Customer Due Diligence (CDD): What Banks and Financial Institutions Need to Know

In order to understand the compliance risks that they face, financial institutions must validate the identities of their customers and ensure that they are being truthful about their business interests by performing suitable customer due diligence (CDD). A critical foundation of any Know Your Customer (KYC) process, CDD is recommended by the Financial Action Task Force (FATF) as part of a risk-based approach to anti-money laundering and is required by financial regulators in jurisdictions around the world. 

To achieve regulatory compliance, firms should understand why customer due diligence is  an important part of the regulatory process and how to deploy it as part of their risk management solution.

What is Customer Due Diligence (CDD)?

Customer due diligence refers to the process of identifying customers and ensuring that they are being truthful about who they are and how they are using an organization’s services. In a financial context, banks and financial institutions must perform CDD in order to inform their risk-based compliance solutions, using the information they gather to make important compliance decisions. 

Accordingly, CDD requires organizations to collect and analyze a variety of data and documentation and verify that data to a sufficient level of confidence. The effectiveness of many critical compliance processes, such as sanctions list and adverse media checks, is predicated on the verification of customer identities during the due diligence process.

Why is CDD important?

CDD is an important tool in the fight against money laundering and the financing of terrorism. Criminals that are seeking to transform illegal funds must find ways to introduce those funds into the legitimate financial system by concealing their identities as a way to avoid AML/CFT controls. CDD provides organizations with a way to identify those customers and deploy suitable compliance measures against them in order to prevent financial crimes. 

CDD is especially important in complex or higher risk financial service environments such as the digital platforms provided by challenger banks. In these environments, money launderers take advantage of the inherent speed and anonymity of online financial services to better conceal their identities, submitting false or incomplete identifying information or even using proxies to access financial services.

What does CDD involve?

Effective CDD involves the following key considerations:

Identifying information: The data that organizations collect to establish a customer’s identity should include name, address, date of birth, business incorporation number, and any other documents that are relevant to their risk profiles. That data must be sourced from official documents, such as passports and driving licenses, and verified by the collecting institution. 

Beneficial ownership information: In some cases, it may be difficult to perform CDD because a transaction involves a commercial entity rather than an individual customer. In these situations, organizations must work to establish ultimate beneficial ownership (UBO) to ensure that criminals are not using shell companies or corporate infrastructure to evade compliance controls. 

What is risk-based CDD? And what is EDD?

Following Financial Action Task Force (FATF) guidance, an organization’s CDD process should form part of a risk-based compliance solution. Risk-based compliance requires firms to assess their customers individually to establish the risk level and then deploy a compliance response commensurate with that risk. In addition, risk-based compliance is a way for organizations to balance their regulatory obligations with their budgetary needs by ensuring that AML resources are directed towards worthwhile targets. With that in mind, higher risk customers may be subject to more intensive compliance measures, while lower risk customers may be subject to simplified measures. 

n a CDD context, higher risk customers should be subjected to enhanced due diligence (EDD) measures which go beyond the level of scrutiny required by standard CDD. EDD is generally more rigorous than standard CDD and might require a customer to provide a greater amount of identifying information or provide a greater degree of verification – such as copies of personal bank statements. In some cases, organizations may engage a third-party to investigate their customers and the identifying information that they have provided. EDD might also integrate peripheral screening considerations more extensively: adverse media stories, for example, may be regarded as a more significant additional check when deployed as part of EDD measures.

How can technology enhance CDD?

Since CDD can represent a significant compliance burden, organizations should seek to integrate suitable compliance technology to help facilitate the process. The speed and accuracy of software automation not only helps firms handle their CDD data collection and analysis obligations but enhances customer experiences at onboarding and reduces the potential for costly compliance errors. 

With the benefit of smart technology, firms may also use data collected during the CDD process to create deeper and more informative customer risk profiles, and to make better compliance decisions when customers diverge from expected financial behaviors or generate AML/CFT alerts. Similarly, smart technology can help firms adjust quickly to changes in AML/CFT legislation or adapt to emergent criminal methodologies, such as novel methods of avoiding identity verification. 


Get in touch to learn how Ripjar can help you with CDD and EDD.