Financial intelligence units (FIU) play an important role within many banks in the fight against financial crime by centralizing the investigation and response to financial crime risk events and other issues relevant to supervisory authorities. A bank FIU may be made up of a number of investigative teams specializing in the analysis of customer data that are indicative of money laundering or terrorism financing, sanctions evasion or bribery and corruption.
Some FIUs extend their work to include the investigation of fraud. Banks with operations in multiple countries often have a Group FIU performing a similar role for the entire Group. The term FIU also commonly refers to national-level supervisory authorities and regulators that perform an investigative function and serve to bridge the gap between banks and law enforcement agencies.
With those factors in mind, it is important that banks understand the investigative role that their FIU should perform as part of their risk management infrastructure, and how it may interact with financial authorities when called upon to do so.
What does an FIU do?
The role of an FIU within a bank is to identify, investigate and mitigate financial crime risks. In order to carry out financial crime investigation, a FIU will collect and analyse customer data, and examine key customer AML/CFT information, including internal watchlists and previous investigations, that are generated by a range of Know Your Customer (KYC) and Anti-Money Laundering (AML) measures. This process includes investigating suspicious transactions, changes to customer risk profiles, sanctions alerts, and adverse media stories. Following analysis, the FIU must determine whether the information they have gathered warrants the submission of a suspicious activity report (SAR), or other filing, to the relevant law enforcement authorities.
During their investigatory process, FIUs may liaise with bank compliance employees, or review both private and public data sources to obtain further information on customers. Where permitted, FIUs may also share details of their internal investigations with other banks to understand how individual banks are being exploited by criminal networks. Similarly, FIUs may participate in subsequent investigations, providing support to law enforcement agencies.
The core functions of an FIU are as follows:
Financial Crime investigations: Prior to the submission of SARs to the relevant authorities, FIUs must investigate risk events to determine whether there has been a breach of the law – and whether a law enforcement investigation is needed. Given the amount of data involved in investigations, FIUs should seek to integrate analytic software in order to prioritize their workload, increase accuracy, and ensure the process takes place as quickly and efficiently as possible.
During the investigative process, FIUs may seek supporting material on a particular customer, or may engage internal experts to scrutinize data more closely. FIUs may reference a range of data sources during their analysis, including publicly available company registers, sanctions lists, and adverse media stories. It may be necessary to reference other internal integrations, including transaction monitoring solutions, screening solutions, enhanced due diligence output, and client data stores.
External resources may also be relevant, including publicly available resources such as the Panama Papers, the Paradise Papers, and so on. FIUs must be able to fuse this data into actionable information, resolving information across different sources from which it is drawn in order to establish an actionable case narrative.
AML/CFT reporting: FIUs act as intermediaries between their banks and the authorities. Accordingly, bank FIUs must determine whether it is appropriate to submit a suspicious activity report when their transaction screening solutions detect certain trigger activities. Examples of suspicious activity that should be reported to FIUs include:
- Transactions above jurisdictional AML/CFT reporting thresholds.
- Unusual patterns of transaction, such as transaction in unusual volumes or frequencies
- Transactions with high-risk AML/CFT jurisdictions
- Transactions that do not match a customer’s established risk profile
Supporting investigations: When FIUs complete internal investigations and submit SARs to regulatory authorities, they may be required to share further information with the authorities to support ongoing investigations. Accordingly, FIUs should seek to make their relationship with authorities as efficient as possible in order to address incidents as quickly as possible and to contribute to national efforts to fight financial crime.
Partnerships: To better contribute to the long-term fight against financial crime, bank FIUs should seek to work in partnership with the wider financial community, sharing information, and building relationships not just with law enforcement agencies but other banks and government bodies. In order to operate in compliance with privacy and data protection laws, FIUs should seek to establish parameters for the legal exchange of AML/CFT information (for example, in the UK, by using the provisions of the Criminal Finances Act), become members of regional Financial Information Sharing Partnerships (FISP) such as the Joint Money Laundering Intelligence Taskforce (JMLIT), and participate in industry data exchange platforms such as the SWIFT KYC Registry.
AML/CFT policy: FIUs should work to identify and manage their banks’ AML risks and vulnerabilities, and use that information to establish new compliance policies and targets. FIUs may discover that new approaches clash with established AML/CFT compliance protocol and should seek to find ways to integrate technology solutions that serve the needs of their customers and their institution.
Additional functions: Beyond their investigatory role, FIUs work to support their banks’ efforts to achieve AML/CFT compliance goals. That work may involve:
- Strategic analysis: FIUs may perform ongoing strategic analysis of their bank’s exposure to risk, beyond law enforcement relevance and without an alert being triggered. Strategic analysis may, for example, involve assessment of the risk that AML/CFT related incidents, such as the Paradise Papers leak, entail.
- Monitoring AML/CFT compliance: FIUs may be able to exert some supervisory influence within their banks, monitoring products and services to ensure compliance with AML/CFT regulations.
- Blocking transactions: If it is related to serious criminal activity, or prohibited by a sanction restriction, for example, FIUs may be required to block a transaction from taking place before law enforcement agencies can step in to investigate.
- Training employees: By training employees in the latest compliance rules and regulations, FIUs can improve the flow and quality of the data they receive from their colleagues. Employee training not only improves a bank’s internal AML/CFT compliance performance but deepens individual understanding of the role the FIU plays .
- Conducting research: By initiating and conducting research projects, FIUs can better adapt to emerging criminal methodologies and evolving legislative landscapes – while enhancing their own analytic capabilities.
- Enhancing public awareness: By helping the public understand what it does, and how it combats and investigates criminal incidents, an FIU increases the potential for external cooperation and positively influences the wider fight against money laundering and the financing of terrorism.
Please get in touch to learn more how Ripjar can help Financial Intelligence Units.
The Financial Conduct Authority (FCA) is an independent regulatory body responsible for overseeing the UK’s financial markets and services. Established under the authority of the Financial Services Act (2012), FCA was introduced on 1 April 2013, replacing its predecessor, the Financial Services Authority (FSA). FCA shares its regulatory responsibilities with the Bank of England’s Financial Policy Committee (FCP), and the Prudential Regulatory Authority (PRA).
What does the FCA do?
The FCA oversees over 51,000 financial service providers in the UK including banks, financial advisers, and mutual societies. In its oversight role, the FCA has three objectives:
- To protect consumers of financial products
- To enhance the integrity of the UK’s financial industry
- To ensure effective competition between UK financial service providers in the interests of consumers
In order to achieve its stated objectives, FCA has a range of duties and powers, including investigating financial services providers that violate the UK’s compliance regulations – principally the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 and the Proceeds of Crime Act 2002 (POCA). In practice, the FCA’s responsibilities include:
- Authorization: The FCA is responsible for authorizing banks and financial service providers to operate in the UK. In order to obtain an operating license, organizations must submit an application to the FCA demonstrating that they have met a set of regulatory criteria.
- Supervision: The FCA supervises UK banks and financial service providers against a ‘framework of principles and rules’ in order to protect consumers and financial markets from harm.
- Enforcement: Where compliance violations are found, FCA has the power to force firms under its jurisdiction to change the way they do business, impose remedial requirements, and issue significant financial penalties. The FCA’s enforcement powers take in criminal and civil measures, and include:
- Prohibition of firms and individuals from carrying out regulated activities
- Fines for firms and individuals found to have violated compliance regulations
- Criminal prosecution against firms and individuals suspected of financial crimes
- Publications or public announcements of disciplinary actions
FCA Rules and Regulations
The FCA has issued a list of conduct rules for both firms and individuals to help them comply with the UK’s financial crime laws, including the Money Laundering Regulations and the Proceeds of Crime Act. The conduct rules are set out in the FCA Handbook and comprise two tiers, one for individuals and one for senior managers working within the financial services industry:
Tier one: individual conduct rules
- You must act with integrity
- You must act with due care, skill, and diligence
- You must pay due regard to the interests of customers and treat them fairly
- You must observe proper standards of market conduct
Tier two: senior manager conduct rules
- You must take reasonable steps to ensure that the business of the firm for which you are responsible is controlled effectively
- You must take reasonable steps to ensure that the business of the firm for which you are responsible complies with the relevant requirements and standards of the regulatory system
- You must take reasonable steps to ensure that any delegation of your responsibilities is to an appropriate person and that you oversee the discharge of the delegated responsibility effectively
- You must disclose appropriately any information of which the FCA would reasonably expect notice
How to Comply with FCA Rules
The FCA expects banks and financial service providers to develop solutions to ensure that they operate in compliance with the UK’s financial crime legislation. In practice, this means that UK firms must implement a range of measures and controls, backed by financial intelligence technology, to detect and assess the criminal risks that they face. These should include:
- Customer identification: UK firms should perform suitable due diligence on their customers to accurately establish and verify their identities and the nature of their business.
- Transaction monitoring: UK firms must monitor their customers’ transactions for signs of financial crime, including unusual transaction patterns, and transactions with high-risk counterparties or jurisdictions.
- International sanctions: UK firms must screen their customers against the relevant sanctions lists, including the UK’s autonomous sanctions list, and international sanctions lists such as the UNSC consolidated list.
- Politically exposed persons: UK firms should establish whether their customers are politically exposed persons (PEP) – and therefore pose a greater risk of financial crime such as money laundering.
Adverse media stories: UK firms should screen regularly for adverse media stories that involve their customers. News media may signal a customer’s involvement in financial crime prior to confirmation by official sources.
Recent FCA Activity
Throughout 2021, the FCA focused on addressing the concerns of a changing financial landscape, and the criminal threats that emerged as a result of the Covid-19 pandemic. Amongst the initiatives that it launched in 2021, were the InvestSmart campaign and the Scamsmart campaign, both intended to protect consumers from fraudulent financial activity, including investment scams and cyber-crime.
The FCA is also focusing on corporate AML compliance and issued a series of significant fines throughout 2021. Notable examples of FCA AML compliance fines in 2021 include a £147 million fine for Credit Suisse, a £63.9 million fine for HSBC, and a fine of over £264 million to NatWest.
The FCA is currently working to raise awareness of the dangers posed by cryptocurrencies and ensure cryptocurrency service providers operate in compliance with the UK’s financial regulations. That effort saw 223 FCA registration applications from cryptocurrency service providers in 2021 and, in January 2022, an FCA proposal for a regulatory crackdown on high risk cryptocurrency investments.
FIND OUT HOW RIPJAR CAN HELP YOU Comply with FCA regulations. PLEASE GET IN TOUCH.
2021 was another difficult year for the financial industry as the effects of the coronavirus pandemic continued to create negative consequences for banks and financial institutions. That trend included a range of new compliance challenges as service providers and financial regulators adapted to a shifting risk landscape and an array of emerging Covid-19-inspired criminal methodologies.
The amount of AML fines issued in 2021 reflects the increased regulatory scrutiny. After investigations are completed, 2021’s AML fines are expected to exceed $2.22 billion – matching the 2020 total. With those figures in mind, numerous regulators took significant enforcement actions against banks and financial institutions under their jurisdiction in 2021. Some notable examples from around the world include:
Financial Conduct Authority (FCA): United Kingdom
In 2021, the UK’s Financial Conduct Authority prioritized the threat of cyber-crime, which increased during the Covid-19 pandemic as customers transitioned en-masse to online banking and financial services. The FCA also focused on corporate compliance, opening around 1,293 enforcement cases and issuing around £189.8 million in penalties.
While FCA issued a £147,190,200 compliance fine to Credit Suisse in October 2021, its largest fine came at the end of the year, when it handed down a fine of over £264 million to NatWest for significant failures to monitor and report suspicious transactions related to jeweler Fowler Oldfield. In the final days of 2021, FCA also issued a fine of £63.9 million to HSBC for failing to address long-term weaknesses in its transaction monitoring controls. Another notable FCA fine handed down in the final days of 2021:
Enforcement target bank: National Westminster Bank PLC (NatWest)
Reason for enforcement action: Significant AML compliance failures
Amount of fine: £264,772,619.95
Australian Transaction Reports and Analysis Center (AUSTRAC) – Australia
In 2020, Australian Transaction Reports and Analysis Center took a significant enforcement action against the Westpac Banking Corporation for serious breaches of Australia’s AML/CFT Act, including a failure to implement transaction monitoring and customer due diligence controls. AUSTRAC ultimately handed Westpac a record $1.3 billion fine. In 2021, Westpac was fined an additional $113 million by the Australian Securities and Investment Commission (ASIC) which cited the bank’s ‘poor compliance culture’ as a factor in its misconduct.
In 2021, AUSTRAC maintained its focus on corporate enforcement but did not issue any AML fines. AUSTRAC did, however, issue a remedial direction to Australian Military Bank Ltd (AMB) to ‘review and uplift’ its compliance with AML/CFT laws. The direction included requirements that AML submit to an independent audit, enhance its AML/CFT reporting protocols, and then submit to an additional audit to ensure the implementation of those measures. In June of 2021, AUSTRAC revealed an investigation into National Australia Bank NAB) for ‘potential serious and ongoing non-compliance’.
Enforcement target bank: Australian Military Bank
Reason for enforcement action: AML compliance deficiencies
Amount of fine: N/A (remedial direction)
Office of Foreign Assets Control (OFAC) – United States
Under President Biden, the US continued to emphasize sanctions compliance, building on trends established during the Trump administration, which took a record 3,900 sanctions actions between 2016 and 2020. In 2021, the Office of Foreign Assets Control took 20 separate enforcement actions against individuals and organizations, totaling $20,896,739.22 in fines. The largest OFAC sanctions fine was issued in January against Union de Banques Arabes et Françaises for violations of the US’ Syria sanctions program.
Enforcement target bank: Australian Military Bank
Reason for enforcement action: Violation of US Syria sanctions program
Amount of fine: $8,572,500
Bank Secrecy Act (BSA) – United States
The BSA is the US’ primary AML legislation and is enforced by the Financial Crime Enforcement Network (FINCEN). In 2021, FINCEN imposed several significant AML fines against US banks and other financial service providers for failures to comply with the requirements of the BSA. FINCEN issued its most significant fine against credit card company, Capital One, in January 2021, for willful and negligent violations of the BSA, including a failure to file thousands of suspicious activity reports and currency transaction reports. The fine amounted to $390 million.
Enforcement target bank: Capital One
Reason for enforcement action: Violation of the Bank Secrecy Act
Amount of fine: $390,000,000
Monetary Authority of Singapore (MAS) – Singapore
Like other regulatory authorities, the Monetary Authority of Singapore focused on addressing the financial challenges of the Covid-19 pandemic during 2021. The regulator took several enforcement actions in response to violations of the Corruption, Drug Trafficking and Other Serious Crimes Act (CDSA), including a S$1 million fine for Bank J Safra Sarasin for ‘serious breaches of MAS’ AML/CFT requirements’. However, MAS most significant fine of 2021 was issued against Goldman Sachs’ Malaysian subsidiary as part of a deferred prosecution agreement with the US Department of Justice over the 1Malaysia Development Berhad scandal. Under the penalty, Goldman Sachs was required to pay the Singapore government $122 million.
Enforcement target bank: The Goldman Sachs Group Inc
Reason for enforcement action: Violations of the Prevention of Corruption Act
Amount of fine: $122 million
Looking ahead to 2022, with a potentially-reduced focus on Covid 19, it will be interesting to see how regulators choose to execute their oversight responsibilities.
FIND OUT HOW RIPJAR CAN HELP YOU with aml and risk compliance. PLEASE GET IN TOUCH.