The Financial Action Task Force (FATF) has released its latest Mutual Evaluation Report (MER) on Germany. As a intergovernmental anti-money laundering (AML) and counter-financing of terrorism (CFT) regulator, the FATF conducts mutual evaluation reports on its members in order to gauge their compliance with the regulatory standards that it sets – specifically its 40 Recommendations. The MER process is in-depth and, when published, sets out details of the country’s AML/CFT compliance performance along with recommendations for regulatory improvements to help combat financial criminal threats.
The FATF released its Germany MER in August 2022. As a prominent regional and global economy, Germany’s response to the MER will have consequences both for the businesses that operate within its borders and those beyond. Given that significance, it is important that firms in Germany understand the contents of the latest MER and what consequences it may have for Germany’s regulatory landscape.
German AML/CFT Progress
The FATF found that while Germany continues to face significant financial criminal threats, its regulatory response is generally well-suited to managing risks, and its financial institutions are generally well supervised by the Federal Financial Services Authority (BaFin) and the Financial Intelligence Unit (FIU). Similarly, Germany’s authorities are effective at detecting and prosecuting terrorism financing threats within its financial system.
The FATF also found that Germany made “significant improvements” to its AML/CFT framework in the five years since its last assessment. Notable AML/CFT advances included:
Use of the National Risk Assessment (NRA) process as a way to enhance the national understanding of money laundering risks.
Introduction of cooperation and coordination mechanisms between federal and state governments.
Boosting human resources for state financial regulator BaFin and the FIU.
Removing asset recovery limitations for money laundering offences.
Introduction of a Transparency Register to allow improved access to beneficial ownership information.
FATF AML/CFT Recommendations
While the FATF praised positive developments in Germany’s approach to AML/CFT regulation, it also stressed a need to address a range of regulatory deficiencies. The key areas for regulatory attention included:
Sources of Risk
Although Germany had demonstrated a strong response to domestic money laundering and terrorist financing risks, its perspective of the wider risk landscape was limited.
The FATF found that the regulatory focus on money laundering risks from real estate and cash was causing German authorities to “overlook other important risks” such as those created by complex corporate structures including shell companies and foreign companies. This kind of threat was attributed to Germany’s status as a global financial hub, which made it a target for international financial criminals. The FATF noted that German law enforcement authorities “tend to focus on natural persons” rather than foreign criminals and professional enablers, an approach which ends up “limiting the information available for assessing risks”.
Correspondent Banks
The FATF noted that, as an international destination for financial services, Germany faces a significant money laundering threat from the higher risk correspondent banking sector. The MER found that German correspondent banking institutions had problems with the scope and accuracy of the data that they were accessing to address and verify those types of banking threats.
In order to improve the way that correspondent banks access and utilise their AML/CFT data, the FATF noted that Germany should accelerate the integration of advanced analytics technologies within public and private sector compliance frameworks. In particular, larger correspondent banks should seek to integrate bespoke technology solutions to address the increased AML/CFT risk that they face.
Risk Assessment
While the FATF found that Germany’s larger financial institutions tended to address their risk exposure with suitable customer due diligence (CDD) measures, smaller institutions, institutions outside the financial sector, and designated non-financial businesses and professions (DNFBP) were not matching that response. In particular, the FATF found that the weaker level of risk understanding from these institutions was negatively impacting “their ability to develop and implement preventative measures aligned to their ML/TF risks”.
The FATF characterised this deficiency as a “reactive rather than proactive” approach to risk based anti-money laundering with the implication that regulators need to take a unified, strategic approach to the problem, strengthened by coordinated AML initiatives such as data-sharing between financial and non-financial organisations.
Sanctions Implementation
The FATF identified failings in the implementation of global economic sanctions amongst firms in Germany’s financial sector. In particular, the FATF criticised Germany for not proactively designating individuals listed on international sanctions lists (such as the UNSC list) in its domestic legislation in line with its AML/CFT strategy.
Similarly, the FATF noted that German regulatory supervision of sanctions compliance was “not fully effective”, with the problem again particularly notable “in the DNFBP sectors”. It also criticised the impact of German financial sanctions on their targets, suggesting that, for example, the amounts of assets frozen in sanctions actions were low “compared to total amounts raised in Germany”.
German FATF Compliance
Germany has committed to addressing the AML/CFT issues raised by its 2022 MER, which placed a strong focus on risk management and customer data. With that in mind, German regulators are likely to emphasise a need for accurate and agile risk management, with a need for firms to integrate software solutions tailored to their specific compliance needs.
With that challenge in mind, Ripjar’s Labyrinth Screening platform is a powerful compliance tool that enables firms to screen against thousands of global risk data sources in real time, including sanctions lists, PEP lists, and adverse media sources in 21 languages. Integrating cutting edge machine learning technology, Labyrinth seamlessly blends structured and unstructured data enabling firms in Germany to stay in control of their risk environments. As the German government responds to the FATFs findings, Labyrinth will also help firms adjust quickly and efficiently to new legislation with tailored risk management solutions – ensuring you stay compliant even as customer risk profiles change.
To learn more about how Labyrinth Screening can support your risk management in Germany, contact us today.
We’re proud to share that Ripjar has been recognised as a category leader in the 2022 Chartis RiskTech Quadrant for Name Screening.
Chartis Research is the leading provider of research and analysis for the global risk technology market. As part of their mission to provide in-depth analysis and advice on all aspects of risk technology, they produce reports on watchlist screening and monitoring solutions, including name screening.
The name screening segment considers a number of criteria, including each solution’s ability to handle naming convention challenges, enrich data with additional information, screen large data volumes, and its speed and efficiency.
Solutions are assessed on the completeness of their offering and their market potential. Scoring highly in both areas, Ripjar has been ranked as a category leader.
“Ripjar’s innovative approach to solving real market challenges, based on advanced technology and analytics capabilities, makes it an exciting player in the name screening space,” said Nick Vitchev, Research Director at Chartis. “Its focus on tackling highly complex client challenges with an effective tech-first approach is reflected in its category leader status in Chartis’ 2022 name screening quadrant.”
About Ripjar’s Labyrinth Screening Platform
With global events resulting in a rapidly-evolving sanctions environment, and regulatory compliance increasingly requiring adverse media screening, comprehensive name screening is more important than ever.
The latest release of Ripjar’s Labyrinth Screening platform includes innovative new AI Risk Profiles. This feature enables organisations to screen across vast amounts of structured and unstructured data with increased accuracy, efficiency and effectiveness. It reviews sanctions list, watchlist, PEP and adverse media data to build enriched, discrete profiles for individuals and organisations, reducing false positives and significantly reducing analyst workloads.
Ransomware is a type of malicious software that encrypts a target computer or network so that its owners cannot access their stored data. The criminals in control of the ransomware then demand money – a ransom – from their victims in order to enable access. Since ransomware attacks take place online, victims rarely know who they are paying ransoms to, or understand the regulatory compliance risks associated with such payments. In 2021, it is estimated that ransomware cost global businesses around $20 billion, with that figure expected to rise to over $256 billion by 2031. However it is notoriously difficult to gauge the real costs as many organisations will not admit to paying a ransom.
In response to the significant criminal threat, global regulators and law enforcement authorities are increasing their focus on detecting and preventing ransomware attacks by imposing a range of penalties against those that launch them. In the case of state sponsored attacks, that also includes imposing sanctions. However, whatever actions regulators take, it is crucial that organisations remain vigilant by understanding ransomware risks and how to avoid falling victim to an attack.
Ransomware and Global Sanctions
Ransomware attacks are a popular criminal methodology amongst international criminals – and are often used to work around the restrictions imposed by international economic sanctions.
The crippling effect of ransomware attacks mean that their victims may be inclined to make ransom payments to unknown criminals in order to free their data, despite the potential sanctions risk associated with doing so. Ransomware is such an effective way of thwarting sanctions measures and raising illegal funds that many ransomware attacks are sponsored by the governments of sanctioned countries, and deployed as part of extensive criminal campaigns targeting organisations in the media, energy, communications, and financial industries.
Recent examples of state-sponsored ransomware attacks include North Korea’s ‘Maui’ ransomware attack on US healthcare organisations in 2021, and Russia’s ‘NotPetya’ ransomware attack on Ukraine in 2017, which originally targeted financial, energy, and government networks but subsequently spread indiscriminately into Europe and back into Russia.
OFAC Ransomware Sanctions 2022
In September 2022, the US Treasury’s Office of Foreign Assets Control (OFAC) announced that it was imposing sanctions against several individuals and entities affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC).
The sanctions followed an OFAC investigation that revealed the individuals and entities were behind a series of ransomware attacks against networks owned by US and global organisations. OFAC was also able to link the attacks to a number of Iranian state-sponsored hacking groups, known to cybersecurity entities as Nemesis Kitten, DEV-0270, APT35, Charming Kitten, Phosphorus APT, and Tunnel Vision. The ransomware attacks perpetrated by those groups included:
An attack on a New Jersey municipality in February 2021 that exploited a Fortinet vulnerability.
An attack on Microsoft Bitlocker in March and April 2021, in which decryption keys were held for ransom. Numerous small businesses were impacted by the attack.
An attack on a US children’s hospital in June 2021 in which a group gained supervisory control of the network and of data acquisitions systems.
A series of attacks from June to September 2021 targeting transportation, healthcare, emergency services, education, and energy providers.
The IRGC-linked group sanctioned by OFAC is made up of employees and associates of Najee Technology Hooshmand Fater LLC and Afkar System Yazd Company. The list includes:
Managing directors Mansour Ahmadi (Najee Technology) and Ahmad Khatibi Aghda (Afkar System).
Employees of Najee Technology and Afkar System: Mojtaba Haji Hosseini, Mohammad Shakeri-Ashtijeh, Mo’in Mahdavi, Aliakbar Rashidi-Barjini, Amir Hossein Nikaeen Ravari, Mostafa Haji Hosseini, Ali Agha-Ahmadi, and Mohammad Agha Ahmadi.
Individuals linked to NET Peygard Samavat Company – as a result of links to the IRGC and the Iranian Ministry of Intelligence and Security.
OFAC’s sanctions mean that the assets of the Iranian persons designated have been frozen in the US, and US persons are prohibited from doing business with them. US firms that violate OFAC sanctions risk significant criminal penalties, while non-US firms risk being sanctioned themselves.
OFAC emphasised the damage that ransomware causes in the US, revealing that the cost of attacks reached “over $590 million in 2021” (up from $416 million in 2020). The US government suggests that figure does not reflect the true cost of the attacks which also covers the disruption of critical systems and ordinary businesses.
Ransomware Risks
The global ransomware threat is a significant anti-financial crime (AFC) priority – especially given the risk of violating sanctions by paying the criminals behind attacks. In March 2022, the Association of Certified Anti-Money Laundering Specialists (ACAMS) released a report on its Global Ransomware Risks Survey, which took in respondents from public and private sector organisations. The report set out a number of key findings, including:
Only 40% of respondents believed their organisation was shielded from ransomware attacks.
Only 41% of respondents considered ransomware attacks as part of their sanctions compliance programs.
Only 24% of respondents were familiar with the potential sanctions compliance risk of paying ransoms to criminals.
Only 20% of respondents felt that their government authorities were doing a good job of protecting companies against ransomware attacks.
Almost 50% of respondents believed that they would be targeted by a ransomware attack in the next 12 months.
The ACAMS report reveals a need for firms around the world to strengthen their sanctions compliance programmes to account for the ransomware threat. In practice, this means implementing suitable cyber-security measures to detect and prevent ransomware attacks, and – should an attack happen – ensuring that they do not violate sanctions compliance regulations by making ransom payments. Firms may address the ransomware sanctions compliance risk in a variety of ways, including:
Reviewing their networks regularly for vulnerabilities to ransomware and other cyber-attacks.
Either directly or working with a Managed Security Service Provider (MSSP), implementing appropriate cyber-security measures across their network, including software solutions and employee training.
Implementing a ransomware sanctions compliance response should an attack take place.
Involving sanctions compliance teams and anti-money laundering (AML) teams in ransomware compliance policies and procedures.
Investing in ransomware insurance.
The ACAMS study revealed that only 24% of respondents were aware of the point at which they should elevate a ransomware attack to a financial crime compliance priority, while only 53% of respondents were aware of the terms of their ransomware insurance – and what they needed to do to comply with the terms of their coverage.
Ransomware Compliance
Addressing the sanctions compliance risk associated with ransomware requires firms to make decisions about customers and risk factors quickly. To meet that challenge, firms must collect and analyse a vast amount of data, and use that data to inform compliance processes before and during a potential ransomware attack. In practice, this means implementing an automated software platform as part of a sanctions compliance solution.
In September 2022, following OFAC’s sanctions announcement, cyber-security firm Secureworks confirmed the link between the designees and the IRGC. The confirmation followed a similar Secureworks Counter Threat Unit (CTU) investigation in May 2022 that revealed a link between ransomware attacks from the Cobalt Mirage group and the Iran-linked Phosphorus APT group.
As part of a next-generation risk management approach, Labyrinth Intelligence and Labyrinth Screening are two powerful tools used in the fight against ransomware and other types of financial crime. Integrating cutting-edge knowledge graph and machine learning technology, Labyrinth enables firms to make sense of complex, diverse, structured and unstructured data. It also enables real-time searches against thousands of global data sources including sanctions lists, watchlists, and adverse media sources, in 22 languages, seamlessly blending data to deliver actionable compliance intelligence.
In a constantly shifting sanctions and regulatory landscape, Labyrinth offers a way for firms to stay on top of customer activities and adapt quickly to emerging risks such as ransomware.
To learn more about how Ripjar can help your firm address ransomware risks, contact us today.
Revolutionise your customer screening with the latest release of Ripjar’s Labyrinth Screening platform, featuring ground-breaking new AI Risk Profiles.
This game-changing development uses sophisticated machine learning, natural language processing and graph analytics to generate person and company-specific risk profiles for significantly improved accuracy, effectiveness and efficiency in the fight against financial crime.
With 80% of the AI Risk Profiles also enriched with additional secondary identifiers, Labyrinth Screening now offers unparalleled accuracy and reduced false positives, including across standard watchlists.
Read on to learn more about how Ripjar’s new AI Risk Profiles can benefit your organisation.
What are AI Risk Profiles?
Labyrinth Screening’s new AI Risk Profiles have been developed to save analysts time and increase accuracy when screening for adverse media, watchlists, sanctions and PEPs.
This industry-leading innovation reviews all relevant data from both structured and unstructured sources to build discrete profiles for individuals and organisations, reducing false positives and significantly improving analyst efficiency.
Rather than showing every news article, advanced natural language processing is used to extract the most relevant items necessary to give a clear and complete view of relevant risks as quickly as possible.
How can your organisation benefit from AI Risk Profiles?
Identifying risk in your client portfolio is a huge challenge. Customer data can be limited and problematic, while media data can be noisy and imprecise. Many screening methods generate a large number of false positives, struggle to achieve accuracy at scale, and put a significant time burden on analysts.
AI Risk Profiles are designed to address these challenges directly, and offer a number of benefits which will help improve your screening accuracy and operational efficiency.
Identify risks you might otherwise miss
AI Risk Profiles help ensure your organisation’s regulatory compliance by identifying risks other screening methods might miss. AI-powered multi-lingual name matching and entity resolution are used to overcome screening challenges such as common or high profile names.
Powered by the Ripjar Knowledge Graph, this latest version of Labyrinth Screening provides global, multi-jurisdictional screening which adds unprecedented additional context to profiles.
By separating out the matches into distinct profiles, analysts can quickly assess if the risky person or company in the news is their new or existing customer. Importantly, once an analyst has marked a specific profile as not being relevant, new alerts will not be generated unless there is a significant change to the client match, eliminating significant operational costs.
Common Names
Clients with common names can be incredibly difficult to screen reliably due to the frequency with which their names appear and the resulting volume of non-relevant data. Traditionally, screening such names requires searching through huge quantities of data and can feel like looking for a needle in a haystack. Risks are missed as a direct result.
With AI Risk Profiles, analysts can identify potential matching profiles from a condensed set, and then quickly review those items marked as a priority, cutting through the noise to access the relevant information.
High Profile Names
Individuals such as politically exposed persons (PEPs) can generate enormous quantities of news, obscuring data on those with similar or identical names. Because AI Risk Profiles segment out recognisable entities, risk associated with customers who share high profile names can easily be differentiated and understood.
Imagine you have a client called David Cameron, who is not the former British Prime Minister. This is a common name, and also a famous person and PEP, making it hard to assess risk in the noise of articles that will be overwhelmingly about the politician. With Ripjar’s AI Risk Profiles, you’ll find a list of different David Cameron profiles with whom risk is associated, making it quicker and easier to identify and assess the correct one.
Achieve accuracy at scale with more secondary identifiers
Ripjar already leads the article-based screening market with unparalleled data classification and entity resolution. The new AI Risk Profiles add an extra technology layer on top of this, combining data together in a way that makes it even more useful to your organisation.
This latest evolution of Labyrinth Screening captures a huge number of secondary identifiers – such as dates of birth, nationalities, locations and roles – from unstructured text. This vast expansion of context around entities leads to richer data and better recall. Standard watchlists are also enriched with these additional properties, improving sanctions and PEP screening accuracy.
80% of AI Risk Profiles contain secondary identifiers, which is key to reducing false positives. Testing has shown that there can be as much as a 91% reduction in false positives alongside a 5% improvement in recall.
By aggregating these properties across millions of articles, Labyrinth Screening enables identifiers to be assigned to entities at a scale which is simply not possible in human-curated profiles, and at an accuracy not achievable with article-based risk evaluation.
AI Risk Profiles assemble all this information into single 360o profile views for people and companies, identifying areas of relevant risk across adverse media, sanctions lists and watchlists and PEPs.
Improve efficiency and reduce analyst workload
AI Risk Profiles offer clear benefits compared to human-curated profiles or article-based review approaches. For example, having a material risk in the 200th article in an alert is not helpful if there is only time to read the first 20. And even if an analyst reads them all, it’s still likely that information will be missed.
With many financial institutions limited on the time – and associated cost – they can spend on screening each client, AI Risk Profiles offer a much faster, more efficient option. They have been shown to decrease analyst workloads by up to 10x, resulting in less operational overhead alongside improved accuracy.
As well as being quick and easy to navigate, these individual summaries deliver more targeted, relevant information to enable analysts to effectively assess risk. Intelligent classification prioritises and pinpoints the most relevant articles to review, reducing analyst workload and reducing the requirement to invest huge quantities of time.
Get in touch to learn more about AI Risk Profiles and request a demo
LONDON, 6 September 2022 – Ripjar, the trusted provider for tackling financial crime, today announces the launch of its updated Labyrinth Screening Platform with the addition of AI Risk Profiles. Financial compliance analysts will now have a more streamlined experience generating discrete profiles from watchlists, sanctions, adverse media data, and PEPs (politically exposed persons), leveraging AI to tackle the large volumes of alerts they have to review.
This game-changing development uses sophisticated machine learning, natural language processing and graph analytics to generate person and company-specific risk profiles. It reviews all relevant data from both structured and unstructured sources to build discrete profiles for individuals and organisations for significantly improved accuracy, effectiveness and efficiency in the fight against financial crime.
Testing of the solution has shown that there can be as much as a 91% reduction in false positives whilst benefiting from a 5% improvement in valid matches found.
Pressures are mounting on financial compliance teams
According to Thomson Reuters, while 74% of financial services companies expect their regulatory burden to increase in the next year, 61% believe their teams will not grow in size, as recruitment needs are called into question. Ultimately, financial compliance teams will be forced to pick up more work without the necessary headcount. Having the right technology to support those extra work loads will be critical.
Identifying risk in a customer portfolio remains a huge challenge thanks to limited and often problematic customer and media data. Many screening methods still rely heavily on manual and time consuming processes, which can generate a large number of false positives, struggle to achieve accuracy at scale, and put a significant time burden on analysts.
Ripjar’s AI Risk Profiles uses AI-powered multi-lingual name matching and entity resolution to overcome those screening challenges such as common or high profile names. The technology automatically separates out the matches into distinct profiles, so analysts can quickly assess if the risky person or company in the news or on a sanctions list is their new or existing customer. Importantly, once an analyst has marked a specific profile as not being relevant, new alerts will not be generated unless there is a significant change to the client match, eliminating operational costs.
This latest evolution of Labyrinth Screening, AI Risk Profiles, captures a large number of secondary identifiers – such as dates of birth, nationalities, locations and roles – from unstructured text. This expansion of context leads to richer data and better recall. Standard watchlists are also enriched with these additional properties, improving sanctions and PEP screening accuracy. 80% of profiles now contain secondary identifiers, which is key to reducing false positives.
“Ripjar’s innovative approach to solving real market challenges, based on advanced technology and analytics capabilities, makes it an exciting player in the name screening space,” said Nick Vitchev, Research Director at Chartis.
Jeremy Annis, CEO at Ripjar: “Financial institutions are coming under increasing cost and time pressures when it comes to compliance and regulation when screening their clients. Ripjar’s new AI Risk Profiles solution within the Labyrinth Screening Platform offers a much faster, more efficient option for financial compliance analysts. They have been shown to decrease analyst workloads by up to 10x, resulting in less operational overhead alongside improved accuracy. With AI, analysts can be confident in the profiles they screen and be a reliable source for tackling financial crime.”