Month: October 2022

De-risking in banking: the challenges and alternatives for risk management

The financial landscape changes constantly and, as new regulations and criminal trends affect global regulatory compliance, banks sometimes act to reduce the amount of risk they face through de-risking policies. While de-risking is a way to protect banks from criminal risk, it often represents a controversial compliance option since it can result in the exclusion of certain businesses from financial markets. 

What is de-risking?

De-risking is the practice of declining or limiting financial services based on prevailing regulatory compliance requirements. More specifically, under a de-risking policy, a bank or financial service provider may adjust, end, or choose not to enter into a business relationship with a customer based on the compliance demands that doing so would present. 

Since anti-money laundering regulations require banks to put policies and procedures in place to identify, prevent, and report financial criminal activities (such as money laundering and terrorism financing), de-risking represents an alternative option for those that cannot comply effectively with the rules. In most cases, de-risking is a commercially-motivated decision: a bank may decide that it is necessary to de-risk in order to be able to afford satisfactory financial compliance in other areas of its services. 

There are no regulatory requirements for the way de-risking policies should be implemented. Financial institutions may apply de-risking measures broadly by restricting their services to entire categories of customer, or assess each customer’s risk level individually. Similarly, de-risking does not always mean that a financial institution limits their financial services: in some cases de-risking may be achieved by increasing compliance spending to boost performance. Some banks devote resources towards ongoing de-risking programmes which constantly assess the commercial viability of certain customer relationships and inform de-risking decisions. 

Why is de-risking problematic?

While de-risking has regulatory and commercial benefits for banks, its exclusionary effects mean that many customers lose or are unable to gain access to the financial system. The de-risking process particularly affects organisations that are viewed as presenting a high money laundering risk, including money transfer businesses, non-profits, charities, correspondent banking services, and fintechs. 

Many of the financial services affected by de-risking policies involve customers and clients that are located overseas, and so the practice disproportionately affects foreign customer groups, which may include vulnerable persons such as immigrants, refugees and asylum seekers, or legitimate businesses in developing countries that need access to international financial markets to grow. Studies by the World Bank have shown that de-risking takes place around the world but affects certain regions disproportionately, especially those with smaller countries or countries with only limited access to financial markets. With that in mind, the consequences of de-risking include:

  • Negative effects on financial inclusion. Customers that are unable to access financial markets are likely to remain in poverty and are less able to contribute to the economic growth of their country.   
  • Humanitarian organisations may lose access to crucial financial services and be unable to provide aid to people and areas in need. 
  • Customers that are unable to access higher quality banking services may be forced to use less-regulated banks. Similarly, criminals may resort to money laundering methodologies outside the scope of traditional AML/CFT controls. 
  • When one bank de-risks, others may follow suit out of competitive necessity, creating significant knock-on effects for the financial system and undermining confidence in the wider financial sector. 
  • De-risking can be a complex administrative process and may not be entirely effective in reducing a bank’s risk exposure. High risk customers that are declined services may be able to access others via a different branch of the same bank.  

What are the alternatives to de-risking?

De-risking policies work against Financial Action Task Force (FATF) guidance that banks should take a risk-based approach to AML/CFT. In practice, the risk-based approach means that banks should assess the compliance risk that individual customers pose, and then adjust their compliance response accordingly. This approach enables banks to balance their compliance obligations with customer service considerations, and offer their services to as broad a customer base as possible. 

With that in mind, banks may address some of the cost concerns that drive de-risking policies by implementing automated software solutions designed to streamline the compliance process. By automating customer data collection and analysis, for example, firms may build accurate risk profiles for their customers quickly and in large volumes, and use that information to make compliance decisions. Similarly, automated software enables firms to conduct transaction screening in seconds, establishing money laundering risk without compromising customer experiences.

Ripjar’s Labyrinth Screening platform is capable of screening customers against thousands of structured and unstructured data sources in real time, including sanctions and watchlists, and adverse media stories in 21 languages. Rather than declining services to customers as part of a de-risking strategy, Labyrinth Screening enables you to enhance customer safety and regulatory compliance, in a challenging financial landscape, and adapt quickly when new methodologies or regulatory responsibilities emerge.  


To learn more about how Ripar can help you find alternatives to de-risking, contact us today

Money Mules: What Are They and How Can You Detect Them?

Money launderers must disguise the origin of their illegal funds in order to avoid the anti-money laundering (AML) and counter-financing of terrorism (CFT) measures put in place to detect them. That requirement often leads to the use of third parties, so-called ‘money mules’ who are engaged to help launderers move funds between accounts. Money muling is an increasingly serious global problem: in 2021, an international investigation led by Europol, INTERPOL, and the European Banking Federation identified over 18,000 money mules, and led to the arrest of 1,803 people involved in criminal enterprises valued at a collective €67.5 million. 

In response to the money laundering threat, in August 2022, INTERPOL launched its #YourAccountYourCrime campaign, an initiative to address money muling and remind financial institutions and the general public of their responsibility to keep their accounts safe from criminal misuse. With global authorities focusing on the detection and prevention of money muling, it’s more important than ever for financial institutions to understand what the crime entails and how to prevent it. 

What is a money mule?

Money mules are people that conduct transactions on behalf of criminals in order to thwart AML/CFT controls and, in doing so, evade regulatory scrutiny. A money mule may be asked to receive money into their bank account or transfer money from their account to another, or may simply open a bank account in their name that other persons then use to move illegal funds. 

While a small number of money mules may handle physical cash on behalf of money launderers, the vast majority of money muling takes place online. A Europol study revealed that over 90% of money mule transactions are related to cybercrimes and types of online fraud. 

While money mules may act in exchange for commission or a fee, they may also be elderly or financially vulnerable people, such as immigrants or the unemployed, who have been coerced or incentivised into working on behalf of criminals. When they are recruited, some money mules may not be aware that they are acting on behalf of money launderers and end up participating in money laundering without initially realising they are involved in a crime.

The #YourAccountYourCrime campaign highlighted several key money mule recruitment methods: 

Employment scams: A criminal may contact a prospective money mule with the offer of employment. In most cases, the ‘employee’ has not applied for the job and the money launderer ‘employer’ does not offer any details about their company or the proposed role on offer. 

Romance scams: Prospective money mules may be contacted via social media or dating websites by money launderers posing as romantic partners. 

Investment scams: Money mules may be contacted online with details of a lucrative investment scheme or quick, ‘no strings’ cash payments. 

Identity theft: Money launderers may assume the identity of employees of banks or courier companies, or even acquaintances or relatives, in order to get individuals to hand over personal account details. 

In person: Some money mules may be approached in person by money launderers. 

How does money muling work?

Once recruited, money mules are used to handle illegally-obtained funds and typically receive their instructions over email or through social media messaging services. Money mule tasks may involve: 

  • Opening a bank account (or multiple bank accounts) under their own name. 
  • Establishing a company under their own name. 
  • Receiving money into one of their bank accounts or transferring money to a third party bank account. 

A money mule may be only a single component in a much larger and more complex laundering operation in which criminals introduce their illegal funds to the legitimate financial system through multiple entry points. After the money mule has moved the funds through the financial system, criminals will withdraw the cash in its laundered state. 

How can financial institutions detect money muling?

Financial institutions must develop risk management solutions capable of detecting customers that are being used as money mules, and remain vigilant for certain financial behaviours. Red flag indicators that customers may be involved in money laundering include: 

  • Customers that are unwilling or unable to pass customer due diligence checks. 
  • Customers that are unfamiliar with the source of the funds moving through their account. 
  • Multiple IP addresses associated with a single online bank account.
  • IP addresses originating from high risk money laundering jurisdictions.
  • Transfers of funds to and from high risk money laundering jurisdictions.
  • Deposits of funds into a bank account that are withdrawn rapidly. 
  • Unusual patterns of transaction that do not match a customer’s risk profile. 

From a regulatory compliance perspective, in order to detect and prevent money muling, firms should take a risk-based approach, assessing each customer individually and implementing the following AML/CFT measures and controls:  

  • Know Your Customer: Firms should implement suitable Know Your Customer (KYC) processes at onboarding and throughout the customer relationship in order to build accurate risk profiles. As part of the customer due diligence (CDD) process, for example, firms should establish and verify customer identities by requiring the submission of official documents such as passports and driving licences. 
  • Beneficial ownership: In addition to CDD, firms should establish the beneficial ownership of customer entities. If a money mule has opened a shell company on behalf of a third party, firms must take steps to identify the real owners of that company and ensure that its accounts are not being used to launder money. 
  • Source of funds: Money mules often handle large amounts of cash on behalf of money launderers. Firms should attempt to establish the origin of a customer’s funds to ensure that they have obtained the money in a manner that aligns with their wealth profile. 
  • Transaction screening: Money mules may engage in transactions on behalf of persons that have been targeted by economic sanctions or that are politically exposed persons (PEP). Accordingly, firms should screen transactions against the relevant sanctions and watch lists to reveal potential risk liability. 
  • Adverse media screening: Information about a customer’s involvement in financial crime may be revealed by news media before it is confirmed by official sources. Accordingly, firms should screen customers for their involvement in adverse media stories, including stories from foreign news outlets. 

Next generation risk screening

In order to detect and prevent money muling, firms must be able to collect and analyse large amounts of customer data quickly and efficiently. Ripjar’s Labyrinth Screening platform enables your firm to search thousands of data sources in real time, including adverse media screening in 21 languages. Labyrinth Screening incorporates next generation machine learning technology to process complex structured and unstructured data so that your firm knows as soon as possible when your customers’ risk profiles change. 


To learn more about how Ripjar can help your firm deal with money mule risks, contact us today.

How to Comply with AML Regulations in the Netherlands

The Netherlands has the 17th largest economy in the world by GDP and attracts an array of international businesses, including a growing number of innovative fintech service providers. As a global financial hub, the Netherlands has also become a target for money launderers and other financial criminals, who seek to exploit the country’s financial system. To meet that threat, the Netherlands’ government implements a robust anti-money laundering (AML) and counter-financing of terrorism (CFT) framework, with significant penalties for firms that fail to comply. Dutch authorities emphasise their focus on regulatory compliance: in 2021, for example, Dutch Bank ABN Amro reached a €480m settlement with prosecutors after an investigation uncovered significant AML compliance failings.

AML regulations in the Netherlands represent an ongoing challenge. To ensure your company avoids penalties, it is important to understand the Netherlands’ AML/CFT infrastructure, and what it takes to achieve compliance. 

What is the AFM?

The Netherlands’ primary financial regulator is the Authority for the Financial Markets, known as the Autoriteit Financiële Markten (AFM). Established in 2002 as a replacement for the Netherlands’ Securities Board, the AFM is an independent administrative authority that operates under the control of the Dutch Minister of Finance.

The AFM is responsible for supervising Dutch financial entities to ensure their compliance with AML regulations in the Netherlands. In that capacity, the AFM oversees the entire financial sector and its products and services, including “savings, investment, insurance, loans, pensions, capital markets, asset management, accountancy and financial reporting”. In order to achieve its supervisory objectives, the AFM has the authority to conduct inspections of Dutch financial institutions and, where necessary, enforce regulations by issuing warnings, filing reports with law enforcement agencies, and imposing fines and penalty payments. 

The AFM shares its responsibilities with the Dutch central bank: De Nederlandsche Bank (DNB). The two entities work closely together, often sharing information. While the AFM focuses on supervising businesses in the Netherlands, and “promoting fair and transparent financial markets”, the DNB focuses on providing prudential supervision. 

In conjunction with the DNB, the AFM is also responsible for issuing licences to all financial institutions that operate in the Netherlands. Firms in the Netherlands that wish to obtain a licence must meet a set of qualification criteria and complete the relevant application process

Key AML Regulations in the Netherlands 

The Netherlands’ main article of AML regulation is the Anti-Money Laundering and Anti-Terrorist Financing Act, known as Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft. The Act requires financial institutions in the Netherlands to take a risk-based approach to AML – as mandated by the Financial Action Task Force (FATF) which means they must perform risk assessments of individual customers and implement a range of compliance measures, including:

  • Identity verification: Firms in the Netherlands must establish and verify the identities of their customers as part of the customer due diligence process (CDD) in order to conduct an effective risk assessment. The identity verification process requires the collection of information such as names, addresses, dates of birth, and official company documentation. 
  • Beneficial ownership verification: The CDD process should extend to the beneficial ownership of customer entities. Beneficial ownership checks are required to ensure that customers are not using corporate infrastructure or shell companies to conceal financial crimes. 
  • Transaction screening: Firms in the Netherlands should screen customer transactions against the relevant risk data sources, including beneficial ownership registries, politically exposed person (PEP) lists, and sanctions lists
  • Adverse media: Firms in the Netherlands should screen customers against global adverse media sources which may reveal changes in risk profile before that information is confirmed by official sources. Depending on risk exposure, it may be necessary to implement adverse media screening on a global scale, with name searches conducted in a range of foreign languages. 

Anti-Money Laundering Directives: As a member of the EU, the Netherlands must implement the anti-money laundering directives (AMLD). The AMLD are released periodically by the European Parliament and include a range of updated AML/CFT measures that member states must transpose into domestic legislation. The latest directive, the Sixth Anti-Money Laundering Directive (6AMLD), came into effect in June 2021, introducing the following AML/CFT measures: 

  • A harmonised list of 22 predicate offences for money laundering, including the 2 new offences of environmental crime and cyber-crime. 
  • An expansion of the criminal scope of money laundering. Under 6AMLD, aiding and abetting money laundering now also falls under the definition of the offence of money laundering. 
  • An extension of criminal liability for money laundering to legal persons. In practice, this means that companies (including management and senior executives) may be held liable for money laundering offences committed by individual employees. 
  • An increase in the criminal penalty for money laundering. Under the new rules, money laundering offences must carry a minimum prison term of 4 years. 
  • New ‘dual criminality’ rules to facilitate the joint prosecution of money laundering offences in different countries. 

Recent AML Developments in the Netherlands

The AFM and the DNB keep firms in the Netherlands up to date with the latest AML/CFT regulatory developments. Key recent updates include: 

  • Enforcement actions: The AFM publicises enforcement actions and the monetary penalties that it imposes for compliance failures. In June 2022, the AFM imposed compliance penalties on Revo Capital Management amounting to over €150,000 for infringements of the Wwft. 
  • Ukraine sanctions: Following Russia’s invasion of Ukraine in February 2022, the DNB published guidance for firms in the Netherlands regarding new sanctions against Russia and Russian individuals. 
  • Fintech: The AFM and the DNB publish guidance and recommendations regarding the regulations of fintech products and services, including cryptocurrencies and cryptocurrency service providers. In 2019, for example, both regulators called for the introduction of an international regulatory framework for cryptocurrencies, and for a national licensing regime for cryptocurrency exchanges. In June 2022, the EU announced it had reached an agreement on a Europe-wide crypto regulation framework, known as Markets in Crypto Assets (MiCA). 

Next Generation Risk Management in the Netherlands 

Ripjar’s Labyrinth Screening platform can help firms in the Netherlands reduce their compliance burden and streamline their screening processes. Labyrinth Screening enables firms to search thousands of risk data sources, including foreign news sources, in real time, in 21 languages. Incorporating next generation name matching technology, Labyrinth Screening enables you to react to changes in legislation or emerging criminal methodologies quickly and efficiently and be informed as soon as your customers’ risk profiles change. 


Contact us to discuss how Ripjar can support your AML compliance in the Netherlands 

Understanding the UK’s Second Economic Crime and Corporate Transparency Bill

In March 2022, following the Russian invasion of Ukraine, the UK government passed the Economic Crime Bill, known as the Economic Crime (Transparency and Enforcement) Act, as a means to address the exploitation of the UK’s financial system by Russian oligarchs. While the long-awaited bill was welcomed by the financial community, observers suggested that it did not go far enough to tackle Russian money laundering in the UK. Accordingly, in September 2022, with Russian aggression against Ukraine ongoing, the UK announced the introduction of the second Economic Crime Bill

The new Economic Crime Bill will bring additional anti-money laundering (AML) measures to bear against inflows of illicit money, including new powers for Companies House and new private sector information sharing obligations. With parliament now discussing the second Economic Crime Bill, it is important that UK firms understand how the imminent legislation differs from its previous version, and how to comply with the new regulations. 

What is the UK’s second Economic Crime Bill?

The second version of the Economic Crime and Corporate Transparency Bill was introduced to Parliament on 22 September, 2022. One of the first acts of Prime Minister Liz Truss’ new government, the passage of the bill suggests that financial crime will be a priority for UK authorities going forward, with a strong regulatory focus on money laundering by foreign criminals, and on promoting the UK’s reputation as a legitimate business destination. 

The bill introduces the following measures: 

Companies House reform: Under the second Economic Crime Bill, the UK’s Companies House will receive enhanced investigation and enforcement powers in order to “become a more active gatekeeper over company creation and custodian of more reliable data”. The powers will include the authority to “check, remove or decline information submitted to, or already on, the Company Register”. 

Limited partnership reform: The Economic Crime Bill will modernise limited partnership regulations and address their criminal misuse by foreign persons. The new measures include tighter registration requirements, increased transparency, and a requirement for companies to maintain a connection to the UK. 

Cryptoassets: UK law enforcement authorities will receive new powers to quickly seize and recover cryptoassets that are acquired through money laundering or other types of financial crime.

Anti-money laundering regulations: The bill strengthens UK AML powers in the following ways:

  • Reform of information sharing rules, including the removal of civil liability for breaches of confidentiality when firms share information for the purpose of addressing economic crime. 
  • Removal of the requirement for a suspicious activity report (SAR) before the UK’s Financial Intelligence Unit (FIU) can issue an Information Order (IO) in order to obtain information about suspected money laundering or terrorism financing. 
  • An increased focus on high value criminal activity, including the reduction of the AML reporting burden, in order to prioritise private sector and law enforcement AML resources. 

How does the second Economic Crime Bill differ from the first?

The first version of the Economic Crime Bill was first drafted in 2018. A long awaited legislative measure, the bill’s implementation was delayed for years as the country’s financial priorities changed – even as the UK’s legal and financial communities urged the government to move forward. The invasion of Ukraine provided the impetus for the bill’s passage and it was introduced to parliament on 1 March 2022. The first Economic Crime Bill set out the following measures:  

  • Overseas entities register: A register of overseas entities that own property in the UK. The register includes beneficial ownership information. 
  • Unexplained wealth orders: An adjustment to the requirements for issuing unexplained wealth orders (UWO). The bill made it easier for authorities to issue UWOs by increasing the evidence review period, lowering legal costs for unsuccessful prosecutions, and broadening the list of possible targets of an order. 
  • Sanctions liability: The introduction of strict liability for sanctions breaches. In practice, this means that the Office of Financial Sanctions Implementation (OFSI) may impose penalties without establishing that the offender knew they were breaching sanctions rules. 

Upon its introduction, many UK politicians and observers predicted that the first Economic Crime Bill would need to be strengthened in the future. Then Home Secretary Priti Patel announced that while the bill focused on the measures that would “have the greatest impact and the greatest enablement”, another bill would be forthcoming because “we simply cannot get all the measures in right now.”

The measures set out in the second Economic Crime Bill specifically address many of the lingering vulnerabilities of the first, with broader requirements for transparency and new responsibilities and powers for financial institutions and authorities. In the past, for example when registering a company in the UK, foreign criminals were able to exploit a lack of checks in order to move illicit funds into the country. Under the new bill, Companies House will now have greater powers to detect foreign money launderers and prevent them from misusing the UK’s financial system, while private sector businesses will be able to share information about suspicious customers more easily.

The second Economic Crime Bill also includes a significant modernising effort, specifically targeting money laundering activities involving cryptocurrencies, and making it easier for UK authorities to seize and recover illegal crypto assets. 

How to comply with the new Economic Crime Bill

With Russia’s aggression against Ukraine likely to continue into 2023, UK firms must understand how the second Economic Crime Bill will affect their compliance responsibilities, and adjust their risk management solution accordingly. When it was introduced in March 2022, the first Economic Crime Bill required firms to review their sanctions compliance solution and risk management processes. Building on those measures, the second Economic Crime Bill will require firms to strengthen further in those areas with a global focus on customer data collection, analysis and management. 

To manage those new compliance requirements, firms must seek to integrate a powerful software solution capable of drawing from multiple global sources, and dealing with structured and unstructured data. With that goal in mind, Ripjar’s Labyrinth Screening platform has been designed to meet the risk management needs of UK firms in a changing, and challenging, compliance landscape. Labyrinth facilitates real-time search of global data sources, including sanctions lists, watch lists, and adverse media in 21 foreign languages, ensuring that your firm knows as soon as possible when a customer’s risk profile changes, or when new regulations alter the compliance environment. 

Integrating next generation machine learning technology, Labyrinth Screening promises to help you manage your UK risk liability accurately and efficiently, while reacting quickly to regulatory changes, such as new sanctions against Russia


To find out more about how Ripjar can help your firm comply with UK AML regulations, contact us today.