Month: December 2022

AUSTRAC Source of Funds and Source of Wealth Guidance 2022

In October 2022, the Australian Transaction Reports and Analysis Centre (AUSTRAC) released guidance on how firms should conduct source of funds and source of wealth checks on their customers, as part of their anti-money laundering (AML) and counter-financing of terrorism (CFT) obligations. Following draft guidance released earlier in 2022, the publication emphasises the importance of the risk-based approach, which requires firms to assess each customer’s risk individually and deploy proportionate compliance measures. 

AUSTRAC’s focus on source of funds and wealth comes in the context of an ongoing investigation in Star Entertainment Group, which allegedly submitted fake source of funds letters to the Bank of China to prevent appropriate AML checks into certain customers’ gambling income. If the investigation finds that the letters were faked, Star Entertainment Group could be charged with money laundering offences, and face significant financial and criminal penalties.

The new AUSTRAC source of funds and source of wealth guidance is designed to help firms in Australia deal more effectively with suspicious high value transactions, and so sets out directions for collecting relevant source of funds and wealth information, and for verifying that information. With the Star Entertainment Group investigation ongoing, it is important the firms in Australia become familiar with the new guidance, and implement it within their own compliance solutions.

Defining Source of Funds and Source of Wealth Checks

AUSTRAC’s guidance states that the identification of sources of funds and wealth “is an important part of understanding your customers’ financial circumstances, background and position” and, crucially, can indicate whether a customer is involved in criminal activity. Before establishing a customer’s source of funds or wealth, however, it is necessary to define certain concepts associated with the check process:

Source of funds: The funds involved in specific transactions or used to pay for designated services. Examples might include gambling payouts, shares and dividends, inheritance payments, pension payments, legal compensation or the sale of property, artwork, or vehicles.

Source of wealth: The funds that comprise a customers’ entire wealth and assets. Source of wealth may also take in the activities that contributed to a customer’s net worth. Examples might include long term investments, income from employment, income from rental properties, income from businesses, and assets acquired through inheritance.

Risk-based approach: AUSTRAC has previously published guidance around the risk based approach to AML/CFT, which essentially enables firms to balance their compliance resources and budget with the level of risk that they face. In practice, ‘risk-based’ means that higher risk customers should be subject to enhanced due diligence (EDD) measures that involve greater scrutiny of their financial activities. Source of funds and source of wealth checks should be part of the EDD process since they enable firms to establish how and where customers obtained their funds and assets. 

Key Guidance

AUSTRAC’s 2022 guidance involves the following key points: 

Risk triggers: Source of funds and wealth checks should be triggered under certain EDD circumstances, including:

  • The overall rating that a customer risk assessment generates, which may depend on the customer’s circumstances, transactional activity, geographic location, and the products and services that they use. 
  • The quality of a customer’s due diligence information. Incomplete, missing, or fraudulent information, for example, may indicate that a customer has high AML/CFT risk and that their source of funds or wealth should be scrutinised. 
  • Adverse media that indicates a customer is involved in criminal activity or that their AML/CFT risk profile has changed (such as designation on a sanctions list, for example). 

Politically exposed persons: Government employees and elected officials, known as politically exposed persons (PEP), carry a higher AML/CFT risk. Accordingly, AUSTRAC requires firms to conduct source of funds and source of wealth checks on all PEP customers, along with their relatives and close associates (RCA). It is worth noting that foreign PEPs present a particularly high AML/CFT risk. 

Privacy law: Source of funds and source of wealth checks often involve the collection of customers’ sensitive personal data, which means that firms should be aware of their responsibilities under Australian privacy law. AUSTRAC emphasises the need to consult the Australian Privacy Principles when collecting funds and wealth data.

Verifying Source of funds and Source of Wealth

AUSTRAC directs firms to collect and analyse a range of information in order to verify sources of funds and wealth. That process may include consulting resources already provided by customers, requesting a formal declaration from customers, and searching secondary sources such as websites, adverse media, commercial databases, and sanctions and watchlists. 

The specific approach a firm takes to verifying source of funds and source of wealth may vary:

Source of funds verification: In order to verify sources of funds, firms must establish the origin of a customer’s funds, and substantiate how the customer received the funds in the first place (property sales, gifts, etc). Where a third party has provided a customer with funds, firms should seek to verify that original transaction. 

Source of wealth verification: AUSTRAC warns that it may be more difficult to verify sources of wealth than sources of funds, and that the type of information required for satisfactory verification may vary depending on a customer’s risk. The guidance suggests that source of wealth verification should be obtained via reputable sources, including company registries, banks, accountants, and lawyers.

Using Technology to Enhance Source of Funds and Wealth Checks

Effective risk-based source of funds and source of wealth checks require firms to collect a range of data, sometimes from disparate, unstructured sources, in order to ensure that they understand their customers’ risk profiles. That objective means screening customers and transactions on an ongoing basis so that firms can detect suspicious transactions and changes in risk as soon as possible. With that challenge in mind, it is crucial that firms implement screening technology capable of managing vast amounts of data, from domestic sources and from around the world, to generate information about funds and wealth quickly and efficiently. 

Ripjar’s Labyrinth Screening solution enables firms to enhance their source of funds and source of wealth checks significantly, gathering customer data from thousands of sources in real time, including sanctions and watch lists, PEP lists, and foreign adverse media stories in over 20 languages. Integrating powerful machine learning technology, Labyrinth blends structured and unstructured data seamlessly in order to reconcile customers’ financial activities with expected behaviour. With Labyrinth Screening we aim to optimise the results of source of funds and wealth checks, reducing noise and false positives in order to deliver actionable intelligence and, ultimately, help you make crucial compliance decisions.



To learn more about risk-based
AML/CFT screening solutions, contact us today. 

OFAC Sanctions Compliance Guidance for Instant Payment Systems

On September 30, 2022, the United States Treasury’s Office of Foreign Assets Control (OFAC) published Sanctions Compliance Guidance for Instant Payment Systems. The guidance emphasises the importance of the risk-based approach that firms in the US must take to sanctions risk, in particular where those firms use payment technologies to handle transactions, such as instant payment systems. 

OFAC published the payment systems guidance following its court settlement with Tango Card Inc, a stored-value card company that distributes products such as electronic gift vouchers and other online rewards. An OFAC investigation found that Tango Card had violated multiple US sanctions by transmitting its products to sanctioned countries. 

With OFAC’s renewed focus on payment systems, it is crucial that service providers understand the new guidance, and how to ensure regulatory compliance.  

What Does OFAC’s Instant Payment Systems Guidance Involve?

The 2022 guidance emphasises that there is no “one-size-fits-all approach” to sanctions compliance, pointing out that each instant payment system “has its own unique characteristics” and does not entail “the same sanctions risks”. Accordingly, OFAC’s guidance states that each financial institution’s sanctions compliance solution “should be based on that institutions’ assessment of its own risk”, and take in a variety of factors for mitigating that risk. 

OFAC’s guidance sets out the following key risk factors relevant to financial institutions offering instant payment systems:

Domestic vs Cross Border Payments: OFAC’s guidance identifies that domestic payment systems which involve the transfer of funds between US bank accounts are typically a lower sanctions risk than those that facilitate cross-border transactions – which are obviously more likely to involve persons designated by US sanctions programs. OFAC points out that US banks already implement robust screening and monitoring processes (as required by US law), along with risk-based customer due diligence, but that non-US banks “may not be subject to the same regulatory requirements and examinations”. 

Nature and Value of Payments: Certain types of payment facilitated by instant payment systems pose a greater sanctions risk than others. To this end, OFAC’s guidance suggests that the “nature and value” of payments should be a relevant risk factor when assessing risk. In particular, banks should examine the consistency of payments with customers’ past behaviour: for example significantly higher value payments than normal, to foreign accounts, may indicate a greater sanctions risk. 

Emerging Compliance Technology: New compliance technology, such as artificial intelligence tools and information sharing mechanisms can significantly reduce the sanctions risk associated with instant payment systems. In particular, OFAC notes that such emerging technologies can “enhance sanctions screening functions and reduce false positives”, and encourages financial institutions to integrate technology wherever possible in order to manage instant payment risk. 

The Tango Card Settlement

The publication of the instant payment systems guidance on 30 September coincided with OFAC’s settlement with Tango Card Inc, following an investigation that ran from 2016 to September 2021. The investigation found that Tango Card had “deficient geolocation identification processes” that had caused multiple US sanctions violations, including the illegal transmission of 27,720 gift cards and debit cards worth $386,828.65. Those cards had been issued to individuals in a number of high risk sanctioned countries, including Iran, Syria, North Korea, Cuba, and Ukraine’s Crimea region. 

While OFAC praised Tango Card’s voluntary disclosure of the violations, it pointed out that the card company should have known that it was delivering cards to customers within sanctioned jurisdictions. The investigation found that Tango Card had failed to implement risk-based measures to identify the non-compliant transactions or establish the location of card recipients, and had failed to implement sufficient “geo-blocking” features to restrict the sale of cards to such customers. While Tango Card did implement contractual provisions that required its direct customers to comply with sanctions provisions, it did not ensure that the cards were not passed to customers in sanctioned jurisdictions. 

Following the investigation, OFAC emphasised that contractual provisions should not be used as a means to transfer sanctions liability since they do not mitigate sanctions risk, nor do they absolve persons of their own compliance liability.

As part of the settlement, Tango Card agreed to pay $116,048.60, as opposed to a maximum penalty of $9.2 billion. The relatively low fine reflected mitigating factors in the case, including Tango Card’s voluntary disclosure of its compliance failures and its subsequent cooperation with OFAC during the investigation. OFAC also commended the steps Tango Card subsequently took to address its failures, which included implementing geo-blocking measures to prevent card issuance to sanctioned jurisdictions, conducting compliance training, integrating new screening tools, and hiring a security consultant.

The Importance of Technology in Sanctions Compliance

The Tango Card settlement, and the subsequent OFAC guidance underline the importance of the risk based approach as a sanctions compliance priority for organisations that offer instant payment services, but also demonstrate the importance of technology in achieving that goal. Many of Tango Card’s sanctions violations could have been prevented with the better application of screening technology within its compliance infrastructure: high risk transactions, for example, would have been flagged automatically, while geo-blocking measures would have identified top line domains and prevented products being issued to designated countries.

Ripjar’s Labyrinth Screening platform was designed to help firms meet their sanctions compliance requirements including the challenges presented by instant payments. When a payment is initiated, Labyrinth enables real time searches of sanctions lists, watch lists, and other types of data, including thousands of adverse media sources. Labyrinth helps firms conduct accurate, efficient assessments of the sanctions risks they face, integrating machine learning technology to manage structured and unstructured data, and generate actionable intelligence in seconds. 


To learn more about sanctions compliance risk for instant payment systems, contact us today.

Wolfsberg Group: Financial Crime Principles for Correspondent Banking

In October 2022, the Wolfsberg Group, a non-governmental association of global banks, published an updated version of its Financial Crime Principles for Correspondent Banking. Originally published in 2014, the Wolfsberg Group compiled the document to provide “guidance and best practices” for correspondent banks, including setting out a distinction between “correspondent banking” and “correspondent relationships”.  The new “Principles” also integrates a Frequently Asked Questions section that was previously not part of the same document. 

Given the influence that the Wolfsberg Group has on global banking regulation, and anti-money laundering (AML) and counter-financing of terrorism (CFT) policy, it is important that correspondent banking service providers become familiar with the updated principles, and use them to update their AML/CFT solutions. With that in mind, let’s take a look at the key points from the updated document.

Who are the Financial Crime Principles for?

The updated Principles set out the risk-based due diligence measures that correspondent banks must implement when onboarding new customers or handling transactions for existing customers. More specifically, the Principles enable banks to conduct effective risk assessments of customers involved in correspondent banking relationships, and establish and maintain accurate risk profiles. The document also includes information for respondent banks, outlining what they should expect from their correspondent banking relationship. 

The major focus of the updated document is on the types of activity that present the most risk for correspondent banks. The update introduces “the concept of a defined risk appetite for correspondent banking activity” and details factors that should be considered during periodic reviews of correspondent banking relationships, as they pertain to a service provider’s risk appetite.

What are the Correspondent Banking Financial Crime Principles?

Central to the updated financial crime principles is the need for correspondent banks to apply risk-based due diligence to their respondents. In practice this means that banks must assess each respondent to determine the level of risk they present, and then deploy AML compliance measures commensurate with that risk. 

Under the Principles, the key risk indicators to consider during the due diligence process are as follows:

Geographic risk: Jurisdictions that have inadequate financial crime standards or poor regulatory supervision present a higher AML/CFT risk. Correspondent banks may refer to guidance from international regulatory bodies, such as the Financial Action Task Force (FATF) to determine what level of risk a particular jurisdiction presents, and factor that information into a risk assessment. 

Branches, subsidiaries, affiliates: Where a correspondent bank provides services to its own affiliates, the level of due diligence applied should reflect the level of control the parent institution exerts. Banks should consider risk factors unique to its branches, subsidiaries, and affiliates when conducting risk assessments. The same principle should be applied to respondents that are not affiliates of a correspondent bank, where they have their own parent institutions. 

Ownership and management: A respondent’s ownership and management structure typically affect its financial crime risk. Salient factors include whether a respondent is state or publicly owned, and the level of transparency with which management personnel operate. Executives should also be considered when assessing risk: politically exposed persons (PEP), for example, pose an elevated AML/CFT risk. 

Products and services: The products and services that respondents offer to customers affect their financial crime risk. Works of art, for example, pose a higher level of AML risk than other types of goods and services, while a respondent’s ability to monitor their own transactions may also be relevant Similarly, the products and services that the correspondent bank offers to its respondents also affect financial crime risk: banks should consider their ability to monitor respondent transactions when assessing this risk factor.  

Respondent customer base: The type of customers that a respondent serves can elevate its AML/CFT risk, especially when a “substantial part of its business income” is drawn from high risk customers. Correspondent banks must be able to assess the risk posed by respondent customers against their risk appetite. 

Regulatory status and history: Correspondent banks should take “reasonable measures” to ensure that respondents are subject to suitable regulatory oversight within their jurisdiction. If the respondent has been subject to previous regulatory actions, such as criminal investigations, the correspondent bank should factor that information into their risk assessment.  

Financial crime controls: Respondents that operate in jurisdictions with poor financial crime controls (FCC) pose a high AML/CFT risk. Correspondent banks should consider whether a jurisdiction’s FCC meet international standards and how effectively they counter the risk presented by other factors (such as customer base). 

Shell Banks: Correspondent banks should confirm that a respondent is not a shell bank – that is, a bank with no physical presence in the country in which it is incorporated. Similarly, correspondent banks should confirm that the respondent does not provide services to, or have business arrangements with, shell banks. 

Site visits: Correspondent banks should arrange a visit to a respondent bank’s premises “prior to or within a reasonable period of time” after establishing a business relationship, in order to “support the customer due diligence process”. If necessary, financial crime experts should also conduct visits. 

Enhanced Due Diligence

Where correspondent banks deal with higher risk respondents, the Principles advise that they apply enhanced due diligence (EDD) in order to establish a greater understanding of the risks involved in the relationship. EDD measures typically involves a more intensive evaluation of the following factors:

  • Politically Exposed Persons: If PEPs are involved in the management or ownership of a Respondent, the correspondent bank should take steps to understand the PEP and the nature of their role. 
  • Downstream FIs: Where a respondent offers its services to financial institutions (FI) that are domiciled within the same country as a respondent, that relationship is referred to as a “downstream FI”. Correspondent banks should “take reasonable steps” to understand the FIs that are downstream from respondents since each FI in the relationship will impact the risk assessment. 

FAQ Update

The Wolfsberg Group incorporated a set of FAQs that were previously available in a separate document, into the updated 2022 Financial Crime Principles. The FAQs offer detailed information about correspondent AML/CFT measures, based on the Group’s perspective on current best practices. The FAQs also set out the Group’s perspective on how correspondent banking AML/CFT best practice should develop in the future. 

The FAQs topics include reasons for the intensive regulatory scrutiny of correspondent banking, how the Principles apply to affiliates and EU member banks, and how to treat high risk respondents.

How to Comply with the Financial Crime Principles

The Financial Crime Principles heavily emphasise the importance of the risk-based approach to effective AML/CFT. That approach relies on the creation of accurate customer risk profiles, which means correspondent banking service providers must collect and analyse customer data on an ongoing basis. Given the sheer amount of customer data involved in correspondent banking AML/CFT, it is vital that service providers use suitable automated software to capture the relevant information. 

Ripjar’s Labyrinth Screening platform gives correspondent banks the power and resources they need to manage their data challenges, and meet the standards set out by the Financial Crime Principles. Using Labyrinth, correspondent banks can screen their respondents against thousands of data sources, including sanctions lists, watchlists, and PEP lists, along with global adverse media in over 20 languages. Labyrinth integrates machine learning technology to blend structured and unstructured data in real time, and generate actionable intelligence to ensure that changes to respondent risk profiles are detected and flagged as soon as possible.


To learn more about correspondent banking
AML/CFT compliance, contact us today. 

EU Russia Sanctions Update

Following the Russian invasion of Ukraine on 24 February 2022, Western countries, including the UK, the US, the EU, Canada, and Australia, imposed an unprecedented amount of sanctions against President Vladmir Putin’s regime. Those sanctions have included import and export bans, asset freezes, and travel bans, and focused on both degrading Russia’s ability to fund its military action and on punishing the individuals that fund it. Collectively, the global sanctions response against Russia has targeted hundreds of Russia entities, including banking and media organisations, and thousands of individuals, including military figures, politicians, and members of Putin’s elite inner circle. 

On 6 October 2022, the EU issued its 8th package of sanctions against Russia. The new sanctions followed Russia’s declared annexation of four Ukrainian regions, and Putin’s repeated threats to use nuclear weapons against Ukrainian forces. The new sanctions package generally broadens the scope of existing EU Russia sanctions, banning the export of a wider range of goods to Russia, targeting more members of Putin’s elite, and depriving Moscow of billions of euros in revenue. The UK joined the EU in imposing new Russia sanctions. 

Key measures from the EU’s latest Russia sanctions update include:

While the EU had already sanctioned the provision of financial services to Russian entities, the new sanctions package extended that ban to include IT consultancy, architectural, engineering, and legal advisory services.

Crude oil price cap

While the purchase, import, or transfer of crude oil products originating in Russia was banned under the EU’s 6th sanctions package, under the 8th package the EU has banned the maritime transport of those products – subject to a price cap. Ths means that EU countries may now trade Russian oil with third countries as long as the price of that oil remains below a price cap set by the European Council.

New import and export bans

The EU has expanded its import bans to Russian iron, steel, jet fuel, plastics, machinery and appliances, vehicles, ceramics, textiles, footwear, jewellery, and certain chemical products. The new import restrictions are estimated to be worth around €7 billion. 

The 8th sanctions package also expands export bans, with a focus on firearms, military goods and technology, and other products that could be used to develop Russia’s defence sector or fuel Putin’s aggression against Ukraine. The export ban specifically targets:

  • Goods and technologies with potential military use, including semiconductors, electronic integrated circuits, certain chemical substances and nerve agents.
  • Small firearms, and goods with no practical use other than torture, punishment, or degrading treatment.
  • Aviation products including certain oils, tyres, and brake pads. 
  • Products that could enhance Russian industrial capacities, including certain types of coal.

RMRS Ban

The EU has applied a transaction ban to the Russian Maritime Register of Shipping (RMRS), which carries out classification and inspection activities of Russian and certain non-Russian ships. From 8 April 2023, any Russian vessel certified by the RMRS will also be banned from accessing EU ports and locks.

Crypto ban

The EU has tightened its existing restrictions on Russian crypto assets by issuing a complete ban on all crypt-asset accounts, wallets, or custody services to Russian customers. The ban previously only applied to assets worth more than €10,000.

Sanctions expansion to Kherson and Zaporizhzhia oblasts

The EU has expanded its trade and investment ban to the non-government controlled areas of Ukraine’s Kherson and Zaporizhzhia oblasts. The ban previously only applied to the non-government controlled areas of Donetsk and Luhansk oblasts. The expansion follows Putin’s order that Russian armed forces enter those areas.

Russian asset freezes

The EU has expanded the list of individuals subject to asset freezes, with two new designations: 

  • PJSC Kamaz, a Russian military and vehicle manufacturer
  • The National Settlement Depository, Russia’s central securities depository

The EU has also introduced a mechanism to freeze the assets of persons that facilitate Russia sanctions evasion.

Sanctions Impact

The EU’s 8th package of Russia sanctions demonstrates the bloc’s commitment to maintaining pressure on Vladmir Putin’s regime while the conflict in Ukraine is ongoing, and  requires firms within the EU to adjust their customer screening and monitoring solutions to account for new designations.

In practice, this involves collecting and analysing a diverse range of customer data, including sanctions list and watchlist data, and information from media sources from around the world. The Russia sanctions landscape evolves rapidly and, as revealed by European Commission Chief Ursula von der Leyen, the EU is already discussing a 9th package of sanctions “to hit Russia where it hurts to blunt even further its capacity to wage war on Ukraine”. 


Given the scope of the Russia sanctions challenge, it is important to implement an automated screening solution with the power to manage vast amounts of customer data, and with the flexibility to adapt to evolving compliance requirements. Ripjar’s Labyrinth Screening platform is designed for exactly that purpose: integrating cutting edge machine learning technology, Labyrinth is capable of searching customer names against thousands of data sources, including sanctions lists, watch lists, and adverse media in over 20 languages. Labyrinth delivers real time results, and screens on an ongoing basis, enabling you to generate more accurate customer risk profiles, and know as soon as possible when that risk changes.


To learn more about Russia sanctions
compliance screening, contact us today.

FATF Changes to Black and Grey Lists

The Financial Action Task Force (FATF) maintains a “black list” and “grey list” of countries that have “strategic deficiencies” in their anti-money laundering (AML) and counter-financing of terrorism (CFT) regimes. 

Officially known as the High Risk Jurisdictions subject to a Call for Action, the FATF black list serves to alert financial service providers to the risks of doing business with certain countries, and to encourage the governments of those countries to take appropriate action to implement the FATF’s AML/CFT Recommendations. The FATF calls on member states to apply enhanced due diligence measures when dealing with customers from black list countries and to “apply counter-measures to protect the international financial system from the money laundering, terrorist financing, and proliferation financing (ML/TF/PF) risks” that they pose.

In addition to the black list, the FATF maintains a “grey list”, referred to as Jurisdictions under Increased Monitoring. Like the black list, the grey list sets out countries that have strategic AML/CFT deficiencies, but that are cooperating with the FATF by working through an action plan to address them expeditiously.

While inclusion on the grey list denotes an elevated level of AML/CFT risk, the FATF does not advise enhanced due diligence (EDD) when dealing with designated countries. However, in the UK and EU it is a legal requirement to apply EDD when customers are based in High Risk Third Countries or if transactions involve those countries. In the UK, HMT’s list of High Risk Third Countries is the FATF grey list. In the EU, the European Commission also largely bases its list on the grey list.

As the FATF conducts its periodic reviews and Mutual Evaluation Reports (MER), countries may be added to, and withdrawn from, the black and grey lists depending on the progress (or lack thereof) that they have made in addressing relevant issues. In October 2022, following a Plenary session, the FATF updated its black list and grey list to reflect the new global AML/CFT risk landscape. In order to remain compliant with domestic AML/CFT regulations, and to avoid potential criminal risks, financial services providers and other obligated entities should be familiar with the updated lists, and understand how to achieve compliance when dealing with customers from designated countries.

Recent changes to the FATF black list

Myanmar

In February 2020, Myanmar committed to an FATF action plan to address strategic deficiencies in its AML/CFT infrastructure. That plan expired in September 2021 and, after noting a “continued lack of progress” in addressing AML/CFT issues, the FATF added Mynamar to its Jurisdictions under Increased Monitoring in October 2022. 

The FATF has identified key measures that Myanmar must implement in order to be removed from the black list. These include:

  • Demonstrating an improved understanding of key money laundering risks
  • Implementing risk-based on-site and off-site inspections 
  • Demonstrating enhanced use of financial intelligence in money laundering investigations
  • Ensuring that money laundering is investigated and prosecuted in line with its risks
  • Demonstrating international cooperation in the investigation of transnational money laundering cases
  • Increasing the seizure of the proceeds of crime, and managing the seized assets to preserve their value prior to confiscation
  • Implementing targeted financial sanctions to combat weapons proliferation financing

Myanmar joins two other countries on the black list:

  • Democratic People’s Republic of Korea 
  • Iran

Recent changes to the FATF grey list

The FATF has recently added the following countries to its Jurisdictions under Increased Monitoring: 

United Arab Emirates: In a 2022 Plenary and Working Group Meeting, the FATF noted that the UAE had made progress in addressing its money laundering and terrorism financing risk. However, it also noted that more work was required to improve the country’s money laundering investigations and prosecutions, and so added the UAE to the grey list in October 2022. 

Democratic Republic of the Congo: Following insufficient progress implementing the recommendations on its 2021 Mutual Evaluation Report (MER), the FATF added the DRC to the grey list in October 2022. 

Mozambique: While Mozambique made a political commitment to improve its AML/CFT deficiencies, the FATF noted that it had not made sufficient progress, and added it to the grey list in October 2022. 

Tanzania: Like Mozambique, the FATF noted that Tanzania had made improvements to its AML/CFT infrastructure following its 2021 MER, but had not made sufficient progress in addressing key points in its action plan. Tanzania was added to the grey list in October 2022. 

In December 2022, the FATF’s list of Jurisdictions under Increased Monitoring included the following countries: 

  • Albania
  • Barbados
  • Burkina Faso
  • Cambodia
  • Cayman Islands
  • Democratic Republic of the Congo
  • Gibraltar
  • Haiti
  • Jamaica
  • Jordan
  • Mali
  • Morocco
  • Mozambique
  • Panama
  • Philippines
  • Senegal
  • South Sudan
  • Syria
  • Tanzania
  • Turkey
  • Uganda
  • United Arab Emirates
  • Yemen

How to comply with black list and grey list changes

Countries on the FATF black list and grey list present a high risk of money laundering, and firms should exercise extreme caution when doing business with companies within those jurisdictions. While all transactions involving black list countries require firms to implement enhanced due diligence measures, firms should also treat grey list countries with a high degree of caution due to the elevated risk of financial crime. 

With this in mind, firms should review their compliance solutions to ensure that they are effectively applying the FATF AML/CFT recommendations. This means conducting risk assessments of each customer and then applying compliance measures, including ongoing screening and monitoring, that are commensurate with the risk profile that those customers present. 

In order to establish an accurate risk profile, however, it will be necessary to collect and analyse a vast amount of customer data, drawn from a range of information sources, including internal due diligence, watchlists, sanction lists, politically exposed person lists, and international media. Ripjar’s Labyrinth Screening platform has been developed for exactly this purpose: Labyrinth enables firms to screen customers in real time against thousands of data sources, including sanctions and watchlists, and foreign media sources in over 20 languages. Integrating cutting-edge machine learning technology, Labyrinth is designed to help you adapt quickly to a changing risk landscape, including updates to the FATF black and grey lists, by seamlessly blending structured and unstructured data to generate actionable compliance intelligence. 


To find out more about FATF black list and
grey list screening, contact us today.

MAS Announces Strategy For Combating the Financing of Terrorism

The Monetary Authority of Singapore (MAS), the city’s primary financial regulator, published its five-pronged National Strategy for Countering the Financing of Terrorism (CFT) on 7 October 2022. The Strategy serves as a roadmap for the development of action plans to counter the financing of terrorism through Singapore’s financial system, and emphasises the role of local law enforcement agencies with international partnerships and counterparts, reflecting the global nature of the terrorism threat.

MAS published the CFT strategy following a holistic assessment conducted in 2020. Following that assessment, the regulator identified Singapore’s key terrorism financing threats as stemming from “regional and international terrorist groups”, and from “radicalised individuals” operating alone. The CFT strategy was devised to enhance coordination between Singapore’s law enforcement agencies, government policy makers, supervisory agencies, regulators, and private sector organisations.

The five prongs of MAS’ CFT strategy are as follows:

1. Coordinated and Comprehensive Risk Identification

Under this prong of the CFT strategy, MAS will ensure that it takes a whole-of-government approach to preventing terrorism financing. In particular, MAS states that government agencies should work closely with each other through “already well-established cooperation committees and networks”. It states that these agencies should review the terrorism financing landscape on a regular basis, considering “current and emerging typologies, international standards and requirements, and inputs from the private sector and academia”.

Under the Strategy, MAS will put a comprehensive legal framework in place so that Singapore’s law enforcement authorities will be able to take “swift and effective action” against the financiers of terrorism, which may include terrorist organisations and terrorists themselves. MAS will also ensure that Singpaore’s financial sanctions framework matches international standards and conventions, and that there is a clear policy framework in place to help identify terrorists that are attempting to raise funds.

3. Robust Regulatory Regime and Risk Targeted Supervisory Framework

MAS will work to ensure that Singapore’s AML/CFT regulatory framework remains robust and resilient. Similarly, it will ensure that the city’s “risk-based supervisory framework” and private sector AML/CFT compliance requirements continue to meet international best practice standards, and the standards set out by the Financial Action Task Force (FATF).

As terrorism financing methodologies become more sophisticated, MAS will also work to improve Singapore’s surveillance and supervisory measures “through the use of data analytics and technological tools”. MAS will use those tools to collect and analyse data from global sources, and to “detect and target higher risk activities and entities” that may present terrorism financing threats.

4. Decisive Law Enforcement Actions

MAS notes that law enforcement agencies already have “an effective operational framework to investigate and prosecute” incidents of terrorism financing, but points out that there is still scope for greater inter-agency cooperation. To that end, the Strategy includes a commitment to enhance cooperation between Singapore’s law enforcement agencies in order to detect and investigate terrorism financing cases promptly. 

MAS will also expand its collaboration with private sector businesses to “better detect and disrupt” terrorism financing. Similarly, it will work to enhance Singapore’s legal framework to ensure that terrorism financing investigations are prosecuted successfully.

5. International Partnerships and Cooperation

MAS notes the importance of international cooperation in the fight against terrorism financing. With that in mind, the Strategy will see MAS “continue to rigorously implement” international anti-money laundering and counter-financing of terrorism standards, which are set by bodies such as the FATF and the United Nations Security Council (UNSC). MAS will also continue to work and cooperate with other international jurisdictions, both seeking and providing legal assistance in order to “proactively tackle” funding flows associated with terrorist financing. 

The Strategy states that MAS will use a range of mechanisms to achieve its CFT partnership and cooperation objectives, including entering into bilateral agreements, and using intelligence sharing platforms. As part of the Strategy, MAS restates Singapore’s commitment to contributing to the international fight against terrorism financing by taking “firm and resolute action” wherever it detects criminal activities.

MAS Compliance

MAS’ five pronged strategy underlines the importance of effective AML/CFT compliance for firms that operate within Singapore. The Strategy is still relatively new to the city-state’s regulatory landscape, so its immediate impact remains to be seen, but the details set out in the five prongs suggest that multilateral cooperation, with Singapore’s law enforcement agencies and with other private sector entities, will be central to AML/CFT regulatory framework going forward. 

Risk based AML/CFT will also continue to underpin Singapore’s compliance landscape, meaning that firms must continue to implement effective automated customer screening and monitoring in order to detect criminal activities. Accordingly, in order to enable that level of risk-based compliance, and cooperation with other entities, firms in Singapore must be able to harness customer data quickly and efficiently. 

Ripjar’s Labyrinth Screening platform has been developed to enable firms to achieve that compliance objective, with the capacity to screen thousands of data sources in real time, including sanctions lists, watch lists, and adverse media in over 20 languages. Labyrinth seamlessly blends structured and unstructured data, delivering actionable intelligence to help you firm understand when risk profiles change or when customers engage in suspicious activities, and then to act decisively to inform MAS in order to prevent terrorist activities


To learn more about compliance with MAS AML/CFT regulations, contact us today.

AUSTRAC Release New Risk Assessment For Independent Remittance Dealers

In September 2018, the Australian government announced funding for a $5.2 million initiative between the Australian Transaction Reports and Analysis Centre (AUSTRAC) and industry partners to produce “targeted national money laundering/terrorism financing risk assessments for Australia’s largest financial sectors” including two risk assessments for the remittance sector. The first would focus on independent remittance dealers (IRD) and the specific money laundering (ML) and terrorism financing risks (TF) that they face, while the second would focus on risks to “remittance network providers and their affiliates”.

In September 2022, AUSTRAC released the first of those risk assessments which drew from a comprehensive review of 1,100 intelligence reports and suspicious matter reports (SMR), 13% of which related to IRDs that “use their own products, platforms or system to provide remittance services directly to customers”. In the report, AUSTRAC points out that the IRD category refers to very large entities and very small entities: consequently, the risk assessment reflects the variety of ML/TF threats that collectively affect the industry. 

AUSTRAC has stated that the risk assessment is not intended to be received as “targeted guidance or recommendations” for IRDs’ anti-money laundering (AML) and counter-financing of terrorism (CFT) compliance efforts. However, the regulator does expect IRDs to review the assessment and use it to: 

  • Inform their in-house risk assessments
  • Improve their risk management systems
  • Improve their understanding of the wider risk landscape

With those factors in mind, let’s take a closer look at AUSTRAC’s IRD report, and examine some of its key highlights.

Remittance Providers’ ML/TF Threat Environment

As part of the risk assessment, AUSTRAC assessed the threat environment facing IRDs in Australia, which refers to “the nature and extent of money laundering, terrorism financing, and predicate offences associated with IRDs”. AUSTRAC classified the threat environment as presenting a “medium” risk but broke down its analysis across the different types of threat: money laundering, predicate offences, and terrorism financing. 

Money Laundering

AUSTRAC assessed the money laundering threat environment to IRDs as presenting a “high” level of risk, with both larger and smaller Australian IRDs facing the same level of threat, including links to “serious and organised crime”. 

The risk assessment suggested that the IRD sector was primarily exploited for the purposes of placing and layering illegal funds because of its specialisation in moving money quickly and at low cost over multiple transactions. High risk foreign money laundering jurisdictions for Australian IRDs included the UK, the US, China, and Nigeria, with most key money laundering predicate offences (such as fraud, trafficking, and tax evasion) originating in Australia. 

AUSTRAC outlined the following common indicators of IRD money laundering: 

  • Customers that are unable to explain their source of funds.
  • Customers using cash payments or multiple debit cards to fund their remittances.
  • Remittances sent through certain jurisdictions that do not match the customer’s profile.
  • Cash deposits in amounts just below reporting thresholds.
  • Seeming coordination between multiple customers opening new accounts.
  • Customers requesting personal details (such as names) to be omitted from transactions.
  • Recipients of remittances that have no apparent connection to the sender.

Terrorism Financing

The AUSTRAC risk assessment classified the IRD terrorism financing threat as ‘medium’. The classification reflects the relatively low number of terrorism-financing related alerts submitted by IRDs and represents a decrease from previous assessments, perhaps a result of changing terrorism financing methodologies. Despite the risk classification, AUSTRAC pointed out that IRDs were involved in 20% of all terrorism-financing intelligence reports in the review. 

Key indicators of terrorism financing involving IRDs include: 

  • Use of cash to fund remittances.
  • Remittances sent to high risk jurisdictions.
  • Enquiries from law enforcement or media organisations.
  • Reasons given for remittances including ‘charitable donation’ or ‘family support’.
  • Individual or non-profit organisation customers.

Predicate Offences

A predicate offence refers to a crime which generates illegal funds that must subsequently be laundered. The AUSTRAC report classified the threat to IRDs from predicate offences as “medium” and the regulator pointed out that the risk was predominantly against larger IRDs, reflecting their dominance in the sector. 

The risk assessment identified the following key predicate offence threats to IRDs:

  • Fraud: IRDs are attractive targets for fraudsters because of their capacity to facilitate money transfers across the world with little prospect of recovery. 
  • Scams: Criminals perpetrate a range of scams in Australia, including romance scams, false billing scams, and remote access scams, and request that victims send them money using IRD services. 
  • Child exploitation: IRDs facilitate the rapid movement of funds to jurisdictions that carry a high risk of child exploitation crimes. 
  • Drug trafficking: IRD services are exploited most commonly for small scale drug trafficking. 
  • Tax evasion: IRDs are used for personal tax evasion as commonly as they are for corporate tax evasion. 

IRD Vulnerabilities

The AUSTRAC risk assessment set out the inherent vulnerabilities of the IRD sector that criminals commonly target.

Customers: The IRD sector serves a diverse customer base, which includes a significant proportion of customers from ethnic communities which are likely to remit money for family support, community funding, and charitable donations. The IRD customer population includes a “moderate number” of higher risk customers, including known criminals, foreign customers, companies and trusts, and politically exposed persons (PEP). 

Products and services: The IRD sector’s products and services represent a “high” ML/TF vulnerability as a consequence of their high exposure to cash and the speed with which they move funds between accounts. Similarly, some IRD services enable customers to exchange currencies, making it more difficult to track their origins. 

Delivery channels: The risk assessment stated that the decline in face-to-face customer contact, and the shift to online or remote service as a consequence of the COVID-19 pandemic, was an increasingly significant vulnerability of the IRD sector. In particular, the anonymity and speed of online IRD services present opportunities for criminals to launder money successfully. AUSTRAC also identified the use of outsourced third party service providers in foreign countries as a vulnerability because of the added complexity that process adds to the remittance process.

Foreign jurisdictions: The IRD sector’s ongoing exposure to foreign jurisdictions represents an ML/TF vulnerability because of the inherent regulatory complexity of the cross-border movement of funds. Cross-border remittances also increase the likelihood of contact with high risk jurisdictions. 

Consequences

AUSTRAC characterised the consequences of ML/TF in the IRD sector as “major”, and set out the effects of those crimes on the following individuals and groups:

Customers

The report suggests that criminal activity may have an increased impact on individual customers, causing both financial and emotional damage. Specific consequences include:

  • Personal and financial loss and emotional distress
  • Potential legal repercussions for victims
  • Increased compliance spends causing price increases for customers
  • Loss of services due to de-risking

Businesses

AUSTRAC suggests that ML/TF threats pose significant “financial, operational, and reputational risks” to the IRD subsector, including:

  • Financial losses and increased insurance costs
  • Reputational damage and difficulties establishing business relationships
  • Stricter regulatory oversight
  • Enforcement and legal actions, potentially with civil or criminal penalties
  • De-banking and de-risking

The Australian Financial System

The AUSTRAC review points out that ML/TF activities damage Australia’s international reputation and the country’s financial infrastructure. Specific consequences include:

  • Difficulties combating crime
  • Reduced government revenues
  • Increased financial and physical damage from predicate crimes
  • Increased financing of illegal activities as a result of undetected money laundering
  • Loss of confidence in the Australian IRD sector

National and International Security

The AUSTRAC review suggests that ML/TF in the IRD sector has the potential to impact national and international security interests, with consequences that include:

  • Gang related violence
  • Increased influence of drug trafficking organisations in foreign countries
  • Increased support for Australian foreign terrorists 
  • Facilitation of terrorism in Australia and overseas

How to Reduce ML/TF Risk in IRDs

AUSTRAC notes that risk mitigation strategies vary significantly between IRDs, which means that some face a greater level of risk than others. While some IRDs have “relatively comprehensive risk mitigation strategies”, others have “unsophisticated approaches” with deficiencies in customer due diligence (CDD), staff training, and understanding of AUSTRAC AML/CFT obligations. The review sets out specific ways that Australian IRDs could enhance their risk mitigation measures, including: 

  • Regular assessments of customer risk
  • Enhancements to CDD and screening processes
  • Comprehensive risk assessments for enterprise IRDs
  • Regular independent audits of risk management solutions
  • Employee training

The review identified enhanced risk assessments, CDD, and customer screening as crucial components of an IRD risk mitigation solution. Implementing those measures effectively as part of a compliance solution means IRDs must collect and analyse vast amounts of customer data, and be able to act quickly when suspicious activity is detected. 

Ripjar’s Labyrinth Screening platform was developed to help IRDs and other financial service providers manage their risk mitigation requirements with speed, accuracy and efficiency, and achieve AUSTRAC compliance on an ongoing basis. Labyrinth Screening enables IRDs to screen customer names against thousands of news and adverse media sources, and international watchlists, in over 20 languages, in real time. Our platform is built with cutting-edge machine learning technology to seamlessly blend structured and unstructured data, and provide actionable intelligence. 


To learn more about IRD screening and risk management solutions, contact us today.