Category: Mission

Evolution or revolution? Rethinking our approach to eliminating dirty money

Graham Barrow
Ripjar Strategic Advisor – Financial Crime

Banks will be waking up this morning to a new world in which the previous sanctity of their Suspicious Activity Reports (SARs) has been lost.

With the publication yesterday of the first batch of stories emanating from the massive FinCEN data leak, the world has changed and will not be able to return to the status quo ante.

For many, this will be the first time they have read in any detail about SARs which are the centre of the furore.

Hitherto, they have been a little-known tool used by the banks to report suspicious activity identified within their operations. And today, depending on who you believe, their release has opened up a previously hidden world in which government departments leap into robust, but unseen, action working to rid the world of some of its most corrupt or criminal actors or it has unmasked the process as simply a useful way for banks to report issues after the fact in an effort to avoid regulatory censure, fines or worse. And often only in response to stories they have read in the newspapers, having previously failed to identify anything suspicious at all.

The truth, as so often, lies somewhere between the two although it is clear from the scale of the leaks and the lack of any obvious corrective action having been taken against the underlying activity identified, that the system isn’t working.

The most compelling question is this. Do we try to refurbish the existing edifice or knock the house down and rebuild it from scratch?

To find an answer, it is necessary to understand the current process.

There are, essentially, two types of SAR. One where you report a transaction which is “in progress” (known here in the UK as a “Defence against Money Laundering SAR or DAML) and the other where you report after the fact. About 1 in 14 SARs filed are DAMLs.

Inevitably, this means that, even where suspicion is identified (which we know to be an exceedingly small percentage of the true criminal funds flowing through the system) overwhelmingly, the identification happens after the fact.

“What’s the point then?” you might reasonably ask.

Intelligence.

Post facto SARs are designed to give the NCA (or equivalent) a huge trove of financial intelligence from which to identify organised criminality or grand corruption. Except, from the evidence we see daily, they don’t.

There are still enormous inflows, for example, into London property purchased on behalf of individuals who have no obvious source of income or capital commensurate with the value of the assets they are buying. And often, these people occupy positions of influence in countries with recently emergent economies and high levels of poverty amongst their indigent populations.

The contrast is stark.

Which brings you to an obvious follow up question.

Why doesn’t all this intelligence make any difference?

In the year to March 2019, the NCA received 478,437 SARs of which 34,151 were DAML SARs. That’s close on 2,000 SARs every working day. In March 2019 there were 118 staff (up from 80 the year before) which simply isn’t enough to process so many SARs, especially as the DAMLs have to take priority because of the need to respond within 7 working days.

If we look specifically at some of the cases currently being reported, we see almost instantly that the actors identified in the SARs are massively multi-jurisdictional. The SAR might identify, for example, a Russian national, with a business that is being run via a UK corporate vehicle, which is controlled by corporate directors based in the Marshal Islands and with a bank account in Estonia.

Just what is a UK based NCA operative supposed to do with such a SAR? They have no jurisdiction over any element of the report save the UK registered address of the company. Which is often just a high street provider of mailboxes.

And that issue, which is replicated the world over, is at the heart of why this is such an important story and why the current system is more to do with banks filing SARs to be compliant and not to help in the fight against financial crime.

How much better would it be if they could file to some form of global centre of excellence (at least for those SARs which have an international flavour) which DID have jurisdiction in at least some of the affected countries?

If we truly are serious about tackling this plague of criminality, these revelations ought to prompt us to act, and not just bemoan the lax security which allowed the leak in the first place.

Financial Crime: How we fight back.

The impact of financial crime is rarely overstated. It is the beating heart of criminal enterprises all over the world; it is the mechanism from which crime pays. Without the ability to launder the proceeds of crime, those that traffic in humans, or narcotics, or fund international terrorist groups – would struggle.

However, that they continue do so with such impunity is cause for serious concern. Despite decades of regulatory best-practice, collaboration, top down and bottom up initiatives – they succeed on a daily basis. Billions in illicit finance that fuels international criminality, bribery, violence, drugs and abuse of fundamental human rights; ultimately threatening our prosperity and collective security.

Against this well-trodden background – and with strong worldwide regulatory frameworks to marshal resources – a collection of people, organisations and technologies has evolved to make criminals life more difficult. By all accounts this is a $250bn+ industry and growing every year. And yet, it never seems to be enough. Case studies of the failings of this regime seem abundant, and becoming more frequent.

We need a revolution the response, much like the surge in innovation and mindset change that went into the global security community after 9/11. Like many of my colleagues here at Ripjar, I worked for over a decade within the UK intelligence community. We saw that response first hand. Working with financial institutions now, we see the same shift in mindset happening. Not just developing new ways of checking boxes faster, but developing much more effective controls to genuinely counter financial crime.

This focus on effectiveness means looking deeply at the methods and techniques that have traditionally been employed. It means questioning received wisdom for how things have ‘always’ been done. It means recognising that despite decades of investment and progress, financial intuitions are still dealing with age old issues of poor quality data, large numbers of false alerts, and a huge amount of manual and tedious analysis that cannot possibly hope to scale to the volume of both clients and data.

Inefficient and ineffective. No wonder criminals have adapted rapidly to ride roughshod through such controls and under the noses of even the most well-resourced compliance departments. Hidden in the noise, through myriad cutouts and cunning tradecraft – they are winning.

One of the key technologies we believe will bring about this revolution is artificial intelligence. Much of the hype around this topic has undoubtedly cost it some advocates, but getting it right is critical to scaling precious resources to covering more risk. Machine learning can both broaden the set of data that is utilised to understand whether a crime is taking place, but also at the same time it can narrow and reduce the noise and likelihood that what is brought back is relevant to an investigation, a review or an alert.

Properly implemented, AI can even spot patterns and behaviours that human beings are just not capable of, and to do so at a scale that would be impossible to resource manually.

The second aspect to this will be a step change in the way that people, teams, organisations, banks, law enforcement and regulators can share data and intelligence. There is not a discipline in history that has not benefited from greater information sharing and collaboration. No single team has all the pieces of the jigsaw. Indeed, the very idea of ‘intelligence failure’ – the inability to connect the dots in advance of a strategic shock – is hard-wired into the security and intelligence community. The ‘need to share’ rather than the ‘need to know’.

However, the difficulties of even sharing the most basic information on criminals abusing the international banking system is clear. Worse, existing methods for sharing data with law enforcement such as Suspicious Activity Reports (SARs) result in both oversharing (resulting in a deluge in poor quality data for the NCA), and dramatic under sharing – where the right data (or parts of the data) are not shared, resulting in large gaps in the overall intelligence picture.

For this reason, it is great to see that a core pillar of the UK government’s recently announced Economic Crime Plan (2019-2022) is to fundamentally look at how information is shared both in a voluntary and regulatory capacity, and even to legislate the necessary changes to ensure effective information sharing can take place between banks, between law enforcement – between the right people needed to protect the integrity of the overall banking system and preventing criminal finance.

This coordinated, industry-wide approach will require a cooperation and collaboration between technology vendors, financial institutions, fintechs, supra-national bodies, governments and law enforcement. I believe that by improving the technological fabric, transforming the way we analyse data, of joining the dots between disparate sources, and finding new ways to securely share intelligence between organisations, is critical to the success of countering financial crime effectively. I’m truly excited that Ripjar can step up to this challenge and look forward to working with the industry.