AML & Financial Crime – grcsight.com

AML Training

AML training teaches a firm’s staff how to recognize and respond to money laundering. It is a legal requirement for regulated firms and covers the warning signs, the reporting process, and each person’s duties. Well-trained staff are a firm’s first line of defense. Key takeaways AML training teaches staff to recognize and report money laundering. It is a legal requirement and one of the pillars of an AML program. Everyone needs it, with deeper training tailored to higher-risk roles. It should cover warning signs, the reporting path, and personal responsibilities. Most firms train staff at least once a year, and again when risks change. Records of training are evidence a regulator will ask to see. On this page What it isWhy it is requiredWho needs itWhat it should coverHow oftenFormatsMaking it effectiveCommon mistakesRecord-keepingFAQsRead more $3B Paid by TD Bank in 2024 after control and awareness gaps Source: US Department of Justice 1989 Year the FATF set the standard training supports Source: FATF $800B to $2T Laundered worldwide each year that training helps catch Source: UNODC What is AML training? AML training is the instruction a firm gives its people so they can spot and respond to money laundering. It turns the rules in a policy into knowledge staff can use on the job. The aim is practical. A trained employee should recognize a warning sign, know who to tell, and understand their own responsibilities under the law and the firm’s policy. Training is one of the required pillars of an AML program. Read more: see how it fits within an AML compliance program. Why AML training is required Training is required because people are the first line of defense against laundering. A tool can flag a transaction, but staff often notice the human signals a system misses. It is also a legal duty. Regulators expect regular, relevant training, and its absence is a common finding. Weak awareness contributes to real failures, including large cases such as TD Bank in 2024, which drew about $3 billion in penalties (US Department of Justice, 2024). Beyond compliance, good training protects staff. An employee who knows the rules is less likely to be drawn into a scheme unaware. Give your team a shared reference Use our red flags checklist so staff have a clear guide to the warning signs their training covers. Open the Red Flags Checklist → Who needs AML training? Everyone in a regulated firm needs some AML training, but not the same amount. The depth should match the role. All staff. A baseline that covers the warning signs and how to report. Front-line teams. Deeper training for those onboarding customers or handling transactions. Compliance and the MLRO. Specialist knowledge of the law and the program. Senior management and the board. Enough to oversee the risk and set the tone. New joiners should be trained early, before they handle customers or payments. Contractors and temporary staff in relevant roles are easy to overlook, but they carry the same duties and the same risk, so they should be trained too. What AML training should cover Good training is specific to the firm and its risks. A generic slideshow rarely changes behavior. The core topics are consistent. What money laundering is. The basics, including the three stages. Warning signs. The red flags relevant to the firm’s customers and products. The reporting path. How to raise a concern and file a suspicious activity report. Personal responsibilities. What the law and the policy require of each person. Consequences. The penalties for the firm and for individuals who get it wrong. Real examples and scenarios make these topics stick far better than rules alone. How often should AML training happen? Training is not a one-time event. It has to be refreshed to stay useful and to meet regulatory expectations. Most firms train staff at least once a year. Training should also be refreshed when something changes, such as a new product, a new rule, a new risk, or a lesson from an incident. New joiners are trained as they start. Base training on your real risks Get an indicative read on where your money laundering risk sits so training can focus where it matters. Try the AML Risk Assessment → Formats and delivery Training comes in several formats, and a mix usually works best. The right choice depends on the audience and the message. E-learning. Quick to roll out and easy to track, good for baseline training. In-person or live sessions. Better for discussion and higher-risk roles. Scenarios and case studies. Turn theory into recognizable situations. Short refreshers. Brief updates that keep awareness current between full courses. Whatever the format, relevance to the person’s actual job is what makes training land. How to make AML training effective Effective training changes what people do, not just what they have seen. A few things separate training that works from training that is endured. Make it specific. Use the firm’s own products, customers, and risks. Use real examples. Scenarios and cases are more memorable than rules. Tailor by role. Give each group what it actually needs. Test understanding. Check that the message landed, not just that the course was opened. Refresh it. Keep content current as risks and rules change. Common AML training mistakes Most weak training programs fail in the same few ways. Avoiding them is the difference between training that changes behavior and training that is simply endured. Generic content. A one-size course that never mentions the firm’s real products or customers. Tick-box delivery. Treating completion as the goal, rather than understanding. Same for everyone. Giving a cashier and an MLRO the identical material. Set once. Content that is never refreshed as risks and rules change. No testing. No check that the message actually landed. Fixing these usually costs little. Tailoring examples to the firm and testing understanding turns a compliance chore into a control that works. Record-keeping Records of training are as important as the training itself. To a regulator, training that is not recorded may … Read more

Willful blindness

Willful blindness Willful blindness is a legal doctrine that treats a person’s deliberate avoidance of confirming a fact as equivalent to actually knowing it. Courts use it to stop defendants from escaping liability just by claiming they never had positive proof of something they strongly suspected and specifically avoided finding out for certain. The doctrine’s clearest foundation in US law comes from a 1976 marijuana smuggling case that had nothing to do with finance, but its logic now sits at the centre of how AML knowledge standards get proven. Key takeaways Willful blindness treats deliberate avoidance of confirming a suspected fact as legally equivalent to knowing it. United States v. Jewell (9th Circuit, 1976) is the clearest foundational US case, involving 110 pounds of marijuana hidden in a car. Courts require two things: a subjective belief in high probability, and a deliberate choice not to confirm it. The doctrine traces to English common law and is deliberately kept narrow to avoid collapsing into simple negligence. In AML cases, it’s a common theory for proving knowledge against professionals who ignored obvious red flags. Genuinely missing a red flag is a control failure; noticing one and choosing not to escalate it is a materially riskier position. On this page What willful blindness actually meansThe case that established it: United States v. JewellThe two-part test courts actually applyWhere the doctrine came fromWhy the doctrine is deliberately narrowHow willful blindness applies in AML and financial crimeWillful blindness vs simple negligenceWhat this means for compliance teams specificallyFAQsRead more 1976 Year the Ninth Circuit decided United States v. Jewell, establishing the doctrine in US law Source: 532 F.2d 697 (9th Cir. 1976) 110 lbs Marijuana hidden in the car at the centre of the Jewell case Source: United States v. Jewell What willful blindness actually means Willful blindness, sometimes called deliberate ignorance or conscious avoidance, lets a court treat a defendant’s intentional failure to confirm a suspected fact as legally equivalent to knowing that fact outright. The idea is simple: someone who strongly suspects something illegal is happening, and deliberately avoids finding out for certain specifically so they can later deny knowledge, shouldn’t be able to use that self-imposed ignorance as a defence. It’s not a finding that someone was careless or should have known better. It requires a genuine, specific choice to avoid confirming something the person already strongly suspected. The case that established it: United States v. Jewell The doctrine’s clearest foundation in US law comes from United States v. Jewell, decided by the Ninth Circuit Court of Appeals in 1976. Charles Jewell was offered $100 to drive a car across the US-Mexico border after being approached by a stranger in a bar; the car turned out to have 110 pounds of marijuana hidden in a secret compartment. Jewell argued he didn’t have positive knowledge the drugs were there. The court, sitting en banc, upheld his conviction, ruling that deliberate ignorance in the face of overwhelming suspicion is legally equivalent to actual knowledge. The decision established what’s sometimes called the “ostrich instruction,” a jury instruction allowing conviction where a defendant deliberately avoided learning a fact they strongly suspected was true. The two-part test courts actually apply Courts applying the doctrine generally require proof of two specific things: that the defendant subjectively believed there was a high probability that the fact in question was true, and that the defendant took deliberate action to avoid confirming it. Both elements matter. Simply failing to investigate isn’t enough on its own; the defendant has to have already strongly suspected the truth and then made a conscious choice not to find out for certain. That second element, the deliberate choice, is what separates willful blindness from ordinary carelessness. A person who never had any real suspicion in the first place hasn’t been willfully blind, whatever else they might be. Where the doctrine came from The Jewell court itself traced the doctrine’s roots to English common law, describing the classic illustration of an innkeeper who deliberately avoids his own back room specifically to escape visual confirmation of the gambling he already believes is taking place there. Legal scholar Glanville Williams, quoted in the court’s opinion, framed the underlying rule tightly: someone suspects a fact, realises its probability, but deliberately avoids the final confirmation because they want to be able to deny knowledge later. That, and only that, is willful blindness. Williams himself warned that the doctrine has to stay narrow. Stretched too broadly, it risks collapsing into the much weaker civil standard of negligence, holding someone liable simply for failing to find something out, rather than for a deliberate choice to avoid confirming a strong suspicion. Worth knowing. The doctrine’s own foundational case traces its logic to an old English illustration: an innkeeper who deliberately avoids his own back room specifically to escape confirming the gambling he already suspects is happening there. Why the doctrine is deliberately narrow Courts have been consistently careful to keep the doctrine’s scope tight for exactly the reason Williams flagged. Where a criminal statute specifically requires proof of positive knowledge, substituting a broader standard, mere carelessness, or a general failure to investigate, would effectively rewrite what the legislature actually required. That’s why the two-part test matters so much in practice: a prosecutor generally can’t get a willful blindness instruction just by showing a defendant failed to ask an obvious question. They need evidence the defendant already strongly suspected the truth and made a specific choice not to confirm it. How willful blindness applies in AML and financial crime In AML enforcement specifically, willful blindness has become a recurring theory for proving the knowledge element behind money laundering charges, particularly against financial professionals who claim they simply processed transactions without asking questions. A banker who repeatedly processes transactions with clear hallmarks of laundering, unusual structuring, implausible business rationale, mismatched documentation, and deliberately avoids the obvious follow-up questions, can face liability under this theory even without a direct admission that they knew. The doctrine gives prosecutors … Read more

Five Pillars of AML

The five pillars of AML are the required parts of a US anti-money laundering program: internal controls, a compliance officer, ongoing training, independent testing, and customer due diligence. The fifth pillar, customer due diligence, was added in 2018, turning the original four pillars into five. Key takeaways The five pillars of AML are the required parts of a US AML program. They are internal controls, a compliance officer, training, independent testing, and CDD. The fifth pillar, customer due diligence, was added in 2018. Before that, US programs were built on four pillars. The fifth pillar includes identifying the beneficial owners of companies. The pillars together form an AML compliance program. On this page What they areWhy five, not fourThe five pillarsThe fifth pillarFive vs fourPart of a programBuilding itWeak pillarsFAQsRead more 5 Pillars of a US AML program today Source: FinCEN 2018 Year customer due diligence became the fifth pillar Source: FinCEN CDD Rule $3B Paid by TD Bank in 2024 after pillar failures Source: US Department of Justice What are the five pillars of AML? The five pillars of AML are the building blocks every US anti-money laundering program must contain. They are set by regulation, and a program missing any one of them is not compliant. The pillars give a program its structure. Each covers a different part of the job, from writing the rules to checking that they work and knowing who the customer is. Together, the five pillars are what a regulator expects to see. Read more: the pillars are the required parts of an AML compliance program. Why five pillars, and not four? For years, a US AML program rested on four pillars. In 2018 a fifth was added, which is the source of the common four-versus-five confusion. The change came from FinCEN’s Customer Due Diligence Rule, which took effect in May 2018. It made customer due diligence, including identifying the beneficial owners of company customers, a formal requirement in its own right. What had been part of good practice became a named pillar. So both numbers are correct, at different times. Programs built before 2018 spoke of four pillars, while modern programs speak of five. If you come across either number, it helps to know which one a source means, since the requirement today is five. The five pillars, one by one Each pillar covers a distinct part of an AML program. Here is what each one means in practice. Internal controls. The written policies and procedures that put the program into action, from onboarding to reporting. A compliance officer. A designated person, the BSA or AML officer, who owns and runs the program. Ongoing training. Regular education so staff can recognize and respond to laundering. Independent testing. A periodic, independent review that checks the program actually works. Customer due diligence. Knowing who the customer is, and who really owns a company customer. The first four are the original set. The fifth, customer due diligence, is the one added in 2018. Build your program on the pillars Generate a tailored AML policy draft that sets out controls, roles, training, and due diligence. Open the AML Policy Generator → Screen customers as part of due diligence Run one search across sanctions, PEP, and adverse media data to support the fifth pillar of your program. Try Combined AML Screening → The fifth pillar explained The fifth pillar, customer due diligence, is worth a closer look, since it is the one that changed the count. It has two parts. The first is knowing the customer: verifying who they are and understanding the nature of the relationship, through customer due diligence. The second is beneficial ownership: for company customers, identifying the real people who own or control them, so a firm cannot be fooled by a shell company. Adding this as a pillar reflected a simple truth. A program cannot manage risk if it does not truly know its customers. Five pillars vs four pillars The difference between five and four is just the fifth pillar. Everything else is shared. Four pillars Five pillars Internal controls Yes Yes Compliance officer Yes Yes Training Yes Yes Independent testing Yes Yes Customer due diligence No Yes (added 2018) If you see a reference to four pillars, it is usually describing a program before 2018, or a simplified summary. Read more: the original set is covered in the four pillars of AML. How the pillars form a program The five pillars are not a checklist to tick once. They work together as a living program that a firm runs continuously. Controls set the rules, the compliance officer runs them, training equips staff, due diligence keeps customer risk in view, and independent testing checks the whole thing works. A weakness in any one pillar undermines the others, which is why regulators look at them as a set. This is also why the pillars are described as a program, not a checklist. A checklist is done once, while a program runs continuously, adapting as the firm and its risks change. Worth knowing. Regulators do not just ask whether all five pillars exist on paper. They ask whether each one actually works. A program can name a compliance officer, run training, and hold a policy, and still fail if those pillars are hollow. Effectiveness, not presence, is the real test. Building a program around the five pillars Standing up the five pillars follows a natural order, where each rests on the one before it. Assess the risk first. Base the whole program on where the firm’s laundering risk actually sits. Write the controls. Turn that risk picture into clear policies and procedures staff can follow. Name the officer. Give a senior person real ownership of the program, with the authority to run it. Build due diligence. Set how the firm identifies customers and the beneficial owners behind companies. Train, then test. Equip staff to play their part, then check independently that the whole thing works. Notice the order. The risk assessment comes first, … Read more

Compliance Culture

Compliance culture is the shared set of attitudes and behaviors toward following the rules across a firm. It is set by the tone at the top, and it decides whether controls are taken seriously or treated as a box-ticking exercise. Key takeaways Compliance culture is the shared attitude toward following the rules. It is set largely by the tone at the top of a firm. Strong culture makes controls work; weak culture undermines them. It differs from compliance risk, the risk of failing to comply. Weak culture sits behind many major compliance failures. It is built through leadership, incentives, and how a firm responds to concerns. On this page What it isTone at the topWhy it mattersStrong vs weakCulture vs riskWhen culture failsBuilding itMeasuring itFAQsRead more $3.09B TD Bank penalty tied to a weak compliance culture, 2024 Source: US Department of Justice 1989 Year the FATF set the global AML standard Source: FATF $800B to $2T Laundered worldwide each year that weak culture enables Source: UNODC What is compliance culture? Compliance culture is the shared attitude a firm has toward following the rules. It is the difference between a place where doing the right thing is simply how things are done, and one where rules are seen as obstacles to work around. Culture is not written in a policy. It lives in how people actually behave, what leaders reward, and what happens when someone raises a concern. A firm can have excellent controls on paper and a poor culture in practice, and the culture usually wins. It underpins everything else in compliance. Read more: it shapes how a firm’s AML governance works in reality. Tone at the top Compliance culture starts at the top of a firm. The attitude of leaders sets the tone that everyone else follows, which is why the phrase tone at the top matters so much. When senior leaders treat compliance as important, back it with resources, and hold people to account, staff take it seriously too. When leaders treat it as a nuisance or quietly reward those who cut corners, that message travels just as clearly. People watch what leaders do far more than what they say, so the tone at the top becomes the culture on the ground. Why compliance culture matters Compliance culture matters because controls only work if people use them properly. A rule that staff ignore or game protects no one. The strongest policies in the world fail if the people applying them do not care whether they work. A good culture means staff report concerns, follow procedures because they understand why, and do the right thing even when no one is watching. A weak culture means the opposite: corners cut, warnings ignored, and problems hidden. This is why regulators increasingly look at culture, not just controls. Signs of a strong or weak culture Compliance culture shows itself in everyday behavior, not in mission statements. A few signs point each way. Strong: concerns are welcomed. People raise issues without fear. Strong: compliance is resourced. The function has the people and tools it needs. Weak: pressure to hit targets. Results valued over doing things properly. Weak: shooting the messenger. Those who raise concerns are sidelined. The clearest test is what happens when compliance and commercial goals collide, and which one gives way. Compliance culture vs compliance risk Compliance culture and compliance risk are related but distinct, and it helps to keep them apart. One is an attitude, the other a threat. Compliance culture is the shared mindset toward following the rules. Compliance risk is the risk that a firm fails to comply and suffers the consequences. The link is that a weak culture raises compliance risk: when people do not take the rules seriously, failures become more likely. Culture is a cause; risk is what that cause can produce. Compliance culture Compliance risk What it is The shared attitude to the rules The risk of failing to comply Nature A mindset and behavior A threat and its consequences Link A weak culture raises the risk The outcome a weak culture invites Put simply, culture is how seriously a firm takes compliance, and risk is what it stands to lose if it does not. Set out expectations in an AML policy Generate a tailored AML policy draft that sets clear expectations and reinforces the right culture. Open the AML Policy Generator → When compliance culture fails Weak compliance culture sits behind many of the largest failures, even where controls existed on paper. The pattern repeats across cases. Time and again, major compliance breakdowns trace back not to missing rules but to a culture that did not take them seriously. In its 2024 case, TD Bank was penalized about $3.09 billion after regulators found long-running AML failures, a case widely read as a failure of culture as much as of controls. When a firm treats compliance as an obstacle, the controls it has tend to be worked around rather than followed. Worth knowing. A recurring lesson from enforcement is that culture beats controls. Firms that suffered the worst failures often had policies and systems in place; what they lacked was a culture that made people use them properly. This is why regulators now probe how a firm behaves, not just what its manuals say. Good controls with a poor culture is a fragile combination. Building a strong compliance culture Building a strong culture takes more than a policy; it takes consistent action from the top. A few things do the heavy lifting. Lead by example. Have senior leaders visibly back compliance. Align incentives. Avoid rewarding results won by cutting corners. Welcome concerns. Make it safe to raise issues, and act on them. Train and explain. Help staff understand why the rules exist. Do this: reinforce the message with structured AML training across the firm. Measuring compliance culture Culture is hard to measure, but not impossible, and firms increasingly try. A few signals give a read. Firms look at things like whether staff feel … Read more

Kleptocracy

Kleptocracy A kleptocracy is a form of government in which those in power use the state primarily to enrich themselves, treating public funds and resources as personal property. The term combines the Greek words for theft and rule. Unlike an isolated corrupt official, a kleptocratic regime makes large-scale theft a structural feature of how the state runs, not an occasional failure of it. Key takeaways A kleptocracy uses state power itself as the mechanism for large-scale theft, not just individual corrupt acts. Transparency International’s 2004 estimate put Sani Abacha’s theft from Nigeria at $2 billion to $5 billion. The US described its 2014 forfeiture of over $480 million in Abacha-linked assets as the largest kleptocracy forfeiture action in US history at the time. The World Bank and UNODC’s StAR Initiative has tracked roughly $6 billion in stolen assets frozen, adjudicated or returned globally since 1980. Stolen state wealth is laundered through the same channels as other criminal proceeds: shell companies, real estate, and offshore structures. Because kleptocrats are almost always PEPs, this risk sits at the centre of enhanced due diligence programmes. On this page What kleptocracy meansHow a kleptocracy actually extracts wealthReal examples and what they revealWhere the stolen money goesWhy kleptocracy is an AML problem, not just a governance oneSpotting kleptocracy-linked wealth in due diligenceFAQsRead more $2bn-$5bn Transparency International’s 2004 estimate of what Sani Abacha stole from Nigeria (1993-1998) Source: World Bank StAR Initiative $480m+ In Abacha-linked assets forfeited by the US in 2014, called the largest kleptocracy forfeiture action in US history at the time Source: US Department of Justice, via World Bank StAR $6bn+ In stolen assets frozen, adjudicated or returned worldwide since 1980, across 240+ documented cases Source: World Bank / UNODC StAR Initiative What kleptocracy means Kleptocracy describes a system, not a single act. Public office becomes a vehicle for personal enrichment at every level the leadership controls: state contracts, natural resource revenues, central bank reserves, and government budgets all become extraction points. What separates it from ordinary corruption is scale and structure. A kleptocratic regime doesn’t just tolerate theft; it’s often organised around it, with loyalty rewarded through access to stolen wealth. How a kleptocracy actually extracts wealth Common mechanisms include diverting state contracts to companies the leadership or their associates secretly own, skimming natural resource revenue before it reaches the treasury, and directly looting central bank reserves or state-owned enterprises under the pretence of national security or other official cover. Real examples and what they reveal Sani Abacha, Nigeria’s military ruler from 1993 to 1998, is one of the most thoroughly documented cases. Transparency International’s 2004 estimate put his theft from the Nigerian state at $2 billion to $5 billion. In 2014, the US Department of Justice forfeited more than $480 million in Abacha-linked assets, which it described at the time as the largest kleptocracy forfeiture action in US history. Recovery has been slow even with clear documentation. Switzerland alone has returned between $700 million and $1.3 billion to Nigeria across multiple settlements since the early 2000s, more than two decades after Abacha’s death. Worth knowing. Recovering stolen assets is slow even when the theft is well documented. Nigeria’s case against Sani Abacha’s estate has run for more than two decades across multiple jurisdictions, and full recovery still isn’t complete. Where the stolen money goes Stolen state wealth needs laundering like any other criminal proceeds: shell companies, real estate purchases in stable jurisdictions, and offshore structures that separate the money from its origin. The World Bank and UNODC’s Stolen Asset Recovery (StAR) Initiative has tracked roughly $6 billion in stolen assets frozen, adjudicated or returned worldwide since 1980, across more than 240 documented cases, and notes that figure likely represents only a fraction of the true total. Why kleptocracy is an AML problem, not just a governance one Once stolen funds leave the state, they enter the same financial system everyone else uses. Banks, real estate agents, and company formation agents in stable jurisdictions become, often unknowingly, part of the laundering chain. That’s why kleptocracy sits squarely inside AML programmes, not just anti-corruption or governance ones. Spotting kleptocracy-linked wealth in due diligence Because a kleptocrat and their family are almost always politically exposed persons, enhanced due diligence and ongoing screening are the primary controls. A source of wealth that can’t be independently corroborated against a documented career or legitimate business history is the clearest warning sign, along with corporate structures with no obvious commercial purpose beyond obscuring ownership. Screen for kleptocracy-linked wealth Cross-check a PEP’s assets against independent public records and adverse media before onboarding. Try Combined AML Screening → Frequently asked questions What is a kleptocracy? A kleptocracy is a form of government where those in power use the state primarily to enrich themselves, treating public funds and resources as personal property. It’s a structural feature of how the regime runs, not an occasional failure. What is the difference between kleptocracy and grand corruption? Kleptocracy describes a system of government organised around theft. Grand corruption describes the abuse of high-level power more broadly, which can happen within a kleptocracy or as a series of individual acts by senior officials in an otherwise functioning state. How much money has been stolen by kleptocratic leaders? Figures vary by case and are hard to verify precisely, but documented estimates run into the billions for individual regimes. Transparency International, for example, estimated Sani Abacha’s theft from Nigeria at $2 billion to $5 billion. How do kleptocrats launder stolen state assets? Through the same channels used to launder any criminal proceeds: shell companies, real estate purchases in stable jurisdictions, and layered offshore structures designed to separate the money from its origin. How does kleptocracy show up in AML due diligence? Kleptocrats and their families are almost always politically exposed persons, so enhanced due diligence and ongoing screening are the primary controls, with particular attention to source of wealth evidence that can’t be independently corroborated. Read more: our ultimate guides, whitepapers and templates Related guides and … Read more

Bureau de Change Risk

Bureau de change risk is the money laundering risk that comes with currency exchange businesses. Because they handle large volumes of cash and can convert one currency to another quickly, they are attractive to launderers and carry higher-than-average AML risk. Key takeaways Bureau de change risk is the ML risk from currency exchange businesses. A bureau de change swaps one currency for another, usually in cash. Cash volume and anonymity make them attractive to launderers. They are a type of money service business and must follow AML rules. They are often subject to de-risking by banks. Strong controls and monitoring are needed to manage the risk. On this page What it isWhy they are riskyHow they are misusedA money service businessThe controls they runDe-riskingRed flagsHow firms manage itFAQsRead more 1970 Year the US Bank Secrecy Act brought exchanges into AML rules Source: FinCEN 1989 Year the FATF set the global AML standard Source: FATF $800B to $2T Laundered worldwide each year, some through cash exchange Source: UNODC What is bureau de change risk? Bureau de change risk is the money laundering risk attached to currency exchange businesses. A bureau de change, or currency exchange, lets people swap one currency for another, and that simple service can be turned to laundering. The risk is not that these businesses are dishonest. Most are legitimate and serve travelers and traders. The risk is that their nature, cash-heavy and fast, makes them useful to criminals who want to move or convert dirty money. They sit among the higher-risk businesses in AML terms. Read more: they are a form of money service business. Why bureaux de change are risky Several features make currency exchanges risky from a money laundering point of view. Together they add up to a real vulnerability. Cash-heavy. They deal largely in physical cash, which is hard to trace. Anonymous. Small exchanges can be done with little or no identification. Fast conversion. Dirty money in one currency becomes clean-looking money in another. High volume. Large numbers of transactions can hide illicit ones. Cross-border. They sit at the point where money changes currency and often country. None of these is a problem on its own, but combined they make exchanges a natural target for laundering. How bureaux de change are misused Criminals misuse currency exchanges mainly to place and convert dirty cash. The service does the work of disguise for them. A launderer can bring in cash from crime and exchange it for another currency, breaking the link to its source. They may also use exchanges to convert smuggled cash after it crosses a border, or to move value without a bank trail. Because a legitimate exchange handles so much cash anyway, illicit transactions can blend in with honest ones. The exchange does not need to be complicit for this to work; a busy, legitimate bureau can be used without ever knowing it. A money service business A bureau de change is a type of money service business, which is why it falls under AML rules. It is not outside the system; it is squarely inside it. As a money service business, a currency exchange must register with the relevant regulator and run a full AML program, including customer checks and reporting. In the US, this duty flows from the Bank Secrecy Act framework overseen by FinCEN. The rules recognize the risk and place clear obligations on the business to manage it. Get an indicative AML risk rating See where your money laundering risk is concentrated, including cash and currency exposure. Try the AML Risk Assessment → The controls a bureau de change must run To manage its risk, a currency exchange runs the same core AML controls as other regulated firms. A few are especially important given the cash exposure. Identify customers. Verify identity, especially above set thresholds. Monitor transactions. Watch for unusual patterns and large cash exchanges. Report. File reports on suspicious activity and large cash transactions. Keep records. Retain evidence of exchanges and checks. Do this: weigh a currency corridor’s risk with our Country Risk Checker. De-risking of bureaux de change Bureaux de change face a particular problem: banks often see the whole sector as too risky and cut them off. This is called de-risking. When a bank closes a currency exchange’s account, the exchange can struggle to operate, since it needs banking to function. This de-risking has hit the sector hard, and regulators have warned that shutting out entire categories of business can push money into less visible channels. The better approach is to judge each exchange on its own controls. Worth knowing. Bureau de change risk shows the tension at the heart of AML. The same features that make a currency exchange useful to travelers, speed and cash, make it useful to launderers. The answer is not to shut down the sector, which drives activity underground, but to hold each business to strong, well-run controls. Risk that is managed is safer than risk that is merely pushed out of sight. Red flags at a bureau de change Certain patterns suggest a currency exchange is being misused. Staff and compliance teams watch for them. Large cash exchanges. Sums that do not fit an ordinary traveler or trader. Frequent exchanges. Repeated conversions just under reporting thresholds. Reluctance to identify. Customers avoiding giving identification. Unusual currencies. Conversions with no clear business or travel reason. A single flag may mean nothing, but a pattern is what prompts a closer look and, where needed, a report. How firms manage bureau de change risk Managing this risk, whether as an exchange or as a bank dealing with one, comes down to strong controls and clear judgment. A few priorities matter most. Assess the risk. Understand the exposure the business or relationship carries. Run strong controls. Apply identity checks, monitoring, and reporting. Judge case by case. Assess each exchange on its controls, not the sector alone. Watch the cash. Pay particular attention to large and unusual cash activity. Screen a customer or counterparty Run … Read more

Underground banking

Underground banking Underground banking describes systems that move money or value between people without it ever passing through a formal bank. Hawala, hundi, and fei ch’ien are the best-known regional names for the same basic idea: a network of trusted brokers who settle value between each other later, often through trade or cash, rather than moving actual currency across borders in real time. FATF has studied these systems for decades because they’re both a genuine financial lifeline for the unbanked and a channel criminals can exploit. Key takeaways Underground banking moves value between locations without it passing through formal banking channels, usually via trusted broker networks. Hawala, hundi, and fei ch’ien are regional names for the same basic mechanism, which FATF groups together as HOSSPs. Chinese fei ch’ien-style networks date back to the Tang Dynasty (618-907 AD), predating formal banking by centuries. These systems are a genuine financial lifeline for the unbanked, which is why outright bans often just push activity further underground. FATF’s standards call for licensing and core AML obligations, not prohibition, as the more effective response. Risk usually surfaces indirectly, through correspondent banking and trade finance activity connected to regions where these systems dominate, not through direct participation. On this page What underground banking actually isHow a hawala-style transfer actually worksThe many names for the same ideaWhy it’s older than the formal banking systemWhy it’s legitimate and vulnerable at the same timeWhere FATF’s standards actually target itRed flags that distinguish licit use from launderingWhat this means for a firm’s own risk assessmentFAQsRead more 618-907 AD Tang Dynasty period during which Chinese fei ch’ien-style transfer networks are documented Source: Australian Institute of Criminology 2013 Year FATF published its detailed typology report on hawala and other similar service providers Source: FATF What underground banking actually is Underground banking is any system for transferring value from one place to another that operates outside formal banking channels. The person sending money hands it to a local broker; a connected broker somewhere else pays out the equivalent amount to the recipient, often within hours. No money physically crosses the border in between. Regulators use several near-synonymous terms for this: alternative remittance systems, informal funds transfer systems, informal value transfer systems. Whatever the label, the mechanism is the same: value moves; currency mostly doesn’t. How a hawala-style transfer actually works A typical transfer works like this: a customer gives cash to a broker in one country, along with a simple identifying code or password. The broker contacts a counterpart broker in the destination country, who pays the equivalent sum, minus a small fee, to whoever presents that code. No wire transfer happens between the two brokers at the time of the transaction. The brokers settle their own accounts with each other later, often through trade invoicing, cash shipments, or simply letting balances run in one direction until it’s worth settling, rather than through the formal correspondent banking system most transfers eventually rely on. The many names for the same idea The same basic system goes by different names depending on the region. Hawala is the term most associated with South Asia and the Middle East. Hundi is the equivalent term used in Pakistan. Fei ch’ien describes similar networks tied to Chinese communities. FATF’s own typology work groups these together as hawala and other similar service providers, or HOSSPs, precisely because they share the same defining features regardless of what a specific community calls them. The systems appear across a huge geographic range, from Hong Kong and Paraguay to Canada and Nepal, which is part of why regulators treat them as a single category of risk rather than a narrow, regional concern. Why it’s older than the formal banking system Underground banking isn’t a modern workaround invented to dodge banking regulation. Chinese funds transfer networks recognisably similar to modern fei ch’ien systems date back to the Tang Dynasty, between 618 and 907 AD, long before anything resembling a formal international banking system existed. Hawala-style networks across South Asia and the Middle East have similarly deep historical roots, originally built to support trade across regions where formal banking was absent, unreliable, or simply didn’t exist yet. That history matters for how regulators approach the systems today. This isn’t fringe infrastructure retrofitted for illicit use; it’s older, more established infrastructure that predates the alternative it’s now measured against. Why it’s legitimate and vulnerable at the same time For millions of people, underground banking is the only practical way to send or receive money, particularly migrant workers sending remittances home to countries with limited formal banking access, weak infrastructure, or populations that are unbanked for reasons ranging from cost to lack of documentation. The World Bank and IMF have both recognised these systems as a genuine, often essential financial lifeline, not merely a workaround. The same features that make these systems useful, speed, low cost, minimal documentation, trust-based settlement, are exactly what makes them attractive to criminals moving illicit proceeds. A system built to move money with a password and a phone call, rather than formal identification, is much harder for a regulator or law enforcement agency to trace after the fact. Where FATF’s standards actually target it FATF addressed this directly in its 2003 best practices paper on combating the abuse of alternative remittance systems, which grew out of what was then Special Recommendation VI on terrorist financing. The core ask is straightforward: countries should require money or value transfer services, including hawala-style networks, to be licensed or registered, and to comply with the same core AML obligations, customer due diligence, record-keeping, suspicious transaction reporting, as formal financial institutions. FATF’s later, more detailed 2013 report on hawala and similar service providers pushed further, arguing that outright bans tend to just push the activity further underground rather than eliminating the underlying risk, and that licensing and engagement produce better visibility than prohibition alone. Worth knowing. FATF’s own research suggests that banning hawala-style systems outright tends to push the activity further underground rather than eliminating the underlying … Read more

Consent Order

A consent order is a formal agreement between a firm and a regulator that settles an enforcement action. It usually sets a penalty and the changes the firm must make, and the firm agrees to it rather than fight the case in court. Key takeaways A consent order settles an enforcement action by agreement with a regulator. It usually sets a penalty and the fixes the firm must make. The firm agrees to it instead of contesting the case. It is a common outcome of AML enforcement by bank regulators. It differs from a deferred prosecution agreement, which is criminal. Ignoring the terms of a consent order brings further, harsher action. On this page What it isHow it worksWhat it containsVs deferred prosecutionVs debarmentIn AMLWhy firms accept themHow firms respondFAQsRead more $3.09B TD Bank penalty, resolved partly through regulatory consent orders, 2024 Source: US Department of Justice 1970 Year the US Bank Secrecy Act, enforced via consent orders, was enacted Source: FinCEN $800B to $2T Laundered worldwide each year that enforcement targets Source: UNODC What is a consent order? A consent order is a settlement. When a regulator finds a firm has broken the rules, the two often agree on how to resolve it, and that agreement is set out in a consent order. The word consent is the key. The firm consents to the terms, usually a penalty and a list of required changes, rather than fighting the regulator in a lengthy legal battle. Both sides get certainty, and the matter is closed on agreed terms. It is one of the most common ways AML cases end. Read more: the failures behind them often involve a weak AML compliance program. How a consent order works A consent order follows a fairly standard path, from finding to agreement. The steps are broadly the same across regulators. The regulator investigates. It examines the firm and identifies failures. Terms are negotiated. The regulator and firm agree on a penalty and required fixes. The order is issued. The consent order sets out the terms in a binding document. The firm complies. It pays any penalty and makes the required changes. Because the firm agrees, a consent order avoids a contested hearing. It is faster and more certain than litigation for both sides. What a consent order contains A consent order typically sets out both the punishment and the path forward. Several elements are common. Findings. A description of the failures the regulator identified. A penalty. A financial amount the firm must pay, in many cases. Required actions. The specific changes the firm must make to fix the problem. Oversight. Sometimes a requirement to report progress or accept a monitor. Often the required actions matter more than the penalty. Fixing the underlying failure is usually the regulator’s real goal. Consent order vs deferred prosecution agreement A consent order and a deferred prosecution agreement both resolve a matter by agreement, but they sit in different worlds. The difference is civil versus criminal. A consent order is usually a civil or regulatory tool, agreed with a regulator to settle an enforcement action. A deferred prosecution agreement is a criminal tool, agreed with a prosecutor to hold criminal charges in abeyance. One resolves a regulatory failing; the other resolves potential criminal liability. Consent order Deferred prosecution agreement Nature Civil or regulatory Criminal Agreed with A regulator A prosecutor Resolves A regulatory failing Potential criminal charges A single large case can involve both at once, a consent order with regulators and a separate agreement with prosecutors. Consent order vs debarment It also helps to separate a consent order from debarment, which people sometimes confuse. They do very different things. A consent order settles an enforcement action, usually with a penalty and required fixes. Debarment excludes a firm or person from contracts or programs, such as government or development-bank work. One is a settlement; the other is an exclusion. A firm can face both, but they are separate consequences. Get an indicative AML risk rating See where your money laundering risk is concentrated so you can fix gaps before a regulator does. Try the AML Risk Assessment → Consent orders in AML In anti-money laundering, consent orders are a familiar tool of the bank regulators. They are how many AML failures are formally resolved. When a bank regulator finds AML failings, such as weak monitoring or poor controls, it often issues a consent order requiring the firm to fix them, frequently alongside a penalty. In its 2024 case, TD Bank resolved matters through a combination of a criminal plea and regulatory consent orders, part of a roughly $3.09 billion resolution. These orders, enforced under the Bank Secrecy Act framework, are a routine part of the AML enforcement landscape. Why firms accept consent orders Firms usually accept a consent order because the alternative is worse. Fighting a regulator is costly, slow, and uncertain. A contested case can drag on for years, cost a fortune in legal fees, and still end in a loss, with the added glare of a public fight. A consent order brings certainty: known terms, a defined penalty, and a chance to move on. For most firms, agreeing is the pragmatic choice, even where they might dispute some of the findings. Worth knowing. A consent order is not just a penalty; it is a roadmap the regulator expects the firm to follow. The required actions often set out, in detail, how the firm must rebuild its controls. Failing to deliver on those actions is itself a serious matter, sometimes treated more harshly than the original failure, because it signals the firm did not take the agreement seriously. How firms respond to a consent order Once a consent order is in place, the firm’s job is to deliver on it fully. A few priorities shape a good response. Understand the terms. Be clear on exactly what is required. Fix the root cause. Address the failure, not just its symptoms. Show progress. Report on the changes the order … Read more

Illicit Financial Flows

Illicit financial flows (IFFs) are money that is illegally earned, transferred, or used as it moves across borders. They cover the proceeds of crime and corruption as well as tax evasion and trade misinvoicing, and they drain huge sums from developing economies each year. Key takeaways Illicit financial flows are illegally earned, moved, or used money crossing borders. They include crime, corruption, tax evasion, and commercial misinvoicing. IFFs are broader than money laundering, though the two overlap. UNCTAD estimated Africa loses about $88.6 billion a year to IFFs. They hit developing countries hardest, draining money needed for development. Fighting them relies on transparency, tax cooperation, and AML controls. On this page What they areTypes of IFFsHow they moveThe scaleIFFs vs launderingThe impactHow they are tackledIFFs and AMLFAQsRead more $88.6B Estimated annual loss to Africa from illicit financial flows Source: UNCTAD, 2020 ~$1T Estimated yearly illicit outflows from developing countries Source: Global Financial Integrity $800B to $2T Laundered worldwide each year, an overlapping problem Source: UNODC What are illicit financial flows? Illicit financial flows are money that breaks the law at some point in its journey across borders. The money may be illegally earned, illegally moved, or illegally used, and any one of these makes the flow illicit. The term is deliberately broad. It captures not only the proceeds of crime, but also money hidden to dodge tax or moved through dishonest trade pricing, even where the underlying business is legal. IFFs are a global concern because the money crosses borders and escapes oversight. Read more: much of it is later hidden through money laundering. Types of illicit financial flows IFFs are usually grouped into three broad types. They differ in where the illegality lies. Criminal. Proceeds of crimes such as drug trafficking, fraud, and smuggling. Corrupt. Bribes and stolen public funds moved out of a country. Commercial. Money hidden through tax evasion and trade misinvoicing, often by otherwise legal businesses. The commercial category is the largest and the hardest to see, because it hides inside ordinary-looking trade and tax arrangements. Estimates suggest it accounts for the bulk of illicit flows, which is why so much attention has turned to trade and tax transparency. How illicit financial flows move IFFs use a range of methods to cross borders unseen. Most rely on hiding the money’s true nature or owner. Trade misinvoicing. Over- or under-pricing goods to move value across borders. Money laundering. Disguising criminal proceeds so they can be moved and used. Hidden ownership. Shell companies and nominees that conceal who really benefits. Tax evasion schemes. Shifting profits to low-tax or secretive places. Trade misinvoicing is thought to be the single largest channel, precisely because global trade is so vast that mispricing hides easily within it. Screen a counterparty across borders Run one search across sanctions, PEP, and adverse media data to check a cross-border customer or partner. Try Combined AML Screening → The scale of illicit financial flows The sums involved are staggering, though hard to measure precisely. Because the money is hidden by design, all figures are estimates. UNCTAD estimated that Africa alone loses about $88.6 billion a year to illicit financial flows (UNCTAD, 2020). Global Financial Integrity has estimated that developing countries as a whole lose around a trillion dollars each year in illicit outflows. Whatever the exact number, it dwarfs the aid many of these countries receive. That gap between what leaves and what comes in is what makes IFFs a development issue, not just a crime one. Illicit financial flows vs money laundering IFFs and money laundering overlap, but they are not the same. The difference is one of scope. Money laundering is about disguising the criminal origin of money. Illicit financial flows are broader: they include laundering, but also tax evasion and trade misinvoicing that may involve legally earned money moved illegally. In short, laundering is one way IFFs happen, not the whole of it. Money laundering Illicit financial flows Focus Hiding criminal origin Any illegal earning, moving, or use Includes Proceeds of crime Crime, corruption, and tax or trade abuse Money involved Illegally earned Sometimes legally earned, illegally moved So every laundered dollar can be an illicit flow, but not every illicit flow is laundering. Check a country’s financial crime risk Look up a country against FATF, sanctions, and corruption data to weigh a cross-border deal. Try the Country Risk Checker → The impact of illicit financial flows The heaviest cost of IFFs falls on developing countries. Money that should fund schools, hospitals, and roads leaves instead, often for wealthier or more secretive places. Beyond the lost funds, IFFs weaken institutions, fuel corruption, and widen inequality. They also undermine trust, since honest taxpayers and businesses compete against those who cheat. This is why bodies such as the United Nations treat cutting IFFs as a development goal. The effect compounds over time. Money that leaves cannot be taxed, invested, or spent at home, so each year of outflows leaves a country a little poorer and a little less able to fund the very institutions that might stop the next round. Worth knowing. The uncomfortable truth about illicit financial flows is that the money does not vanish, it lands somewhere. Funds drained from poorer countries often end up in property, banks, and companies in wealthier ones, which is why transparency in rich financial centers matters as much as enforcement in the countries losing the money. How illicit financial flows are tackled Fighting IFFs takes more than any one country can do alone, because the money crosses borders. The main tools work together. Transparency. Beneficial ownership registers that reveal who is behind companies. Tax cooperation. Countries sharing tax information to catch evasion. AML controls. The screening, monitoring, and reporting that catch dirty money. Trade scrutiny. Checks on pricing to catch misinvoicing. Do this: weigh the country side of a cross-border deal with our Country Risk Checker. Illicit financial flows and AML AML is one of the main defenses against IFFs. The same controls that catch laundering … Read more

Modern Slavery

Modern slavery is the exploitation of people through force, coercion, or deception for profit. It is also a financial crime: it generates hundreds of billions of dollars a year that must be laundered, and banks play a role in detecting and reporting it. Key takeaways Modern slavery is the exploitation of people for profit through force or coercion. It is a serious financial crime and a predicate offense for money laundering. The ILO estimates 50 million people are in modern slavery worldwide. Forced labor generates about $236 billion in illegal profits each year. The money is laundered, so financial data can reveal it. Banks help detect it by spotting financial red flags and reporting suspicion. On this page What it isA financial crimeThe scaleHow the money movesFinancial red flagsLawsThe role of banksHow firms detect itFAQsRead more 50 million People in modern slavery worldwide Source: ILO, 2021 estimates $236 billion Annual illegal profits from forced labor Source: ILO, 2024 $800B to $2T Laundered worldwide each year, including these profits Source: UNODC What is modern slavery? Modern slavery is the exploitation of people who cannot refuse or leave because of force, coercion, or deception. It is an umbrella term covering forced labor, human trafficking, debt bondage, and forced marriage. It is a grave abuse of human rights, and it is also a business for those who profit from it. That second fact is what brings it into the world of financial crime. Where there is profit, there is money to hide. Read more: those profits are cleaned through money laundering. Modern slavery as a financial crime Modern slavery is a financial crime because it is driven by money. Traffickers exploit people to make a profit, and that profit has to be collected, moved, and hidden. This makes modern slavery a predicate offense: the underlying crime that produces dirty money for laundering. It also means the money leaves a trail. Wages withheld, fees collected, and profits moved all pass through the financial system, where they can be spotted. For a bank, this is where it can make a difference. It may never see the exploitation, but it can see the money. That shift in perspective, from looking for a crime to looking for its money, is what makes financial institutions useful allies against a crime they rarely witness directly. The scale of modern slavery The scale is vast, both in human and financial terms. The figures are hard to grasp. The ILO estimates that 50 million people were living in modern slavery in 2021, including around 28 million in forced labor. Forced labor alone generates about $236 billion in illegal profits each year (ILO, 2024). That money, like other criminal proceeds, has to be laundered to be used. Those profits are part of the wider flood of criminal money that AML systems exist to catch. Behind every figure, though, is a person, which is part of what makes this one of the most serious forms of financial crime to detect. Screen a business and its people Run one search across sanctions, PEP, and adverse media data to check a customer or business for links to exploitation. Try Combined AML Screening → How the money moves The proceeds of modern slavery move through the financial system in ways that can look ordinary. Recognizing the patterns is the key to catching them. Wage accounts. Wages for many workers paid into one account controlled by a trafficker. Cash. Large cash deposits from exploitation, often through a front business. Recruitment fees. Payments from victims for jobs, travel, or debt. Layering. Moving the profits through accounts and businesses to hide their source. Because the money mixes with legitimate activity, it takes a trained eye and good monitoring to separate it out. Financial red flags of modern slavery Certain patterns in financial data can point to modern slavery. None is proof, but each is worth a closer look. Many workers’ wages paid into a single account. One address or phone number linked to many separate accounts. Salary payments that are immediately withdrawn in full. A business whose accounts do not match its stated activity. Little or no normal personal spending on a worker’s account. Payments to recruitment or travel agents that look like debt repayment. Laws on modern slavery Modern slavery is a crime everywhere, and some countries add specific duties for businesses. The laws combine criminal offenses with corporate responsibility. UK Modern Slavery Act 2015. Criminalizes slavery and trafficking and requires large firms to report on their supply chains. US laws. Federal trafficking laws, plus rules against importing goods made with forced labor. Financial crime rules. AML laws that treat the proceeds of trafficking as dirty money. Together, these mean a firm has reasons beyond decency to act: it faces legal duties on both exploitation and the money behind it. The role of banks and financial firms Banks sit in an unusual position in the fight against modern slavery. They rarely witness the crime, but they handle the money it produces. That gives them a chance others do not have. By watching for the financial patterns of exploitation and reporting suspicion, a bank can help uncover trafficking that would otherwise stay hidden. Many financial firms now train staff specifically to spot these signs. Some banks have gone further, working with law enforcement and anti-slavery charities to sharpen what they look for. The financial angle does not replace the human response, but it adds a set of eyes in a place traffickers cannot easily avoid, the banking system they rely on to collect their money. Worth knowing. Modern slavery is one of the clearest cases where following the money works. A victim may be invisible to a bank, but the account paying forty people’s wages to one address is not. This is why financial red flags have become a real tool against trafficking, sitting alongside the human and law-enforcement response. How firms detect modern slavery Firms detect modern slavery mainly by watching for its financial fingerprints and acting … Read more