AML & Financial Crime – Page 2 – grcsight.com

Drug Trafficking Proceeds

Drug trafficking proceeds are the profits from selling illegal drugs, usually in the form of large amounts of cash. Laundering this money is one of the biggest drivers of money laundering worldwide, and it has led to some of the largest bank penalties in history. Key takeaways Drug trafficking proceeds are the cash profits of the illegal drug trade. The drug trade produces vast amounts of cash that must be laundered to be usable. It is one of the biggest single drivers of global money laundering. Wachovia was penalized over about $378 billion in poorly monitored transfers linked to drug money. Common methods include cash smuggling, structuring, and cash-intensive businesses. Drug trafficking is a predicate offense for money laundering. On this page What it isWhy it needs launderingThe scaleHow it is launderedA predicate offenseRed flagsNotable casesHow firms detect itFAQsRead more $378B Poorly monitored transfers Wachovia was penalized over in 2010 Source: US Department of Justice $1.9B Paid by HSBC in 2012 over laundering for drug cartels Source: US Department of Justice $800B to $2T Laundered worldwide each year, much of it drug money Source: UNODC What are drug trafficking proceeds? Drug trafficking proceeds are the money made from selling illegal drugs. Because drug sales happen largely in cash, the profits pile up as physical notes that are hard to spend or bank without questions. That cash is useless to a criminal until it looks clean. Turning it into money that can be spent, invested, or moved is where laundering comes in, and drug money is one of its largest sources. The link is direct: the drug trade creates the dirty cash, and laundering hides it. Read more: the process itself is money laundering. Why drug money needs laundering Drug money needs laundering because raw cash is both a burden and a risk. Large sums of physical cash are hard to hide, hard to move, and dangerous to hold. A cash pile cannot be deposited in a bank without triggering questions, and it cannot buy a house or a business openly. Spending it draws attention, and holding it invites theft and detection. Laundering solves this by giving the money a clean story. This is why the drug trade and money laundering are so tightly linked. One creates the problem, the other hides it. The scale of drug proceeds The amounts involved are enormous. The global drug trade generates hundreds of billions of dollars a year, and much of the money laundering estimate is driven by it. The UNODC has estimated that between $800 billion and $2 trillion is laundered worldwide each year, roughly 2 to 5 percent of global output, and drug money makes up a large share of that. The scale is what makes it a priority for banks and regulators. The size of the problem is also why failures have been so costly, as the cases below show. Know the warning signs before they cost you Use our red flags checklist to review customers and transactions for the signs of drug-related laundering. Open the Red Flags Checklist → How drug trafficking proceeds are laundered Drug money is laundered through a familiar set of methods, most built around handling large volumes of cash. The common techniques are consistent. Cash smuggling. Physically moving bulk cash across borders to a friendlier system. Structuring. Breaking deposits into small amounts to stay under reporting limits. See structuring. Cash-intensive businesses. Mixing drug cash with the real takings of a cash-intensive business. Trade-based laundering. Hiding money in the over- or under-pricing of goods. Money mules. Using other people’s accounts to move the funds. Because drug money starts as cash, most of these methods focus on getting it into the financial system without setting off a report. Drug trafficking as a predicate offense Drug trafficking is a predicate offense for money laundering. That means it is the underlying crime that produces the dirty money. A person can face two charges: one for trafficking, and a separate one for laundering the proceeds. In fact, drug trafficking is one of the oldest and most common predicate offenses, and much of modern AML law grew out of the effort to attack drug money. Worth knowing. Modern anti-money laundering law was born largely from the war on drugs. The US made drug money laundering a federal crime in 1986, and the effort to trace and seize drug profits shaped the reporting and screening systems that banks still use today for every kind of financial crime, not just drugs. Red flags of drug-related laundering Certain patterns point to drug money. None is proof, but each is worth a closer look. Large, frequent cash deposits with no clear business source. Deposits kept just under the reporting threshold. Cash in small denominations, typical of street drug sales. Funds moving quickly to or from high-risk regions. A business whose cash far exceeds what its trade could produce. Many accounts or people used to move linked sums. Notable cases Some of the largest financial crime penalties in history involved drug money. They show how much is at stake for a bank that fails to control it. Wachovia was penalized in 2010 over a failure to monitor about $378 billion in transfers linked to Mexican exchange houses and drug cartels (US Department of Justice). Two years later, HSBC agreed to pay about $1.9 billion after admitting it had laundered money for the Sinaloa cartel and others (US Department of Justice, 2012). These cases reshaped how seriously banks treat drug-related risk. Screen a customer against global watchlists Run one search across sanctions, PEP, and adverse media data to check a customer or counterparty before you deal with them. Try Combined AML Screening → How firms detect drug-related laundering Firms detect drug money mainly by watching cash and following patterns. The controls focus on the point where dirty cash tries to enter the system. Monitor cash. Flag large or unusual cash deposits against a customer’s profile. Assess geography. Weigh exposure to known drug-producing and transit regions. Watch for … Read more

Financial Crime Risk Assessment

A financial crime risk assessment is a firm-wide analysis of exposure across every type of financial crime, including money laundering, sanctions, fraud, and bribery. It is broader than an AML risk assessment, which looks only at money laundering, and it sits at the heart of a financial crime compliance function. Key takeaways A financial crime risk assessment covers all financial crime, not just laundering. It spans money laundering, sanctions, fraud, bribery, and terrorist financing. It is broader than an AML risk assessment, which covers money laundering alone. The method is the same: inherent risk, minus controls, equals residual risk. It is the foundation of a financial crime compliance function. A stale or missing assessment is a common examination finding. On this page What it isVs AML risk assessmentWhat it coversWhy firms need oneRisk factorsHow to conduct oneHow often to refreshCommon mistakesFAQsRead more $800B to $2T Laundered worldwide each year, one part of financial crime Source: UNODC ~$300B Laundered in the United States each year Source: US Department of the Treasury $3B Paid by TD Bank in 2024 after control failures Source: US Department of Justice What is a financial crime risk assessment? A financial crime risk assessment is a structured look at where a firm is exposed to financial crime of every kind. It maps the threats the business faces, rates how serious each is, and sets how strong the controls need to be. The output is a single, ranked picture of financial crime risk, written down and defensible. That picture then guides how much effort each control deserves, across the whole range of crime types. It is the base a financial crime function is built on. Read more: it underpins financial crime compliance as a whole. Financial crime risk assessment vs AML risk assessment This is the point that causes the most confusion, so it is worth being clear. The two assessments share a method but differ in scope. An AML risk assessment looks only at money laundering. A financial crime risk assessment is wider: it covers money laundering plus sanctions, fraud, bribery, and terrorist financing. In many firms, the AML assessment is one part of the broader financial crime one. AML risk assessment Financial crime risk assessment Scope Money laundering only All financial crime Covers Laundering risk Laundering, sanctions, fraud, bribery, TF Sits within The AML program The financial crime function Same discipline, wider lens. A firm with mature controls often runs the financial crime assessment as the parent, with the AML view nested inside it. What a financial crime risk assessment covers The assessment spans the full range of financial crime a firm can face. Each area has its own risks, but they are judged together in one view. Money laundering. The risk of the firm being used to hide criminal money. Sanctions. The risk of dealing with restricted parties or countries. Fraud. The risk of deception that takes money from the firm or its customers. Bribery and corruption. The risk of improper payments. See anti-bribery and corruption. Terrorist financing. The risk of funds reaching terrorists. Judging these together is the point. A firm that assesses each crime in isolation can miss how they overlap and reinforce each other. Get an indicative financial crime risk rating See where your financial crime risk is concentrated across customers, products, markets, and channels. Try the AML Risk Assessment → Why firms need one A firm needs a financial crime risk assessment because it justifies the whole compliance function. Without it, controls are set on instinct rather than evidence. It also focuses effort where it counts. Financial crime risk is spread unevenly across a business, so a clear assessment lets a firm put people and tools where the real threats are, rather than spreading them thin. Regulators treat a weak assessment as a serious gap. The TD Bank case in 2024, with about $3 billion in penalties, stemmed in part from controls that did not match the firm’s real risk (US Department of Justice, 2024). Risk factors across crime types A sound assessment weighs several factors, each of which can apply to more than one crime type. They are judged together. Customers. Who they are, including higher-risk types and complex ownership. Products and services. Whether they favor anonymity or fast movement of funds. Geography. Exposure to high-risk and sanctioned countries. Channels. Whether business is done face to face or remotely. Delivery and third parties. The agents and partners the firm relies on. Do this: weigh the geographic side of your exposure with our Country Risk Checker. Screen a customer across financial crime risks Run one search across sanctions, PEP, and adverse media data to feed real signals into your assessment. Try Combined AML Screening → How to conduct one The method mirrors an AML risk assessment, applied across a wider set of crimes. It moves from raw exposure to a considered rating. Identify inherent risk. List the financial crime risks the firm faces before controls. Assess controls. Judge how well existing controls reduce each risk. Calculate residual risk. Work out what remains after controls. Prioritize and act. Focus attention where residual risk is highest. Document it. Record the risks, ratings, reasoning, and review date. Worth knowing. The advantage of one financial crime assessment over separate ones is that it shows how risks connect. Fraud and money laundering, for example, are often the same case seen from two ends. A single assessment catches that link, where two separate ones each see only half. How often to refresh it A financial crime risk assessment goes stale as the business changes. It should be refreshed on a schedule and whenever something material shifts. Most firms review it at least once a year. A new product, a new market, a new customer segment, a regulatory change, or a lesson from an incident should all trigger an update outside the normal cycle. A short note in the assessment recording when it was last reviewed, and when it is next due, keeps this on track and … Read more

Professional Enabler

A professional enabler is a lawyer, accountant, banker, or similar expert who helps criminals move, hide, or launder money. They may act knowingly, or through willful blindness, and their skills make serious financial crime possible. Key takeaways A professional enabler helps criminals move, hide, or launder money. They are usually lawyers, accountants, bankers, or company service providers. They may act knowingly, or turn a blind eye to obvious warning signs. Their expertise makes complex laundering and hiding of money possible. Enablers are a gatekeeper problem, and a growing enforcement focus. Being an enabler is a behavior; a DNFBP is a regulated category. On this page What it isWho they areKnowing or blindThe gatekeeper roleWhy they matterEnforcementEnabler vs DNFBPHow to avoid itFAQsRead more 11.5 million Documents leaked in the Panama Papers, exposing enablers Source: ICIJ, 2016 $800B to $2T Laundered worldwide each year, much of it with expert help Source: UNODC 1989 Year the FATF set the global anti-money laundering standard Source: FATF What is a professional enabler? A professional enabler is an expert who uses their skills to help criminals with their money. Instead of using their training for honest clients, they put it to work moving, hiding, or laundering dirty funds. The word professional is doing real work here. These are not street criminals; they are qualified people, often respected, whose knowledge of law, finance, or company structures is exactly what a launderer needs. Their help turns simple crime into sophisticated laundering. Read more: the activity they assist is money laundering. Who professional enablers are Professional enablers come from the trusted professions. Their roles give them the tools criminals cannot easily get elsewhere. Lawyers. Who can set up companies, move money through client accounts, and lend an air of legitimacy. Accountants. Who can disguise the flow of money in the books. Bankers. Who can wave through transactions that should be questioned. Company service providers. Who create the shell companies that hide ownership. Estate agents. Who help turn dirty money into property. What they share is access and trust. A launderer working alone is limited, but with a professional’s help, the options widen sharply. Knowing help or willful blindness Not every enabler is a hardened criminal, and the law recognizes shades of fault. Two broad situations arise. Knowing enablers. Those who understand what they are doing and help anyway, for a fee. Willfully blind enablers. Those who ignore obvious warning signs so they can keep the business. Willful blindness is not a defense. A professional who looks the other way when the signs are clear can still be held responsible, because the duty is to ask questions, not to avoid the answers. Screen a client before you act Run one search across sanctions, PEP, and adverse media data to check a client or counterparty before taking them on. Try Combined AML Screening → The gatekeeper role Professional enablers matter because of where they sit. They are gatekeepers, standing at the points where money enters companies, property, and the financial system. A launderer needs these gatekeepers to open doors: to form a company, to move money through a trusted account, to buy a building. When a professional opens that door, dirty money flows. When they refuse, it is blocked. This is why so much AML policy focuses on the professions that act as gatekeepers. Spot the signs early Use our red flags checklist so your team can recognize the warning signs before taking on a risky client. Open the Red Flags Checklist → Why professional enablers matter Professional enablers matter because they scale up crime. A single corrupt lawyer or accountant can help launder sums no ordinary criminal could manage alone. They also lend legitimacy. A transaction signed off by a respected firm looks clean, which is precisely its value to a criminal. This makes enablers a high priority for regulators, since removing them takes away a tool that serious financial crime depends on. Worth knowing. Professional enablers are often the difference between petty crime and grand corruption. Stealing money is one thing; hiding hundreds of millions of it across borders needs lawyers, accountants, and company formers who know how the system works. This is why targeting enablers has become a way to attack the largest laundering schemes at their weakest point. Enforcement against enablers Enablers have become a growing focus for authorities. For years, enforcement centered on the criminals themselves, but attention has turned to those who help them. The Panama Papers leak in 2016, with 11.5 million documents, laid bare how a single law firm helped clients around the world hide wealth (ICIJ, 2016). Cases like it pushed regulators to pursue enablers directly, through fines, prosecutions, and the loss of professional licenses. The message is that expertise is no shield when it is used to launder money. Some countries have set up dedicated units to target enablers, treating them as a way to disrupt the schemes they support rather than only the criminals at the top. Professional enabler vs DNFBP Professional enabler and DNFBP are related but different ideas, and it helps to keep them apart. One is a behavior, the other a category. A DNFBP is a regulatory category: the non-financial businesses, such as law and accountancy firms, that must follow AML rules. A professional enabler is a person or firm that actually helps criminals launder money. Most enablers come from within the DNFBP professions, but being a DNFBP does not make a firm an enabler. The vast majority meet their duties honestly. Professional enabler DNFBP What it is A behavior: helping crime A regulated category Judged by What they actually do Which sector they are in Most members A small minority who abuse trust Honest firms meeting their duties In short, DNFBP describes who is covered by the rules, while professional enabler describes who has broken them. How firms and professionals avoid it An honest professional avoids becoming an enabler by doing the basics and asking questions. A few habits keep a firm on the right … Read more

Predicate Offense

A predicate offense is the underlying crime that generates the dirty money later laundered. Drug trafficking, fraud, and corruption are common examples. In short, it is the source crime that produces criminal proceeds, which laundering then tries to hide. Key takeaways A predicate offense is the crime that produces the money later laundered. Common examples include drug trafficking, fraud, corruption, and theft. It is the source crime; the money it produces is the proceeds of crime. Money laundering is a separate offense from the predicate crime. The FATF lists designated categories of predicate offenses. Many countries treat almost any serious crime as a possible predicate. On this page What it isExamplesVs proceeds of crimeAll-crimes or a listWhy it mattersLink to launderingTax as a predicateHow firms think about itFAQsRead more 21 Designated categories of predicate offense listed by the FATF Source: FATF $800B to $2T Proceeds of predicate crimes laundered worldwide each year Source: UNODC 1989 Year the FATF set the global anti-money laundering standard Source: FATF What is a predicate offense? A predicate offense is the crime that comes first, before the laundering. It is the illegal act that produces the money a criminal then needs to clean. Every case of money laundering starts with one. Without an underlying crime to generate dirty money, there would be nothing to launder. The predicate offense is that starting point, the source of the tainted funds. The crime and the cleaning are two separate things in law. Read more: the cleaning itself is money laundering. Examples of predicate offenses Almost any profit-making crime can be a predicate offense. Some appear far more often than others. Drug trafficking. One of the oldest and most common sources of dirty money. Fraud. From investment scams to invoice fraud. Corruption and bribery. Stolen public funds and improper payments. Theft and robbery. Proceeds taken directly from victims. Tax evasion. Money kept by cheating the tax authorities. Human trafficking. Profits from the exploitation of people. What links them is profit. A crime that generates money creates the need to launder it, which makes it a predicate offense. Predicate offense vs proceeds of crime This is the pairing people most often confuse, so it is worth being clear. The two are linked but distinct. A predicate offense is the crime. The proceeds of crime are the money or property that crime produces. One is the act, the other is the result. Drug dealing is the predicate offense; the cash from selling the drugs is the proceeds of crime. Predicate offense Proceeds of crime What it is The underlying crime The money or property it produces Example Fraud The stolen funds Role The source The result to be laundered Keeping them apart helps. The predicate offense explains where the money came from, and the proceeds of crime are what laundering tries to disguise. Screen a customer against watchlists Run one search across sanctions, PEP, and adverse media data to check a customer or counterparty. Try Combined AML Screening → All-crimes or a listed set Countries take one of two broad approaches to defining predicate offenses. The choice affects how wide the net is cast. An all-crimes approach. Almost any serious crime can be a predicate offense, which casts a wide net. A listed approach. Only specific, named crimes count as predicate offenses. The FATF sets out designated categories of offenses that should be predicates, such as trafficking, fraud, and corruption, and many countries go further with an all-crimes rule. The wider the approach, the harder it is for a criminal to argue their money is somehow clean. Know the warning signs Use our red flags checklist to review customers and transactions for the signs of an underlying crime. Open the Red Flags Checklist → Why predicate offenses matter Predicate offenses matter because they connect laundering to real crime. To prove laundering, you often need to show the money came from an underlying offense. They also shape the scope of AML law. A country that treats almost any crime as a predicate captures far more laundering than one with a narrow list. And for a firm, the range of predicate offenses is a reminder that dirty money can come from many directions, not just the obvious ones. Worth knowing. A useful point about predicate offenses is that the launderer does not have to be the one who committed the underlying crime. A person can be guilty of money laundering for cleaning someone else’s criminal proceeds, even if they had no part in the original offense. This is why handling suspect funds, not just committing the source crime, carries real risk. How it connects to laundering The predicate offense and the laundering are two links in one chain. The first produces the money, the second hides it. A criminal commits the predicate offense, such as fraud, and ends up with dirty money. They then launder it to make it look legitimate. Because the two are separate offenses, a person can be charged with both, and often is. The laundering charge, in effect, targets what happens to the money after the first crime. This two-offense structure is deliberate. It lets authorities pursue the money trail even when the original crime happened abroad or is hard to prove, giving them a second route to hold criminals to account. Tax offenses as predicates Tax crimes deserve a mention, because their status has changed. For years, some countries did not treat tax evasion as a predicate offense for laundering. The FATF has since made clear that serious tax crimes should be predicate offenses, and many countries have brought them in. This matters because it means money kept through tax evasion can be treated as criminal proceeds, widening the reach of AML rules into an area once left out. How firms think about predicate offenses For a compliance team, predicate offenses are less a legal puzzle than a reminder to stay broad. A few points shape how firms approach them. Assume many sources. Dirty money can come … Read more

Self-laundering

Self-laundering Self-laundering is money laundering committed by the same person who committed the crime that generated the proceeds in the first place. It sounds like an obvious extension of ordinary laundering law, but several legal systems didn’t punish it as a separate offence until surprisingly recently. Italy only criminalised self-laundering in 2014, decades after its ordinary money laundering offence already existed. Key takeaways Self-laundering is money laundering committed by the same person who committed the underlying crime. Italy only criminalised self-laundering specifically in 2014, via Law 186/2014 and article 648-ter.1 of its penal code. Before that, Italy treated self-laundering as an unpunishable consequence of the original crime. The UK never had this gap: POCA 2002 was drafted so its offences cover an offender’s own proceeds from the outset. Italy’s self-laundering offence actually carries a lower maximum penalty (8 years) than its third-party laundering offence (4-12 years). Third-party laundering, laundering someone else’s proceeds, is the conceptual opposite, though the two often coexist inside one criminal operation. On this page What self-laundering actually meansWhy some legal systems didn’t punish itItaly’s 2014 turning pointWhat Italy’s self-laundering offence actually coversThe UK’s different starting pointSelf-laundering vs third-party launderingWhy the distinction matters for penaltiesWhere self-laundering shows up in AML risk assessmentFAQsRead more 2014 Year Italy first criminalised self-laundering as a standalone offence Source: Law 186/2014, Italian Penal Code Art. 648-ter.1 8 years Maximum sentence under Italy’s self-laundering offence, lower than its 4-12 year third-party laundering range Source: Italian Penal Code, Art. 648-ter.1 / 648-bis What self-laundering actually means Self-laundering happens when the person who committed a crime, drug trafficking, fraud, corruption, whatever generated the illicit proceeds, then personally launders those same proceeds rather than handing them off to someone else. The predicate offender and the launderer are the same individual. That might seem like the most obvious case money laundering law should cover. In practice, several legal systems drew a sharp line between the predicate crime and any laundering that followed, treating the laundering as something only a third party could commit. Why some legal systems didn’t punish it The reasoning behind excluding self-laundering wasn’t laziness. Many legal traditions treat using or hiding your own criminal proceeds as a natural, almost inevitable consequence of the original crime, a “post-factum” act that doesn’t deserve separate punishment on top of whatever sentence the predicate offence already carries. Punishing the same underlying conduct twice raised genuine double-jeopardy concerns in some systems. Italy is the clearest documented example. Its ordinary money laundering offence, article 648-bis of the criminal code, explicitly excludes anyone who participated in the predicate crime. For decades, a person who stole money and then laundered it themselves faced only the theft charge. Italy’s 2014 turning point That changed with Law 186/2014, which introduced article 648-ter.1 into the Italian penal code specifically to criminalise self-laundering, known in Italian as autoriciclaggio. Before this law, Italy’s own Financial Intelligence Unit noted that self-laundering was treated as a mere consequence of the original offence and therefore not punishable in itself, even though EU law already defined money laundering to include it. The gap had been visible for years. Legislative Decree 231/2007 had already adopted an EU-aligned definition of money laundering covering a predicate offender investing their own illicit proceeds, but that definition lived inside an administrative decree, not the criminal code, so it didn’t actually create a prosecutable crime. What Italy’s self-laundering offence actually covers Article 648-ter.1 punishes someone who, having committed or participated in a predicate crime, employs, substitutes, or transfers the resulting proceeds into economic, financial, business, or speculative activity in a way that concretely hinders identifying where the money came from. The maximum penalty runs to eight years, alongside a fine, lower than the four-to-twelve-year range that applies to ordinary third-party laundering under article 648-bis. The law also carved out an explicit exception: merely using or personally enjoying the proceeds, spending stolen money on yourself rather than reinvesting it to obscure its origin, isn’t punishable under this offence. Italy’s Supreme Court confirmed the scope of that exception in a 2023 ruling, finding that simply depositing drug trafficking proceeds into a personal bank account didn’t automatically qualify as the reinvestment the offence requires. Worth knowing. Italy’s Supreme Court ruled in 2023 that simply depositing drug trafficking proceeds into a personal bank account didn’t automatically count as self-laundering. The offence requires reinvestment that conceals the money’s origin, not just spending or holding it. The UK’s different starting point The UK never had this gap. The Proceeds of Crime Act 2002’s explanatory notes state plainly that all three principal money laundering offences, sections 327 to 329, apply to the laundering of an offender’s own proceeds of crime just as much as to someone else’s. There’s no separate self-laundering offence in UK law because the ordinary offence was drafted from the start to cover both scenarios. That’s a genuinely useful contrast for compliance teams working across jurisdictions: assuming every country treats self-laundering the same way UK law does is a mistake that can create real gaps in a cross-border risk assessment. Self-laundering vs third-party laundering Third-party laundering describes the opposite scenario: someone launders proceeds generated by a different person’s crime, without having committed that crime themselves. Historically, this was the default assumption behind most money laundering law, a launderer working on behalf of a criminal client rather than cleaning up after their own conduct. The two aren’t mutually exclusive within a single criminal operation. A drug trafficking network might involve members who both generate proceeds and launder some of their own money, while also using specialist third parties, sometimes professional money launderers, to handle larger or more complex sums. Why the distinction matters for penalties Where a jurisdiction distinguishes between self-laundering and ordinary laundering, the penalties usually differ too, and not always in the direction people expect. Italy’s self-laundering offence actually carries a lower maximum sentence than its third-party laundering offence, reflecting the view that hiding your own crime’s proceeds is, in some sense, a less separately culpable act than a … Read more

Whistleblowing

Whistleblowing is the act of reporting wrongdoing inside an organization, either internally or to the authorities. In financial crime, whistleblowers often expose what a firm’s own controls miss, which is why many countries now protect and even reward them. Key takeaways Whistleblowing is reporting wrongdoing inside an organization. It can be internal, to the firm, or external, to a regulator. In financial crime, insiders often see what controls miss. Laws protect whistleblowers from retaliation such as dismissal. The SEC has awarded over $2.2 billion to whistleblowers since 2011. A newer US AML whistleblower program rewards reports of money laundering. On this page What it isWhy it mattersInternal and externalProtectionsReward programsIn AMLThe challengesHow firms encourage itFAQsRead more $2.2B Awarded to whistleblowers by the SEC since 2011 Source: SEC 2011 Year the SEC whistleblower program began Source: SEC 2020 Year the US created an AML whistleblower program Source: FinCEN What is whistleblowing? Whistleblowing is speaking up about wrongdoing inside an organization. A whistleblower is someone, usually an employee, who reports misconduct they have seen, rather than staying silent. The wrongdoing can be many things: fraud, corruption, money laundering, safety failures, or breaking the law. What makes it whistleblowing is that the person raising it has inside knowledge and chooses to report it. In financial crime, this inside view is valuable. Read more: whistleblowers often surface issues a firm’s AML program did not. Why whistleblowing matters Whistleblowing matters because insiders see things that systems and outsiders cannot. A control can miss a problem; a person sitting next to it often does not. Financial crime is frequently hidden deliberately, and the people who know are usually inside the organization. A whistleblower can reveal in one report what monitoring might never catch, which is why regulators treat them as one of the most effective sources of intelligence they have. For a firm, a whistleblower is also a warning it can still act on. Hearing about a problem internally is far better than reading about it in an enforcement notice. Internal and external whistleblowing Whistleblowing can take two routes, and the difference matters for how it is handled. Both have their place. Internal. Reporting the wrongdoing within the organization, through a manager, compliance, or a hotline. External. Reporting to an outside body, such as a regulator or law enforcement. Many people report internally first, giving the firm a chance to fix the problem. If that fails, or if reporting internally feels unsafe, external channels exist. Good firms make internal reporting easy, precisely so problems surface early. The choice of route often comes down to trust. Where staff believe the firm will act fairly, they tend to report internally, which is the outcome most firms want. Where they do not, they go straight to a regulator, and the firm loses the chance to put things right on its own terms. Whistleblower protections Because speaking up carries real risk, the law protects whistleblowers in many countries. The protections exist to make reporting possible. The central protection is against retaliation: a whistleblower who reports in good faith should not be dismissed, demoted, or punished for it. Laws in many places make such retaliation illegal and give whistleblowers a route to challenge it. Some regimes also allow anonymous reporting, so a person can raise concerns without revealing who they are. These protections are not only fair to the individual; they serve the wider goal. A worker who fears losing their job for speaking up will usually stay silent, so shielding whistleblowers from reprisal is what keeps information flowing to the people who can act on it. Set out whistleblowing in your AML policy Generate a tailored AML policy draft that includes how staff can report concerns safely. Open the AML Policy Generator → Whistleblower reward programs Some regimes go further than protection and pay whistleblowers for information that leads to enforcement. The idea is to make speaking up worthwhile as well as safe. The US Securities and Exchange Commission runs the best-known scheme, and has awarded more than $2.2 billion to whistleblowers since the program began in 2011, paying a share of the penalties their information helps recover. A newer AML whistleblower program, created in 2020, extends similar rewards to people who report money laundering and sanctions breaches. These awards have made whistleblowing a serious force in financial crime enforcement. Whistleblowing in AML In anti-money laundering, whistleblowing plays a specific and growing role. Insiders can reveal exactly the failures that are hardest to detect from outside. A whistleblower might report that a firm is ignoring warning signs, failing to file reports, or turning a blind eye to a major customer. These are the failures behind many of the largest enforcement cases, and they are often known internally long before a regulator finds them. The new AML whistleblower program exists precisely to draw out this knowledge. The value to a firm is that it can still respond. A concern raised internally can be investigated and fixed quietly, long before it becomes an enforcement case. Suppressing such a report, by contrast, tends to turn a manageable problem into a far larger one. Worth knowing. Whistleblowers have been behind some of the most significant financial crime cases of recent years. Time and again, a firm’s failures were known internally long before regulators acted. This is why reward programs have grown: authorities recognize that the fastest route to a hidden problem is often a person on the inside who decides to speak. The challenges Whistleblowing is not easy, for the person or the firm. Several challenges get in the way. Fear of retaliation. Worry about losing a job or being frozen out. Loyalty and doubt. Reluctance to report colleagues, or uncertainty about what was seen. Weak culture. An organization where raising concerns is discouraged. Poor channels. No clear, safe way to report. Each of these can keep a problem hidden, which is why the protections and channels matter so much. How firms encourage whistleblowing A firm that wants problems surfaced early makes whistleblowing … Read more

Monetary penalty notice

Monetary penalty notice A monetary penalty notice, or MPN, is a formal document a UK regulator issues to impose a fine for breaching financial sanctions or anti-money laundering rules. The Office of Financial Sanctions Implementation uses the term for sanctions breaches under the Policing and Crime Act 2017. HMRC issues its own penalty notices for money laundering supervision breaches under a separate regime. Key takeaways A monetary penalty notice is a formal, published fine for a sanctions or AML breach. OFSI’s maximum penalty is the greater of £1 million or 50% of the estimated breach value (Policing and Crime Act 2017, s.146). Since 15 June 2022, OFSI can fine on a strict liability basis, without proving the firm knew it was breaching sanctions. HMRC issues separate penalty notices under the Money Laundering Regulations 2017; its largest ever, against MT Global Limited, was £23.8 million before review. OFSI issued its first monetary penalty in February 2019: a discounted £5,000 fine tied to an Egypt sanctions breach. A financial sanctions breach can also be prosecuted as a criminal offence carrying up to seven years in prison, separate from any civil penalty. On this page What a monetary penalty notice isOFSI’s power to issue themHow OFSI calculates the maximum penaltyHMRC’s parallel penalty regime for AML supervisionNotable monetary penalty casesHow firms respond to a penalty noticeFAQsRead more £1m or 50% OFSI’s maximum sanctions penalty: the greater of £1 million or half the breach value Source: Policing and Crime Act 2017, s.146 £23.8m HMRC’s largest-ever AML monetary penalty, issued to MT Global Limited, 2021 Source: HMRC 7 years Maximum prison term for a criminal breach of UK financial sanctions Source: OFSI What a monetary penalty notice is A monetary penalty notice formally records a regulator’s decision that a firm or individual breached a legal obligation, and sets out the fine imposed as a result. It’s a civil enforcement tool, distinct from criminal prosecution, though the two aren’t mutually exclusive for the same underlying conduct. OFSI’s power to issue them The Office of Financial Sanctions Implementation gained the power to impose civil monetary penalties for financial sanctions breaches under section 146 of the Policing and Crime Act 2017. Since 15 June 2022, OFSI can impose these penalties on a strict liability basis, meaning it no longer has to prove the firm knew, or had reasonable cause to suspect, it was in breach. How OFSI calculates the maximum penalty Where OFSI can estimate the value of a breach, the maximum penalty is the greater of £1 million or 50% of that estimated value. Where the value can’t be estimated, the cap is a flat £1 million. OFSI’s first-ever monetary penalty, issued in February 2019, was a £10,000 fine against R. Raphael & Sons plc, discounted to £5,000 for voluntary disclosure and cooperation, over a £200 payment connected to a sanctioned associate of former Egyptian president Hosni Mubarak. Worth knowing. Voluntary disclosure genuinely changes the outcome. OFSI’s first-ever monetary penalty was cut in half, from £10,000 to £5,000, specifically because the firm disclosed the breach itself and cooperated with the investigation. HMRC’s parallel penalty regime for AML supervision HMRC issues its own penalty notices under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, separate from OFSI’s sanctions-specific powers. HMRC supervises sectors including estate agents, accountants, trust and company service providers, and money service businesses, and has a statutory duty to publish details of the penalties it issues. Notable monetary penalty cases HMRC’s largest AML penalty to date was £23.8 million, issued to money transfer company MT Global Limited in 2021 for failures spanning risk assessment, controls, and due diligence, later reduced to £1.9 million on review. On the sanctions side, OFSI imposed a £465,000 penalty on Herbert Smith Freehills’ former Moscow office in March 2025, over six payments totalling roughly £3.93 million made in breach of Russia sanctions. How firms respond to a penalty notice A firm that receives a penalty notice can make representations to the regulator and, if that fails, appeal: to a minister in OFSI’s case, or through HMRC’s review and tribunal process. Beyond the appeal itself, most firms also move quickly to fix the underlying control failure, since a breach of financial sanctions can additionally be prosecuted as a criminal offence carrying up to seven years in prison, separate from any civil penalty already paid. Spot red flags before they become a penalty Work through the warning signs that precede most AML and sanctions enforcement action. Open the Red Flags Checklist → Frequently asked questions What is a monetary penalty notice? A monetary penalty notice is a formal document a UK regulator issues to record a breach of financial sanctions or AML rules and set out the fine imposed. It’s a civil enforcement tool, separate from criminal prosecution. What is the maximum monetary penalty OFSI can impose? Where OFSI can estimate the value of a breach, the maximum is the greater of £1 million or 50% of that value. Where the value can’t be estimated, the cap is a flat £1 million. Does OFSI have to prove intent to issue a penalty? Not since 15 June 2022. OFSI can now impose civil monetary penalties on a strict liability basis, meaning it no longer has to prove the firm knew, or had reasonable cause to suspect, it was breaching sanctions. What is the largest AML monetary penalty HMRC has issued? HMRC’s largest AML penalty to date was £23.8 million, issued to money transfer company MT Global Limited in 2021, later reduced to £1.9 million following review. Is a breach of financial sanctions a criminal offence too? Yes. A breach of financial sanctions can be prosecuted as a criminal offence carrying up to seven years in prison, in addition to, or instead of, any civil monetary penalty. Read more: our ultimate guides, whitepapers and templates Related guides and resources to help you act on what you just read. Consent OrderThe US settlement equivalent.Read guide →Deferred Prosecution AgreementThe criminal … Read more

Obliged Entity

An obliged entity is a business that is legally required to follow anti-money laundering rules. The term is used mainly in the European Union, and it covers banks and other financial firms as well as many non-financial businesses such as lawyers and estate agents. Key takeaways An obliged entity is a business legally required to follow AML rules. The term is used mainly in the European Union. It covers financial institutions and many non-financial businesses. Obliged entities must run customer checks, keep records, and report suspicion. The categories are set by the EU’s anti-money laundering directives. It overlaps closely with the FATF idea of a DNFBP. On this page What it isThe term explainedWho countsTheir obligationsThe EU frameworkObliged entity vs DNFBPWhy it mattersStaying compliantFAQsRead more 6 EU anti-money laundering directives issued to date Source: European Union $800B to $2T Laundered worldwide each year that these rules target Source: UNODC 1989 Year the FATF set the global standard these rules follow Source: FATF What is an obliged entity? An obliged entity is any business that the law requires to follow anti-money laundering rules. The name captures the idea plainly: these are the firms that are obliged to check for and report dirty money. The term is most common in the European Union, where AML law lists the types of business that must comply. If a firm is an obliged entity, it cannot opt out of the rules; the duties apply by law. The category is wide, covering far more than banks. Read more: those duties are built around customer due diligence. The term explained The phrase obliged entity is a legal one, and each word matters. Together they mark out who the rules bind. Obliged. Bound by law to comply, not doing so by choice. Entity. A business or professional practice, rather than a private individual. Other regimes use different labels for the same idea, such as regulated entity or reporting entity. The meaning is broadly the same: a business the law has placed inside the AML system. Who counts as an obliged entity? The list of obliged entities is set by law and is deliberately broad. It reaches well beyond the financial sector. Banks and financial institutions. The core of the list. Payment and e-money firms. Including many money service businesses. Lawyers and accountants. When they handle certain transactions. Estate agents. Because property is a laundering channel. Trust and company service providers. Firms that set up and run companies. Casinos and high-value dealers. Where large sums change hands. The common thread is that each sits at a point where dirty money might enter the system. That is what earns a place on the list. Screen a customer against watchlists Run one search across sanctions, PEP, and adverse media data to meet your customer check duties. Try Combined AML Screening → The obligations of an obliged entity Every obliged entity carries the same core duties, scaled to its size and risk. The obligations are consistent across the EU. Customer due diligence. Verify who customers are, and their beneficial owners. Risk assessment. Judge the money laundering risk of customers and services. Record-keeping. Keep evidence of checks and transactions, usually for years. Reporting. File a report on suspicious activity to the authorities. Internal controls. Run an AML program with training and oversight. Do this: get an indicative read on your exposure with the AML Risk Assessment. The EU framework The concept of an obliged entity comes from the EU’s anti-money laundering directives. These directives set the rules that member states then write into national law. The EU has issued a series of these directives over the years, refining and widening the duties each time. The most recent numbered one is the Sixth Anti-Money Laundering Directive, and the EU has since agreed a further package that creates a central AML authority. Each round has tended to add obliged entities and tighten what they must do. Worth knowing. The list of obliged entities keeps growing. Each new EU directive has tended to bring in more sectors, from estate agents to crypto firms to, more recently, traders in luxury goods. The direction of travel is clear: as criminals find new channels, the law extends the duty to the businesses that sit on them. Obliged entity vs DNFBP Obliged entity and DNFBP are closely related, and it helps to see how they fit. One is broader than the other. A DNFBP is the FATF’s term for the non-financial businesses covered by AML rules, such as lawyers and estate agents. An obliged entity is the EU’s broader term, covering both those non-financial businesses and the financial institutions. So all DNFBPs are obliged entities, but obliged entities also include banks. DNFBP Obliged entity Used by FATF, globally The EU Covers Non-financial businesses only Financial and non-financial Includes banks No Yes In short, obliged entity is the wider umbrella, and DNFBP is the non-financial slice within it. Why the term matters The term matters because it defines who the law applies to. If a business is an obliged entity, the full weight of AML rules falls on it. For a firm, knowing whether it is an obliged entity is the first compliance question. It decides whether the firm must run checks, keep records, and report, or whether it sits outside the rules. Getting that wrong, and assuming the rules do not apply, is a serious mistake. The line can be finer than it looks. A business that only occasionally handles client money, or that sits on the edge of a listed sector, may still be caught, which is why firms in doubt take advice rather than guess. Staying compliant as an obliged entity An obliged entity stays compliant by building the AML basics into how it works. The steps are the same across sectors, sized to the firm. Confirm your status. Be clear that the rules apply and which ones. Check customers. Verify identity and beneficial ownership. Assess and monitor. Rate risk and watch for unusual activity. Report and … Read more

Independent AML Audit

An independent AML audit is an arm’s-length review that tests whether a firm’s anti-money laundering program actually works. It is one of the required pillars of a program, and it gives leadership and regulators an honest picture of what is working and what is not. Key takeaways An independent AML audit tests whether an AML program actually works. It is a required pillar, also called independent testing. It must be genuinely independent, done by internal audit or an outside firm. It covers the whole program: controls, due diligence, monitoring, and reporting. Most firms run one every 12 to 18 months, based on risk. Its value is honest findings that leadership then acts on. On this page What it isWhy it is requiredWho performs itWhat it coversHow oftenThe processAudit vs examActing on findingsFAQsRead more 12 to 18 months Common cycle for an independent AML audit Source: FFIEC guidance $3B Paid by TD Bank in 2024 after control and testing gaps Source: US Department of Justice $800B to $2T Laundered worldwide each year that programs aim to stop Source: UNODC What is an independent AML audit? An independent AML audit is a review that checks whether a firm’s anti-money laundering program is doing its job. It is done at arm’s length, by someone not responsible for running the program, so the findings are honest. The word independent is the key. A team cannot credibly grade its own work, so the audit brings in a separate set of eyes to test the program against the rules and against reality. It is one of the required parts of an AML program. Read more: it is the testing pillar within the five pillars of AML. Why an independent audit is required The audit is required because a program can look sound on paper and still fail in practice. Independent testing is how a firm finds out which it is. Without it, weaknesses go unseen until a regulator, or a criminal, finds them first. The audit catches gaps early, while there is still time to fix them, and it gives leadership an honest view rather than a reassuring one. Regulators treat weak or missing testing as a serious gap. The TD Bank case in 2024, with about $3 billion in penalties, involved controls that testing should have surfaced (US Department of Justice, 2024). Set out testing in your AML policy Generate a tailored AML policy draft that records your controls, roles, and independent testing approach. Open the AML Policy Generator → Who performs an independent AML audit? The audit must be independent, but it does not have to be external. What matters is that the reviewer is separate from the program being tested. Internal audit. A firm’s own audit team, provided it is independent of compliance. An outside firm. An external auditor or consultancy brought in for the review. A qualified third party. A specialist with the knowledge to test an AML program. A small firm without an internal audit function usually hires an outside party. The reviewer should have real AML knowledge, not just general audit skills. That knowledge matters more than it sounds. An auditor who does not understand laundering can tick boxes without ever testing whether the program would catch a real scheme, which is the one thing the audit exists to do. What an independent AML audit covers A thorough audit looks at the whole program, not just one part. It tests each pillar and how they work together. Internal controls. Whether policies and procedures are sound and followed. Customer due diligence. Whether the firm really knows its customers. Transaction monitoring. Whether monitoring catches what it should. Reporting. Whether suspicion is escalated and reported properly. Training and governance. Whether staff are trained and oversight is real. The aim is to test whether the program works in practice, by sampling real cases, not just reading the manual. How often should it happen? There is no single legal interval, but a common cycle is every 12 to 18 months. The right frequency depends on the firm’s size and risk. US regulatory guidance points most banks toward independent testing every 12 to 18 months, and higher-risk firms may test more often. A firm should also run an audit after a major change, such as a new product or a serious incident. The interval is a floor, not a ceiling. A firm that has just overhauled its monitoring, entered a new market, or had a near-miss should not wait for the calendar. The point is to test when the risk warrants it, not merely when the cycle comes due. The audit process An independent audit follows a clear sequence, from planning to follow-up. The steps are consistent. Set the scope. Agree what the audit will cover, based on risk. Test the program. Sample real cases and check controls against the rules. Identify findings. Record gaps, weaknesses, and what is working. Report. Give leadership and the board a clear, honest write-up. Follow up. Track that the findings are actually fixed. Worth knowing. An audit is only as useful as the honesty of its findings and the response to them. A report that softens problems to keep the peace, or that leadership files and forgets, is worse than no audit at all, because it creates a false sense of safety. The value is in the fixing, not the finding. Independent audit vs regulatory exam An independent audit and a regulatory exam both test a program, but they are not the same thing. The difference is who runs it. Independent audit Regulatory exam Run by The firm, at arm’s length The regulator Purpose Find and fix gaps early Check compliance and enforce Timing On the firm’s cycle On the regulator’s schedule A firm that audits itself well is far better prepared when the regulator arrives, because the gaps have already been found and fixed. Acting on the findings The audit only adds value if the firm acts on it. Findings that sit in a report change nothing. Prioritize. … Read more

Deferred Prosecution Agreement

A deferred prosecution agreement, or DPA, is a deal in which a prosecutor agrees to hold criminal charges in abeyance if a company meets strict conditions. Those usually include a large penalty, remediation, and a monitor, over a set period. Key takeaways A deferred prosecution agreement holds criminal charges in abeyance. The company avoids prosecution by meeting strict conditions. Conditions usually include a penalty, remediation, and often a monitor. It differs from a guilty plea, where the company is convicted. It is used in major AML, sanctions, and corruption cases. HSBC resolved its 2012 AML case through a DPA. On this page What it isHow it worksWhat it containsVs a guilty pleaVs a consent orderIn AMLThe criticismHow firms respondFAQsRead more $1.9B HSBC penalty under a deferred prosecution agreement, 2012 Source: US Department of Justice 5 years Typical length of a corporate DPA, as in the HSBC case Source: US Department of Justice $8.9B BNP Paribas penalty, resolved by a guilty plea instead, 2014 Source: US Department of Justice What is a deferred prosecution agreement? A deferred prosecution agreement is a way of resolving a criminal case without a conviction. A prosecutor charges a company but agrees to hold, or defer, the prosecution, on condition the company does what the agreement requires. If the company meets the conditions over the set period, the charges are dropped. If it does not, the prosecution can go ahead. In effect, the company is on probation, with prosecution hanging over it as the consequence of failure. It is a common outcome in large corporate cases. Read more: the failures behind them often trace to a weak AML compliance program. How a DPA works A DPA follows a clear structure, built around conditions and time. The company is charged but given a path to avoid conviction. Charges are filed. The prosecutor brings criminal charges against the company. An agreement is reached. Prosecution is deferred in exchange for conditions. The company complies. It pays penalties, remediates, and accepts oversight. Charges are dropped. If the company meets the terms, the case ends without conviction. The set period is often several years, giving the prosecutor time to see whether the company truly reforms. What a DPA contains A DPA sets out both the punishment and the conditions for avoiding conviction. Several elements are standard. A financial penalty. Often a very large fine or forfeiture. Remediation. A requirement to fix the failures that led to the case. A monitor. In many cases, an independent monitor to oversee progress. An admission. Usually an acknowledgment of the underlying facts. The monitor is often the sharpest part. An outsider inside the company, checking its progress, is a powerful and uncomfortable form of oversight. DPA vs a guilty plea A DPA and a guilty plea are two ways a corporate criminal case can end, and the difference is conviction. One avoids it; the other does not. Under a DPA, charges are deferred and, if conditions are met, dropped, so there is no conviction. Under a guilty plea, the company admits guilt and is convicted. A conviction can carry heavier consequences, such as losing licenses or being barred from certain business, which is part of why prosecutors sometimes prefer a DPA for a company whose collapse would harm others. Deferred prosecution agreement Guilty plea Conviction No, if conditions are met Yes Outcome Charges dropped after the term A criminal conviction Example HSBC (2012) BNP Paribas (2014) Both bring large penalties and remediation; the key difference is whether a conviction is recorded. DPA vs a consent order A DPA also differs from a consent order, though both resolve matters by agreement. The line is criminal versus regulatory. A DPA is a criminal tool, agreed with a prosecutor to defer criminal charges. A consent order is usually a civil or regulatory tool, agreed with a regulator to settle an enforcement action. A major case can feature both, a DPA with prosecutors and consent orders with regulators, each resolving a different kind of exposure. Get an indicative AML risk rating See where your money laundering risk is concentrated so you can close gaps before they escalate. Try the AML Risk Assessment → DPAs in AML Deferred prosecution agreements have played a central role in the largest AML cases. They are how several major banks resolved serious failings. The classic example is HSBC, which in 2012 entered a five-year DPA and paid about $1.9 billion after admitting weak AML controls that let drug-cartel money flow through the bank. The case, with its large penalty and independent monitor, became a template for how AML failures at big institutions are resolved. Not every case ends this way; BNP Paribas instead pleaded guilty in 2014 over sanctions breaches, showing prosecutors will sometimes require a conviction. The criticism of DPAs DPAs are not without controversy, and the criticism is worth understanding. It centers on whether they let big companies off lightly. Critics argue that DPAs allow large firms to avoid the full consequences of serious wrongdoing, paying a fine instead of facing conviction, a concern sometimes summed up as too big to jail. Supporters counter that a conviction could destroy a company and harm innocent employees and customers, and that a DPA with a heavy penalty and forced reform can be more effective. The debate reflects a real tension between accountability and collateral damage. Worth knowing. The value of a DPA to a prosecutor is the hold it keeps. Because the threat of prosecution remains live throughout the term, the company has every incentive to reform, cooperate, and meet its conditions. A guilty plea ends the matter; a DPA keeps a sword hanging over the company, which can drive deeper change than a one-time conviction might. How firms respond to a DPA A company under a DPA has one overriding job: meet every condition and reform for real. A few priorities shape the response. Deliver on the terms. Pay penalties and complete required remediation. Work with the monitor. Cooperate fully with any … Read more