AML & Financial Crime – Page 3 – grcsight.com

Money Laundering

Money laundering is the process of making money from crime look like it came from a legal source. Criminals move dirty funds through banks, businesses, and assets in three stages, placement, layering, and integration, so the money can be spent without drawing attention. Key takeaways Money laundering disguises the criminal origin of money so it can be used freely. It runs in three stages: placement, layering, and integration. The UNODC estimates $800 billion to $2 trillion is laundered every year, 2 to 5 percent of global GDP. Common methods include splitting cash deposits, shell companies, trade schemes, and real estate. Regulated firms must verify customers, monitor transactions, and file suspicious activity reports. Under 1 percent of laundered funds are ever seized, so prevention beats recovery. On this page What it isThe three stagesMethods and examplesLaws and penaltiesHow firms detect itVs fraud and TFFAQsRead more $800B to $2T Laundered globally each year (2 to 5 percent of global GDP) Source: UNODC Under 1% Of illicit flows are seized or frozen Source: UNODC, 2011 ~$300B Laundered in the United States each year Source: US Department of the Treasury What is money laundering? Money laundering is how criminals turn illegal profits into money that looks clean. The goal is simple: spend or invest the proceeds of crime without a bank, a regulator, or the police asking where it came from. The crime that produces the dirty money is the predicate offense. Drug trafficking, fraud, corruption, and human trafficking are common ones. Laundering is a separate offense stacked on top of that first crime. Most of it never gets caught. The UNODC estimates that under 1 percent of laundered money is seized (UNODC, 2011). Read more: the three stages of money laundering section below shows how it works step by step. The three stages of money laundering Money laundering usually moves through three stages. Each one adds distance between the money and the crime that produced it. Placement. Dirty cash enters the financial system, often through deposits, a cash-heavy business, or buying assets. This is the riskiest step, because raw cash is easiest to trace. Layering. The money moves through transfers, conversions, and accounts to hide the trail. Cross-border wires, shell companies, and crypto swaps are common here. Integration. The funds come back as apparently legal income, such as business revenue, a property sale, or investment returns. By now the money looks legitimate. Stage Example Warning sign Placement Daily cash deposits just under $10,000 Frequent small cash deposits Layering Wires through three countries and two shell firms Rapid, circular transfers with no purpose Integration Buying property through an anonymous company Wealth that does not match known income See where your money laundering risk sits Answer a few questions about your customers, products, and markets to get an indicative risk rating in minutes. Try the AML Risk Assessment → Common money laundering methods and examples Money launderers rely on a handful of proven methods. Most involve breaking up cash, hiding who owns an asset, or disguising value as trade or property. Structuring (smurfing). Splitting a large sum into many small cash deposits below reporting limits. Shell companies. Firms with no real activity used to move and hold funds. Trade-based laundering. Over-invoicing or under-invoicing goods to shift value across borders. Real estate. Buying property, often through anonymous companies, to absorb large sums. Cryptocurrency. Mixers and fast swaps to break the on-chain trail. Money mules. People who move funds through their own accounts, sometimes unknowingly. Use the tool: check a person or company against sanctions, PEP, and adverse media data with Combined AML Screening. Worth knowing. Laundering does not need a bank. Casinos, law firms, art dealers, and used-car lots have all been used, because each can take in cash and hand back a clean-looking receipt. Is money laundering illegal? Laws and penalties Yes. Money laundering is a criminal offense in almost every country, and penalties include prison and heavy fines. United States. The Bank Secrecy Act of 1970 and 18 U.S.C. 1956 and 1957, with FinCEN handling reporting. A single count can carry up to 20 years. United Kingdom. The Proceeds of Crime Act 2002, with a maximum of 14 years. European Union. The AML directives and the 2024 AML package, which created the AMLA supervisor. Global standard. The FATF, founded in 1989, sets the 40 Recommendations most countries follow (FATF). Firms get penalized too, not just individuals. In 2024, TD Bank agreed to pay about $3 billion to US authorities over Bank Secrecy Act failures, including a record $1.3 billion FinCEN penalty (US Department of Justice, 2024). Know the warning signs before they cost you Run through our money laundering red flags checklist to spot suspicious behavior across onboarding and transactions. Open the Red Flags Checklist → How firms detect and report money laundering Regulated firms catch money laundering with three controls. Each one covers a different gap. Know your customer. Verify identity and risk at onboarding, with enhanced due diligence for higher-risk cases. Screen names. Check against sanctions, PEP, and adverse media data. Monitor and report. Watch for patterns like structuring, then file a suspicious activity report through the MLRO. Do this: get an indicative read on your exposure with the AML Risk Assessment before your next audit. Money laundering vs fraud and terrorist financing Money laundering, fraud, and terrorist financing overlap but are separate. Knowing the difference helps you file the right report. Fraud is a way to steal money. Laundering is what happens to that money afterward, which makes fraud a common predicate offense. Terrorist financing can use clean money for illegal ends, the reverse of laundering. Screen a name against global watchlists Run one search across sanctions, PEP, and adverse media data to check a customer or counterparty before you deal with them. Try Combined AML Screening → Frequently asked questions What is money laundering in simple terms? Money laundering is making money from crime look like it came from a legal source. Criminals pass dirty funds through banks, businesses, … Read more

Senior management responsibility

Senior management responsibility Senior management responsibility means that named individuals, not just the firm as a whole, can be held personally accountable when an AML programme fails. In the UK, this runs through the Senior Managers and Certification Regime, which gives every senior manager a statutory duty to take reasonable steps to prevent or stop a breach in their area. It’s a deliberate move away from AML failings being treated as a purely corporate problem. Key takeaways Senior management responsibility means named individuals, not just the firm, can be held accountable for AML failings. The UK’s Senior Managers and Certification Regime extended to all FCA solo-regulated firms on 9 December 2019. Every Senior Manager has a statutory duty of responsibility, and the FCA carries the burden of proving they failed to take reasonable steps. SMF16 (Compliance Oversight) and SMF17 (MLRO) are required functions every core firm must appoint someone to. Overall responsibility for a firm’s AML framework is a Prescribed Responsibility, typically allocated to SMF17. SM&CR replaced the Approved Persons Regime specifically to stop accountability getting lost in collective decision-making. On this page What senior management responsibility actually meansThe Senior Managers and Certification RegimeThe duty of responsibility, and what “reasonable steps” meansSMF16, SMF17, and the AML-specific functionsPrescribed Responsibilities: why AML gets a named ownerStatements of Responsibilities and Responsibilities MapsWhy the regime exists: what came before itWhat this means day to day for an AML programmeFAQsRead more 9 Dec 2019 Date SM&CR extended to all FCA solo-regulated firms Source: Financial Conduct Authority What senior management responsibility actually means Senior management responsibility is the principle that a firm’s leaders can be held individually accountable, not just collectively, when the firm’s controls fail. In an AML context, that means a named senior manager, not an anonymous “the firm,” can face regulatory action if the anti-money laundering programme they’re responsible for breaks down. This matters because it changes incentives. A rule that only ever punishes the corporate entity gives an individual little personal reason to push hard for better controls. A rule that can reach the individual changes that calculation directly. The Senior Managers and Certification Regime In the UK, this runs through the Senior Managers and Certification Regime, SM&CR, which the FCA extended to all FCA solo-regulated firms on 9 December 2019, having already applied it to banks and insurers earlier. A Senior Manager under the regime is anyone performing a senior management function, defined as managing an aspect of the firm’s regulated business that could carry serious consequences if it goes wrong. Before taking up an SMF role, an individual now needs FCA approval, supported by a Statement of Responsibilities setting out exactly what they’re accountable for. The duty of responsibility, and what “reasonable steps” means Every Senior Manager carries a statutory duty of responsibility under the Financial Services and Markets Act. If the firm breaches one of the FCA’s rules in that manager’s area, the FCA can hold the individual accountable if they failed to take reasonable steps to prevent or stop it. Critically, the burden of proof sits with the FCA, not the individual: the regulator has to show the senior manager didn’t take reasonable steps, rather than the manager having to prove they did. What counts as reasonable varies by role and circumstance, but the FCA has published guidance on the factors it weighs, including how clearly responsibilities were documented and how actively the individual engaged with known risks. Worth knowing. The burden of proof under the duty of responsibility sits with the FCA, not the senior manager. The regulator has to show a senior manager failed to take reasonable steps; the individual doesn’t have to prove their innocence from the outset. SMF16, SMF17, and the AML-specific functions Two senior management functions matter most directly for AML: SMF16, Compliance Oversight, and SMF17, Money Laundering Reporting Officer. Both are “required functions,” meaning every core firm has to have someone appointed to each one; they’re not optional based on the firm’s structure the way some other SMFs are. It’s entirely possible, and common in smaller firms, for one person to hold both SMF16 and SMF17, alongside another executive role such as SMF3. What matters to the regulator isn’t how many roles one person holds, but whether the Statement of Responsibilities makes clear who owns what. Prescribed Responsibilities: why AML gets a named owner The FCA also requires certain “Prescribed Responsibilities” to sit with a specific named senior manager, rather than being left to a firm’s own allocation. Overall responsibility for the firm’s AML framework is one of these, and it’s typically allocated to whoever holds SMF17. This is deliberate. Prescribed Responsibilities exist precisely because the FCA wants certain critical areas, AML among them, to always have one accountable name attached, rather than responsibility drifting across a committee or getting lost between roles. Statements of Responsibilities and Responsibilities Maps Firms above a certain size also need to maintain a Management Responsibilities Map, a document setting out the governance structure, reporting lines, and how responsibilities are actually divided across senior managers. This exists so that, if something goes wrong, it’s possible to trace exactly whose area it fell within, rather than reconstructing accountability after the fact. The FCA has been explicit that a Statement of Responsibilities needs to be self-contained and specific. Vague or overlapping descriptions of who’s accountable for what have been flagged as a recurring weakness in its own review of how firms implement the regime. Why the regime exists: what came before it SM&CR replaced the FCA’s earlier Approved Persons Regime, which regulators concluded hadn’t done enough to hold individuals accountable after the 2008 financial crisis and a string of conduct failings across UK financial services. The core criticism was that senior individuals could point to collective decision-making and diffuse responsibility, making it hard for the regulator to pin accountability on anyone specific. The duty of responsibility was designed to close that gap directly, tying accountability to a named person’s documented area of responsibility rather than to the firm’s … Read more

Four Pillars of AML

The four pillars of AML are the original core of a US anti-money laundering program: internal controls, a designated compliance officer, ongoing training, and independent testing. Since 2018, a fifth pillar, customer due diligence, has been added, so modern programs are often described as having five. Key takeaways The four pillars of AML are the original core of a US AML program. They are internal controls, a compliance officer, training, and independent testing. They trace back to the US Bank Secrecy Act, enacted in 1970. In 2018, a fifth pillar, customer due diligence, was added. Modern US programs are often described as having five pillars. The pillars are the backbone of an AML compliance program. On this page What they areThe four pillarsEach in practiceTheir originFour vs fiveWhy they matterPart of a programWeak pillarsFAQsRead more 4 Original pillars of a US AML program Source: US Bank Secrecy Act 1970 Year the Bank Secrecy Act was enacted Source: US Bank Secrecy Act 2018 Year a fifth pillar, customer due diligence, was added Source: FinCEN CDD Rule What are the four pillars of AML? The four pillars of AML are the original foundation of a US anti-money laundering program. For decades, these four elements defined what a compliant program had to contain. They come from the Bank Secrecy Act, the US law that first required banks to help detect money laundering. The four pillars became the standard way to describe a program’s core parts. They remain the backbone of AML today, even after a fifth was added. Read more: the pillars are the required parts of an AML compliance program. The four pillars Each pillar covers a different part of the job. Together they form a program that can spot and prevent laundering. Internal controls. The rules, policies, and procedures a firm builds to detect and prevent laundering. A designated compliance officer. A named person, the BSA officer, responsible for running the program. Ongoing training. Regular education so staff can recognize and act on laundering risk. Independent testing. A separate, periodic review that checks the program actually works. These four have anchored US AML programs since long before the fifth pillar arrived. Each pillar in practice The four pillars are simple to name but demanding to run well. Here is what each looks like day to day. Internal controls. More than a policy on a shelf, they are the working rules staff follow to onboard customers, monitor activity, and report suspicion. Compliance officer. A real owner with the time, authority, and support to run the program, not just a name on a form. See the MLRO role. Training. Education tailored to each role, so a teller and an executive each learn what they need. Independent testing. A genuine, arm’s-length review, often by internal audit or an outside party. Build your program on the pillars Generate a tailored AML policy draft that sets out your controls, roles, training, and testing. Open the AML Policy Generator → Where the four pillars come from The four pillars are not a modern invention. They grew out of the US Bank Secrecy Act, passed in 1970, which first required banks to help the government detect money laundering. Over the years, regulators and examiners settled on four core elements that a compliant program had to contain, and these became known as the four pillars. The framing gave banks a clear, memorable way to describe what a program needed. The language stuck because it works. Even now that a fifth pillar exists, people still reach for the four-pillar framing as the foundation, because it captures the original core of what an AML program is for. Four pillars vs five pillars The four pillars became five in 2018, which is the source of a common question. The difference is a single addition. In May 2018, FinCEN’s Customer Due Diligence Rule added customer due diligence, including beneficial ownership, as a formal fifth pillar. The original four did not change; a fifth was placed alongside them. Pillar In the four In the five Internal controls Yes Yes Compliance officer Yes Yes Training Yes Yes Independent testing Yes Yes Customer due diligence No Yes So a modern US program is usually described as having five pillars. Read more: the current set is covered in the five pillars of AML. Screen customers with your controls Run one search across sanctions, PEP, and adverse media data as part of the checks your controls require. Try Combined AML Screening → Why the four pillars matter The four pillars matter because they still form the core of every US AML program. The fifth pillar added to them; it did not replace them. Each of the four does a job the others cannot. Controls set the rules, the officer runs them, training carries them to staff, and testing proves they work. Remove any one and the program has a hole, which is why regulators weigh them as a set. It is worth stressing that the fifth pillar did not demote the four. Customer due diligence was added because knowing the customer proved essential to managing risk, but the original four remain the frame that holds a program together, and a firm that neglects them cannot be saved by strong due diligence alone. Worth knowing. The four pillars are sometimes called the four pillars of BSA compliance, since they come from the Bank Secrecy Act. Whatever the label, the point is the same. They are the minimum a US program needs, and the fifth pillar, customer due diligence, sits on top of this original foundation rather than replacing it. How the four pillars form a program The four pillars are not a one-time setup. They run together as a continuous program that a firm maintains over time. Controls provide the framework, the compliance officer keeps it running, training keeps staff sharp, and independent testing catches what the others miss. A weakness in one pillar spreads to the rest, so a program is only as strong as its weakest … Read more

Dual-Use Goods

Dual-use goods are items that have both civilian and military uses, such as certain chemicals, electronics, and machinery. Because they can help build weapons, they are controlled through export rules, and they are a central concern in proliferation financing and sanctions. Key takeaways Dual-use goods have both civilian and military uses. Examples include certain chemicals, electronics, software, and machinery. They are controlled to stop them helping weapons programs. Export controls such as the Wassenaar Arrangement govern their trade. They are central to proliferation financing and sanctions. A dual-use transaction can look like ordinary trade, which raises the risk. On this page What they areExamplesWhy they are controlledExport controlsDual-use and proliferationThe role of sanctionsRed flagsHow firms manage itFAQsRead more 42 Participating states in the Wassenaar Arrangement on dual-use controls Source: Wassenaar Arrangement 1996 Year the Wassenaar Arrangement was established Source: Wassenaar Arrangement 2020 Year the FATF required firms to assess proliferation financing risk Source: FATF What are dual-use goods? Dual-use goods are items that can be used for both peaceful, civilian purposes and military ones. The same product might sit harmlessly in a factory or become part of a weapons program, depending on who buys it and why. This double nature is what makes them tricky. A chemical used in fertilizer can also make explosives; a component in a civilian aircraft can serve a missile. The item itself is neutral; the risk lies in its end use. They are a key concern where trade meets security. Read more: they sit at the heart of proliferation financing. Examples of dual-use goods Dual-use goods span many industries, from chemistry to computing. A few categories show the range. Chemicals. Substances used in industry that can also make weapons. Electronics. Components that serve both consumer and military systems. Software and technology. Including encryption and advanced computing. Machinery. Precision tools that can produce weapons parts. Materials. Special metals and materials with military applications. What unites them is that each has a genuine civilian market and a potential military use, which is exactly why they are watched. Why dual-use goods are controlled Dual-use goods are controlled to keep dangerous capabilities out of the wrong hands, without shutting down legitimate trade. It is a balancing act. If these items flowed freely, a state or group seeking weapons could simply buy the pieces on the open market. Controls exist to catch that, requiring licenses and checks for sensitive exports, while still letting honest businesses trade. The aim is to allow the civilian use and block the military one, which is difficult precisely because the goods are the same. Export controls on dual-use goods Dual-use goods are governed by export control regimes, both international and national. These set out what is controlled and how. The main international framework is the Wassenaar Arrangement, established in 1996, whose 42 participating states coordinate controls on dual-use goods and technologies. Its control lists are written into national laws, such as the US export rules and the EU dual-use regulation. Exporters of listed items must obtain licenses and follow checks, so that sensitive goods are not diverted to weapons programs. Screen a customer or counterparty Run one search across sanctions, PEP, and adverse media data to check a party in a sensitive trade. Try Combined AML Screening → Dual-use goods and proliferation financing Dual-use goods are tightly linked to proliferation financing, the funding of weapons of mass destruction. The two go hand in hand. Proliferation financing often works by paying for dual-use goods that help a weapons program, routed to disguise the true buyer and purpose. A payment for machinery or chemicals can look like normal trade while actually supporting proliferation. This is why financial institutions, not just exporters, need to be alert: the money behind a dual-use shipment can be where the risk shows up first. The role of sanctions Sanctions reinforce dual-use controls by targeting the parties and countries of greatest concern. The two systems work together. Where a country or entity is subject to sanctions over its weapons programs, dealing in dual-use goods with them is doubly restricted. Firms must screen against sanctions lists as well as check export controls, since a dual-use transaction with a sanctioned party is a serious breach. Together, export controls and sanctions form the main defense against dangerous goods reaching weapons programs. The overlap can be a trap for the unwary. A firm focused only on export paperwork might miss that the buyer is a sanctioned party, while one focused only on sanctions might miss that the goods are controlled. Both checks are needed, because a dual-use deal can fail on either front. Red flags in dual-use trade Certain signs suggest a dual-use transaction may not be what it seems. Firms and exporters watch for them. Mismatched end use. Goods that do not fit the stated buyer or purpose. Opaque parties. Buyers hidden behind front companies or intermediaries. High-risk destinations. Routes linked to proliferation concerns. Unusual payment. Funding that does not match a normal commercial deal. The common thread is a transaction where the real buyer or purpose is being obscured, which is what proliferation networks rely on. Worth knowing. The hardest thing about dual-use goods is that the item alone tells you very little. A shipment of valves or software may be entirely legitimate or part of a weapons program, and the paperwork often looks the same either way. This is why context matters so much: who is really buying, where the goods are going, and whether the money makes commercial sense are what separate honest trade from proliferation. How firms manage dual-use risk Managing dual-use risk means combining export awareness with financial vigilance. A few priorities matter most. Know the controls. Understand which goods are export-controlled. Screen the parties. Check buyers and counterparties against sanctions lists. Question the end use. Confirm who is buying and why. Watch the money. Look at whether the payment fits a genuine trade. Weigh a destination’s country risk Look up a country against FATF, sanctions, and corruption data to … Read more

Money Laundering Typologies

Money laundering typologies are the recurring methods and patterns criminals use to clean dirty money. They range from structuring and trade-based laundering to shell companies and money mules, and knowing them is how firms design the checks that catch laundering. Key takeaways Money laundering typologies are the recurring methods used to clean money. Common ones include structuring, trade-based laundering, shell companies, and mules. Knowing typologies helps firms build monitoring rules and train staff. Typologies are the methods, stages are the phases, and red flags are the signs. New typologies appear as criminals adapt, especially with technology. The FATF and similar bodies publish typology reports to share what they see. On this page What they areWhy they matterThe main typologiesStructuring and smurfingTrade-based launderingDigital typologiesHow firms use themTypologies vs stages vs flagsFAQsRead more $800B to $2T Laundered worldwide each year through these methods Source: UNODC 1989 Year the FATF was founded, which publishes typology reports Source: FATF $3B Paid by TD Bank in 2024 after monitoring failures Source: US Department of Justice What are money laundering typologies? Money laundering typologies are the recurring methods criminals use to make dirty money look clean. Each typology is a recognizable technique, a pattern that has been seen enough times to be named and studied. Think of them as a catalog of the ways laundering is done. Criminals rarely invent something wholly new; they reuse and adapt methods that work, which is exactly what makes typologies so useful to the people trying to stop them. Knowing the methods is the first step to catching them. Read more: for real cases, see our money laundering examples. Why typologies matter Typologies matter because they turn a vague threat into something a firm can act on. You cannot design a control against laundering in the abstract, but you can design one against structuring or trade misinvoicing. They shape monitoring rules, guide training, and sharpen investigations. When an analyst knows the typologies, they recognize a pattern faster, because they have seen its shape before. Bodies such as the FATF publish typology reports precisely so that firms and regulators can learn from what has been seen elsewhere. There is a practical rhythm to this. A method surfaces in one country, gets written up in a typology report, and firms elsewhere update their monitoring before it reaches them. Shared knowledge is one of the few lasting advantages the defenders have. The main money laundering typologies Laundering methods are many, but a core set appears again and again. These are the typologies most firms build controls around. Structuring. Breaking cash into small deposits to stay under reporting limits. Trade-based laundering. Hiding money in the over- or under-pricing of goods. Shell companies. Using companies with no real activity to move and hide money. Money mules. Using other people’s accounts to move funds. Cash-intensive businesses. Mixing dirty cash with the takings of a cash business. Real estate. Buying property to store and clean large sums. Cryptocurrency. Moving value through digital assets to obscure the trail. Most real laundering schemes combine several of these rather than relying on just one. A single scheme might place cash through a restaurant, layer it through a shell company, and integrate it into property, using three typologies in one chain. Recognizing that combination is often what breaks a case open. Know the warning signs of each method Use our red flags checklist to review customers and transactions against common laundering typologies. Open the Red Flags Checklist → See which risks you face most Get an indicative read on your money laundering risk across customers, products, and channels. Try the AML Risk Assessment → Structuring and smurfing Structuring is one of the oldest and most common typologies. It works by breaking a large sum into many small transactions to avoid a reporting threshold. When the work is spread across many people, each making small deposits, it is called smurfing. See structuring for detail. The aim is the same: keep each transaction below the level that triggers a report, so the total slips through unseen. It is a classic sign of the placement stage. Trade-based laundering Trade-based laundering hides money inside international trade. It is one of the hardest typologies to catch, because it uses the sheer volume and complexity of global trade as cover. The method works by mispricing goods. Over-invoicing an export or under-invoicing an import moves value across borders while looking like ordinary business. Because real goods and real paperwork are involved, the money can be very hard to separate from legitimate trade. Digital and emerging typologies As banking has gone digital, so has laundering. Newer typologies use technology to move money faster and with less visibility. Cryptocurrency. Moving value through digital assets, sometimes across many wallets. Money mules recruited online. People persuaded to move money through their accounts. Fast payments. Using real-time transfers to move funds before checks can catch them. These do not replace the old methods so much as add to them, giving criminals more tools and firms more to watch. The lesson is that new typologies rarely retire the old ones; they stack on top of them. Worth knowing. Typologies are a moving target. The moment a control reliably catches one method, criminals shift to another, which is why typology reports and monitoring rules need regular updating. A program built to catch last year’s typologies will slowly go blind to this year’s. How firms use typologies Firms turn typologies into practical defenses. Knowing the method is only useful if it shapes what the firm actually does. Build monitoring rules. Design alerts around known typologies, such as structuring. Train staff. Teach teams to recognize the shape of each method. Assess risk. Judge which typologies the firm is most exposed to. Update regularly. Refresh controls as new typologies appear. Do this: get an indicative read on which risks you face most with the AML Risk Assessment. Typologies vs stages vs red flags Typologies, stages, and red flags are related ideas that are easy to mix up. … Read more

Supervisory technology

Supervisory technology Supervisory technology, or SupTech, is the technology regulators themselves use to supervise, monitor, and analyse the firms under their watch. It’s the regulator-side counterpart to RegTech, which describes the technology regulated firms use to meet their own compliance obligations. Central banks and financial regulators have been building SupTech capability steadily since around 2018, and it’s now a stated strategic priority for many of them. Key takeaways SupTech is the technology regulators use to supervise firms; RegTech is the technology firms use to comply. The BIS’s Financial Stability Institute launched the Informal SupTech Network in 2018 to connect supervisors across jurisdictions. The Financial Stability Board’s October 2020 report documented 28 real case studies of SupTech in use. Common uses include automated regulatory returns, closer-to-real-time monitoring, and sector-wide analytics. The European Central Bank has built a dedicated SupTech Hub as part of its core supervisory strategy. Post-2008 reforms increased reporting volume faster than manual review could keep up, a major reason SupTech adoption accelerated. On this page What supervisory technology actually isSupTech vs RegTech: who’s using the toolWhat SupTech is actually used forThe technology underneath itReal examples from regulatorsWhy regulators adopted SupTech when they didThe limits and challengesWhat SupTech means for the firms being supervisedFAQsRead more 2018 Year the BIS’s Financial Stability Institute launched its Informal SupTech Network Source: Financial Stability Board 28 Case studies of SupTech in use documented in the FSB’s October 2020 report Source: Financial Stability Board What supervisory technology actually is Supervisory technology describes the tools regulators and other supervisory bodies use internally to oversee financial institutions, markets, and business operations. It covers everything from automated data collection systems to machine learning models that flag anomalies across an entire regulated population, rather than one firm at a time. The core idea is straightforward: regulators sit on enormous amounts of data submitted by the firms they oversee, and SupTech is about actually using that data at scale, rather than relying purely on periodic manual reviews and on-site inspections. SupTech vs RegTech: who’s using the tool SupTech and RegTech are often mentioned together, and easy to confuse, but they describe opposite sides of the same relationship. RegTech is technology regulated firms use to meet their compliance obligations more efficiently, things like automated transaction monitoring or KYC verification tools. SupTech is technology the regulator itself uses to supervise those firms. The two increasingly interact. A regulator’s SupTech platform might ingest data directly from a firm’s RegTech systems, which is part of why some authorities now think about the two as a connected pipeline rather than separate problems. What SupTech is actually used for In practice, SupTech gets used for a specific set of jobs: collecting and validating regulatory returns automatically rather than manually, monitoring firms and markets closer to real time instead of waiting for periodic reports, and running analytics across an entire sector to spot risks or patterns that wouldn’t be visible looking at any single firm in isolation. The Financial Stability Board’s own assessment is that SupTech can improve a regulator’s oversight, surveillance and analytical capability, and generate real-time risk indicators that support more forward-looking, judgement-based supervision, rather than supervision that only reacts after a return gets filed. The technology underneath it The technical building blocks behind most SupTech tools are the same ones reshaping the wider financial sector: artificial intelligence and machine learning for pattern detection, natural language processing for parsing unstructured text like news reports or firm disclosures, cloud computing and APIs for handling large volumes of data efficiently, and in some cases distributed ledger technology for tracking specific asset classes. None of these are unique to supervision. What makes them SupTech specifically is who’s using them and why: a regulator applying them to oversee a population of firms, rather than a firm applying them to run its own business or meet its own obligations. Real examples from regulators The Bank for International Settlements’ Financial Stability Institute launched the Informal SupTech Network in 2018, giving supervisors from different countries a standing venue to compare notes on what’s actually working. The Financial Stability Board’s own 2020 report on the subject, published 9 October 2020, documented 28 separate case studies from regulators around the world putting SupTech to work. The European Central Bank has gone further, building a dedicated SupTech Hub and a Digitalisation Roadmap as a core part of its strategic vision for banking supervision, rather than treating SupTech as a side project sitting outside its main supervisory function. Why regulators adopted SupTech when they did Much of the push behind SupTech traces back to the aftermath of the 2008 financial crisis. Post-crisis reforms significantly increased the volume and granularity of data firms had to report to regulators, and manual review processes weren’t built to keep pace with that volume. SupTech emerged largely as a response to that mismatch: more data coming in than a purely human review process could realistically process well. Canada’s Office of the Superintendent of Financial Institutions put it plainly in 2019, describing RegTech and SupTech as ways to increase the scope and efficiency of its assessments and sharpen where it focuses its interventions, while acknowledging that adopting the technology meant rethinking talent, process, and data structure alongside it. Worth knowing. SupTech adoption is largely a response to a data mismatch, not a technology trend for its own sake. Post-financial-crisis reforms significantly increased how much firms had to report, and manual review simply couldn’t keep pace with the volume. The limits and challenges SupTech isn’t a solved problem for regulators. The FSB’s own research found that implementation challenges persist even where there’s broad consensus on the benefits, spanning everything from data quality issues to the talent and skills needed to build and run these systems inside a public authority rather than a technology company. There’s also a genuine tension between automation and judgement. Supervision has always relied partly on experienced human assessment of a firm’s culture and conduct, something that’s harder to fully automate than flagging a numeric anomaly in a … Read more

Compliance Risk

Compliance risk is the risk of legal penalties, financial loss, or reputational damage that a firm faces when it fails to follow laws, regulations, or its own rules. In AML, it is the risk of getting screening, reporting, or controls wrong and paying for it. Key takeaways Compliance risk is the risk of loss from failing to follow the rules. It covers legal penalties, financial loss, and reputational damage. In AML, it means the risk of weak controls, screening, or reporting. It differs from compliance culture, the shared attitude to the rules. When it materializes, the cost can run into billions. It is managed through controls, oversight, and a strong culture. On this page What it isTypes of compliance riskWhat drives itRisk vs cultureWhen it materializesManaging itIn AMLReducing itFAQsRead more $8.9B BNP Paribas penalty when compliance risk was realized, 2014 Source: US Department of Justice $3.09B TD Bank penalty for AML failures, 2024 Source: US Department of Justice 1989 Year the FATF set the global AML standard Source: FATF What is compliance risk? Compliance risk is the danger a firm faces from not following the rules it is bound by. Those rules can be laws, regulations, or a firm’s own internal policies, and failing to meet them carries a cost. That cost takes several forms: fines from regulators, financial losses, legal action, and damage to reputation. Compliance risk is, in short, the exposure a firm carries whenever there is a chance it falls short of what it is required to do. It is one of the main risks any regulated firm manages. Read more: in AML it is a core part of financial crime compliance. Types of compliance risk Compliance risk is not a single thing; it shows up in several forms. Each represents a different way a failure can hurt. Regulatory risk. The risk of fines or action from a regulator. Legal risk. The risk of lawsuits or criminal liability. Financial risk. The direct cost of penalties and remediation. Reputational risk. The loss of trust from customers, partners, and investors. These often come together. A single serious failure can bring a fine, legal action, remediation costs, and reputational harm all at once. What drives compliance risk Compliance risk rises and falls with a number of factors. Understanding them helps a firm see where its exposure sits. Weak controls, poor training, complex or fast-changing rules, high-risk customers, and a weak compliance culture all push the risk up. A firm operating in many countries, or in a heavily regulated sector like finance, naturally carries more compliance risk than a simple domestic business. The level of risk reflects both how exposed a firm is and how well it manages that exposure. Compliance risk vs compliance culture Compliance risk and compliance culture are two sides of the same coin, and it helps to separate them. One is the threat, the other the attitude that shapes it. Compliance risk is the risk of failing to comply and paying the price. Compliance culture is the shared attitude toward following the rules in the first place. The two connect directly: a strong culture lowers compliance risk, while a weak one raises it. Culture is the behavior; risk is the exposure that behavior creates. Compliance risk Compliance culture What it is The risk of failing to comply The shared attitude to the rules Nature A threat and its consequences A mindset and behavior Link Raised by a weak culture The behavior that shapes the risk A firm manages compliance risk partly by building the culture that keeps it low. Get an indicative AML risk rating See where your compliance and money laundering risk is concentrated across the business. Try the AML Risk Assessment → When compliance risk materializes When compliance risk turns into reality, the cost can be severe. The largest cases show just how much is at stake. In 2014, BNP Paribas paid about $8.9 billion after breaching US sanctions, and in 2024 TD Bank paid about $3.09 billion over AML failures. These are compliance risk realized: the exposure a firm carried becoming an actual, enormous cost. Beyond the headline fines came monitors, remediation, and lasting reputational damage, which often outlast the payment itself. Managing compliance risk Firms manage compliance risk the way they manage any risk: by understanding it and putting controls against it. A few steps form the core. Assess the risk. Identify where the firm is most exposed. Build controls. Put policies, screening, and monitoring against the risk. Provide oversight. Give compliance the authority to challenge the business. Strengthen culture. Build the attitude that keeps the risk low. Do this: document your controls with a tailored AML policy. Compliance risk in AML In anti-money laundering, compliance risk has a specific and serious edge. Getting AML wrong is one of the fastest ways for compliance risk to materialize. An AML failure, such as weak screening, poor monitoring, or missed reports, can bring some of the largest penalties in the whole field, as the biggest fines show. AML compliance risk is heightened by the high stakes involved: the money is criminal, the rules are strict, and regulators enforce them hard. This is why AML sits at the center of most firms’ compliance risk management. Worth knowing. Compliance risk is often underestimated until it materializes. A firm may run for years without a serious failure and come to see compliance as a cost rather than a protection. Then a single breakdown brings a fine, a monitor, and reputational damage that dwarfs what prevention would have cost. Treating compliance risk as real, before it bites, is far cheaper than treating it after. Reducing compliance risk Reducing compliance risk is about closing the gaps that let failures happen. A few priorities matter most. Keep controls current. Update them as rules and risks change. Train people. Make sure staff understand their obligations. Screen and monitor. Catch risks through proper checks. Fix issues early. Address gaps before they become failures. Screen a customer against watchlists Run one search across … Read more

Petty corruption

Petty corruption Petty corruption is the everyday abuse of entrusted power by lower-level officials, most often a small bribe paid to get access to a service the person was already entitled to. It’s the version of corruption most people actually encounter: a payment to a police officer, a clerk, or a permit inspector, rather than a scheme run out of a minister’s office. It’s also far more common than the headline cases suggest. Key takeaways Petty corruption is everyday bribery of lower-level officials for services a person is already entitled to. Nearly 1 in 4 people worldwide paid a bribe to access a public service in the past year (Transparency International, GCB 2017). It differs from grand corruption by scale and seniority, not just the amount of money involved. A facilitation payment is a narrower, business-context version of the same broader pattern. The burden falls hardest on people with less money and social standing. Structural fixes, simpler processes, digitisation, fair public sector pay, tend to work better than enforcement alone. On this page What petty corruption actually looks likeHow common it still isPetty corruption vs grand corruptionWhy petty corruption persists even where it’s illegal everywhereWho tends to get asked for a bribe, and who tends to payPetty corruption and facilitation paymentsWhy it matters for AML programmesWhat reduces itFAQsRead more 1 in 4 People worldwide who paid a bribe to access a public service in the previous 12 months Source: Transparency International, Global Corruption Barometer 2017 162,136 Adults surveyed across 119 countries for that finding Source: Transparency International, GCB 2017 1 in 5 People in Asia who used a public service and paid a bribe in the past year Source: Transparency International, GCB Asia 2020 What petty corruption actually looks like Petty corruption happens at the point where an ordinary person meets a low-level official who controls something they need: a permit, a police interaction, a hospital bed, a school place, a customs stamp. The official asks for, or clearly expects, a payment to do their job at all, or to do it faster. It’s distinct from grand corruption mainly in scale and who’s involved. A police officer asking for a small payment at a checkpoint is petty corruption. A minister diverting a national infrastructure budget is grand corruption. Both are corruption; they operate at completely different levels of the system. How common it still is Transparency International’s Global Corruption Barometer, the largest recurring public opinion survey on corruption, found that nearly one in four people worldwide paid a bribe to access a public service in the 12 months before being surveyed. That finding came from interviews with 162,136 adults across 119 countries between March 2014 and January 2017. Regional numbers vary sharply. A more recent Global Corruption Barometer Asia survey found that roughly one in five people who used a public service in the previous year paid a bribe to get it, across 17 countries and nearly 20,000 respondents. Petty corruption vs grand corruption Grand corruption and petty corruption sit at opposite ends of the same problem, not on a single sliding scale. Grand corruption involves senior officials, state institutions, and harm at national or economic scale, sometimes running into billions of dollars. Petty corruption involves everyday interactions between ordinary citizens and lower-level officials, usually amounts small enough that no single payment looks significant on its own. The two aren’t unconnected. A senior official running a grand corruption scheme often relies on a chain of petty corruption below them, junior staff who process the paperwork, look away, or collect small payments as part of the wider system. Worth knowing. A senior official running a grand corruption scheme often relies on a chain of petty corruption below them: junior staff who process the paperwork, look away, or collect small payments as part of the wider system. The two aren’t unconnected. Why petty corruption persists even where it’s illegal everywhere Petty corruption survives partly because it fills a gap between what a public service is supposed to deliver and what it actually delivers. Where processes are genuinely slow, unclear, or understaffed, a small payment becomes a practical shortcut, even when everyone involved knows it’s illegal. Transparency International’s own research into the Asia region found that unclear regulatory frameworks and unnecessary bureaucracy were cited as direct drivers, pushing citizens toward informal payments and personal connections rather than official channels. That’s not an excuse for it. It’s a reason enforcement alone rarely fixes it without also fixing the underlying process. Who tends to get asked for a bribe, and who tends to pay The burden of petty corruption doesn’t fall evenly. People with less money, less education, and less social standing are typically the ones asked to pay, and the ones least able to refuse or complain. Someone with connections or status can often get the same service without paying, using influence instead of cash. That’s part of why petty corruption is treated as more than a minor nuisance in development and governance policy. It functions as a regressive tax, hitting people who can least afford it hardest, and it erodes trust in public institutions over time. Petty corruption and facilitation payments Petty corruption overlaps with, but isn’t identical to, a facilitation payment. A facilitation payment specifically describes money paid to speed up a routine action an official already owes, often in a cross-border business or trade context. Petty corruption is the broader pattern of everyday bribery, which includes facilitation-style payments but also covers payments to avoid a fine, get preferential treatment, or access a service that shouldn’t require payment at all. Why it matters for AML programmes Petty corruption itself rarely appears as a standalone line item in AML programmes; the amounts involved are usually too small to trigger transaction monitoring on their own. Where it matters for AML work is upstream, in third-party and country risk assessments. A jurisdiction where petty corruption is widespread is also one where due diligence documentation, licences, and even law enforcement records can be less reliable, … Read more

Nominated officer

Nominated officer A nominated officer is the person a UK firm appoints to receive internal reports of suspected money laundering or terrorist financing from staff, and decide whether to pass them on to the National Crime Agency as a suspicious activity report. The role comes from the Money Laundering Regulations 2017 and the Proceeds of Crime Act 2002. Most firms use the term interchangeably with MLRO, though the two aren’t identical in every jurisdiction. Key takeaways A nominated officer receives internal reports of suspected money laundering and decides whether to file an external SAR with the NCA. The role comes from regulation 21(3) of the Money Laundering Regulations 2017 and Part 7 of POCA 2002. In everyday use, “nominated officer” and “MLRO” mean the same person. The MLCO is a separate, board-level role accountable for the firm’s overall AML compliance, not the same job. Failing to report a suspicion that should have been reported can mean up to 5 years in prison under POCA. The definition isn’t universal: Guernsey’s nominated officer only covers the MLRO’s absence, a narrower role than the UK version. On this page What a nominated officer actually doesWhere the role comes fromNominated officer vs MLRO: the practical answerNominated officer vs MLCO: the real distinctionWhat happens after a staff member reports somethingPersonal liability: why the role carries weightDeputies and cover arrangementsHow the role differs outside the UKFAQsRead more 5 years Maximum prison term for failing to disclose a suspicion that should have been reported Source: Proceeds of Crime Act 2002, via ACCA 14 days Window the SRA requires firms to notify it when their MLRO changes Source: Solicitors Regulation Authority What a nominated officer actually does The nominated officer sits at the centre of a firm’s internal reporting chain. When a member of staff suspects money laundering or terrorist financing, they don’t go straight to the National Crime Agency. They report it internally, to the nominated officer, first. From there, the nominated officer reviews what’s been reported, decides whether it meets the threshold for suspicion, and files a suspicious activity report with the NCA if it does. If it doesn’t, they record the decision and the reasoning behind it. That makes the role a filter, not a passthrough. A firm that reports everything without evaluating it, or one that fails to report things that clearly warrant it, both fall short of what the regulations expect. Where the role comes from The legal requirement sits in two places. Regulation 21(3) of the Money Laundering Regulations 2017 requires firms in the regulated sector to appoint an individual as nominated officer. Regulation 3 defines the term: someone nominated to receive disclosures under Part 3 of the Terrorism Act 2000 and Part 7 of the Proceeds of Crime Act 2002. POCA creates the underlying reporting offence. Under sections 330 to 332, failing to disclose a suspicion of money laundering, when you’re in a position where you should have known, is a criminal offence in its own right, separate from the laundering itself. Nominated officer vs MLRO: the practical answer In everyday use, nominated officer and MLRO mean the same person doing the same job. MLRO, or money laundering reporting officer, is the common industry name for whoever holds the statutory nominated officer position. Most policies, job titles, and regulator correspondence say MLRO, even though the regulations themselves say nominated officer. Sole practitioners with no staff are the main exception. Regulation 21 doesn’t require a nominated officer where there’s nobody internal to report to in the first place. Worth knowing. Sole practitioners with no staff and nobody else to report to are the main exception to the nominated officer requirement. Regulation 21 doesn’t apply where there’s no one internal to make a disclosure to. Nominated officer vs MLCO: the real distinction The genuine split is between the nominated officer and the MLCO, the money laundering compliance officer. Regulation 21(1) requires a separate, board-level appointment: someone senior who’s accountable for the firm’s overall compliance with the Money Laundering Regulations. The nominated officer’s job is narrower and operational: receive internal reports, decide on external SARs. The MLCO’s job is broader: policies, procedures, training, and the firm’s whole AML framework. In smaller firms, one person often holds both roles. In larger, FCA-regulated firms, they’re frequently split, with the MLRO holding the formal SMF17 senior management function. What happens after a staff member reports something Once a report reaches the nominated officer, the clock starts. They review the facts, decide whether a genuine suspicion exists, and act on that decision without unnecessary delay. If they file an external SAR, the firm generally can’t proceed with the transaction in question until it gets consent from the NCA, or a set time limit passes. Staff who reported the original concern also need to stay quiet about it. Tipping off the customer, even by accident, is a separate criminal offence. Personal liability: why the role carries weight The nominated officer carries personal criminal exposure, not just professional risk. Under POCA, failing to disclose a suspicion that should have been reported can mean a fine and up to five years in prison. That’s a meaningful part of why firms take the appointment seriously, and why the role tends to go to someone experienced rather than whoever happens to be free. Getting the call wrong, in either direction, has consequences that land on the individual, not just the firm. Deputies and cover arrangements Every firm needs a plan for when the nominated officer is away. Larger organisations often appoint one or more deputies of sufficient seniority to step in during absences, with clear internal guidance on when that authority applies. Smaller firms typically name a single deputy in their AML policy. What matters to a regulator is that the arrangement is documented, and that staff know exactly who to report to at any given time rather than being left to guess. How the role differs outside the UK The UK’s version of the role isn’t universal. In Guernsey, for example, … Read more

Regulatory Technology (RegTech)

Regulatory technology, or RegTech, is software that helps firms meet compliance rules more quickly and at lower cost. In financial crime, RegTech automates customer checks, screening, transaction monitoring, and reporting, so teams can keep up with rising rules and volumes. Key takeaways RegTech is technology that automates compliance and risk work. In AML it powers screening, monitoring, identity checks, and reporting. It exists because rules, data, and transaction volumes have outgrown manual work. Estimates of the market’s size vary, but growth is steady at around 20 percent a year. RegTech speeds up compliance, but a human still decides the outcome of alerts. Free tools are a form of accessible RegTech for smaller firms. On this page What it isWhy it existsWhat it does in AMLTypes of RegTechBenefits and limitsRegTech vs FinTechHow to adopt itThe futureFAQsRead more ~20% a year Estimated growth of the global RegTech market Source: Grand View Research $800B to $2T Laundered worldwide each year that RegTech targets Source: UNODC $3B Paid by TD Bank in 2024, driving compliance tech spend Source: US Department of Justice What is regulatory technology (RegTech)? Regulatory technology is software built to help firms follow the rules. It takes tasks that people used to do by hand, such as checking a customer or reviewing a transaction, and does them faster and more consistently. The term is a blend of regulatory and technology. It grew out of the wider financial technology, or FinTech, movement after the 2008 financial crisis, when a wave of new rules made manual compliance hard to sustain. In practice, most RegTech today is aimed at financial crime and compliance. Read more: it is the engine behind a modern financial crime compliance function. Why RegTech exists RegTech exists because compliance has outgrown what people can do alone. Three pressures pushed firms toward technology. More rules. Regulation has grown in volume and complexity across every market. More data. Digital banking produces far more transactions than any team can review by hand. Higher stakes. Penalties keep climbing, so the cost of a missed control is severe. The TD Bank case in 2024, with about $3 billion in penalties, is the kind of failure firms now spend on technology to avoid (US Department of Justice, 2024). Estimates of the RegTech market’s size vary widely, from roughly $12 billion to $25 billion in recent years, but the direction is consistent: fast, double-digit growth of around 20 percent a year (Grand View Research). See RegTech in action, free Run one search across sanctions, PEP, and adverse media data and see the kind of check RegTech automates at scale. Try Combined AML Screening → What RegTech does in AML and compliance In anti-money laundering, RegTech carries the heavy, repetitive work. It handles the parts that need speed and consistency, freeing people for judgment. Identity and KYC. Verifying customers and checking documents at onboarding. Screening. Matching names against sanctions, PEP, and adverse media data. Transaction monitoring. Flagging unusual activity across large volumes. See transaction monitoring. Risk scoring. Turning customer and transaction data into a risk rating. Reporting. Preparing and filing regulatory reports and keeping an audit trail. Worth knowing. The biggest practical win from RegTech in AML is not finding more crime, it is cutting false positives. A tool that flags everything buries analysts, so the value is in accuracy, letting a team spend its hours on the alerts that actually matter. Types of RegTech RegTech covers several categories, and most firms use more than one. Each targets a different compliance need. Compliance management. Tracking rules and mapping them to internal controls. Identity and KYC. Verifying who a customer is and screening them. Risk management. Assessing and scoring financial crime and other risks. Transaction monitoring. Watching payments and behavior for signs of crime. Regulatory reporting. Collecting data and submitting it to regulators. Increasingly these use artificial intelligence and machine learning to spot patterns a rules-only system would miss. Benefits and limits of RegTech RegTech brings clear gains, but it is not a complete answer. Knowing both sides keeps expectations realistic. On the upside, it is faster, more consistent, and able to handle volumes no team could review by hand. It also lowers cost and creates a clean record for regulators. On the downside, a tool is only as good as its setup. Poorly tuned rules produce noise, and a system with nobody reviewing its alerts is a finding, not a control. Technology speeds up the work, but a person still decides the outcome. There is a middle path many firms miss. The strongest results come from pairing a capable tool with a skilled reviewer, so the technology carries the volume and the person carries the judgment. Treating RegTech as a replacement for people, rather than a support for them, is where projects tend to disappoint, and where regulators tend to find gaps. Data quality is the other quiet factor. A screening tool that runs on stale or thin lists will miss real risks and flag false ones, no matter how good the software is, which is why the source behind a tool matters as much as the tool itself. Get an indicative AML risk rating See where your money laundering risk is concentrated across customers, products, channels, and geographies. Try the AML Risk Assessment → RegTech vs FinTech and SupTech RegTech is often confused with related terms. The difference is who uses the technology and why. Term Who uses it Purpose FinTech Financial firms and consumers Deliver financial products and services RegTech Regulated firms Meet compliance and manage risk SupTech Regulators Supervise firms and analyze data RegTech is best seen as a branch of FinTech focused on compliance, while SupTech is the same idea applied by the regulator rather than the firm. How to adopt RegTech Adopting RegTech works best as a considered step, not a rushed purchase. A short, ordered approach avoids common mistakes. Start from risk. Base the choice on your AML risk assessment and where the gaps are. Define the need. Be clear on … Read more