← Certified Anti-Money Laundering Specialist (CAMS)
Test yourself →

Risks and Methods of Money Laundering and Terrorist Financing

## Risks and Methods of Money Laundering and Terrorist Financing

Understanding the dynamic risks and diverse methods of money laundering (ML) and terrorist financing (TF) is crucial for AML professionals. Risks vary significantly based on customer, product/service, geography, and delivery channel.

## Key Risk Factors

  • Customers: High-risk customers include Politically Exposed Persons (PEPs), non-resident aliens, cash-intensive businesses, charities/Non-Profit Organizations (NPOs), and shell companies lacking clear beneficial ownership.
  • Products/Services: Products facilitating rapid movement of funds or anonymity are high-risk. Examples include wire transfers, private banking, correspondent banking, Payable Through Accounts (PTAs), virtual assets, and trade finance.
  • Geographies: Jurisdictions with weak AML/CFT regimes, high corruption, OFAC sanctions, or known terrorist activity pose elevated risks.
  • Delivery Channels: Non-face-to-face interactions, internet banking, and new technologies can increase anonymity and risk.

## Stages of Money Laundering

Money laundering typically involves three stages:

1. Placement: Introducing illicit proceeds into the financial system, often through structuring cash deposits or purchasing monetary instruments.

2. Layering: Separating illicit proceeds from their source through complex layers of financial transactions to obscure the audit trail and disguise ownership. This might involve multiple wire transfers, shell companies, or investments.

3. Integration: Returning the "cleaned" funds to the legitimate economy, often through investments in real estate, luxury goods, or legitimate businesses, making them appear legitimate.

## Methods of Money Laundering

Launderers exploit various sectors:

  • Financial Institutions: Misuse of correspondent banking, private banking, wire transfers, and Payable Through Accounts (PTAs).
  • Non-Bank Financial Institutions (NBFIs) & Designated Non-Financial Businesses and Professions (DNFBPs): Money Service Businesses (MSBs), casinos, real estate, precious metals/stones dealers, and lawyers/accountants are vulnerable.
  • Trade-Based Money Laundering (TBML): Involves manipulating trade transactions to move value, such as over-invoicing, under-invoicing, phantom shipments, or misrepresenting goods.
  • New Technologies: Virtual assets (cryptocurrencies), peer-to-peer payment platforms, and online gambling offer new avenues for illicit fund movement.
  • Shell Companies & Trusts: Used extensively to obscure beneficial ownership and create complex layering schemes.

## Terrorist Financing (TF)

TF differs from ML primarily in the origin of funds and end goal. TF funds can originate from legitimate sources (e.g., donations, legitimate businesses) or illicit activities, but are always intended to fund terrorist acts or organizations.

  • Sources: Misuse of NPOs/charities, legitimate businesses, and criminal activities.
  • Methods: Often involves smaller, less conspicuous transactions. Includes hawala (informal value transfer systems), cash couriers, and the use of shell companies and virtual assets.
  • ML risks are dynamic, varying by customer, product, geography, and delivery channel.
  • **Placement** is the first stage of money laundering, introducing illicit funds into the financial system.
  • **Politically Exposed Persons (PEPs)** are considered high-risk customers due to potential for corruption.
  • **Trade-Based Money Laundering (TBML)** uses commercial transactions like over- or under-invoicing to move value.
  • Terrorist financing (TF) can originate from legitimate funds, unlike money laundering which always uses illicit funds.
  • **Correspondent banking** is a high-risk service due to its global reach and potential for anonymity.
  • **Virtual assets** (cryptocurrencies) pose ML/TF risks due to their pseudo-anonymity and speed.
  • **Layering** is the most complex stage of ML, designed to obscure the audit trail of illicit funds.
What are the three stages of money laundering?
Placement, Layering, Integration.
tap to reveal
What is a key difference between money laundering (ML) and terrorist financing (TF) regarding fund origins?
ML always involves illicitly derived funds; TF can involve funds from legitimate sources.
tap to reveal
Name three high-risk customer categories for ML/TF.
Politically Exposed Persons (PEPs), non-resident aliens, cash-intensive businesses, shell companies, NPOs/charities.
tap to reveal
What is Trade-Based Money Laundering (TBML)?
The process of disguising the proceeds of crime and moving value through the use of trade transactions.
tap to reveal
Which stage of money laundering involves introducing illicit funds into the financial system?
Placement.
tap to reveal
Why is correspondent banking considered a high-risk service for ML?
It allows financial institutions to conduct transactions globally, often for unknown third-party beneficiaries, increasing anonymity and complexity.
tap to reveal
What is "hawala"?
An informal value transfer system (IVTS) based on trust, often used in TF, that operates outside traditional banking channels.
tap to reveal
Give an example of a high-risk product/service for ML.
Private banking, wire transfers, virtual assets, Payable Through Accounts (PTAs), shell companies.
tap to reveal

International AML/CFT Standards

## International AML/CFT Standards: A Global Framework

The global fight against money laundering (ML) and terrorist financing (TF) relies on a robust framework of international standards and cooperation. These standards provide a common benchmark for countries to develop effective AML/CFT regimes, promoting transparency and accountability across jurisdictions.

## Financial Action Task Force (FATF)

The FATF is the leading inter-governmental body that sets international standards to prevent ML and TF. Its 40 Recommendations are the globally recognized benchmark for AML/CFT. They cover a wide range of topics, including:

  • Criminalizing ML and TF.
  • Customer Due Diligence (CDD) and record-keeping requirements.
  • Reporting suspicious transactions (STRs) to Financial Intelligence Units (FIUs).
  • Transparency of legal persons and arrangements (beneficial ownership).
  • International cooperation (mutual legal assistance, extradition).
  • Sanctions for designated terrorist groups and proliferation financing.
  • Regulation and supervision of financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs).

FATF conducts mutual evaluations of member countries to assess their compliance with the Recommendations and the effectiveness of their AML/CFT systems. Countries identified with strategic deficiencies are placed on the FATF grey list or black list.

## Key International Bodies and Conventions

  • United Nations (UN) Conventions:
  • Vienna Convention (1988): Focused on illicit trafficking in narcotic drugs and psychotropic substances, requiring criminalization of drug-related ML.
  • Palermo Convention (2000): Targets transnational organized crime, broadening the scope of predicate offenses for ML.
  • International Convention for the Suppression of the Financing of Terrorism (1999): Requires countries to criminalize terrorist financing.
  • Basel Committee on Banking Supervision (BCBS): Provides guidance on banking supervision, including principles for Customer Due Diligence (CDD) for banks. Its Core Principles for Effective Banking Supervision include AML/CFT elements.
  • Wolfsberg Group: An association of 13 global banks that develops frameworks and guidance for managing financial crime risks, including Correspondent Banking, Politically Exposed Persons (PEPs), and Trade-Based Money Laundering (TBML). Its principles are widely adopted as private sector best practices.
  • Egmont Group of Financial Intelligence Units (FIUs): A global network of FIUs that facilitates the secure exchange of financial intelligence to combat ML and TF. It promotes international cooperation among FIUs.
  • International Monetary Fund (IMF) and World Bank: Conduct AML/CFT assessments, provide technical assistance, and promote the adoption of international standards.
  • The **FATF 40 Recommendations** are the global standard for AML/CFT.
  • FATF conducts **mutual evaluations** to assess country compliance and effectiveness.
  • The **UN Vienna Convention** targets drug-related money laundering.
  • The **UN Palermo Convention** focuses on transnational organized crime.
  • The **Wolfsberg Group** provides private sector best practice guidance for financial crime risk management.
  • The **Egmont Group** facilitates secure information exchange among Financial Intelligence Units (FIUs).
  • The **Basel Committee** provides banking supervision guidance, including CDD principles.
  • FATF identifies countries with strategic AML/CFT deficiencies via its grey and black lists.
What is the primary role of the FATF?
To set international standards (the 40 Recommendations) to combat money laundering and terrorist financing.
tap to reveal
Which international body facilitates secure information exchange among FIUs?
The Egmont Group of Financial Intelligence Units.
tap to reveal
What is the focus of the UN Vienna Convention (1988)?
Combating illicit trafficking in narcotic drugs and psychotropic substances, including drug-related money laundering.
tap to reveal
What kind of guidance does the Wolfsberg Group provide?
Private sector best practice guidance for managing financial crime risks, such as correspondent banking and PEPs.
tap to reveal
What are FATF mutual evaluations?
Assessments of a country's compliance with the FATF Recommendations and the effectiveness of its AML/CFT system.
tap to reveal
Which UN Convention requires countries to criminalize the financing of terrorism?
The International Convention for the Suppression of the Financing of Terrorism (1999).
tap to reveal
What is the Basel Committee on Banking Supervision's role in AML/CFT?
It provides principles and guidance for effective banking supervision, including Customer Due Diligence (CDD) for banks.
tap to reveal
What is the purpose of the FATF grey and black lists?
To identify countries with strategic AML/CFT deficiencies that pose a risk to the international financial system.
tap to reveal

AML/CFT Compliance Programs

## AML/CFT Compliance Programs: Core Components

An effective Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) compliance program is the cornerstone of a financial institution's defense against illicit finance. Based on FATF Recommendation 18, such programs typically comprise four essential pillars: robust Internal Controls, a designated AML Compliance Officer, comprehensive Training for relevant staff, and an Independent Audit function to assess effectiveness.

## The Risk-Based Approach (RBA)

Central to any robust AML/CFT program is the Risk-Based Approach (RBA). This methodology requires institutions to identify, assess, and understand their money laundering and terrorist financing risks, and then implement controls proportionate to those risks. The RBA allows for the efficient allocation of resources, focusing more intensive controls on higher-risk areas (e.g., certain customers, products, geographies) while applying simplified measures where risks are demonstrably lower. This dynamic process involves continuous monitoring and adjustment of controls based on evolving risk landscapes.

## Customer Due Diligence (CDD)

Customer Due Diligence (CDD), also known as Know Your Customer (KYC), is a critical component for managing customer-related risks. It involves:

  • Identifying and verifying the identity of the customer and, where applicable, the beneficial owner.
  • Understanding the nature and purpose of the business relationship.
  • Ongoing monitoring of the business relationship and transactions to ensure they are consistent with the institution's knowledge of the customer and their risk profile.

For higher-risk customers or relationships, Enhanced Due Diligence (EDD) measures are required, involving more rigorous scrutiny. Conversely, Simplified Due Diligence (SDD) may be applied to lower-risk scenarios.

## Suspicious Activity Reporting (SARs/STRs)

Institutions must have systems to identify and report suspicious transactions to the relevant Financial Intelligence Unit (FIU). This obligation, known as Suspicious Activity Reporting (SAR) in the US or Suspicious Transaction Reporting (STR) internationally, is vital for law enforcement. A crucial aspect is the "no tipping off" rule, which prohibits informing customers or third parties that a SAR/STR has been filed.

## Training and Independent Audit

Regular, tailored training is essential to ensure all relevant employees understand their AML/CFT obligations and can identify suspicious activities. The scope and frequency should align with the institution's risk profile. Finally, an independent audit or testing function must periodically assess the effectiveness of the AML/CFT program, identify deficiencies, and recommend corrective actions. This audit must be conducted by qualified individuals independent of the AML compliance function being reviewed.

  • FATF Recommendation 18 outlines the four core pillars of an AML/CFT program.
  • The Risk-Based Approach (RBA) requires identifying, assessing, mitigating, and monitoring ML/TF risks.
  • Customer Due Diligence (CDD) involves identifying, verifying, understanding, and ongoing monitoring of customers.
  • Enhanced Due Diligence (EDD) is mandatory for higher-risk customers and relationships.
  • The "no tipping off" rule prohibits disclosing that a SAR/STR has been filed.
  • The AML Compliance Officer requires sufficient authority, resources, and independence.
  • AML training must be ongoing, tailored to roles, and cover current risks.
  • An independent audit function ensures the AML program's effectiveness and identifies weaknesses.
What are the four core pillars of an effective AML/CFT compliance program?
Internal Controls, AML Compliance Officer, Training, Independent Audit.
tap to reveal
What is the primary objective of a Risk-Based Approach (RBA) in AML/CFT?
To identify, assess, mitigate, and monitor ML/TF risks, allocating resources proportionately.
tap to reveal
What are the key components of Customer Due Diligence (CDD)?
Identifying/verifying customer identity and beneficial owner, understanding the business relationship's purpose, and ongoing monitoring.
tap to reveal
When is Enhanced Due Diligence (EDD) typically required?
For higher-risk customers, products, services, or geographic locations.
tap to reveal
What is the "no tipping off" rule in the context of Suspicious Activity Reports (SARs)?
Prohibits informing customers or third parties that a SAR/STR has been filed.
tap to reveal
What characteristics should an AML Compliance Officer possess to be effective?
Sufficient authority, resources, independence, and direct access to senior management/board.
tap to reveal
What is the purpose of an independent audit or testing of an AML/CFT program?
To assess the program's effectiveness, identify deficiencies, and recommend corrective actions.
tap to reveal
What does ongoing monitoring of customer relationships entail under CDD?
Scrutinizing transactions to ensure consistency with the customer's profile, risk rating, and source of funds/wealth.
tap to reveal

Customer Due Diligence (CDD)

## Customer Due Diligence (CDD) Overview

Customer Due Diligence (CDD) is a foundational component of an effective Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) program. It involves identifying and verifying customers, understanding the nature and purpose of their business relationship, and assessing the money laundering/terrorist financing (ML/TF) risks they pose. The primary goal of CDD is to prevent financial institutions (FIs) from being used for illicit activities, comply with regulatory requirements, and protect the institution's reputation.

## Key Elements of CDD

  • Customer Identification Program (CIP): This involves collecting essential identifying information about the customer. For individuals, this typically includes name, address, date of birth, and an identification number. For legal entities, it includes the entity's name, legal form, address, proof of existence, and identification of beneficial owners.
  • Verification: Once information is collected, it must be verified using reliable, independent source documents, data, or information. This ensures the customer is who they claim to be.
  • Understanding the Business Relationship: FIs must gain an understanding of the customer's expected activities, the purpose of the account, and the anticipated volume and type of transactions. This helps in building a customer profile against which future transactions can be monitored.
  • Ongoing Monitoring: CDD is not a one-time process. It requires continuous monitoring of transactions and account activity to ensure consistency with the customer's profile and risk assessment. Customer information, especially for higher-risk clients, should be periodically reviewed and updated.

## Risk-Based Approach to CDD

The Financial Action Task Force (FATF) recommends a risk-based approach to CDD, meaning the intensity of CDD measures should be proportionate to the identified ML/TF risks.

  • Simplified Due Diligence (SDD): May be applied in lower-risk situations, such as for publicly traded companies, government entities, or certain low-value products. While less intensive, basic identification is still required.
  • Enhanced Due Diligence (EDD): Is mandatory for higher-risk customers or situations. This includes Politically Exposed Persons (PEPs), customers from high-risk geographic locations, complex or opaque legal structures, and cash-intensive businesses. EDD requires more rigorous verification, deeper understanding of the source of wealth and funds, senior management approval for establishing relationships, and enhanced ongoing monitoring.

## Beneficial Ownership and PEPs

  • Beneficial Ownership: Identifying the beneficial owner(s) – the natural person(s) who ultimately own or control a legal entity or arrangement – is crucial. Obscuring beneficial ownership is a common ML/TF tactic. FIs must take reasonable measures to identify and verify these individuals, often using a threshold (e.g., 25% ownership).
  • Politically Exposed Persons (PEPs): Individuals entrusted with prominent public functions, their family members, and close associates are considered high-risk due to their vulnerability to bribery and corruption. EDD measures for PEPs include obtaining senior management approval, establishing the source of wealth and funds, and conducting enhanced ongoing monitoring.
  • CDD is fundamental for preventing financial crime and ensuring regulatory compliance.
  • FATF recommends a risk-based approach, tailoring CDD intensity to ML/TF risk.
  • Key CDD elements include CIP, verification, understanding relationship, and ongoing monitoring.
  • **Enhanced Due Diligence (EDD)** is required for high-risk customers like PEPs and complex structures.
  • **Simplified Due Diligence (SDD)** can be applied in clearly identified low-risk scenarios.
  • Identifying and verifying **beneficial owners** is critical to combatting illicit finance.
  • **Politically Exposed Persons (PEPs)** inherently pose a higher ML/TF risk due to potential for corruption.
  • CDD is an ongoing process, not a one-time event, requiring periodic reviews and updates.
What are the four core elements of Customer Due Diligence (CDD)?
Customer Identification Program (CIP), Verification, Understanding the Business Relationship, Ongoing Monitoring.
tap to reveal
What is the primary purpose of a risk-based approach to CDD?
To tailor the intensity of CDD measures to the identified money laundering/terrorist financing (ML/TF) risks, applying more resources to higher-risk areas.
tap to reveal
When is Enhanced Due Diligence (EDD) typically required?
For high-risk customers or situations, such as Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex structures, or cash-intensive businesses.
tap to reveal
Define "Beneficial Owner" in the context of CDD.
The natural person(s) who ultimately own or control a customer (legal entity or arrangement) or the natural person on whose behalf a transaction is being conducted.
tap to reveal
What special measures are typically required for Politically Exposed Persons (PEPs) under EDD?
Senior management approval for the relationship, reasonable measures to establish source of wealth/funds, and enhanced ongoing monitoring.
tap to reveal
Can Simplified Due Diligence (SDD) be applied without any identification?
No, even with SDD, basic customer identification is still required; the intensity of verification and ongoing monitoring may be reduced.
tap to reveal
Which international body's recommendations heavily influence global CDD standards?
The Financial Action Task Force (FATF).
tap to reveal
Is CDD a one-time process or ongoing?
CDD is an ongoing process, requiring continuous monitoring of transactions and periodic review/update of customer information.
tap to reveal

Transaction Monitoring and Reporting

## Transaction Monitoring and Reporting

Transaction monitoring (TM) is a crucial component of an effective Anti-Money Laundering (AML) program. It involves the systematic review of customer transactions to identify unusual or potentially suspicious activities that may indicate money laundering, terrorist financing, or other illicit financial crimes. The primary goal is to detect patterns or deviations from expected behavior that warrant further investigation.

Key Components of a TM System

1. Data Collection and Aggregation: TM systems rely on comprehensive and accurate data from various sources, including customer accounts, payment systems, trade finance, and other financial products. Data quality is paramount for effective monitoring.

2. Rule-Based Systems: Most TM systems utilize predefined rules or scenarios to flag transactions. These rules are designed to identify known money laundering typologies, such as large cash deposits, rapid movement of funds between unrelated accounts, frequent transactions with high-risk jurisdictions, or structuring attempts.

3. Behavioral Analytics and Artificial Intelligence (AI): More advanced systems incorporate behavioral analytics and AI/machine learning to establish baseline customer behavior profiles. They then identify deviations from normal behavior, which can help reduce false positives (alerts that are not genuinely suspicious) and detect more sophisticated schemes.

4. Alert Generation and Management: When a transaction or series of transactions triggers a rule or deviates significantly from a behavioral profile, the system generates an alert. These alerts are then routed to trained AML analysts for review.

5. Investigation and Escalation: Analysts investigate alerts by gathering additional information, reviewing customer profiles, and conducting due diligence. If the activity appears genuinely suspicious after investigation, it is escalated for potential suspicious activity report (SAR) or suspicious transaction report (STR) filing.

Challenges in Transaction Monitoring

  • False Positives: A significant challenge is the high volume of false positives, which can overwhelm AML teams and divert resources.
  • Data Quality: Inaccurate, incomplete, or inconsistent data can severely impair the effectiveness of TM systems.
  • Evolving Typologies: Money launderers constantly adapt their methods, requiring TM systems and rules to be regularly updated.
  • Resource Intensity: Effective TM requires substantial investment in technology, skilled analysts, and ongoing training.

Reporting Suspicious Activity (SAR/STR)

When a financial institution identifies suspicious activity that cannot be reasonably explained, it has a legal obligation to file a SAR/STR with the relevant Financial Intelligence Unit (FIU).

  • Purpose: SARs/STRs provide valuable intelligence to law enforcement agencies for investigating and prosecuting financial crimes.
  • Content: Reports typically include details about the customer, the nature of the suspicious activity, the amounts involved, and the reasons for suspicion.
  • Timelines: Filing deadlines are jurisdiction-specific but generally require prompt reporting (e.g., within 30 days of initial detection).
  • Confidentiality: It is critical to maintain the confidentiality of the SAR/STR filing. Tipping off, which is informing a customer that a report has been filed or is being considered, is strictly prohibited and can carry severe penalties.
  • Transaction monitoring systematically reviews customer activity to detect potential money laundering or terrorist financing.
  • Data quality is fundamental for the accuracy and effectiveness of any transaction monitoring system.
  • Rule-based systems use predefined scenarios to flag transactions that match known money laundering typologies.
  • Behavioral analytics helps reduce false positives by identifying deviations from a customer's normal activity profile.
  • A Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) informs the FIU about suspected illicit activity.
  • Filing SARs/STRs is a legal obligation for financial institutions when suspicious activity cannot be reasonably explained.
  • "Tipping off" refers to informing a customer about a SAR/STR filing, which is strictly prohibited and carries penalties.
  • High volumes of false positives represent a significant challenge for transaction monitoring teams and systems.
What is the primary purpose of transaction monitoring in AML?
To detect and report unusual or suspicious activity that may indicate money laundering or terrorist financing.
tap to reveal
What is a common challenge faced by transaction monitoring systems?
High volumes of "false positives" (alerts that are not genuinely suspicious).
tap to reveal
What is a SAR/STR?
A Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) filed by a financial institution with a Financial Intelligence Unit (FIU) regarding suspected illicit activity.
tap to reveal
What is "tipping off" in the context of SAR/STR filing?
Informing a customer or third party that a SAR/STR has been filed or is being considered, which is strictly prohibited.
tap to reveal
Why is data quality crucial for effective transaction monitoring?
Inaccurate or incomplete data can lead to ineffective monitoring, missed suspicious activity, and increased false positives.
tap to reveal
What type of system uses predefined scenarios to flag transactions?
Rule-based systems.
tap to reveal
When should a financial institution consider filing a SAR/STR?
When it identifies suspicious activity that cannot be reasonably explained by legitimate business or personal activities.
tap to reveal
How do behavioral analytics improve transaction monitoring?
By establishing baseline customer behavior and identifying deviations, reducing false positives and detecting more sophisticated schemes.
tap to reveal

AML Risk Assessment

## AML Risk Assessment Fundamentals

An AML Risk Assessment is the cornerstone of an effective Anti-Money Laundering (AML) program, enabling a risk-based approach (RBA). Its primary purpose is to identify, assess, mitigate, and monitor the money laundering and terrorist financing (ML/TF) risks an institution faces. This process ensures that resources are allocated effectively to areas of highest risk, aligning with international standards like FATF Recommendation 1.

## Key Components and Factors

Institutions must conduct an Enterprise-Wide Risk Assessment (EWRA), considering various factors:

  • Customers: Evaluate customer types (e.g., individuals, corporations, trusts), their geographic locations, occupations/industries, and beneficial ownership. Politically Exposed Persons (PEPs) and customers in high-risk industries (e.g., casinos, real estate) pose elevated risks.
  • Products & Services: Assess the inherent risk of offerings like private banking, correspondent banking, wire transfers, cash-intensive services, new payment technologies, and virtual assets. Products allowing anonymity or rapid movement of funds are generally higher risk.
  • Geographies: Consider the ML/TF risk associated with jurisdictions where customers reside, transactions originate, or funds are destined. This includes countries subject to sanctions, those with weak AML/CFT regimes, or high levels of corruption.
  • Delivery Channels: Evaluate how products and services are offered, such as non-face-to-face onboarding, reliance on intermediaries, or third-party payments.

## The Risk Assessment Process

The process is dynamic and involves several steps:

1. Identify Risks: Pinpoint potential ML/TF threats specific to the institution's business model.

2. Assess Inherent Risk: Evaluate the likelihood and impact of these identified risks *before* applying any controls.

3. Mitigate Risks: Implement appropriate controls to reduce the inherent risk. These include Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), transaction monitoring, staff training, and robust internal controls.

4. Determine Residual Risk: Assess the risk remaining *after* the implementation of controls. This is the institution's actual exposure.

5. Monitor & Review: The risk assessment is not a one-time event. It must be regularly reviewed and updated, especially when new products, services, geographies, or regulatory changes occur, or following significant incidents.

Thorough documentation of the risk assessment process, methodologies, and findings is crucial for demonstrating compliance to regulators.

  • AML Risk Assessment is the foundation of a risk-based approach (RBA).
  • FATF Recommendation 1 mandates countries and financial institutions to assess ML/TF risks.
  • An Enterprise-Wide Risk Assessment (EWRA) considers risks across customers, products, geographies, and delivery channels.
  • **Inherent risk** is the risk before controls; **residual risk** is the risk after controls.
  • Key risk factors include PEPs, high-risk industries, cash-intensive businesses, and sanctioned jurisdictions.
  • The risk assessment process is dynamic and requires regular review and updates.
  • Effective mitigation involves CDD, EDD, transaction monitoring, and robust internal controls.
  • Documentation of the risk assessment methodology and findings is critical for regulatory compliance.
What is the primary purpose of an AML Risk Assessment?
To identify, assess, mitigate, and monitor an institution's money laundering and terrorist financing (ML/TF) risks.
tap to reveal
Which FATF Recommendation directly relates to AML Risk Assessment?
FATF Recommendation 1.
tap to reveal
Name the four key categories of factors considered in an Enterprise-Wide Risk Assessment (EWRA).
Customers, Products/Services, Geographies, and Delivery Channels.
tap to reveal
What is the difference between "inherent risk" and "residual risk" in AML?
**Inherent risk** is the risk before applying controls; **residual risk** is the risk remaining after controls have been implemented.
tap to reveal
Give examples of customer types that typically present higher ML/TF risk.
Politically Exposed Persons (PEPs), customers in cash-intensive businesses, and those with complex ownership structures.
tap to reveal
Why is an AML Risk Assessment considered a dynamic process?
It requires regular review and updates due to changes in business activities, customer base, products, technologies, regulatory landscape, and emerging threats.
tap to reveal
What are some common mitigation controls used to reduce AML risks?
Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), transaction monitoring, staff training, and robust internal controls.
tap to reveal
What is the importance of documenting the AML Risk Assessment?
To demonstrate to regulators the institution's understanding of its risks, the methodology used, and the rationale behind its control framework.
tap to reveal

Sanctions Compliance

## Sanctions Compliance: Core Concepts

Sanctions are political and economic measures imposed by countries or international bodies to achieve foreign policy and national security objectives. They aim to deter threats to international peace and security, prevent proliferation of weapons of mass destruction (WMD), combat terrorism, protect human rights, and curb illicit financial activities. Compliance with sanctions is a critical component of an effective Anti-Money Laundering (AML) program.

## Types of Sanctions

Sanctions regimes typically fall into two main categories:

  • Comprehensive Sanctions: These are broad prohibitions on virtually all direct or indirect dealings with a particular country, region, or regime. Examples include sanctions against Cuba, Iran, North Korea, and Syria, though the scope can vary significantly by jurisdiction.
  • Targeted/Smart Sanctions: The predominant modern approach, these sanctions focus on specific individuals, entities, groups, or sectors rather than entire countries. They aim to minimize humanitarian impact while maximizing pressure on designated targets. Common measures include asset freezes, travel bans, arms embargoes, and restrictions on specific economic sectors (e.g., finance, energy).

## Key Sanctions Authorities (International Focus)

  • UN Security Council (UNSC): Imposes legally binding sanctions on all UN member states under Chapter VII of the UN Charter. These are universally recognized and implemented by national governments.
  • Office of Foreign Assets Control (OFAC): Part of the U.S. Department of the Treasury, OFAC administers and enforces U.S. economic and trade sanctions programs. Its reach is significant due to the global use of the U.S. dollar and the extraterritoriality of some U.S. sanctions, affecting non-U.S. persons and entities with a U.S. nexus.
  • European Union (EU): Implements UN sanctions and its own autonomous sanctions regimes. EU regulations are directly binding on member states, which then implement them into national law.
  • Office of Financial Sanctions Implementation (OFSI): Part of HM Treasury, OFSI is the UK's financial sanctions enforcer, implementing UN and autonomous UK sanctions regimes post-Brexit.

## Core Compliance Obligations

Financial institutions (FIs) must adopt a risk-based approach to sanctions compliance, which includes:

  • Screening: Regularly screening customers, beneficial owners, transactions, and payment messages against relevant sanctions lists (e.g., OFAC's Specially Designated Nationals and Blocked Persons (SDN) List, UN Consolidated List, EU Consolidated List, UK Sanctions List).
  • Due Diligence: Conducting enhanced due diligence on customers and transactions involving high-risk jurisdictions or entities.
  • Reporting: Promptly reporting any confirmed sanctions hits or blocked assets to the relevant sanctions authority.
  • Prohibitions: Freezing assets of designated persons/entities and prohibiting any dealings or provision of services to them.
  • Evasion Detection: Identifying attempts to circumvent sanctions, such as through the use of shell companies, third-party intermediaries, mislabeled goods, or alternative payment methods.

Non-compliance can lead to severe penalties, including substantial fines, reputational damage, criminal charges, and loss of correspondent banking relationships.

  • Sanctions are political and economic measures used to achieve foreign policy and national security objectives.
  • The UN Security Council (UNSC) imposes legally binding sanctions on all UN member states.
  • OFAC is the primary U.S. sanctions enforcer with significant extraterritorial reach.
  • Targeted sanctions are the most common type, focusing on specific individuals, entities, or sectors.
  • Financial institutions must implement a risk-based approach to sanctions compliance.
  • Key compliance obligations include screening against sanctions lists and reporting hits to authorities.
  • The SDN List is OFAC's primary list of Specially Designated Nationals and Blocked Persons.
  • Non-compliance with sanctions can result in severe financial penalties and criminal charges.
What is the primary purpose of sanctions?
To achieve foreign policy, national security, and international law objectives by deterring illicit activities and pressuring regimes or individuals.
tap to reveal
Which international body imposes legally binding sanctions on all UN member states?
The UN Security Council (UNSC).
tap to reveal
What does OFAC stand for, and what is its role?
Office of Foreign Assets Control. It's the primary U.S. agency administering and enforcing economic and trade sanctions programs.
tap to reveal
What is the key difference between comprehensive and targeted sanctions?
Comprehensive sanctions prohibit most dealings with an entire country, while targeted sanctions focus on specific individuals, entities, or sectors to minimize broader impact.
tap to reveal
What is the SDN List?
OFAC's Specially Designated Nationals and Blocked Persons List, which identifies individuals and entities with whom U.S. persons are generally prohibited from dealing.
tap to reveal
What is meant by 'extraterritoriality' in the context of U.S. sanctions?
The application of U.S. sanctions laws to non-U.S. persons and entities, particularly when dealing with U.S. currency or having a U.S. nexus.
tap to reveal
What is a core compliance obligation for financial institutions regarding sanctions?
Regularly screening customers, beneficial owners, and transactions against relevant sanctions lists.
tap to reveal
What are the potential consequences of sanctions non-compliance?
Severe financial penalties, reputational damage, criminal charges, and loss of correspondent banking relationships.
tap to reveal

Conducting and Responding to Investigations

## Conducting and Responding to Investigations

This topic covers the critical processes financial institutions (FIs) undertake when investigating potential money laundering (ML) or terrorist financing (TF) activities, and how they interact with law enforcement.

Internal Investigations

FIs conduct internal investigations to detect, prevent, and mitigate AML/CFT risks, and ensure compliance with regulations. These investigations can be triggered by various factors, including suspicious transaction reports (STRs/SARs), internal audit findings, employee tips, law enforcement inquiries, or media reports. Key steps involve:

  • Defining Scope: Clearly outlining the objectives and boundaries of the investigation.
  • Evidence Gathering: Collecting relevant documents, electronic communications, and conducting interviews while maintaining confidentiality.
  • Documentation: Meticulously recording all findings, actions taken, and decisions made.
  • Reporting: Presenting findings to senior management and the board, recommending remedial actions (e.g., policy changes, disciplinary action, enhanced monitoring).
  • External Reporting: Determining if an STR/SAR is warranted or if law enforcement should be notified.
  • Legal Counsel: Involving legal counsel is crucial, especially for complex cases, to ensure legal privilege and proper handling of evidence.

Responding to Law Enforcement Requests

FIs frequently receive requests for information from domestic and international law enforcement agencies. These can include subpoenas, search warrants, production orders, or requests under Mutual Legal Assistance Treaties (MLATs) or letters rogatory. Proper response protocols are essential:

  • Verification: Always verify the legitimacy and authority of the requesting agency and the scope of the request.
  • Compliance: Comply promptly but carefully, disclosing only the information legally required. Over-disclosure can violate privacy laws.
  • Tipping Off: Strictly avoid tipping off customers or third parties about an ongoing investigation or the filing of an STR/SAR, as this is prohibited and can obstruct justice.
  • Documentation: Keep detailed records of all requests, responses, and communications.
  • Legal Review: Involve legal counsel to review complex requests and ensure proper handling, especially concerning asset freezes or international cooperation.

International Cooperation and Information Sharing

Combating ML/TF often requires cross-border collaboration. MLATs are formal agreements between countries to provide assistance in criminal matters. Letters rogatory serve a similar purpose when no MLAT exists. Financial Intelligence Units (FIUs), often members of the Egmont Group, facilitate secure and confidential exchange of financial intelligence between jurisdictions. Challenges include differing legal systems, data privacy laws, and dual criminality requirements. Effective information sharing, both domestically (e.g., public-private partnerships) and internationally, is vital for a robust AML/CFT regime.

  • Internal investigations detect, prevent, and mitigate AML/CFT risks and ensure compliance.
  • Triggers for internal investigations include STRs/SARs, audit findings, and law enforcement inquiries.
  • When responding to law enforcement, always verify the request's legitimacy and avoid tipping off.
  • Mutual Legal Assistance Treaties (MLATs) facilitate international legal assistance in criminal matters.
  • The Egmont Group is a global network of FIUs that enables secure information exchange.
  • Documentation of all investigative steps and law enforcement interactions is crucial.
  • Legal counsel should be involved in complex investigations and responses to ensure compliance and privilege.
  • Confidentiality is paramount during internal investigations to protect integrity and individuals.
What are common triggers for an internal AML investigation?
STR/SAR filings, internal audit findings, employee tips, law enforcement inquiries, or media reports.
tap to reveal
What is the primary purpose of conducting an internal AML investigation?
To detect, prevent, and mitigate AML/CFT risks, and to ensure compliance with relevant laws and regulations.
tap to reveal
What is 'tipping off' and why is it prohibited?
Informing a customer or third party that an STR/SAR has been filed or that an investigation is underway. It is prohibited to prevent obstruction of justice and compromise investigations.
tap to reveal
What is a Mutual Legal Assistance Treaty (MLAT)?
A formal agreement between two or more countries to provide assistance in criminal investigations and prosecutions, including obtaining evidence or freezing assets.
tap to reveal
What is the Egmont Group?
A global network of Financial Intelligence Units (FIUs) that provides a platform for the secure exchange of financial intelligence to combat money laundering and terrorist financing.
tap to reveal
What steps should a financial institution take upon receiving a law enforcement request (e.g., subpoena)?
Verify its legitimacy, limit disclosure to what is legally required, document all interactions, and consult legal counsel.
tap to reveal
Why is documentation critical in both internal investigations and responses to law enforcement?
It provides an audit trail, supports findings and decisions, demonstrates compliance, and can be used as evidence in legal proceedings.
tap to reveal
What are 'letters rogatory'?
A formal request from a court in one country to a court in another country for judicial assistance, often used when an MLAT is not in place or insufficient.
tap to reveal