LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label BSA. Show all posts
Showing posts with label BSA. Show all posts

Monday, May 5, 2025

Common Red Flags in Money Laundering

QUESTION

I am the COO of a mid-sized lender in the Midwest. We have contacted your firm to do an Anti-Money Laundering Risk Assessment. One of the big issues we have is trying to identify the most common red flags. 

In streamlining our system AML reporting, we are using AI to determine common red flags. Unfortunately, AI is not able to provide real-world data. We need practical experience, which is why I would like you to let me know the kinds of common red flags you find in your audits. 

What are the common red flags for money laundering in mortgage banking? 

SOLUTIONS 

RESPONSE 

Since 2003, FinCEN has issued a number of analyses, reports, and advisories regarding emerging trends in mortgage fraud, money laundering, and terrorist financing activity involving residential mortgage loans. 

While FinCEN publishes a list of potential red flags, we often find that our list of activities that could trigger the filing of Suspicious Activity Reports continues to expand. At this point, we have hundreds of such findings. 

Thank you for retaining us to provide the AML Risk Assessment. 

Lenders Compliance Group was the first compliance firm in the country to provide AML audit tests to non-bank residential mortgage lenders and originators. Of course, we have also offered AML audits to banks involved in residential mortgage banking for many years. 

So, by this point, we have rock-solid indicia and identifiers that help us review for AML compliance. There are many common red flags. I am going to provide a half-dozen of them that keep turning up in our audits with the proviso that the list is not comprehensive. 

Activities considered red flags in mortgage banking include: 

(1) A loan secured by pledged assets held by a third party unrelated to the borrower. 

(2) A loan secured by deposits or other readily marketable assets, such as securities, when owned by apparently unrelated third parties. 

(3) A borrower default on a case-secured loan or any loan that is secured by assets that are readily convertible into currency. 

(4) A loan made for, or paid on behalf of, a third party with no reasonable explanation. 

(5) A customer, to secure a loan, purchases a certificate of deposit using an unknown source of funds, particularly when funds are provided via currency or multiple monetary instruments. 

(6) A loan that lacks a legitimate business purpose, provides the depository institution with significant fees for assuming little or no risk, or tends to obscure the movement of funds (i.e., loans made to a borrower and immediately sold to an entity related to the borrower). 

It is important to ensure that your system solution requires the reporting of any activity that is suspected of violating a criminal statute. Additionally, the federal money laundering criminal statutes consider money laundering to be the handling of the proceeds of criminal activity, with mortgage fraud considered to be a predicate offense for the money laundering criminal statutes. Mortgage-related criminal activity is a specific predicate offense. 


Jonathan Foxx PhD., MBA
Chairman & Managing Director
Lenders Compliance Group

Thursday, May 9, 2024

Online Data Collection Challenge

QUESTION 

Most of our business is from originating mortgages. Recently, we started originating Buy-Now-Pay-Later loans. I know you specialize in mortgage banking. And these are not mortgage loans. However, they are available online just like we offer our mortgages online. 

Our attorney told us that getting a customer's social security number for online Buy-Now-Pay-Later loans poses consumer privacy and information security risks. She says we could collect partial SSN information directly from the customer and then use a third party source to obtain the full SSN before opening the account. 

This is not a practical solution. As the sales manager, I am trying to find some kind of workaround. We need the SSN when the loan comes in online. Processing begins immediately and includes our CIP filters. However, if we use a third party to handle the BSA requirement, there could be a processing delay. 

Hopefully, you can shed some light on how to resolve this situation. Our attorney reads your articles and often sends them to us. So, I'm sure she will read your view on getting online SSN information. 

Can you explain why our attorney is concerned about our online CIP data collection involving Buy-Now-Pay-Later loans? 

COMPLIANCE SOLUTION 

Website Compliance Review 

Policies and Procedures

ANSWER 

Since 2006, Lenders Compliance Group has offered mortgage banking compliance. We do not provide compliance guidance for Buy-Now-Pay-Later (BNPL) loans. The BNPL loan is an installment loan that typically allows a customer to purchase something immediately with little or no initial payment and pay off the balance over four or fewer payments.[i] 

I will answer your question because you have an online origination platform that is used to originate mortgage loan products, where you have now introduced the origination of BNPL loans. 

You do not state if your company is contemplating partnering with a nonbank third party service provider to facilitate BNPL loan originations. 

Read on to find out why that information is a critical compliance element. 

I think there are more reasons for your attorney's directive than is described in your question. Given that you are marketing mortgage and non-mortgage products online, the online platform should be evaluated for its overall compliance with CIP requirements, among other things. Depending on the online consumer disclosures, product and service array, origination technology, and other factors, I think her concern is warranted. 

Please ask your attorney to contact me here. We'll discuss and resolve the situation. 

Your question comes as FinCEN is evaluating, via a Request for Information (RFI), existing requirements for banks under the Customer Identification Program Rule ("CIP Rule") to collect a taxpayer identification number (TIN) from a customer before opening an account. I'll provide a bird's-eye view of the anticipated plans, which may be responsive to your attorney's concerns. 

Generally, banks and nonbanks ("financial institution(s)" or "institution(s)") must collect a full Social Security Number (SSN) from a customer who is an individual and a U.S. person. The RFI, mentioned above, is being issued in consultation with staff at the OCC, FDIC, NCUA, and the Federal Reserve System (collectively, the "Agencies"). 

FinCEN is looking for feedback to understand the potential risks, benefits, and safeguards that could be established if financial institutions were permitted to collect partial SSN information directly from the customer for U.S. individuals and subsequently use reputable third party sources to obtain the full SSN before account opening. So, FinCEN's inquiry seems to align with your attorney's suggestion. Agencies usually issue an RFI because they want certain information to evaluate practices and, in this case, a better understanding of current industry practices and perspectives related to the CIP Rule's TIN collection requirement. So, their inquiry is based on wanting to assess the potential risks and benefits associated with a change to that requirement. 

From the start of anti-money laundering compliance, financial institutions have collected identifying information from a customer before opening an account. FinCEN, in consultation with staff at the Agencies, seeks information and comments from interested parties regarding the CIP Rule requirement for financial institutions to collect a taxpayer identification number (TIN) and other information from a customer who is a U.S. person before opening an account. 

There are minimum standards[ii] for such information collection, including, among other things, reasonable procedures[iii] for 

(1) verifying the identity of any person seeking to open an account to the extent reasonable and practicable; and 

(2) maintaining records of the information used to verify a person's identity, including name, address, and other identifying information.  

It is, therefore, a given that, to satisfy the CIP Rule's TIN collection requirement for a U.S. individual, a financial institution must collect the full SSN from the customer before opening an account. While an institution's procedures for verifying a customer's identity may be risk-based and may vary among institutions, the CIP Rule makes clear that the collection of certain identifying information is a minimum requirement, and such information must be collected directly from the customer before opening an account, except concerning credit card accounts. 

That said, the CIP Rule generally does not allow a financial institution to collect an individual's SSN from a person other than the customer (i.e., a third party service provider). 

When the CIP Rule was adopted, institutions were exempted from the requirement for credit card accounts to collect identifying information directly from the customer, including an identification number. Rather, financial institutions may collect the customer's identifying information, such as the SSN, for credit card accounts, from a third party source before extending credit to the customer. The agency saw at that time that without this exception, the CIP Rule would change an institution's business practices by mandating information beyond what was already obtained directly from a customer who opened a credit card account at the point of sale or by phone. 

Concerns were raised during the proposed CIP Rule's comment period that, for instance, a person applying for a credit card account would be hesitant to provide their SSN, especially through non-face-to-face means, because of consumer privacy and security concerns. 

It seems clear that FinCEN saw requiring a bank to collect a customer's identifying information from the customer in every case, including over the phone, would likely alter how they do business. Consequently, credit card accounts were exempted from the CIP Rule's information collection requirements, allowing banks and nonbanks to obtain, for these purposes, a customer's identifying information from a third party source, such as a credit bureau, before an extension of credit. In its issuances, FinCEN considered this practice an efficient and effective means of extending credit with little risk that an institution did not know the borrower's identity. 

Since the CIP Rule was adopted in 2003, FinCEN has become aware that there has been significant innovation in how customers interact with financial institutions and receive financial services, and in CIP data collection and verification tools available to financial institutions. 

So, here's the crux of the matter: some banks partner with nonbank third party service providers to facilitate new financial products and services. A Buy-Now-Pay-Later loan product is an example of a nonbank financial institution, a third party service provider, that enables such financial products and services by extending credit to customers at the point of sale. 

These products and services operate in a similar manner to credit cards but may be offered by nonbank financial institutions that may or may not be subject to the Bank Secrecy Act (BSA) and its implementing regulations or other comparable regulatory requirements.[iv] Even so, institutions that do not comply with the CIP Rule may face supervisory action, particularly if a nonbank with which a bank has partnered does not collect the customer's identifying information directly from the customer, as required by the CIP Rule. 

The RFI[v] will presumably inform FinCEN's understanding in this area and help the agency evaluate the risks, benefits, and potential safeguards related to certain CIP Rule requirements applicable to financial institutions. Specifically, FinCEN is seeking input from institutions and other interested parties regarding the Rule's SSN collection requirement. The results may allow financial institutions to collect partial SSN information from the customer and use a third party source to collect the full SSN. Partial SSN collection is when a bank collects a certain part of the SSN from individuals who are customers (i.e., the last four digits of an individual's SSN) and then obtains the full SSN from a reputable third party service provider. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] What is a Buy Now, Pay Later (BNPL) Loan?, Consumer Financial Protection Bureau, Issuance (Last Reviewed: December 2, 2021), https://www.consumerfinance.gov/ask-cfpb/what-is-a-buy-now-pay-later-bnpl-loan-en-2119/ 

[ii] Section 326 of the USA Patriot Act amended the BSA to require, inter alia, the Secretary to prescribe regulations "setting forth the minimum standards for financial institutions and their customers regarding the identity of the customer that shall apply in connection with the opening of an account at a financial institution." 

[iii] 13 CFR Part 103, Financial Crimes Enforcement Network; Customer Identification Programs for Certain Banks (Credit Unions, Private Banks and Trust Companies, That do not Have a Federal Functional Regulator, Department of the Treasury

[iv] An example of a nonbank financial institution that is a third-party service provider used to facilitate new financial products and services would be one that provides BNPL loans that extend credit at the point of sale to customers.

[v] The RFI supports FinCEN's ongoing efforts to implement Section 6216 of the Anti-Money Laundering Act of 2020, which requires the agency to, inter alia, identify regulations and guidance that may be outdated, redundant, or otherwise do not promote risk-based AML’s requirements for CFT, the acronym for combating the financing of terrorism.

Thursday, February 1, 2024

Identity-Related Suspicious Activity

QUESTION 

We are a large mortgage lender in the West. A hedge fund owns us. Recently, the hedge fund came down hard on our compliance department for allowing the originating of loans that our AML process should have screened out. They were up in arms because our state regulator issued an administrative action against us. 

We didn't file some SARs that were identity-related, but we did document why the SARS were not filed. That didn't satisfy the regulator because they said we did not follow our own AML program guidelines. We may now lose our Safe Harbor because we didn't file the SARs by following our own policy. 

There are other issues, but the biggest one involves not screening for identity-related suspicious activity. That's the regulator's term: "identity-related suspicious activity." 

The auditor we hired to do our annual AML test was fired. Now, to comply with the regulator, we have to find an auditor who will work with us to review the last 36 months to determine if we should have filed more identity-related SARs. This is a massive undertaking. I am one of several operations persons drafted into the compliance department to assist. I want to know more, and I hope you will give us some feedback. 

What is identity-related suspicious activity? 

ANSWER 

We provide Anti-Money Laundering (AML) testing and training. We were the first compliance firm in the country to offer testing, training, and a written AML Program. Also, we handle large AML due diligence projects such as the one you've described. If you want information about our AML compliance support, contact us here. 

For years, the Financial Crimes Enforcement Network (FinCEN) has issued trend analyses showing that identity-related suspicious activity is a huge percentage of filings. For instance, in 2021, approximately 1.6 million SARs (42% of the SARs filed that year) related to identity, which was $212 billion in suspicious activity. 

Just a few weeks ago, FinCEN published its findings as part of its ongoing Identity Project ("Report").[i] The Report outlines how bad actors exploit identity-related processes in processing transactions as well as opening and accessing accounts. 

I will provide a cursory overview of the Report and then move on to an answer to your question. 

TYPOLOGIES 

The Report discusses the existence of significant identity-related exploitations through various schemes. FinCEN identified over fourteen "typologies" commonly indicated in identity-related SARs. 

The most frequently reported were 

(1) fraud,

(2) false records,

(3) identity theft,

(4) third-party money laundering, and

(5) circumvention of verification standards. 

These top five typologies accounted for 88% of identity-related SARs and 74% of the total suspicious activity reported in 2021. 

TRENDS 

Trends found in the BSA reporting include: 

·       Although identity-related suspicious activity impacted all types of financial institutions, depository institutions filed the most identity-related BSA reports, which was about 54% of all identity-related filings. 

·       The impact of identity-related exploitations by BSA report volumes and cited U.S. dollar values are significant. Attackers most frequently use impersonation tactics, followed by compromise during authentication, and then circumvent verification to evade detection. Compromised credentials have a disproportionally large monetary impact compared to impersonation and circumvention. 

·       The Report found that compromised credentials have a disproportionate financial impact compared to other types of identity exploitation. 

SAFE HARBOR 

I will not comment on your company's exposure to losing the Safe Harbor except to point out that the Safe Harbor provision of the Bank Secrecy Act (BSA)[ii], among other things, shields financial institutions, their officers, and employees from civil liability for reporting known or suspected criminal offenses or suspicious activity by filing a SAR. From your question, I can't tell who told you that your company may lose the Safe Harbor. 

The Safe Harbor provides immunity to any "financial institution that makes a voluntary disclosure of any possible violation of law or regulation to a government agency." This protection precludes liability under any federal, state, or local law, or regulation, or under any contract. Nevertheless, courts have disagreed about the scope of the protection it affords. You should be working with competent counsel in responding to the regulatory agency. 

SCREENING PROCEDURES 

It seems to me that your screening procedures failed to identify identity-related suspicious activity. You state that the regulator alleges you did not follow your own AML program procedures. That infers that you have procedures in a ratified AML Program that were not implemented. 

There are three stages to a systemic framework that mitigates identity-related suspicious activity.[iii] These stages are: (1) Validation; (2) Verification; and (3) Authentication. I do not think this framework is failsafe, but it is quite comprehensive. Nonetheless, in the age of Artificial Intelligence, we can expect updates to these stages. 

The following is a brief outline of each stage. 

Validation 

The validation stage begins when a customer presents identity attributes and supporting evidence (i.e., birth certificate, passport, driver's license, and so forth) – in person or remotely – for review by a financial institution. The financial institution then attempts to determine:

a)     Whether the presented identity exists (i.e., whether it is tied to a real-life identity);

b)     Whether the presented identity is unique (i.e., whether it is claimed by only one entity);

c)     Whether the presented information and evidence are authentic and accurate. 

Generally, the financial institution makes these determinations by comparing the presented information and evidence against authoritative government data, such as public records and Social Security Administration data, or third-party data sources, such as credit reporting agency, utility, and employer data (i.e., independent and reliable data sources). 

Verification 

In the verification stage, the financial institution confirms that the previously validated identity evidence belongs to the customer. The financial institution may, for instance, match the customer's appearance in person (or virtually) via photo or video to a photo on the customer's driver's license, passport, or other photo identification. 

Verification tools and techniques can rely on humans or be entirely automated. These tools may also use biometrics like facial recognition and "liveness" detection or verify documents and attributes to determine a match. This process may also use various other technical and risk data from third parties. 

Authentication 

In the authentication stage, a financial institution assesses whether the customer is who they purport to be based on the customer's possession and control of valid "authenticators." Financial institutions may also engage in other activities involving transactions, such as verifying counterparties and other transaction monitoring. 

Authentication is supposed to provide "risk-based" assurance that the customer is the same customer whose identity was validated and verified during previous steps of the identity process. 

The authentication process can occur in person or remotely, be manual or digital, rely on humans or machines, and is considered more robust when it depends on multiple authentication factors (i.e., multifactor authentication). 

Common authentication factors include: 

a)     Ownership of something the customer has (i.e., a badge, phone, or cryptographic key);

b)     Knowledge of something the customer knows (i.e., a password, passphrase, or PIN);

c)     Inherent or something the customer is (i.e., a fingerprint or other biometric data).

Thursday, January 25, 2024

Filing the Suspicious Activity Report

QUESTION 

Recently, we had training in our anti-money laundering program. I have to say, it wasn't very good. We went to our compliance officer to request another training because the trainer kept skirting our questions. He listened to the recording and agreed with us. So, now he's looking for a new trainer for the anti-money laundering training.

In the meantime, we still don't have clear answers to several questions. We want to know more about SAR filings, like when they're required and the timing to file. My teammate wants to see if we can discuss the filing of a SAR with the person we're reporting on. You would think these are obvious questions, but our trainer did not know the answers! So, we hope you can provide answers for us. By the way, we love your weekly newsletter! 

When is a SAR required? 

Can we question the individual we're reporting the SAR on? 

What goes into SAR decision-making? 

What is the timing to file the SAR? 

ANSWER 

Thank you for your kind words. We are grateful! 

We provide Anti-Money Laundering (AML) testing and training. In fact, we were the first compliance firm in the country to offer testing, training, and a highly esteemed, written AML Program. If you want information about our AML compliance support, contact us here. 

Because money is the basis for criminal activity or, in the case of terrorism, is an integral part of the activity, the United States government has prioritized pursuing the funds generated or used in these activities. Since financial institutions occupy a critical position in the U. S. financial system, the government not only requires financial institutions to report information, it requires them to be proactive in looking for transactions that may be part of a criminal activity. 

In particular, this responsibility takes the form of the Suspicious Activity Report (SAR). This report is required as part of the Bank Secrecy Act (BSA).[i] The banking regulatory agencies and the NCUA have adopted identical regulations to implement this requirement.[ii] 

The law and regulations make it clear that an effective BSA compliance program includes controls and measures to identify and report suspicious transactions in a timely manner. A financial institution must apply due diligence to make an informed decision about the suspicious nature of a particular transaction and whether to file a suspicious SAR. 

I will provide some guidelines to consider in response to your questions. The applicable statutes are quite complicated, and there's plenty of case law. However, I think a general answer is certainly important for you to consider. 

I will take your questions in order. 

When is a SAR required? 

The SAR is the primary method by which financial institutions are to report suspected criminal activity. However, it is not the only means. There are instances requiring more immediate attention, such as when a reportable violation occurs, the financial institution must immediately notify, by telephone, appropriate law enforcement and financial institution supervisory authorities. 

One area that is not specifically addressed in the regulation but – which has become extremely important since September 11, 2001 – is terrorism. To facilitate the reporting of suspected terrorist activities, the Financial Crimes Enforcement Network (FinCEN) established a Financial Institutions Hotline, (866) 556-3974, for financial institutions to voluntarily report to law enforcement suspicious transactions that may relate to terrorist activity against the United States. This hotline is operational seven days a week, 24 hours a day. 

However, financial institutions must be aware that contacting law enforcement directly, whether about terrorism or anything else, does not eliminate the need to file a SAR. A SAR must be filed when required, even if law enforcement was contacted by telephone. 

The agencies' SAR regulations mandate that a SAR must be filed for: 

·       Insider abuse involving any amount. 

·       Violations of federal law aggregating $5,000 or more when a suspect can be identified. 

·       Violations of federal law aggregate $25,000 or more regardless of a potential suspect. 

·       Transactions aggregating $5,000 or more that involve potential money laundering or violations of the BSA if the institution knows, suspects, or has reason to suspect that the transaction: 

o   Involves funds from illegal activities or is intended or conducted to hide or disguise illicit funds or assets as part of a plan to violate or evade any law or regulation or to avoid any transaction reporting requirement under federal law; 

o   Is designed to evade any of the BSA regulations; or 

o   Has no business or apparent lawful purpose or is not the sort in which the particular customer would normally be expected to engage, and the institution knows of no reasonable explanation for the transaction after examining the available facts, including the background and possible purpose of the transaction. 

Can we question the individual we're reporting the SAR on? 

Questioning individuals about potentially suspicious activity requires considerable discretion. When determining suspicious activity, institutions are responsible for "examining all the facts, including the background and possible purpose of the transaction." 

Thus, as part of an institution's due diligence to determine whether suspicious activity has occurred, a reasonable investigation into the nature and purpose of the activity may be necessary. Institutions have expressed concern over the perceived tension between questioning a customer about potentially suspicious activity and the institution's responsibility to maintain the confidentiality of SARs. 

FinCEN recognizes that under certain circumstances, institutions may discreetly question a customer about the nature and purpose of a transaction without revealing their intention to file a SAR. For example, to determine whether a customer's transactions are "designed to evade any [reporting] requirements," an institution may wish to ask a customer why they are making frequent cash deposits slightly below a certain reporting or recordkeeping threshold. If the customer provides an answer that reasonably satisfies the institution that the transaction is not designed to evade reporting requirements (i.e., their business has a verifiable insurance policy that covers up to $10,000 in currency in the event of a burglary), no SAR would be required. 

However, it is important to keep in mind that any questioning should not risk "tipping off" the customer or otherwise disclose that a SAR is being filed. In short, institutions will need to exercise discretion and judgment when determining how and when to inquire of customers about unusual activity. 

What goes into SAR decision-making? 

Our auditors and reviewers get this question often. Sometimes, many variables and nuances go into deciding to file a SAR. The financial institution should have policies, procedures, and processes for referring unusual activity from all business lines to the personnel or department responsible for evaluating unusual activity. The process should effectively evaluate all applicable information (i.e., criminal subpoenas, NSLs, or section 314(a) requests). 

You should document SAR decisions, including final decisions not to file a SAR. Thorough documentation provides an essential record of the SAR decision-making process (viz., what determines whether or not a SAR would be filed). The decision to file a SAR is an inherently subjective judgment. 

Examiners usually focus on whether the institution has an effective SAR decision-making process, not individual SAR decisions. Examiners also may review individual SAR decisions to test the effectiveness of the SAR monitoring, reporting, and decision-making process. If the financial institution has an established SAR decision-making process, followed existing policies, procedures, and processes, and determined not to file a SAR, it should not be criticized for failing to file the SAR unless the failure is significant or accompanied by evidence of bad faith. 

What is the timing to file the SAR? 

A financial institution must file a SAR within 30 calendar days after the date of the initial detection of facts that may constitute a basis for filing a SAR. If no suspect was identified on the date of detection of the incident requiring the filing, the financial institution could delay filing a SAR for an additional 30 calendar days to identify a suspect. However, that is the maximum length of time the institution can delay the reporting. In no case can the reporting be delayed more than 60 calendar days after the date of initial detection of a reportable transaction. If no suspect can be identified by the end of the 60 days, a SAR must be filed without the identity information. 

The phrase "initial detection" should not be interpreted as meaning the moment a transaction is highlighted for review. Various legitimate transactions could raise a red flag simply because they are inconsistent with an account holder's normal account activity. For instance, a real estate investment (purchase or sale), the receipt of an inheritance, or a gift may cause an account to have a significant credit or debit inconsistent with typical account activity. The institution's automated account monitoring system or initial discovery of information, such as system-generated reports, may flag the transaction; however, this should not be considered initial detection of potential suspicious activity. 

The 30-day (or 60-day) period does not begin until an appropriate review is conducted and a determination is made that the transaction under review is "suspicious" within the meaning of the SAR regulations. 

You should promptly initiate a review upon identifying unusual activity that warrants investigation. The timeframe required for completing the review of the identified activity, however, may vary given the situation but should be completed in a reasonable period of time. 

Naturally, you’ll want to know what constitutes a reasonable period of time. The timeframe will vary according to the facts and circumstances of the particular matter being reviewed and the effectiveness of each institution's SAR monitoring, reporting, and decision-making process. The key factor is that an institution has established adequate procedures for reviewing and assessing facts and circumstances identified as potentially suspicious and that those procedures are documented and followed. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] 31 USC § 5318(g)

[ii] The regulations can be found at: OCC (national banks; federal savings associations): 12 CFR 21, 12 CFR 163.180; Federal Reserve (state member banks): 12 CFR 208.62; FDIC (state nonmember banks and savings banks; state savings associations) 12 CFR 353, 12 CFR 390.355; NCUA (credit unions) 12 CFR 748.1(c).

Thursday, October 19, 2023

AML Examinations: Common Audit Findings

QUESTION 

We are a credit union with several branches. Our concern is that we don't believe we have a comprehensive training program for BSA/AML. We are going to have a regulatory examination soon, and I think we will be written up for having an incomplete training program and aids. But that's just one of the weaknesses. 

We need some direction here. First, our compliance manager is contacting your firm to review our written AML program. Second, we need to know the areas of weakness that regulators often find in our AML program. 

What are some areas of weakness we can anticipate being reviewed in an AML examination? 

ANSWER 

If you expect the AML examination soon, you and other subscribers can contact us here

We have conducted hundreds of AML risk assessments over the years, and the findings regarding BSA/AML vary depending on the financial institution's risk profile, size, complexity, and products and services. Still, there is a common grouping of weaknesses that tend to recur. 

Before listing the more salient, I urge you to segment your responsibility matrix for those personnel involved in the Anti-Money Laundering review process. Regulators take a keen interest in evaluating whether an institution properly allocates responsibilities and authorities along the chain of command in reviewing AML data. 

Segmenting the specific responsibilities will make the written AML program easier to execute. Importantly, the regulators will be able to determine that your institution is complying in a procedurally reliable way. 

I will segment the responsibilities into four groups: (1) Frontline Staff, (2) Operations Staff, (3) Board of Directors, and (4) New Personnel. Now, consider the following brief description of each. You can take these responsibilities as a "starting point." I suggest you broaden them to reflect your institution's normative information paths.

Frontline Staff 

Responsibilities 

  • CTR reporting requirements,
  • Recognizing suspicious activity,
  • Completing a SAR,
  • Customer Identification Program due diligence, and
  • Office of Foreign Assets Control (OFAC) requirements (if applicable). 

Operations Staff 

Responsibilities 

  • Wire transfers,
  • ACH Transactions,
  • Debit, Credit, Gift Card Transactions
  • Recognizing and reporting suspicious activity related to applicable financial products and services, and
  • OFAC requirements (if applicable). 

Board of Directors

Responsibilities 

  • Methods to enhance the importance of BSA/AML requirements,
  • Consequences and risks of noncompliance, and
  • Changes and new developments in the BSA laws and regulations. 

New Personnel 

Responsibilities

  • Orientation for BSA/AML overview, 
  • Jobs requiring performance of BSA/AML and/or OFAC duties must receive thorough training prior to starting the position.

There are eight recurring weaknesses we have found through our AML risk assessments. I will list them here, with the caveat that they are by no means meant to be comprehensive. Also, keep in mind our AML test audits and risk assessments are focused on residential mortgage loan originations and servicing compliance. 

My advice is for you to review your written AML program to ensure you cover these areas with respect to policies, descriptions, and procedures. And be sure to test them! 

Some Commonly Recurring Weaknesses 

in 

Anti-Money Laundering Programs

  • Customer ID Program requirements.
  • Timely 314(a) reviews and CTR reports.
  • Independent audits must address all the issues they identify.
  • BSA policies should note both the BSA/AML officer and the backup BSA/AML officer.
  • Risk assessments must consider all new products and services.
  • Confidentiality of all SARs must be maintained at all levels of the institution.
  • BSA training is kept current and available; examiners scrutinize training records and materials.
  • Customize the BSA/AML training program to employees' specific responsibilities. 

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Thursday, September 14, 2023

Pig Butchering

QUESTION 

We have a problem with a particular loan. Out of an abundance of caution, we filed a SAR on it. But we are not sure if we should have filed one. 

Our concern began when we found that our customer was involved in unusual account activity, Even though she always maintained high balances. When our manager asked her why there were sudden increases in activity, she said that she was involved in converting her money to virtual currency. 

Since it did not appear her account activity was without an economic purpose nor used for criminal activity, we took no action. But then she applied for a HELOC, and alarm bells went off in our compliance department. We found she used the proceeds to wire her funds to a virtual provider to buy virtual currency. 

At this point, we filed the SAR. FinCEN contacted us, and they are now investigating. I have never seen anything like this and wonder if you can tell us what is happening. Thank you for your awesome weekly newsletter. 

Why are home equity proceeds causing a red flag when used to buy virtual currency?

COMPLIANCE SOLUTION

Anti-Money Laundering Test and Training 

ANSWER 

Your question is the first we’ve received from our readership that describes an insidious scam that takes a wrecking ball to an individual’s financial stability. The Financial Crimes Enforcement Network (FinCEN) has known about this scam for some time, but the problem is growing quickly. This con is one of the many cryptocurrency investment scams. 

Perhaps you have not heard the term before, but this type of scam operates by fraudsters gaining the confidence of their victims before eventually enticing them to invest in fraudulent virtual currency trading platforms. 

The scam has a rather gruesome term: Pig Butchering. 

This grisly term comes from a Chinese term[i] that translates to pig butchering. The pig butchering confidence game originated in Southeast Asia and has spread globally. ProPublica published a detailed article last year about this scam and how it works.[ii] There has been considerable media attention to pig butchering and regulatory interest in this scam, including, most recently, a FinCEN alert.[iii] 

Update your AML Program with guidelines for staying notified of SAR compliance. You should conduct an AML Test and AML Training annually to ensure that you comply with all BSA’s Anti-Money Laundering Program requirements. For information and scheduling, please contact us here. 

These scams are called “pig butchering” because they resemble the practice of fattening a hog before slaughter. Victims in this situation are referred to as “pigs” by the scammers who leverage fictitious identities, the guise of potential relationships, and elaborate storylines to “fatten up” the victim into believing they are in trusted partnerships. The scammers then refer to “butchering” or “slaughtering” the victim after their assets are stolen, causing financial and emotional harm to the victim. 

In many cases, the “butchering” phase involves convincing victims to invest in virtual currency or, in some cases, over-the-counter foreign exchange schemes. But scammers go beyond virtual currency into other modalities, such as electronic funds transfers, foreign currency and dollar-denominated Forex gold contracts, as well as wire transfers – as was the case with your customer. 

The goal is to defraud the victims of their investment. Indeed, U.S. law enforcement agencies estimate victims in the United States have lost billions of dollars to these scams and other virtual currency investment frauds.[iv] In fact, in 2022, investment fraud, as a general category, caused the highest losses of any scam reported by the public to the FBI, totaling $3.31 billion. Fraud involving cryptocurrency, including pig butchering, represented the majority of these scams and increased 183% from $907 million in 2021 to $2.57 billion in reported losses in 2022.[v] 

SAR COMPLIANCE 

Your customer may be a victim of a Pig Butchering scam. You acted appropriately by filing a Suspicious Activity Report (SAR). In the future, when you file the SAR, the narrative should include the key term “FIN-2023- PIGBUTCHERING” and select “Fraud-Other” under SAR field 34(z) with the description “Pig Butchering.”[vi] 

PIG BUTCHERING 

There are four parts to the Pig Butchering scam: Initial Contact, Sales Pitch, Promising Huge Profits, and Point of No Return.   

Initial Contact 

A scammer typically makes initial contact with a potential victim through text messages, instant messaging, professional networking sites, social media, dating sites, or other communication tools and platforms. A common ruse is to contact a victim under the guise of accidentally reaching the wrong number or trying to re-establish a connection with an old friend.[vii] The scammer, who may claim to be an investor or money manager, may also create a social media profile that showcases wealth and an enviable lifestyle. Once the scammer elicits a response from a victim, the scammer will communicate with them over time to establish trust and build a relationship.[viii] 

Sales Pitch 

Once trust or a relationship is established, the scammer introduces the victim to a supposedly lucrative investment opportunity in virtual currency, directing them to use virtual currency investment websites or applications designed to appear legitimate[ix] – but which are fraudulent and ultimately controlled or manipulated by the scammer. Legitimate applications with third-party plugins allow the scammer to manipulate or falsify information presented to the victim.[x] 

According to the FBI, many victims also report being directed to make wire transfers to overseas accounts or purchase large amounts of prepaid cards to buy virtual currency. Wire transfers appear to be the method used by your scammed customer. 

Once the victim acquires the virtual currency, the scammer directs them to “invest” the funds through the bogus investment websites or applications. However, the funds are funneled to virtual currency addresses and accounts controlled by scammers and their co-conspirators. 

Occasionally, scammers leverage high-pressure sales tactics such as telling their victims that they will lose out on the opportunity if they do not invest by a certain deadline.[xi]  A scammer may also encourage the victim to bring their friends and family to invest in the scheme.[xii] 

Promising Huge Profits 

At this point, the victim has been snookered. They have invested in the scam, and the scammer shows them incredible returns on their investment. All those returns, of course, are fabricated. To convince the victim of the authenticity of their investment, the scammer may even allow the victim to withdraw a small amount of that investment to further build the victim’s confidence before urging the victim to invest more. Victims have been known to liquidate holdings in tax-advantaged accounts or take out home equity lines of credit (HELOCs) and second mortgages on their homes to increase their investments. And that seems to have happened to your customer! 

Point of No Return 

If a victim slows or stops investing, the scammer uses aggressive tactics to extract final payments. For instance, the scammer may present the victim with supposed losses on the investment and ask them to make up the difference through additional deposits. But if the victim attempts to withdraw their investment, the scammer demands that the victim pay purported taxes or early withdrawal fees. Inevitably, once the victim cannot pay more into the scam, the scammer abruptly ceases communication, making off with the victim’s entire investment. 

RED FLAGS 

FinCEN compiled three types of red flags relating to pig butchering: behavioral, financial, and technical, consisting of a total of fifteen indicators. Lenders Compliance Group has a checklist for these red flag indicators. Please contact us here if you would like a copy of the Red Flags Indicators.


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] “Sha Zhu Pan” is the Chinese term that loosely translates to pig butchering.

[ii] What’s a Pig Butchering Scam? Here’s How to Avoid Falling Victim to One, by Podkul, Cezary, September 19, 2022, ProPublica

[iii] FinCEN Alert on Prevalent Virtual Currency Investment Scam Commonly Known as “Pig Butchering”, FIN-2023-Alert005, September 8, 2023, Financial Crimes Enforcement Network

[iv] See The FBI Warns of a Spike in Cryptocurrency Investment Schemes, Public Safety Announcement, Alert I-031423-PSA, March 14, 2023, FBI

[v] See 2022 Internet Crime Report, FBI, March 9, 2023, at p. 12.

[vi] Idem

[vii] See Cryptocurrency Investment Schemes, Public Service Announcements, Alert I-100322-PSA, October 3, 2022, FBI

[viii] Idem

[ix] The term for this is “spoofing.” The term “spoofed” refers to a cyberattack in which fraudsters or hackers seek to persuade individuals that a web address or email belongs to a legitimate and generally trusted company, when in fact it links the user to a false site controlled by a cybercriminal.

[x] A scammer may also request remote access to the victim’s devices to register accounts with virtual currency service providers (i.e., virtual asset service providers, or VASPs) on the victim’s behalf. The scammer may also instruct their victims to take screenshots of their device so that the scammer can direct them through the process of purchasing virtual currency.

[xi] See Scammers Defaud Victims of Millions of Dollars in New Trend in Romance Scams, Public Service Announcement, Alert I-091621-PSA, September 16, 2021, FBI

[xii] See Criminals Steal Cryptocurrency through Play-to-Earn Games, Public Service Announcement, Alert I-030923-PSA March 9, 2023, FBI. The scammer may also invite the victim to join online or mobile games, advertised as “play-to-earn” games offering financial incentives to players, but which in reality are fake gaming applications created by the scammer to steal virtual currency from players.

Thursday, July 13, 2023

AML Compliance: Violations Bait and Land Mines

QUESTION 

I am updating our Anti-Money Laundering Program. It was last updated three years ago. We had an AML test last year, and the report showed problems with the written program, yet we did not update it even then. This delay has happened because of staff turnover. 

My concern is what areas I should emphasize in this new update. I would like to know what kinds of issues and challenges are critical, so I can identify them in the program and provide procedures for resolving them. Since your firm is known for conducting AML tests for mortgage companies, I thought you would list important AML issues. 

What challenges do you see occurring in your AML audit tests? 

ANSWER 

If you do not review your Anti-Money Laundering Program (Program) for updates, as needed, and at least annually, you are not complying with Bank Secrecy Act (BSA) guidelines. You are violating the applicable statute if you are not conducting an Anti-Money Laundering (AML) test annually but no later than eighteen months from the previous test. 

If you are not implementing AML training annually, including, when needed, for new hires, you have caused a statutory violation. 

And, if you do not have a responsible, designated, and ratified AML Officer, you have not complied with the BSA mandates. 

The Program is the written structure on which the four pillars of AML compliance rest. Those pillars are (1) ratifying the Program itself, (2) establishing an AML Officer, (3) conducting the AML test, and (4) implementing AML training. 

Lenders Compliance Group was the first compliance firm in the country to provide AML audit tests for Residential Mortgage Lenders and Originators (RMLOs), the specific term used in the BSA. RMLOs were required to develop and implement a Program and begin filing Suspicious Activity Reports (SARs) by August 13, 2012. If you want LCG to conduct an AML test or provide other AML Compliance support, please contact us. 

The test may be conducted internally, following FinCEN guidelines, or by an external auditor entirely independent of the AML Officer. If the findings report recommends that you go further by conducting an AML Risk Assessment, do it. 

In using the term RMLOs, I am referring to two types of entities that are considered loan or finance companies: the mortgage lender, the entity that is explicitly stated in the note as being the initial payee in connection with a mortgage transaction, and the mortgage originator, the party that accepts a mortgage loan application or offers or negotiates the terms of a residential mortgage loan. 

Each RMLO must adopt a policy and procedure for AML compliance in recognition of its obligations under BSA, other related money laundering regulations, the Financial Crimes Enforcement Network requirements, and federal and state licensing agencies. 

That you are not revising policies and procedures pursuant to a competent AML test may put your firm at considerable regulatory risk. The audit results must be reported to the audit committee of the RMLO's management and the BSA/AML Officer. It is the responsibility of the AML Officer to take appropriate action to correct any problems found as a result of the audit and promptly respond to the RMLO's audit committee or appropriate senior management. 

Crooks and bandits continue changing tactics, and your organization must adjust your AML program accordingly. Several "land mines" can be anticipated in BSA/AML examinations. 

We keep a record of evolving money laundering schemes. At this point, our due diligence auditors avail themselves of an extensive database that keeps us alert to the nefarious money laundering tactics the crooks have developed and, unfortunately, continue to develop. 

I will provide several actions and non-actions – what some organizations do or don't do – that trigger regulatory violations. My focus is on RMLOs. 

Violations Bait and Land Mines 

1.     314(a) searches aren't completed promptly. RMLOs should make certain that the U.S. Patriot Act contacts listed in their online profiles are current and that they certify these profiles when contacts are updated. Moreover, companies must ensure that their policies and procedures name a point of contact. 

They should also provide the following: 

 a.     steps for when the primary contact is unavailable; 

 b.     ways to ensure information confidentiality; 

 c.     how to respond to FinCEN requests; 

 d.     how to determine if and when to file a SAR; and 

 e.     the process for independent testing of 314(a) compliance. 

2.     Inadequate AML training for appropriate personnel. Board members and the AML Officer do not always receive the appropriate BSA/AML training for their roles. Failure to educate staff on illicit financial activities to keep members safe and the organization compliant. We believe financial institutions should train new staff as soon as possible. 

To prevent staff-related issues, AML functions and responsibilities should encompass adequate resources, a sufficient level of aggregate AML expertise, and an appropriate allocation of time to AML tasks. 

3.     An AML Officer must be designated to own the system and ensure that processes are followed and updated, reports are filed, training is robust, and the entire system is running effectively. The board should grant the AML Officer the duties and authority to implement AML processes and policies. 

4.     AML training should include examples of money laundering and suspicious activity monitoring relevant to each operational area. This training also should provide officials with a sufficient understanding of the institution's risk profile and BSA/AML regulatory requirements. 

Additionally, companies must document all training, including the following: 

 a.     testing materials; 

 b.     attendance records; 

 c.     employees that fail to participate; and 

 d.     corrective actions taken concerning employees who fail to attend training. 

5.     A lack of independent testing. Avoid utilizing in-house staff that does not satisfy the "qualified" and "independent" criteria for independent testing. If staff is not qualified and independent, the work product is worthless and will likely be rejected by regulators. Not using an external resource to conduct the independent review causes delays in the required testing. 

6.     No written and approved Program. BSA/AML compliance programs must be in writing, approved by the board, and documented in board meeting minutes. It should be comprehensive. Off-the-shelf AML policies are notoriously defective. 

Additionally, the Program must set forth requirements for internal controls, independent testing, a designated AML Officer, training for appropriate personnel, member due diligence, and customer identification data. AML policies and procedures should be documented, comprehensive, consistent with best practices, approved by stakeholders, and regularly updated. 

7.     Stay alert to sanctions issued by the Office of Foreign Assets Control (OFAC). To be compliant with OFAC-governed sanctions regulations, your firm must ensure it is not engaging in trade or transaction activities that violate the rules behind OFAC's country-based sanctions programs or engaging in trade or transaction activities with sanctions targets named on OFAC's list of Specially Designated Nationals and Blocked Persons. 

The linkage to AML compliance requires an organization's policies and procedures to address aspects of OFAC compliance and controls, including customer onboarding, screening, and even specialized training. 

Customer Identification Program (CIP) requirements should be applied to all customers opening a new account as that term is defined in the Bank Secrecy Act and implementing regulations. The CIP must include procedures for making and maintaining a record of all information obtained to verify a customer's identity. At a minimum, the record must include all the identifying information gathered by the firm about a customer. 

8.     Noncompliant SARs. SARs are not filed within 30 or 60 days and are not complete or accurate, particularly SAR narratives. Failure to promptly detect, escalate, investigate, and file SARs. Include appropriate risk-based procedures for conducting ongoing customer due diligence, including (i) understanding the nature and purpose of customer relationships to develop a customer risk profile and (ii) conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information. 

9.     Know Your Customer (KYC) practices do not clearly define and align with customer attributes and risks (i.e., customer identification programs, customer due diligence, enhanced due diligence, and special circumstances due diligence). 

10.  Certain loan products pose a higher risk of criminal activity than others and attract money laundering criminality. You must document processes for monitoring your high-risk products and services for potential money-laundering activity. A "best practice" is to ensure that the AML Officer and compliance department are part of product plans at your institution.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group