Showing posts with label AML/ BSA. Show all posts
Showing posts with label AML/ BSA. Show all posts

Sunday, May 15, 2016

Know Your Customer: ISP Future Horizon...

The American public is changing their behavior as a result of the privacy and security failures across the private sector business policy landscape.  As the latest NTIA survey data reveals again, online commerce is being impacted and government agencies are now trying to further communicate there is a growing problem:

Lack of Trust in Internet Privacy and Security May Deter Economic and Other Online Activities
May 13, 2016 by Rafi Goldberg, Policy Analyst, Office of Policy Analysis and Development

Every day, billions of people around the world use the Internet to share ideas, conduct financial transactions, and keep in touch with family, friends, and colleagues. Users send and store personal medical data, business communications, and even intimate conversations over this global network. But for the Internet to grow and thrive, users must continue to trust that their personal information will be secure and their privacy protected.

NTIA’s analysis of recent data shows that Americans are increasingly concerned about online security and privacy at a time when data breaches, cybersecurity incidents, and controversies over the privacy of online services have become more prominent. These concerns are prompting some Americans to limit their online activity, according to data collected for NTIA [1] in July 2015 by the U.S. Census Bureau. This survey included several privacy and security questions, which were asked of more than 41,000 households that reported having at least one Internet user.

Perhaps the most direct threat to maintaining consumer trust is negative personal experience. Nineteen percent of Internet-using households—representing nearly 19 million households—reported that they had been affected by an online security breach, identity theft, or similar malicious activity during the 12 months prior to the July 2015 survey. Security breaches appear to be more common among the most intensive Internet-using households.

This survey is indeed only one facet of a much larger topic and pervasive problem.  Digital Trust is the output of making affirmative "Trust Decisions" with computing devices. Whether they are machine-to-machine, person-to-machine, or machine-to-person requires several technology engineering elements and business rules, that are understood and agreed upon.  The question is by whom?

Consumers who are using the Internet for communications and commerce and are the victims of Identity theft, stolen funds or other fraudulent schemes, are just the first wave of targets for transnational organized crime (TOC).  We have known this since the invention of virus scanners and bug bounty programs, in the early days of the 21st century.

Yet fifteen plus years later, the government is doing a study on the consumers feelings about privacy and security.  As a business or a consumer, we understand that the speed of commerce and technology is always far ahead of the regulations and the laws.  When enough people or businesses seem to be harmed, then the momentum begins for policy shifts and new laws are sometimes enacted after thousands of pages of semantic negotiation.

The answers and the outcomes we seek will come.  However, they will not first be solved by politicians and lawyers.  They will be mostly solved by our brilliant mathematicians, software engineers and data scientists.  At this point in time, we are getting so much closer to achieving digital trust through new innovations and inventions.  Just look at IBM Watson.

It is now time for business and commerce to begin the process of finding the truth.  Why do we continue to allow the levels of known bad actors to operate inside and within our networks?  It's a numbers game and it is because the criminals also employ the smartest social engineers and data scientists.

Digital Trust in the next fifteen years will mean something different than it does today.  We will have found the formula along the journey, the new equations and the rules agreed upon by all to make online and digital commerce more safe and secure.  So what will we do today and tomorrow, until the engineers and scientists save the day?

At this point in time, it is simply called "Know-Your-Customer"(KYC).  If this was utilized more effectively across critical infrastructure sectors beyond finance in our digital economy, then we would be making some progress.  Where are we talking about next? 

The FTC and FCC are well on their path to defining those critical elements of improving the trust that consumers have using their digital tools with ICT and on service providers web sites.  Yet even to this day, you still can find the criminals using and leveraging our own Internet Service Providers (ISP) to launch their attacks and perpetuate their fraudulent schemes.  How will this ever be deterred?  Could a version of KYC work with the ISP's?

Even with a global banking system in place you have pockets of greed and deceit.  Rogue nations or territories that have become the go-to-locations for the transnational organized crime syndicates to flourish.  Yet we can do much better, than we are today.

Just ask any "BlackHat" hacker from Eastern Europe who they prefer to do business with.  Query the experts that exist on the dark side and you will find the ISPs they prefer to do business with.  One day the regulators will realize this is where the business of e-crime has an opportunity for change and additional reform.  It will be more than just opening an account to gain access to the Internet.  It will be about scaling up our systems to a future horizon with new rules and robust real-time behavioral predictive analytics.  In the mean time:
May 11, 2016 
In testimony before Congress today, the Federal Trade Commission outlined its work over the past 40 years to protect consumers’ privacy at a hearing convened to examine privacy rules proposed by the Federal Communications Commission.

Chairwoman Edith Ramirez and Commissioner Maureen Ohlhausen testified on behalf of the Commission. The testimony before the Senate Judiciary Committee’s Subcommittee on Privacy, Technology and the Law provided background on FTC law enforcement efforts, policy work and consumer and business education programs related to protecting consumers’ privacy.

The testimony highlighted the FTC’s extensive history of privacy-related work. The testimony noted that the agency has brought more than 500 privacy-related enforcement cases in its history against online and offline companies of varying sizes, including companies across the internet ecosystem. In addition, the testimony highlighted a number of recent cases of note.

The testimony also provided information on the FTC’s policy work in the privacy area, going back to its first internet privacy workshop in 1996. The testimony noted that recent policy work has been based on principles featured in the FTC’s 2012 privacy report, and also highlighted workshops and reports related to the Internet of Things, big data, and other issues, including cross-device tracking.

The testimony also described the FTC’s extensive consumer and business education efforts related to privacy, including the FTC’s Start With Security campaign for businesses, and the newly-updated IdentityTheft.gov.

Sunday, October 30, 2011

Arab Spring: Information Operations Risk Management...

The Operational Risks associated with doing business on an international scale is nothing new. Global companies have for years been subjected to laws in the U.S. that are highly scrutinized by the Treasury Department. The Office of Foreign Asset Control (OFAC) is one such office. Companies in several key industry sectors including financial services have been obligated to know who they doing business with KYC (Know Your Customer) programs. This complies with the Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) laws. The Commerce Department has the U.S. Bureau of Industry and Security.

As compliance in any business is one of those areas that in many cases may seem burdensome, it is only one aspect of a total risk management strategy in the enterprise. One industry group that may have underestimated the magnitude of compliance and an effective export control operation is the high technology sector. During the next decade as emerging markets are building new communications infrastructure, this will be even more important; perhaps not for the reasons one would normally think about.

Information Operations (IO) are alive and well within the ranks of official and clandestine forces around the world. Why is John Q. Public surprised to hear this news? The political aspirations of new and rising factions within nation states have found the tools of the Internet and "Social Media" to instigate and to perpetuate non-kinetic components of asymmetric warfare. Now, technology companies in the United States must be ever more so cognizant of the risk implications associated with this social, political and military nexus. Here is more from theWSJ:

By JENNIFER VALENTINO-DEVRIES, PAUL SONNE and NOUR MALAS
A U.S. company that makes Internet-blocking gear acknowledges that Syria has been using at least 13 of its devices to censor Web activity there—an admission that comes as the Syrian government cracks down on its citizens and silences their online activities. Blue Coat Systems Inc. of Sunnyvale, Calif., says it shipped the Internet "filtering" devices to Dubai late last year, believing they were destined for a department of the Iraqi government. However, the devices—which can block websites or record when people visit them—made their way to Syria, a country subject to strict U.S. trade embargoes.

Discussions on the intersection of "The Arab Spring" and "Social Media" has been going on now for well over 9 months in the published press. One can only imagine that Google, Facebook and Twitter management have behind closed doors, been entertaining conversations from a myriad of .ORG and .GOV entities on this very subject. This week, the dialogue has taken on a more serious tone with comments from U.S. Secretary of State Clinton regarding Iran in the Washington Post:

By Thomas Erdbrink, Published: October 29
TEHRAN — An Iranian police unit that was formed this year to counter alleged Internet crimes is playing a key role in an escalating online conflict between the United States and the Islamic Republic. The “cyber police” force is part of a broad and largely successful government effort to block foreign Web sites and social networks deemed a threat to national security. Iranian officials say they must control which sites Iranians are able to visit, to prevent spying and protect the public from “immoral” material. The United States, they charge, is waging a “soft war” against Iran by reaching out to Iranians online and inciting them to overthrow their leaders. Secretary of State Hillary Rodham Clinton on Wednesday played into such accusations, saying U.S. officials had asked Twitter, the social networking site, to postpone online maintenance in 2009 so that it would be available for Iranian anti-government protesters organizing demonstrations against President Mahmoud Ahmadinejad’s disputed election victory. Iran’s state radio responded Thursday, citing Clinton’s comments as proof that Washington is using U.S. Internet companies to influence events inside Iran. Tensions between the two countries are high following allegations that an Iranian American citizen had plotted to assassinate the Saudi ambassador to Washington at the behest of the Quds Force, an elite branch of Iran’s Revolutionary Guard Corps. Iran has denied the accusations, but the United States has called for tougher sanctions against Tehran.

Again, where have John and Jane Q. Public been for the past few years? This is not new news to those who have been watching the growth of mobile communications and the explosion of the "Internet of Things." The utilization of wireless mobile communications and its intersection with social media apps in civilian environments is here to stay. How these consumer based applications have been now leveraged for situational awareness and information operations is exploding across the emerging nations, where the Internet is now gaining even more ubiquitous use.

What this means for risk managers in the C-Suites of major technology companies is a heightened sensitivity and awareness to the ways your tools and capabilities could be utilized in the hands of the wrong end user. No different than the unleashing of certain tools likeMetasploit, to help understand vulnerabilities within the confines of the corporate enterprise. These same tools could be utilized by nefarious cyber terrorists to quickly exploit the weakness in our own U.S. government and corporate network systems.

Like many inventions by mankind, they can be used for good and simultaneously for evil in the hands of the wrong person. Risk Management in the high technology sector will be just as much of an imperative as the manufacturing and shipment of products from Barrett or the manufacturers of detcord. The "Export Control" compliance mechanism is here to stay and companies who operate in the new age of emerging social media via mobile technologies, will need more effective OFAC internal controls.

Operational Risks exist within the business processes that you use with your sales and business development organization. When was the last time you had a compliance-based OFAC discussion within the ranks of the sales force at your new emerging technology company? Are you fully funded by the VCs and ready to sell your new encrypted social media app for Android to the world? We need to make sure that part of the roll out strategy, encompasses the right conversations with the correct government departments to determine the right process and the online tools available to better understand where and who you can sell your products to outside the U.S..

The past Arab Spring and the next organized movement utilizing social media and mobile internet technologies that include encrypted messaging, GPS and live video will be more closely scrutinized by internal compliance officers and the regulatory watchdogs domestically and abroad. Yet the most effective management tools going forward, may lie in the same ones used by your Mother and Father growing up. The ethical and the moral arguments in many cases can have a dramatic impact on people at an early stage in their lives. Perhaps it is still not too late to reinforce and to emphasize the fact that our cyber environments, are nothing more than the mirror image of the physical world we already know. Good and bad.

The future of risk management online and the effective compliance with legal sanctions may well begin with a heart-to-heart conversation at your next company sales meeting.

Sunday, January 09, 2011

Cyber Theft Rings: A Nexus with Terrorism...

BSA/AML compliance is an Operational Risk that continues to plague even the largest institutions. The ability to effectively program information systems to address "Politically-Exposed Persons" (PEP) and the risk to the banks reputation are still a challenge for some executives.

Why is this still an OPS Risk issue? In many cases, the lack of procedures being followed by adequate staff in the alert investigations unit where backlogs are prevalent. This becomes a business risk because there continues to be a lack of closure on these alerts. The simple monitoring of funds transfers to ensure timely reporting of suspicious activity associated with PEP's should be AML 101.

Retaining and deploying an independent consultant to review compliance and systems controls is the primary responsibility of an Audit Committee chair of the Board of Directors. For those institutions that have found themselves under the recent oversight of the OCC in the United States, many realize they have underfunded this obligation and the staff requirements to stay in pace with the expanding volume of electronic transactions.

Monitoring accounts of current or former senior political figures is well within the PEP definition and includes their families and any close associates. Therefore, the BSA officer will require even more robust budgets, staffs and systems programming to continue to be effective in regulatory compliance of the Bank Secrecy Act and Anti-Money Laundering statutes. And this just covers the risks associated with the banks regulatory obligations in the United States and many other countries of the world.

Yet this is the area that has traditionally been the foundation for the 20th century criminals and other entities who need to move money to places in large sums or to perpetuate fraudulent activities. Now what about the 21st century asymmetric threat, "Cyber Theft Rings"?

Malware exploiters purchase malware on the black market Internet and use it to steal victims banking credentials. They launch attacks from systems that are already compromised across the globe in small businesses and other commercial or government organizations. This allows the transnational cyber criminal to transfer stolen funds and deter the tracking of their activities. Money Mule networks then transfer funds to other accounts or get cash from ATM's and then buy stored value cards before they ship them back overseas to the crime syndicates.

The victims remain the financial institutions and the owners of the infected systems. So how large is this method of cyber theft? In 2010 the FBI reported close to 400 cases that had attempted loss of $220M and actual losses of $70M.

Today's (October 1, 2010) coordinated operation demonstrates that these 21st-century bank robbers are not completely anonymous; they are not invulnerable. Working with our colleagues here and abroad, we will continue to attack this threat and bring cyber criminals to justice."

Most of the accused hailed from Eastern Europe; many were based in Ukraine, where several worked as Web developers. Ten suspects were arrested in New York on Thursday, with another 10 having been arrested previously. The FBI is still seeking 17 others .


Where is the money going and what is it being used for? In a recent study by officials at the New York State Intelligence Center titled: "The Vigilance Project: An Analysis of 32 Terrorism Cases Against the Homeland", the statistics are the face of the US challenges with money laundering and terrorism:

  • 82 % were between the ages of 18 and 33.
  • 61 % attended some college and of these 64% of the educated terrorists were engineering majors.
  • 50 of the 80 suspects in the study whose citizenship could be identified were born in the U.S. .
  • 11 of the 32 cases studied happened in the past two years. In these cases, 17 of the 19 defendants were in the United States legally.
The banking community understands that it has to remain vigilant when it comes to BSA/AML regulations. Not only to avoid the millions of dollars in potential fines, but also because of the potential nexus with counterterrorism.

Tuesday, November 11, 2008

AML: Transnational eCrime Ecosystem...

The Operational Risk threat matrix from "Advance Fee Fraud", "Nigerian Letter (419) Fraud, Foreign Lottery/Sweepstakes Fraud and "Overpayment Fraud" is still growing exponentially. During our current economic crisis, the spike in these consumer Mass Marketing schemes is to be expected. Global Anti-Money Laundering (AML) operations are in high gear at home and abroad.

The "Transnational Economic Crime Ecosystem" is thriving and the major phases of the environment continue to be a major challenge for global financial institutions and law enforcement:

  1. Collection
  2. Monetization
  3. Laundering

Let's take a closer look at "Overpayment Fraud":

Overpayment Fraud - Victims who have advertised some item for sale are contacted by buyers who remit counterfeit instruments, in excess of the purchase price, for payment. The victims are told to cash the payments, deduct any expenses, and return or forward the excess funds to an individual identified by the buyer, only to discover they must reimburse their financial institution for cashing a counterfeit instrument.

The predominantly transnational nature of the mass marketing fraud crime problem presents significant impediments to effective investigation by any single agency or national jurisdiction. Typically, victims will reside in one or more countries, perpetrators will operate from another and the financial/money services infrastructure of numerous additional countries utilized for the rapid movement and laundering of funds. For these reasons, the FBI is uniquely positioned to assist in the investigation of these frauds through its network of Legal Attache offices located in over 60 U.S. embassies around the world. By leveraging its global presence and network of liaison contacts, the FBI has successfully cooperated with other domestic and foreign law enforcement agencies to combat, disrupt, and dismantle international mass marketing fraud groups.

Despite the best inter-agency enforcement efforts to combat mass farketing fraud, the FBI remains cognizant of the fact that the only enduring remedy for this crime problem lies in consumer education and fraud prevention programs. Towards this end, the FBI has not only produced its own mass marketing fraud prevention pamphlet but coordinates on other public information efforts with the DOJ, FTC, and the USPIS. The FBI also supports a consumer fraud prevention website in conjunction with the USPIS which can be located on the web at: http://www.lookstoogoodtobetrue.gov.

While the number of Mass Marketing Fraud cases has declined over the past few years, the number of new money laundering cases has risen to over 500 in FY 2007 alone. This is to some degree as a result of the cooperation being given to law enforcement by the financial instituions themselves. And for good reason. There is a new sheriff in town.

(Reuters) - A U.S. tax investigation into UBS AG (UBSN.VX: Quote, Profile, Research, Stock Buzz) is concentrating on senior and midlevel executives and bankers, and could result in one or more indictments, the New York Times said, citing people briefed on the matter.

Investigators are sifting through more than 70 names and related account details of American clients provided by UBS over the last few months to the Justice Department, which has passed the details to the Internal Revenue Service for further scrutiny, the paper said.

The Justice Department and the IRS plan to build both civil and criminal tax-evasion cases against some of the clients, the people told the paper.

The U.S. tax investigation risks compounding damage to UBS's reputation at a time it has been forced to make bigger writedowns than any other European bank in the credit crisis.

The U.S. Department of Justice is investigating UBS over offshore services provided to U.S. clients from 2000 to 2007 to find out whether UBS helped wealthy Americans dodge taxes. The Swiss bank was singled out by U.S. President-elect Barack Obama as one of the banks who helped "tax cheats." It decided earlier this year to stop offering offshore Swiss bank accounts to U.S. citizens.


Yet the collection phase of mass marketing fraud is not about "70" or a "100" UBS clients who are trying to cheat on their taxes. It is still about the millions of phishing and spam messages that circle the digital globe in search of their targets or prey. These illusive criminal organizations behind this organized cybercrime wave are continually exploiting the vulnerabilities of our financial institutions and our own human behavior.

"Merchandise Mules"
are being recruited by the hundreds if not thousands to reship goods outside North America. These criminals are utilizing stolen identities and credit cards to purchase goods on eCommerce sites and eBay and then requesting to ship the goods overseas. Unfortunately, those who are elderly or even just down on their economic luck fall victim to this tremendous economic crime tsunami:

Much of the modern organized crimes are very similar to the old. The most significant transformation from the streets to cyberspace has enlarged the territory of individuals and organized groups.

Enabled by the Internet, criminals can operate in cyberspace where less governance, a transnational stage, and a multitude of transactions to monitor complicate surveillance and enforcement. From counterfeiting drugs and software to identity theft and credit-card fraud, illegal transactions are increasingly infiltrating legitimate businesses where counterfeited goods and money laundering are buried in the billions of legitimate computer transactions made daily around the globe.

Counterfeited products are rising through global distribution via Internet sites. According to the World Health Organization, 50 percent of the medicines sold online are counterfeit.

The expanse of international criminal activity has been followed with an increase in prosecution through cooperating international law enforcement agencies willing to join the fight against globalized crime.

Tuesday, October 07, 2008

FCPA: 21st Century Investigations...

Intellectual property theft, corporate espionage, transnational economic crime and the Foreign Corrupt Practices Act (FCPA) are on collision course with international 21st Century investigators. New age professionals who were almost born with a keyboard or PDA in their hand; remain ever vigilant.

The use of third parties, offshore banking and other avoidance mechanisms such as Black Market Peso Exchange (BMPE) increases the potential for theft, corruption and abuse buried in global commerce using the Internet Protocol (IP).

The FCPA prohibits corrupt payments through intermediaries. It is unlawful to make a payment to a third party, while knowing that all or a portion of the payment will go directly or indirectly to a foreign official. The term "knowing" includes conscious disregard and deliberate ignorance. The elements of an offense are essentially the same as described above, except that in this case the "recipient" is the intermediary who is making the payment to the requisite "foreign official."

Intermediaries may include joint venture partners or agents. To avoid being held liable for corrupt third party payments, U.S. companies are encouraged to exercise due diligence and to take all necessary precautions to ensure that they have formed a business relationship with reputable and qualified partners and representatives. Such due diligence may include investigating potential foreign representatives and joint venture partners to determine if they are in fact qualified for the position, whether they have personal or professional ties to the government, the number and reputation of their clientele, and their reputation with the U.S. Embassy or Consulate and with local bankers, clients, and other business associates. In addition, in negotiating a business relationship, the U.S. firm should be aware of so-called "red flags," i.e., unusual payment patterns or financial arrangements, a history of corruption in the country, a refusal by the foreign joint venture partner or representative to provide a certification that it will not take any action in furtherance of an unlawful offer, promise, or payment to a foreign public official and not take any act that would cause the U.S. firm to be in violation of the FCPA, unusually high commissions, lack of transparency in expenses and accounting records, apparent lack of qualifications or resources on the part of the joint venture partner or representative to perform the services offered, and whether the joint venture partner or representative has been recommended by an official of the potential governmental customer.


Digital fingerprints and technology has changed the way we manage and store information just as it has changed the way cases are developed and presented to new juries who understand the evidence. Organizations operating on a global scale with branch offices in London, Frankfurt, Mumbai, Hong Kong and Shanghai are continually exposed to operational risks associated with rogue employee behavior in the normal course of doing business in country. The legal matrix of risk exposures are magnified by Internet commerce, privacy, intellectual property and transnational policing.

In the recent "2008 Report to the Nation on Occupational Fraud and Abuse" by the ACFE, the Banking / Financial Services industry group suffered the highest frequency of losses:

  • # of Cases - 132
  • % of Cases - 14.6%
  • Median Loss - $250,000.00
The type of scheme with the highest percentage was corruption at 33.3% of banking cases. Government had 106 cases with 26.4% of these associated with corruption. The telecommunications sector endured the biggest impact with 16 cases reported yet with a median loss of $800,000.00 . Healthcare suffered 76 fraud cases at 26.3% involving corruption.

In all cases the digital trail is there for the forensic professionals to track, trace and assemble the history and chronology of events. Unfortunately for the prosecution and the plaintiffs, there is a tremendous backlog for the collection and analysis of this modern day CSI. Independence and expertise is the key element of getting your favorable day in court. Judges and juries are far more educated on the new Federal Rules of Evidence and Civil Procedure. Lawyers are utilizing the eDiscovery threat to force premature settlements. Meanwhile, the digital evidence continues to be collected, imaged and stored for analysis waiting it's day in court.

21st Century investigators utilize digital forensic certifications and training combined with years of education and experience. Managing the legal risk to institutions and those who have been implicated is their only priority by achieving a defensible standard of care. Judging the evidence is not their interest nor their objective. Insuring that the relevant information is soundly collected, preserved and presented without spoilation or prejudice, is the primary mission.

Wednesday, June 25, 2008

Transnational eCrime: Leaderless Networks...

Transnational crime and the multi-phase process of Collection, Monetization and Laundering is no better illustrated than in this Citibank case of this past year. This week more arrests have occurred as the informants intelligence has been utilized in capturing those who are part of this international criminal network. Kevin Poulson at Wired writes:

The FBI has recently made at least six more arrests in New York -- bringing the total to 10 -- thanks to information from arrested scam suspects, a lucky traffic stop, and an undercover operation that at one point had Eastern European hackers chasing a female FBI agent through the streets of New York, trying to mug her for ATM-card-programming gear. Six months after the 2007 breach, Wired.com is receiving scattered reports of Citibank customers still suffering mysterious withdrawals from their bank accounts.

The FBI believes the brains behind the operation is a Russian man, who's receiving the lion's share of the profits through international wire transfers and online-payment systems. While Citibank and federal officials are being closed-mouthed about the PIN theft and the ensuing fraud, the Citibank heist provides a rare look at how a single high-value breach reverberates through the international "carding" community of bank-card fraudsters. What's more, neither Citibank nor the third-party transaction processor involved in the breach has warned consumers to watch for fraudulent withdrawals, raising questions about the disclosure policies in the financial industry.


The case is unfolding in the media and the finger pointing will continue on where the breach occurred. Was it on a Citibank network or an outsourced third party supplier of 7-Eleven who operates the retail stores where the ATM's are located? ID Theft is not the real issue here as much as a bold database hack of accounts, PIN's and counterfeiting of ATM cards.

This facet of Operational Risk is another lesson learned about the safety and security of customer data especially when it is outside your own corporate domain. Service Level Agreements (SLA) are too often the only item that is consistently presented as evidence of the due diligence of auditing a third-party processor of customer data. The actual physical audits are few and typically are not done on a rigid schedule. Resources and funding are the excuse more often than a total lack of oversight.

Transnational crimes such as piracy, illegal traffic of drugs and humans, counterfeiting and intellectual property theft or espionage is not new to the Operational Risk Managers of global enterprises and international organizations. What the financial motivations are and where the proceeds are going is potentially the greatest challenge any investigator has on their agenda. Where does it all lead? What does the target plan to do with the money gained from these illegal activities and incidents?

The answer is that there is no single target. The target is a network. And like a starfish, it can reconstitute itself from any severed part; there is no brain. Douglas Farah captures the thinking on why leaderless networks are a continuous threat:


Any one piece of the leaderless network can reconstitute itself with little difficulty, without waiting around for someone to give an order and for that order to move down the chain of command.

Clearly, it seems, there are better and worse individuals within the network, and taking out the really good ones takes something of a toll. And leaderless groups are not highly efficient. But they survive.

If you have a system of enterprising freelance operations acting on impulses (the urge for profit, the urge to carry out attacks, the urge to acquire weapons etc.), these impulses will overlap. The actions will be taken to benefit all parties, and the networks can thrive with no one person making the important decisions.

This strikes me a perhaps the most dangerous mutation that both organized crime groups and terrorist groups (particularly Islamist terror groups, who seem more adept at moving through nerve impulses, without specific orders, than most), can take.

Successfully countering these groups and their growing reach will require a radical new assessment of both strategy and tactics in the military, intelligence community and law enforcement. But that will require a willingness to dump old assumptions and paradigms, something that has not really happened since 9-11.

Thursday, March 06, 2008

Policing The Globe: Transnational Risk...

The nature of transnational crime today can be broken down into three fundamental steps. Collection, Monetization and Laundering. This is not anything new yet the evolution of "Policing The Globe" has made dramatic leaps in the past few years. New Legal Attaches (Legats), Memorandums of Understanding with INTERPOL and other national law enforcement entities has created an increased coordination and cooperation across borders and continents.

Data warehousing, convergence of records data and more sophisticated methods for link analysis from companies such as i2 has made the detection and investigation of potential incidents more effective.

When the Collection phase is focused on harvesting Personal Identifiable Information (PII) for the purpose of ID Theft using Botnets or other cyber-related ploys the consumer will consistently suffer the direct effects. The retail banking institutions will be the ultimate target of the next phase of the criminal life cycle, the Monetization phase.

Using PII to gain access to bank accounts is taking on different forms these days, especially during times of economic hardship. The HELOC refinancing trends are upon us and at the same time the unsuspecting homeowner may be giving up vital equity that still exists in their loans or lines of credit, to criminal elements. Once any of these scams and frauds are completed the funds are quickly turned into cash using wire transfers, ACH and or even the old reliable ATM using 3rd parties. And it doesn't even have to go this far, when you can sell PII for cents or dollars per record in terms of it's quality and whether the targets have a stellar credit score or deep equity.

And finally we find that funds are then turned around into other business ventures to help conceal the source or origin of the proceeds, so that the money goes through the enevitable Laundering phase.

Now let's look at it through the lens of an OPS Risk perspective?

"Pirates, bandits, and smugglers have bedeviled governments since time immemorial. Politicians and media today obsess over terrorism and trafficking in drugs, arms, people and money. Far less is said or known, however, about the expanding global reach of the police, prosecutors, and agencies like Interpol and Europol charged with targeting transnational crime."

Peter Andreas and Ethan Nadelmann in their book, "Policing The Globe: Criminalization and Crime Control in International Relations" provide analysis and bridge the connections between justice and politics.

To what degree does your institution actually initiate proactive due diligence on your own, to try and identify who is attacking your organization or your assets? The nexus with Operational Risk has to do with the legal compliance and transnational agreements with other nations on what the "Rules of the Game" are for privacy, investigations and obtaining evidence. More importantly what are the coordination and cooperation activities with your own domestic and the foreign jurisdictions for a prosecution strategy, especially if you have employees and operations in-country?

This morning an explosive device was detonated in front of a defense recruiting office in Times Square, New York City by a bicyclist. This incident could be a precursor to a potential terrorist suicide attack or most likely, just a disgruntled war activist. A few days earlier, domestic Ecoterrorism is suspected in the burning of three high value homes in the Seattle, Washington area.

"The mention of a bicyclist raised possible links to a May 2005 bombing at the British Consulate and an Oct. 26 explosion at the Mexican Consulate," the New York Daily News notes. "In both cases, police said, the suspect was possibly riding a bicycle when hollowed-out grenades - filled with black powder and a fuse - were tossed into the consulates. No arrests were made in those attacks."

Whether the ID theft crimes are committed online collecting zeros and ones from unsuspecting consumers or businesses without the proper controls in place or the direct physical attack on specific or symbolic assets, the transnational question is in the forefront of many peoples minds.

While it's too early to try and connect these two incidents to the same individuals or to countries outside the United States, one thing is certain. The laws, tools and capabilities of International Law Enforcement are accelerating at a more rapid pace, as new operational risks emerge on a global scale. Politics will in some cases, try to influence the agenda and to unleash sanctions that diplomats and State Departments will work on collaboratively to achieve preemptive law enforcement agendas.

Here then are some of the steps the State Department said Barbados had taken in recent years to prevent fraud and money laundering:

  • Extended the money laundering laws to cover offenses other than those involving drugs.
  • Forced financial institutions to report suspicious transactions that may involve criminal activities, such as terrorism.
  • Enabled the police to pursue "all potential prosecutions" of money laundering.

Placed the burden of proof on accused persons to demonstrate that property in their possession was "derived from a legitimate source". Failure to do so could lead to a presumption that it was acquired through illegal means.

The transnational ecosystem of crime control and international relations will continue to be a challenging arena for global enterprises. Ensuring that Operational Risk Teams are well equipped to provide assistance to investigators, law enforcement and government agencies is essential. Simultaneously preparing your employees for their inevitable exposure to these cases, law suits and incidents is a proactive strategy executives are actively investing in.

Liechtenstein remains vulnerable to money-laundering despite efforts by authorities to tighten regulations, International Monetary Fund and Council of Europe experts said Wednesday.

The tiny Alpine principality, currently at the heart of an international tax evasion scandal, offers "discreet and flexible legal structures, strict bank secrecy and favourable tax arrangements," the IMF said in a report.

Around 90 percent of Liechtenstein's financial services business is provided to non-residents, it noted.

"By it's nature, Liechtenstein's financial sector business creates a particular money laundering risk," the IMF said.

Thursday, February 21, 2008

Hedge Funds: Focus on Sound Practices...

So what is on the mind of Hedge Fund Managers in these days of "volatility" and uncertainty? Afterall the CFOs and COOs at hedge funds and fund of funds must have some questions about best practices for auditing their funds' operations, and mitigating the most common forms of operation risk.

Top industry practitioners and industry advisors will discuss these topics at THE HEDGE FUND OPERATIONAL RISK MANAGEMENT SUMMIT Strategies for Stress Testing and Hedging Operational Risks:
  • New auditing standards – an operational due diligence checklist
  • Methods for attaining greater transparency while protecting strategies
  • Financing your operations – key considerations for managing operational risk
  • Implementation of disaster recovery strategies
  • The role of operational due diligence in your risk management strategy
  • Current issues in regulation and compliance
  • Updates on tax risk management and international tax compliance
  • Understanding methodologies for hedge fund ratings
  • ERISA – new info for hedge fund operations
  • Best practices for managing counterparty risk
The speakers and panelist's are prominent leaders in banking, alternative investments and the usual suspects of lawyers and accountants. Yet there is one item in the list that stands out. The topic of ERISA and new info for hedge fund operations. Among other things, ERISA provides that those individuals who manage plans (and other fiduciaries) must meet certain standards of conduct. The law also contains detailed provisions for reporting to the government and disclosure to participants. There also are provisions aimed at assuring that plan funds are protected and that participants who qualify receive their benefits.

Hedge Funds CxO's are thinking more about implementation of disaster recovery strategies. We know that they have been planning for it since the day the doors opened somewhere in Greenwich, yet now the vital topic of "Implementation" is at the forefront of the discussion.

In the context of Operational Risk Management with hedge funds, the goal is no different even while the feds may not have all the new regulations in place or the laws on the books. After all, the industry as a whole is just now getting their new leader in place to lobby "The Hill". The Managed Funds Association (MFA) has announced their new President, Mr. Baker .

Oversight and transparency will be a continuous topic for regulators. Yet as managers of several trillion dollars in assets, there are some important and vital practices that will gain momentum within the ranks of the Alternative Investments Industry.

We are pleased to see that Section I of the MFA Sound Practices Guidance includes Information Technology Controls:

The Recommendations also include information technology (“IT”) guidance in order to control changes to any software applications, data, and IT infrastructure and to maintain proper security therein. Finally, the Recommendations in Section 1 provide guidance on relationships with third-party service providers that perform key business functions, such as calculating net asset value (“NAV”) or monitoring risk.

And beyond the normal rules around "Ethics" and best practices associated with the code of conduct in the financial services industry, Hedge Funds must realize that they are not hedging their Operational Risk by outsourcing to 3rd Parties. They are still responsible for the oversight of these 3rd Parties and the extent to which they are in compliance with all federal and state laws.

V. PERFORMANCE OF INVESTOR IDENTIFICATION AND
OTHER AML PROCEDURES BY THIRD PARTIES

A. Relationships between the Hedge Fund Manager and Third Parties

This section should address the fact that the U.S. Department of Treasury has recognized the ability of a Hedge Fund or Hedge Fund Manager to contractually delegate the implementation and operation of certain aspects of its AML compliance program to third parties (e.g., fund administrators, IAs, CPOs, CTAs, broker-dealers, and futures commission merchants), although the Hedge Fund and Hedge Fund Manager remain fully responsible for the program.

With so much riding on the hedge funds industry and it's importance to the performance of the markets, it's everyones wish that the CxO's implement robust compliance and ethics programs to support their Operational Risk Management Frameworks.

Friday, September 07, 2007

BMPE: Internal Audit Awareness...

Risk in the supply chain may not always come from that vendor who provides your power, water or telecommunications. Black Market Peso Exchange (BMPE) is an Operational Risk that is starting to gain more awareness with Internal Auditors. This has been around since the 1980's yet even today some of our most sophisticated financial services institutions are being subjected to this system of fraud. The BMPE has been another way for money laundering from illicit criminal drug proceeds to impact our risk management controls:
American Express Bank International's anti-money laundering program was deficient in three of the four core elements. Namely, the Bank failed to implement adequate internal controls, failed to conduct adequate independent testing, and failed to designate compliance personnel to ensure compliance with the Bank Secrecy Act. American Express Bank International's high-risk customer base, product lines, and international jurisdiction of operations required elevated measures to manage the risk of money laundering and other financial crimes.

Nevertheless, the Bank conducted business without adequate systems and controls reasonably designed to manage the risk of money laundering, including the potential for Black Market Peso Exchange transactions that may be used by Colombian drug cartels to launder the proceeds of narcotics sales. American Express Bank International's failure to comply with the Bank Secrecy Act and the regulations issued pursuant to that Act were serious, repeated and systemic.

This method of money laundering is effective for the drug traffickers and requires more awareness on the behalf of fraud examiners and independent auditors. The IRS form 8300 requiring companies and financial entities to disclose receipts in excess of $10K in cash or equivalents doesn't work very well as wire transfers are not considered cash or cash equivalents.

Javier Sarmiento with GlassRatner has a substantive article on the subject in the last issue of the ACFE Fraud Magazine.

A point is made that needs to be emphasized here. "Don't rely on banks and financial institutions to conduct anti-money laundering (BSA/AML) procedures on behalf of the company." Is it possible that your organization has purchased inventory with funds that have been utilized as part of the BMPE scheme? What about resellers and distributors that are part of your own revenue supply chain.

In terms of Independent testing, make sure that your Internal Audit department is educated and aware of this particular mechanism for use by money launderers:

American Express Bank International's independent testing of its Bank Secrecy Act program was ineffective. Internal Audit Staff lacked sufficient training and knowledge to facilitate compliance with the Bank Secrecy Act. Audit scopes were not always tailored or designed to capture and test for compliance with certain requirements of the Bank Secrecy Act.

Internal Audit staff also failed to conduct sufficient customer transaction testing to adequately evaluate the overall sufficiency of the anti-money laundering program at the Bank. Furthermore, Internal Audit failed to assist management with tracking and following-up on previously identified regulatory examination deficiencies. In addition, Internal Audit failed to conduct adequate testing of the suspicious activity monitoring system or identify the numerous data integrity concerns associated with this system for an extended period of time. The ineffectiveness of the Internal Audit function at American Express Bank International contributed to the failure to identify significant deficiencies in this system before 2007.

Thursday, August 30, 2007

BSA/ AML: Testing the Channel...

Legal compliance with the Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) is a complex and growing concern by regulators, enforcement and Operational Risk Executives. In the United States, the FFIEC (Federal Financial Institutions Examination Council) has published the latest Examination Manual to provide guidance:

Enterprise-Wide BSA/AML Risk Assessment

Holding companies or lead financial institutions that implement an enterprise-wide BSA/AML compliance program should assess risk both individually within business lines and on a consolidated basis across all activities and legal entities. Aggregating risks on an enterprise-wide basis for larger or more complex organizations may enable an organization to better identify risks and risk exposures within and across specific lines of business or product categories. Consolidated information also assists senior management and the board of directors in understanding and appropriately mitigating risks across the organization. To avoid having an outdated understanding of the BSA/AML risk exposures, the holding company or lead financial institution should continually reassess the organization’s BSA/AML risks and communicate with business units, functions, and legal entities. The identification of a BSA/AML risk or deficiency in one area of business may indicate concerns elsewhere in the organization, which management should identify and control.

When a financial institution utilizes a strategy for it's channel or broker network the goal is to build controls into the consumer application process. These controls help the parent financial institution with compliance issues and give the independent broker or registered investment advisor with the tools and mechanisms for risk mitigation. However, to what degree do these independent brokers who interface with the consumer actually understand, implement and comply 100% with BSA/AML laws?

This question may haunt the minds of many OPS Risk professionals as they try to manage the mountain of data and documentation requirements at the home office or processing center. When there are dozens or hundreds of independent brokers in the client acquisition process your risk exposure increases dramatically. When and how often do you need to audit these important entities in your member or client supply chain?

Independent testing (audit) should be conducted by the internal audit department, outside auditors, consultants, or other qualified independent parties. While the frequency of audit is not specifically defined in any statute, a sound practice is for the bank to conduct independent testing generally every 12 to 18 months, commensurate with the BSA/AML risk profile of the bank. Banks that do not employ outside auditors or consultants or have internal audit departments may comply with this requirement by using qualified persons who are not involved in the function being tested. The persons conducting the BSA/AML testing should report directly to the board of directors or to a designated board committee comprised primarily or completely of outside directors.

Those persons responsible for conducting an objective independent evaluation of the written BSA/AML compliance program should perform testing for specific compliance with the BSA, and evaluate pertinent management information systems (MIS).

This is not any surprise to large banks and securities dealers who have been working diligently on these compliance management problems for decades. Whenever an organization is deploying a distributed and indirect model for acquiring new consumers, high net worth individuals and other business entities for financial-based products and services; BSA/AML programs should be robust. The individuals who are planning to launder money that has been obtained illegally or are part of a fraud scheme will prey on those unsuspecting and naive institutions first. In some cases, it could be an independent broker or business who is the target of a sophisticated and influential individual. They want to find a weak link in the institutions sales channel to gain access to a well known brand to leverage their scheme with new victims.

The criminal trial of ex-Refco Inc. Chief Executive Phillip R. Bennett and two other former executives has been postponed until March 2008, according to court transcripts.

During a telephone conference last month, U.S. District Judge Naomi Reice Buchwald delayed the trial of Bennett; Robert C. Trosten, Refco's ex-chief financial officer; and Tone N. Grant, the commodities broker's former president, until March 17. A transcript of the call was released publicly earlier this week.

The case was originally scheduled to go to trial in October.

The men are facing a variety of charges including conspiracy, securities fraud, bank fraud, wire fraud and money laundering.

Late Wednesday, the litigation trusts representing Refco's creditors announced they had sued Thomas H. Lee Partners LP in federal court in Manhattan, alleging the buyout firm uncovered red flags about Refco and its executives before the buyout firm's 2004 purchase of a controlling stake in Refco, but failed to follow up in hopes of profiting from Refco's initial public offering the next year. Lee has denied the claims.