Enforcement Trends, Crypto, Regulatory Developments — and More

I am very pleased to co-chair again the Practicing Law Institute’s 2023 Anti-Money Laundering Conference on May 16, 2023, starting at 9 a.m. in New York City (the event also will be virtual). 

I am also really fortunate to be working with co-chair Elizabeth (Liz) Boison

On February 14, 2023, both the American Bankers Association (“ABA”) and the Bank Policy Institute (“BPI”) submitted comments to the Financial Crimes Enforcement Network (“FinCEN”) on FinCEN’s notice of proposed rulemaking (“NPRM”) relating to access to beneficial ownership information (“BOI”) reported to FinCEN under the Corporate Transparency Act (“CTA”). While both organizations had similar comments, mainly being that the proposed limits on FIs’ ability to use BOI retrieved from the database contradicts the CTA’s objective, the ABA recommended that FinCEN entirely withdraw the NPRM. Below, we break down each organization’s comments and strong critiques regarding the NPRM.

Continue Reading  Bank Industry Groups Heavily Criticize FinCEN’s Proposed Rule on Access to Beneficial Ownership Information

Factual Statement Is a Tale of Whistleblowing, High-Risk Customers, and Misleading U.S. Banks

Earlier this month, Danske Bank was sentenced in the Southern District of New York to three years of probation and forfeiture of $2.059 billion.  The sentencing capped a tumultuous and global scandal that became public several years ago, as the enormous scope of the bank’s anti-money laundering (“AML”) compliance problems emerge:  several hundred billion in suspicious transactions allegedly were processed over time at the bank’s former Estonian branch.  As a result of the sentencing, Danske Bank was ordered to make an actual payment of $1,209,062,646; the bank received credit for the rest of the forfeiture amount on the basis of a $178.6 million payment to the Securities and Exchange Commission and a $672.3 million payment to Denmark authorities.

Danske Bank was charged not with violating the Bank Secrecy Act (“BSA”), but rather with bank fraud.  According to the press release issued in December 2022  by the Department of Justice (“DOJ”) at the time of the bank’s plea, the bank had “defrauded U.S. banks regarding Danske Bank Estonia’s customers and [AML] controls to facilitate access to the U.S. financial system for Danske Bank Estonia’s high-risk customers, who resided outside of Estonia – including in Russia.”  The DOJ’s choice to charge bank fraud presumably was predicated upon issues relating to U.S. jurisdiction and the actual applicability of the BSA to Danske Bank and activities in Estonia – but the heart of the criminal case is that Danske Bank allegedly hid its own AML failures from three U.S. banks, thereby thwarting the U.S. banks’ own AML programs and compliance with the BSA.

The plea agreement contains a lengthy statement of facts full of eye-catching allegations.  As we describe, it sets forth a tale of intentional and sometimes brazen misconduct by Estonian branch employees, coupled with lax oversight and implicit approval, or at least tolerance, of such conduct by some people in upper management.  Further, it involves another example of a financial institution, in the eyes of law enforcement and regulators, over-valuing profit and under-valuing compliance systems.  The case also highlights, again, the potential risks associated with correspondent bank accounts held by non-U.S. banks, the importance of having fully integrated and coordinated monitoring systems, and the potential role of whistleblowers.

Finally, this saga is not necessarily over entirely.  Danske Bank is subject to three years of probation.  The plea agreement requires numerous compliance commitments by the bank, including signed certificates of compliance and self-reporting of potential AML failures.  Danske Bank’s troubles also have involved lawsuits brought by investors claiming to have been defrauded, although the bank has had success in fending off these actions (see here, here and here).

Continue Reading  SDNY Sentences Danske Bank in Massive AML Scandal

Indictment Focuses on “High Risk” Transactions Involving Mexico, Bulk Cash, and Zero SAR Filings

On September 13, the United States Attorney’s Office for the Eastern District of New York announced that defendant Hanan Ofer pleaded guilty to “failing to maintain an effective anti-money laundering program.”  Ofer and his co-defendant, Gyanendra Asre, were named in a March 2021 indictment (the “Indictment”) alleging they funneled “hundreds of millions of dollars from high-risk foreign jurisdictions” – primarily, Mexico – from 2014 to 2016, through “small, unsophisticated financial institutions” without implementing an anti-money laundering program as required by the Bank Secrecy Act (“BSA”).  Ofer and Asre were charged with failure to maintain an effective anti-money laundering (“AML”) program, failure to file (any) Suspicious Activity Reports (“SARs”), and the operation of an unlicensed money transmitting business.

As we discuss, it is a little difficult to draw clear lessons from the Indictment.  Although the DOJ press release emphasizes the eye-catching number of $1 billion, neither the press release nor the Indictment actually describe these transactions as “suspicious,” much less as involving specific illicit proceeds.  Rather, and as we discuss, the transactions are described merely as “high risk.” Thus, and although it is entirely possible that the government has access to evidence which it did not reference in the charges, the Indictment appears to rely heavily on a very process-oriented theory of prosecution:  the defendants failed to implement adequate processes to monitor and/or prevent transfers that were “high risk,” but not demonstrably related to illicit funds involving specific underlying criminality.

It is also important to acknowledge the Indictment’s allegations against both defendants for operating, apparently “on the side,” a separate unlicensed money transmitter business of their own.  Here, the allegations are more concretely severe:  the unlicensed money transmitter business “involved the transportation and transmission of funds that were known to the defendants to have been derived from a criminal offense or were intended to be used to promote and support unlawful activity.”  Although it is impossible to know, this charge presumably pressured in part Mr. Ofer to plead guilty to more process-oriented BSA charges involving the $1 billion in “high risk” transfers at other financial institutions.

Continue Reading  AML Compliance “Expert” Pleads Guilty to Failure to Maintain Effective AML Program for Over $1 Billion in High-Risk Transactions

As we have repeatedly blogged, concerns about perceived anti-money laundering (“AML”) risks in the real estate industry are rising globally.  Consistent with this concern, the Financial Action Task Force (“FATF”) has updated its AML guidance for the real estate sector in a document entitled “Guidance for a Risk-Based Approach: Real Estate Sector,” (“FATF Guidance” or “the Updated Guidance”).  The FATF Guidance urges a variety of players in the real estate industry to adopt a risk-based approach (“RBA”) to mitigate AML risks and sets forth some high-level recommendations.  The Updated Guidance notably coincides with FinCEN’s advanced notice of proposed rulemaking to impose reporting and perhaps other requirements under the Bank Secrecy Act (“BSA”) for persons involved in real estate transactions to collect, report, and retain information, and the  recent extension of Geographic Targeting Orders for U.S. title insurance companies.

The FATF Guidance appears to be driven, at least in part, by FATF assessments showing that the real estate sector has high AML risks, which industry players often fail to appreciate and/or mitigate.  The Updated Guidance explains how various industry players can use an RBA to mitigate those risks.  It identifies sector-specific risks, sets forth strategies for assessing and managing those risks, and describes challenges the industry faces in doing so.  The FATF also offers specific guidance for “private sector players” and “supervisors” (e.g., countries and self-regulatory boards) for going forward.  The Updated Guidance includes tools, case studies, and examples of both private sector and supervisory practices to show real estate supervisors and practitioners how to implement FATF standards in an adequate, risk-based and effective manner.

The FATF is an inter-governmental policymaking body dedicated to creating AML standards and promoting effective measures to combat money laundering (“ML”) and terrorist financing (“TF”).  The FATF issued the Updated Guidance with input from the private sector, including from a public consultation with thirteen private-sector representatives (including from sector specific professional associations, the legal profession, FinTech providers, and non-profit organizations) in March and April 2022.  This consultation urged FinCEN, among other things, to provide greater clarity in the Updated Guidance regarding its applicability to the real estate sector and related professions (such as lawyers, notaries, and financial institutions) and extend FATF recommendations to broader real estate activities (such as property development and leasing).

Continue Reading  FATF Updates Risk-Based Approach Guidance for the Real Estate Sector

The Office of the Comptroller of the Currency (“OCC”) entered into a Consent Order (available here) with Anchorage Digital Bank (“Anchorage”), which requires Anchorage to create a compliance committee and take steps to remediate alleged shortcomings with respect to the implementation and effectiveness of Anchorage’s Bank Secrecy Act/Anti-Money Laundering (“BSA/AML”) program.  Notably, Anchorage will pay no civil penalty.

Anchorage is not any regular entity overseen by the OCC:  it is a cryptocurrency custodian.  As we will discuss, the timing of the Consent Order indicates that even when regulators permit crypto activities by financial institutions, they remain cautious, particularly as to BSA/AML compliance.  The OCC’s actions send a clear message that regulated entities offering emerging technology financial services must adhere to the same BSA/AML monitoring and reporting requirements as more traditionally regulated entities.
Continue Reading  OCC Targets BSA/AML Compliance by Anchorage Digital Bank – Only 15 Months After Granting National Trust Bank Charter to the Crypto Custodian

Consent Order Stresses that Only Three AML Analysts Struggled to Review 100 “Alerts” Per Day, Each – and Notes in Passing that “Outside Examiners” Blessed the Bank’s AML Program for the Same Five Years that the Bank Allegedly Maintained a Willfully Deficient Program

On December 16, 2021, the Financial Crimes Enforcement Network (“FinCEN”) entered into a Consent Order with CommunityBank of Texas, N.A. (“CBOT”), in which CBOT admitted to major shortcomings with respect to the implementation and effectiveness of its anti-money laundering (“AML”) program. The monetary penalties imposed on CBOT are substantial: FinCEN assessed an $8 million penalty, although CBOT will receive credit for a separate $1 million penalty to be paid to the Office of the Comptroller of the Currency (“OCC”).

The Consent Order, available here, offers valuable insight into FinCEN’s reasoning for its enforcement actions.  According to the Consent Order, CBOT has a regional footprint and operates several branches in Texas.  It serves small and medium-sized businesses and professionals.  And, in the “back of the house,” CBOT established a typical AML system designed to detect and escalate alerts for suspicious activity for investigation and potential filing of Suspicious Activity Reports (“SARs”). However, FinCEN alleged that over a period of at least four years, CBOT “willfully” failed to effectively implement its AML, program, leading to a failure to file SARs and otherwise detect specific suspicious activity.  As detailed below, many of the alleged shortcomings of CBOT’s AML program flowed from a lack of compliance resources and personnel between 2015 and 2019: too few analysts were assigned to review and investigate potentially suspicious transactions, and as a result, downstream investigations and due diligence suffered, including an alleged failure to file at least 17 specific SARs.

Because the detailed Consent Order offers a somewhat rare opportunity to glean FinCEN’s reasoning behind its enforcement actions generally, we explore the alleged failures in some detail below.  Then, we summarize key details of the Consent Order, offer key takeaways, and note several questions that the Consent Order still leaves unresolved.
Continue Reading  FinCEN Assesses Civil Penalty Against CommunityBank of Texas for AML Program Weaknesses

On December 1, 2021, the Federal Financial Institutions Examination Council (“FFIEC”) released updates to its Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Examination Manual (the “Manual”), which provides guidance to examiners for evaluating a financial institution’s BSA/AML compliance program and its compliance with related regulatory requirements.  This update is the third of 2021: the FFIEC also released updates to the Manual on February 25, 2021 and June 21, 2021.

This most recent update to the Manual adds a new introductory section, Introduction – Customers.  The updated Manual also includes changes to sections pertaining to Charities and Nonprofit Organizations, Independent Automated Teller Machine Owners or Operators, and Politically Exposed Persons (“PEP”).  The breadth of this most recent Manual update is consistent with the previous 2021 updates.  In February, FFIEC released an introductory section and updates to three sections pertaining to Customer Identification Programs (“CIP”), Currency Transaction Reporting (“CTR”), and Transactions of Exempt Persons.  In June, the FFIEC released updates to four sections pertaining to International Transportation of Currency or Monetary Instruments Reporting, Purchase and Sale of Monetary Instruments Recordkeeping, Reports of Foreign Financial, and Special Measures.

Consistent with prior FFIEC Interagency press releases associated with Manual updates, the FFIEC explained that “[t]he updates should not be interpreted as new requirements or as a new or increased focus on certain areas,” but rather “provide information and considerations related to certain customers that may indicate the need for bank policies, procedures, and processes to address potential money laundering, terrorist financing, and other illicit financial activity risks.”  Despite this disclaimer, the updates provide helpful insight into what examiners prioritize with regard to BSA/AML compliance.
Continue Reading  The FFIEC’S Third 2021 Update to the BSA/AML Examination Manual

Meaningful Overlap or Superficial Similarities?

On October 3, the release of the Pandora Papers flooded the global media, as millions of documents detailed incidents of wealthy and powerful people allegedly using so-called offshore accounts and other structures to shield wealth from taxation and other asset reporting. Data gathered by the International Consortium of Investigative Journalists, the architect of the Pandora Papers release, suggests that governments collectively lose $427 billion each year to tax evasion and tax avoidance. These figures and the identification of high-profile politicians and oligarchs involved in the scandal (Tony Blair, Vladimir Putin, and King Abdullah II of Jordan, to name a few) have grabbed headlines and spurred conversations about fairness in the international financial system – particularly as COVID-19 has highlighted and exacerbated economic disparities.

Much of the conduct revealed by the Pandora Papers appears to involve entirely legal structures used by the wealthy to – not surprisingly – maintain or enhance wealth.  Thus, the core debate implicated by the Pandora Papers is arguably one of social equity and related reputational risk for financial institutions (“FIs”), rather than “just” crime and anti-money laundering (“AML”). Media treatment of the Pandora Papers often blurs the distinction between AML and social concerns – and traditionally, there has been a distinction.

This focus on social concerns made us consider the current interest by the U.S. government, corporations and investors in ESG, and how ESG might begin to inform – perhaps only implicitly – aspects of AML compliance and examination.  ESG, which stands for Environmental, Social, and Governance, are criteria that set the foundation for socially-conscious investing that attempts to identify related business risks.  At first blush, the two are separate fields.  But as we discuss, there are ESG-related issues that link concretely to discrete AML issues: for example, transaction monitoring by FIs of potential environmental crime by customers for the purposes of filing a Suspicious Activity Report, or SAR, under the Bank Secrecy Act (“BSA”).  Moreover, there is a bigger picture consideration regarding BSA/AML relating to ESG:  will regulators and examiners of FIs covered by the BSA now consider – consciously or unconsciously – whether FIs are providing financial services to customers that are not necessarily breaking the law or engaging in suspicious activity, but whose conduct is inconsistent with ESG principles?

If so, then ESG concerns may fuel the phenomenon of de-risking, which is when FIs limit, restrict or close the accounts of clients perceived as being a high risk for money laundering or terrorist financing.  Arguably, and as we discuss, there also would be a historical and controversial analog – Operation Chokepoint, which involved a push by the government (not investors) for FIs to de-risk certain types of customers.  Regardless, interest in ESG means that FIs have to be even more aware of potential reputational risk with certain clients.  Even if the money in the accounts is perfectly legal, the next data breach can mean unwanted publicity for servicing certain clients.

These concepts are slippery, involve emerging trends that have yet to play out fully, and the similarities between AML and ESG can be overstated.  Nonetheless, it is possible that these two fields, both of which are subject to increasing global interest, may converge in important respects.  A preliminary discussion seems merited, however caveated or subject to debate.
Continue Reading  ESG, AML Compliance and the Convergence of Social Concerns

OFAC Updates Advisory on Enforcement Risks Relating to Agreeing to Pay Ransomware

First Post in a Two-Part Series on Recent OFAC Designations

On September 21, 2021 OFAC issued its first sanctions designation against a virtual currency exchange by designating the virtual currency exchange, SUEX OTC, S.R.O. (SUEX) “for its part in facilitating financial transactions for ransomware variants.”  Although this is a unique development, the broader and more important issue for any financial institution or company facing a ransomware attack is the continuing problem encapsulated in OFAC’s six-page Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments, which OFAC released in conjunction with the announcement of the SUEX designation.  The Updated Advisory illustrates a “Catch 22” scenario, in which a victim that halts a ransomware attack by making the demanded payment then may find itself under scrutiny from OFAC on a strict-liability basis if it turns out that the attackers were sanctioned or otherwise had a sanctions nexus.  The Updated Advisory states that OFAC will consider self-reporting, cooperation with the government and strong cybersecurity measures to be mitigating factors in any contemplated enforcement action.

OFAC has been busy.  Tomorrow, we will blog on a more traditional action announced by OFAC right before the SUEX designation:  OFAC’s designation of members of a network of financial conduits funding Hizballah and Iran’s Islamic Revolutionary Guard Corps-Qods Force.  This designation is notable for the targets’ alleged use of gold as a vehicle to launder illicit funds through front companies.
Continue Reading  OFAC Targets Virtual Currency Exchange For Ransomware Attack