Wednesday, 16 January 2019

The compliance function at an inflection point - Views on the McKinsey benchmark


In McKinsey’s 2018 compliance benchmarking survey https://www.mckinsey.com/business-functions/risk/our-insights/the-compliance-function-at-an-inflection-point. 5 conclusions are drawn from the analysis among 24 leading banks:
  • Compliance spending growth is slowing
  • Size and effectiveness of the compliance function are not yet in balance
  • Compliance maturity is not high
  • Automation and analytics remain a challenge
  • Spending more on technology does not guarantee maturity

No surprises in these findings, but let me make 1 observation and talk about 2 of the recommendations.

First the observation. If people talk about the cost of compliance, the focus is often on the compliance function; the 2nd line of defence. I assume that McKinsey is no different. However, the cost of compliance involves all staff that are performing work on compliance processes, whether that is explaining policies to clients, clarifying monitoring alerts or obtaining documentation required from clients for the sake of the customer due diligence process. Plus of course the dedicated AML operations teams. The number of FTEs in the 1st LoD is easily 10 or even 20 times as high as the number of FTEs working on Financial Economic Crime in the 2nd LoD. Achieving operational compliance needs a focus on the 1st LoD.

Secondly a few notes on 2 of the recommendations in the article

-             Strengthening risk ownership in the first line

This recommendation is a no-brainer; client contact and operational tasks are executed in the 1st LoD. The compliance function instructs, advises and checks but the actual work is done in the 1st line, if something goes wrong from a compliance point of view it is usually there. The fact that ownership in the 1st LoD is still not where it should be, is troubling. Despite all the fines, publicity, tone-at-the-top workshops and more it’s disappointing that bankers apparently still don’t get the message.

-          Streamlining compliance processes in the first line

Streamlining is perhaps an oversimplification; to achieve an operationally compliant financial institution you need compliance with all policies, proper and prompt customer services and efficient execution of operational process. Every day, with every transaction, with every client interaction, in every corner of the bank. This is best achieved under single headed ownership; meaning that there is 1 person in the 1st LoD ultimately responsible for the adherence to FEC policies.


There’s still a lot of work to be done for FIs globally; in the first line of defence.

Wednesday, 9 May 2018

Quality Assurance in Customer Due Diligence

It's not easy 'to get it right' in the art or craft of Customer Due Diligence. What's even more difficult is to measure quality and demonstrate that your institution is meeting all quality requirements.
We had a look at a solution called  KYC Quest  it's still in development but nevertheless promising.


It's an interesting regtech initiative based out of Amsterdam which provides financial institutions with automated questionnaires to perform Enhanced Due Diligence. It guides users through all regulatory steps, helps to identify and mitigate risks and enforces a 4-eye process.

It not only adds control but also increases efficiency in the KYC process while at the same time increasing the quality assurance and auditability significantly.  

We'd  like to hear from you if you're struggling with your Quality Assurance and Improvement discipline, perhaps we can be of service.

Thursday, 30 November 2017

The ugly truth about compliance and…..what to do about it


This article 7 ugly truths for compliance officers is not new but the observations still hold.
Compliance is not a favorite topic for many in financial institutions and it’s still extremely hard ‘to get it right’ for any organization. So why is that? Let us share the i-KYC view on this.
First and foremost, the reach of ‘compliance’ or ‘the 2nd Line of Defense’ is (very) limited. It’s not uncommon to have only 1 or 2 compliance officers focused on FEC in an organization with over 1000 staff.
Secondly, the compliance team often focuses on policy setting and case handling. That’s what they should do but that leaves little time for other activities.
Thirdly, most compliance programs focus on rules, regulations and policies. Once policies are implemented, the compliance team ensure the policy is rolled out and will furthermore test the design of SOPs and individual (high risk) cases against the policy. That hardly reaches the entire institution.
These observations point all to 1 key issue: operational compliance can only achieved by the 1st Line-of-Defense. And often nobody is responsible for operational compliance across the organization since AML/CFT touches almost all departments, divisions and units of a financial institution, which makes it difficult to point at 1 accountable department.
Achieving operational compliance needs to be a formal goal for the organization and one executive needs be made accountable for this. Only then there’s a good chance to ‘get it right’.
If you want to know how contact us.

#compliance
#FEC
#AML
#CFT
#AML/CFT
#operational compliance
#financial services
#financial institution



Friday, 26 May 2017

Pakistan is not the only country where this can happen

This article published in ‘Dawn’ last year not only describes the K&K case clearly but at that highlights some of the underlying issues in Pakistan. A large informal economy, a tradition of sending money abroad and widespread use of hawala networks are the 3 basic factors. Then there’s a widespread use of over- and under-invoicing and the use of other Trade Based Money Laundering techniques involved. Add to that the difficulty to actually prove the money transferred is related to crime and you have a recipe for the disaster described.

A question that comes to mind though is: would a proper country risk assessments have revealed these issues? And: wouldn’t it make sense to do a risk assessment at country level in other counties were similar situations are expected? Just to prevent cases like this. 

Tuesday, 9 May 2017

The impact of MyInfo in Singapore on the cost of compliance

The MAS had already announced it a while ago but newspapers are picking up on the news of an ‘account opening utility’ now as well (StraitsTimes). The idea is not new of course but it is an achievement and definitely good news for the (individual) customer. Instead of having to fill out forms and bring along different original documents to open an account, an individual Singaporean customer will in future just have to do that once with MyInfo. Thereafter banks can use that information combined with the already available public information for their internal account opening process knowing that all regulatory requirements on documentation have been met.
Is this solving ‘all’ problems with account opening and client onboarding though? Let’s analyze the impact.
For individuals, opening a bank account will become easier, but likely a prospective client will still have to provide information to the bank and will have to sign forms, signature cards, consent forms etc. Not all information that a bank needs to meet regulatory requirement will be in MyInfo
For banks it means a more streamlined onboarding process and the ability to offer a better customer experience.
The harmonization of account opening requirements is a major achievement and creating a common repository for account opening documentation will reduce the burden for individuals to open an account. Further integration with the banks’ Apps and extending the service to more products will even make life more convenient.
If this helps banks in their overall CDD and KYC efforts is yet to be seen. For most banks the bulk of the ‘cost of compliance’ sits in periodic reviews of commercial clients. MyInfo will not provide much relief for that issue. 

Thursday, 9 February 2017

Lack of confidence in your AML/CFT program? Why?

A substantial number of compliance officers (about 44 per cent) lack confidence in the anti-money laundering (AML) programs of their organizations, according to a new report
That’s an interesting finding since compliance officers are ultimately responsible for compliance of the whole organization in their role as MLRO. The pace and complexity of changes are mentioned as causes as well as insufficient clarity of regulations. Investments in AML programs have gone up and are expected to increase also because of ongoing technological innovations.
The article quotes: Nadim Najjar, managing director, Middle East and North Africa, Thomson Reuters: “The business of compliance, which in the past was seen by many as a mere tick box exercise, has become incredibly dynamic. It has evolved into a critical, demanding role that challenges executives to stay up-to-date and conversant with regional and global regulatory change and information.”
All the reasons make sense and we see many of our clients working hard to improve their AML/CFT policies, processes and procedures. What is not mentioned – and is often still not sufficiently recognized – is that interpreting regulations into policies is only the beginning of the implementation of an AML/CFT Program.
Implementing policies in all operational areas of a financial institution would need to cover branches, trade finance departments, customer service teams, relationship managers and transaction processing units. Where the compliance function sits in the 2nd line of defense, a lot of heavy lifting in daily operation sits in the 1st line of defense.

That’s exactly what we focus on. 

Thursday, 8 December 2016

The bank’s responsibility or not?

The Financial Times last weekend reported on the MAS banning a banker from operating in the Singapore market for 10 years due to wrongdoings found in the 1MD investigation in this article . “Mr Leissner was found by the MAS to have issued an unauthorized reference letter, using Goldman Sachs letterhead, to a financial institution based in Luxembourg in June 2015.”

Two things are remarkable about this:
1.       Maybe 10 years is a long time but it’s ‘just’ a prohibition to work in Singapore. If you know how difficult it is to get a work permit in Singapore this can hardly be seen as a punishment. There are millions of people who want to work in Singapore and cannot. It doesn’t appear to be a harsh or severe treatment. Certainly not if you take into account that Goldman received 300 million in fees for the transaction of which mr Leissner without doubt got a handsome share.
2.       Secondly it’s puzzling that a person can be banned for doing something while his employer goes completely free. If a person is doing something that is not allowed he or she should be held accountable but if the person is doing that as an employee also the employer should be held accountable I’d say


Interesting..