This article is a compilation of the major anti-money laundering and counter terrorist financing (CFT) trends for the year 2020.

 

1. Increased money laundering (ML) threats

New threats and vulnerabilities arising from COVID – 19 related crimes impacted on money laundering and terrorist financing risks. Businesses are being conducted online with individuals working from home. The year 2020 has also seen a surge in the sale of medical equipment and medications. Banks and financial institutions are also functioning remotely with limited in – person banking.

Criminals are taking advantage of the COVID – 19 pandemic and according to the Financial Action Task Force (FATF) observers and open source information, criminals are indulging in the following fraudulent activities or ‘medicrimes’:

  • Impersonation of government officials with the intent of obtaining personal banking information or physical cash for medical or tax purposes;
  • Online scams involving counterfeit essential goods where the criminals claim that they are from reputed businesses;
  • Fundraising for fake charities and funds; and
  • Fraudulent investment schemes claiming that the products or services of publicly traded companies can prevent, detect or cure COVID – 19.

In the above instances, we note the misuse of foreign legal entities and scamming website which stand as duplications of genuine on-line shopping websites and businesses. Front companies were also created to aid in channeling economic relief and demonstrating a real commercial activity with significant volume, and which were in fact, ML vehicles.

According to MONEYVAL, a FATF-style regional body, Financial Intelligence Units (FIU) reported ‘a moderate increase in number of STRs potentially related to supplies of unsafe and/or unreliable imported products doubled by forged or absent conformity certificates (e.g. for the medical goods).’

 

2. Cyber Crime

With the COVID – 19 restrictions, the overall level of criminality remained stable or slightly decreased owing to the restrictions in physical movement and cross – border travelling. However, a surge was noted in certain crimes with transnational elements, such as cybercrime, creating new sources of proceeds for ML purposes.

The demand for online communication and purchases let to people sharing more personal payment information. Authorities saw an increase in phishing emails and text messages containing links to malicious websites and attachments to obtain payment information. Often, this was in the form of a link which when clicked, causes the loss of personal data, infects the electronic device and installs malicious tracking software.

 

3. Fines and Penalties

Enforcement actions and penalties for non-compliance with anti – money laundering laws have increased. The Bank Fines 2020 report reveals the list of banks fined by regulators for various violations. The total aggregated bank fines in 2020 stand at $ 17.74B with the largest fines issued to Goldman Sachs amounting to $ 3.90B. Overall, the banks were fined for the following AML breaches:

  • Allowing the use of corporate accounts as a personal piggy bank;
  • Creation of fake accounts over years;
  • Manipulation of precious metals and treasury markets;
  • Conspiracy to commit ML;
  • Deficiencies in managing ML risks and lack of and/or inefficient use of internal controls;
  • Ignoring red flags and going ahead with transactions; and
  • Misleading the regulator in investigations.

US regulators have, historically, been the toughest enforcers of AML rules and for out of the top 10 banks fined, we find 6 banks in the United States.

 

4. Customer Due Diligence (CDD)

The year 2020 also saw the inclusion of digital ID system in CDD. The FATF Guidance on Digital ID published in March 2020 sets forth how this system works.; bearing in mind that digital ID is to be applied using the risk-based approach. For high risk customers, the regulated entity must determine if the system is developed and functional enough to cater for these types of applicants for business or customers. Institutions embracing the use of digital ID must ensure that there are anti – fraud and cyber security processes in place to cater for digital identity proofing, binding, portability and authentication for AML/CFT purposes. The following are instances where digital ID systems are being/can be used:

  • Accepting scanned copies of documents and performing electronic verification to establish the authenticity of the documents/ information;
  • Using digital credentials;
  • Using biometrics such as facial and voice recognition and fingerprint analysis;
  • high-resolution video transmission (allowing for remote identification and verification and proof of “liveness”);
  • digital device identifiers and related information (e.g., MAC and IP addresses); and
  • mobile phone numbers, SIM cards, global position system (GPS) geolocation).

 

5. Ultimate Beneficial Owner (UBO)

In terms of UBO disclosure, the United States, with the Corporate Transparency Act 2019, are aiming to increase transparency on ultimate beneficial ownership disclosure. Under this Act, both new and existing corporations, including LLPs must now disclose UBO information to the Financial Crimes Enforcement Network (FINCEN). Financial institutions are required to identify and verify the identity of any natural person holding 25% or more of a legal entity. In case no natural person is identified, there is an obligation to identify the controlling persons of the entity. While UBO details are disclosed to FINCEN, in Europe, the member states are working on their specific registries and have to ensure that information on the beneficial owner is accessible “in all cases to competent authorities, obliged entities, within the framework of customer due diligence and member of the general public that are permitted to access at least the name, the month and year of birth and the country of residence and nationality of the beneficial owner as well as the beneficial interest held.” For trusts and other legal arrangements, access to trust information is limited to individuals with legitimate interest on the trust. The central registers should be interconnected via the European Central Platform by 10 March 2021

 

6. Central Bank Digital Currency (CBDC)

Central banks around the world are exploring the idea of state-backed digital currencies. These interests turned into action are partly owing to the COVID – 19 outbreak which forced people to opt for digital payments to avoid spreading virus due to the usage of cash and help people in lockdowns or working remotely carry on with their life. Bahamas launched a pilot project for a CBDC in 2019 and in October 2020, the country launched the Sand Dollar. Bahamas is the first country in the world to officially launch a CBDC. Currently, the United States and the European Union have established a proof of concept for a CBDC. China and South Korea have each introduced a CBDC on a pilot program. Other countries like France and South Africa have launched a research to determine the potential benefits of a CBDC.

 

7. Sanctions

As for sanctions compliance, trends denote that sanctions are becoming more targeted, requiring greater precision and nuance to comply. There is an increased expectation of the regulators that reporting persons demonstrate sanctions compliance backed by proof of internal controls applied. This proof can either be in the form of a screening reports kept on record where the screening is performed manually, or an audit trail which is time-stamped when automated screening tools are used.

This year, the United States imposed additional sanctions targeting Iran’s construction, mining, manufacturing, and textiles industries through the Executive Order 13902 in order to deny the Iranian government financial resources that may be used to fund and support its nuclear program, missile development, terrorism and terrorist proxy networks, and malign regional influence. Moreover, in response to the authoritarian leadership of Nicolás Maduro, the Office of Foreign Assets Control (“OFAC”) of the US Department of the Treasury, targeted some 159 Venezuelan and Venezuelan connected individuals, and has revoked the visas of more than 1,000 individuals and their families. Sanctions were also imposed on the state-owned oil company of Venezuela, ministers, senior officials and central bank. OFAC also sanctioned entities and vessels facilitating Venezuelan oil transactions. We also note that OFAC continues to slap Syrian individuals and entities close to the regime of Bashar Al – Assad in response to the Syrian government’s support of international terrorism and democratic and human rights violations. Targets are in the army, intelligence, telecommunications, private security and transportation industries. The Caesar Syria Civilian Protection Act of 2019 provides the US with tools to help end the conflict in Syria by promoting accountability for the Assad regime. The Caesar Act entered into force and the US Treasury in 2020 designated individuals and entities related to the Syrian government as well as third-party individuals and entities providing direct or indirect assistance to the government. The first designations targeted individuals and entities involved in luxury real estate projects that directly or indirectly generate revenue for the Syrian government. Sanctions on North Korea remain in force with added targets involved in illicit cyber and maritime activities. In terms of development in the sanctions landscape, we note the imposition of sanctions on Chinese government officials in response to human rights abuses against the Uyghur people. The US also imposed sanctions on senior officials of the Chinese Communist Party for undermining Hong Kong’s autonomy and restricting the freedom of expression or assembly.

In the European Union (EU), we note that the European Council imposed the first ever sanctions against cyber-attacks in July 2020. The restrictive were adopted against six individuals and three entities responsible for or involved in the attempted cyber-attack against the Organisation for the Prohibition of Chemical Weapons) and the cyber – attacks publicly known as ‘WannaCry’, ‘NotPetya’, and ‘Operation Cloud Hopper’. The European Council imposed additional sanctions for human rights abuses and arms embargo violations on Libyan individuals and entities whose actions threaten the peace and security of Libya or obstruct the successful completion of its political transition. In September 2020, the European Council also imposed restrictive measures against individuals identified as responsible for repression and intimidation against peaceful demonstrators, opposition members and journalists in the wake of the 2020 presidential election in Belarus, as well as for misconduct of the electoral process. In an attempt to address human rights violations and abuses, the United Kingdom adopted the Global Human Rights Sanctions Regulations 2020, targeting state and non – state actors involved in serious human rights violations such as the killing of Jamal Khashoggi, persecution and torture of LGBT persons in Chechnya, mistreatment of Sergei Magnitsky which contributed significantly to his death, and torture, and degrading treatment of detained protestors and journalists in Belarus. The biggest development for the European Union happened on the 7th of December 2020 whereby the European Council came forward with its own global human rights sanctions regime. For the first time, the EU is equipping itself with a framework that will allow it to target individuals, entities and bodies – including state and non-state actors – responsible for, involved in or associated with serious human rights violations and abuses worldwide, no matter where they occurred.

 

End Note

2021 will see the coming into effect of the 6th Anti –Money Laundering Directive. Authorities will be empowered to go after those who are “aiding and abetting” and “attempting and inciting” in money laundering offences. In the EU still, criminal liability will be extended to legal persons involved in the commission of financial crimes. Globally, with a shorter timeframe to compile and submit suspicious transaction reports, the compliance function will face more pressure to become more efficient. Moreover, will the obligation to disclose beneficial ownership information, institutions will need to keep their client records up-to-date through remediation, ongoing monitoring and periodic file review. With the FATF Guidance on Digital ID, we will also see the increasing application digital identification and verification in the CDD process.

In terms of sanctions, after the Brexit transition period, EU sanctions will no longer apply in the UK after 11pm on 31 December 2020. UK sanctions regimes will come into force under the Sanctions and Anti-Money Laundering Act 2018 (the Sanctions Act) from that time. Concerning the US sanctions regime, Joe Biden’s team plans to conduct a review of the sanctions programs in place.