Account takeover
Which scenario joins a login or contact-detail change to the payments that follow it?
A scenario that places here
example"Outgoing RTP payments to newly added payees after a password reset"
Channels it applies to
4 of the 20 in the dictionaryWDM RTP P2P ONL
Domestic wires, real-time payments, person-to-person payments and online and mobile banking: one sector each on the coverage chart, hatched where no scenario reaches it.
Obligations
4 regimes| Regime | Obligation |
|---|---|
| Bank Secrecy Act and its regulations (31 CFR Chapter X) | BSA BSA-AML-15 Transaction Monitoring |
| FATF 40 Recommendations | FATF R.10 Customer due diligence |
| FATF Recommendation 16, payment transparency, by paragraph | FATF R.16 INR16.30 Beneficiary institution: detecting misdirected payments through alignment checks |
| Anti-Money Laundering and Counter-Terrorism Financing Act (Australia) | AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring |
The obligations, quoted
BSA BSA-AML-15 Transaction MonitoringAutomated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.
Where programmes usually fall short: No model validation; Scenarios not aligned to risk assessment
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
FATF R.10 Customer due diligenceFinancial institutions may not keep anonymous accounts or accounts in obviously fictitious names and must, by a principle set out in law, undertake customer due diligence when establishing a business relationship, carrying out an occasional transaction above USD or EUR 15,000 or a payment or value transfer covered by INR.16, when money laundering or terrorist financing is suspected, or when they doubt previously obtained identification data: identify and verify the customer from reliable independent sources; identify the beneficial owner and take reasonable measures to verify that identity, understanding the ownership and control structure of legal persons and arrangements; understand and where appropriate obtain information on the purpose and intended nature of the relationship; and conduct ongoing due diligence and transaction scrutiny consistent with the customer's profile including, where necessary, the source of funds. The extent of each measure follows a risk-based approach; verification takes place before or during establishment of the relationship, or as soon as reasonably practicable after it where risks are managed and business would otherwise be interrupted; an institution that cannot complete CDD does not open the account or perform the transaction, or terminates the relationship, and considers a suspicious transaction report; the requirements apply to new customers and, on materiality and risk, to existing ones. The Interpretive Note sets the risk-based approach, enhanced and simplified measures, the specific measures for legal persons, arrangements and beneficiaries of life insurance, reliance on prior verification and the timing rules.
Where programmes usually fall short: Beneficial owner identified but never verified; Ownership and control structure of corporate customers not understood
Source: FATF 40 Recommendations
FATF R.16 INR16.30 Beneficiary institution: detecting misdirected payments through alignment checksFor cross-border transfers above the threshold the information received on the intended beneficiary informs the beneficiary institution's monitoring, aimed at detecting misdirected payments from possible laundering, fraud or error, and it mitigates the risk of transfers reaching an unintended beneficiary through at least one of: a per-transaction check of the extent to which the beneficiary name and account number in the message align with its own records (alignment need not be an exact match and may vary with risk and context); holistic ongoing risk-based monitoring for anomalous accounts, transactions and activity including misaligned beneficiary information; or, where both institutions participate in a pre-validation mechanism such as confirmation or verification of payee, that pre-validation in place of the other two.
Where programmes usually fall short: No alignment check of any kind; Exact-match rule generating false rejections without risk basis
Source: FATF Recommendation 16, payment transparency, by paragraph
AUSTRAC AMLCTF-PartA-TxnMon Transaction MonitoringSystems and controls for monitoring customer transactions for unusual or suspicious activity.
Where programmes usually fall short: No transaction monitoring
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)