AML Scenario Gap Finder

Business email compromise

Which scenario reads a business paying a known supplier at new bank details for the first time?

A scenario that places here

example

"Business email compromise: first-time payee with changed bank details"

Read this scenario

Channels it applies to

3 of the 20 in the dictionary

ACH WDM WIN

ACH and direct entry, domestic wires and international wires: one sector each on the coverage chart, hatched where no scenario reaches it.

Obligations

4 regimes
RegimeObligation
Bank Secrecy Act and its regulations (31 CFR Chapter X)BSA BSA-AML-15 Transaction Monitoring
FATF 40 RecommendationsFATF R.10 Customer due diligence
FATF Recommendation 16, payment transparency, by paragraphFATF R.16 INR16.30 Beneficiary institution: detecting misdirected payments through alignment checks
Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring

The obligations, quoted

BSA BSA-AML-15 Transaction Monitoring

Automated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.

What an examiner asks to see: TM scenario inventory; Threshold tuning documentation; Above-the-line/below-the-line testing; Model validation reports
Where programmes usually fall short: No model validation; Scenarios not aligned to risk assessment
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
FATF R.10 Customer due diligence

Financial institutions may not keep anonymous accounts or accounts in obviously fictitious names and must, by a principle set out in law, undertake customer due diligence when establishing a business relationship, carrying out an occasional transaction above USD or EUR 15,000 or a payment or value transfer covered by INR.16, when money laundering or terrorist financing is suspected, or when they doubt previously obtained identification data: identify and verify the customer from reliable independent sources; identify the beneficial owner and take reasonable measures to verify that identity, understanding the ownership and control structure of legal persons and arrangements; understand and where appropriate obtain information on the purpose and intended nature of the relationship; and conduct ongoing due diligence and transaction scrutiny consistent with the customer's profile including, where necessary, the source of funds. The extent of each measure follows a risk-based approach; verification takes place before or during establishment of the relationship, or as soon as reasonably practicable after it where risks are managed and business would otherwise be interrupted; an institution that cannot complete CDD does not open the account or perform the transaction, or terminates the relationship, and considers a suspicious transaction report; the requirements apply to new customers and, on materiality and risk, to existing ones. The Interpretive Note sets the risk-based approach, enhanced and simplified measures, the specific measures for legal persons, arrangements and beneficiaries of life insurance, reliance on prior verification and the timing rules.

What an examiner asks to see: CDD policy and procedures with triggers and thresholds; Customer files with identity, beneficial ownership, purpose and risk rating; Ongoing monitoring and periodic review records
Where programmes usually fall short: Beneficial owner identified but never verified; Ownership and control structure of corporate customers not understood
Source: FATF 40 Recommendations
FATF R.16 INR16.30 Beneficiary institution: detecting misdirected payments through alignment checks

For cross-border transfers above the threshold the information received on the intended beneficiary informs the beneficiary institution's monitoring, aimed at detecting misdirected payments from possible laundering, fraud or error, and it mitigates the risk of transfers reaching an unintended beneficiary through at least one of: a per-transaction check of the extent to which the beneficiary name and account number in the message align with its own records (alignment need not be an exact match and may vary with risk and context); holistic ongoing risk-based monitoring for anomalous accounts, transactions and activity including misaligned beneficiary information; or, where both institutions participate in a pre-validation mechanism such as confirmation or verification of payee, that pre-validation in place of the other two.

What an examiner asks to see: The chosen alignment method and its design; Alignment mismatch handling records; Participation in a confirmation-of-payee scheme where relied on
Where programmes usually fall short: No alignment check of any kind; Exact-match rule generating false rejections without risk basis
Source: FATF Recommendation 16, payment transparency, by paragraph
AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring

Systems and controls for monitoring customer transactions for unusual or suspicious activity.

What an examiner asks to see: Transaction monitoring system & rules; Alert investigation records
Where programmes usually fall short: No transaction monitoring
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)

Other typologies in fraud-adjacent laundering