It’s a Marathon, Not a Sprint – Advancing the Discipline of Customer Due-Diligence

The way in which your firm performs customer due diligence is like an athlete training for the Olympics. Athletes spend years working towards their goal – they research the best foods to eat, weights to lift, paths to run. They carefully pick a coach with a winning record and dedicate hours every day (sometimes all of the hours of the day) to training. Without this daily dedication to improved strength, the athlete will never achieve the Olympic dream. No Olympian ever went to a coach, performed a perfect 10 on their first day, and then quit. That’s because it requires ongoing improvement and strength building to perform at peak levels, just like customer due diligence. Businesses need to move from a “job done” philosophy to the ongoing monitoring needed to truly understand their full business relationship over the long-term with customers.


As a core discipline of operational risk, customer due diligence is the process of understanding your customers’ history, future intentions, expectations, and what you can anticipate during the business relationship.


Though customer due diligence is not new, financial crimes are increasingly complex and difficult to detect, accentuated by the increasing pace of innovation in financial markets which lead to greater competition and constantly evolving financial crime threats. However, with global money laundering estimated between 715 billion and 1.87 trillion euros1, increasing financial crime risks threaten the sustainability of the global financial system.


There are two types of financial crimes to consider for your risk management framework:


  • Dishonest activities that generate wealth for those directly involved with conducting financial crime (i.e. cybertheft, human trafficking, terrorism, political risks); and
  • Activities that involve protecting wealth or other goods obtained or that facilitate the procurement of such things (i.e. bribery, money laundering, tax avoidance, fraud)

The cost of failing to perform due diligence


Ask an athlete why they do practice every day without fail, and they’ll tell you that the more they do it, the more confident they are in their own strength. In business, this confidence translates to entering into riskier customer segments or higher-risk markets in the pursuit of higher returns. These higher risk segments typically include those closer to political risk and those that may be more motivated to be involved with committing financial crimes (whether directly or not).


Risk management of financial crime is a well-established discipline, but it’s often overlooked as a core pillar of risk management for several reasons, including:


  • The need to move quickly in the market in pursuit of profits
  • An increased risk appetite for higher customer risk segments
  • Evolving geopolitical risks requiring new legal entity and operating structures
  • Language and cultural differences that make explaining due diligence difficult
  • The complexity of performing due diligence checks including concerns about:
    • Pressure from management to achieve sales and growth targets
    • No standardised data across regulatory agencies across countries and regions
    • Lack of central repository for companies to source data
    • Manual and time-consuming nature of checks
    • Frequently changing and evolving regulations making it difficult to keep up

While these apprehensions hold some merit, the cost of failing to perform appropriate customer due diligence is high. In 2019, the Financial Conduct Authority imposed five times as many fines to companies involved in financial crimes – crimes that often occur when companies work with customers they have not vetted adequately (see Cases 1, 2, and 3 below).


In several of the cases, the financial institutions were aware of the risks they were taking but did not have the risk management discipline to detect, mitigate, and prevent systemic failures. In other cases, risk management frameworks were not updated or prepared to address more modern methods of abuse.


Case 1. A British bank’s AML shortcomings

In April 2019, a British multinational banking and financial services firm was fined £102.2 million for “serious and sustained shortcomings” in the bank’s anti-money laundering (AML) controls. According to the Financial Conduct Authority’s report, issues like an account opened with £500,000 cash from a suitcase with no investigation into the origins of the funds was among the breaches in maintaining appropriate measures to prevent financial crimes risk.


Case 2. An Australian bank’s failure to report

In November 2019, an Australian bank was accused of more than 23 million breaches of laws including those connected with facilitating child exploitation, terrorism financing, and money-laundering. The bank was warned their low-cost international transactions were a risk but failed to appropriately address the issue. In addition to a $700 million fine, the bank reported it had experienced its worst earnings ever and shares in the bank dropped dramatically.


 Case 3. A Danish bank’s suspicious transactions

Between 2007 and 2015, a branch of a Danish financial institution failed to ensure proper oversight of over €200 billion of suspicious transactions from Russia and several former Soviet states. The alleged money laundering led to the investigation of 12 employees, cessation of the financial institution’s ability to operate in the country where the incident took place, and the former CEO and nine other senior managers were charged with Serious Economic and International Crimes. Further, the stock price has declined enough that there has been significant damage to shareholder value.


Financial crime oversight is increasing in complexity and becoming more comprehensive. Firms must know how customers are using the firm and how they plan to continue using the firm throughout the business relationship.


The pressure of social responsibility


The criticality of due diligence is about more than simply avoiding fines. It also means being socially responsible and accountable to customers, investors, and shareholders alike. An intergenerational shift in consumer values has led to pressure on companies to act with more transparency to earn the brand loyalty of consumers.


By adopting leading practices of financial crime risk management, you can improve the speed of customer onboarding while improving the overall relationship with the customer. As a result of integrating automated financial crime controls for ongoing monitoring of criminal activity into your firm’s operational and risk management practices, you will demonstrate your commitment to upholding the highest measure of social and governance standards.


Companies found to be involved in practices that link them to financial crimes can leave legitimate customers questioning the integrity of the brand. With the proliferation of social media, customers are better armed to spread information and build dissatisfaction. Rather than viewing customer due diligence as a box-ticking exercise for the regulators or a cost to the firm, having sound due diligence processes will build trust in your brand, help you prevent reputational damage, and build long-term, sustainable customer relationships.

“…the sheer scale of impact caused by financial crimes is a significant threat itself to the stability and reputation of the financial system.”

In many respects, the volume, consistency and increasing severity of financial crimes within the global financial system underpins the need for stringent regulatory requirements supported by strong regulatory governance. Market participants have not yet demonstrated the ability to represent the best interests of their customers when it comes to identifying, managing, monitoring, and governing financial crimes. This is not to suggest that there are not leading examples of financial crime risk management, but that the sheer scale of impact caused by financial crimes is a significant threat itself to the stability and reputation of the financial system.


Controls to prevent financial crimes


As established earlier, detecting financial crimes requires fresh thinking to enhance detection techniques that keep pace with the speed at which threats are advancing. While these techniques are evolving, there are control standards that every organisation should establish as a minimum threshold. These include:


  • Having clear documentation of policies, frameworks, and procedures demonstrating your approach to complying with regulatory requirements that are regularly reviewed and updated
  • Performing thorough due diligence and ensuring management oversight where a firm uses a third party to generate business and rolling out the firm’s framework to these third parties
  • Obtaining information about the purpose and nature of the business relationship to understand if there are associated money laundering risks
  • Gaining a better understanding of the customer’s or beneficial owner’s reputation and/or role in public life and assessing how this affects the level of risk associated with the business relationship
  • Checking and documenting ownership and control structures of corporate clients including the reasons for any complex corporate structures
  • Establishing the source of the customer’s or beneficial owner’s funds or wealth to be satisfied that they are not comprised of proceeds from crime
  • Using electronic verification of banks and individuals and screening for links to PEPs, sanctions, or adverse media (and regularly updating the databases/systems)
  • Obtaining further clarity, approval of senior management, or MLRO consent to enter the business relationship in high risk situations

The benefits of customer due diligence


To have a strong financial or operational risk control environment, you have to give your customer due diligence the same attention athletes give to their training schedule. Establishing ongoing competence in your customer due diligence program has several benefits, including:


  • Building trust between your firm and the customers you serve and increase confidence in your ethical standards
  • Boosting your firm’s reputation as a reputable business to conduct business
  • Providing competitive leverage when systemic failures occur
  • Mitigating involvement in and/or facilitation of financial crimes
  • Ensuring compliance with regulatory and legislative obligations
  • Avoiding financial penalties and reputational damage

Customer due diligence is a multifaceted discipline that requires ongoing, proactive risk management. Create a starting point for forecasting that details where and when financial crimes may happen within the market, and as you move into high-risk customer segments, look into innovations that help prevent, avoid, or mitigate threats from more intelligent criminal activities.


Have you assessed the strength and ability of your firm’s control environment to mitigate financial crime risk to your firm’s brand value and social and governance commitments?

Have you assessed how your approach to financial crime should vary by market, product, or customer segment?

This publication contains general information only and Risk Panorama is not, by means of this publication, rendering business, or other professional advice or services. This publication is not a substitute for such professional advice or services; nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult with a professional advisor. Risk Panorama shall not be responsible for any loss sustained by any person who relies on this publication.

Subscribe
Notify of
guest

0 Comments
0
Would love your thoughts, please comment.x
()
x