Using a risk-based approach to combat financial crimes
Financial crimes of various sorts are a serious challenge to organisations operating in this sector. A risk-based approach to business is key to effectively combating such felonies.
In recent years, financial crime has increasingly become of concern to both governments and financial institutions around the world, particularly crimes like money laundering, terrorist financing, fraud, bribery and corruption.
In the financial services sector, managing risk is perhaps the key discipline, but while those in the financial services sector (FSS) are accustomed to managing perils in areas like credit risk or market risk – which are easily calculated and quantified – assessing financial crime risks is different. These are called ‘consequential’ risks, meaning some risks here may only become evident once the customer began transacting through the account.
It is for this reason, says Jaco van der Merwe, Capability Architect at Ovations Group, that the monitoring of customer transactions is a fundamental component of the risk-based approach (RBA). This approach requires FSS organisations to identify, assess and understand each of the risks to which they are exposed, and then to target their resources at the most serious risks and de-prioritise where required.
“With the implementation of the Financial Intelligence Centre Act (FICA), South African accountable institutions are now required to implement a risk-based approach to manage money laundering and terrorist financing risks. This has introduced several challenges to the banking industry, such as updating policies, procedures and processes, as well as the training of resources. To ensure compliance to FICA, accountable institutions chose to establish risk management and compliance programmes accordingly,” says Van der Merwe.
“Conducting a Business Risk Assessment is about determining an organisation’s inherent risk (IR). This represents their exposure to money laundering and sanctions risks in the absence of any control environment being applied. After the design and implementation of anti-money laundering and sanctions controls, and in combination with other business controls, IR is ultimately reduced to residual risk (RR). After all efforts to identify and eliminate risk have been made, RR is the threat that remains.”
Furthermore, when talking about risk, he adds, it must be remembered that the COVID-19 pandemic has also had a significant impact on enterprises around the world, and it is important that organisations put policies, processes and procedures in place to minimise the impact of the virus and to ensure business continuity.
“However, these operational changes can introduce additional risks into a business. Therefore, it is clear that these organisations will benefit from the execution of a risk assessment to assess whether their controls are still effective in managing the risks, in the aftermath of the pandemic.
“Adopting a risk-based approach to compliance management is necessary in today’s complex FSS environment. Such an approach requires entities to not only be able to understand the various laws and regulations with which they are required to comply, but also the impact that non-compliance with each of these will have on the organisation. With such knowledge, organisations can decide on the number of resources to employ to manage compliance risk. They can also decide how to deploy their resources, focusing firstly on the highest risk areas identified and following up with those that have less of an impact.”
When it comes to indicators that can enable the assessment and measurement of the level of risk, continues Van der Merwe, one must interrogate the details relating not only to the customers themselves, but also their country of origin, the industry in question, the channel being utilised and even the products and services involved.
“Although these risk factors are crucial to establish the clients' risk profile, we are seeing a shift to a more entity-centric, risk-led approach, something that is underpinned by a technology-enabled scenario involving continuous scoring of risks across a customer's interactions,” he states.
“The benefit of such an approach is that it provides a continuous, timely and comprehensive understanding of clients and counter-parties across previously siloed risk areas. Specific enabling technologies are vital in delivering the required support for an entity-centric, risk-led approach, and can include agile platforms and scalable data access, advanced data management and algorithms, predictive modelling based on data science, process automation and optimisation, behavioural risk models and integrated due diligence.”
Ultimately, a risk-based approach is considered an important component in the initial client onboarding process, Van der Merwe adds. It is at this point that FSS entities can establish a risk assessment strategy, which can help to mitigate and assess the risks involved in dealing with high-risk customers, not to mention the ongoing due diligence required to mitigate these risks.
“Financial crime is a global concern and companies can no longer only focus on their home base – instead, they need to be aware of the risks in every country in which they operate. Moreover, constantly changing laws and regulations, onboarding of new products, services and clients, each with their own degree of risk, necessitates that organisations ensure they assess their risk-based approach in a way that ensures it aligns with their risk appetite," he concludes.
- Input into the article by Roy Melnick, Director at Financial Crime Risk Management Consultants.