JD Supra Banner
Regulatory Risk Advisory

Correspondent Banking: 25 Years After 9/11, What's Changed?

 By 

Stanley Foodman

A quarter of a century since the tragic events of September 11, 2001, correspondent banking continues to be a quandary when it comes to anti-money laundering (AML) and countering the financing of terrorism (CFT). In the aftermath of that tragic day, correspondent banking was pointed to as a glaring compliance weak point in terms of AML, CFT and know-your-customer (KYC) compliance. Part of the response was the passage of the Patriot Act which, at the time, was said to make correspondent banking costly and cumbersome – with some financial institutions severing ties with their foreign correspondents altogether.

Since then, we have seen the passage of the Foreign Account Tax Compliance Act, or FATCA, with its added know-your-customer KYC) and the more recently the Anti-Money Laundering Act (AMLA), in addition to the earlier Nixon-era Bank Secrecy Act (BSA).

The way things were and the road forward

Pre-9/11, many rules regarding AML and financial crime at the federal level were uniform. Before the Patriot Act, there were few rules on correspondent banking as it was not considered a high-risk proposition.

Then and now, different geographic and demographic areas get different degrees of attention based on their risk assessment – which hinges on who overseas compliance at a particular bank and what its risk appetite is.

Moving forwards, correspondent banking will continue to be a high-risk service offering – with it requiring six to 12 months to open a correspondent account in certain parts of the US. An aspect has become riskier is the possibility of Office of Foreign Asset Control (OFAC) sanctions against banking clients or foreign banks. If as US dollar transaction involves someone or an entity on the SDN list or a country on the OFAC list, anything to do with Iran or Russia, even if it is attenuated, will be flagged as high-risk. That raises the protentional of legal liability in the US relating due to OFAC sanctions, which has gotten much more complex since Russia’s 2022 invasion of Ukraine.

Ultimately, the problems associated with correspondent have not gone away in intervening 25 years. The overall situation is worse due to the emergence and growth of online scams as the fastest growing financial crime.

The use of US dollar-denominated stablecoins to subvert correspondent banking rules and OFAC restrictions must also be considered. In that sense, correspond banking is only a part of the picture – in the future, the focus will need to be on stablecoins as a way of avoiding many of the AML controls currently in place.

In an earlier age the attitude of most bankers was to maximize deposits and make loans. They never regarded it as their role to police the money supply. Yet, in an unstable world, money laundering and terrorist financing cannot be taken lightly. To that end, the US has opted to use money supply access as a tool for its national political will globally. In such a world, OFAC and AML rules become critically important.

The US has long taken the view that its laws and regulations have extraterritorial reach. Specifically, what makes AMLA onerous are its extra-long-arm provisions which grant the ability to go straight through correspondent accounts. That is something the Justice Department did not have prior to 2020 and it empowers banks to enforce such rules – not unlike FATCA which many say has deputized banks worldwide to American ends.

Yet, when one looks into the impact on customers in foreign jurisdictions, AMLA’s provisions contravene local law. In most European courts, for example, it is not enough for bank to just look at an OFAC list to determine if one is a politically exposed person (PEP). Foreign banks must do their own due diligence to determine if they can open an account for a person or entity that satisfies their own domestic laws, hence the conflict with US dictates and policy goals.

Compliance professionals must adapt and retool

On the personnel front, what has changed post-9/11 is that banks have not necessarily increased the size of their compliance departments – though, at many institutions that has happened – to more closely scrutinize their correspondent banking partners, but hey have also placed a greater emphasis on the compliance staff they recruit.

The way correspondent banking is now treated also means compliance offers need different or possibly additional training. Things have become more complex and information technology and artificial intelligence driven which requires a different type of compliance office, in part because model validation nis a different type animal and therefore, banks are moving towards a less manpower-driven model to an IT and AI model for correspondent banking compliance and account monitoring. That may portend leaner, yet more competent and sophisticated compliance. Yet, compliance professionals still Computers can’t do yet perform judgment sampling, seeing less people, people better trained.

Systems validation is a new pillar of AML requiring banks to test enough samples of input and output data such that their systems operate as intended for BSA and OFAC compliance. It is critical to understand the different world of correspondent banking compliance we are in. In earlier times, there was always independent testing of AML, KYC and CFT data, but it fell under the rubric of audits – what in contemporary times would be more accurately called independent risk assessment.

The importance of humans using their judgment and experience in data sampling will persist, yet AI will discover things people have heretofore not uncovered; discerning patterns of financial crime that people do not see. As a result, some banks are unloading or letting go of compliance staff because of IT improvements and power of IT combined with AI means more efficient independent data testing

The next step is AML risk assessment. A proposed rule under the Anti-Money Laundering Act (AMLA) requires strengthening and finalizing AML risk assessments. For that purpose, model validation helps financial institutions evaluate trained models by determining or confirming if they have achieved their intended purpose given changes over time. That requires a specific level of AI training banks’ compliance teams.

The next step is to have appropriate risk-based procedures for conducting customer due diligence. Risk-based approaches – something for which no set of rules has yet been produced by the US Treasury’s Financial Crimes Enforcement Network (FinCen) that banks can rely on – help institutions determine their risk appetite if something goes awry. Banks still getting penalized for lapses in their risk-based approaches.

Money laundering and terrorist financing have been around for years. What is required for compliance officers in assessing their banks’ correspondent partners is a deeper level of KYC, as well as knowing-your-customer’s-customers (KYCC) and knowing-your-customer’s business (KYCB). Who they are and where they got their money from are perennial questions that need to be asked periodically – not just at banking. Queries surrounding one’s ‘source of wealth’ and ‘source of funds’ are not going away and are merely the first step to sound compliance post-9/11.

Want to stay informed? Receive our latest insights in your inbox.

Contributing to
Partnering with
Trans World
* required
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.