On Monday, January 26, Associations of Certified Anti-Money Laundering Specialists (hereon ACAMS) held its Third Annual AML Risk Management Conference at The Conrad Hotel in downtown New York. Over the course of this week, summaries and takeaways from the key notes and panel discussions will be shared in this blog.
- Vasilios Chrisos, Moderator, Principal, Fraud Investigation and Dispute Services, Ernst & Young
- Richard Small, CAMS, Senior Vice President, Enterprise-Wide AML, Anti-Corruption and International Regulatory Compliance, American Express | Chair, ACAMS Advisory Board
- Meg Zucker, Global AML Officer, Royal Bank of Canada Capital Markets
Risk Assessment is key to a successful Compliance Program. This panel discussion talks about the issues surrounding the development, implementation, execution, review and management of the various risk assessments necessary. Here are ten takeaways from this session:
- In large financial institutions, multiple risk assessment could be performed on clients for different lines of businesses. Good communication between the two risk assessment programs regarding the same client is key to reducing risk assessment friction, cost overruns, and addressing the uniqueness of each client.
- Number of Suspicious Activity Reports (SARs) is not a good measure of the need for additional elements in Risk Assessment because it is not an indicator. however, it might be one of the good places to start for developing the risk assessment when looking for issues.
- Lower level executives are still surprised by the requirement to attend compliance training for them, not just for their staff.
- Big firms are highly aware of the need for training and compliance since regulators are primarily focused on big firms. It is the medium size firms that might be lacking in Compliance awareness.
- Many regulators want to see Audit Reports and Risk Assessments as their starting point in an exam, review or an investigation.
- Dealing with businesses within a firm is harder than dealing with AML or Sanctions because businesses often are not as aware of regulatory risks as AML or Sanctions are.
- Geographic risks cannot be painted in broad strokes. An example: A client regulated in Hong Kong is likely very low risk while client in Hong Kong but not regulated are likely very high risk.
- Technology is great for efficiency but not always good for developing methodology or for troubleshooting risks, even for those who are technologically savvy.
- Cooperative environment is the best environment for getting cooperation in Risk Assessment, as with anything else. Cooperative environment should be the goal of the whole firm, not just with Compliance.
- Regulators are starting to pin down senior leaders to their risk appetite, asking for explicit declarations. Firms generally shy away from this as much as possible.
About the Author: Marcus Maltempo is a compliance professional with more than a decade of experience helping banks, law firms and clients manage investigations and regulatory responses.
He tweets @MoneyCompliance