AML Risk / Interconnectedness of Risk Flashcards
What are the two broad categories of criminal offences in a business setting?
- Crimes against individuals, property or services.
- Violations of laws and regulations that are per se offences.
What six methodologies could an organisation use to counter crime?
- Use of external background checking firms.
- Implementation of clear conduct policies, checks and procedures.
- Ongoing training.
- Regular audits to identify early signs of criminal conduct.
- Use of security cameras and infrastructure.
- Use of RM to identify vulnerable areas.
What three methodologies might be used for cyber crime prevention purposes?
- Installation of password-protected firewalls and current antivirus software.
- Retention of specialist firms to identify and resolve security weak posts (e.g. too many employees with privileged access).
- Ensure adequate back-up processing of key records.
What are the three principal losses arising from financial crime?
- Direct financial loss (e.g. arising from employee fraud).
- Reputation and brand loss (e.g. stemming from adverse publicity).
- Legal and regulatory sanctions due to breach of anti-financial crime laws and regulations.
What are the three stages of the money laundering process?
- Placement.
- Layering.
- Integration.
How do AML laws generally counteract money laundering?
- AML laws often define in-scope organisations that are obliged to prevent money from being laundered.
- Regulated organisations that fail to prevent money laundering may be subject to sanctions.
- Additionally, directors and senior management personnel of non-compliant regulated organisations may be similarly sanctioned.
How do ML and TF risks differ?
- With ML, am offence must occur from which proceeds of crime are laundered.
- With TF, funds are mobilised to enable the commission of a relevant offence.
How five considerations are relevant to management of ML and TF risks?
- Process is similar to management of other risks - identification and assessment of prevailing risks, with control and monitoring of the same.
- For the identification step, organisations should identify how their product and services could be used, inadvertently or deliberately, to support ML or TF.
- Emphasis should be placed upon the products, services, stakeholders and locations that are most susceptible to ML and TF risks.
- Exposure should be measured in the usual way (probability x impact).
- Controls and monitoring arrangements should be implemented to address ML and TF risks (e.g. appointment of MLRO; use of compliance reviews and IA).
What four activities are typically subject to AML/CTF regulation?
- Receipt and execution of large cash transactions (UK - >£10k).
- Provision of credit.
- Provision of products that offer investment returns.
- Provision of certain insurance policies.
=> Solicitors, accountants, banks/breaux de change, estate agents, insurers and investment firms often regulated.
How is bribery and corruption regulated in the UK, and what six internal control mechanisms should organisations implement to counteract bribery and corruption?
- Bribery Act 2020 renders organisations and their employees liability for acts of bribery committed either with public officials or on a business to business basis.
- Organisations should, hence, introduce internal control mechanisms to counteract bribery and corruption risks, predicated on six principles:
- Proportionality;
- Top-level commitment;
- Risk assessment;
- Due diligence;
- Communication;
- Monitoring and review. - Internal controls should be proportionate to the size and risk profile of the relevant organisation - an internationalised mining company, with significant revenue, will require more intricate and responsive controls, than, for example, a small coffee shop chain.
What are the three facets of political risk?
- Represents risks that an organisation may face due to political changes or political instability (e.g. arising from sanctions).
- Political risks are extremely DIFFICULT TO PREDICT and may lead to SUBSTANTIAL STRATEGIC, FINANCIAL AND EMPLOYEE LOSSES for an organisation.
- High degree of political freedom as NOT NECESSARILY TRANSLATE into a low level of political risk.
Name the two categories of political risk.
- MACRO RISK - Not organisation-specific, instead AFFECT ENTIRE COUNTRY (e.g. civil war);
- MICRO RISK - ORGANISATION-SPECIFIC or centric to a project performed by an organisation (e.g. windfall taxation on energy companies).
What is behavioural risk management?
- Emphasis on managing INDIVIDUAL and COLLECTIVE BEHAVIOUR or organisation’s employees, targetting:
- Attitudes;
- Perceptions; and
- Relationships of an organisation’s employees. - PROMOTION OF GOOD BEHAVIOURS that help achievement of organisational objectives and PREVENTION OF BAD BEHAVIOURS that threaten that same (e.g. negligence, recklessness, bullying, H&S neglect).
- Focus on LONG-TERM BENEFITS, rather than SHORT-TERM REWARDS - ensuring adherence to policies/procedures, encouraging communication/adherence to advice/good practices and pursuing personel objectives in a manner consistent with organisational requirements (e.g. FS conduct of business).
What is climate change risk?
Presentation of FINANCIAL RISKS to an organisation, arising from two chief causes:
1. PHYSICAL - Changing weather patterns, extreme weather events, rising sea-levels; may be particularly ACUTE IF UNINSURED.
2. TRANSITIONAL - Adjustment to lower/carbon neutral operating models; changes in government climate policy.
What does resilience means?
- RM focused on anticipated impact and probability of risks, to quantify and control exposure. Where there is uncertainty, resilience planning ensures organisation can RESPOND TO UNANTICIPATED RISK EVENTS to MITIGATE their effects.
- Emphasis is there NOT PREVENTION but EFFECT REDUCTION of uncertainties that become risk events.
- Four-stage risk reduction process:
- Implementation of EFFECTIVE CRISIS MANAGEMENT and BUSINESS CONTINUITY ARRANGEMENTS;
- QUICK REACTION;
- Investment in EFFECTIVE RISK REDUCTION TOOLS (e.g. PR management); and
- LEARNING from PAST EVENTS, incluing SUCCESSES and FAILURES.