[ad_1]
The New York Department of Financial Services (DFS) recently announced a $100 million settlement with Coinbase, Inc., one of the world’s largest cryptocurrency exchanges, over legal compliance lapses. on bank secrecy/anti-money laundering (BSA/AML), which could have a broad impact on the fiat currency and cryptocurrency (digital asset) communities. DFS found a wide range of significant deficiencies in Customer Identification Program (CIP)/Customer Due Diligence (CDD), Transaction Monitoring, Reporting of Suspicious Activity, People Screening Politically Exposed Persons (PEPs) and cyber event reporting. DFS reported that the Coinbases BSA/AML compliance program has failed to keep up with Coinbases’ growth, despite working with an independent monitor since early 2022. As a result, Coinbase will pay a $50 million fine and will invest an additional $50 million in its BSA/AML compliance program. . While intended for crypto exchanges and relevant to the blockchain industry, this regulation also provides clear warnings to all financial institutions.
C.I.P./CD
DFS described the Coinbases CIP/CDD integration requirements as a simple checkbox exercise. It is important to note that Coinbase has not assigned clients an informed client risk rating; collect CIP beyond a copy of a photo ID; clearly identify inaccurate information; determine the customer risk profile; or perform CDD on high-risk clients, resulting in a backlog of over 10,000 CDD exams.
Shortcomings of the transaction monitoring system
According to DFS, Coinbase was unable to keep up with the increased number of alerts generated by its transaction monitoring system, resulting in a backlog of more than 100,000 unexamined transaction monitoring alerts at the end of 2021. While Coinbase has hired over 1,000 consultants to review the backlog of alerts. , Coinbase provided insufficient oversight. Due to poor training and quality control, a significant portion of alert reviews contained errors.
PEP screening
Coinbase allowed its customers to access its platform while using VPNs or the Dark Web, allowing a user to appear to be in a different place or country than their actual location. DFS discovered that Coinbase had never developed a risk-based policy for customers using these channels. Additionally, Coinbase customers were apparently not subject to ongoing sanctions monitoring or PEP screening until December 2020.
Cybersecurity Event Reporting Requirements
In 2021, approximately 6,000 Coinbase customers fell victim to a phishing scam that led to unauthorized access to their account. Although DFS regulations required Coinbase to report this event to DFS within 72 hours of discovery, the breach was not reported until five months later.
Gaps in Suspicious Activity Reporting
BSA/AML compliance failures have led to multiple potential instances of money laundering, drug trafficking, and other unreported suspicious activity. DFS also found that Coinbase repeatedly filed Suspicious Activity Reports (SARs) months after suspicious activity was identified. In many other instances, Coinbase was unable to manage SAR data and was unable to meaningfully respond to DFS requests for information related to suspicious activity.
The takeaway for all financial institutions
Announcing the settlement, DFS Superintendent Adrienne A. Harris said, “It is critical that all financial institutions protect their systems from bad actors, and the Department’s expectations of consumer protection, Cybersecurity and anti-money laundering programs are just as stringent for cryptocurrency companies as they are for traditional financial services institutions. His statement clearly warned blockchain and traditional financial institutions, including banks, that they must implement strong CIP/CDD policies, procedures and processes that are the foundational building block of BSA/AML compliance programs. . The regulation also makes clear that financial institutions must monitor how customers access online platforms and mitigate risk, and banks must monitor their customers’ transactions to and from crypto exchanges. As DFS has repeatedly stated, financial institutions must proactively and skillfully manage their growth or risk taking enforcement action. Finally, this settlement and other cases, such as FTX and Bittrex, make it clear that long overdue federal and state regulatory oversight for blockchain and crypto may finally have arrived.
Harris Beach attorneys monitor the legal landscape for banking and digital assets and provide advice and compliance strategies in many areas. Please review some of the services we provide to financial institutions and businesses in the blockchain and digital asset industry.
If you would like more information on this topic, please contact Constantine P. Lizas at (202) 975-9780 or [email protected]; Ross B. Hofherr at (212) 313-5482 or [email protected]; Peri Berger at (212) 912-3574 or [email protected]; or Adrianna M. Baranello at (914) 298-3023 or [email protected].
This alert does not replace legal advice on specific legal issues.
Harris Beach has offices throughout New York State, including Albany, Buffalo, Ithaca, New York, Rochester, Saratoga Springs, Syracuse, Uniondale and White Plains, as well as Washington DC, New Haven, Connecticut and Newark , New Jersey.
|
Sources 2/ https://www.harrisbeach.com/insights/new-york-sends-clear-message-crypto-exchanges-and-banks-must-meet-aml-obligations/ The mention sources can contact us to remove/changing this article |
[ad_2]