New York Sends Clear Message to Crypto Exchanges and Banks Must Meet AML Obligations | Harris Beach LLC

[ad_1]

The New York Department of Financial Services (“DFS”) recently announced a $100 million settlement with Coinbase, Inc., one of the world’s largest cryptocurrency exchanges, over compliance failures with the Bank Secrecy/Anti-Money Laundering Act (“BSA/AML”), which could have a broad impact on the fiat currency and cryptocurrency (digital asset) communities. DFS found a wide range of material deficiencies in the Customer Identification Program (“CIP”)/Customer Due Diligence (“CDD”), transaction monitoring, reporting of suspicious activity, politically exposed person (“PEP”) screening and cyber event reporting. DFS reported that Coinbase’s BSA/AML compliance program has failed to keep up with Coinbase’s growth, despite working with an independent monitor since early 2022. Coinbase will pay a $50 million fine as a result. and will invest an additional $50 million in its BSA/AML compliance program. . While intended for crypto exchanges and relevant to the blockchain industry, this regulation also provides clear warnings to all financial institutions.

C.I.P./CD

DFS described Coinbase’s CIP/CDD integration requirements as “a simple tick-box exercise.” It is important to note that Coinbase has not assigned clients an informed client risk rating; collect CIP beyond a copy of a photo ID; clearly identify inaccurate information; determine the customer risk profile; or perform CDD on high-risk clients, resulting in a backlog of over 10,000 CDD exams.

Shortcomings of the transaction monitoring system

According to DFS, Coinbase was unable to keep up with the increased number of alerts generated by its transaction monitoring system, resulting in a backlog of more than 100,000 unexamined transaction monitoring alerts at the end of 2021. While Coinbase has hired over 1,000 consultants to review the backlog of alerts. , Coinbase provided insufficient oversight. Due to poor training and quality control, a significant portion of alert reviews contained errors.

PEP screening

Coinbase allowed its customers to access its platform while using VPNs or the Dark Web, allowing a user to appear to be in a different place or country than their actual location. DFS discovered that Coinbase had never developed a risk-based policy for customers using these channels. Additionally, Coinbase customers were apparently not subject to ongoing sanctions monitoring or PEP screening until December 2020.

Cybersecurity Event Reporting Requirements

In 2021, approximately 6,000 Coinbase customers fell victim to a phishing scam that led to unauthorized access to their account. Although DFS regulations required Coinbase to report this event to DFS within 72 hours of discovery, the breach was not reported until five months later.

Gaps in Suspicious Activity Reporting

BSA/AML compliance failures have led to multiple potential instances of money laundering, drug trafficking, and other unreported suspicious activity. DFS also found that Coinbase repeatedly filed Suspicious Activity Reports (“SARs”) months after the suspicious activity was identified. In many other instances, Coinbase was unable to manage SAR data and was unable to meaningfully respond to DFS requests for information related to suspicious activity.

The takeaway for all financial institutions

Announcing the settlement, DFS Superintendent Adrienne A. Harris said, “It is critical that all financial institutions protect their systems from bad actors, and the Department’s expectations of consumer protection, cybersecurity and anti-money laundering programs are equally stringent. for cryptocurrency companies as well as traditional financial services institutions. His statement clearly put blockchain and traditional financial institutions – including banks – on notice to implement strong CIP/CDD policies, procedures and processes that are the foundational building block of BSA/AML compliance programs. The regulation also makes it clear that financial institutions must monitor how customers access online platforms and mitigate risk, and banks must monitor their customers’ transactions to and from crypto exchanges. As DFS has repeatedly stated, financial institutions must proactively and skillfully manage their growth or risk taking enforcement action. Finally, this settlement and other cases, such as FTX and Bittrex, are a clear signal that federal and state regulatory oversight – arguably long overdue for blockchain and crypto – may finally have arrived.

Sources

1/ https://Google.com/

2/ https://news.google.com/__i/rss/rd/articles/CBMiTmh0dHBzOi8vd3d3Lmpkc3VwcmEuY29tL2xlZ2FsbmV3cy9uZXcteW9yay1zZW5kcy1jbGVhci1tZXNzYWdlLWNyeXB0by02MzY3NDgxL9IBAA?oc=5

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts