Evidence submitted by LexisNexis Risk Solutions (ECR0005)

LexisNexis Risk Solutions submission to the Treasury Select Committee ‘Economic Crime’ inquiry

 

26 April 2018

 

Who we are

 

LexisNexis Risk Solutions (LNRS) and its sister company LexisNexis Legal & Professional are part of RELX Group, the UK-based FTSE 20 global provider of information and analytics for professional and business customers across industries. RELX serves customers in more than 180 countries and has offices in about 40 countries, employing approximately 30,000 staff globally.

 

LNRS provides data, analytics and insight that enable customers to predict, assess and manage risk, and develop intelligence which supports more confident business decisions, improved economic outcomes and enhanced operational efficiency.

 

LNRS is also a leading provider of name screening software globally (by revenue, number of names screened and number of customer measurements). LNRS holds the largest repository of US Public Record information and a similar collection of content in the UK. This critical information enables better management of customer data and improved anti-money laundering (AML), Know Your Customer (KYC), identity, fraud and credit assessment processes. LNRS in the UK is regulated by the Financial Conduct Authority as an authorised Credit Information Provider.

 

  1. Introduction

 

We have made this submission drawing on insights from:

 

a)      The wide overview LNRS has of the way AML, CFT and sanctions regimes are working in the UK and internationally, and in particular the role of information sharing, derived from our experience as a provider of AML and KYC services to a significant proportion of the world’s major financial institutions, as well as to a growing number of institutions and firms within the legal and property industries in the UK and beyond; and

b)      LNRS’s surveying and interviewing of large numbers of senior financial crime leaders operating in major UK financial institutions, as reflected in our recent report ‘Future Financial Crime Risks 2017’, and the earlier ‘Future Financial Crime Risks 2015’ which we carried out for the British Bankers Association.

 

  1. The effectiveness of the Treasury and its associated bodies in supporting and supervising the regimes

 

2.1   In this section we have confined our comments to the operation of the Joint Money Laundering Intelligence Unit (JMLIT).

 

2.2   The creation under the auspices of Treasury of JMLIT is viewed by us and, we believe, the wider financial crime community as a highly positive development in promoting greater trust and better information sharing between the three key sets of stakeholders: government, law enforcement and private sector.

 

2.3   Initial results from JMLIT’s operation would support this positive view. According to the National Crime Agency’s (NCA) review of JMLIT, in which participating organisations and individuals were surveyed, a significant majority rated the initiative as a success.[1] From our own interviews with banking professionals, the cited benefits included a greater level of protections (and indeed legal privilege) to share information with law enforcement, the ability of banks and law enforcement to take more holistic and informed actions together, the ability to learn from each other about processes and emerging threats, and the opportunity to reduce the time that risk might be on a bank’s books.

 

2.4   An even more fundamental benefit of JMLIT, which potentially opens a new chapter in the fight against money laundering and terrorist financing, is that through collaboration, banks, regulators and law enforcement are beginning to overcome the various siloes and stereotypes that have been inhibiting information sharing. In particular, we believe JMLIT is beginning to enable a new culture of trust that was previously lacking between these stakeholders and is laying the foundations for further partnership and collaborations.

 

2.5   Until recently, as illustrated in our ‘Future Financial Crime Risks 2015’ report, there had been a notable lack of trust between the stakeholders that stymied information sharing. As one financial crime professional stated to us at the time, one of the barriers to collaboration was “continuing mistrust between the Government, regulators and enforcement on one hand and banks on the other”.[2] We believe these atmospherics, and their impact on information sharing, had a negative impact on organisations’ ability collectively to fight financial crimes.

 

  1. The current legislative and regulatory landscape, including any weaknesses in the rules and their enforcement

 

3.1   In this section we have focussed our comments on the impact of the Criminal Finances Act 2017, discussions on how to improve the Suspicious Activity Report (SARs) regime, and the performance of the Senior Managers Regime.

 

Criminal Finances Act 2017 and the SARs regime

 

3.2   The Criminal Finances Act 2017 was introduced with the intention of allowing firms in the regulated sector to share information between each other to develop a better understanding of money laundering activities and to use that to communicate with the NCA for support and protection.

 

3.3   We observe that reactions to the Act have been largely positive. There is a recognized value of widening the scope of sharing through peer-to-peer communications, with the anticipation that over time the Act (and AML Action Plan overall) could deliver better AML outcomes.[3]

 

3.4   The bedding in of the new information sharing powers presents some challenges in terms of ensuring that the recently adopted guidance for the Act is as clear as possible, increases information sharing from a broader range of sectors (i.e. not just in the FS sector) while crucially, at the same time, improving the quality of filed SARs and reducing the generation of unnecessary SARs.

 

3.5   Over one million SARs are filed in the EU each year with over 65% of these being lodged with Financial Investigation Units (FIUs) in the UK and Netherlands. Less than 10% of SARs are used or investigated, with SARs generation in the relevant non-FS sectors being much lower. The scale of SARs production has created major costs burdens on the regulated sectors, while the flows of SARs into the UK’s FIU at current levels is creating major challenges in terms of it being able to process information and identify leads in the most efficient and effective manner.

 

3.6   We believe there is clear scope to improve the SARs regime in ways that would increase the quality of SARs filed with FIUs and to ensure that those non-FS sectors that are currently underperforming in terms of filings make great contributions without adding extensive friction and cost burdens into their core operations. (See LNRS recommendation 6.2 below)

 

Senior Managers Regime (SMR)

 

3.7   In 2015, when the introduction of the SMR was pending, we detected among financial crime professionals in banks considerable concern about implications. However, a few years later, in our 2017 survey, over half (61%) of survey respondents indicated that its impact has been as much or more positive, than a negative.[4]

 

3.8   Attestations have made senior executives in banks more sensitive and alert to compliance priorities. Combining these with shifting responsibility to the so called ‘First line of defence’, it has been noted that personal liability has made organisations focus upon greater operational efficiencies to remain on the right side of compliance. Over two-thirds of survey respondents said the policy of making executives personally accountable for employee action has been positive for the financial industry itself.[5]

 

3.9   However, whilst acknowledging the positive aspects of increased liability, there are points of confusion that still exist, particularly around lack of clarity and guidance in relation to what actions, or lack thereof, are liable to land individuals in trouble. As one professional noted to us, “It’s not a clear picture of what passes the threshold of being personally and criminally liable. You don’t know which thing that isn’t paid any attention to is the one that causes you to get into trouble.” As a result, many transactions get higher levels of scrutiny than they otherwise would or should, resulting in over-reporting of SARs and micro-management. This, in turn, creates “box ticking” compliance behaviour at the expense of proactive financial crime fighting – which is exactly what the FCA publicly states it does not wish to have happen.[6]

 

3.10           For those new to ‘First line of defence’ accountability, it may not yet be entirely clear that significant liability occurs from egregious or willful error (or both). Such tensions may ease as it becomes more widely understood, newer processes are put in place and people become accustomed to increased accountability.

 

  1. The impact of the implementation of the current regimes on individuals, firms and the wider economy, including unintended consequences, such as the removal/refusal of financial services from/to individuals or firms

 

Compliance Costs

 

4.1   Respondents to our 2017 survey told us that the cost of compliance for UK banks continues to rise and is a significant issue. Nearly two-thirds indicated that costs had been increasing over the last two years, with retail / wholesale banking particularly experiencing this trend.[7]

 

4.2   Greater regulation and increasingly complex criminal methods have driven up compliance costs. Resource hiring and managing legacy technology systems are key cost components related to compliance obligations. Mass recruiting of staff into compliance roles looks to be over, but there is strong demand for senior skilled specialists which has further driven up salary demands.

 

4.3   We observe that the FCA has been working hard on encouraging both understanding and use of new technologies for compliance in the financial services sector via its sandbox model, but the sector would probably admit itself that it has struggled to adopt new, efficient systems. Therefore, we have seen continued inefficient technology programmes in the compliance area, which tend to be people heavy and expensive as a result.  

 

‘De-risking’

 

4.4   Financial firms have the commercial freedom to choose with whom they do business within certain parameters. Consequently, so called ‘de-risking’ can occur for a range of factors, most obviously as a result of a firm’s perceptions of excessive credit risk or an overall assessment of profitability in relation to a client. However, the performance of AML obligations, as well as the cost of compliance itself, has emerged as a factor in driving the exiting of client relationships.

 

4.5   Money services bureaus (MSBs), charities, fintechs and correspondent banks are types of organization that we observe have typically been affected by de-risking. Concerns about these organisations are driven by one or more of the following characteristics: not being bound by the same rules and regulations as banks; having clients who may, for various reasons, be ineligible to hold a bank account (MSBs); lacking transparency into transaction details (i.e. limited visibility into their customers: MSBs, correspondent banks, charities); operating in higher risk locales.

 

4.6   We do not believe de-risking by financial firms in relation to these sectors means a blanket approach is being applied to all players within those sectors, but rather it is an acknowledgement that higher potential for risk requires more due diligence and costs, and that there are times when banks need to do what is required as a result: to exit or refuse an account based on either risk or commercial profitability.

 

4.7   In some cases, laws and regulations can pit different objectives against one another, even in instances where exiting a client relationship might be the appropriate course. For example, under the Bank of England and Financial Services Act 2016, the FCA will now potentially have authority to penalize financial firms for doing too much due diligence where politically exposed persons (PEPs) and their family members or close associates are identified, as well as being able to penalize for too little due diligence. This feels like a Catch-22 to some with whom we spoke: “So now you’ll get fined at the top end of the scale and the bottom end of the scale. So if you do too much due diligence, you’ll be fined. If you do too little, you’ll be fined.”[8] Our view is that the financial services industry is best equipped in terms of resources and talent to manage ML/TF risk and enable successful enforcement of rules. Ideally regulations should therefore promote a culture of managing risk.

 

4.8   In some instances, financial firms are required to manage risk and to exit relationships, yet financial crime concerns are being affected by new regulations that can lessen their control and freedom to act. For example, the Basic Payment Accounts Regulations 2016 which came into force in September 2016 make it mandatory for UK banks to offer at least a basic payment account to consumers. Banks have indicated that this will further restrict their ability to terminate basic payment accounts. This could make it easier for criminals and terrorists while adding more work for financial firms to monitor and assess risk they might have otherwise shut out at the beginning.

 

  1. The UK’s role in international efforts to tackle money laundering and terrorist financing and implement sanctions

 

5.1   We have addressed this topic through comments about the impact of Brexit, and the broader international environment for data sharing relevant to AML/CTF and sanctions implementation.

 

Brexit

 

5.2   The ability to share information within and between banks both in the UK and across EU borders will depend in no large part upon any adequacy agreement reached between the UK and the EU for the purposes of data transfer. The Government has a clear role, as it has recognized, in prioritizing the achievement of such an agreement during the negotiations on the UK’s future relations with the EU.

 

5.3   Since full separation from the EU continues to be some way off, assuming the UK achieves its goal of securing a transition period, the UK will continue to draw for some time from EU-derived legislation, notably the Fourth Anti-Money Laundering Directive and the evolution of the Fifth. Post-separation, the Government may seek to diverge from EU policy and legislation in this area, but it would need to consider whether this would lead to increased costs and complexities in relation to an AML system that, despite an already heavy cost burden on market participants, has room for improvement.

 

5.4   Brexit should not affect the UK’s sanctions positions. Many of these are UN-mandated, and will not be affected by leaving the EU, and whilst the UK may seek to strengthen some of its sanctions laws, it will need to keep in mind the ability of these to work within the parameters set by other global partners, including the EU.

 

Data protection rules

 

5.5   One of the most significant barriers to international banks playing their full role in greater collaboration and sharing of high quality information to support effective AML/CTF, relates to the proliferation of data protections rules country-by-country and material variations within those rules. In some jurisdictions data protections rules are relatively mature, in other countries they are under development or undergoing significant reshaping (e.g. Brazil, India).

 

5.6   There is therefore an increasing risk of conflict arising between obligations to protect and limit use of data on the one hand and, on the other, the policies and regulations and practices that are being developed in multiple jurisdictions including the UK to improve AML/CTF outcomes. For example, the absence of a unified and coherent approach in the EU to the implementation of member state options in Article 10 of GDPR risks fragmenting bank access to data that is relevant to risk profiling for the purpose of AML. Such a patchwork of international rules risks creating opportunities that criminals will learn to exploit.  

 

  1. LNRS recommendations to policy-makers and other stakeholders

 

6.1   More collaboration between stakeholders. No single stakeholder or group of stakeholders has all the insights, concepts or expertise to identify the most effective way to screen for suspicious activities or to design the most effective way of sharing information among stakeholders. For example, the typologies of crime in the AML space are best understood by law enforcement, while banks as the custodians of account data and transaction data that span multiple jurisdictions have access to core source material that could be turned into actionable intelligence for law enforcement agencies. Similar to what we have seen achieved through the creation of JMLIT, we believe a tighter collaboration between the main three groups of stakeholders (government, law enforcement, private sector) would enhance the functioning of the SARs regime too.

 

6.2   Embrace new technology. We believe that ‘private sector’ in the context of enhancing collaboration and the SARs regime should be understood to include the providers of technology, as well as banks, law firms and the property industry. Banks, regulators and law enforcement agencies are not technology providers and would benefit from greater collaboration with industry associations like TechUK and the UK’s world-leading technology providers themselves. Existing financial crime technology and the information ecosystem is highly inefficient. Data is often of poor quality and in disparate silos spread across legacy systems, further fragmented across business units within banks themselves. Making sense of this landscape and pinpointing the data that, for example, should form the basis of a SAR increasingly could and should require the application of technology, including so called ‘regtech’ solutions. The UK is particularly well-placed to harness new technologies relevant to AML/CTF, such as enhanced analytics and artificial intelligence, given the strength of UK industry in this space.

 

6.3   Educate stakeholders. In respect of use of data, we recommend that Government and the banking sector consider programmes that would educate consumers and media on the importance of information sharing between organisations, with appropriate safeguards, for the purpose of anti-fraud, AML and terrorist financing. We believe there is a risk, in light of increasing concerns about uses of personal information by public and private sectors that public sentiment shifts in ways that will undermine current AML/CFT data sharing programmes and plans to enhance them, despite such measures being clearly in the public interest.

 

6.4   Use G2G discussions to advance effective data rules. We recommend that the UK considers making more use of high profile intergovernmental fora, such as the G20 and FATF, and the UK’s bilateral dialogues with major emerging economies, such as Brazil and India, to make the case for data protection rules that allow banks and other intermediaries, which are screening for potential instances of AML/CTF, to be able to use data for those purposes and, crucially, to be able to transfer that data across borders to support sharing and collaboration.

 

6.5   Work with the European Commission and EU member state on Article 10. We recommend that the UK uses its role as a global leader in the AML/CFT space and its regulatory expertise to engage with EU partners to encourage implementation in full across the bloc of the member state options located in Article 10 of GDPR.

 

6.6   Ensure the outcome of Brexit does not hinder AML/CTF efforts. We recommend that the UK prioritises the achievement of a data adequacy agreement, or some other equally robust form of legal basis, for maintaining the free flow of data between the UK and EU, subject to maintaining existing privacy safeguards. In respect of UK efforts on AML/CTF, it would be problematic if, as a result of a failure of the UK and EU to reach a deal, UK financial institutions found their access to data relating to EU accounts and transactions reduced.    

 

 

For further information about this submission, please contact:

 

Alistair Tebbit, Head of UK Government Affairs, RELX Group (the parent company of LexisNexis Risk Solutions) at alistair.tebbit@relx.com

 

April 2018

6

 


[1] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 6.

[2] 2015 Future Financial Crime Risks, a LexisNexis Risk Solutions report produced for the BBA, November 2015, page 18.

[3] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 10.

[4] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 16.

[5] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 18.

[6] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 20.

[7] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 23.

[8] Future Financial Crime Risks 2017, a LexisNexis Risk Solutions report, page 30.