BIS国际清算银行-Financial-crime-in-times-of-Covid-19---AML-and-cyber-resilience-measures_12页_330kb
报告摘要
FSI Briefs No 7: Financial Crime in Times of Covid-19 – AML and Cyber Resilience Measures
Highlights
- Criminal Exploitation of Lockdown Vulnerabilities: The global lockdown has created new opportunities for cybercrime, money laundering (ML), and terrorist financing (TF) due to increased online activity and remote working.
- Increased Cyber Threats:
- Ransomware attacks rose by 148% in March 2020.
- The finance sector was the top target, with a 38% increase in cyberattacks.
- Over 1,500 high-risk domains related to both Covid-19 and financial services were identified.
- Google reported 18 million daily malware/phishing emails related to the pandemic in early April 2020.
- AML and TF Risks:
- Remote onboarding and identity verification have created potential loopholes for ML.
- Cash withdrawals have increased, which could be used to mask ML activities as the situation stabilizes.
- Flexibility in AML/CFT Frameworks: Authorities have emphasized the need to apply AML/CFT requirements flexibly, especially in the context of the pandemic.
- Collaboration and Information Sharing:
- Financial institutions and authorities are enhancing cooperation through information sharing.
- Public-private partnerships and international platforms (e.g., ECRB, CRCC) are being used to share threat intelligence and best practices.
Core Content
Introduction
The global lockdown due to the pandemic has significantly increased the online presence of individuals and businesses, making financial institutions and their staff more vulnerable to cyber threats. This has also expanded the scope for financial crime, including money laundering and terrorist financing. The situation has put pressure on cyber resilience and AML frameworks, requiring a balance between risk mitigation and operational flexibility.
Financial Crime During the Pandemic Crisis
- Cybercrime Trends:
- A significant rise in cyber threats, including ransomware and phishing, has been observed.
- The finance sector is a primary target for cybercriminals.
- Malicious domains and emails with a "Covid-19" theme have surged.
- AML/TF Risks:
- Remote customer onboarding and identity verification have introduced new risks.
- Financial institutions may struggle to monitor suspicious transactions due to resource constraints.
- Authorities have delayed AML inspections and reporting to manage workload.
- Increased cash withdrawals could provide cover for money laundering activities.
Cyber Resilience Measures
- Public Awareness Campaigns:
- Authorities have issued public statements to raise awareness about cyber threats.
- Emphasis is placed on vigilance against ML and TF, and on educating employees.
- Guidance on Cybersecurity:
- Secure VPN connections, multi-factor authentication, and device controls are recommended.
- Financial institutions are advised to review and update their incident response plans.
- Third-Party Risk Management:
- Authorities stress the importance of assessing and managing third-party risks.
- The DFS encourages coordination with critical vendors to address new risks.
- Training and Awareness:
- FINRA recommends staff training on secure remote access and identifying scams.
- IT support staff should be trained to detect and respond to fraud and social engineering.
- Information Sharing:
- Domestic and international platforms (e.g., ECRB, CRCC) are used to share threat intelligence and best practices.
- Public-private partnerships are being formed to enhance information exchange on financial crime.
AML Measures
- FATF Guidance:
- FATF encourages the use of a risk-based approach to AML/CFT, with flexibility in response to the pandemic.
- It promotes responsible digital onboarding and simplified due diligence processes.
- Flexibility in AML/CFT Requirements:
- Authorities such as the HKMA and FINMA have implemented flexible measures, including extended due diligence periods and regulatory relief.
- The OCC supports FinCEN's approach, allowing for reasonable delays in reporting.
- Use of Technology:
- Machine learning is being used to improve ML detection, but its effectiveness may be impacted by changes in client behavior.
- Digital ID systems and other technologies are being encouraged to ensure trustworthiness in customer verification.
- Collaboration with Financial Sector:
- Supervisors, FIUs, and law enforcement agencies are working closely with financial institutions to share information on ML and TF risks.
- FINCEN has established a specific reporting mechanism for financial institutions to communicate concerns related to the pandemic.
Key Information
- Covid-19 has increased financial crime risks due to the shift to remote work and online transactions.
- Authorities are balancing risk mitigation with operational flexibility, recognizing the need to avoid excessive burdens on financial institutions.
- Cyber resilience and AML frameworks are being adapted to the new environment, with a focus on remote access, third-party risk, and information sharing.
- Public-private and international cooperation are critical in addressing these challenges, as seen through the use of platforms like ECRB and CRCC.
Conclusion
The pandemic has created a conducive environment for financial crime, necessitating enhanced cyber resilience and AML measures. Authorities are responding with guidance, flexibility, and increased collaboration, ensuring that financial institutions remain prepared and compliant while adapting to the new challenges posed by the crisis.
试读结束,高清完整版pdf/doc/ppt,请点下载