Banks find AML "Ineffective" because the premise is erroneous. KYC is a sham because bankers don't actually know their customers and checking that you have a valid ID before you can open an account has no value . Criminals, or their straw men, have a valid ID. To detect crime you need detectives to investigate crimes. The transaction record by itself means nothing because the banks have no way to know what any of the…
You don't need to posting about doing crimes for your FB profile to be useful for risk assessment. Your connections or other posts (e.g. about how some emergency means you're suddenly short of cash) could contribute to an elevated score.
The proposal doesn't go into much detail about how they imagine it will work, but it sounds like they're just saying that a statistical model (based on a larger set of data) would be more useful than a set of rules based on a tiny set of inputs. This seems entirely reasonable.
Here is the relevant paragraph:
Input data for MSA platforms should incorporate not only transactional data, customer static data and internal reference lists, but also other dynamic behavioural customer information where proportionate to the risk (e.g. device ID, IP addresses). Using an RBA, input data may also include data from reputable external, publicly available sources, including information on company structures, Ultimate Beneficial Owners (UBO), and watch lists, as well as complementary sources such as market data and verified customer social media accounts. Finally, FIs should establish robust data governance and quality control frameworks.