Live data from Hacker News

Banks find AML "ineffective", propose access to social media

therage.co

41–50 of 57 posts

Re: Banks find AML "ineffective", propose access to social media

#41

Banks find AML "Ineffective" because the premise is erroneous. KYC is a sham because bankers don't actually know their customers and checking that you have a valid ID before you can open an account has no value . Criminals, or their straw men, have a valid ID. To detect crime you need detectives to investigate crimes. The transaction record by itself means nothing because the banks have no way to know what any of the…

Even if a piece of information isn't informative on an individual basis, it might provide improve the performance of a model that combines it with other inputs. You don't need to posting about doing crimes for your FB profile to be useful for risk assessment. Your connections or other posts (e.g. about how some emergency means you're suddenly short of cash) could contribute to an elevated score. The proposal doesn't…

Fighting crime should not be a bank problem.

Putting this burden on banks is a thing pretty unique to the US. Not sure why anyone would be surprised to find out this does not work.

Re: Banks find AML "ineffective", propose access to social media

#42
post #41

Earlier quoted context omitted.

Even if a piece of information isn't informative on an individual basis, it might provide improve the performance of a model that combines it with other inputs. You don't need to posting about doing crimes for your FB profile to be useful for risk assessment. Your connections or other posts (e.g. about how some emergency means you're suddenly short of cash) could contribute to an elevated score. The proposal doesn't…

Fighting crime should not be a bank problem. Putting this burden on banks is a thing pretty unique to the US. Not sure why anyone would be surprised to find out this does not work.

It's not at all unique to the US. The EU has AML/KYC legislation, which pushes the burden down through the banks to the customer.

Re: Banks find AML "ineffective", propose access to social media

#43
This is clickbait.

When you read the actual statement it's reporting on, and ctrl+f "social", you find that it is used exactly once.

> Input data for MSA platforms should incorporate not only transactional data, customer static data and internal reference lists, but also other dynamic behavioural customer information where proportionate to the risk (e.g. device ID, IP addresses). Using an RBA, input data may also include data from reputable external, publicly available sources, including information on company structures, Ultimate Beneficial Owners (UBO), and watch lists, as well as complementary sources such as market data and verified customer social media accounts. Finally, FIs should establish robust data governance and quality control frameworks.

In other words, do a thorough investigation based on all of these inputs. If you're looking at potential money laundering through a business, go to Companies House and learn as much as you can about the business to determine how legit it is. When you're looking a potentially fraudulent customer, look at their digital footprint online, including social media to determine how legit they are.

This is standard practice in banks today. What the statement suggests is that in addition to monitoring individual transactions, banks should periodically monitor customers as well.

The statement doesn't call for "access", nor does it even use the word "access" in the main text. It's simply clickbait, which people reading the headline + comments alone have fallen for.

Re: Banks find AML "ineffective", propose access to social media

#44
Every time the banks ask me for KYC/AML stuff, I think about the Danske Bank Estonia scandal [1].

In 8 years, €800 billion of suspicious transactions flowed through Danske Bank Estonia, which is over 5 x Estonian GDP during that period. Five times!

If this does not set off alarm bells, then checking my little transactions is not going to solve anything. Security theatre.

[1] https://en.wikipedia.org/wiki/Danske_Bank_money_laundering_s...

Re: Banks find AML "ineffective", propose access to social media

#45
post #41

Earlier quoted context omitted.

Fighting crime should not be a bank problem. Putting this burden on banks is a thing pretty unique to the US. Not sure why anyone would be surprised to find out this does not work.

It's not at all unique to the US. The EU has AML/KYC legislation, which pushes the burden down through the banks to the customer.

Kind of true, yes, in theory, because FATF is largely controlled by the US and it enforced US-style rules to the rest of the world. However, on the practical level AML/KYC works differently outside of the US. Regulator would create well-defined criteria for banks to execute: To onboard a customer bank must do this and this, check that field against that record. In the US regulators just washed their hands and placed the burden on banks: banks must make all the "reasonable" efforts to "know" their customer and what is is deemed "reasonable" varies across banks, branches and even individual clerks.

Re: Banks find AML "ineffective", propose access to social media

#47

Earlier quoted context omitted.

Even if a piece of information isn't informative on an individual basis, it might provide improve the performance of a model that combines it with other inputs. You don't need to posting about doing crimes for your FB profile to be useful for risk assessment. Your connections or other posts (e.g. about how some emergency means you're suddenly short of cash) could contribute to an elevated score. The proposal doesn't…

> Your connections or other posts (e.g. about how some emergency means you're suddenly short of cash) could contribute to an elevated score. This sounds more like a way to send desperate people into a death spiral by raising interest rates or denying credit availability right at the worst possible moment than any kind of system that would prevent crime. > The proposal doesn't go into much detail about how they imagin…

> opaque government-facilitated denial of service without due process

That's not what the report is about.

Banks and financial institutions are required to file Suspicious Activity Reports (SARs) and Suspicious Transaction Report (STRs). Filing such a report doesn't stop a transaction from happening.

The report suggests that banks think they could improve the usefulness of these reports and reduce the number of false positives, if they had more freedom to choose the criteria.

Re: Banks find AML "ineffective", propose access to social media

#48

Banks find AML "Ineffective" because the premise is erroneous. KYC is a sham because bankers don't actually know their customers and checking that you have a valid ID before you can open an account has no value . Criminals, or their straw men, have a valid ID. To detect crime you need detectives to investigate crimes. The transaction record by itself means nothing because the banks have no way to know what any of the…

Not to mention the risks to those of us who have no social media presence at all. Will that be considered a big red flag all by itself?

Re: Banks find AML "ineffective", propose access to social media

#49

How is this different from China's social credit score?

China's social credit system requires actual recorded offenses to trigger penalties, in particular delinquency in paying fines or tax, not some bank's AI inhaling and rating your Facebook account history. The "Social" in the name is nothing to do with social media.

True, theirs is a lot more fair

Re: Banks find AML "ineffective", propose access to social media

#50

It feels like we're gradually slipping into a dystopian nightmare world, predicted again and again by sci fi writers for decades, with no real strong opposition. There's the EFF, I guess? But advocacy groups don't seem particularly powerful or influential. I can't even hope for a "it'll get worse before it gets better" scenario. A world with normalized lack of privacy seems unlikely to suddenly care about it again. P…

The relevancy of advocacy groups is at an all time low because of just how little the professionally informed care these days. Tech was a "community" when the grifters slid in wanted something from the rest of us, and YOLO fuck you I got mine backstabbery when anyone suggested maybe not selling out our privacy quite so hard. And it infects the rest of us. When our friends and colleagues have jobs swinging pickaxes at…

[deleted]
Post reply on HN