News

11:07 AM
Connect Directly
RSS
E-Mail
50%
50%

Software Helps Banks Comply With Patriot Act

As financial institutions scramble to comply with the federal government's Oct. 1 deadline for implementing strict customer-identification procedures, they're looking for technology to scour transactions for patterns of fraud.

As financial institutions scramble to comply with the federal government's Oct. 1 deadline for implementing strict customer-identification procedures, they're looking for technology to scour transactions for patterns of fraud. The USA Patriot Act is aimed primarily at banks, investment firms, insurance companies, and stock and commodities exchanges, regarded as gatekeepers of the nation's financial system. At a minimum, they must put in place procedures to collect information on customers when they open accounts to verify that customers are who they say they are and check whether customers appear on terrorist lists. Records must be retained for five years after an account is closed. The law applies to any organization deemed a likely target for illicit cash, including pawnshops, travel agents, casinos, precious-metals dealers, and money-transfer agents.

Most banks say they're ready to meet the law's requirements. "We've tweaked all our Bank Secrecy Act and anti-money-laundering policies and procedures," says Dennis Algiere, senior VP for compliance at the Washington Trust Co., a $1.8 billion asset institution.

But demands on these companies may grow. For example, the Patriot Act requires banks to check a terrorist list provided every two weeks by the U.S. Treasury's Financial Crimes Enforcement Network, which channels suspicious activity reports to the FBI and other law-enforcement agencies. That's in addition to a similar list that the Treasury's Office of Foreign Assets Control provides--and there's talk of a third list that might have to be checked. "I don't know how many lists to expect," Algiere says. "All I know is we have two right now."

Seeking to meet the demand for high-end solutions created by the Patriot Act, software vendors are flooding the market with anti-money-laundering products ranging from simple watch-list filters to sophisticated behavior-detection systems. Key vendors include ACI Worldwide, Fair Isaac, Mantas, SAS Institute, Searchspace, and Sybase.

From 2003 through 2005, financial institutions will spend an estimated $632 million on anti-money-laundering software and related hardware and services, according to Celent Communications, a consulting and research firm that specializes in financial-services technology. "Even though the Patriot Act might not put it in writing, regulators in effect are looking for IT solutions," Celent analyst Neil Katkov says.

Citigroup and ABN Amro use anti-money-laundering software that utilizes sequence-matching and risk-scoring algorithms to detect suspicious activities, such as fund transfers from high-risk geographic regions or series of large cash transactions. "Money launderers will buy strings of consecutively numbered $500 money orders" to evade the $3,000 reporting limit currently in place to control illicit activity, says Don Temple, a consultant at Mantas, which provides the software Citigroup and ABN Amro use.

A good anti-money-laundering system is capable of connecting seemingly unrelated transactions to detect patterns occurring over long periods of time. "The pattern may score low this month and next month, but eventually it will reach a threshold, and the transactions will get flagged," Temple says.

Anti-money-laundering software can reduce or even eliminate the need to screen all customers. Only a tiny fraction of transactions represent potential money laundering, Temple says. "The software can eliminate the 99% of customers who are honest and point out the ones you need to know better."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Here is what the client expects us to develop...
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.