Thank you for Subscribing to CIO Applications Weekly Brief

Major Risks Open Banking Poses to Financial Crime Compliance
Compliance executives and teams at financial institutions should be worried that Open Banking would render their present AML/CTF and KYC compliance processes ineffective.
By
CIO Applications | Thursday, June 09, 2022

Customers may use additional services ranging from personal budgeting and expenditure alerts to private cash transfers and cryptocurrency wallets.
Fremont, CA: Compliance executives and teams at financial institutions should be worried that Open Banking would render their present AML/CTF and KYC compliance processes ineffective. An ecosystem of third-party suppliers is forming around open banking (TPPs). These organizations interact with FI systems to obtain data or transactional functions, using any manner from regulated Open Banking APIs to unmonitored screen scraping. Customers may use additional services ranging from personal budgeting and expenditure alerts to personal cash transfers and cryptocurrency wallets.
Here are key issues that compliance officers should consider when reviewing AML/CTF compliance processes for Open Banking:
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
• Widespread screen scraping of customer data
Many TPPs have screen-scraped data from banks' consumer online portals and applications using customers' login credentials, often without the bank's knowledge. Screen-scraping is deemed insecure, may fall beyond the established scope of existing AML standards, and its usage gets heavily regulated in the EU. As a result, banks must evaluate how to oversee this popular activity in areas where it is less regulated.
• When API technology fails, AML strategies are required.
A huge ecosystem of API vendors has evolved to assist fintech with various business operations, including KYC and AML checks. API providers might specialize in certain services. For example, while many companies offer KYC APIs, not all also provide AML/CTF checks. Fintechs may thus utilize a combination of API providers. FIs will need to examine norms and processes to manage technology failures such as API insufficiency and unavailability.
• Increased vulnerability to crypto attacks
Open Banking involves new, and well-known AML/CTF risks such as money laundering via bitcoin exchanges. Some cryptocurrency exchanges get geared to lure financial criminals by providing anonymity and concealing the source of cash. Whether regulated or not, KYP mechanisms must improve monitoring of the crypto sector for AML/CTF and sanctions adherence.
• The ecosystem demands continual scrutiny.
Concerns got raised that a TPP may get approved as an AISP – those that just read and acquire account information – but subsequently become a PISP – those that provide payment transactions without being permitted or becoming AML/CTF compliant. However, because the ecosystem will develop and evolve, vetting it for compliance will be a continual exercise for FIs.
More in News

