Transaction monitoring system
A transaction monitoring system with data mining and centralized case management addresses the inefficiencies in detecting suspicious transactions, improving compliance and reducing penalties for financial institutions.
Patent Information
- Application Number
- JP2025170313
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2012-08-27
- Filing Date
- 2025-10-08
- Publication Date
- 2026-02-18
AI Technical Summary
Financial institutions struggle to effectively detect and report suspicious transactions, particularly money laundering and terrorist financing, due to the limitations of traditional fraud detection methods that rely on behavioral changes, and face challenges in complying with regulations like the Bank Secrecy Act and USA PATRIOT Act, leading to significant penalties and resource wastage.
A comprehensive transaction monitoring system using a computer system that employs data mining and multiple detection algorithms to analyze transaction patterns over time, integrating results into a centralized case management platform, and records decision-making rationale for suspicious transactions, reducing human error and resource wastage.
Enhances the detection of suspicious transactions, including money laundering and terrorist financing, by minimizing false positives, optimizing resource utilization, and ensuring compliance with regulatory requirements, thereby reducing penalties and operational costs.
Smart Images

Figure 2026027236000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates generally to transaction monitoring systems.
[0002] More particularly, the present disclosure relates to assisting businesses in monitoring and detecting different types of suspicious transactions and assisting businesses in complying with various laws and regulations through computer systems. [Background technology]
[0003] The Bank Secrecy Act in the United States was first established in 1970. Under the Bank Secrecy Act, financial institutions must report suspicious transactions to the government. Historically, financial institutions train their front-line personnel (e.g., tellers) to observe and identify suspicious transactions. However, most financial institutions have not been able to effectively comply with the Bank Secrecy Act. After the 9 / 11 tragedies, U.S. legislators believe that true compliance with the Bank Secrecy Act by financial institutions may have prevented the 9 / 11 tragedies.
[0004] To further strengthen the Bank Secrecy Act, the U.S. Congress passed the USA PATRIOT Act, which imposes severe civil and / or criminal penalties for violations of the Bank Secrecy Act. Additionally, U.S. government agencies such as the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency (OCC), the Federal Reserve Banks (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), State Banking Departments, and the Department of Financial Institutions, among others, strongly urge financial institutions to comply with the Bank Secrecy Act, particularly in their obligation to submit Suspicious Activity Reports (SARs) to FinCEN.
[0005] Suspicious transactions cover a very broad scope: for example, money laundering, terrorist financing, fraud, embezzlement, identity theft, computer intrusion, self-dealing, bribery, false statements, forged documents, mysterious disappearances, etc. are all classified as suspicious transactions.
[0006] However, many financial institutions do not detect or report suspicious transactions. In fact, many financial institutions use products that are effective at preventing fraud but ineffective at preventing money laundering or other financial crimes. Generally, fraud can be detected based on changes in behavior because fraudsters who steal victims' personal information (or financial instruments) behave differently from their victims. If account transactions differ from expected transactions as derived from past behavior, computer systems can detect instances of fraud.
[0007] For example, U.S. application (Publication No. 2003 / 0177087) discloses that high-risk variables can indicate a change in the normal behavior of a given account, for example, if a transaction occurs outside of its profile. According to this publication, beta, delta, and theta models are used to detect transactions that occur outside of a customer's profile.
[0008] However, money laundering and some other financial crimes can be committed without changes in behavior. As a result, traditional approaches that detect fraud based on changes in behavior cannot detect some basic money laundering transactions or other financial crimes. In the realm of money laundering, high-risk customers may not be suspicious. For example, money service businesses (MSBs), pawnbrokers, ATM vendors, and flight attendants are commonly classified by banks as high-risk customers in anti-money laundering programs. However, that does not mean that these high-risk customers are engaging in money laundering transactions. Although high risk is associated with these customers, nothing about these customers may be wrong.
[0009] Some businesses are very difficult to monitor. For example, MSBs handle a large number of transactions every day, and a single money laundering transaction combined with a large number of transactions may go undetected by traditional approaches.
[0010] Challenges noted for compliance with the USA PATRIOT Act and the Bank Secrecy Act (BSA) are just a few examples illustrating the importance of identifying suspicious transactions. Identifying suspicious transactions can also be used to comply with other laws, such as the Fair and Accurate Credit Transactions Act (FACT Act), the Unauthorized Internet Gambling Improvement Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), regulations set by the Office of Foreign Assets Control (OFAC), and other laws and regulatory bodies.
[0011] Regulatory compliance is traditionally enforced by policies and procedures that require human workers to take certain actions depending on certain conditions. For example, to comply with the Bank Secrecy Act, banks train their branch tellers to observe and report anything that they find suspicious.
[0012] This traditional approach is no longer effective in the modern era because bank customers no longer need to appear in a bank branch. Customers can conduct electronic transactions remotely (e.g., ATMs, the Internet, etc.), and there are many financial products available to customers (e.g., checks, credit cards, debit cards, etc.). Furthermore, criminals are sophisticated and know how to avoid the attention of tellers. As a result, relying on tellers to detect suspicious transactions is insufficient for compliance with the Bank Secrecy Act.
[0013] Furthermore, the cost of this human-based approach is very high. Rigorous training must be performed regularly to ensure that human workers truly know how to respond to each different situation that complies with different laws and regulations. However, human workers are prone to error. In fact, due to human oversight, many financial institutions have failed to comply with different laws and regulations and have received severe punishment from government agencies.
[0014] The present disclosure provides several solutions that can detect different types of suspicious transactions and assist businesses in complying with different types of laws and regulations. Summary of the Invention
[0015] This disclosure leads to a comprehensive transaction monitoring system in which a computer system monitors transactions and detects suspicious transactions, which can then assist financial institutions in complying with the Bank Secrecy Act.
[0016] In addition to the Bank Secrecy Act, computer systems can help businesses comply with many other laws and regulations through transaction monitoring. Depending on the specific requirements of these laws and regulations, computer systems can monitor different types of transactions using different methods. This disclosure provides various details on how to monitor transactions and help businesses comply with different types of laws and regulations. This computer system can reduce or eliminate human burden and error, save resources and costs, and effectively achieve improved results for businesses.
[0017] In this disclosure, the term "network" generally refers to a communications network or networks that may be wireless or wired, private or public, real-time or non-real-time, or a combination thereof, and includes the well-known Internet.
[0018] In this disclosure, the term "computer" or "computer system" generally refers to either one computer or a group of computers that may work alone or together to accomplish the purpose of the system.
[0019] In this disclosure, the term "processor" generally refers to either one processor or a group of processors that may work alone or together to accomplish a processor purpose.
[0020] In this document, the term "module" refers to a single component or multiple components, which may be hardware, software, firmware, or a combination thereof, that may work alone or together to achieve the purpose of the module.
[0021] In this disclosure, "bank" or "financial institution" generally refers to a financial service provider, either a bank or a non-bank, through which financial and money services are provided. Some examples of financial institutions may be banks, credit unions, insurance companies, insurance agencies, stockbrokers, securities firms, mortgage finance companies, money services businesses, institutions for money services businesses, institutions for organizations providing financial services or money services, etc.
[0022] In this disclosure, a "bank account" or "financial account" refers to an account associated with a financial institution, either a bank or a non-bank, and financial transactions may be performed by financial instruments such as, for example, cash, checks, credit cards, debit cards, ATM cards, stored value cards, gift cards, prepaid cards, wires, monetary instruments, letters of credit, bills, securities, commercial paper, commodities, precious metals, electronic funds transfer, automated clearing facilities, etc.
[0023] In this disclosure, "financial transaction" generally refers to transactions related to financial transactions, including, but not limited to, payments, funds transfers, money services, payroll, billing, trading, escrow, insurance, underwriting, mergers and acquisitions, account openings, account closings, etc.
[0024] In this disclosure, "trading" generally refers to both private and public trading transactions, such as, but not limited to, stocks, currencies, commodities, rights, value, securities, derivatives, goods, services, products, etc.
[0025] In this disclosure, "securities" are generally referred to in accordance with the definition in the Securities Act of 1933. For example, securities may generally include notes, stock certificates, bonds, debentures, checks, drafts, warrants, travelers' checks, letters of credit, receipts, negotiable bills of lading, evidence of indebtedness, certificates of interest or participation in any profit-sharing agreement, ancillary trust instruments, pre-structured certificates or reservations, transferable shares, investment contracts, voting trust instruments, valid or blank motor vehicle certificates, property-related instruments, whether tangible or intangible, descriptions, documents, or written evidence of personal property, products, and goods, or the transfer or assignment of any right, certificate, or interest in personal property, products, and goods, or generally, any instrument commonly known as a "securities," receipts of warrants, any certificate of interest or participation in a temporary or provisional certificate, or a subscription or right to purchase any of the foregoing.
[0026] In this disclosure, "consumer" generally refers to a customer, person, subject, payer, payee, beneficiary, user, client, etc., seeking to conduct a transaction with an individual, organization, merchant, and / or financial institution.
[0027] In this document, the term "personal information document" generally refers to passports, driver's licenses, ballots, benefit slips, student ID cards, social security cards, national identity cards, identity cards, legal status certificates, and other certifiable official documents and information that identify a designated individual by some verifiable characteristic and that are issued by a consulate, embassy, government agency, private or public organization, or other governmental authority and are protected by a responsible party or parties against unauthorized copying or alteration. In particular, such "personal information documents" may be formed from a variety of materials, including paper, plastic, polycarbonate, PVC, ABS, PET, Teslin, composites, etc., and may have personal information embedded in them in a variety of formats, including printed or embossed on the document (or card), written on a magnetic medium, programmed into an electronic device, stored in memory, and combinations thereof. "Personal Information" may include, but is not necessarily limited to, name, identification number, date of birth, signature, address, password, telephone number, email address, personal identification number, tax identification number, national identification number, ID issuing country, ID issuing state, ID expiration date, photograph, fingerprint, iris scan, physical description, and other biometric information. The embedded information may be read through optical, acoustic, electronic, magnetic, electromagnetic, and other media.
[0028] For purposes of this disclosure, "personally identifiable information" generally refers to name, address, date of birth, personal identification number, user ID, password, tax identification number, type of personal information document used, identification number associated with the personal information document, country, state, governmental and / or private organization issuing the personal information document, expiration date of the personal information document, telephone number, screen name, email address, photograph, fingerprint, iris scan, physical description, and other biometric information.
[0029] For purposes of this disclosure, "personal information" includes personal identifying information, personal relationships, personal status, personal background, personal interests, and personal financial information, including information related to financial instruments, financial accounts, and financial transactions.
[0030] In this disclosure, "financial instruments" generally refer to instruments used to effect financial transactions. Examples of financial instruments include cash, credit cards, debit cards, ATM cards, prepaid cards, stored value cards, gift cards, checks, monetary instruments, wire transfers, AHC transfers, letters of credit, bills, securities, commercial paper, commodities, gold, silver, etc.
[0031] In this disclosure, "personal communication device" generally refers to a device interface used for personal communication purposes.
[0032] In this disclosure, "device interface" generally refers to keyboards, keypads, monitors, displays, terminals, computers, control panels, vehicle dashboards, network interfaces, mechanical interfaces, video interfaces, audio interfaces, electrical interfaces, electronic interfaces, magnetic interfaces, electromagnetic interfaces including electromagnetic wave interfaces, optical interfaces, light interfaces, acoustic interfaces, video interfaces, audio interfaces, contactless interfaces, mobile phone interfaces, smartphone interfaces, smartbook interfaces, other communication device interfaces, personal digital assistant (PDA) interfaces, handheld device interfaces, portable device interfaces, wireless interfaces, wired interfaces, and other interfaces.
[0033] As used herein, the term "terminal" or "kiosk" generally refers to devices that interface a user with a computer network, including computers and / or their peripherals, microprocessors and / or their peripherals, ATM terminals, check cashing kiosks, money services kiosks, merchant checkout stations, cash registers, currency exchange machines, parking payment kiosks, other payment kiosks, contactless devices, wired phones, mobile phones, smartphones, smartbooks, personal communication devices, tablet devices, digital assistants, entertainment devices, network interface devices, routers, and / or personal digital assistants (PDAs), etc., that enable a user to interact with computer systems and other devices connected to the computer network.
[0034] Additionally, reference should be made to co-pending applications entitled "Global Customer Identification Network" (U.S. Patent Application Publication No. 2012 / 0123942 to SONG et al.) and "Paperless Coupon Transactions System" (U.S. Patent Application Publication No. 2011 / 0225045 to SONG et al.), which are expressly incorporated herein by reference in their entireties.
[0035] The features and technical advantages of the present disclosure have been outlined broadly in order that the detailed description that follows may be better understood. Additional features and advantages of the present disclosure will be described below. It should be understood by those skilled in the art that this disclosure may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of the present disclosure. It should also be understood by those skilled in the art that such equivalent constructions do not depart from the teachings of the disclosure as set forth in the appended claims. The novel features believed to be characteristic of the present disclosure, both as to method of operation and structure, together with further objects and advantages, will be better understood from the following description when considered in connection with the accompanying drawings. It is to be expressly understood, however, that each of the figures is provided for the purpose of illustration and description only and is not intended as a definition of the limits of the present disclosure. [Brief explanation of the drawings]
[0036] The features, characteristics, and advantages of the present disclosure will become more apparent from the following detailed description when taken in conjunction with the drawings. [Figure 1] Figure 1 illustrates a system and network diagram of a computer system for transaction monitoring to enable BSA enforcement officers, compliance enforcement officers, security enforcement officers, and / or other responsible parties to comply with different types of laws and regulations. [Figure 2] Figure 2 is a flowchart of an example process illustrating how a BSA enforcement officer, compliance officer, security officer, or other responsible person may detect and report suspicious transactions using the computer system illustrated in Figure 1.
[0037] The following detailed description, associated with the accompanying drawings, is intended as a description of various configurations and is not intended to represent the only configurations in which the concepts described herein may be practiced. The detailed description includes specific details intended to provide a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring such concepts. As used herein, the use of the term "and / or" is intended to mean "inclusive or," and the use of the term "or" is intended to mean "exclusive or." DETAILED DESCRIPTION OF THE INVENTION
[0038] The U.S. government strictly compels businesses, especially financial institutions (e.g., banks, credit unions, mortgage lenders, money service businesses, stockbrokers, insurance companies, etc.), to comply with laws such as the USA PATRIOT Act, the Bank Secrecy Act (BSA), the Fair and Accurate Credit Transactions Act (FACT Act), the Unauthorized Internet Gambling and Gambling Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), regulations set by the Office of Foreign Assets Control (OFAC), and other laws and regulations. Hundreds of millions of dollars have already been collected by U.S. government authorities and agencies in civil monetary penalty statutes (CMPs) against some financial institutions for violating these laws and regulations. Criminal penalties have also been issued against some individuals working for financial institutions.
[0039] Financial institutions are just one type of business. Financial institutions are not the only organizations that must comply with these laws and regulations. Many businesses also must comply with these laws and regulations. Financial institutions are under more pressure because they are closely regulated by government agencies. This disclosure applies to all businesses that are required to comply with laws and regulations to prevent different types of crime.
[0040] The laws and regulations of the United States are used as examples in this disclosure. Similar laws and regulations exist in many other countries. Furthermore, this disclosure is applicable in those countries to assist businesses in complying with their respective laws and regulations.
[0041] Similarly, the Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC) are U.S. organizations. Many other countries have similar organizations that perform similar tasks. This disclosure may also be used to comply with the requirements of those organizations.
[0042] Very often, it is unclear whether a person or group of people actually engaged in suspicious transactions. According to the Bank Secrecy Act in the United States, when a business files a Suspicious Transaction Report (SAR) with FinCEN, it is under no obligation to prove whether the reported transactions are truly illegal. In fact, the "immunity" rule encourages businesses to report more suspicious transactions without worrying about the repercussions of being accused of falsely reporting legitimate transactions. Under this "immunity" rule, no person (or organization) can file a lawsuit against any entity because the entity has filed a Suspicious Transaction Report (SAR) with FinCEN about that person (or organization). SARs are used by the government to gather information, and businesses are only expected to provide information and opinions in the SAR. Whether the transactions reported in the SAR are truly suspicious is determined by the government agency based on its own investigation.
[0043] In general, the decision process regarding whether to report a suspicious transaction (that is not fraud) is often very different from the decision process regarding whether to report a fraud case. In the case of a fraud case, someone (either the business or the consumer) may lose money. Therefore, this is generally an obvious situation. Therefore, whether to report a fraud case is an easy decision. In fact, it is also easier to prevent fraud. Generally, when a computer system detects a high fraud risk associated with a transaction, it can immediately block the transaction and have an investigator investigate the transaction to determine whether it is indeed a fraud case.
[0044] In one aspect of the present disclosure, for fraud detection purposes, a computer system calculates a risk score associated with a transaction based on a number of different factors associated with the transaction, which may include, for example, the account's past activity, deviations from expected activity, location, time, amount, frequency and characteristics of the transaction, relationships between multiple accounts, account holder type, characteristics and composition, etc.
[0045] In one aspect of the present disclosure, for fraud detection, the computer system blocks a transaction if the fraud risk score of the transaction exceeds a threshold, which may be predetermined based on business policies.
[0046] In one aspect of the present disclosure, for fraud detection, a computer system generates cases based on detected high fraud risk transactions, and the cases and associated information are presented to an investigator for further investigation.
[0047] In comparison, whether to report a suspicious transaction (that is not fraudulent) is not an easy decision because there may not be clear evidence to prove illegal activity. For example, if a customer frequently deposits large amounts of cash, according to a bank's anti-money laundering monitoring practices, it is possible that this customer sells drugs and receives cash as payment. It is also possible that this customer sells homemade products at an agricultural market that only accepts cash as payment. Many times, due diligence is required to determine whether something suspicious exists.
[0048] Furthermore, a customer may sell their homemade products at a farm market but secretly sell drugs elsewhere. If the bank does not actually buy drugs from this customer, or if the customer (or anyone) does not tell the bank that the customer is selling drugs, the bank has no evidence to prove that the customer is selling drugs. However, if the customer does sell drugs and the bank does not report these suspected transactions to FinCEN, as soon as the customer is caught by the government selling drugs, the bank could later face severe penalties for failing to report the case to FinCEN.
[0049] On the other hand, if a bank were to report every case that even remotely had the slightest possibility of being suspicious, the bank could attract unnecessary attention from government agencies, which could take months internally to investigate the bank's operations and have a very adverse effect on the bank's operations.
[0050] Therefore, whether or not to report a case is often a matter of personal opinion by the person investigating the case. Furthermore, this decision-making process can be quite subjective. Furthermore, a business cannot block a transaction simply because it appears to be a suspicious money laundering transaction. A consumer could sue a business for blocking the consumer's transaction if the business cannot actually prove that money laundering occurred. In fact, many government agencies often advise businesses that report suspected (non-fraudulent) transactions, such as money laundering or terrorist financing, to remain calm and treat the suspicious transaction as a normal transaction, lest suspects become alarmed and flee. This approach gives government agencies more time and opportunity to identify all perpetrators involved.
[0051] Under U.S. bank secrecy laws, a business that files a SAR is obligated to keep it confidential and cannot inform the suspect (i.e., anyone involved in the case) about anything related to the SAR, including its existence. SARs can only be investigated by authorized government agencies. Even if a judge knows about the existence of a SAR in his or her case, the judge cannot see the contents of the SAR.
[0052] Because handling suspicious transaction cases is, as previously discussed, very different from handling fraud cases, many traditional approaches and concepts applicable to fraud detection and prevention are no longer effective for detecting and managing suspicious transactions, such as money laundering, terrorist financing, elder abuse, online gambling, etc. In one aspect of the present disclosure, the computer system records the opinion of a person who decides not to report a detected suspicious transaction case. Under such circumstances, it is important to record the person's justification for making such a decision.
[0053] Unlike fraud cases, suspicious transaction cases may not be revealed to those investigating the case until further evidence becomes available. Thus, a person may initially dismiss a detected suspicious transaction case but later change their mind if further evidence becomes available. In one aspect of the present disclosure, a person investigating a detected suspicious transaction case may also need to review all previously detected cases involving the same suspect to determine whether any new evidence, perhaps when combined with older evidence from dismissed cases, makes the newly detected case more suspicious. As a result, even if a case was previously dismissed as a false positive, the dismissed case may later be re-investigated.
[0054] This suspicious transaction case investigation practice is very different from fraud case investigation practice because fraud cases usually have a clear conclusion. If the customer is the fraudster, the customer's account will be immediately closed and there will be no future transactions associated with the customer. If the customer is the victim of fraud, the detected fraud case has no bearing on the customer and the evidence will not be used against the customer in the future. Therefore, fraud investigators typically focus only on newly detected cases and make quick decisions. Conversely, non-fraud suspicious transaction investigators may need to investigate the history of detected cases and make a decision after intensive investigation and analysis. In one aspect of the present disclosure, the justification for the decision not to report the suspicious transaction is stored in a database and available for future reference.
[0055] In another aspect of the present disclosure, the computer system also records the personal information of individuals who decide not to report a detected case. In yet another aspect of the present disclosure, the computer system compares decisions made by multiple individuals not to report suspicious transactions of the same suspect (or group of suspects) to determine whether any individuals are attempting to conceal a detected suspect or case.
[0056] For a large business, thousands of suspicious transactions may be detected each month. A group of people may be required to investigate these detected cases to determine whether the business needs to file SARs for these cases. In one aspect of the present disclosure, a computer system automatically assigns detected cases to different people based on policies set by the business.
[0057] In another aspect of the present disclosure, the computer system monitors and records the status of each detected case, and if a case is indicated for investigation by a particular person, the computer system will alert the business to such delays.
[0058] In yet another aspect of the present disclosure, the computer system monitors the workload of each person investigating detected cases, and if this person is investigating an abnormally high number of cases compared to others investigating detected cases during the same time period, this person may be a suspect or a suspicious person.
[0059] On the other hand, if this person investigates an unusually small number of cases when compared to others investigating detected cases during the same period, this person may also be a suspect or suspicious person. In either of the above two situations, a business manager may want to investigate the situation and reach their own conclusions and solutions.
[0060] In one aspect of the present disclosure, the computer system monitors the workload of each person investigating detected cases, and if this person dismisses an abnormally large number of cases compared to others investigating detected cases during the same time period, this person may be a suspect or a suspicious individual.
[0061] In another aspect of the present disclosure, if this person dismisses an unusually small number of cases when compared to others investigating detected cases during the same time period, this person may also be a suspect or suspicious person. In either of the above two situations, a manager of the business may wish to investigate the situation and reach their own conclusions and solutions.
[0062] Generally, since suspicious transactions can occur in many different types of transactions, many detection algorithms are used to detect suspicious transactions. Because the detection of suspicious transactions is not obvious, some detected cases may not be truly suspicious after investigation. Under such circumstances, such detected cases are "dismissed" as false positives or false positives. False positives or false positives are generally referred to as the conclusion of the case investigation, rather than as reasons to justify why the case was dismissed.
[0063] For example, if several customers live at the same address and deposit large amounts of cash into a financial institution, the case may be about a drug dealer family, with many of the family members depositing proceeds from drug sales. However, after investigation, it may be determined that the case is actually a group of students living together who are depositing tips received from working at a restaurant. The justification for the decision not to report this case should be "students living together are depositing tips received from part-time work." The conclusion of the detected case would then be a "false conclusion" or a "false positive" depending on this reason.
[0064] Typically, after investigation of a detected case, the case may be classified as a false positive (or a false positive) by the person investigating the case. In one aspect of the present disclosure, the computer system provides information and / or statistics for a user to analyze all detected cases classified as false positives. From these false positives, the user may identify detection algorithms that have produced an unusually high number of false positives. The user may further improve these detection algorithms to be more effective in detecting future suspicious transactions.
[0065] The USA PATRIOT Act, Bank Secrecy Act (BSA), Anti-Money Laundering (AML), and Anti-Terrorist Financing (ATF) have become the most important compliance issues in the financial industry since 9 / 11. Many financial institutions have invested significant capital in these compliance issues, yet still miss genuine money laundering and terrorist financing cases.
[0066] The root cause of these compliance problems is that many financial institutions do not detect even basic cases of money laundering, and senior management at financial institutions struggle to understand these problems. Many financial institutions use fraud detection principles to detect money laundering transactions and the mixing of fraudulent and non-money laundering cases.
[0067] In reality, however, money laundering is very different from fraud. Fraud detection products can easily compare an account holder's current transactions with the account holder's past transactions and detect possible fraud if the current transactions deviate from the expected transactions derived from the past transactions. For example, if a fraudster steals a victim's credit card, the fraudster will make purchases that differ from the victim's past transactions. It is simply a matter of time before the credit card company detects the fraudulent transactions and blocks the credit card. If a new account does not yet have a sufficient past record, fraud detection products can compare the account holder's current transactions with what the account holder said during the account opening process.
[0068] Because the goal of fraud detection products is to stop losses as quickly as possible, financial institutions typically perform fraud detection or risk scoring in real time, or at least once daily. In contrast, real-time risk scoring, real-time detection, daily risk scoring, and daily detection methods that are effective for fraud detection cannot detect many basic money laundering transactions. In fact, as previously explained, high-risk customers may not be money launderers. Assuming that high-risk customers are conducting suspicious money laundering transactions is a waste of time.
[0069] Financial institutions typically have Bank Secrecy Act Enforcement Officers (BAS Enforcement Officers) responsible for reporting suspected money laundering or terrorist financing transactions to FinCEN. The following example illustrates how BSA Enforcement Officers within a financial institution may waste significant time investigating real-time or daily risk scoring results while missing actual money laundering cases. This example consists of the following facts: (a) Client A transfers less than $3,000 to XYZ around the 5th of each month. (b) Client B transfers less than $3,000 to XYZ around the 8th of each month. (c) Client C transfers less than $3,000 to XYZ around the 12th of each month. (d) Client D transfers less than $3,000 to XYZ around the 17th of each month. (e) Client E transfers less than $3,000 to XYZ around the 24th of each month. (f) Client F transfers less than $3,000 to XYZ on or about the 29th of each month. (g) A, B, C, D, E, and F are unrelated individuals. And (h) XYZ is a Los Angeles drug dealer with no prior criminal history.
[0070] In the above example, if a BSA officer were to compare a client's current transactions with the client's past transactions to detect changes in behavior, the BSA officer would not detect any anomalies because the client consistently performs similar transactions month after month. When a bank teller asks a client about the purpose of a fund transfer, the client could easily lie. Because these clients perform these transactions on different days of the month, the BSA officer would not be able to detect risk on a given day of the month.
[0071] Furthermore, because these clients are not related, BSA enforcement officers would not see their entire transactions. Furthermore, because each transaction involves only a small amount of dollars that occurs once a month, and the recipients of the funds live in U.S. cities with large populations and active commercial transactions, none of these clients would be viewed as high-risk or suspicious based on these transactions. As a result, fraud detection products would miss these basic cases of money laundering, despite the fact that BSA enforcement officers work diligently with fraud detection products every day.
[0072] In one aspect of the present disclosure, to detect these money laundering cases, a computer system collects transaction data from a financial institution and performs data mining based on anti-money laundering and anti-terrorist financing scenarios across all transactions of all clients for a 30-day or longer period. The computer system collects details of all funds transfer transactions within the financial institution from different data sources, such as wire, ACH, card payments, mobile payments, etc., and identifies common recipients of these funds transfer transactions.
[0073] If a common payee is identified, the computer system may show the financial institution's BSA enforcement officer all transactions sent to the common payee. The BSA enforcement officer investigates the transactions identified by the computer system. The BSA enforcement officer also investigates all past cases linked to the suspect in the newly detected case. If the BSA enforcement officer (i.e., responsible person) agrees that such transactions are suspicious because the common payee has received so much money, the computer system assists the BSA enforcement officer in filing a SAR with FinCEN. If the BSA enforcement officer decides not to file a SAR, he or she enters into the computer system the reasons justifying his or her decision not to report the detected transaction.
[0074] As can be easily understood, mining the vast amount of transaction data accumulated over time for all of a financial institution's clients is time-consuming, even for very small financial institutions. Since financial institutions do not directly lose any money in money laundering cases, according to regulatory guidelines, BSA enforcement officers have a maximum of 30 days to file a SAR. This example illustrates the waste of time and resources involved in performing daily or real-time risk scoring, which would actually miss genuine money laundering transactions.
[0075] In fact, many BSA enforcement officers express a common frustration that they waste time daily on false positives at the expense of detecting actual cases of money laundering. This frustration is the result of the widespread erroneous notion that money laundering and fraud are crimes often perpetrated by the same criminals and should be detected together based on detected behavioral changes. After purchasing fraud detection products, some financial institutions attempt to simultaneously detect both money laundering and fraud cases. This results in significant wasted time, money, and resources. This erroneous notion can be corrected with a proper understanding of the sophisticated facets of transaction risk.
[0076] Transaction risk is defined as the risk directly associated with a transaction. For example, money laundering risk and fraud risk are directly associated with a transaction. However, these risks have very different characteristics. Customers who launder money through financial institutions intend to use the institution as a means to achieve their own goals. These money launderers usually pretend to be "good customers" because they need the financial institution's support to carry out their schemes. They do not care about paying additional taxes or losing interest on their money. Therefore, from the financial institution's perspective, these money launderers appear to be good customers. This is one of the main reasons why financial institutions need to perform data mining on all transactions to detect money laundering transactions hidden behind the scenes.
[0077] In comparison, fraud risks present themselves very differently. Fraud committed by customers is generally divided into two categories: (1) third-party fraud and (2) counter-party fraud. Third-party fraud is defined as fraud committed by a third party that is neither the financial institution nor the customer. For example, if a fraudster (i.e., the third party) steals a check from a customer, both the financial institution (i.e., the primary party) and the customer (i.e., the counter party) may be victims. Under such circumstances, the transaction initiated by the third-party fraudster has no connection to the customer. Therefore, it is a waste of time, money, and resources if BSA enforcement officers are misled by ineffective fraud detection that assumes a customer is engaging in money laundering (e.g., when there is a change in behavior) because the customer is merely a victim of fraud committed by a third party.
[0078] Counterparty fraud is defined as fraud committed by a customer (i.e., the counterparty) who defrauds a financial institution (i.e., the primary party). Once the customer successfully defrauds the financial institution, they immediately disappear and do not use the financial institution to launder money. A fraudster may use Financial Institution A to launder money that the fraudster stole from Financial Institution B. To Financial Institution B, this is a fraud case. To Financial Institution A, this is a money laundering case. However, neither Financial Institution A nor Financial Institution B sees any fraud or money laundering cases that occur with this same customer. Clearly, a system intended to detect fraud cases daily would systematically generate many false positives for money laundering and actually miss true money laundering cases. Using such an approach increases the workload of BSA enforcement officers and exposes financial institutions to unnecessary regulatory risk.
[0079] There are many other risks under the category of third-party fraud that are worth noting. For example, counterfeit checks, credit card fraud, debit card fraud, ATM fraud, online fraud, etc. are typical risks under the category of third-party fraud. Similarly, under the category of counter-party fraud, there are many different risks such as check fraud, deposit fraud, loan fraud, etc. Therefore, a good transaction risk management system will use multiple detection algorithms that intelligently consider the unique characteristics of each of the different types of fraud to correctly detect fraud.
[0080] Furthermore, as previously explained, many customers launder money or fund terrorist financing by conducting one small transaction for each person together on different days, and daily monitoring would miss such cases. This leads to the logical conclusion that a system using a single method to detect behavioral changes would waste resources and miss true cases of money laundering and terrorist financing. In one aspect of the present disclosure, money laundering and terrorist financing transactions are detected by a different detection method that performs data mining based on user-defined scenarios on all transactions across a financial institution accumulated over a period of time.
[0081] In one aspect of the present disclosure, a computer system utilizes multiple detection methods to monitor transactions and integrates these detection results into a centralized case management platform. This approach maximizes and streamlines anti-money laundering, anti-fraud, and anti-financial crime efforts while maintaining a holistic, accurate picture at all times. As a result, financial institutions can efficiently comply with regulatory requirements, eliminate risk, avoid losses, boost productivity, minimize resources in managing transaction risk, reduce costs associated with hardware, databases, and software, lower IT maintenance workloads, and increase overall profitability.
[0082] In one aspect of the present disclosure, a computer system compares a customer's (or a group of customers') transaction patterns with several known money laundering transaction patterns to detect suspected money laundering transactions. If there is a match, a possible money laundering transaction may be detected.
[0083] For example, many criminals know that if more than $10,000 in cash is deposited into a bank account on the same day, the bank must file a Currency Transaction Report (CTR) with the U.S. government. To avoid filing a CTR, criminals often split one large cash deposit into multiple smaller cash deposits, each made on a different day and each for less than $10,000. This transaction pattern is a known money laundering transaction pattern, and computer systems can detect this type of transaction pattern. There are many other types of transaction patterns known as money laundering transaction patterns. Computer systems can be designed to detect each of these known money laundering transaction patterns. As a result, money laundering transactions can be detected based on suspicious transaction pattern(s), even without any change in behavior.
[0084] In one aspect of the present disclosure, a BSA enforcement officer (or responsible officer) investigates the detected case to determine whether it is a true money laundering case. In one aspect of the present disclosure, the BSA enforcement officer also investigates all past cases associated with the suspect(s) in the currently detected case. In one aspect of the present disclosure, if the BSA enforcement officer agrees that such a transaction is suspicious, the computer system assists the BSA enforcement officer in filing a SAR with FinCEN. In another aspect of the present disclosure, if the BSA enforcement officer decides not to file a SAR, the BSA enforcement officer enters into the computer system a reason justifying the decision not to report the detected transaction.
[0085] In another aspect of the present disclosure, to detect suspected money laundering transactions, groups of customers with at least one common risk factor (or characteristic), such as, for example, business type, business model, organizational structure, size, location, product, service, carrier type, location, etc., are compared together. If one customer's transactions (e.g., transaction pattern, transaction volume, transaction frequency, transaction trend, transaction number, transaction amount, transaction derivative, etc.) differ from those of other customers, the customer may have engaged in suspected money laundering transactions. In one aspect of the present disclosure, statistics, such as the median, variance, standard deviation, etc., of a group of customers are used to facilitate these comparisons. Similarly, if one customer behaves differently from other customers with the same set of risk factors (or characteristics), the customer may have engaged in suspected money laundering transactions. As a result, suspicious money laundering transactions may be detected even if there is no change in account behavior.
[0086] Often, it is not easy to compare groups of customers together. For example, an MSB with 100 branches may conduct more cash transactions than another MSB with only two branches. In one aspect of the present disclosure, to achieve a more effective comparison, it is useful to compare some derivatives (e.g., ratios of some numbers) instead of the original raw data. For example, the ratio may be "total cash withdrawals from the bank divided by the total number of checks deposited in the bank." In this example, the number of checks deposited may be used to measure the size of the MSB's check cashing operations. Thus, the ratio "total cash withdrawals divided by total number of checks deposited" essentially scales the check cashing operations of an MSB with 100 branches to roughly the same level, so that they can be compared from an apples-to-apples perspective, based on check cashing transactions.
[0087] Many other derivations may also be used to achieve good comparisons. Generally, derivations for more effective comparisons may involve a first profit variable divided by a second variable measuring the size of the business (or operation). For example, "total ACH withdrawal transaction volume divided by total checks deposited," "total wire withdrawal transaction volume divided by total checks deposited," "total number of prepaid cards issued divided by total checks deposited," "total ACH withdrawal transaction volume divided by total branch offices," "total wire withdrawal transaction volume divided by total branch offices," "total number of prepaid cards issued," "total ACH withdrawal transaction volume divided by total prepaid cards issued," "total wire withdrawal transaction volume divided by total prepaid cards issued," etc. are just a few examples of possible derivations that may be used. In one aspect of the present disclosure, other forms of mathematical transformations, in addition to the ratios above, produce derivations.
[0088] In one aspect of the present disclosure, a computer system compares the derivation of a particular customer to the derivation of a group of customers who share at least one risk factor (or characteristic) with the particular customer (e.g., the same type of business or occupation). If the derivation of the particular customer significantly deviates from the derivation of the group of customers, the particular customer may have engaged in suspected money laundering transactions. In one aspect of the present disclosure, statistical analysis of the group of customers, such as median, variance, standard deviation, etc., facilitates such comparison.
[0089] In one aspect of the present disclosure, the computer system uses many different risk factors to determine the money laundering risk of each customer of the financial institution. For example, these risk factors may be industry, customer category, customer business type, customer geographic area, customer country of address, customer business characteristics, business product type, business service type, business structure, customer occupation, nationality, past record, type of transaction performed, account balance, fund inflow, fund outflow, transaction pattern, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivation, transaction location, transaction time, transaction country, sender of remittance transaction, sender location, sender country, sender characteristics, recipient of remittance transaction, recipient location, recipient country, recipient characteristics, relationship, social status, political exposure, past transactions, etc. Indeed, thousands of risk factors may be considered to determine a customer's money laundering risk. "Risk factors" are also called "risk dimensions."
[0090] In one embodiment of the present disclosure, each degree of risk of the same type is a risk factor and assigned a risk score. For example, the total cash transaction volume within a 30-day period may be used to measure the degree of risk associated with money laundering. For example, we may define the total cash transaction volume as follows: $0 to $5,000, $5,001 to $50,000, $50,001 to $250,000, $100, $250,001 to $1,000,000, $200, $1,000,001 to $10,000,000, $500, and $10,000,000 or more, $1,000. In this example, someone who made total cash transactions of $60,000 during a 30-day period would have a risk score of 100.
[0091] "Cash transaction volume" is used merely as an example. Other considerations, such as the volume of cash transactions, the acceleration of cash transactions, etc., may also be used as a risk associated with money laundering. In addition to cash, other financial transactions, such as checks, wires, ATMs, ACHs, credit cards, debit cards, prepaid cards, monetary instruments, transfers, etc., may also be used as a risk associated with money laundering. One skilled in the art can readily recognize many risk factors based on the above examples.
[0092] In one aspect of the present disclosure, each risk factor is assigned a risk score, and the customer is assigned a total risk score, which may be the sum of all of the risk scores of the risk factors associated with the customer. This total risk score may be used to determine the level of risk associated with the customer. Summation is used as an example in this disclosure. In fact, many different types of mathematical transformations may be used to achieve a similar effect.
[0093] As previously explained, unlike in fraud situations, high-risk clients may not be suspected of money laundering or terrorist financing. High risk can simply be a characteristic of the client. For example, MSBSs, pawnbrokers, car dealers, pilots, flight attendants, etc. are often classified as high-risk clients for anti-money laundering and anti-terrorist financing purposes, but this does not mean that these clients are conducting money laundering transactions or terrorist financing.
[0094] Nevertheless, because the customer has a high risk score, they may be monitored more closely and a different monitoring method may be applied. Thus, in one aspect of the present disclosure, a customer's total risk score is used to determine the monitoring method to be applied to monitor the customer. If the customer's total risk score is higher, a more strict monitoring method may be applied to monitor the customer. If the customer's total risk score is lower, a more lenient monitoring method may be applied to monitor the customer.
[0095] In other words, in one aspect of the present disclosure, a customer's total risk score is not used to determine whether the customer is suspicious, but instead is used to select an algorithm or set of algorithms for monitoring the customer.
[0096] In one aspect of the present disclosure, groups of customers with the same risk factors are compared together. For example, we may compare all customers who are flight attendants together. In one aspect of the present disclosure, if a particular flight attendant's total risk score is much higher than the baseline total risk scores of all flight attendants in this comparison, this particular flight attendant may have engaged in some suspected money laundering transactions. The baseline may comprise an average, median, weighted average, and / or other statistical value.
[0097] Statistical approaches can also be applied to facilitate the detection of suspicious transactions. For example, the center, variance, and standard deviation can be derived from the total risk scores of all customers who are flight attendants. In one aspect of the present disclosure, if a particular flight attendant's total risk score is four or more standard deviations higher than the average total risk score of all flight attendants, then this particular flight attendant may have committed a suspicious transaction.
[0098] The above criterion of "four times" is merely an example. The number "four" can be any number, such as 3.75, 4.21, 10, etc. In one aspect of the present disclosure, if a particular flight attendant's total risk score is more than x standard deviations higher than the median total risk score of all flight attendants, then this particular flight attendant may have engaged in suspected money laundering transactions, where x is a number assigned by a BSA enforcement officer (or responsible person). This statistical approach can be applied whenever a group comparison is used.
[0099] Flight attendants are merely an example used to illustrate this method of detecting suspicious money laundering transactions among a group of entities. Indeed, many other risk factors may be used for similar purposes. Because there are thousands of risk factors, in one embodiment of the present disclosure, the computer system allows a user to select any risk factor to identify all customers with the same risk factor. In one embodiment of the present disclosure, a particular customer may be conducting suspicious money laundering transactions if they have a total risk score that is significantly higher than the baseline total risk scores of other customers with the same risk factor. This baseline may comprise an average, median, weighted average, and / or other statistical value.
[0100] Instead of a single risk factor, a group of risk factors can also be used. Indeed, a group of risk factors can improve the accuracy of detection results. For example, in addition to the risk factor of occupation (e.g., flight attendant), the arrival country of the flight on which the flight attendant works can be another risk factor that can be useful for detecting money laundering risks. For example, a flight attendant working on a flight between New York and Chicago may have a different transaction than another flight attendant working on a flight between Miami and Mexico City. Comparing subgroups of flight attendants working on flights between Miami and Mexico City may be more accurate. In this example, two risk factors, namely, flight arrival / destination city and occupation, are considered to improve the accuracy of detection.
[0101] In one embodiment of the present disclosure, a set of risk factors is used to identify a group of entities. If a particular entity has a total risk score that is significantly higher than the total risk score of all entities with the same set of risk factors, the particular entity may have engaged in suspicious money laundering transactions. This criterion may comprise a mean, median, weighted average, and / or other statistical value. To facilitate comparisons between groups of entities, group statistics such as median, variance, standard deviation, etc. may be derived. As a result, a computer system may detect suspicious money laundering transactions based on the above approach, even when there is no change in account behavior.
[0102] Often, such entities are so different from the other entities that it may be useful to exclude some entities from the group comparison process. In one aspect of the present disclosure, the computer system allows a user to select some entities that will not be included in the group comparison process.
[0103] Detecting flight attendants as having suspicious money laundering transactions is just one example. Similar methods can be applied to many other different situations. For example, money service businesses (MSBs) have many transactions every day, and one money laundering transaction can be hidden among many other legitimate transactions, so it is usually very difficult for a bank or credit company to detect an MSB customer as having suspicious money laundering or terrorist financing transactions.
[0104] In one aspect of the present disclosure, an additional risk factor (e.g., proximity to the Mexican border) is used to identify a group of MSBs with the same set of risk factors (i.e., in addition to the first risk factor—business type). If a particular MSB has a total risk score higher than a measure of the total risk scores of all MSBs with the same set of risk factors, the particular MSB is likely conducting suspected money laundering transactions. This measure may comprise a mean, median, weighted average, and / or other statistical value. Similarly, group statistics such as median, variance, standard deviation, etc., may be derived to facilitate such comparisons between groups of MSBs.
[0105] Often, it is not easy to compare groups of MSBs because they may have different types of operations and different sizes. In one embodiment of the present disclosure, part-time MSBs and full-time MSBs may have different business characteristics and therefore are assigned two different risk factors. In another embodiment of the present disclosure, a risk factor is assigned to each different type of MSB product and / or service. For example, a risk factor is assigned to each of remittance services, check cashing, currency exchange, prepaid card management, etc., even though they are all provided by the same MSB. In one embodiment of the present disclosure, a set of risk factors that precisely defines the type of service and / or product is used to identify risk.
[0106] In one aspect of the present disclosure, some risk factors are adjusted based on the size of an operation to make group comparisons more effective. For example, an MSB with 50 branches may typically have five times the total cash transaction volume of another MSB with 10 branches. Often, to perform group comparisons, risk factors affected by the size of these operations may be adjusted to account for the size of these operations. For example, for an MSB with 50 branches, the total cash transaction volume over a 30-day period is divided by 50 to establish adjusted risk factors and risk scores for group comparisons. Branches are used here as an example to measure the size of an operation. Other information, such as the number of customers, the number of transactions, the number of employees, the size of assets, etc., may also be used to measure the size of an operation.
[0107] In one aspect of the present disclosure, a set of risk factors adjusted based on the size of the operation (“adjusted risk factors”) is used to identify a group of entities having this adjusted set of risk factors. The risk score for the adjusted risk factors is referred to as the adjusted risk score. A particular entity may have conducted suspected money laundering transactions if it has a total adjusted risk score that is significantly higher than the total adjusted risk score of all entities having the same set of adjusted risk factors. This measure may comprise an average, median, weighted average, and / or other statistical value. Generally, in one aspect of the present disclosure, a detection algorithm that incorporates risk factors may also be modified to incorporate adjusted risk factors into the detection algorithm. A detection algorithm that incorporates risk scores may also be modified to incorporate adjusted risk scores into the detection algorithm.
[0108] To facilitate comparisons between groups of entities, group statistics such as median, variance, standard deviation, etc. may be derived based on the adjusted risk factors and adjusted risk scores. As a result, a computer system may detect suspected money laundering transactions based on the above approach, even if there is no change in behavior in any of the accounts.
[0109] Because MSBs may have different transactional patterns than other types of businesses, it is more efficient to monitor MSBs based on their unique transactional patterns. Therefore, in one embodiment of the present disclosure, different sets of detection algorithms may be used to monitor entities with different sets of risk factors. In one embodiment of the present disclosure, a set of risk factors is used to identify a group of entities with the set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering transactions among the group of entities. From another perspective, a set of detection algorithms is selected to monitor a group of entities based on the set of risk factors associated with the group of entities.
[0110] In another aspect of the present disclosure, a set of risk factors is adjusted based on the size of the operation and used to identify a group of entities having the adjusted set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering transactions among the group of entities. From another perspective, a set of detection algorithms is selected to monitor a group of entities based on the set of adjusted risk factors associated with the group of entities.
[0111] It is often meaningful to monitor entities with higher risks that are closer than entities with lower risks. Therefore, different sets of detection algorithms are used to monitor different entities with different levels of risk. In one aspect of the present disclosure, a set of detection algorithms is selected to monitor an entity based on the entity's total risk score. In another aspect of the present disclosure, a set of detection algorithms is selected to monitor an entity based on the entity's total adjusted risk score, where the total adjusted risk score is obtained from the risk scores of the adjusted risk factors.
[0112] In one aspect of the present disclosure, when an MSB is detected as having possible money laundering transactions, the computer system may identify a transaction (or group of transactions) for the detected MSB that has a higher total risk score than a measure of the total risk scores of all MSBs. This measure may comprise an average, median, weighted average, and / or other statistical value. When an MSB is detected as having possible money laundering transactions, the computer system may identify a transaction (or group of transactions) for the detected MSB that has a higher total adjusted risk score than a measure of the total adjusted risk scores of all MSBs. This measure may comprise an average, median, weighted average, and / or other statistical value. As a result, money laundering transactions (or groups of money laundering transactions) may be identified using this approach. This approach of identifying particular transactions (or groups of transactions) with higher risk scores (or higher adjusted risk scores) may also be used for other types of customers, not just MSBs.
[0113] Traditionally, a higher risk score means higher risk. However, there is no rule prohibiting a person or business from defining a lower risk score for higher risk. To avoid confusion, the explanation in this disclosure will be based on the convention that a higher risk score means higher risk. Furthermore, risk scores can be negative. A negative risk score, based on this convention, means reduced risk.
[0114] As mentioned above, MSBs are only one example. Other types of businesses, such as pawn shops, car dealerships, etc., may be similarly monitored. As a result, the risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, and total adjusted risk scores may be used in a variety of ways to detect suspicious money laundering transactions, even in the absence of behavioral changes in any of the accounts.
[0115] Indeed, government agencies such as the OCC, FDIC, Federal Reserve, NCUA, FinCEN, etc. may monitor financial institutions such as banks, credit unions, insurance companies, stockbrokers, etc. based on an approach similar to that described above for monitoring MSBs. Different risk factors, risk scores, adjusted risk factors, and adjusted risk scores may be defined for this monitoring purpose.
[0116] In one aspect of the present disclosure, a computer system uses a number of different risk factors to determine whether a financial institution is in compliance with regulatory requirements for filing SARs for money laundering and terrorist financing cases. For example, these risk factors may be the number of SARs filed for money laundering and terrorist financing cases, the financial institution's category, the financial institution's business type, the financial institution's geographic area, the financial institution's headquarters country, the financial institution's business characteristics, the business's product type, the business's service type, the business's structure, the financial institution's customer profile, past records, the type of transactions performed, fund inflows, fund outflows, transaction patterns, the number of transactions, the transaction amount, transaction volume, transaction frequency, transaction derivation, transaction location, transaction time, transaction countries, sender of remittance transactions, sender location, sender countries, sender characteristics, recipient of remittance transactions, recipient location, recipient countries, recipient characteristics, relationships, customer social status, customer political exposure, sender political exposure, recipient political exposure, past transactions, etc. In fact, thousands of risk factors can be considered to determine a financial institution's compliance risk.
[0117] In one aspect of the present disclosure, the number of branches is used to adjust the risk factor and risk score. In another aspect of the present disclosure, asset size is used to adjust the risk factor and risk score. Many other factors may also be used to adjust the risk factor and risk score. In this current example, the "number of SARs filed" risk factor may have a negative value because the more SARs filed by a financial institution, the less chance the financial institution has of not filing a SAR.
[0118] In one aspect of the present disclosure, a set of risk factors is adjusted based on the size of operations and used to identify a group of banks that have this adjusted set of risk factors. A particular bank may not be meeting its compliance obligations to detect and report suspicious money laundering and / or terrorist financing transactions if it has a total adjusted risk score that is significantly higher than the total adjusted risk score of all banks that have the same set of adjusted risk factors. This measure may comprise a mean, median, weighted average, and / or other statistical value. To facilitate comparisons, group statistics such as median, variance, standard deviation, etc. may be derived to facilitate such comparisons between groups of entities.
[0119] Furthermore, different detection algorithms may be used to monitor different banks having different sets of risk factors. In one aspect of the present disclosure, a set of risk factors is used to identify a group of banks having the set of risk factors, and a particular set of detection algorithms is used to detect possible oversights in compliance issues in the group of banks. From another perspective, in one aspect of the present disclosure, a set of detection algorithms is selected to monitor a group of banks based on the set of risk factors associated with the group of banks.
[0120] In another aspect of the present disclosure, a set of risk factors is adjusted based on the size of operations and used to identify a group of banks having this adjusted set of risk factors. A specific set of detection algorithms is then used to detect possible oversight of compliance issues in the group of banks. From another perspective, a set of detection algorithms is selected for monitoring the group of banks based on the set of adjusted risk factors associated with the group of banks.
[0121] While banks are used in the above examples, the same set of methods can be used to monitor credit unions, stockbrokers, insurance companies, other financial institutions, and other types of businesses. Moreover, the scope of monitoring is not limited to compliance with anti-money laundering and anti-terrorist financing issues. Indeed, by properly defining the risk factors, risk scores, adjusted risk factors, adjusted risk scores, and detection algorithms associated with such issues, all types of issues in all types of businesses can be monitored by the methods described in this disclosure.
[0122] MSBs are also under pressure to comply with numerous laws and regulations. However, unlike a bank or credit union, an MSB does not actually know who its clients are. A typical MSB provides money services to any consumer who walks into its offices. Even if an MSB collects personal information from all of its clients, the MSB may not be able to accurately identify money laundering transactions. For example, a customer could use their Mexican passport to conduct one $7,000 remittance transaction by paying cash to the MSB in the morning, and then use their California driver's license to conduct another $8,000 remittance transaction by paying cash to the same MSB in the afternoon. Because two personal information documents are used, the same consumer may appear to be two different people. The MSB may not be able to file currency transaction reports, as required by law, because more than $10,000 in cash is provided by the same consumer. This situation becomes even more complicated if the MSB has multiple branches. This is because the same consumer may visit different branches and perform transactions based on different personal information documents.
[0123] In one aspect of the present disclosure, the computer system compares the names, phone numbers, addresses, dates of birth, etc. of all consumers who have conducted transactions with the MSB to identify all transactions conducted by the same consumer. After all transactions associated with the consumer have been identified, the computer system may detect suspicious money laundering transactions associated with this consumer based on the transactions associated with this consumer.
[0124] In one aspect of the present disclosure, a BSA enforcement officer (i.e., responsible person) investigates the detected case to determine whether it is a true money laundering case. The BSA enforcement officer also investigates all past cases associated with the consumer of the newly detected case. If the BSA enforcement officer agrees that the detected case is a suspected money laundering case, the customer system assists the BSA enforcement officer in filing a SAR with FinCEN. If the BSA enforcement officer decides not to file a SAR, the BSA enforcement officer enters into the computer system the reasons justifying the decision not to report the detected case.
[0125] Often, a bank will receive a wire transfer from a client of corresponding bank A and retransmit the wire transfer to another client of corresponding bank B because corresponding bank A and corresponding bank B do not have a direct banking relationship. This situation often arises during international wire transfers because banks in two different countries do not have a direct banking relationship. This type of wire transfer is often called an intermediated wire transfer.
[0126] Banks that provide intermediary wire transfer services are exposed to a very high money laundering risk because the sender and receiver of the intermediary wire transfer are not the bank's customers. Furthermore, the bank may not know the true background of the sender and receiver of the wire transfer. It is possible that the sender is a terrorist financier and the receiver is a terrorist. Banks that provide intermediary wire transfer services can unknowingly become channels for money laundering and terrorist financing.
[0127] In one configuration of the present disclosure, a computer system compares the names, addresses, countries, telephone numbers, email addresses, etc. of all senders and recipients of intermediated wire transfers to identify transactions associated with each sender and each recipient. In one aspect of the present disclosure, if the computer system detects an unusually high number of wire transfers from the same sender, the sender and recipient may be involved in money laundering or terrorist financing transactions. If the computer system detects an unusually high total amount of wire transfers from the same sender, the sender and recipient may be involved in money laundering transactions.
[0128] Similarly, if a computer system detects an unusually large number of wire transfers to the same recipient, the sender and recipient may be involved in money laundering or terrorist financing transactions. If a computer system detects an unusually large number of wire transfers to the same recipient, the sender and recipient may be involved in money laundering transactions.
[0129] If a computer system detects an unusual number of wire transfers sent from the same sender to the same recipient, this sender and recipient may be involved in money laundering or terrorist financing transactions.If a computer system detects an unusually large number of wire transfers from the same sender to the same recipient, this sender and recipient may be involved in money laundering or terrorist financing transactions.
[0130] In one aspect of the present disclosure, a BSA enforcement officer (i.e., responsible person) investigates such a detected case to determine whether it is a true money laundering case. The BSA enforcement officer also reviews all past cases associated with the suspect in the newly detected case. If the BSA enforcement officer agrees that there is a suspicious money laundering transaction, the computer system assists the BSA enforcement officer in filing a SAR with FinCEN. If the BSA enforcement officer decides not to file a SAR, the BSA enforcement officer enters into the computer system the reasons justifying the decision not to report the detected transaction.
[0131] Because a large portion of the population is rapidly aging, Elder Abuse Reporting Acts (EARA) have recently been established in several states to protect elderly people who are unable to protect themselves. Elderly people can very often be deceived by perpetrators and end up giving money to them. Therefore, financial institutions train their frontline personnel to observe and report what appear to be possible cases of elder abuse. This human-based approach is inefficient because transactions are conducted remotely and perpetrators can effectively mask their actions. Furthermore, human workers are prone to error and mistakes. Relying on human workers to detect and report cases of elder abuse is inefficient.
[0132] In many businesses, customer birthdate information is stored in a database. In one aspect of the present disclosure, a computer system collects the birthdate information and identifies seniors who are older than a predefined age. The computer system monitors all seniors' transactions and detects any changes in the transactions of these seniors.
[0133] For example, if an unusually large amount of funds was transferred from an elderly person's account, the financial institution may wish to investigate the purpose of the fund transfer. In one aspect of the present disclosure, if an unusually large number of checks were deposited into an elderly person's account, the financial institution may wish to investigate whether counterfeit checks were given to the elderly person in exchange for the elderly person's actual money or assets. If there is an unusual transaction pattern (e.g., unusual frequency or volume) in an elderly person's account, the financial institution may wish to investigate the transaction(s). If an elderly person's account balance is decreasing rapidly, the financial institution may wish to investigate the transactions associated with the account.
[0134] In one aspect of the present disclosure, the methods for selecting risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, total adjusted risk scores, statistical approaches, and detection algorithms described above may be applied to detect possible cases of elder abuse. Because elder abuse is different from money laundering, a different set of risk factors and risk scores may be used for elder abuse detection. For example, these risk factors may include the person's age, the person's gender, the person's income level, the person's appearance, judgments about the person, the person's personal circumstances, the person's family circumstances, the person's family members, the circumstances of the person's family members, the person's friends, the circumstances of the person's friends, the person's past record, the person's business category, the person's geographic area, the person's country of address, the person's occupation, nationality, type of transaction performed, account balance, fund inflows, fund outflows, transaction pattern, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivation, transaction location, transaction time, transaction country, sender of a remittance transaction, sender location, sender country, sender characteristics, recipient of a remittance transaction, recipient location, recipient country, recipient characteristics, relationship, social status, political exposure, past transactions, etc. Indeed, many different risk factors may be considered to determine a person's risk of elder abuse.
[0135] For example, in one embodiment of the present disclosure, risk factors are used to identify a group of elderly people who have the same risk factors. If a particular elderly person has a total risk score that is higher than a baseline total risk score of all elderly people who have the same risk factors, then the particular elderly person may be a potential victim of elder abuse. This baseline may comprise a mean, median, weighted average, and / or other statistical value. In another embodiment of the present disclosure, a set of risk factors is used to identify a group of elderly people who have the set of risk factors. If a particular elderly person has a total risk score that is higher than a baseline total risk score of all elderly people who have the same set of risk factors, then the particular elderly person may be a potential victim of elder abuse. This baseline may comprise a mean, median, weighted average, and / or other statistical value.
[0136] To facilitate comparisons, group statistics such as median, variance, standard deviation, etc. may be derived to facilitate such comparisons between groups of entities. As a result, even if there is no change in behavior in an account, the computer system may still detect possible cases of elder abuse based on the above approach.
[0137] A business may often have a compliance officer who is responsible for all regulatory compliance issues. In one aspect of the present disclosure, a responsible person (e.g., a compliance officer) investigates a detected case to determine whether a true case of elder abuse has occurred. The compliance officer also investigates all past cases associated with the elderly person in the newly detected case. If the compliance officer agrees that the case is a possible case of elder abuse, the computer system assists the compliance officer in reporting the detected case. If the compliance officer decides not to report the detected case, the compliance officer enters into the computer system a reason justifying the decision not to report the detected case.
[0138] According to the Sarbanes-Oxley Act (SOX), a company (e.g., a publicly traded company) must implement internal control monitoring to prevent fraudulent activities committed by its employees. Traditionally, such internal control monitoring is performed by human workers (e.g., auditors) who spend several months each year auditing a business's financial records. This human-based approach is inefficient because human workers are prone to making mistakes and errors. Furthermore, auditing financial records takes a considerable amount of time, so it may be too late to prevent crime.
[0139] In one aspect of the present disclosure, a computer system monitors accounting general ledger entries to identify suspected internal fraud and detects any unusual patterns (e.g., unusual frequency, volume, acceleration, etc.) associated with the general ledger entries. For example, if travel expense general ledger entries suddenly increased by 500% this month compared to the previous 12-month history, this could indicate that some employees are abusing their privileges and incurring unusual expenses.
[0140] In one aspect of the present disclosure, a computer system compares the current value of an accounting general ledger item to a baseline of past values of the same accounting general ledger item for the past x months, where the value x is predefined. If the current value is greater than the baseline of past values by a significant margin, some employees may have committed fraud. This baseline may comprise an average, median, weighted average, and / or other statistical value. Further investigation may be performed to determine why the general ledger item value was derived from the past value.
[0141] In another aspect of the present disclosure, the computer system compares an employee's current transactions with past transactions to detect any changes. For example, if a loan officer is issuing an unusually large number of loans compared to past numbers, the loan officer's transactions may be suspicious. If a loan officer is issuing loans in loan amounts that are unusually large compared to past amounts, the loan officer's transactions may be suspicious. If a loan officer is issuing an unusually large total loan amount compared to past total amounts, the loan officer's transactions may be suspicious.
[0142] Transactions may often be measured by a value referred to as transaction value. For example, a loan officer's transactions may be measured by the number of loans, the maximum loan amount, the total loan amount, the average amount per loan, the number of loans to the same customer, the number of changes in the loan record, the number of changes in the loan record with the same customer, the frequency of changes in the loan record, the frequency of changes in the loan record with the same customer, the type of loan, etc. A bank teller's transactions may be measured by the total number of transactions, the total transaction amount, the maximum transaction amount, the average amount per transaction, the type of transaction, the number of customers transacting business with the teller, the average number of transactions per customer, the number of transactions with the same customer, the number of changes in the customer record, the number of changes in the customer record with the same customer, the frequency of changes in the customer record, the frequency of changes in the customer record with the same customer, etc. In one aspect of the present disclosure, a computer system compares the current value of a transaction to a measure of past values for the same transaction. If the current value is greater than a measure of past values by a significant margin, the person who performed this transaction may be committing fraud. Further investigation can be performed to determine whether the person is indeed committing fraud. This measure can comprise an average, median, weighted average, and / or other statistical value.
[0143] In one aspect of the present disclosure, the computer system compares an employee's transactions with those of other employees in the same role at the business. For example, if a teller (or loan officer, etc.) behaves very differently from other tellers (or loan officers, etc.) at the same branch, this teller (or loan officer, etc.) may be engaging in some suspicious transactions.
[0144] In one aspect of the present disclosure, a computer system compares the value of a particular employee's transaction to a benchmark of all transaction values of the same transaction for all employees with the same responsibilities. If the value of the particular employee's transaction significantly deviates from the benchmark of all transaction values of all employees with the same responsibilities, the particular employee may have committed fraud. Further investigation may be performed to determine whether the employee has indeed committed fraud. This benchmark may comprise an average, median, weighted average, and / or other statistical value.
[0145] When comparing a single employee to a group of employees, the statistical approach used in the flight attendant example described above can be applied. For example, a comprehensive set of risk factors associated with the employee is identified, and a risk score is assigned to each risk factor. As a result, each employee has a total risk score that is derived from a mathematical transformation (e.g., summation) of all risk scores associated with the employee.
[0146] The set of risk factors for detecting employee-related fraudulent activities may differ from the set of risk factors for detecting other types of suspicious transactions, such as money laundering. For example, risk factors for detecting employee fraudulent activities may include the type of job performed by the employee, the employee's education level, the employee's income level, the length of employment in the current job, performance survey records, work history, the duration of each job in the work history, the reason for the termination of each job in the work history, the employee's age, the employee's gender, the employee's personal situation, the employee's family situation, the employee's family members, the status of the employee's family members, the status of the employee's friends, the employee's past records, the type of work performed, the number of transactions performed, the amount of transactions performed, the maximum amount of transactions, the number of transactions with a particular counter party, the amount of transactions with a particular counter party, the number of changes to vital records, and These risk factors may include the number of changes to vital records associated with the counter party, the geographic area of the employee's residence, the geographic area of the employee's office, the employee's country of address, nationality, the type of transaction performed, the account balance, fund inflows, fund outflows, transaction patterns, the number of transactions, the amount of transactions, transaction volume, transaction frequency, transaction derivation, transaction location, transaction time, transaction country, sender of the remittance transaction, sender location, sender country, sender characteristics, recipient of the remittance transaction, recipient location, recipient country, recipient characteristics, relationships, social status, political exposure, past transactions, etc. Indeed, numerous risk factors may be considered to determine an employee's fraud risk. In one aspect of the present disclosure, different sets of risk factors may be used to detect different types of suspicious transactions.
[0147] In one aspect of the present disclosure, if a particular employee's total risk score is higher than the average total risk score of all employees with the same risk factors as the particular employee by a significant margin, the particular employee may have engaged in suspicious trading. This significant margin may be set in terms of a number of standard deviations.
[0148] To improve the accuracy of the detection results, multiple risk factors are used instead of a single risk factor. In one aspect of the present disclosure, if a particular employee's total risk score is higher by a significant margin than the average total risk score of all employees who have the same set of risk factors as the particular employee, the particular employee may have engaged in some suspicious transactions. In one example, the significant margin is set in terms of a number of standard deviations.
[0149] Indeed, a statistical approach based on a total risk score for each entity to identify suspicious transactions of a particular entity can be applied to many other situations in addition to money laundering, terrorist financing, and employee fraud by identifying risk factors associated with groups of entities and appropriately assigning a risk score to each risk factor.
[0150] In one aspect of the present disclosure, a number of risk factors are associated with a group of entities. Each of the risk factors may be assigned a risk score. Each entity may be given a total risk score based on a mathematical transformation, such as a summation. For example, but not limited to, other possible mathematical transformations include multiplication, division, subtraction, sum of squares, square of sums, combinations of the above, and other similar techniques for combining risk scores.
[0151] In one aspect of the present disclosure, if a particular entity's total risk score is higher than the average total risk score of all entities with the same risk factors as the particular entity by a predefined margin, the particular entity may have engaged in some suspicious transactions. This predefined margin may be set in terms of a number of standard deviations.
[0152] In another aspect of the present disclosure, if the total risk score of a particular entity is higher by a predefined margin than the average total risk score of all entities that have the same set of risk factors as the particular entity, then this particular entity may have engaged in some suspicious transactions.
[0153] In one aspect of the present disclosure, a computer system identifies a transaction (or group of transactions) for a particular entity that has a total risk score higher than the average total risk score of all entities, and such a transaction (or group of transactions) may be suspicious.
[0154] The statistical approach mentioned is just one way of managing risk. Many other group comparison methods can also be used. Furthermore, suspicious transactions may not be limited to illegal or prohibited transactions. A transaction becomes suspicious because it differs from normal transactions. It may be harmless or even possibly well-intentioned. Therefore, an investigation is often required to make a final decision on whether to report a detected case.
[0155] In one aspect of the present disclosure, a responsible person investigates a newly detected case to determine whether it is a true crime. The responsible person also investigates all past cases associated with the suspect(s) in the newly detected case. If the responsible person agrees that the detected case is a possible crime, the computer system assists the responsible person in reporting the detected case. If the responsible person decides not to report the detected case, the responsible person inputs into the computer system a reason justifying the decision not to report the detected case.
[0156] After the 9 / 11 tragedies, the U.S. Congress passed the Unlawful Internet Gambling Act (UIGEA) because online gambling could be a means for conducting money laundering and terrorist financing transactions. Regulation GG was established in response to the Unlawful Internet Gambling Act. Regulation GG requires financial institutions to ask questions during the account opening process regarding whether new customers intend to conduct any online gambling transactions. However, because perpetrators know that online gambling is illegal, they will lie during the account opening process. As a result, the "question-and-answer" approach defined in Regulation GG has become merely formal. However, Regulation GG specifically states that it does not change financial institutions' obligations to file SARs under the Bank Secrecy Act.
[0157] In other words, if a perpetrator lies during the account opening process and actually conducts an online gambling business, the financial institution has an obligation to report this case to FinCEN through a SAR. In fact, many financial institutions already fail to detect or report these perpetrators who provide false information during the account opening process. In one aspect of the present disclosure, a computer system compares the sender and receiver of all funds transfer transactions during a period of time. If a customer sends a large amount of money to a receiver and receives a large amount of money from the same receiver during a period of time, such transactions may be payments related to money obtained from gambling transactions between an online gambler and an online gambling organization and deposits of gambling funds. The computer system detects these cases as possible instances of illegal online gambling. Once a case is detected, further investigation is required.
[0158] In one aspect of the present disclosure, if a computer system detects many transactions involving large amounts of dollars associated with a customer, it detects the customer as a possible online gambling organization because online gambling organizations generally handle large amounts of money and many clients. The computer system detects such cases as possible cases of illegal online gambling. If a case is detected, further investigation is required.
[0159] In one aspect of the present disclosure, a computer system compares a list of known names of online gambling organizations with the senders and recipients of funds transfer transactions associated with a customer. If there is a match, the customer may be involved in an online gambling transaction. The computer system detects this case as a possible case of illegal online gambling. If a case is detected, further investigation is required.
[0160] In addition to the transaction pattern monitoring mentioned above, the group comparison method described above can also be applied to detect possible illegal online gambling transactions. In one embodiment of the present disclosure, all risk factors related to online gambling are identified. For example, these risk factors may include customer due diligence results, length of account history, customer company category, customer business type, number of name matches with gambling organizations in transactions, customer geographic area, customer headquarters country, customer business characteristics, business product type, business service type, business structure, customer occupation, nationality, past record, type of transaction performed, account balance, fund inflow, fund outflow, transaction pattern, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivation, number of chargebacks, transaction location, transaction time, transaction country, sender of money transfer transaction, sender location, sender country, sender characteristics, recipient of money transfer transaction, recipient location, recipient country, recipient characteristics, relationship, social status, political exposure, past transactions, etc. Indeed, many different risk factors may be considered to determine online gambling risk. As explained earlier in this disclosure, adjusted risk factors may also be used, such that an adjusted risk score may be applied based on the size of the operation.
[0161] In one embodiment of the present disclosure, risk factors are used to identify groups of customers with the same risk factors. If a particular customer has a total risk factor that is higher than the baseline total risk score of all customers with the same risk factors, the particular customer may be associated with illegal online gambling. In another embodiment of the present disclosure, a set of risk factors is used to identify groups of customers with this set of risk factors. If a particular customer has a total risk score that is higher than the baseline total risk score of all customers with the same set of risk factors, the particular customer may be associated with illegal online gambling. This baseline may comprise a mean, median, weighted average, and / or other statistical value. To facilitate comparison, group statistics such as median, variance, standard deviation, etc. may be derived to facilitate comparisons between groups of customers.
[0162] In one aspect of the present disclosure, a responsible person (or BSA enforcement officer) investigates the detected case to determine whether it is a true case of online gambling. The BSA enforcement officer also investigates all past cases associated with the suspect in the newly detected case. If the BSA enforcement officer agrees that the detected case is a possible case of illegal online gambling, the computer system assists the BSA enforcement officer in filing a SAR with FinCEN. If the BSA enforcement officer decides not to file a SAR, the BSA enforcement officer enters into the computer system a reason justifying the decision not to report the detected case.
[0163] The U.S. Congress passed the Fair and Accurate Credit Transactions Act (FACT Act) to protect consumers. Among other things, businesses are expected to identify and report instances of identity theft. Financial institutions are also expected to file SARs if instances of identity theft are detected.
[0164] In one aspect of the present disclosure, a computer system monitors consumer reports and other available information to detect fraudulent or active liability alerts contained in consumer reports, credit freeze notices, and / or address mismatch notices. When a suspicious transaction is detected, the computer system makes the detected case available for investigation by responsible parties.
[0165] In one aspect of the present disclosure, the computer system monitors consumer reports and available information to detect patterns of transactions inconsistent with the past or that indicate an applicant's or customer's usual patterns of transactions. For example, a recent significant increase in the volume of inquiries, particularly regarding recently established credit relationships, an unusual number of recently established credit relationships, a material change in credit usage, or accounts closed by a financial institution or lender that have been closed or identified as the cause of account privilege abuse may indicate an abnormal pattern. When suspicious transactions are detected, the computer system makes the detected instances available for investigation by responsible parties.
[0166] In one aspect of the present disclosure, a computer system detects whether documents submitted for personal information appear to be flagged or forged, and if a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0167] In one aspect of the present disclosure, the computer system detects whether a photograph or physical characteristics in the personal information does not match the appearance of the applicant or customer whose personal information represents the personal information. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0168] In one aspect of the present disclosure, the computer system detects whether other information in the personal information does not match information provided by the person opening the new account or the customer representing the personal information. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0169] In one aspect of the present disclosure, the computer system detects whether other information in the personal information does not match readily accessible information on file with the financial institution or applicant, such as a signature card or recent check. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0170] In one aspect of the present disclosure, the computer system detects whether an application appears to be flagged or forged, or appears to have been destroyed and reconstructed, and if a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by a responsible party.
[0171] In one aspect of the present disclosure, the computer system determines whether the provided personal identifying information, when compared to external information sources used by the financial institution or lender, contains a mismatch (e.g., an address does not match an address in Consumer Reports, a Social Security Number (SSN) is not issued, or the person is listed in the Social Security Administration Death Master File). If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0172] In one aspect of the present disclosure, the computer system determines whether the personal identifying information provided by the customer is inconsistent with other personal identifying information provided by the customer. For example, there may be a lack of correlation between SSN ranges and dates of birth. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0173] In one aspect of the present disclosure, the computer system determines whether the provided personally identifiable information is associated with known fraudulent transactions as indicated by internal or third-party sources used by the financial institution or lender. For example, an address on the application may be the same as an address provided in a fraudulent application. Or, a phone number on the application may be the same as a number provided in a fraudulent application. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0174] In one aspect of the present disclosure, the computer system determines whether the provided personally identifiable information is of a type commonly associated with fraudulent transactions as indicated by internal or third-party sources used by the financial institution or lender. For example, the address on the application may be a fictitious mailbox or a prison. Or the phone number may be invalid or associated with a pager or answering machine. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0175] In one aspect of the present disclosure, the computer system determines whether the social security number provided is the same as that issued by another person who has an account or other customer. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0176] In one aspect of the present disclosure, the computer system determines whether the provided address or telephone number is the same as or similar to an abnormally large number of account numbers or telephone numbers issued by other people who have opened accounts or other customers. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0177] In one aspect of the present disclosure, the computer system determines whether an account holder or customer has not provided all requested personal identifying information at the time of application or in response to notification that the application is incomplete. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0178] In one aspect of the present disclosure, the computer system determines whether the provided personally identifiable information does not match personally identifiable information on file with the financial institution or lender. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by a responsible party.
[0179] In one aspect of the present disclosure, the computer system determines whether an account holder or customer is unable to provide authentication information, such as answers to challenges beyond those that would generally be available from a wallet or consumer report. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0180] In one aspect of the present disclosure, the computer system determines whether there is unusual account usage or suspicious activity associated with the account, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0181] In one aspect of the present disclosure, the computer system determines whether the financial institution or lender has received a request for a new, additional, or replacement card or mobile phone, or a request for an addition to the authorized user's account, immediately after notification of a change of address for the account. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0182] In one aspect of the present disclosure, the computer system determines whether a new revolving credit account is being used in a manner commonly associated with known patterns of fraudulent activity. For example, much of the available credit is used for cash advances or items that are easily convertible to cash (e.g., electronics or jewelry), or the customer does not make the first payment, or makes the first payment but does not make subsequent payments. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0183] In one aspect of the present disclosure, the computer system determines whether an account is being used in a manner inconsistent with established transaction patterns for the account, such as nonpayment of a payment when there is no history of delinquency or default, a material increase in the use of available credit, a material change in purchasing or spending patterns, a material change in electronic funds transfer patterns associated with a deposit account, or a material change in calling patterns associated with a mobile phone account. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0184] In one aspect of the present disclosure, the computer system determines whether an account that has been inactive for a significant period of time has been used (taking into account the type of account, expected patterns of use, and other relevant factors). If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0185] In one aspect of the present disclosure, the computer system determines whether mail sent to a customer is repeatedly returned as undeliverable even though transactions continue to be performed in connection with the customer's account. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0186] In one aspect of the present disclosure, the computer system determines whether a financial institution or lender has been notified that a customer has not received a paper statement. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0187] In one aspect of the present disclosure, the computer system determines whether a financial institution or lender has been notified of a transaction or unauthorized charge related to a customer's account. If a suspicious transaction instance is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0188] In one aspect of the present disclosure, the computer system determines whether the financial institution or lender has been notified by a customer, a victim of identity theft, law enforcement, or any other person who has opened a fraudulent account for a person involved in identity theft. If an instance of a suspicious transaction is detected, the computer system makes the detected instance available for investigation by responsible parties.
[0189] As mentioned above, in addition to monitoring transaction patterns, the group comparison method described above can also be applied to detect possible identity theft cases. Identity theft cases can be divided into two main categories. The first category involves cases in which a victim's accounts, financial instruments, or personal information documents are stolen by a fraudster executing a transaction. Under such circumstances, as described above, a computer system can detect transactions that deviate from the victim's expected transactions, which can be established from the victim's past transactions.
[0190] The second category involves cases where a victim's personal information is stolen to open a new account and / or initiate several new transactions. Under these circumstances, the victim is irrelevant from day one. Without the victim's past true transactions, the victim's expected transactions cannot be properly established for fraud prevention purposes. Someone could ask the perpetrator several questions and collect answers during the account opening process with the intention of establishing the perpetrator's expected transactions, but this question-and-answer approach would not work because the perpetrator would know how to answer the questions to establish the expected transactions without triggering any alerts.
[0191] In one aspect of the present disclosure, all risk factors for a new account or new customer are identified to detect identity theft when no true past transactions are available. For example, these risk factors may include customer due diligence results, the customer's previous record with other businesses, the customer's credit report record, the customer's company category, the customer's business type, the customer's geographic area, the customer's country of address, the customer's business characteristics, the business's product type, the business's service type, the business's structure, the customer's occupation, nationality, past records, types of transactions performed, account balance, fund inflows, fund outflows, transaction patterns, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivation, number of chargebacks, transaction location, transaction time, transaction country, sender of a money transfer transaction, sender location, sender country, sender characteristics, recipient of a money transfer transaction, recipient location, recipient country, recipient characteristics, relationships, social status, political exposure, past transactions, etc. In fact, many risk factors can be taken into account to determine the risk of identity theft.
[0192] In one aspect of the present disclosure, risk factors are used to identify a group of people with the same risk factors. If a particular person has a total risk score that is significantly higher than the baseline total risk score of all people with the same risk factors, then this particular person may be involved in an identity theft case. A set of risk factors may be used to identify a group of people with this set of risk factors. If a particular person has a total risk score that is significantly higher than the baseline total risk score of all people with the same set of risk factors, then this particular person may be involved in an identity theft case. This baseline may comprise a mean, median, weighted average, and / or other statistical value. To facilitate comparison, group statistics such as median, variance, standard deviation, etc. may be derived to facilitate such comparisons between groups of people.
[0193] In one aspect of the present disclosure, a responsible person (or compliance officer) investigates the detected case to determine whether it is a true case of identity theft. The compliance officer also investigates all past cases associated with the newly detected case. If the compliance officer agrees that the case is a possible case of identity theft, the computer system assists the compliance officer in filing a SAR with FinCEN. If the compliance officer decides not to file a SAR, the compliance officer enters into the computer system a reason justifying the decision not to report the detected transaction.
[0194] The Office of Foreign Assets Control (OFAC) has a very simple rule that states that it is illegal to have any business transactions with any entity on the list established by the Office of Foreign Assets Control. This list is commonly referred to as the "OFAC List." This rule applies to all U.S. persons and entities, including financial institutions. For example, Walmart was fined by OFAC for violating this rule. U.S. financial institutions under the strictest regulatory monitoring must usually strictly comply with this rule.
[0195] At first, it was a very simple rule. However, the meaning of this rule has become much more complex over the past decade. A common problem arises when a person misspells (including mistypes, mispronounces, etc.) their own name. Even if an entity's name is misspelled but is on the OFAC list, financial institutions are still obligated to identify this entity as an entity on the OFAC list (commonly referred to as an OFAC match).
[0196] A natural question is how much deviation from the original name on the OFAC list is required to be classified as a "misspelling." OFAC and government authorities have not provided any precise guidance to answer this question. A very common practice for examiners or auditors is to use infamous names like "Osama bin Laden" as a sample to test businesses. Typically, businesses are expected to identify all business transactions associated with "Osama bin Laden," "Osama Laden," "Osama Latin," "Latin Osama," "Latin Osama," etc. as possible OFAC matches. Given the broader range of deviations from OFAC names, it is questionable whether financial institutions would be expected to identify the single term "Obama," the name of the current U.S. president, as a possible OFAC match. It is easy to see how such a simple OFAC rule has caused significant confusion in recent years.
[0197] In one aspect of the present disclosure, an "OFAC concordance scale" is used to measure the degree of deviation. A value referred to as a "relative correlation" ("RC value") may be generated by the OFAC concordance scale to measure the similarity between two names. For example, if a name has an RC value of 100%, it is an exact match with an OFAC name on the OFAC list. If a name has an RC value of 97%, it may differ by one or two letters from an OFAC name on the OFAC list. If a name has an RC value of 0%, it is completely different from all OFAC names on the OFAC list.
[0198] In one aspect of the present disclosure, the length of the name also affects the RC value: for example, if a name differs by one character from an OFAC name having 25 characters, the RC value may be 96%, while another name differing by only one character from another OFAC name having 10 characters may have an RC value of 90%.
[0199] For example, some long words, such as international, corporation, limited liability company or organization, are commonly used for business names, and such words also appear on the OFAC name list. As a result, these long words generate higher RC values for businesses that use these long words in their names. In one aspect of the present disclosure, to avoid unnecessary false positives, commonly used long words may be replaced with shorter words to reduce the impact of the RC value. For example, the word "international" may be replaced with "intl."
[0200] Additionally, some countries do not use the descriptors "first name" and "last name." As a result, if a person is asked to provide their first and last name, they may use a different order of names. "Osama Laden" could become "Laden Osama." In one aspect of the present disclosure, the OFAC match scale identifies possible "off-sequence" OFAC matches.
[0201] Furthermore, some words are commonly used in several cultures without contributing to a clear distinction. For example, in Islamic cultures, "bin" means "son of" and "binchi" means "daughter of." A formal name in an Islamic culture has either "bin" or "binchi" in its name. For example, if a Muslim father has the name "John," his daughter "Mary" would have the formal name "Mary binchi John." Also, his son "David" would have the formal name "David bin John." Under such circumstances, the commonly used words "bin" and "binchi" in Islamic names would create "false similarities" between the two Islamic names. In one embodiment of the present disclosure, to provide more scientifically accurate results, the OFAC concordance scale may filter out these types of "unimportant words" before calculating the RC value. Often, names are translated into English based on their pronunciation. Therefore, in one embodiment of the present disclosure, the OFAC concordance scale should measure the degree of phonetic agreement to determine the RC value.
[0202] In one aspect of the present disclosure, a financial institution determines which threshold to use when performing an OFAC check. For example, if the financial institution uses a 75% threshold, a possible OFAC match is detected if the name has an RC value of 75% or higher. Because each financial institution may have a different risk exposure than other financial institutions, it is very likely that X is the best threshold for Financial Institution A, while Y is the best threshold for Financial Institution B. As a general guideline, the X or Y value is selected according to risk-based principles.
[0203] In general, the higher a financial institution uses a threshold, the fewer possible OFAC matches the institution will detect. This saves time during the investigation process because more false positives are avoided. However, if the threshold is too high, the institution may miss possible derivations from OFAC names, such as "Osama bin Laden." If the threshold is too low, the institution may falsely detect many of its clients as possible OFAC matches. Best practice is to find a trade-off between having too many possible OFAC matches to investigate and missing actual OFAC name derivations caused by misspellings.
[0204] In one aspect of the present disclosure, a user may randomly select a number of OFAC names from the OFAC list and find out how the OFAC match scale responds to variations from these selected OFAC names. The user may then determine when to call a "possible OFAC match" based on this test. It is desirable to maintain the results of this test for review by future auditors and examiners.
[0205] Certain names may be very close to OFAC names. For example, American Express, a highly reputable credit card company, is often falsely detected as an OFAC match due to the word "express." Therefore, in one aspect of the present disclosure, to avoid these types of frequent false positives, an exclusion list is generated by the user to include these well-known, reputable businesses on the exclusion list. Businesses on the exclusion list are classified as false positives, either automatically by the computer or manually by the user, when detected as a possible OFAC match.
[0206] Quite frequently, a business may have an OFAC enforcement officer who handles all OFAC-related matters. In one aspect of the present disclosure, if a financial institution's OFAC enforcement officer (i.e., a responsible person) detects a possible OFAC match with an RC value above a predefined threshold, the OFAC enforcement officer investigates whether this is a true OFAC match. If the OFAC enforcement officer believes this is a true match, he or she should handle the case in accordance with guidelines issued by the Office of Foreign Assets Control. According to OFAC regulations, in some cases, the OFAC enforcement officer may need to block the transaction to prevent a person on the OFAC list from benefiting from it. If the OFAC enforcement officer determines after investigation that the OFAC match is a false positive, he or she should enter a reason into the computer system justifying why the OFAC match case should not be reported to the Office of Foreign Assets Control and / or should not block the transaction.
[0207] Section 314(a) of the USA PATRIOT Act requires financial institutions to detect matches of names on the 314(a) list, which is periodically published by FinCEN. As previously mentioned, computer systems may handle 314(a) compliance issues using an approach similar to that used to handle OFAC compliance issues.
[0208] Often, the 314(a) list also includes additional personally identifying information, such as, for example, a personal information document number, date of birth, address, etc. In one aspect of the present disclosure, in addition to the methods described above for detecting possible OFAC matches, the personally identifying information, such as, for example, a personal information document number, address, and / or date of birth, etc., is used by a computer system to determine whether a detected 314(a) is a true match. This approach may reduce false positives in the 314(a) matching process.
[0209] In one aspect of the present disclosure, when a compliance officer (i.e., a responsible person) at a financial institution detects a possible 314(a) match with an RC value above a predefined threshold, the compliance officer investigates whether this is a true 314(a) match. In one aspect of the present disclosure, if the compliance officer believes it is a true match, the compliance officer reports the 314(a) match to FinCEN. If the compliance officer, after investigating, determines that the 314(a) match is a false positive, the compliance officer enters into a computer system a reason justifying why the 314(a) match was not reported to FinCEN.
[0210] In one aspect of the present disclosure, a computer system receives customer information and transaction data from a core data processing system of a financial institution. The computer system receives customer information and transaction data from other data processing systems, which may be internal or external to the financial institution.
[0211] In one aspect of the present disclosure, a computer system receives information regarding suspicious transactions observed by frontline personnel. The computer system may receive information entered by frontline personnel. The computer system may also receive information provided by other internal or external sources.
[0212] While a "financial institution" is used as an example for ease of explanation, this disclosure also applies to other types of businesses. Generally, any business that must comply with laws and regulations may apply a transaction monitoring system such as that described in this disclosure.
[0213] As contemplated in the described embodiment, one of many possible combinations is described below by way of example: A computer network 600, such as a local area network, and a computer system for transaction monitoring 500 enable BAS officers 100, compliance officers 200, security officers 300, and other responsible parties 400 to comply with different types of laws and regulations as illustrated in FIG.
[0214] As illustrated in the flowchart of Figure 2 in combination with the system diagram of Figure 1, a person may use computer system 500 to detect and report suspicious transactions in accordance with applicable laws and regulations, including at least the USA PATRIOT Act, the Bank Secrecy Act (BSA), the Fair and Accurate Credit Transactions Act (FACT Act), the Unauthorized Internet Gambling Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), regulations established by the Office of Foreign Assets Control (OFAC), rules established by the Financial Crimes Enforcement Network (FinCEN), and other laws and regulations.
[0215] First, computer system 500 receives customer information and transaction data from a core data processing system and / or other systems of a business (block 2001). Based on the customer information and transaction data, computer system 500 detects new suspicious transaction instances by using at least one of the suspicious transaction detection methods described in this disclosure (block 2002).
[0216] Additionally, computer system 500 assists a user (i.e., BSA officer 100, compliance officer 200, security officer 300, and / or other responsible party 400) in investigating a newly detected suspicious transaction case via network 600 (block 2003). Computer system 500 also assists a user in investigating other related cases previously detected by computer system 500. This investigation process helps the user make a better determination as to whether a newly detected case is indeed a suspicious transaction case.
[0217] The user makes a decision as to whether to report the newly detected case (decision block 2004). If the user decides to report the newly detected case (YES branch 2005), the computer system 500 assists the user in reporting the detected case (block 2007). If the user decides not to report the newly detected case (NO branch 2006), the computer system 500 allows the user to enter a reason justifying the decision not to report the newly detected case (block 2008). This reason and the newly detected case are stored in a database for future reference. As previously explained, a case that is not reported as a suspicious transaction case today may become part of a true suspicious transaction case in the future as more evidence becomes available.
[0218] The methods described herein may be implemented by various means, depending on the application. For example, the methods may be implemented in hardware, firmware, software, or any combination thereof. In a hardware implementation, the processing may be implemented within one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, or other electronic units designed to perform the functions described herein, or any combination thereof.
[0219] For a firmware and / or software implementation, the methods may be implemented with modules (e.g., procedures, functions, etc.) that perform the functions described herein. Any machine-readable medium tangibly embodying instructions may be used in implementing the methods described herein. For example, software code may be stored in a memory and executed by a processor. The memory may be implemented within the processor or external to the processor. As used herein, the term "memory" may refer to any type of memory, whether long-term, short-term, volatile, non-volatile, or otherwise, and should not be limited to any particular type or number of memories or the type of medium on which the memory is stored.
[0220] When implemented in firmware and / or software, the functions may be stored as one or more instructions or code on a computer-readable medium. Examples include computer-readable media encoded with data structures and computer-readable media encoded with a computer program. Computer-readable media include physical computer storage media. Storage media may be any available medium that can be accessed by a computer. By way of example and not limitation, such computer-readable media may comprise RAM, ROM, EEPROM, CD-ROM, DVD, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer; as used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc; disks typically reproduce data magnetically, while discs reproduce data using a laser. Combinations of the above should also be included within the scope of computer-readable media.
[0221] In addition to being stored on a computer-readable medium, the instructions and / or data may be provided as signals on a transmission medium included in a communications device. For example, a communications device may include a transceiver having signals indicative of instructions and data. These instructions and data are configured to cause one or more processors to perform the functions outlined in the claims. A communications device may not necessarily store all instructions and / or data on a computer-readable medium.
[0222] The embodiments described in this disclosure can be configured to form various applications based on needs. Those skilled in the art and technology to which this disclosure pertains will recognize that changes and modifications in the described configurations can be made without significantly departing from the principles, spirit, and scope of the present disclosure. Such changes and modifications should not be construed as a departure from the present disclosure.
Claims
1. 1. A computer system for assisting a business in complying with anti-money laundering laws and / or regulations, comprising: a memory device; at least one processor connected to the memory device; The at least one processor deriving a total risk score for each of a plurality of entities based on a plurality of risk factors, wherein each of the plurality of risk factors has been assigned a risk score; Detecting an entity if the detected entity's total risk score differs from a criterion derived from the total risk scores of the plurality of entities by a predetermined margin; A computer system configured to assist a user in identifying at least one transaction that caused the detected entity to have a total risk score that differs from a standard derived from the total risk scores of the multiple entities.
2. The at least one processor further comprises: If the user decides to report the identified at least one transaction, assisting the user in reporting the identified at least one transaction as a suspected money laundering transaction; The method of claim 1 , further configured to store a reason to justify the user's decision not to report the identified at least one transaction if the user decides not to report the identified at least one transaction.
3. 2. The computer system of claim 1, wherein the risk factors include at least a customer's company category, a customer's business type, a customer's geographic area, a customer's country of address, a customer's business characteristics, a business product type, a business service type, a business structure, a customer's occupation, a nationality, a past record, a type of transaction performed, an account balance, a fund inflow, a fund outflow, a transaction pattern, a number of transactions, a transaction amount, a transaction volume, a transaction frequency, a transaction derivation, a location of the transaction, a time of the transaction, a country of the transaction, a sender of a remittance transaction, a location of the sender, a country of the sender, a sender characteristic, a recipient of a remittance transaction, a location of the recipient, a country of the recipient, a recipient characteristic, a relationship, a social status, a political exposure, and / or a past transaction.
4. 10. The computer system of claim 1, wherein the at least one processor is further configured to, if the entity is a business, adjust at least one of the risk factors based in part on a size of an operation.
5. 10. The computer system of claim 1, wherein the at least one processor is further configured to obtain the total risk score by a mathematical transformation of all risk scores of all risk factors.
6. The computer system of claim 5 , wherein the mathematical transformation is a sum of all risk scores of all risk factors.
7. The computer system of claim 1 , wherein the predetermined margin is determined in part based on a statistical approach and / or human judgment.
8. The computer system of claim 7 , wherein the statistical approach is based in part on a standard deviation of all of the total risk scores of the plurality of entities.
9. 10. The computer system of claim 1, wherein the suspected money laundering transactions are reported to a government agency.
10. 10. The computer system of claim 9, wherein the government agency is a Financial Crimes Redress Network.
11. The method of claim 1 , wherein the metric derived from the total risk scores of the plurality of entities comprises a mean, average, median, weighted average, and / or statistical value of the total risk scores of the plurality of entities.
12. 1. A computerized method for assisting a business in complying with anti-money laundering laws and / or regulations, comprising: identifying a plurality of entities having at least one common risk factor; deriving a total risk score for each of the plurality of entities based on a plurality of risk factors, wherein each of the plurality of risk factors is assigned a risk score; Detecting, by a computer system, an entity if a total risk score of the detected entity differs by a predetermined margin from a criterion derived from the total risk scores of the plurality of entities; and providing past transactions and / or related cases of the entity to enable investigation of the identified transaction as a suspected money laundering transaction.