Home > Financial Services Information Security Tips > Compliance and Governance Digest > How AML compliance applies to remote deposit capture
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND GOVERNANCE DIGEST

How AML compliance applies to remote deposit capture


Dan M. Fisher, Contributor
06.04.2009
Rating: -2.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Remote deposit capture emerged as an unintended consequence of the Check Clearing for the 21st Century Act and is growing in popularity. Fundamental to the efficient and effective deployment of banking technology is the understanding of the regulatory implications and the development and integration of a compliance program as part of the design and implementation process.

Consequently, financial institutions need to consider how the Bank Secrecy Act and anti-money laundering regulations (BSA/AML) apply to remote deposit capture (RDC).

BSA/AML regulations, in large measure, have to do with required financial transaction record keeping by federally insured financial institutions and other designated entities. The requirements are in the areas of monitoring, risk assessments and reporting. The purpose of the act and subsequent regulations relate to the information and how the information is considered beneficial in investigations of criminal wrongdoing, tax code or regulatory violations.

There's no question that the Bank Secrecy Act applies to remote deposit capture, said Paul Carrubba, a payments system law expert with Adams and Reese LLP, a regional law firm with offices throughout the South. In fact, he said financial institutions can expect increased regulatory scrutiny with the use of RDC technology and cross-border transactions. Carrubba cautions institutions using RDC for customers located in foreign countries depositing checks drawn on domestic institutions, particularly instruments such as official checks, money orders and traveler's checks that are known vehicles for money laundering.

"When offering RDC," Carrubba said, "knowing your customer, in regard to these types of transactions, is critical to understanding and managing risk and to reduce potential adverse exposure to fraud and illegal activities."

In January, the Federal Financial Institutions Examination Council issued guidance regarding RDC, but it should be pointed out that in August of 2007 the FFIEC updated the BSA/AML examination handbook. Included in the electronic banking section is a discussion of examination control objectives regarding RDC that was issued almost 15 months prior to the issuance of specific guidance on RDC, which expanded the definition and scope of RDC technology. Ultimately, just including RDC in the exam objectives is enough to support the assertion that BSA/AML does, in fact, apply.

So, what are the issues and what steps should institutions take?

Complying with BSA/AML translates into taking overt and active measures that specifically address the control objectives outlined in the updated FFIEC BSA/AML handbook. Institutions need to establish:

  1. Controls that can effectively monitor RDC activity, including:
    1. Type of instruments deposited.
    2. Dollar limits.
    3. Transaction volume and frequency.
  1. Specific "Know Your Customer" criteria that comply with the Customer Identification program requirements (CIP) such as:
    1. The type of business.
    2. Location of business.
    3. Seasonal trends that may impact the business.
    4. Deviations or swings in account activity based on business environment.
  1. A continuous reporting process that will indentify and inform the organization immediately of suspicious activity.
  1. A mechanism for the timely reporting of suspicious activity in compliance with BSA/AML.

Key to an effective KYC program is an aspect noted by Carrubba: "An institution should also put controls in place so the customer cannot go unnoticed as a money service business without registering."

Finally, BSA/AML is not the only regulatory implication financial institutions need to address. The FFIEC Guidance on RDC picked up where the BSA/AML exam handbook left off. Simply stated, The FFIEC defines RDC as:

  1. A deposit transaction delivery system.
  2. The digitizing of public and non-public information.
  3. The movement of money.

The conclusion is not only does BSA/AML apply, but both the Gramm-Leach-Bliley Act (GLBA) and the U.S. Patriot Act apply as well.

Ultimately, RDC is a tremendously beneficial technology; however, it is not without risks. The guidance is clear about what needs to be done in regard to establishing a comprehensive and effective compliance program.


About the author:
Dan Fisher is president and CEO of The Copper River Group, a consulting firm based in Fargo, N.D. that focuses on technology, payment systems research and consulting for community financial institutions. For nearly 30 years, Fisher has worked in the financial industry using technology to improve the bottom line. He has served as a director of the Federal Reserve Board of Minneapolis, chairman of the American Bankers Association Payment Systems Committee, and member of the Independent Community Bankers of America Payments Committee. He has written numerous articles on banking technology and the payments system, has authored or co-authored six books and recently published "Capturing Your Customer! The New Technology of Remote Deposit" You can contact him at dan@copperwombat.com


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance and Governance Digest
Shifting to a flexible information security framework
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
Data breach protection: Implementing vendor breach safeguards
How to manage security risks in vendor contracts
Red Flags Rule and preparing for new regulations
Companies lagging in PA DSS compliance
Social media: Risk management strategies for financial institutions
FFIEC guidance on RDC: Guidance overview
FFIEC guidance on RDC: Risk management basics

FFIEC compliance guidelines
Five mistakes banks make in pandemic planning
Data breach lawsuit puts spotlight on bank's security measures
Get ready for remote deposit capture risk management scrutiny
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
Defendants in banking fraud scheme accused of exploiting regulation
FFIEC guidance on RDC: Guidance overview
FFIEC guidance on RDC: Risk management basics
FFIEC guidance on RDC: Top five RDC mistakes
Download presentations from Financial Information Security Decisions 2009

Bank Secrecy Act compliance and anti-money laundering training
FDIC warns of rise in "money mule" schemes
Financial institutions reported more suspected fraud in 2008
Cooperating with law enforcement for U.S. security
Expert: Lengthy logs not always a good thing
USA Patriot Act suggestions for wireless Internet user identification

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
FFIEC compliance  (SearchFinancialSecurity.com)
Podcast: What is FFIEC compliance?  (SearchFinancialSecurity.com)
remote deposit capture (RDC)  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts