Go back

Solvable: We Can Beat Financial Crime Pt.2: Carole House, Ari Redbord & Matt Van Buskirk

58m 42s

Solvable: We Can Beat Financial Crime Pt.2: Carole House, Ari Redbord & Matt Van Buskirk

The discussion highlights the urgent challenge of financial crime in an era of rapid technological advancement and geopolitical shifts. Current regulatory frameworks are too slow, risking economic competitiveness and security, especially with China's rise. Crimes like fraud, money laundering, and cyberattacks are accelerating due to AI and digital assets, enabling bad actors to operate at scale. To address this, the approach must shift from viewing financial crime as a compliance issue to treating it as a global security threat. Key solutions include fostering real-time public-private partnerships, improving data sharing with privacy protections, and establishing common international standards. Additionally, investing in digital identity infrastructure and updating legal systems are essential to keep pace with technological changes and effectively combat these evolving threats.

Transcription

9946 Words, 55838 Characters

English
Our entire regulatory system has been designed to be methodical and deliberative, and that means slow. And Terry's point, the criminal world moves incredibly fast. But the Carol's point also, we're now in a, we haven't really faced geopolitical competition in my lifetime, really. We now do have credible competition from China that we need to be reactive to. And I feel like like the default thinking regulation is sort of like America is always going to be the dominant financial player in the world. Therefore, we can take our time and do what we want and the rest of the world will follow. That's not true anymore. We may make decisions that will cause a large portion of the world to move out of our sphere of influence into China's. So our regulators need to actually be accounting for whether our economy and our country as a whole is going to be competitive and innovative. A geopolitical sense and then whether or not we're sitting ducks from the criminal sense as well. Barefoot Innovation starts right now. Long-time listeners know that every now and then we have a show that goes into my own personal pantheon of favorites. This one is among the very top. It is part two of the terrific show we did last fall on financial crime with Erie Redboard of TRM Labs, Carol House of the number of strategies and Matt Van Busker of Hummingbird. These are people who know how to find financial crime and have built tools that do it. Today's conversation is so great that it inspired me to kick off a new series for a barefoot innovation that I'm calling "solvable". These will be episodes where we're going to talk about big problems that actually could already be solved by today's technology. If only we humans will realize it, grasp the opening and change how we do things to actually put new solutions in place. Some of these challenges will be harder than others. Financial crime will be very tough for sure. It's a huge financial, human, legal and geopolitical problem. For a snapshot of how bad it is, listen to part one of this two-part show and also listen to the opening of this episode where my guests share eye-opening stats and examples of the breathtaking scope of these crimes today. Fraud, scams, money laundering and cyber risk, which are all expanding at light speed now that their perpetrators are armed with AI that has become easy, affordable and massively powerful. Yes, the solutions are very difficult, but they are also fundamentally simple. These are financial crimes. That means they can be found in financial data using the techniques that have become available in recent years. We have the financial data. All we have to do is pool it and analyze it to detect the patterns, the connections and typologies that signal possible crime. To pool it, of course, we have to be sure we can protect it in terms of both privacy and security. And that in turn means that we don't literally want to pool it. We don't want to put it all in one place that becomes a honey pot attracting bad actors. Instead, we want to make it widely available and useful to the legitimate players who need it, such as law enforcement, national security, and the banks and other financial companies. And thanks to new technology, there are ways to do this. Technologically, it's solvable to share it and protect it. So let's solve it. The discussion in this episode doesn't get us all the way there. Of course, we can't map all the solutions in 45 minutes, but my guests do identify most of the key elements needed. So in our solvable episodes, I want to do exactly that. Clarify. Just come in on what needs to happen to solve a problem, identify the obstacles that are preventing them from happening, and then pinpoint what has to change to solve for those obstacles and who needs to do it. My mind is obsessing on solutions this year because so many things are changing so fast and are being driven so often by new technology. Some problems are rapidly getting worse. Some new ones are arising. They're all moving faster than our current problem solving toolbox is designed to address. If we try to solve these problems with our old methods, we are going to fail. Bad things will happen and good things won't happen. Things that are becoming possible and could be incredibly beneficial, but may accidentally be strangled by outdated legal and regulatory measures. What are we going to do about that? To answer that question, we need to develop the reflex of asking whether technology itself can be part of the solution because usually it can. To counter AI risks, for example, we're going to need to use AI. Beyond that, we are going to have to change the human systems operating around new technologies to be able to deploy it safely and effectively, and of course, to do the many things that technology can't. We will need to change people issues like talents and training and cultures. We will need to change legal frameworks and we will need better ways to collaborate across the silos that are so strong in the financial and regulatory sectors. I think we can find our way to doing the people work if we believe that hard problems can actually be solvable. So let's hear from our guests on how to solve financial crime. Hey everybody. I am so glad that we are assembled to record part two of our podcast on Fighting Financial Crime. I have the same incredible guests that we had in part one. We have ARI Redboard, Global Head of Policy at DRM Labs. We have Carol House, CEO of Penumbra Strategies, and also she is a Distinguished Senior Fellow at ACAMS. And we have Matt Van Bussker, co-CEO for regulatory and hummingbird. We will link in the show notes to part one. Everyone should go back and listen to it. I don't think we've ever done a show before where in the middle of the show, I said we have to come back and keep going. And then it took us longer than we thought we would need to reassemble. But in part one, we talked about the importance and the difficulty, but still the durability of making a dent in the growth of financial crime. And what I want to do in part two is really dig deeper into the collective wisdom of this group to think about what really needs to be done. What can we do? Let's switch to action mode and problem solving mode in a field where a lot of people spend their time talking just about how many problems they are and how huge they are. So before we turn to the solution topic though, I do hope everyone listening will listen to part one if you haven't. But before we jump into the next part, let's just recap a couple of thoughts on the scope scale and frankly terrifying nature of what's going on in financial crime. So just give me your top of the head thinking on some of you want to be sure the audience is keeping in mind as they as they listen to the rest of the show. All right, do you want to start? Yeah, no, happy to. And thanks again for reconvening or bringing the band back together, Joanne, I think it's an awesome group and and also really close friends. So it's love these conversations. I guess a couple things are top of mind for me right now when it comes to sort of the problem set. The first is AI and AI is transformative technology. But the reality is that AI is supercharging, money laundering, elicit finance and financial crime. We basically have seen bad actors, leverage AI the same way we all do lawful users to move faster. So we're seeing scam activity done at scale, right? You don't need scammers on the other end of a line anymore. You can have agent agents who are sending these sort of spam scam text messages, email social media engagement at the click of a button hundreds thousands millions. We've seen ransomware groups use AI agents to deploy malware. We've seen scammers use deep fake technology and other types of technology to sort of really scale. There was a world in which scams and fraud were a series of phishing attacks and broken English. Today it's perfectly tailored to individual users. So I'd say that's the first sort of thing that we're tracking really closely and looking forward to getting into solutions there. And the other is really obviously I'm very focused on the digital assets ecosystem. We saw about 158 billion in illicit activity last year within the crypto ecosystem. That is a record-setting year. Still a relatively small percent of overall illicit activity. But what we're starting to see is bad actors, particularly nation-state actors, really leverage infrastructure. Rather than these are not just one-off payments anymore that we're tracking and tracing, this is nation-state actors, IRGC, in Iran, for example, using cryptocurrency exchanges to move billions of dollars. It's Venezuela, it's cyberattacks at the speed of the internet by North Korea stealing billions of dollars. So I'd say those are sort of the two big things right now is bad actors using crypto infrastructure, really at scale for the first time. And obviously AI just over everything. Carol, what do you want to point to? Well, of course, areas in-site it is always the speed and scale of the evolution of the tech, the adaptation of these technologies for illicit purposes by these transnational organized crime groups remain like front and foremost, like here, like they're front of mind and really a core issue that we have to figure out how to increase the pace. So I think that it, that underscore that that's an underlying issue that really helps to highlight some of the bigger problem sets that we have. We still have a major problem of the speed and scale of enforcement, which I know isn't necessarily the most popular view across across the industry, but the idea that enforcement approaches often take actions on a fast timeline, like citing activity from four years ago, but in many cases are in fact citing activity from a decade ago. That is not a pace that is an effective deterrent. It's not an effective disruptor. This is not, this is not working. And it's definitely not working when seeing the like 1300% increase in deep fake fueled fraud that I think pin drop just dropped that assessment, but there have been many other, many other assessments about the like 100,000 percent fold increase in fraud and other AI fueled illicit activities and cybercrime as well as financial crime that's occurring. But it underscores this bigger problem that we've had given before we had the the generative AI uptick and all of this, which is that we are not keeping pace with with enforcement and application across the industry. And even if you have policy that that applies, if you're not enforcing it and not implementing it, then it ultimately ends up being feckless in the first place. I think some other underlying issues we've still not we've not really addressed the core building blocks. And I guess that'll lead into some of the solutions that we need to get to, but this absence of strategic thinking at looking at what are the core underlying causes of a lot of these things, like the complete absence of effective digital identity and infrastructure continues to be one of my many high horses. It's my highest horse in fact that I like jumping on, but this problem has reared its head certainly in cybercrime definitely in in fraud. Obviously identity is the major vector of compromise that's occurring there. But now ultimately with agentech AI, like without effective digital identity, you are just continuing to systematically build in pro cyclicality and programmability and scale and like delegating authorities into a world where we do not have sufficient trust across the digital ecosystem. So these these issues about the speed scale and sophistication of the of the technologies being exploited very quickly by bad actors who were looking for those seams and were not we're not even keeping pace like tactically after the fact right of boom on the enforcement side and we're certainly not looking at the root causes and investing in those. So I think those are my biggest concerns. I'm also all say that I do think that prioritization and dismantling of a lot of of a lot of critical rules and enforcement apparatus are some other concerns that I'm worried about right now. A big focus on cost and not enough work thinking about the efficacy and the benefits of an AML framework. Matt what do you want to add? I think some of the data points I would be citing here or maybe repeating for our first episode. A couple of things I remember coming out from a conference in London that I mentioned before was that the explosion in AI is making a cost effective for standards to go after people who maybe their whole net worth is only $50 now or previously they were trying to target sort of wealthy retirees to get more bang for their buck. I also heard recently countries like Finland previously had no real problems with fraud because the language was not commonly spoken and fraudsters were mostly going after English-speaking countries but suddenly you have an entire country that is having to deal with the problem of scams coming in and perfectly written finish without any cultural antibodies and like not responding to these types of messages and kind of expand that across the entire planet you're starting to think of your sea. If scams exceeded narcotics some estimates have shown last year as the largest category of criminal activity I feel like it's only dropped in the bucket compared to what it could be as these things keep getting accelerated through adoption of all the technologies so like you're not this is an arms race we can't continue to defend ourselves the way we have been when the bad guys out there are adopting the bleeding edge constantly. Yeah Matt you might have said the Syntha prior show but I think you've got a statistic that the North Korean missile program is mostly funded by scams against the West. Is that accurate? And also something you said to me that really struck me was that if financial crime was a country it would be a member of the G7 and you know we're acting like somehow if we just kind of keep doing what we do but you know do it a little better or a little more or something we're going to solve these problems and we as you said Carol we are not on a track to solve them to the country it's all getting worse and we're trying to combat these problems with tools that don't scale and don't move quickly and so on. So what we want to do in today's show is let's pretend for a moment that you all have been made the zars of solving financial crime by whatever powers that be in the US internationally somebody has said to you come up with the blueprint for actually turning the tide on this and we know we're not going to eliminate it all we'll talk later about what good looks like what success looks like but right now the people driving this including these geopolitical players who are really making a nexus between this crime and national security issues all over the world we're going to we really want to think about you know what is the ecosystem of change that needs to happen and go from there so what are the most important things that needs to be done and then we're going to talk about what's preventing them being done and what to do about that jump in. I guess I can start here I got an invite to a council of Europe event and Brussels about three weeks ago and the initiative that they're exploring there was really interesting it basically they're trying to create a common minimum data standard for suspicious activity reporting across Europe and in the initial briefing they pointed out an example which saying if you're a financial institution filing in Europe and you're filing in multiple countries because you operate in multiple countries you know that a particular fraud rain or something that you're reporting on huts across all these jurisdictions but if you file in France and you file in Germany France and Germany can't tell that it's the same actors even on the same report activity being reported because they have different data standards and the FIUs are sort of saying we need to be able to trace this activity without having to do a whole bunch of data reformatting in Excel literally every time so basically the structure of how we've imposed regulations globally is actually imposing well structural challenges to going around the bad guy or catching the bad guy say able to run the rains around this so a couple things stood out to me about it it was led by the FIUs they were coming to the council of Europe and the European Union and saying like hey we need to figure out something to do here they're coming up with a technical approach themselves this was sort of a learning event across the industry where they were presenting their initial thoughts get feedback across the industry from a wide variety of different types of financial institutions from traditional banks to crypto to gaming companies all the kind of thing and it was two days workshops basically and there was a ton of feedback and one of the challenges I saw was towards the end of it one of the financial institutions were raising their hands and really trying to emphasize how expensive everything was going to be whenever they were changing these efforts and one of the FIU representatives got up and said well we kind of have to do this if we actually want to do something about financial crime and it really cut back to the core theme, I think we've experienced here, which is the fight against financial crime for 40, 50 years now has really been treated as a compliance exercise. And it's not it's a conflict. We need to stop treating it like compliance. So we need to be ensuring our regulatory bodies are holding people to a standard that is not how good they are an executing paperwork, but how effective they are getting information to enforce them. And I hope to see we can't fight global crime locally and that's what we've been doing and more we have this fragmentation around the world of all sorts of different reporting standards and such. There's just it'll be structurally impossible for us to make a real difference. So the EU initiative is really exciting and I hope to see more of those happening that are more global in nature as well. Yeah, happy to jump in here. I mean, I love Matt's take and I remember from the last segment also I thought he beautifully articulated this idea that this is not a compliance issue. This is a national and global security issue. And we should start treating it that way. I'm kind of building on that a bit. If I sort of had that magic one, Joanne, I'd really start with public private partnership. And as I just said that everyone's eyes glazed over in your audience because that is the cop out answer whenever you have a recommendation for anything. And but what I what I want to talk about is is not I think how we've always conceived public private partnerships, but we really need to reimagine them. It's not a bunch of people sitting around the table iterating on standards and best practices. It's real time information sharing, interdiction seizure, prosecution and offensive cyber type activity. We live in this really interesting moment in human history where the private sector holds all of the data and the public sector has all of the authorities. And we really need to give the private sector some of those authorities and we need to make sure that the public sector has access to all of that information. I talked I think in our last session about the beacon network, which is a real time information sharing and interdiction network for crypto. I think we need to kind of expand that. I think you know there's all kinds of conversations on letters of mark that is happening on Capitol Hill. I'm a very big proponent of that that type of activity where the private sector has authorities to actually proactively go after and seize funds. Carol is smiling and I'm never sure whether that means she agrees with me or is excited to disagree with me. So I'm going to let her jump in here. But like when I think about public private partnership, public private information sharing to me, it's about disruption. It's not about a bunch of people sort of sharing ideas around the table, which I think is kind of, you know, sadly, how how really public private partnerships have looked in the past. Yeah, thank you. Yeah, so I love it like the I was actually going to bring up the letters of Mark debate because it's such a such a big area focus. And it's always something that comes up. Is there a debate? I just think it's an amazing idea. Like pretty non-controversially. But I'm sure there are people who disagree with that. I'm very leading into the audience has been to explain what it is. Absolutely. Carol, you want to go for it? Sure. So there's my cheeky answer, which like is cyberspace piracy. But okay. So back into like actually what it was back when pirates were very like was a very real problem. And basically that like like the US Navy just didn't have the like the ability, the resources to be able to go and like counter the amount of piracy that was hurting Americans and commerce. We issued letters of Mark to private tears. So basically state sponsored pirates like lowercase p pirates to go after the capital p pirates to go after the bad guys that were hurting American commerce. Generally that ended and went out of vogue because it got exploited in the end. But like I mean that there were certainly successful examples of it. But but when when when an authority like that is not properly overseen, which was especially difficult. At that time, I would say like there's a reason why that went out of style and then literally went out of style in the sense that private hearing is now a part of the treaty of Paris like a core which I know the US is not directly seated to but generally has like adopted those norms as a practice to not. Support, private hearing. So there's really interesting questions around like international norms, which certainly I will say that even now in the geopolitical context has been. There's certainly a lot more interest in this in discounting certain existing norms, especially if we feel that it's in US interests. So I understand why why it's a top of mind and frankly it's been I saw it as a point of discussion under on the hill both under Trump 1.0 and in the Biden administration and other. Likewise, like it's one of those things that comes up as a point of discussion and it's becoming very meaningfully mentioned here because especially when law enforcement timelines are like what I mentioned and the fact that as things get more and more digitized, there's lots of very valuable information and now where data is also the asset of value like with digital assets. And you get into where it had traditionally been in my experience sort of siloed into cyber security discussions and debates around hack back debates it's now being discussed in crypto recovery to try to get back assets like either sometimes discussed in like ransomware. But for the most part it's more like in crypto high thefts and frauds so I have my own feelings about whether or not you need a letter of mark. I think ultimately what I do completely agree on is that there needs to be a scaled like a scaled actual strategy and approach. Building the technical policy rails and political will to scale asset recovery capabilities, including in partnership with industry. I don't actually think the unique letters of mark to do that I think that the US government has plenty of existing authorities including contracting capabilities and others to be able to do it without letters of mark. But either way like I'm function over form like whatever it is it needs to be a public power partnership to enable that asset recovery and then you know specific policymakers can discuss and debate like the pros and cons of very specific forms to be able to do that so either way I'm very much on board with the need to scale. asset recovery capabilities in partnership with industry whether it's through letters of mark or through something else but it is it's really it was really neat to see it bridge from like hard cyber. Conversations into the cryptocurrency world so it's a neat point of debate. I think that's a theme that we should be emphasizing here that a lot of the cyber world is much further ahead than financial crime world in the realities of a lot of these threats that we've been facing and they actually have implemented solutions and new types of public private partnerships that I mean they obviously could be improved upon but compared to what we have in financial crime are much better. So we're not reinventing the wheel here there are methodologies we could embrace. Yeah I totally agree this was something that even since 2018 certainly as a regulator we were encouraging industry and I wish that the government had also like picked up the torch sooner but I think that we can now on exactly the initiative that Matt was talking about that that's happening in Europe. This issue around there is no like in cyber you have things called sticks and taxi the standards for sharing of cyber threat indicators and information because we learned this lesson that when criminals are exploiting your globally connected infrastructure at the speed of the internet that you need to be able to share in an instantaneous machine readable way. So we have information indicators around what's happening on the offense and then how to defend against it we haven't done that with illicit finance like we have tons of financial information standards like and there's tons of standards on like literally like the year C22 is like this is something that would be perfect perfectly positioned for cryptocurrency. So we're just generally for illicit finance we should have that standard and that should be feeding into exactly what the structured data fields are that age that law enforcement is asking for in response to subpoena requests and that agencies like Finsen are leveraging. There are some really brilliant minds who have been talking on this like Natalie Loebner has like comment on this for a long time and and I like I think she's totally right like this issue of us not investing in those underlying building blocks of fixing the data problem which will enhance the like at least getting actionable information into the hands of the right actor then if the actor doesn't act enter enforcement right or enter other levers of influence right like if the first step has to be that partnership that area was was really emphasizing of like. Getting actionable information into the hands of the right actor and then if they don't act. Figure out the right incentive character stick can make the Mac and that's where you think about disruption authorities as well as other positive incentives and including things like liability protections and insurance etc like that kind of mapping of thinking about what a strategy looks like in the near term the nearest term is standing up those partnerships finding those who are willing to act leveraging that willingness to sit on the desk of industry building those standards around data. That we know very largely there's the global signals exchange that's doing some of that work on technical information we do this for the Nick Mac we can do this for a less in finance. I have a million questions but let me encourage you to just keep going what else is most important that we haven't touched yet. Matt one sort of interesting thing is the distinction that you made between sort of the cyber space and the financial crime space and I tend to sort of like maybe just like loop them together in some ways right or wrong you know when I think about cybercrime, it always involves money, either right laundering funds or stealing them essentially. You know, the these pig butchering scam compounds, you know, 30 billion last year, that's probably 85% higher based on underreporting, right? I think of that as right an interesting mix between, you know, there's to Carol's point stealing funds at the speed of the internet, but having sort of like a really close cyber nexus, I wonder to what extent there is too much of a silos around how we're thinking about cyber and how we're thinking about financial crime. And I know Joanna is the host here, but when you said that, it sort of struck me as like, hey, is that actually something we could be doing better? And the answer is quite frankly, I don't know. I just tend to loop them in and talk about them only almost as one problem a lot of times. Yeah, I think the explosion in AI technology is all this seems like increasingly everything is becoming cyber in some way or another. Yeah. But I mean, going, we mentioned in our last recording, you were giving the example in Las Vegas of sort of the origin of the FBI being the fact that we had cars able to drive across state borders. So we needed to have a interstment law enforcement that body able to fight crime across state borders. Our whole money laundering architecture, financial crime architecture is still like psychologically grounded in the 70s. And it is all cyber. Everything is being done electronically now. If you are a multinational criminal organization, you probably are getting cash through drug proceeds and such. But your goal is to convert that cash into electronic funds that you can use to do other things. So it is, I think you're completely right. We need to be breaking all the silos, basically, would be my number one recommendation for fixing this type of thing. And that is it's not just between illicit finance and cyber, but I think it's also within illicit finance. You know, we have these very siloed legal frameworks, government bodies, activities inside a financial company for doing AML work versus fraud versus so there's the maybe retouchment in this for the first show. But there's fraud that the if you're a bank that you've got to pay for if you don't catch it. But then there are scams that the customers going to have to pay for because they've chosen to send their money to someone they shouldn't. You know, those are different categories. Different people are watching over them. And you know, they've got different compliance requirements around them. AML has dominated for so long as a cost center and activity for the banks where the bank doesn't have much of an incentive to focus on that other than the compliance side risk of it and compliance and enforcement. Fraud, they do have a self interest in trying to save their own money. Scams, you know, they're concerned, but they're not on the hook for it. So I just think, but as you're saying, they're increasingly blending together. The same people are doing frauds and scams are laundering the money. And the cyber, as you say, has a common denominator. So I don't know what to do about that. But I think we somehow have to connect the ecosystem in a different way. Go ahead, girl. Yeah, I. Yeah, go ahead, Matt, because I'm sure you that's yours is right on that. Well, I just want to redirect it to you, actually, Carol. I feel like my number one thing is break the silos, but I think I would also say the other biggest thing is identity. Yeah. It's so true. My great, there's so many interesting issues. And I think that especially in the current context of that in the US, what you're seeing is an emphasis on enforcement and new regulation is not what's going to happen for the next few years. So even though I think that mapping, important regulatory controls is necessary, understanding the present reality is also critical. So thinking about what the near term, midterm and long term solutions and initiatives are, but first requires mapping, like what are the problems? And you guys have pointed to several of the core problems. We do not have the trust tech infrastructure to really believe in a verified way, who is in fact on the other side of this transaction. Selfie and live news check and voice-based identification is no longer something that can be trustworthy. San Alten said that like a year or two ago highlighted that the state of AI is just at this point. There still are measures that can be put in place to try to defend against a deep fake field fraud. The reality is that like the tech is just going to continue to evolve and get more sophisticated. So the reality is that we need to be looking at cryptographic based identity solutions and actually promoting and supporting their adoption, like some of the counter fraud measures that we had put in the cyber EO at the end of the last administration. That unfortunately were rescinded in whole. I hope that they reissue them all. It's part of a broader counter fraud, like as an appropriately calibrated counter fraud strategy and approach in a more strategic and cohesive way. Like that would be fine and good. And at something that requires partnership with industry providers, TSA is doing some stuff right now about implementing work with digital identity providers through mobile driver's licenses. I think that there's some real investment that needs to get placed in on that front. And there's implications there for KYC utility sandbox and experimentation. But like the near term efforts that can create the operational space for the longer problems are things like investing in this data in rehiring people in and helping to support their scaled iterative like it should enforcement should be early and often across the ecosystem. It should because if you have a groundbreaking like record breaking huge enforcement penalty, that also means that we allow it to become a record breaking enforcement problem, right? Like that's not actually a good new story and we shouldn't view it that way. We should view enforcement as a purpose of shaping a sector and not breaking it. But so I think that there's efforts on that front that need to be invested in and focusing on helping the people that exist there scaling the ability to do enforcement using that data, leaning on industry. But then also looking at like efficacy, we have not done the work to assess and defend the efficacy of the AML framework treasury has not done that work. Even the RFIs that came out from the agencies, while importance to finally get real benchmarks for cost did not ask the meaningful questions that were needed for the efficacy of AML. Nor is there really a mapping and understanding of how AML controls are necessary for things like credit and civil litigation and taxes and revenue. Like there's a bigger connective tissue of these ecosystems and in cyber, we see this because like financial institutions love to point to well, it's the tech infrastructure's problems. Like that's where we need to be pointing because finance is regulated. We're not regulating for KYC purposes like domain, web hosting services and other things. But like there was a KYC for infrastructure as a service EO that was issued by Trump 1.0 and then upheld by Biden. But it never got issued because there's huge tensions across industry as well as even inside of the US government on whether we want to put in place KYC frameworks that industry claim don't work even in finance. Why would we want to impose that on more sensitive information activity? Like these tensions need to be resolved, but those are going to be longer term problems. So I think in the near term, thinking about how we actually measure efficacy of AML, which can feed better use of things like AI to detect it. And then like those near term efforts focusing on data and creating like sandbox frameworks that we can stop having to continue to circle in this like we don't allow innovation in AML even though I think we do. But like fine, publish some sandbox frameworks I think would be good. Hey Carol, real quick. So again, like Joanne, I'm not trying to steal your job. I promise you. No, no, I'm responded. We have responded at TRM to a number of these sort of RFIs on like BSA modernization across a couple different administrations now, right? It's obviously something that FinSEN has been thinking about for some time since you were there quite frankly. And I actually think a lot of the questions are the right questions, right? Like what are the controls that you could in place? What are the tooling that can be used? What is the technology that's out there? Do you have any inside base ball on sort of like where that is? And then I think one thing that's cool. I mean, Secretary Besen has made some really helpful statements over the course of his time at Treasury on you know, a risk-based approach, not a check box, you know, regime, thinking about using technology, AI, etc. What do you have inside baseball on like how this, you know, obviously it's going to take the hill as well. And this is kind of a herculian task. So maybe is it just like this is too hard? But what what's your take there? Yeah, I think the biggest problem that we have is that like metrics on effectiveness of AML like our hard are really really hard and we haven't put the best thinking on economists and national security benefit and mapping with an overlap of regulatory frameworks into thinking about it. So even though I do agree that there's been certainly a lot of emphasis on trying to reduce cost, that's a part of improving efficiency, having seen a time on improving effectiveness besides wanting to integrate like emerging technologies, which you're right over the past decade that's been a talking point at Treasury. But actually like making where the rubber meets the road is where I think the town problems and challenges have been, and mostly they've been around the fact that we haven't done those underlying issues that will help to allow for that vision to be accomplished. So it's not that the vision is entirely wrong. It's that like I don't think that there's an understanding of the root cause analysis that if you don't fix the data problem, if you don't understand like how these things intersect with even a national security community and the fact that like law enforcement, like they even carry and capture any metrics, just generally, this isn't a problem for just law enforcement agencies. If you look at most of their assessments of efficacy, they're pointing to like numbers of alerts that are issued, not like actual reduction of risk. And this problem that we have on people that want outcomes based enforcement approaches, that's good. We like, I like risk based approaches. No, I've also never really seen an architecture for it. And here's how you actually accomplish that at scale. Here's how you scale every examiner's ability to create up a spoke outcomes oriented exam every single time that they go in and conduct an examination. So the rubber meets the road problem. It's that translation that requires a like a really strategic approach to it. I hope that that's what will come out of a lot of these RFIs. I just, this is, this has been the problem that I think's been missing from a lot of the work over the past decade. Everyone familiar with the Santa Fe Institute and the kind of concept of the study of complexity as a science. It's an interesting model. They kind of core concept that, without getting into history, there's a book about them. It's just called complexity. And it was basically a bunch of Manhattan Project scientists who came together, post-Mahatton Project. And they realized that a biologist talking to a physicist, talking to an early economist or whatever, that the cross field population or propagation of thinking was causing inspirations from in their own field, just by hearing something from some other field. So that created the Santa Fe Institute. They are basically focused on the study complex systems, which could be biological, how people interact, all the kind of stuff. The core thesis that they have though is just saying that a lot of the ways we, we as humans think and also the way we enact policy is we sort of try to simplify systems down to something that we can kind of model in our minds. The solutions to this are, we simplify them does not work. They are inherently complex multivariate. We can one thing here and there doesn't work. We need to have, having like a fundamental top down reinvention of it. The kind of cool thing about it though is the advent of large language models and AI capabilities suddenly let us do a lot more of this sort of population level simulation of these types of things. But I think Carol to your point, the solutions this really would be something like the Santa Fe Institute or someone out there going and doing the research and coming up with, in my mind, a real solution of this thing is a much more tech-enabled government with a lot more free flow of information going on real time back and forth. There's a lot of ways that could be hijacked for nefarious purposes. You don't want to have the government having unfettered access to everyone's financial activity. So we've seen trying to go down a path of like social credit scores and high level super monitoring of everyone's personal lives. I think that we need to come up with a Western democratic alternative to that type of thing, which is acknowledging that we don't want our government to be hamstrung by excessive bureaucracy and paperwork and all these other things that's structurally slowing them down. We want them to have the ability to move lightning fast when it's needed, but you also need to build in the controls and structures and such to prevent that from being abused and have high transparency. So, I mean, if we really want to solve this problem, I think that we need to sort of stop hiding our heads in the sand and waving our hands around and saying, "Now we're doing an X, Y, and Z things that we'll believe will achieve a result." And actually find a bunch of funding to put together in commission real research on the costs, the impacts, the burdens, the waste, things could be abused, and area to your point like this will require Congress. Like we need to have a next generation overhaul of financial crime laws, but we all know Congress is not going to figure this out in a vacuum. They need to be given credible paths to follow. And I think that's where the community we're collectively building through all of our networks here and what Aero is doing is going to be lively and important. Yeah, I think that that same thinking is basically where the DOD Office of Net Assessment came from, like this concept, but only seen in DOD and like Treasury, the financial system is the underpinning of our economic strength. Why is there no equivalent of that inside of Treasury? Like you have weird, like interesting little pieces like OFR, but they really are mostly kind of exclusively pointed at more FSOC stability issues. So I hope that they would consider something like a listed like scale, a listed finance and integrity of the system as a whole to be part of stability. But like, I mean, even like the first economists that were in TFI came after the sanctions review at the beginning of the Biden administration. And they were inside of OFAC, not inside of Fincent, or benefiting all of TFI. Like you said, this need for a rethink, whether through FFRDC, through Think Tank, through Public Repert Partnership, through government, like wherever. But to bring that really, really big think, because measuring the benefit of a deterrent is really, really difficult and really complex. So I agree with you, I think that that's the kind of effort that would be good. It's a longer term Manhattan project. And then some of the near term things that we know that we can at least start getting actions and motion on certain R&D sandbox approaches, fixing the enforcement, dismantling, work around data. Like I think that those are some of the near term actions that can create operational space for the longer term fixes. You know, that little sound clip of what you just said Carol is almost like a microcosm of the challenge because you just used a whole bunch of acronyms that I'm pretty sure half of our audience doesn't even know what they stand for. And I definitely said DoD, so sorry, Department of War, the Office of Financial Research, sorry, that supports the financial stability of our site. Yeah, but I think that's part of the point that we're talking about here is we have all these groups that are very specialized in doing what they do and we need to figure out how to put it together. I think it can be helpful and I know it's helpful in these kinds of discussions to differentiate between the tech problem solving capability versus the human systems legal frameworks and so on. And I will say as a general proposition, we see every day at air that the tech problems are mostly solvable and the human ones are the hard ones. But let me ask you that do we have the technology to reliably keep data safe? If we're going to share it more widely, secure and protecting privacy, should people have confidence that if we share more across country borders, across public and private as you were saying, are we? That can we use encryption techniques or privacy enhancing technologies, zero knowledge groups, whatever they are? What are the ways to be sure that if we create this much more robust sharing that it won't lead to massive exposure? Yeah, I'll let Carol or Matt dive in here just really quickly. I think we do. I think we're I think we have people that are certainly building this today and I think it's getting better and better. I think we should be sharing less and using technology in order, like you mentioned zero knowledge proofs. I think that's a great example of how we can arguably share less or just what is needed as opposed to creating these giant honey pots of information to be sold as we have today. Carol, I have heard you speak on this for years. Go for it. Sure, and I'm so curious what Matt has to say since he's literally built a REC tech tool to help implement some of these things and help investigators. I know that I'll first highlight like a controversial view that I have because I know that there are like and this isn't disagreeing with with with areas, disagreeing with certain arguments that have been made from parts of the crypto industry where they've stated that they should not have to do things like share information like like originator and beneficiary information because well this other country doesn't have you know how do I know if it's being protected or whatever or that like it made create a honey pot and a target for information. My own view was and remains that like so just to be clear you feel that you guys should be trusted to custody digital financial assets but not the information to help you understand whether or not that is a designated person or ISIS or North Korea like just to be clear like that is your position that you should be trusted to custody that digital asset but not the information that allows you to comply with really important rules. So lots of people have very strong feelings in response to that and I get it but I also do agree that there's lots of information that is being shared all the time that does not need to and where it requires that nuance of really thinking about what are the attributes that are necessary in order to conduct what specific use cases on detecting suspiciously, on issuing due process on like because those features look different, right? Like someone's physical address may not be an indicator of whether or not they are illicit. The attribute of whether or not that physical address matches some other like you know supported or um um you know given identity document that may be the attribute that you care of does match like you know x1 um but then maybe that only needs to be discoverable when law enforcement says great warrant um I'm going to go arrest this person because I've determined that they're part of a money laundering network supporting a curtail or whatever and that's when they should be able to get access to the underlying attribute um but there's other attributes that are that are a part of really understanding the risk profile of who you're dealing with so like it demands that kind of nuance and the tech like you said is there it's really the the discussions around the governance practices and architectures and that's where when industry says things like homomorphic encryption, multi-party computation, seronology proofs, all these fun privacy enhancing technologies. I agree we have fact-retelling industry in 2018 that the future of crypto was going to be privacy tech because people were not going to want to publish their information on public on obscured ledgers forever so we knew that but industry hasn't yet I've not seen industry or governments come with a framework of here's the entire ecosystem architecture that allows for appropriate discoverability for the complexities of what is knowing your customer and their risk profile through the life cycle of account management as well as supporting suspicious transaction monitoring and supporting due process and then that and then that just gets expanded into more complexities because of cross-border issues but like there's some opportunities there to to really like carve into the like the tech I think is mostly there I think I think the issue is governance and policy frameworks so before you speak to it Matt I just want to observe that if that's right and I believe you because I hear this from so many people like you who have looked at it deeply if that's right then one of the hurdles to overcome is that the decision-makers don't believe it I think there's just a lot of ignorance frankly and skepticism that these things are doable and wouldn't be just creating even bigger nightmares but go ahead Matt. Yeah and industry hasn't coalesced around like an answer to yeah exactly exactly I think one piece of this that we always default to is acting like the status quo is private and safe and the name one has worked in the industry one of the ways information sharing happens under 314b today is literally emailing a word document with a bunch of vi in it to someone else and then password protecting that word document and then sending the password separately in a different email as if that makes it secure but like literally financial institution procedural procedures sometimes are still doing that type of thing I also remember a prior experience where I've got an unencrypted email from a not to be named law enforcement agency with about 400 social security numbers I encrypted it and just saying do you have any of these they're involved in a CSAM activity and like you have just put me in violation of my own information security policy here because now I have a PII in an unencrypted environment so I think we need to acknowledge number one that the status quo is incredibly not private and the second thing I think is we should be willing to also entertain the question of do we really care about low level of criminal activity they say that's like what you're designing a fraud program the correct level of fraud is not zero because if you have zero fraud the only way you can achieve that is by also kicking out a whole bunch of good customers and uptripping some flags if the correct amount of crime is not zero either the only way to do that is to have a dystopian kind of government big brother control of all aspects of society but we need to find a way to invert what we have today which is that the most sophisticated large scale criminal actors never get caught because they make it too difficult to detect them and we only catch the low level people obviously it says grocery generalization I saw in the news yesterday what one of the Epstein fallout elements a famous person in Europe was saying she first had resigned from whatever roles they were involved in and also six companies that they were involved in were going to be shut down and this person was the only board member of all six companies and all six of them do not have any kind of clear purpose for why they exist so one of the breakthroughs in my mind happened when I was serving an operational role trying to figure out how to implement any money laundering controls was realizing it was important to look for known suspicious activity patterns but it was even more powerful to invert it and say let's just train behavioral models based off of other normal customers look like and then anything that has a behavioral fingerprint of normal activity is fine and then you devote your investigator effort to look at the anomalies like people who are unusual in different ways if we think about it next generation anti-money laundering paradigm here where like throw KYC transaction monitor and all the other stuff that we do out the window as it's done today and go back to first principles on it and say like maybe we don't need to have KYC activity I mean you can kind of do this in the money transmitters a little bit but like you can't you don't have to KYC activity below a certain threshold but then you worry about worry about money mules and you worry about people creating multiple accounts but do we have the technology now to create like a biometric linked proof of person hood token that cannot be replicated where it's not your identity and your address all these other things being attached to it but you can prove it's just only me engaging in this financial network and then you increase the threshold KYC on me if I start exceeding thresholds activity but then also if we have every financial activity sorry I can't speak this morning financial transactions happening on chain and you can start to see when all these low level actors kind of connect up behind the scenes maybe five or ten hops down the road we've got machine learning tools here that can start to tease out the behavioral network like put networks together I mean CRM has done a phenomenal job as a company of deploying these types of tools so to your point Joanne I feel like if we toss everything out the window and come back like say what do we really care about here we don't want the really big sophisticated actors to be able to run rains around us we want to be able to preserve privacy at the individual level and we want to have sort of the ability for government to go in and figure out what's happening in aggregate I think the combination of the various types of blockchain technologies tokenizing assets tokenizing identities all these types of things we put them together you can kind of start to see the outlines of the next generation anti-money laundry approach that could make the anarcho crypto people who don't want any identity out there at least a little bit more comfortable with things while still ensuring that the big bad actors are interdictable so the government and anti-money laundry people will be on board with that and I love to see us really sort of maybe it's a mandate for error here to come in and actually create a thousand page paper on what the next generation looks like here fortunately people would be able to meet it with generative AI so first of all we are we block time that ends in five minutes can you go a little bit longer or do you have a hard stuff I kind of have a hard stuff I'm so sorry so I'm going to maybe threaten that we're going to need part three I'm so sorry yeah you guys obviously keep keep keep rocking a roll in but I don't know what the next assessment is a finance AI it's going to be great so I have one thing I want to talk about if you guys would entertain another conversation let me tell you some of the things that I'm thinking about one is we haven't really talked about a Genetic AI and Matt what you do

Podcast Summary

Key Points:

  1. The current regulatory system is too slow and methodical to effectively combat rapidly evolving financial crimes, especially with new geopolitical competition from China.
  2. Financial crime is escalating due to technologies like AI and cryptocurrency, enabling fraud, money laundering, and cyberattacks at unprecedented scale and speed.
  3. Solutions require reimagining public-private partnerships, real-time data sharing, and global cooperation, moving beyond compliance to treat financial crime as a national security issue.
  4. There is a critical need for updated legal frameworks, digital identity infrastructure, and technological tools to detect and prevent crimes while protecting data privacy and security.

Summary:

The discussion highlights the urgent challenge of financial crime in an era of rapid technological advancement and geopolitical shifts. Current regulatory frameworks are too slow, risking economic competitiveness and security, especially with China's rise. Crimes like fraud, money laundering, and cyberattacks are accelerating due to AI and digital assets, enabling bad actors to operate at scale.

To address this, the approach must shift from viewing financial crime as a compliance issue to treating it as a global security threat. Key solutions include fostering real-time public-private partnerships, improving data sharing with privacy protections, and establishing common international standards. Additionally, investing in digital identity infrastructure and updating legal systems are essential to keep pace with technological changes and effectively combat these evolving threats.

FAQs

The regulatory system is slow and methodical, while criminals move quickly using advanced technologies like AI. This mismatch allows financial crimes to expand rapidly, outpacing traditional enforcement methods.

AI is supercharging financial crime by enabling scams at scale, deepfake fraud, and automated attacks. Bad actors use AI to tailor schemes to individuals, making crimes more effective and harder to detect.

Cryptocurrency is used by nation-state actors and criminals to move billions of dollars illicitly. It provides infrastructure for large-scale operations, such as funding cyberattacks and evading traditional financial tracking.

Enforcement is often slow, with actions based on outdated data from years ago. This lack of timeliness fails to deter or disrupt modern, fast-moving criminal activities effectively.

The absence of effective digital identity systems allows identity-based fraud and cybercrime to thrive. Without trusted digital identities, it's difficult to prevent unauthorized access and delegations in the digital ecosystem.

Partnerships need real-time information sharing, interdiction, and prosecution capabilities, not just discussions. This involves giving the private sector some authorities and ensuring public access to private data for coordinated action.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.