The Laundry Math

BASKING RIDGE, N.J. — Replacing its manual process, the $1.8-billion Affinity FCU has successfully automated its anti-money laundering procedures, reducing the time it takes to remain compliant with related regulations while not increasing its headcount.

Processing Content

The credit union chose the Fiserv AML Manager, gong live with the solution December 2008 by integrating with its XP2 core system, also from Fiserv.

"It's a transaction monitoring program that looks for what we consider to be suspicious behavior," said Janae Sasman, director of compliance product management for Fiserv's risk management division. "They can choose to open a case if it's warranted. [The credit union's piece] is to resolve the alert."

Jim Wilcox, AVP-risk administration with the credit un ion, noted, "In order to comply with federal regulations that require more robust transaction monitoring, we needed to find an automated tool that would help us find needles in our haystack. While identifying reportable currency activity is fairly easy, monitoring has become increasingly more difficult as regulators require us to perform more in-depth analysis of transactions. Absent technology, it would be impossible for credit unions to perform this level of analysis-especially when we process millions of transactions annually. Our first reason for implementing AML Compliance Manager was to provide us with the automated means to identify these types of suspicious activity."

On a nightly basis, AML Manager extracts transaction data from the account processing system, combines it with other credit union-gathered data, and conducts dynamic risk scoring on each transaction. The dynamic risk score is based on thresholds and criteria recommended within AML Manager and modified as needed by the credit union. Daily reports categorize transactions as low, medium or high risk, enabling Affinity FCU's internal investigator to focus on attention on the highest risk items. The software also periodically runs member and transaction data against the most current OFAC and 314a lists in compliance with federal regulations.

"The implementation was a three-phase process," Wilcox noted. First, prior to hardware/software installation, the CU met with Fiserv representatives to begin to discuss the monitoring parameters that would later be used to alert Affinity to suspicious activity.

"During this phase, we determined all of the essential elements that would make any one of more than 20 alerts low, medium or high," Wilcox said.

Second, after initial configuration, Fiserv loaded the AML Compliance Manager Server and data began to collect immediately after it was installed in December 2008.

"The nature of this monitoring software required 60-90 days of priming," Wilcox said. "The final phase was to view our alerts and make adjustments to the parameters established in step No. 1 to ensure the output would be valuable in terms of identifying truly suspicious activity."

The credit union has avoided the costs of hiring the estimated one-to-two employees who would have been needed to continue handling the process manually.

Wilcox said the AFCU is now in a better position to identify activities outside the norm, and to manage risk more effectively. He noted that AML Compliance Manager already has identified several cases of suspicious activity, which Affinity FCU has reported to federal authorities through Suspicious Activity Reports.

"Immediately after installation, we cut the time and cost of reviewing our member database against select government lists, including the bi-monthly 314(a) lists by more than 50%," Wilcox said. "As new lists are downloaded, AML Compliance Manager runs them against our database and immediately provides us with alerts based on matches. We review each to determine whether we have a hit or false/positive, and flag the alerts accordingly. It also captures large currency transactions an enables us to inspect them to ensure they are reportable."

For other CUs looking to emulate this best practice, Wilcox said he "cannot over emphasize the value in choosing a third-party monitoring product that is compatible with your core system. Knowing your core processor and third-party application group are supporting one another helps expedite resolutions to some of the small, but important issues that are apt to arise during implementation."

Best Practices CUJ 2009
CU: Affinity
Best Practice: ALM Compliance
Vendor: Fiserv


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More