Featured Product

    FSI Note Discusses Official Response to Cyber and ML Risks Amid Crisis

    May 14, 2020

    FSI published a brief note that outlines official response of the authorities worldwide to the increasing risks of cyber-attacks, money laundering (ML), and terrorist financing (TF) amid the pandemic-related lockdowns. Authorities worldwide have responded by providing guidance on ways to improve cyber security and mitigate ML and TF risks. Financial authorities are warning financial institutions to be watchful in relation to their IT networks and non-public data, third-party risk, and cyber-security incident response plans and to focus additional effort on staff training and awareness.

    The note highlights the financial crime seen so far during the current crisis—when 90% of the banking and insurance workers may be working from home—and summarizes official approaches to strengthening the cyber resilience of financial institutions. It also describes the main anti-money laundering (AML) measures taken by selected authorities worldwide. In response to current and emerging cyber threats, the measures taken by regulatory authorities include:

    • Raising awareness through public statements about increasing levels of cyber crime. A few authorities publicly outlined the types of cyber resilience measures undertaken in the context of COVID-19 crisis. An example of this approach is the April 2020 public joint statement by the Bank of Italy and IVASS.
    • Providing guidance on the most relevant cyber resilience areas. Some authorities including New York State Department of Financial Services provided guidance on the heightened risks to IT networks and non-public information. Several authorities are emphasizing staff training and awareness at financial institutions. Incidentally, as part of its 2020 work program, FSB is consulting on a toolkit of effective practices to assist financial institutions before, during and after a cyber incident.
    • Information-sharing on COVID-19-related threats. Some authorities are using existing domestic channels to exchange information on COVID-19-related cyber threats with financial institutions and other trusted counterparts. Organizations, such as the Bank of Italy and IVASS, are using these channels to disseminate security bulletins, organize webinars on attack techniques and possible countermeasures, and facilitate training on the correct use of company devices and the strengthening of controls connected to remote work. At the international level, the Euro Cyber Resilience Board for pan-European Financial Infrastructures and the Cyber Resilience Coordination Center of BIS are expected to play an important role in facilitating the exchange of information on COVID-19-related threats.

    Furthermore, as a result of the crisis, many authorities are prioritizing other prudential areas and, therefore, postponing AML onsite inspections or relying only on off-site monitoring. Some are also delaying AML reporting and other AML regulatory requirements to alleviate the resource pressure on financial institutions. Moreover, a number of jurisdictions have seen an increase in cash withdrawals during the crisis. When the flow of cash goes into reverse as the situation stabilizes, this could provide cover for ML activities. Overall, the note concludes that, in the areas of both cyber and ML/TF risks, the guidance provided by the authorities worldwide underscores the trade-offs between expecting financial institutions to enhance or adjust their cyber resilience and AML frameworks and, on the other hand, avoiding imposing an excessive burden that could hinder financial institutions in delivering key financial services. 


    Related Link: FSI Brief

    Keywords: International, Banking, Insurance, COVID-19, Cyber Risk, AML/CFT, Operational Risk, FSI

    Featured Experts
    Related Articles
    News

    EBA Publishes Regulatory Standards to Identify Shadow Banking Entities

    The European Banking Authority (EBA) published the final draft regulatory technical standards specifying the criteria to identify shadow banking entities for the purposes of reporting large exposures.

    May 23, 2022 WebPage Regulatory News
    News

    EU Agencies Update LCR Rule and Macro-Prudential Policy Recommendation

    The European Commission (EC) published the Delegated Regulation 2022/786 with regard to the liquidity coverage requirements for credit institutions under the Capital Requirements Regulation (CRR).

    May 23, 2022 WebPage Regulatory News
    News

    OSFI Discusses Benchmark Rate Transition, Sets Out Work Priorities

    The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.

    May 17, 2022 WebPage Regulatory News
    News

    EBA Proposes Standards to Support Secondary NPL Markets

    The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.

    May 17, 2022 WebPage Regulatory News
    News

    EU Confirms Agreement on Rules on Cybersecurity and Banking Resolution

    The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).

    May 13, 2022 WebPage Regulatory News
    News

    EBA Issues Standards for Crowdfunding Service Providers Under ECSPR

    The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.

    May 13, 2022 WebPage Regulatory News
    News

    EU to Amend Credit Risk Adjustment Rules; ESAs Submit Queries on SFDR

    The European Council published a draft Commission Delegated Regulation to amend the regulatory technical standards on specification of the calculation of specific and general credit risk adjustments.

    May 13, 2022 WebPage Regulatory News
    News

    EU Confirms Agreement on Rules on Cybersecurity and Banking Resolution

    The European Securities and Markets Authority (ESMA) published a paper that examines the systemic risk posed by increasing use of cloud services, along with the potential policy options to mitigate this risk.

    May 12, 2022 WebPage Regulatory News
    News

    MAS Amends Notice 635 and Issues Second Proposal on Green Taxonomy

    The Monetary Authority of Singapore (MAS) published amendments to Notice 635, which sets out requirements that a bank in Singapore has to comply with when granting an unsecured non-card credit facility to individuals.

    May 12, 2022 WebPage Regulatory News
    News

    EC Consults on PSD2 and Open Finance; EU Reaches Agreement on DORA

    The European Commission (EC) published a public consultation on the review of revised payment services directive (PSD2) and open finance.

    May 11, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8201