Featured Product

    FSI Note Discusses Official Response to Cyber and ML Risks Amid Crisis

    May 14, 2020

    FSI published a brief note that outlines official response of the authorities worldwide to the increasing risks of cyber-attacks, money laundering (ML), and terrorist financing (TF) amid the pandemic-related lockdowns. Authorities worldwide have responded by providing guidance on ways to improve cyber security and mitigate ML and TF risks. Financial authorities are warning financial institutions to be watchful in relation to their IT networks and non-public data, third-party risk, and cyber-security incident response plans and to focus additional effort on staff training and awareness.

    The note highlights the financial crime seen so far during the current crisis—when 90% of the banking and insurance workers may be working from home—and summarizes official approaches to strengthening the cyber resilience of financial institutions. It also describes the main anti-money laundering (AML) measures taken by selected authorities worldwide. In response to current and emerging cyber threats, the measures taken by regulatory authorities include:

    • Raising awareness through public statements about increasing levels of cyber crime. A few authorities publicly outlined the types of cyber resilience measures undertaken in the context of COVID-19 crisis. An example of this approach is the April 2020 public joint statement by the Bank of Italy and IVASS.
    • Providing guidance on the most relevant cyber resilience areas. Some authorities including New York State Department of Financial Services provided guidance on the heightened risks to IT networks and non-public information. Several authorities are emphasizing staff training and awareness at financial institutions. Incidentally, as part of its 2020 work program, FSB is consulting on a toolkit of effective practices to assist financial institutions before, during and after a cyber incident.
    • Information-sharing on COVID-19-related threats. Some authorities are using existing domestic channels to exchange information on COVID-19-related cyber threats with financial institutions and other trusted counterparts. Organizations, such as the Bank of Italy and IVASS, are using these channels to disseminate security bulletins, organize webinars on attack techniques and possible countermeasures, and facilitate training on the correct use of company devices and the strengthening of controls connected to remote work. At the international level, the Euro Cyber Resilience Board for pan-European Financial Infrastructures and the Cyber Resilience Coordination Center of BIS are expected to play an important role in facilitating the exchange of information on COVID-19-related threats.

    Furthermore, as a result of the crisis, many authorities are prioritizing other prudential areas and, therefore, postponing AML onsite inspections or relying only on off-site monitoring. Some are also delaying AML reporting and other AML regulatory requirements to alleviate the resource pressure on financial institutions. Moreover, a number of jurisdictions have seen an increase in cash withdrawals during the crisis. When the flow of cash goes into reverse as the situation stabilizes, this could provide cover for ML activities. Overall, the note concludes that, in the areas of both cyber and ML/TF risks, the guidance provided by the authorities worldwide underscores the trade-offs between expecting financial institutions to enhance or adjust their cyber resilience and AML frameworks and, on the other hand, avoiding imposing an excessive burden that could hinder financial institutions in delivering key financial services. 


    Related Link: FSI Brief

    Keywords: International, Banking, Insurance, COVID-19, Cyber Risk, AML/CFT, Operational Risk, FSI

    Featured Experts
    Related Articles
    News

    PRA and FPC Finalize Changes to Leverage Ratio Framework in UK

    The Prudential Regulation Authority (PRA) published the final policy statement PS21/21 on the leverage ratio framework in the UK. PS21/21, which sets out the final policy of both the Financial Policy Committee (FPC) and PRA

    October 08, 2021 WebPage Regulatory News
    News

    CFPB Proposes Rule on Small Business Lending Data Collection

    The Consumer Financial Protection Bureau (CFPB) proposed to amend Regulation B to implement changes to the Equal Credit Opportunity Act (ECOA) under Section 1071 of the Dodd-Frank Act.

    October 08, 2021 WebPage Regulatory News
    News

    PRA Decides to Maintain O-SII Buffers for Another Year

    The Prudential Regulation Authority (PRA) decided to maintain, at the 2019 levels, the buffer rates for the Other Systemically Important Institutions (O-SII) for another year, with no new rates to be set until December 2023.

    October 08, 2021 WebPage Regulatory News
    News

    FSB Report Assesses Implementation of Recommendations on Stablecoins

    The Financial Stability Board (FSB) published a progress report on implementation of its high-level recommendations for the regulation, supervision, and oversight of global stablecoin arrangements.

    October 07, 2021 WebPage Regulatory News
    News

    APRA Updates Loan Serviceability Expectations for Home Lending

    In a letter to the authorized deposit taking institutions, the Australian Prudential Regulation Authority (APRA) announced an increase in the minimum interest rate buffer it expects banks to use when assessing the serviceability of home loan applications.

    October 06, 2021 WebPage Regulatory News
    News

    CPMI and IOSCO Consult on Guidance on Stablecoin Arrangements

    The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) are consulting on the preliminary guidance that clarifies that stablecoin arrangements should observe international standards for payment, clearing, and settlement systems.

    October 06, 2021 WebPage Regulatory News
    News

    EBA and EIOPA Set Out Work Priorities for 2022

    The European Banking Authority (EBA) and the European Insurance and Occupational Pensions Authority (EIOPA) have set out their respective work priorities for 2022.

    October 05, 2021 WebPage Regulatory News
    News

    MFSA Issues Reporting Updates and Guidance for Banks

    The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0, in addition to the reporting module on leverage under the common reporting (COREP) framework.

    October 05, 2021 WebPage Regulatory News
    News

    EC Publishes Decision on List of Equivalent Third Countries Under CRR

    The European Commission (EC) published the Implementing Decision 2021/1753 on the equivalence of supervisory and regulatory requirements of certain third countries and territories for the purposes of the treatment of exposures, in accordance with the Capital Requirements Regulation or CRR (575/2013).

    October 04, 2021 WebPage Regulatory News
    News

    EC Rule on Contractual Recognition of Write-Down and Conversion Powers

    EC published the Implementing Regulation 2021/1751, which lays down implementing technical standards on uniform formats and templates for notification of determination of the impracticability of including contractual recognition of write-down and conversion powers.

    October 04, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 7552