Loading component...
How to strengthen financial crime controls

Podcast episode
Vincent Mok:
Even after you have developed your product, you go to the market. The reality is that they will attack you throughout the process. Some would still nevertheless be able to enter your system and perform transaction activities so that continuous surveillance is necessary.Elinor Kasapidis:
Welcome to CPA Australia's With interest podcast. I'm Elinor Kasapidis, chief of policy, standards and external affairs here at CPA Australia. Today we're in our Singapore studio talking about financial crime. Specifically, we're talking about the growing challenge of fraud and the role of anti-money laundering and counter-terrorism financing and the controls that are used to protect the financial system. It's an area that's getting renewed attention in Australia, with new AML CTF laws being rolled out, including to professional accountants.At the same time, we're also seeing fraud risks increasing in scale and sophistication, driven by digital payments, cross-border activity and organized crime. Joining me here today to explore what this means in practice. I'm joined by Vincent Mok. Vincent has more than 25 years experience across major international banks, and now serves as group chief risk officer at GXS Bank, a digital bank.
He specializes in risk modeling, data analytics, enterprise risk management and works closely with regulators, boards and industry partners on financial crime and governance. Welcome to With interest, Vincent.
Vincent Mok:
Thank you. Thank you for having me this morning.Elinor Kasapidis:
So before we get into the mechanics of financial crime and AML CTF, I wanted to hear a little bit about you. So you've done a lot of work across banks. And how have you found yourself in a group chief risk officer role specializing in financial crime?Vincent Mok:
Oh, that's a very long story. Interesting question. Actually, I started off, of course, you know, finishing off my CPA program. And thereafter I joined one of the international bank, Citibank. I started off in the retail business in the area of collections. And thereafter I've kind of went through the the journey looking at analytics, then into credit, into then business, and also then moving on to different areas.So over time, I've covered the entire credit business spectrum end to end, and therefore thereafter, I guess over time opportunity came about. You know, I was in a regional role covering seven markets and then the opportunity to set up a digital banking. And of course, I think for many that itself is really a decision in your career because you have to decide, are you happy with your comfort zone or are you willing to start afresh with a blank piece of paper?
I thought the latter because, you know, it's hard for an opportunity to come where you set up a bank from scratch. So I thought that that would be pretty exciting. My area of specialty was actually more on credit risk and modeling data modeling. However, I think, you know, when I landed a job here, I think one of the bigger focuses was, was financial crime.
And the reason for that is really because as a digital setup is, is things move very quick. Product offering, we do it pretty quick onboarding in a couple of minutes, and therefore it has incentive for financial crime syndicates to actually target the bank. And therefore it became an area that I spent quite a bit of time in.
Elinor Kasapidis:
That's a really interesting career story. And we have many CPAs who actually specialize in data analytics right from the beginning. And with technology, digital banking is the next frontier, and we're seeing a lot of those. It facilitates things a lot more easily. People don't necessarily need to have a bricks and mortar retail bank anymore. So it is the new frontier and that reflects a shift in the environment.As technology improves, you have borderless transactions and people are moving around the world as well. They use their credit card, their bank account in lots of different regions, and that makes fraud more and more a risk that is global. It's cross-border, it's manifesting in digital systems and sophisticated. And I can, you know, I have a little bit of history in financial crime as well.
And so you see the sophistication and the cleverness, I guess you can say, of organized crime as well as opportunistic threats as well. And regulators are always trying to catch up with the pace of change. So as you've evolved into this role from credit risk into financial crime, how do you see the landscape evolving?
Vincent Mok:
I think for financial crime, it will be ever evolving. And there is... and I often use this analogy for us to combat financial crime it's really a game of chess. You know, you, you you set safeguards, set controls. And then they will figure out how do they actually bypass the system. Still, I think the intent is a simple one is to, to either bring money out of the to beat the system, to move money around.Of course, I think ultimately is not for good purposes. And therefore in the changing landscape, I guess the reflection I had was really that how do we move from the defensive to also offensive? Because defensive, what it means is you will always end up playing catch up game and you will think about, you know, what is actually hitting us and then you implement controls and whatnot.
I guess it's actually useful for organizations to think about how you reform and reshape your architecture and control. So you need not have incidents to occur before you decide to implement some control. So when we do new product development, for example, we think about what potentially could go wrong. And often if you think about, you know, a very seamless journey, you always think customer first and that's the right thing to do.
But however, you also need to wear the hat, because what these syndicates will aim to do is to capitalize on that, to build the system. So you have to have a fair balance between speed and trust. And therefore, I think if one that is actually able to combat it better will be one that can incorporate both speed and trust in their build elements.
Elinor Kasapidis:
And you mentioned before, people can set up an account in a few minutes. And so people talk a little bit around bringing some friction in so that it's not always right on time. So from the onboarding process to the money that flows through the account, and in terms of closing the door as the horse is bolted. So you will have fraud of care, but you can detect it.How do you break down when you're developing a new product? That's sort of psychology of the criminal so that you can test your processes?
Vincent Mok:
I think one would have to have where the head of a fraudster, I mean, we may not be the best in it, but you would imagine that every process within the system that you create be onboarding, you know, transaction activity, even the loan process, etc. all those actually will have that touchpoint that potentially be vulnerable. And therefore in doing so, you will have to think about what kind of safeguards you put.Of course, the regulatory framework does provide some guidance, but I would say doing bare minimum will often be balanced. It will be okay as a start. But as things evolve, I would say you have to do much more than what the regulation prescribed.
Elinor Kasapidis:
It's a little bit like in it they get hackers, white hat hackers to exactly the security system. So it's almost similar in the banking sector where you're testing the product. Is that right?Vincent Mok:
Yes. In fact, you know, as we go through the process, even with our regulator there sometimes also where the hat as a hacker and said, what if I were to do this, if you do a if, say, for example, they test out our selfie capability, they will say, you know what, if I use my kids image, have you tested tampering?How do you deal with fake identities. So these questions actually gets challenged. But internally of course is almost being true. As examination. You often have to be very prepared in your response as well.
Elinor Kasapidis:
Yeah. There's a lot of things in what you just said because you've got fraudulent identities. There's also fake paperwork. There's misrepresentation. I know in Australia we have instances where, you know, disadvantaged people are brought in by criminals to use their identities and they're not necessarily aware of what they're signing up for. If you do this, you can get $1,000, but they don't realize that they're being used to get more.Do you see some of those behaviors coming through the system?
Vincent Mok:
Yes. I think a financial crime, and these criminals often rely on a couple of key principles. First, you know, focus on the vulnerable, the attack on basically emotions and basically on fear, urgency, great love. These are some of the kind of principles that they have. So if you fall under these so-called vulnerable categories, more likely than not you would either end up, you know, being on one side or the other, whether you would be targeted for like, you know, a conduit to, to to help them some, some end up actually being mules.And on the other side, if you know, you, you, you know, of course everyone make and earn a living and therefore in doing so, you know, are attracted to very attractive investments, not whatnot. And therefore, you know, they are also vulnerable, but in the perspective of being a victim. Yeah.
Elinor Kasapidis:
And it's broader than just sort of AML CTF. But yeah, touching on frauds, scams, victimization of the vulnerable. It's a really big space. And you can never necessarily assume that you're not going to be affected or that someone else is close to you might be impacted as well. And the banks play a really important role in that. Speaking of which, the banks, there's an expectation and they're the probably the frontline of AML, CTF and financial crime detection.You know, what does a good fraud control process look like inside a bank today? You've touched on some of the aspects, but as a risk officer, what are you looking at from a governance perspective in a product development perspective?
Vincent Mok:
And from a product development perspective? Of course, I think what is important is think about having all the lines of controls, participating in that whole journey development journey. It is actually not just something that belongs to business or first line of defense, but when you get the various SMB people who come in. That's where you get the complete perspective.However, having said that, I life doesn't really stop there because even after you have developed your product, you go to the market. The reality is that they will attack you throughout the process. They will. Some would still nevertheless be able to enter your system and perform transaction activities so that continuous surveillance is necessary. In my mind, what is a good control is really understanding the tough attacks that you have.
So imagine, you know, you always have homes, you have doors and windows, have you shut down, close your doors and windows properly. And whether do you know if anything is flying in or not. So the surveillance that you had has had to be extreme. You instead of putting guards, you probably have to have sensors everywhere. And therefore if you are able to know on real time, even I would say if you could know every morning like what the top scam attempts that's been, that's happening.
If there's anyone who would try to knock on your window, you know, then you could react. And the faster you are in doing that, the better it is. The second one is that we spoke about two things. One is on fraud and AML, but interchangeably. So if you think about it, it's perhaps two sides of the same coin.
So on one spectrum, if you are looking at transaction activity, it may tell you that someone has been scammed. But if you look at the reverse, it may tell you that someone is attempting to perform AML activities. So from a from a governance setup, some of the more conventional practices is that we have dedicated fraud division, we have dedicated AML division, but seldom they speak to each other or they work together.
And one that has integration of these two functions, I believe works better. And of course, if you think about implementing or making reforms, you really need to turn from the top. So what is needed? You really need a good sponsor who will lobby for a push for the change, because otherwise what is just going to happen is that people will you will end up creating capacity to manage these volumes, but it keeps coming.
So it's a question whether it's our job to just deal with what's coming or to stop it. So I think have clear narrative on that will be very useful.
Elinor Kasapidis:
And everyone has a role in in detecting these things and all the way down, perhaps in a traditional bank, the retail frontline, the customer service officers, it sounds like for you as a digital bank, you have technology, you have that constant surveillance. I love the sensors analogy. That's a really good one. And you did touch on it's not just the banks.So there is a regulatory environment. There are other participants in the system and we use the term, you know, the system is only as strong as the weakest link. So how do you collaborate with others, both your customers, the regulators, other people in the ecosystem to help raise awareness and not to have to always just deal with it at a transactional level?
Vincent Mok:
One which is important is that the ecosystem collaboration, private public coordination is extremely important. And the reason why I say that is because you could imagine many organizations didn't get hit at the same time the same way. Something that is actually hitting you today may hit your fellow industry peers tomorrow, and vice versa.They may see things that you don't see. And the question is really, you know, when you are talking about fraud or financial crime is higher the better or lower the better. Lower means you don't have the data. Higher means you have things to process, but you also learn. So it's a question of striking the balance and the industry collaboration just means that you get signals and the various signals combine makes it more meaningful. And I think given the skill of financial crime, it really takes beyond just a particular party to combat it, really require, you know, you could think about, you know, the extension. So, so in the past, if you're thinking about that, predominantly people think about the, you know, the central bank, the police force and the banks.
But today, if you are thinking about that, right, you actually extend beyond like many, many industries you are thinking about also telco, social media, where actually, you know, some of these are happening and you could imagine it extends to other industry as well brokers, real estate, real estate, agent, lawyers, so much so, so I think, you know, that concept is the right one to actually get everybody be part of the whole system.
Elinor Kasapidis:
Harden the environment so the criminals can't get there and intelligence. So in Australia we have a statutory body called Austrac, which is the government body that gets a lot of intelligence. And there's a lot of... it's interesting because sometimes you're obviously competing on product, you're competing as a bank. But there are elements like financial crime where the cost to society, the cost to the bank, the cost to government is quite high.So do you do you share intelligence? Not not necessarily at that transactional level, but just behaviors and how they're attacking the system. Is there a mechanism for that?
Vincent Mok:
We do share Intel. And of course this is actually done within the boundary of data protection as well. So it's a fine line. And we have to always exercise balance and control as we share data as well. But in terms of I think for confirmed financial crimes, in fact the profiles and credentials are shared across system. So so that everyone deals with appropriately.Elinor Kasapidis:
You mentioned before just the broadening of the ecosystem that can be used to control and deal with financial crime. How do you see accountants and professional advisors and lawyers? Because many, many times, you know, they are supporting small to medium enterprises or they're supporting individuals to establish these accounts. So what should they be preparing for?So from a bank perspective, you've been there. You've been in the space for a long time. You mentioned doing the basics. What the regulator or what the laws require is a good start, but perhaps there's more. Any tips or insights for our listeners today?
Vincent Mok:
Yeah, I think one is that, you know, of course, each of the profession has a professional code of conduct. And of course, there will be guiding principles that the regulator prescribed. So one of the things that is being implemented is a shared responsibility. And if you think about shared responsibility. What is it really says is that everyone comes together to have protect, you know, customers for greater good.And, and therefore I think in regardless of the industry is important to differentiate who are your good legit customer was just those that is the the syndicated ones and the bad ones. And I think as a as an industry, I think the general principles is we do business with the good legit customer. I think be it estate agents be it lawyers, accountant, that same principle has to apply. And I think form over substance is the concept shared responsibility framework. I don't think the industry needs to wait until there is an enforcement of such conduct before we do something. I guess the principle, if you know that this these are important, I guess one would have to understand that everyone has a role to play.
Of course, having said that, you know, a smaller setup when you serve small medium enterprise, sometimes cost of implementing these controls are also expensive. So I guess this is going to be an evolving thing, but a small part done by everyone does help system become stronger.
Elinor Kasapidis:
Yeah, I love that shared responsibility concept. And if we think about the code of ethics, there's, you know, acting in the client's best interests. You want to have the client who clients who are good. But there's also the noncompliance with laws and regulations, requirements, professional skepticism, making sure that you know your client, proof of identity. That onboarding process, I think is really important for public practitioners is of course, banks would do do the same.Vincent Mok:
If you think about what we do in CPA Australia. You know, ethics is really the core and you don't get through without, you know, making sure you pass. But I think it's just beyond, you know, memorizing what is right is really ingrained in that principle of doing the right thing, which is really important.Elinor Kasapidis:
And if you take that approach, then really your system of quality management, the processes that you put in place, the tone from the top. So it really is if you're living the code and you're living those values, it's really documenting what you're probably doing anyway. And that's a critically important thing. I'll also give a plug for we've recently released some resources on financial abuse, being able to detect it and what to do when you see it, and then the AML CTF obligations, which is around knowing your client and reporting suspect transactions.And that can touch so many different things. I think we always think of organized crime or criminal behavior as a problem that's over there. But in fact, I'm sure in the banking sector you see it manifest at a retailer level or, you know, there are people who might be enslaved in an arrangement. And as an accountant, you're seeing a lot of the money coming through the accounts.
So it's part of hardening and being aware of those sorts of manifestations.
Vincent Mok:
Exactly. And of course, taking action is important.Elinor Kasapidis:
Criminals will always find the next step. They're always testing the system. Your sensors are activated, you shut down the risk. And we now have AI using your child's face. But soon people will be able to generate pretty much or already can really good images, documents, fraudulent transactions, even like they can create histories that don't exist. How do you see AI and the latest frontier of technology manifesting in the financial crime space, and what are we going to do about it?Vincent Mok:
You know, the concept of AI is really an interesting one, good and bad at the same time, exciting and scary. So one of the things that I guess the theme today from this perspective is we have to use AI to fight AI. So one of the things is for everyone to think about how you would leverage on that.I guess we are fortunate in that way because as a native digital bank, we don't have large workforces, but we have many of the latest tools. And basically we do invest a lot and pretty heavily in terms of AI and technology and therefore in terms of you could imagine typically the process that we go through, we have actually built fraud and AML models that is AI driven, which we continue to improvise over time with the new data points and therefore the data point made earlier.
Whether is it more, the better or lesser, the better. Likewise, in terms of many of the detection processes, in terms of investigation process, today we do have AI bots that is actually supplementary doing supplementary work in terms of that investigation. So I think people do talk about agentic AI as well. I think we it would mature, would take time to get there.
But at the moment is pretty much AI with human in the loop. And of course it will be used in many fronts and we just have to implement additional safeguards along the way and, and evolve our technology at the same time. It has to be a place where we don't just watch and do nothing, but really is to think about how you would evolve this space as well.
So you could imagine if these syndicates have invested in R&D in AI, I guess. Likewise, we would have to double down on that. So one of the one of the suggestion that I've actually shared with participants was to think about how this space would be in the next three years and set up perspective. I said, what are you going to do in your respective organization to be prepared for that?
The work has to start now because you don't. You wouldn't just change overnight. So so there's a lot of work that needs to be done ground up.
Elinor Kasapidis:
I love the thinking about being proactive and using the technology and training the bots on the behaviors and the prototypes and the profiles of what you're seeing. And finally, I've kept on bringing it back to professional advisors, and we've talked a little bit about the governance piece, but do you have any tips around what are the priorities? So let's say you haven't really been doing AML CTF and you've got a client base.Where do they start on that journey?
Vincent Mok:
I, I think what is important is do not start the journey when you are in the verge of getting a reprimand or a fine, because that's not a good space to be in. I guess the question is really how strong as well in terms of, you know, the respective legislation, but it's one that I think it requires that awareness and self-governance.And of course, if you could imagine if if the cost of a mistake is expensive, then then there is going to be the need to do the right thing. So I would imagine for the accounting profession, for example, the, the, the taxation firms, accounting firms, imagine when they if the punitive action for sanctions or for noncompliance is a heavy penalty, it could potentially both the earnings of of the organizations.
So if you have that mindset, I guess everyone would probably think about it a little bit more differently. I think in the banking world, of course, we are fortunate. Unfortunately, we do have very stringent requirements. And therefore, you know, we constantly have to be on our toes. And we we always, I guess, here in this part of the world is pretty mature.
We go to the extent of collaborating with each other while working with the regulator to set policies that we think is appropriate and so on. So I guess the same principle should apply. It would be helpful across the industry and profession to to think about it that same way.
Elinor Kasapidis:
Well, accountants love a cost benefit analysis and the costs can be very, very high. The fines and the consequences can be high. And as well as a profession, the shared responsibility, we do have a social obligation to clients, to the community. And taking on that responsibility is critical. So we've traversed a lot of areas today. So financial crime, money laundering.And I think it really comes down to the key points for me where the flip side. So AML CTF is the flip side of fraud. You know how those those criminals and we didn't touch on opportunistic ones either. But there is also a group of people who will take an opportunity if they know there's a weakness in the system.
We do see the promulgation of scams through social media, and that's a whole new area as well of monitoring and surveillance to see. And that's a challenge, I'm sure, for regulators too. And as a digital bank, it's great to see how you're using technology to combat technology related crimes. So, Vincent, thank you so much for taking the time to speak with us today.
Vincent Mok:
Thank you. Thank you for having me.Elinor Kasapidis:
And for our Australian public practitioners. Check out our AML CTF web page, which has got a whole range of resources to guide you with your onboarding journey. And we also have an online learning module that you can take for your CPD. If you enjoyed this episode, don't forget to subscribe to With Interest and share this episode with your friends and colleagues in the business community.Until next time, thank you for listening.
Loading component...
About the episode
Financial crime is evolving fast, becoming more sophisticated, cross-border and digitally enabled.
This episode examines how organisations can move beyond reacting to fraud and take a proactive approach to building controls that anticipate how criminals may attack their systems.
The discussion is particularly relevant as Australia extends AML/CTF obligations to professions including accountants, lawyers, and real estate professionals.
Listeners will gain expert insight on:
- Why fraud and AML/CTF should be treated as two sides of the same problem
- How to test products and processes from a fraudster's perspective
- Why continuous surveillance matters after customer onboarding
- How banks, regulators and other industries can share intelligence
- What shared responsibility means for professional advisers
- How AI is being used to detect financial crime and why AI will also increase the threat
- Where firms should start when strengthening AML/CTF controls
Tune in now.
Host: Elinor Kasapidis, chief of policy standards and external affairs, CPA Australia.
Guest: Vincent Mok Yau Yee. He is currently a member of the Malaysian Divisional Council of CPA Australia and the group chief risk officer for GXS Bank based in Singapore.
Learn more about GXS at its website.
CPA Australia also has information on anti-money laundering reforms as well as guidance for practitioners around AML/CTF.
Loving this podcast?
You can listen to more With Interest episodes and other CPA Australia podcasts on YouTube.
CPA Australia publishes four podcasts, providing commentary and thought leadership across business, finance, and accounting:
Search for them in your podcast platform.
You can email the podcast team at [email protected]
Subscribe to With Interest
Follow With Interest on your favourite player and listen to the latest podcast episodes