This is just a continuation of the previous post, which I wrote to give more context about why banks are so annoying with their demands for information. Everyone knows the famous process that banks have in terms of identifying their clients so that they know who they are dealing with. It may seem simple, but as banking in the digital world has become easier, it has also become easier to hide. So, this is about why banks need to identify their not only their clients but other parties as well.
When establishing relationships with clients, suppliers, and others, banks take very good care to identify and understand who those people or companies are. This process is very simple when it comes to individuals. Bankers get identification information (i.e. name, date of birth, residence, picture of their face, etc.) and then cross-check that with names and information on the lists that are published or banks manage themselves. Sometimes, if you’re unlucky, they request more information, because your information may partially match someone on a list somewhere. E.g. the name Muhammad (in its various forms) is mentioned over 500 times only on the UN list. So you may have a similar name and/or surname of someone on a list, therefore the bank must make sure that you are not even closely related to that person. The process becomes much more complicated when banks deal with legal entities (e.g. companies, NGOs, trusts, etc.). Banks must make sure that the actual ‘people’ that own or run those legal entities are not related to any people or entities on lists either. In today’s world, it’s very easy to create a web of companies incorporated in various jurisdictions1Countries actually compete with each other on how easy it is to create a business, and the World Bank used to keep track of it on a list, and then open a bank account. You can have tens of layers between the actual person that owns and/or controls the legal entity and the actual legal entity opening a bank account. In those cases, banks need to verify who is the Ultimate Beneficial Owner and who are the Senior Managing Officials of those legal entities. How do they do that? They ask those clients/potential clients for information.
Laws all over the world not only require banks to get this information when creating the relationship, but also obligate them to update this information in regular intervals (i.e. for low-risk clients every 5 years, for high risk clients every year (or more frequently)). If you read the terms and conditions of your bank, you will see that the obligation is on you to let the bank know about any changes in your circumstances (i.e. change of address, change of contact information, change of ID documents, etc.), however, lawmakers know that they cannot rely on people to be diligent, so they require banks to force their clients to provide this information periodically.
Knowing that information is the first step2other steps involve analysing transactions and client activities, a topic for another post in ensuring that no one is laundering money or financing terrorism through the bank. That’s why banks will ask for all kinds of information (information, copies of passports, birth certificates) to verify whether the involved individuals (owners, senior management, trust directors, etc.) are not in any list. The situation is the same with bank suppliers as well. If a bank plans to purchase a product or service from someone, they have to check whether the supplier is a criminal (or part of a criminal organisation) as well. Similarly, in cases where a bank wants to donate money to someone, or sponsor someone, the same checks need to be made. All of those are ways to launder money or finance terrorism. So, if you’re an aspiring money launderer, take notes.

Naturally, this is not only about Sanctions. Each bank has their own risk and tolerance levels that they decide when it comes to establishing a line that they will not cross when it comes to establishing relationships with their clients or suppliers. So, in addition to trying not to be involved in any crime, banks also have reputations that they need to protect. In addition to various sanctions lists that banks process, banks also have their own lists that they constantly update. Those lists may include criminals or suspected criminals. In addition to filtering lists, many banks have established practices where they have specific queries for search engines (e.g. Google), and they will analyse the first few pages of the results. Some banks may even decide to not open accounts for certain activities. I.e. a bank may decide not onboard companies that are involved in currency exchange, or crypto exchange. Whether it’s actual financial security risk, or reputational risk, each bank decides for themselves. If a person is in prison for tax evasion, does that mean that banks must refuse to open a bank account for that person? What if a person has been convicted for corruption? What if then that person is acquitted by the court of appeals? Situations are never simple.
To further illustrate the possible complexity of situations, consider the current geopolitical situation. We have country leaders who are increasingly more brash, and do not care about diplomacy. They can use these frameworks that were set up to stop complex criminal organisations on a whim, just to further their personal agenda. This is especially true if those leaders are old and/or have an orange tan3For example this situation. Now, imagine a person minding their own business, becomes designated and ends up on a list. What if that person owns 5% of shares in a company that is the client of a bank? Does that mean that that bank must immediately cut ties with that client? What if a designated person owns 30% of shares in that company? What if that company has a 2m EUR loan? You can’t expect a company to have that kind of cash sitting in their accounts so that they can immediately close the loan. If they did, they probably wouldn’t need the loan. Then this whole situation becomes a big deal in bank, and you need those ‘compliance’ people to follow it closely until it is resolved.

All of these processes have been established in the past couple of decades. Criminals continuously get more creative, and legislators have to follow. Unfortunately, the burden is usually placed on banks, since they are more flexible operationally, and also because they have more money to create processes and employ people to process the necessary information to try and identify people. However it’s not always simple, and that’s why banks and their processes are sometimes annoying. Could the process be improved? Probably, but we also need to balance the right to privacy and data protection4Which is a topic for another day. I just hope with the rise of AI, and how easy it has become to falsify identities, banks don’t have to resort to requiring fingerprints from their clients.
Leave a Reply