FINMA finds deficiencies in anti-money laundering processes at Credit Suisse
The Swiss Financial Market Supervisory Authority FINMA has concluded two enforcement procedures against Credit Suisse AG.
In the first procedure, FINMA identified deficiencies in the bank’s adherence to anti-money laundering due diligence obligations in relation to suspected corruption involving the International Federation of Association Football FIFA, the Brazilian oil corporation Petrobras and the Venezuelan oil corporation Petróleos de Venezuela (PDVSA).
The second procedure relates to a significant business relationship for the bank with a politically exposed person (PEP). In this instance too, FINMA identified deficiencies in the anti-money laundering process, as well as shortcomings in the bank's control mechanisms and risk management.
FINMA has decreed measures to further improve anti-money laundering processes and to accelerate the implementation of steps already initiated by the bank. It will commission an independent third party to monitor the implementation and effectiveness of these measures.
FINMA has conducted investigations at several banks since 2015 in relation to suspected corruption involving FIFA, Petrobras and PDVSA. The objective of these inquiries was to establish whether clients of Swiss banks were involved and whether the banks had complied with regulatory provisions, particularly as regards combating money laundering. FINMA commissioned an investigation to establish the relevant facts at Credit Suisse AG. The investigation covered the period from 2006 to 2016. FINMA launched one integrated enforcement procedure in February 2017 due to the commonalities among the three cases. In September 2018, FINMA concluded this integrated enforcement procedure as well as another procedure involving a PEP business relationship.
FINMA determined through its enforcement procedure that Credit Suisse AG had infringed its anti-money laundering supervisory obligations. The established shortcomings are as follows:
• Identifying the client
• Determining the beneficial owner
• Categorising a business relationship as posing an increased risk
• Performing the necessary clarifications upon increased risk plus associated plausibility checks.
The identified shortcomings occurred repeatedly over a number of years, mainly before 2014. An above-average number of faults were discovered in business relationships opened by the former Group subsidiary Clariden Leu AG. The reviews of the bank’s conduct in the FIFA, Petrobras and PDVSA affairs were conducted independently of each other but show similar results.
To combat money laundering effectively, every relevant department within the bank must be able to see all the client’s relationships with the bank instantly and automatically. Credit Suisse AG has been in the process of implementing such a "single client view" since 2015. Progress has been made, however this overview is still to be extended outside the Compliance unit. This results in organisational weaknesses in addition to the contraventions of anti-money laundering provisions.
The second procedure relates to the management of a significant business relationship for the bank with a politically exposed person (PEP). FINMA initiated enforcement proceedings in 2016 and appointed an investigator to establish the facts. FINMA again identified shortcomings in compliance with anti-money laundering due diligence obligations.
The bank was too slow to identify and treat the PEP client as posing increased risks. Moreover, the due diligence and corresponding documentation relating to the business relationship were incomplete. The bank failed to meet its heightened due diligence obligations regarding investigation, plausibility checks and documentation regarding the client and certain related high-risk transactions.
The PEP business relationship case also reveals weaknesses in the bank’s organisation and risk management. FINMA established that the bank had failed to adequately record, contain and monitor the risks arising over a number of years from the PEP business relationship and the responsible (and since criminally convicted) client relationship manager.
The relationship manager in question – who was very successful in terms of assets under management – breached the bank's compliance regulations repeatedly and on record over a number of years. However, instead of disciplining the client manager promptly and proportionately, the bank rewarded him with high payments and positive employee assessments. The supervision of the relationship manager was inadequate due to this special status.
FINMA accordingly identified both organisational deficiencies (in terms of allocation of responsibilities, supervision and control) and a lack of effective corrective intervention. Given the significance of the PEP business relationship and the associated risks, the bank’s risk management was not appropriate in this instance.
The bank has addressed the situation in-house and adopted several measures since the end of 2015 to strengthen its compliance in general and, in particular, to combat money laundering. It also cooperated with FINMA during the procedure. FINMA acknowledges the improvements, some substantial. However, it has also decreed additional measures to complement the bank’s actions and restore full compliance with the law. These measures are designed to further improve the bank’s governance, organisation and risk management in the wealth management business.
Credit Suisse AG must remediate the relevant control systems and processes, and so prove that higher-risk business relationships and transactions are adequately detected, categorised, monitored and documented.
In addition, the bank must have implemented the "single client view" for all relationships and for all relevant functions by the end of 2019.