RSS Amplifier

Dirty Money Weekly's Substack · Aug 17, 2026

Knowledge = Burden

0
Sign in to vote or save

SB Felix · Dirty Money Weekly's Substack

Three stories this week, two threads running through all of them: 1) if you have knowledge, you have burden; and 2) the government keeps shrinking the net while expecting financial institutions to catch more fish.

FINRA cashed $2.295M in checks over 90 days - almost all of it for missed suspicious activity. Treasury gutted the CTA and told us, without support, that it won’t hurt law enforcement. And a scale manufacturer in Wisconsin got hit by OFAC because employees read emails from Iran and didn’t know that reading them created a burden.

If you only have five minutes, scroll to the bottom. If you have fifteen, there’s a to-do list under each one.

$2.295M in monetary penalties in the last 90 days:

Pictet Overseas $610k; Blue Ocean $550k; Prime Number $335k; RBC Capital Markets $275k; Trading Block $220k; Outset Global Trading Ltd $130k; Herold & Lantern $125k; Moody Capital Solutions $50k.

Missed suspicious activity showed up in all but one of these orders. The whole reason we do any of the things we do is to get information into the hands of LE in a timely manner. Full stop. FINRA is making sure their firms know they are serious about that mission. 🙌

Low-priced securities are the theme running through these failures. FINRA has clearly spelled out what is expected. At what point does it become willful blindness? Asking for a friend.

1️⃣ Service institutional clients? Conduct periodic reviews of FFI account activity. If you don’t have staff for that, you must staff for it. There is no third option.

2️⃣ Audit your “we don’t do that” list. Does your firm have procedures that say “…does not have, nor does it intend to open accounts for…”? When did you last verify it? I don’t mean read it and account for it in your head. I mean comb through your customer types, transaction types, and everything else to ENSURE that list is actually true.

3️⃣ Stop treating policy inaccuracies as paperwork problems. A written misstatement is never just a written misstatement. It always results in some type of control failure, and it typically leads to the biggest failure of all - failure to monitor for suspicious activity.

4️⃣ Restart your independent tests. Moody has been a FINRA member since 1985, and from 2020 to current they just… stopped. Make sure the audits are tailored to the threats of the firm. And remember: a clean audit is not a good audit.

5️⃣ Read the Regulatory Notices (RNs). Today. RN 02-21, 19-18, 21-03, 22-25. If your firm isn’t hyper-familiar with these, today is your day.

6️⃣ Measure the increase in shares traded - and tie it directly into your threat assessment, which should then influence your monitoring approach and your staffing. Not doing that? Today is also your day.

7️⃣ Write your threats down. A list of threats for your type of institution and the types of products you offer belongs in your P&Ps, with monitoring efforts tied to each threat identified.

8️⃣ Pressure-test the monitoring system. Is it tailored to your threats? Does it incorporate all the red flags listed in the RNs? Are alerts being dispositioned with copy/paste? Are canceled trades part of your monitoring? If the answer is no to one or all of these… yikes.

9️⃣ CDD is still required. What activity warrants an update to due diligence? Initial? Ongoing? Have an answer.

🔟 Choose effectiveness reviews over model validations. Most of these AWCs covered 2020 to present. The RBC one covered 2016–2023. YIKES. I’d take effectiveness reviews all day, every day - but your firm must define and outline what effectiveness actually looks like. Reach out for a starter list of effectiveness indicators.

Some first thoughts as I read through the final rule.

Shell companies appear in every FinCEN advisory and alert. Every one. So what are FIs supposed to do with that level of inconsistency in government policy? Asking for a friend.

Pages 23–24 echo that same tension, and Treasury makes this statement without a single thing supporting it:

“Treasury assesses that the targeted, risk-based approach to BOI collection set out in the IFR and in this final rule would not—despite commenters’ concerns—undermine law enforcement and national security, as it ensures the collection of BOI that is highly useful to law enforcement while minimizing burden on the business community to the greatest extent possible.”

⁉️ What? So only foreign companies present national security risks?

Why would anyone register as a foreign company when you can start a US one - and avoid disclosing UBOs entirely - for a mere $125? Is anyone going to measure the upward trend in our onshore-offshore states: WY, NV, SD, DE? When a foreign person can get a US registered agent plus a physical person in that state to serve as their “natural person,” why would they ever register as foreign? Secrecy and taxes are both better on the US side. And will anyone regulate the gatekeepers - the registered agent companies selling “US company applicants” for a few bucks?

The rule also assumes, incorrectly, that professional money launderers would not be US persons. Why exempt US persons from being reported on the BOI of foreign businesses and foreign pooled investment vehicles? We have golden passport programs, EB-5 visas, and an influx of illegal immigrants receiving US benefits - meaning they hold some form of ID that could construe US citizenship.

The CTA had its issues. For sure. But it was better than nothing.

❌ And then this: the determination that collecting this BOI “would not serve the public interest” and “would not be highly useful in national security, intelligence, and law enforcement agency efforts.” Which flies directly in the face of every advisory that names shell companies as the problem. 😔

The net effect: it adds to the burden of FIs - traditional and non-bank alike - to pick through the haystack of indicators and find the shell companies themselves.

1️⃣ Put BOI data in your SARs - especially in the backup documentation section. LE is going to need every scrap of data FIs have just to offset being blind to state-level UBO data.

2️⃣ Start looking for indicators of shell companies yourself. Don’t know where to start? I have a starter list. DM me.

Small penalty, big lessons. Rice Lake Weighing Systems - $60,764.

Ah, the global reach of OFAC. Love it and get frustrated by it at the same time. It is genuinely difficult to ensure OFAC compliance for products and services sitting multiple layers down from US businesses or persons.

But in this case, employees had knowledge. They should have had burden, and they didn’t know any better - which makes this an operational training issue, not a screening technology issue.

If you only take one thing from this entire section, take #2.

1️⃣ Print this sentence and hand it to every employee: “If you have knowledge, you have burden.” While you’re at the printer, run off a list of the countries and regions subject to comprehensive and/or partial sanctions under OFAC.

2️⃣ Screen your employees’ email - addresses and bodies - for mentions of OFAC’d countries. The emails here contained references to Iran and came from an Iranian domain. Are large global businesses really not doing this? We talk about screening country-level email domains for clients in the FI/MSB world. But your own internal communications? New one. Interesting take.

3️⃣ Be timely, take ownership, take immediate corrective action. That is how you reduce liability. It visibly reduced their penalty dollars here.

4️⃣ Buying foreign subsidiaries? Get in the weeds. Other countries do not have the severe restrictions OFAC imposes on US businesses and persons. Your new subsidiary does not know what it doesn’t know.

5️⃣ Stop treating sanctions as a name-matching exercise. I know, I say this A LOT. It needs repeating. Sanctions restrictions are nuanced. If your company - no matter the industry - is simply screening names and nothing else, you are MISSING IT. It is only a matter of time before your company, or you, ends up on the OFAC Around and Find Out penalty page.

6️⃣ Operationalize the 2019 OFAC Framework document. If your firm hasn’t, get to it. They lay it all out, and in every single penalty they point you right back to it. It is your roadmap to stay off their radar.

7️⃣ Go look for Iran indicators in your data. They hide in plain sight, in so many places.

Knowing something and not building a control around it. This goes not just for OFAC issues, but also for the death of the CTA. Now that we know the CTA has been gutted, how will that change how you, AML Officer at an FI, view your newly incorporated business customers and members? Will it have no impact? Think again. Be on guard for shell and front companies.

If you have knowledge, you have burden.

© 2026 Palmera Consulting

No posts

Read the original on dirtymoneyweekly.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.