MANAMA, 27 June 2006 — From around the Middle East, executives traveled to Manama two weeks ago to participate in the “Bahrain Institute of Banking and Financing (BIBF) Advanced Training Course on Fraud, Money Laundering and Anti-Terrorist Financing.” Each day of the five-day course had a specific focus: “The Principles of Prevention,” “The Electronic Threat,” “Money Laundering and Terrorist Financing,” “Crisis Management and Action Plans” and “The Internal Threat.” The 45 participants from organizations such as Samba, the Syrian Central Bank, the Qatar Islamic Bank and the Palestinian Monetary Authority learned that evolving, targeted, incessant efforts are required to defeat the criminals engaged in fraud, money laundering and terrorism financing. Countering these criminals is in many ways about the proper management of information security. And as always, when it comes to issues involving information security, success can only be achieved with a three pronged approach involving people, processes and technologies.
Speaking for the course organizers, Mark Nunan, director of International Financial Compliance and Training, said: “I am impressed with the level of knowledge I’ve seen from the regional participants in our course. Since many of our speakers were here three years ago, sophistication concerning the issues has developed. We see the Middle East as the future hub of the financial world as it is directly between China, India and the developing markets of the Far East and the Western world. In that regard, it is essential that financial institutions in the Middle East have the latest information in regards to fraud, money laundering and terrorist financing as there will be great dependence on them to contain and counter these threats.”
Banks that take steps to defend against money laundering find that this is the basis for defending against other types of fraud and other breaches of security. However, according to Martin Smith, MD, The Security Company (www.thesecurityco.com), senior management often perceives that defending against fraud is a cost center.
“Management often thinks that fraud prevention generally is boring, dull and is done by geeks who operate the technical systems. They think it’s not really part of the business,” Smith said. “The truth is that in this day and age we have completely dismantled the barriers around the finance business. We have created an extended enterprise where we are dealing electronically with complete strangers all over the world. So the need for the bank to put up secure processes and procedures is growing all the time. If appropriate defenses aren’t in place, the eventual damage to a bank’s reputation is certain to be severe.”
Smith asserted that rather than costing banks money, effective fraud protection actually saves banks money.
“If they don’t lose money, reputation, credibility or customers, then financial institutions have gained and have a chance to grow,” he remarked. “All the technology, processes and people which are focused on anti-money laundering, anti-terrorism and fraud prevention are actually business enablers. For example, why do cars have brakes? To stop them? No! Cars have brakes so they can go faster. It is impossible to drive a car at all without brakes and the best, biggest brakes are on Formula 1 cars. Cars with brakes can go much faster and much farther than cars without brakes. Financial institutions with effective information security and fraud prevention can grow much faster than organizations that don’t have these systems in place.”
But it is important that financial institutions understand that information security and fraud prevention involve effective use of people, process and technology. There are no computers that commit financial crimes and no processes that commit financial crimes. People are responsible for committing financial crimes and only people can ultimately stop such crimes. Technology can make it easier and quicker to spot financial crimes, but all the technology in the world is worthless if people don’t understand the dangers and put in basic procedures to harness the technology. In fact, anti-fraud and anti-money laundering technology not updated and backed up by people and processes can create a worse scenario because people are lulled into a false sense of security.
“For instance,” said Smith, “you go out and buy a smoke alarm for your house, but you install it wrong. Then you don’t change the battery regularly and no one knows what the alarm would sound like on the slim chance that it did go off. What do you think will happen if there is a fire? Unfortunately, you will have a false sense of security because you bought the smoke alarm in the first place! People and processes must be combined with technology to prevent and intercept criminals committing financial abuses at all organizations.”
Importantly, the more people in an organization who understand the information security risks and are aware of the means to defend against them, the more secure the organization will be.
“Ask any bank how many people are in their security department. Too often, they haven’t a clue,” commented Smith. “Actually every employee of a financial institution should be counted as a member of the security department. Every employee of a bank should be an information security guard and an anti-money laundering reporting officer and a data protection officer — no matter what other tasks they perform at the bank. All bank employees should be educated on information security, anti-money laundering and anti-fraud issues. This is the only way to truly improve security within a financial institution.”
Effective fraud prevention has become a constant talking point for the CEO of local information security firm, IT Matrix (www.itmatrix.com), Mirza Asrar Baig, whose presentation during the training course focused on real examples of financial fraud that have and are taking place both regionally and in other geographies.
“I tried to stress on the thought that we have an advantage in this region in being behind the world in certain areas because we can learn from the mistakes of others,” Baig said. “Whereas some major Western financial institutions have had to face these frauds first hand, we can learn from their experiences. We can see what type of mitigation strategies have been used, what worked and can implement these strategies immediately before such frauds hit us severely. A bank often believes that if a fraud isn’t happening to them, then it won’t happen. Nothing could be further from the truth. If financial criminals are blocked at one financial institution, they will try to perpetrate the same crime elsewhere. It’s human nature.”
One way to thwart criminals Baig taught the managers in the course, is to start thinking like those criminals and then implement effective means to prevent the proposed financial crimes. Additionally, in the past, it has been the IT people who have been looking at the means to prevent financial crimes. The top managers in the financial institutions weren’t involved in these efforts. This needs to change.
“In other countries there is legislation that makes the CEO, CFO, CIO and other top managers responsible for anti-money laundering and fraud prevention within all companies,” Baig said. “With such legislation in place, anti-money laundering and fraud prevention are no longer just technical issues. This is how more people and processes have been added to technology to create effective information security. Information Security Management systems are the responsibility of the senior management at all companies. While corporate IT staff play an vital role in information security, all business lines, within every company, have important roles to play too.”
He added, “In Saudi Arabia right now we are working to build awareness that there can be no effective information security until this issue is embraced by the most senior corporate management and its importance is communicated to all the staff of those companies. We should not need legislation to make information security a priority, but I believe more laws will come into effect in the Kingdom on this issue if the private sector does not quickly make the appropriate moves.”
(Comments to: [email protected])

