SlideShare uma empresa Scribd logo
1 de 13
Baixar para ler offline
Copyright 2018 IdentityMind
WEBINAR:
MASTER TODAY'S
REGULATIONS AND BE
PREPARED FOR
TOMORROW’S:
OFAC INCLUDES
BITCOIN
DEC. 12, 2018
Copyright 2018 IdentityMind
Panelist Introductions
David Murray, VP of Products and Services at FIN
Neal Reiter, Director of Product, Virtual Currencies, IdentityMind
Jose Caldera, Chief of Product and Marketing, IdentityMind
Copyright 2018 IdentityMind
Agenda
● Background
● Regulations and cryptocurrencies
● OFAC and cryptocurrencies
● Impact
○ Banks
○ Financial Institutions
○ Auditors + examiners
● Use-Cases
○ Direct Transactions
○ Indirect Transactions
○ Digital Identities
Copyright 2018 IdentityMind
A Recording of This Webinar is Available
Click below for a recording of the full discussion & panelist insights:
Copyright 2018 IdentityMind
OFAC and Sanctioned Addresses
● On November 28, OFAC designated two Iran-based individuals who helped exchange ransom
payments from bitcoin into Iranian rial.
○ Ali Khorashadizadeh and Mohammad Ghorbaniyan used two digital currency addresses to process over 7,000
transactions and interacted with over 40 exchangers—including some U.S.-based exchangers—and to send
approximately 6,000 bitcoin worth millions of U.S. dollars, some of which involved bitcoin derived from SamSam
ransomware.
○ The SamSam scheme has over 200 known victims; it has targeted corporations, hospitals, universities, and government
agencies, demanding ransom in exchange for restored administrator access to networks.
● For the first time, OFAC publicly attributed two digital currency addresses to the designated
individuals.
○ Traditional identifiers associated with OFAC listings have included, e.g., street addresses, email addresses, DOB
○ Treasury: “We are publishing digital currency addresses to identify illicit actors operating in the digital currency space.
Treasury will aggressively pursue Iran and other rogue regimes attempting to exploit digital currencies and weaknesses
in cyber and AML/CFT safeguards to further their nefarious objectives.”
Copyright 2018 IdentityMind
Iran Sanctions Background
● U.S. primary sanctions on Iran are comprehensive, with few exceptions. This means that almost all
dealings by U.S. persons involving Iran are prohibited.
○ These restrictions also cover non-U.S. entities owned or controlled by U.S. persons such as foreign subsidiaries of American
companies.
● Using secondary sanctions, the United States threatens non-U.S. persons with penalties if they engage in
certain Iran-related dealings—even if those dealings do not touch the United States or U.S. persons. Iran-
related dealings targeted by secondary sanctions fall into two general categories:
○ Dealings with certain persons: Most Iranian persons on the SDN List as well as persons on the SDN List for Iran-related
reasons.
○ Dealings in certain activities: Iranian energy (crude oil as well as petroleum products and petrochemicals, rial transactions;
issuance of Iranian sovereign debt; and gold and precious metals.


Copyright 2018 IdentityMind
Challenges for Financial Institutions

● It can be difficult for financial organizations to differentiate between businesses in the cryptocurrency
ecosystem and to understand the specific risks posed by each.
○ Business types in the ecosystem include, among others, exchangers,
ATMs, wallet providers, and payment processors. Not all of these
businesses are MSBs, and not all MSBs have identical risk profiles.
○ It is critical for financial organizations to identify customers who may be
exposed to tumblers, mixers, dynamic exchanges, or cryptocurrencies
designed to shield the identities of users (e.g., Monero, Zcash, Dash).
Copyright 2018 IdentityMind
Challenges for Banks
● Financial institutions banking cryptocurrency exchangers need to follow core customer due diligence (CDD)
measures.
○ However, enhanced due diligence (EDD) measures for correspondent banking
relationships should also be applied to cryptocurrency exchangers because these
exchangers present intermediated risks similar to those associated with
correspondent banking.
● Independent audit of the exchanger’s AML/CFT and sanctions compliance functions will be necessary.
● Banking such exchangers may require a hands-on approach by the financial institution (e.g., seconding
personnel in the exchange to better understand risks and mitigation measures).
● Note that banks may be exposed to virtual currency risks through customers who participate in peer-to-peer
services such as Paxful which match buyers and sellers to facilitate exchange. Those who are selling bitcoin
through Paxful are effectively operating as unlicensed MSBs.


Copyright 2018 IdentityMind
What this Means for Auditors and Examiners
● Are the AML controls reasonably designed to prevent the exchanger from being used to facilitate
money laundering and terrorist financing?
● Is the filtering program reasonably designed for the purpose of interdicting transactions that are
prohibited by OFAC?
● Have the board and senior management taken ownership of the financial crimes compliance program?
● Has the exchanger established a strong culture of compliance?
● Is the financial crimes compliance adequately resourced with a prominent role in the institution?


Copyright 2018 IdentityMind
Use Case #1 – Direct Transactions
● Use Case #1 - Direct Transactions
○ A client receives bitcoin directly from a sanctioned address
○ A client sends bitcoin directly from a sanctioned address
Copyright 2018 IdentityMind
Use-Case #2 – Indirect Transactions
● Use Case #2 - Indirect Transactions
○ A client receives bitcoin from an address who received those bitcoin from
a sanctioned address
○ A client sends bitcoin to a non-sanctioned address who sends them to a
sanctioned address
Copyright 2018 IdentityMind
Use-Case #3 – Digital Identities
● Use Case #3 - Digital Identity
○ A client sends bitcoin to a sanctioned address via their wallet, then tries
to onboard at your exchange
○ A client receives bitcoin from a sanctioned address via their account a
virtual currency exchange, then tries to onboard at your bank
Copyright 2018 IdentityMind
Thank You!
To read more of our award-winning analysis
on virtual currency compliance and more,

Mais conteúdo relacionado

Último

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Último (20)

08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 

Destaque

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Destaque (20)

AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 

Virtual Currency Risk Assessment - OFAC lncludes Bitcoin

  • 1. Copyright 2018 IdentityMind WEBINAR: MASTER TODAY'S REGULATIONS AND BE PREPARED FOR TOMORROW’S: OFAC INCLUDES BITCOIN DEC. 12, 2018
  • 2. Copyright 2018 IdentityMind Panelist Introductions David Murray, VP of Products and Services at FIN Neal Reiter, Director of Product, Virtual Currencies, IdentityMind Jose Caldera, Chief of Product and Marketing, IdentityMind
  • 3. Copyright 2018 IdentityMind Agenda ● Background ● Regulations and cryptocurrencies ● OFAC and cryptocurrencies ● Impact ○ Banks ○ Financial Institutions ○ Auditors + examiners ● Use-Cases ○ Direct Transactions ○ Indirect Transactions ○ Digital Identities
  • 4. Copyright 2018 IdentityMind A Recording of This Webinar is Available Click below for a recording of the full discussion & panelist insights:
  • 5. Copyright 2018 IdentityMind OFAC and Sanctioned Addresses ● On November 28, OFAC designated two Iran-based individuals who helped exchange ransom payments from bitcoin into Iranian rial. ○ Ali Khorashadizadeh and Mohammad Ghorbaniyan used two digital currency addresses to process over 7,000 transactions and interacted with over 40 exchangers—including some U.S.-based exchangers—and to send approximately 6,000 bitcoin worth millions of U.S. dollars, some of which involved bitcoin derived from SamSam ransomware. ○ The SamSam scheme has over 200 known victims; it has targeted corporations, hospitals, universities, and government agencies, demanding ransom in exchange for restored administrator access to networks. ● For the first time, OFAC publicly attributed two digital currency addresses to the designated individuals. ○ Traditional identifiers associated with OFAC listings have included, e.g., street addresses, email addresses, DOB ○ Treasury: “We are publishing digital currency addresses to identify illicit actors operating in the digital currency space. Treasury will aggressively pursue Iran and other rogue regimes attempting to exploit digital currencies and weaknesses in cyber and AML/CFT safeguards to further their nefarious objectives.”
  • 6. Copyright 2018 IdentityMind Iran Sanctions Background ● U.S. primary sanctions on Iran are comprehensive, with few exceptions. This means that almost all dealings by U.S. persons involving Iran are prohibited. ○ These restrictions also cover non-U.S. entities owned or controlled by U.S. persons such as foreign subsidiaries of American companies. ● Using secondary sanctions, the United States threatens non-U.S. persons with penalties if they engage in certain Iran-related dealings—even if those dealings do not touch the United States or U.S. persons. Iran- related dealings targeted by secondary sanctions fall into two general categories: ○ Dealings with certain persons: Most Iranian persons on the SDN List as well as persons on the SDN List for Iran-related reasons. ○ Dealings in certain activities: Iranian energy (crude oil as well as petroleum products and petrochemicals, rial transactions; issuance of Iranian sovereign debt; and gold and precious metals. 

  • 7. Copyright 2018 IdentityMind Challenges for Financial Institutions
 ● It can be difficult for financial organizations to differentiate between businesses in the cryptocurrency ecosystem and to understand the specific risks posed by each. ○ Business types in the ecosystem include, among others, exchangers, ATMs, wallet providers, and payment processors. Not all of these businesses are MSBs, and not all MSBs have identical risk profiles. ○ It is critical for financial organizations to identify customers who may be exposed to tumblers, mixers, dynamic exchanges, or cryptocurrencies designed to shield the identities of users (e.g., Monero, Zcash, Dash).
  • 8. Copyright 2018 IdentityMind Challenges for Banks ● Financial institutions banking cryptocurrency exchangers need to follow core customer due diligence (CDD) measures. ○ However, enhanced due diligence (EDD) measures for correspondent banking relationships should also be applied to cryptocurrency exchangers because these exchangers present intermediated risks similar to those associated with correspondent banking. ● Independent audit of the exchanger’s AML/CFT and sanctions compliance functions will be necessary. ● Banking such exchangers may require a hands-on approach by the financial institution (e.g., seconding personnel in the exchange to better understand risks and mitigation measures). ● Note that banks may be exposed to virtual currency risks through customers who participate in peer-to-peer services such as Paxful which match buyers and sellers to facilitate exchange. Those who are selling bitcoin through Paxful are effectively operating as unlicensed MSBs. 

  • 9. Copyright 2018 IdentityMind What this Means for Auditors and Examiners ● Are the AML controls reasonably designed to prevent the exchanger from being used to facilitate money laundering and terrorist financing? ● Is the filtering program reasonably designed for the purpose of interdicting transactions that are prohibited by OFAC? ● Have the board and senior management taken ownership of the financial crimes compliance program? ● Has the exchanger established a strong culture of compliance? ● Is the financial crimes compliance adequately resourced with a prominent role in the institution? 

  • 10. Copyright 2018 IdentityMind Use Case #1 – Direct Transactions ● Use Case #1 - Direct Transactions ○ A client receives bitcoin directly from a sanctioned address ○ A client sends bitcoin directly from a sanctioned address
  • 11. Copyright 2018 IdentityMind Use-Case #2 – Indirect Transactions ● Use Case #2 - Indirect Transactions ○ A client receives bitcoin from an address who received those bitcoin from a sanctioned address ○ A client sends bitcoin to a non-sanctioned address who sends them to a sanctioned address
  • 12. Copyright 2018 IdentityMind Use-Case #3 – Digital Identities ● Use Case #3 - Digital Identity ○ A client sends bitcoin to a sanctioned address via their wallet, then tries to onboard at your exchange ○ A client receives bitcoin from a sanctioned address via their account a virtual currency exchange, then tries to onboard at your bank
  • 13. Copyright 2018 IdentityMind Thank You! To read more of our award-winning analysis on virtual currency compliance and more,