HSBC
What happens when a risk rating removes two-thirds of payment volume from automated monitoring?
The OCC found that HSBC Bank USA excluded wire transfers from 'standard' and 'medium' risk countries from automated BSA/AML monitoring, representing two-thirds of dollar volume for its payments business. The DOJ resolution included $1.256 billion of forfeiture and $665 million of civil penalties.
Documented impact
Authoritative findings
The documented event
On 11 December 2012, HSBC Holdings plc and HSBC Bank USA entered a five-year deferred prosecution agreement with the US Department of Justice. HSBC agreed to forfeit $1.256 billion and pay $665 million in civil penalties. The DOJ stated that, from at least 2006 to 2009, HSBC Bank USA rated Mexico as 'standard' risk, its lowest AML risk category, and failed to monitor more than $670 billion in wire transfers and more than $9.4 billion in purchases of physical US dollars from HSBC Mexico. The OCC separately found that the bank excluded wire transfers from countries rated 'standard' or 'medium' from automated BSA/AML monitoring, representing two-thirds of dollar volume for its payments business, and that a subsequent lookback and alert backlog led to 890 late-filed suspicious activity reports addressing $6.34 billion of activity.
Hypothetical institutional scenario
How might the same control pattern appear?
A group payments business uses country and affiliate risk ratings to decide which transactions enter automated monitoring. The ratings were approved years ago, and 'standard' or 'medium' categories remove most payment value from the monitoring population. Alternative manual controls exist on paper but have not been tested for coverage or effectiveness. Alert backlogs and late reports are treated as operational capacity issues rather than evidence that the risk model and monitoring perimeter are mis-specified.
Stress-test questions
Questions for challenge and assurance
-
Risk committee
What percentage of payment value is excluded from automated monitoring by country, customer, product or affiliate risk rating?
-
Audit
Can each material monitoring exclusion be traced to a current risk decision, tested alternative control and accountable approver?
-
Operations
At what backlog age or late-report volume does a capacity problem become a formal challenge to the risk model and monitoring design?
-
Board
Who independently reassesses long-standing low- or medium-risk ratings when transaction value, geography or external intelligence changes?
NFRisk practitioner interpretation
Control implication
A risk rating is a control decision, not a descriptive label. Its effect on monitoring coverage, due diligence and escalation should be visible in management information and periodically challenged against transaction value, external intelligence and observed exceptions. Coverage metrics should show what is excluded as clearly as what is screened. Backlogs, late reports and repeated overrides are not only workflow measures; they are evidence about whether the control architecture remains fit for the risk.
Framework relevance
Explicitly labelled analytical mappings
OCC BSA/AML control lens: coverage, due diligence and independent testing
The OCC order identifies deficiencies in internal controls, customer due diligence, suspicious-activity monitoring, alert disposition and independent testing. These are direct regulatory findings about the bank's programme.
OCC BSA/AML control findings · Office of the Comptroller of the CurrencyBasel event-type lens: Clients, Products & Business Practices
NFRisk maps the AML and correspondent-banking control failures to the Basel event type covering clients, products and business practices. This is an analytical mapping, not a DOJ or OCC classification.
Sound Practices for the Management and Supervision of Operational Risk · Basel Committee on Banking SupervisionEvidence register
Primary and supporting sources
-
US Department of Justice
HSBC Holdings Plc. and HSBC Bank USA N.A. Admit to Anti-Money Laundering and Sanctions Violations (opens in a new tab) 11 December 2012 · Authoritative primary source -
Office of the Comptroller of the Currency
In the Matter of HSBC Bank USA, N.A. - Civil Money Penalty 2012-262 (opens in a new tab) 11 December 2012 · Authoritative primary source -
Basel Committee on Banking Supervision
Sound Practices for the Management and Supervision of Operational Risk (opens in a new tab) 1 February 2003 · Authoritative primary source
Publication note
A documented external event—not an NFRisk client engagement.
The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.
Return to the Risk Scenario LibraryFrom scenario to mandate
Test the equivalent control assumption in your environment.
NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.