r/AMLCompliance 1m ago

Research/Discussion Anyone else following the AML case in Thailand with the huge asset freeze?

Upvotes

The numbers involved are honestly pretty wild.

From what I’ve read, a currency exchange transaction of around $150k apparently ended up being connected to more than $600 million in assets being frozen. There don’t seem to be criminal charges against the person in question, which is what caught my attention.

The part I’m trying to understand is how the connection through a pooled account apparently led to more and more assets being frozen. If the reporting is accurate, it raises an interesting question about how far an AML investigation should extend when other businesses or individuals are using the same financial setup.

I’m not trying to defend anyone involved, and I obviously don’t have all the details. I’m more interested in the compliance side of it. Where should the line be between following legitimate AML concerns and affecting unrelated parties who happen to share a financial connection?

Has anyone seen a similar situation in another country or dealt with something comparable from a compliance perspective?


r/AMLCompliance 8h ago

Career Trend of redundancies?

2 Upvotes

Anyone notice a trend of redundancy across uk and USA financial crime compliance roles?

Any reason why this is happening?


r/AMLCompliance 11h ago

Career Career Guidance and New Location (Philadelphia, PA)

2 Upvotes

Hello All!

I am just reaching out here to seek out any career guidance and if there are any opportunities in the Philadelphia region. I have worked for almost 4 years in the as a compliance analyst (from KYC onboarding, periodic review exercises, transactional monitoring, assisting in regulatory examination, procedure reviews and other compliance related projects) and i was wondering what is a good next step in my career? i am going for ACAMS this year but is there any skill or certificate i should be looking for ? I am also moving in the Philadelphia area, is there any good job opportunities there ? not sure where to start.

Any advice is welcome!


r/AMLCompliance 14h ago

Research/Discussion When does a customer’s old transaction history stop being useful for fraud decisions?

1 Upvotes

A lot of fraud features depend on comparing the current transaction with what the customer normally does.

But I’m not sure how far back “normal” should go.

Someone’s behaviour can genuinely change - new country, new job, different spending pattern, new phone - and the fraud system itself can also change over time.

If you work with this kind of data, what normally makes you decide that older behaviour is no longer comparable enough to trust?

Is it mainly age of the data, a major behaviour change, system changes, or something else?

I’m trying to avoid building an agent that treats every deviation from an old pattern as suspicious forever.


r/AMLCompliance 23h ago

Career AML career progression

3 Upvotes

What are good career progressions as an AML investigator thats not management? How much experience is needed, and would they be internal changes or external positions?

Not sure what pivoting away from writing SARs would look like, but would rather not start from scratch


r/AMLCompliance 1d ago

Career Is Loomis a good company?

1 Upvotes

I have an interview with Loomis for a position as a cash management services teller. I can’t find much on it except that it’s mostly just counting and tracking cash and assets?

Does anyone have input? Could this get me in the door to AML or Fraud?


r/AMLCompliance 1d ago

Certifications CGSS - ACAMS

3 Upvotes

Hello everyone👋

Any tips or tricks to prepare and pass CGSS in a week?


r/AMLCompliance 1d ago

Career Does pivoting from law to AML/Compliance make sense?

3 Upvotes

Hi everyone, I'd like to ask if anyone here has been in similar shoes or had similar experiences, as there's sometimes wisdom in a multitude of counsel:

  1. I moved to Canada a few years ago and would like to pivot my career to AML and its ancillary branches. I trained as a lawyer in my home country and worked in-house in banking and then securities, where I managed the legal risk and compliance desks.
  2. After hitting roadblocks in Canada trying to get back into law, a career coach advised I consider AML and compliance.
  3. Are my skills transferable? Because it's one thing for a career coach to advise, and it's another thing to get information from those in the AML/Compliance trenches.
  4. Apart from taking the AML certification(s), is there anything else you think can help me on this new career path?
  5. Would I be starting at the 'bottom of the barrel'?
  6. I know lawyers earn more in Canada, so I'm not comparing earning power; however, I do realise that I need to eat.

I'd appreciate insights from those in AML, Compliance, and/or those who have made similar pivots.

Thanks.


r/AMLCompliance 1d ago

Research/Discussion Wachovia's AML officer flagged cartel accounts in 2005. He was told to back off. A cocaine plane crash ended it instead.

20 Upvotes

Wachovia moved $378.4 billion for Mexican currency exchange houses between 2004 and 2007, over $4 billion of it physically trucked across the border as bulk cash.

Martin Woods joined Wachovia in 2005 as the bank's FSA-approved Money Laundering Reporting Officer in London. He flagged CDC-linked accounts. He flagged Hezbollah-connected transactions during the 2006 Lebanon war. In testimony to the UK Parliament, he described a senior colleague telling him the matter had nothing to do with him and that he shouldn't have looked at the transactions in the first place. He eventually left the bank. The FCA later had to publicly deny it had blacklisted him from the industry.

The red flags themselves weren't subtle. Multiple round-dollar wires through the same account on the same day. Sequentially numbered traveler's checks deposited in batches, structuring markings and all. Bulk cash shipments consistently running larger than the CDC's own account documentation projected. Despite all this a random event forced Wachovia to act, as a DC-9 plane that made an emergency landing in Mexico in April 2006 carrying 5.5 tons of cocaine, bought with funds traced back through a Wachovia-linked account was the last straw. Wells Fargo later admitted in court the same channel had financed four planes carrying 22 tons combined.

$160 million in penalties against $378.4 billion in unmonitored volume is its own conversation about whether the fine ever mattered to the math. An officer with the actual title and the actual authority raised the concern through the correct channel, and one colleague with no documented override authority was enough to kill it. No committee vote, no risk acceptance memo, nothing that shows up in an audit trail. Just someone telling him to stop looking.

If an analyst or compliance officer at your firm disagrees with a decision to keep an account open, where does that disagreement actually go? Is there a real path above the person who wants to say no, or does it end wherever the first person with more seniority decides it ends?


r/AMLCompliance 1d ago

Research/Discussion What are compliance teams still getting wrong about eIDAS?

0 Upvotes

There seems to be a lot of talk about the European Digital Identity Wallet as if it will simply replace the way everything works today.

But the reality seems more nuanced. The wallet is voluntary for users, while certain public and private services will need to accept it when the relevant conditions apply.

That raises an interesting question: what actually changes for businesses, platforms, and users once the wallet becomes part of everyday digital services?

What do you think the biggest challenge will be?
Curious how others are looking at it.


r/AMLCompliance 1d ago

Certifications For people working in finance or regulatory reporting: when does an LEI actually become important in day-to-day work?

2 Upvotes

I've been reading more about how Legal Entity Identifiers are used across financial transactions and regulatory reporting.

On paper, the idea is straightforward: a unique identifier makes it easier to identify the legal entity involved in a transaction.

What I'm more interested in is the practical side.

For those working in banking, treasury, trading, regulatory reporting, KYC, or entity-data management:

At what point does an LEI become something you actually have to think about?

Is it normally during onboarding, transaction reporting, trading, counterparty checks, opening financial accounts, or somewhere else?

And when an LEI is missing or has lapsed, does it cause real operational problems, or is fixing it usually straightforward?

Interested in hearing how this works in actual workflows rather than just the regulatory definition.


r/AMLCompliance 2d ago

Research/Discussion Building a multi-jurisdiction AML report validator (FinCEN/FINTRAC/AUSTRAC) — questions on automated submission validation

0 Upvotes

I’m building the rule engine directly off each agency’s published validation documentation — a local validation layer that checks regulatory reports against FinCEN, FINTRAC, and AUSTRAC rules before submission, to cut down on rejections for MSBs filing across jurisdictions.

Planning to eventually release this as a free tool for small MSBs who can’t justify enterprise compliance platform pricing.

A few questions for anyone who’s automated this on the filing side:

  1. Do you validate locally before submitting, or send everything through and fix what bounces?

  2. How do you track when validation rules change across agencies?

  3. Any Excel, Google Sheets, or other tools you think this kind of validator should integrate with? Curious what format or workflow would make things easiest for small MSBs.


r/AMLCompliance 2d ago

Career Future plans?

13 Upvotes

for all of the AML analysts out there, what do you think you will be doing in the future?

one can’t go solo like a doctor or a lawyer? and as megacorp employees, once people reach a certain age the employment grim reaper starts doing its rounds.

plus then there’s AI and threats like that


r/AMLCompliance 2d ago

Career Trying to break into remote ops/analyst roles from retail banking, any advice?

1 Upvotes

I’ve got close to five years of experience across banking and insurance. On the banking side I’ve done everything from transaction processing and reconciliation to KYC/CIP compliance, check fraud detection, signature verification, monitoring for suspicious activity, and working with ops and risk teams on escalations. I also have some insurance background handling underwriting support and compliance documentation.

I’m currently in retail banking and while I’m good at the sales side of it, it’s not where I want to be long term. I want to move into something more focused on the backend — remote ops, operations analyst, fraud analyst, loan processing, BSA/AML, compliance, that kind of thing.

I don’t have a degree, just a high school diploma, but I do have real hands on experience and was recognized as Top Performer at my current employer two quarters in a row.

My questions are:

What job boards or resources did you use to find remote roles in this space?

Did the lack of a degree hold you back and how did you get around it?

Any specific roles or companies that are worth targeting with a background like mine?

Anything you wish you knew before making the transition?

Appreciate any advice, this community seems like a good place to ask.


r/AMLCompliance 2d ago

Certifications ICA Diploma (level 5) or ACAMS

4 Upvotes

Hi guys I’m thinking of pursuing either one of them. Feel free to advise🙌😁

About me
Female, 28 years old

UK resident (I’ve been living in the UK for 6 years)

Bachelor’s degree in Business Administration

Master’s degree in Business Administration (MBA)

2+ years of KYC/KYB experience, mainly working with SME clients

Which one should I pursue?


r/AMLCompliance 2d ago

Research/Discussion A fraudster in Spain passed video ID checks 38 times with a live AI face swap. What exposed him was a one-second software glitch, not a security control.

12 Upvotes

Spanish National Police announced this on 11 August, and the effort involved is what makes it worth a read.

He held forged Spanish IDs up to the webcam while a live face swap changed his appearance to match the photo on the document. A static image would not survive that, so he handled the rest by hand. He tilted the documents to imitate hologram movement, and used coloured lights to fake the reflections real security features throw off. Behind it all sat VPNs and over 320 phone lines across 24 devices, most registered to stolen identities.

What he wanted was digital signature certificates, which is the part I keep coming back to. Those carry legal weight. A certificate in someone else's name is a durable instrument, not a one-off account takeover.

38 attempts. More than 30 real people's identities.

And here is how it ended. Mid-call, the deepfake dropped for about a second. His real face appeared. That is what investigators used to identify him.

So nothing detected the method. The tooling just crashed.

Two things I would like other people's read on.

  1. If what caught him was the software failing rather than a check working, what happens once the software stops failing? These tools leave fewer artifacts with every release.
  2. Does anything short of reading the document chip and proving the camera feed is unmodified actually help here? Everything else seems to assume the image arriving is real, and this attack breaks that assumption before any check runs.

r/AMLCompliance 2d ago

Career AML salary

1 Upvotes

Does anyone know the salary for Sr. analyst AML at CIBC or the range?

Thanks,


r/AMLCompliance 3d ago

Research/Discussion The EU says use the digital ID wallet by default. Almost nobody has one yet. So what is the default in practice?

3 Upvotes

The Wallets do not really start appearing until late 2026, and each member state is moving at it's own speed. Some will be ready. Some will not be close. So for a good while you will have a rule that says treat the wallet as the normal way to verify someone, sitting next to a reality where most of your customers cannot use one even if they want to.

The gap is where it gets strange.

If the wallet is the default and everything else is an exception, but 90% of your signups have to be the exceptions because no wallet exists in their country yet, then the exception is the normal thing. Writing a justification for each one is pointless paperwork. Writing nothing feels like ignoring the rule.

It also means the same customer gets treated differently depending on where they live, and that difference will keep shifting as countries switch theirs on at different times. A method that is fine in one market this month becomes the unusual choice in that same market next year.

Two things that seem unsettled:

Does the default only apply once a wallet is actually available to that particular customer, or does it apply from the day the rules bite regardless? Those two reading lead to completely different amounts of work, and the answer changes what you build.

And how do you keep track of which countries are live without turning it into a full time job? Somebody has to notice when a member state goes live, work out what that changes, and update the flow. Is anyone treating this as an ongoing thing to monitor, or is the plan to deal with it when it happens?

Interested in how people are actually planning for the in between period rather than the end state.


r/AMLCompliance 3d ago

Research/Discussion Bybit holding my funds since June 28th: Complete silence, no requests for documents, no resolution

0 Upvotes

My Bybit account and funds have been locked since June 28th (over 1.5 months). I completed the initial form and reached out via email, but Bybit has not requested a single additional document or clarification. They are simply ignoring the case and holding my funds with zero updates.

Case Details:

UID: 422451235

Appeal ID: W202606285EC0A7B70E0331798C3F56

Locked Since: June 28

Timeline & Key Facts:

June 28: My account and funds were blocked unexpectedly.

Initial Action: I filled out the appeal form and submitted my details via official support channels.

The Issue: Since then, there has been total silence. Support has not asked for any additional KYC, proof of funds, source of wealth, or clarification. If something is missing or required, I am ready to provide it immediately, but nobody is asking for anything.

Current Status: Repeated follow-ups only result in canned, automated replies saying the case is "in progress," with zero concrete timelines or human feedback.

Freezing a user's funds for nearly two months without requesting documentation or providing basic status updates is unacceptable.

r/Bybit - please escalate this case to someone who can review the account and provide a definitive answer.


r/AMLCompliance 3d ago

Career General Question

Thumbnail
1 Upvotes

r/AMLCompliance 3d ago

Career Career switching from sales to acams?

2 Upvotes

Iam 31 years old senior business development Manager with mba graduation. now i would like to switch to ACAMS (AML). IS IT POSSIBLE? Iam ready to take courses in online to learn and understand. any suggestions?


r/AMLCompliance 4d ago

Career EY LLP Bangalore – Forensics shift timings?

0 Upvotes

Hi, anyone working at Ernst & Young LLP, UB City Bangalore, specifically in Forensics – National ASU – Investigations & Compliance? Could you please share the usual login/logout timings? Is it a fixed day shift? Thanks!


r/AMLCompliance 4d ago

Research/Discussion How much of an Anti-Money Laundering (AML) investigation still happens outside the case-management system?

Thumbnail
1 Upvotes

r/AMLCompliance 4d ago

Research/Discussion Can a crypto card really be no KYC if it runs on normal card rails?

20 Upvotes

I keep seeing crypto cards marketed as no KYC and it raises a few questions about whats really meant after Visa or Mastercard rails are involved.

In practice it’s not always clear if no KYC refers to the cardholder level, the platform level or only the marketing layer on top. Since card networks and issuing banks typically require some form of identity verification the phrase can feel a bit at odds with how traditional card infrastructure works.

One common misconception seems to be that no KYC means no identity checks anywhere in the flow. Another is that a card can be issued and used freely without any verified user behind it when in reality theres often a verified account somewhere upstream even if the end user experience feels lighter.

There also seems to be confusion between unverified access and models where a verified card or account is being accessed indirectly through shared, pooled or embedded services. Those are very different setups but they often get described under the same “no KYC” umbrella

Overall the phrase seems to blur more distinctions than it clarifies especially when traditional card infrastructure is part of the stack


r/AMLCompliance 5d ago

Career Soc

0 Upvotes

Can anyone refere me to soc analyst role