FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Listen: CRO breaks down risks of automating compliance

Loraine LawsonbyLoraine Lawson
February 17, 2021
in Strategy
Reading Time: 9 mins read
0
Share on Facebook

Automation can help eliminate risk — if it’s used correctly. But this is often not the case, according to a chief risk officer who has worked with censured banks.

The most common mistake banks make is using technology without auditing or understanding it, according to Andrew Stines, chief risk officer at the $1.77 billion Coastal Community Bank in Everett, Wash. Stines is a former managing director at the consulting, assurance, tax and transaction services firm EY, where he helped banks revamp their compliance programs after regulatory events, such as receiving a consent order for a Bank Secrecy Act (BSA) violation.

“You have to understand that technology, and so many folks don’t understand what it was that was implemented,” Stines said. “They don’t understand what’s running behind the scenes, how it’s really identifying unusual activity.”

A successful BSA program has four pillars, according to Stines:

  1. A training program for all employees, including directors;
  2. An independent monitor;
  3. Internal controls that mitigate the risk of money laundering and terrorist financing; and
  4. A BSA officer responsible for implementing and executing the program.

“If you violate one, maybe two, of those pillars, it may not reach the level of a consent order — it might be a private memorandum of understanding or something like that. But when you violate all those pillars, that’s where you get into big trouble,” Stines told Bank Automation News.

In this podcast, Stines, the former chief risk officer at Sunwest Bank, where he rebuilt the bank’s regulatory program, as well as an attorney, explains how banks can find themselves in trouble with regulators and the caveats for ensuring risk-free automated systems.

Bank Automation Ignite, on April 13-14, is the event for inspiring automation initiatives and investment in financial services. At the virtual event, financial services professionals can discover new use cases and technologies that are accelerating automation in banking. Learn more and register at www.BankAutomationIgnite.com.

The following is a transcript generated by AI technology that has been lightly edited but still contains errors.

Good day, my name is Loraine Lawson and I’m an associate editor with Bank Automation News. Recently, I spoke with Andrew Stines Chief Risk Officer at Coastal Community Bank in Everett, Wash. Prior to joining Coastal Community Bank, Stines was with Ernest & Young as a managing director in their regulatory practice group. He focused on anti-money laundering and OFAC, working with financial institutions to achieve compliance after receiving consent orders and similar directives. Previously, he was chief risk officer at a financial institution that itself was under a consent order for Bank Secrecy Act, or BSA, violations, where he helped the bank tear down it program and rebuild it from the ground up. Stines and I discussed how banks get themselves in trouble and what automation can do to help.

Loraine Lawson
What gets banks in trouble with anti-money laundering and BSA?

Andrew Stines
So there’s a host of rules, there’s about a 500-page manual out there called the FFIEC BSA/AML Examination Manual manual 507 pages of just guidance and regulations. So BSA, it’s super interesting, it touches every aspect of a bank, the product of a BSA program is to file a suspicious activity report with FinCEN, the Financial Crimes enforcement network, to report suspicious activity. FinCEN has a massive database that’s accessible by law enforcement and other government authorities. And they go in and they search these suspicious activity reports. And they can oftentimes say, Okay, this bad actor is at this bank doing this, but he was also over here doing this over here, and we see massive amounts of money moving, and then they go in and do the investigation and figure out who the bad actors are and what they’re up to. Some major crime rates have been wound and undone through this suspicious activity reporting. So it’s taken very seriously by our regulators, and more importantly, it’s taken very seriously, from a bipartisan perspective in Congress. So it’s not really we’ve never seen it affected by changes in administration. Whereas you might see changes in the consumer compliance side of the CFPB. The Democrats tend to be more regulation-focused and more interested in that. Whereas the Republican Party tends to back off a little bit and give banks a little bit more freedom. We don’t see that with regard to AML because it’s such an important tool for law enforcement and there’s such a benefit to society. You asked, getting back to your question you ask what gets them into trouble? It’s usually a failure to report or identify that activity through numerous types of failures. Whether it be the transaction monitoring failure, whether it be people not trained any number of things, and then not getting that information out to the to law enforcement in a timely manner. That’s, that’s what really gets them in trouble. Usually, usually, it’s a sign when you’re all the way to a consent order, which is a pretty big violation, it’s a public order, I call it jail, no handcuffs on the on the bank. While that while that consent order exists. Usually it’s a sign of a bigger problem. Usually, it’s a risk management problem, because like I said, BSA affects so many different aspects of the bank, that if you’re failing on all the different angles, or all the things that you need to do, there’s a bigger problem behind, typically. But BSA has four pillars, and I don’t want to, I don’t want to bore you. So feel free to cut me off, No, go ahead. There, it will tie into what our discussion is about a little bit. So there are four pillars you’ve got, you have to have a training program, right. So everybody, including your directors have to be trained, there has to be independent testing, and monitoring of this program by by a third party or an independent party, you have to have internal controls, to mitigate, to mitigate the risk of the institution with regard to money laundering and terrorist financing. And you also need to appoint a BSA officer, somebody who’s who’s responsible for implementing and executing this program. And it’s more than just putting a title on somebody, if you’ve got to give them the right resources, you’ve got to give them the right authority to really do a good job. If you violate one, maybe two of those pillars, it may not reach the level of a consent order, it might be a private memorandum of understanding or something like that, or an MRI. But when you violate all those pillars, that’s where you hit, you get into big trouble.

Loraine Lawson
So who do you hear from when you get in big trouble?

Andrew Stines
It would be the it would be the Prudential regulator, the primary regulator of whatever that financial institution is. And so No, that’s, it gets more technical than that. We probably don’t need to go that. But that’s the regulator that comes in but fines can be instituted by fincen.

Loraine Lawson
Are there particular mistakes that you see banks make to get in trouble? I mean, is there a pattern?

Andrew Stines
Yeah, I was just doing the math in my head this morning about how long I’ve been doing BSA. And I realized, and I’m dating myself here, but I’ve been doing BSA for 16 years. And it’s always been with troubled institutions with the exception of this one. This is which is nice. I would say common problems. common problems are definitely technology, misusing the technology or not using it at all. That’s a big one. Training. I would also say a big problem is the lack of director and senior management support for BSA. They’re in institutions where you have a problem, I’ve typically we’ll find that there has been a lack of good compliance culture in that institution. And because of that, there aren’t enough resources being provided to the BSA department to effectuate what its intended mission is just lack of training, lack of concern over it, just getting by trying to do the bare minimum. That’s the big problem. When you see consent orders, that’s usually behind it. It’s a it’s a compliance culture shift that needs to happen to correct it. So it’s not it’s not uncommon for BSA consent orders to you’ll subsequently see resignations of VPS and CEOs because of it.

Loraine Lawson
I bet you talked about the technology piece. You said sometimes they’re using it wrong. Sometimes they’re not using it we we write about automation. And I wonder closely about that automation piece. Are there cases in which automation can help? And are there cases in which automation has caused the problem?

Andrew Stines
Oh, absolutely. So automation absolutely helps. And it’s absolutely necessary. I think, in today’s world, if you were to walk into a financial institution that isn’t using technology around AML. And this is specifically transaction monitoring systems in case management systems. Something’s wrong. They’re either very, very small, and no risk, and they can prove that they can manually review their transactions, but most likely, there’s just a real problem. So you’re not seeing that today so much that there’s a lack of technology, but yes, being misused. So so often. If you don’t If you’re if you’re in the role of overseeing that department, in my case, I have a BSA officer who oversees it. But I oversee all of BSA as well. So the buck stops with me so to speak, you have to understand that technology. And so many folks don’t, they don’t understand what it was that was just implemented, they don’t understand what’s running behind the scenes, how it’s really how it’s really identifying unusual activity. They’re not getting that model tested by an independent outside party that comes in and says, Hey, you plug it in correctly, you’ve got the pipes and the bolts and everything done correctly. So often, if they fail to do that, they find out that their model wasn’t working at all a year later. And they’ve missed all kinds of unusual activity, therefore, they have a SAR violation, right. They didn’t file SARS, timely, which is 30 days from point that you’ve detected, or determined that the activity is suspicious, and you have 30 days to file. So I’ve seen it in many institutions, where they, they don’t implement it, right, they don’t have things plugged in, they don’t understand the model. And that’s where they get in trouble. And I’ve seen institutions waste two and three years trying to figure it out. It’s crazy millions of dollars, I can’t even show you the number of hours that the teams put into it. And it doesn’t work. At the end of the day, it’s like building a car, you spend two years out in your garage, building the car, and then it doesn’t run, and you can’t figure out why. So they end up having to scrap and start all over. But where it works today, what we’re doing, which is really fun. As you know, or may not know, we’re in banking as a service, at coastal community bank, what that means is that we partner with, in addition to our core bank, so we’re a commercial lender, and in Snohomish County, and Everett and all that area, so, but outside of that we partner with fintechs. And these fintechs have their own platforms, their own core processors, they they typically will collect customer identification, program, material, you know, materials, they’ll, they’ll they’ll collect know, your customer KYC information so that you understand the customer and the source, they’ll collect all that. And they’ll put it in this really fancy mobile digital app, right, that’s user friendly. And they work with that customer, we as the bank behind that support that function, we provide the charter that allows them to facilitate many transfers, to lend in different states to have banking deposit to have accounts. So we they use our payment rails, so to speak, to do their business.

With that we have several fintechs, right, and we’re growing. But we need to grow in a safe and sound manner. And scalability, building scalable technology and scalable processes is part of getting it be maintaining being safe and sound. Our transaction monitoring system that we’ve developed is really cool. It started with what’s traditionally known as static rule sets. These are like the if this, then that type situation. So you know, if I want to detect you, Loraine, that you’re moving $10,000 in cash, I might have a rule out there that says, if we’re you know, if this person moves $10,000 a cash, I want you to flag it and then we look into it, that alert pops out our investigators look at it, they look at you and they say why is this teacher who’s out of work moving $10,000 in cash around every week, right? And that’s where we begin from there. But this system in today’s world, we’re starting to finally leverage machine-based learning and automate and in AI artificial intelligence, right. And this is what’s great. So as you start with our static rules, then we use the machine-based learning to look at what’s popping what’s coming out for as far as alerts, and then looking at behavior patterns, right, and then saying, Hey, you know, Lorraine, Lorraine does this normal month after month after month, and then all of a sudden, bam, we have a lot of crazy activity to a foreign country. I’m obviously being very hypothetical here, but hopefully making some point. Yeah, all of a sudden, there’s all this movement to a foreign country that we’ve determined to be higher risk for money laundering that machine-based learning would have would catch that and pop that out and say, Hey, you might want to look at this. Right? That wasn’t a static rule. It was something that said I identified something that was behaviorally different. Then you have the artificial intelligence, which is learning and teaching itself. I’m probably not the best guy to talk to about explaining AI. But, but that’s okay. It’s good stuff. The key that I, the key message here that I would get across to anybody who reads or listens to this is you do have to understand what your machine-based learning is doing actually doing. And you need to understand what the AI is actually doing. You have to be able to just spell it out. So that you’re not making any mistakes. It’s especially important when it comes to lending and underwriting, you don’t want to leave it, you might mistakenly have your AI discriminating even though there was no intent to do so. But it might be doing it on its own. So it’s very important that you have the right individuals in house, to who understand it and can explain it, and can actually test it and make sure that it’s within the bounds of what your what your goals are, and not doing something that, you know, illegal for, for lack of better terms, or that would violate a law rule of some sort. So that’s, that’s what we’re doing in our space.

Tags: BSAPremiumRisk Management
Previous Post

Truist’s head of digital banking outlines 2021 digital roadmap

Next Post

Goldman Sachs’ Marcus Invest takes a human-automation approach to robo-advisors

Related Posts

Strategy

BMO, IBM weigh in on agentic AI-quantum synergy

July 20, 2026
A data graph tracks the movement of stocks on the stock exchange in Germany. Photographer: Bloomberg Creative Photos/Bloomberg Creative Collection
Strategy

Tradeweb, 3forge embedding AI to make trading easier

July 20, 2026
To celebrate the launch of its free financial wellness program Money Roots™, Ally planted a literal money tree in New York City to give away $100,000 – both in person and online – to those who share their money story, ultimately easing financial stress nationwide. Courtesy/Ally
Strategy

Sathish Muthukrishnan leaving Ally

July 20, 2026
Next Post
Image courtesy of Marcus by Goldman Sachs: 
Visuals, including
values, are for illustrative purposes only. Investing involves risk and investments may lose value.

Goldman Sachs’ Marcus Invest takes a human-automation approach to robo-advisors

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account