PODCAST

 

This Week in AML

Clarity Stalls, Deepfakes Come Down, and VTB Gets Designated Again

Joe McNamara sits in for Elliot Berman this week alongside John Byrne. Joe and John discuss the Senate vote that failed to advance the Clarity Act, the interagency proposal to rescind and replace third-party risk management guidance, and the CJEU ruling on Latvia's public shareholder disclosure law and what it signals for beneficial ownership transparency. They also cover the DOJ indictment of a Russian intelligence services network, the Manhattan DA's seizure of 12 deepfake websites and the payment infrastructure behind them, Transparency International's analysis of seven years of EU rule of law reporting, and OFAC's designation of VTB Bank under Operation Economic Outcast. They close with CSIS's look at the terrorism landscape 25 years after 9/11, the shift toward lone actor threats, and the underused potential of 314(a) and 314(b) information sharing.

Resources mentioned in this episode:

Senate cloture vote on the Clarity Act: https://www.cnbc.com/2026/09/15/senate-cloture-vote-on-clarity-act-fails-dealing-regulatory-setback-...
Proposed interagency third-party risk management guidance: https://www.federalregister.gov/documents/2026/09/15/2026-18859/proposed-third-party-risk-management...
CJEU ruling on Latvian shareholder disclosure (Case C-798/24): https://cyprus-mail.com/2026/09/13/european-court-decides-on-public-access-to-shareholder-informatio...
DOJ release on the Russian intelligence services network indictment: https://www.justice.gov/opa/pr/members-russian-intelligence-services-network-charged-conspiring-fina...
Manhattan DA seizure of 12 deepfake websites: https://manhattanda.org/manhattan-d-a-s-office-seizes-domains-of-12-illegal-websites-selling-ai-gene...
Transparency International, Anti-Corruption Gaps Are Leaving Democracy in Europe Exposed: https://www.transparency.org/en/news/anti-corruption-gaps-leaving-democracy-europe-exposed
Treasury designation of VTB Bank under Operation Economic Outcast: https://home.treasury.gov/news/press-releases/sb0629/
Riley McCabe, CSIS, Adapting to the New Terrorism Landscape 25 Years After 9/11: https://www.csis.org/analysis/adapting-new-terrorism-landscape-25-years-after-911
ProPublica reporting on the Trump Jr. wedding financing: https://www.propublica.org/article/donald-trump-jr-wedding-bankrolled-russian-oligarch-umar-kremlev-...

 

Clarity Stalls, Deepfakes Come Down, and VTB Gets Designated Again - Transcript

Joe McNamara: Hey, John. How are you this week?

John Byrne: I'm good, Joe. Thanks for once again sitting in for Elliot. Appreciate it, and I know Elliot does as well. It's good. I was able to go see my Giants beat the Cowboys on Sunday night, which we haven't done in probably a decade. So it's a good week regardless.

Joe McNamara: No kidding, it was fun to watch that squad roll around, and that running at the end was fantastic. So, we obviously have a bunch of things to cover, and as we always do, we're recording midweek.

John Byrne: The Senate did fail to advance the Clarity Act. We've talked a bit about that in the past. It was a close vote, but obviously this is an interesting dynamic in that the traditional banking industry was opposed to the Clarity Act because they believed there was going to be, my words, not theirs, a run on community bank deposits with some of the language that's in the legislation. And the crypto lobby obviously wanted to see this. So it's going to be interesting to watch what happens going forward. There are a lot of experts on LinkedIn and other places that say this is not the end of the conversation on digital assets. I don't pretend to be as well versed on that, but obviously this was an important vote, and we'll continue to follow it going forward.

Joe McNamara: Yeah, and I think that's a great summation, to be quite honest with you. This is clearly not the end of the conversation, clearly not the end of where we're going. But I would say, at least from what we've seen thus far, it makes a lot of sense as to why it didn't pass. I saw something else, too, just around third-party risk management. I know you were reading up on that particular one this week. Any thoughts or comments there?

John Byrne: Yeah. So all the banking agencies and the credit union agency are proposing together a third-party risk management guidance and also issuing statements on community bank engagement with what they're calling core service providers. So all the various agencies, 60-day comment period. Just referencing what the Board of Governors' staff said in their staff memo: the staff is recommending that the agencies propose to rescind and replace the existing guidance on third-party risk management and issue what they're calling more streamlined guidance.

And again, quoting from the memo, the all-bank guidance would provide third-party risk management guidance applicable to all banking organizations and address concerns through at least three principles. One is the establishment of a principles-based approach that they say is non-binding. So it doesn't set forth enforceable standards or prescriptive requirements, but noncompliance with the guidance is not preferred. It won't result in supervisory action, though. That's an interesting statement. Then they want to emphasize a risk-based approach, which we've seen obviously in all forms of reg oversight. And then the third thing the staff is recommending is recognizing innovative approaches to third-party risk management. They said there are things that need to be considered for assessments, whether you hire consultants and so on. They also add that the all-bank guidance would note that third-party relationships could raise additional consumer compliance considerations that may be relevant but are not directly addressed in the proposed guidance.

So the proposal poses specific topic questions and invites comments. It's a notice of proposed rulemaking with a series of questions for stakeholders and other interested parties to respond to. It's a 60-day comment period: Fed, FDIC, OCC, and NCUA.

Joe McNamara: Makes a lot of sense. And I'm going to pull a somewhat tangential thread here. It's not particularly affiliated with only third-party risk management, but we also did see something that came out of the CJEU last week, just around beneficial ownership and the transparency that's at risk. You know, it was those dang Latvians. So apparently there were 17 minority shareholders that challenged Latvia's public disclosure law. And while it's not necessarily a huge thing, I think there were a couple of reminders there, at least that I saw. In part, it was really just around the concept of the burden associated with beneficial ownership and ultimate beneficial ownership. Regardless of where it lands, it's still going to end up at the feet of these traditional FIs. But in terms of what you saw, was there anything else you wanted to weigh in on with that one?

John Byrne: Well, Transparency International, who we reference quite a bit, the EU portion of TI, mentioned that with this ruling, they think that by restricting access, it makes it much harder to detect and prevent corruption, money laundering, and tax evasion. So they find that problematic, and TI has certainly weighed in on the beneficial ownership issue in the States as well. But that was another comment they made that is definitely relevant.

Let me mention a couple of other things real quick. One is the Department of Justice issued a release yesterday. We've recorded on Wednesday. Members of a Russian intelligence services network were charged with conspiring to finance, excuse me, terrorism and commit murder for hire in the U.S. So, according to the announcement, they unsealed charges against five individuals working for the intelligence services of the Russian Federation to conduct attacks and murders around the world. The announcement quotes Attorney General Blanche and U.S. Attorney Jamie McDonald for the Southern District of New York. And again, this is an indictment, and the indictment also references James Barnacle, assistant director in charge of the FBI New York office, who has also been a presenter at our Partnership Forum in the past, when he was in DC. So this is a lengthy explanation of the indictment of the network, and I would just say it's nice to know that we are still somewhat focused on Russian misbehavior, to say the least. A good release, a lot of activity in there, and as with every other press release, it's a good training tool for AML professionals. So I wanted to mention that.

And since we mentioned New York, District Attorney Alvin Bragg had a press conference this week, an action against harmful deepfake websites. I know you identified this a while back. It's not directly related to financial crime. It is, of course, a crime, and it deals with technology. This was about celebrity deepfake websites, but obviously important enough that Bragg held a press conference about the action. What jumped out at you about this?

Joe McNamara: Yeah, and again, I think in terms of the takeaways for our community, it's really about that infrastructure of crime, right? And Bragg kind of framed it as that's really what they were targeting. So of the 12 sites, and the approximately 1,200 people that were mostly women and mostly public figures, ultimately it's the hosting layer that they're going after, not necessarily the individual uploaders. Which is not to say that that's any less of a crime, but what's really applicable to our folks is the fact that these sites sold the content, meaning there was payment processing, crypto on-ramps, and some merchant accounts associated. Ultimately, that leads to the fact that our FIs are going to have that level of exposure. And so it's trying to figure out what level of exposure, if any, your particular FI would have.

And then again, just the overarching theme of fraud, right? Like synthetic identity and voice-cloned wire authorizations. We're starting to see a lot more of this stuff. I can't even say pop up, because it's afflicted this space now for quite a few years. But the only other thing I would say is FinCEN kind of flagged this back in 2024, too, around deepfake media. And ultimately, the enforcement side of this risk is really already, or should be already, in your risk assessment.

John Byrne: Another posting by Transparency International. They've done a new analysis, and this one is focused on European Commission oversight. Basically, they looked at seven years of European Commission rule-of-law reporting in eight different countries. And according to TI's analysis, they think strong laws alone are not enough, and I certainly agree with that phrase. They go on to say that many countries have adopted anti-corruption laws, but weak enforcement, inadequate oversight, and persistent transparency gaps, which we talked about with beneficial ownership, continue to undermine public trust and leave decision-making vulnerable to undue influence. And then they go on to say that with the EU anti-corruption directive now requiring national implementation, they urge governments to strengthen prevention, enforcement, and what they're calling democratic resilience. The headline of the report is "Anti-Corruption Gaps Are Leaving Democracy in Europe Exposed." Again, we quote very frequently what Transparency International looks at and analyzes, and this is another good training resource, I would argue, for those that are paying attention to the anti-corruption aspects of transactional activity.

Joe McNamara: I would agree. And in the theme of what I would consider under-resourced oversight, I would actually point to something else we saw just around VTB Bank last week. Obviously, as it came out, there was definitely a little bit of a hubbub as it related to a combination of it being a Russian entity as well as the Iranian sanctions and the evasion that we saw there. In some cases, and I told you off air, I was talking to Elliot last week and I said, what's the there there? Obviously there are a couple of different ways you can look at it, but what really jumped out to you in terms of what you saw?

John Byrne: Well, several analysts took a look at the speculation prior to the announcement by Treasury Secretary Bessent, because on September 10th he said a large bank would be sanctioned on the following Monday, which was obviously this week. And he also said it would be timed, in his words, to honor 9/11 victims, so that obviously perked everybody's interest. The answer to all this, though, was the designation of VTB Bank, Russia's second-largest lender, for facilitating Iranian sanctions evasion, which comes under the executive order that deals with what they've called Operation Economic Outcast.

Those that have looked at this said what was interesting is that VTB Bank had been previously blocked by OFAC back in 2022. So it's not clear, to me at least, what the announcement was in terms of anything new. According to one analyst, the action does add a second independent legal basis for the designation of that bank. But once you've already been sanctioned, what's the impact of a second designation? I would leave it to the sanctions experts that listen to our podcasts to weigh in on this. But that was the announcement, and according to many, there did not seem to be much new there. I'll leave it at that.

Joe McNamara: Yeah, and I'm still waiting to figure out how the 9/11 wrinkle folded into that. But speaking of which, we did see something else that came out. And obviously, I know that you and Dennis Lormel did an excellent job in terms of recounting the last 25 years and what that landscape looks like since 9/11. For those of you that haven't listened to it yet, it published on Friday. Shameless plug: please go listen, go watch. I thought it was a tremendous conversation. And no, I'm not just saying that because you're on the other line. It's very, very insightful. But there was something else that Riley McCabe from CSIS commented on, just around the terrorism landscape. And I'm going to read a little bit. Sorry.

John Byrne: I'm sorry, go ahead.

Joe McNamara: No, no, go ahead. Go ahead.

John Byrne: No, go ahead.

Joe McNamara: I'm going to read a little bit here. Essentially, post-9/11 counterterrorism succeeded at stopping large, foreign-directed plots, which is exactly why today's threat is lone actors. They estimated that the 9/11 attacks cost roughly between 400 and 500,000 dollars through the formal system, but that since then we've really seen this shift away from those formalized funding channels into things like the New Orleans Bourbon Street attacker, which I know was a couple of years ago, where there's almost no terrorist financing to detect in the classical sense. And so I know that you and Dennis covered some of this as well. But for those of us that are still trying to, and should continue to, fight that good fight, how are we looking through these classic terrorist financing typologies, and how can we continue to combat these things?

John Byrne: Well, a couple of things. I mean, I've seen some others post on LinkedIn that we haven't learned lessons since 9/11. I just disagree with that. I think we have gotten much better and much more proactive in terms of identifying things. But what McCabe makes the comment about, which I don't disagree with, is when there are lone actors. Dennis has talked in separate conversations I've had with him about lone actors that aren't part of either a cartel or a network, and how it becomes much, much more difficult. We did learn some lessons about the failure of imagination and the lack of agencies working together. In fact, I'm going to be interviewing, this week, and we'll post it in a week or so, John Roth, who was one of the primary authors of the 9/11 Commission report. We'll talk a bit about that as well, lessons learned. He's also there because we're going to talk about the impact of losing all these Inspectors General on oversight in the government.

But McCabe says things like, lacking formal training and support, lone actors are generally less capable and therefore less destructive than organized terrorist groups. But at the same time, they're often harder to identify before an attack because there are fewer organizational connections that might expose their plans. And he references a couple of terrorist-related lone actor attacks. So I think that's right. I mean, the 19 hijackers worked in concert with one another, and obviously we had some indication prior, but not enough to do anything. And certainly the financial sector didn't really have any direction in terms of looking at transactional activity.

But the bottom line is, we continue to evolve as proactive anti-terrorism people, whatever industry we're in, and you have to continue to do this. Those that are just sort of turning their nose up, saying the 9/11 response didn't solve anything, you're just doing that to be critical. There's a lot we can learn from this, but I think those are just simplistic answers. And those of you who do that, you know who we mean. Pretty active LinkedIn posters. Come on, folks, give me a break. I mean, some of these laws have worked, some have not, but that's how these things are. And I'll get off the soapbox. But bottom line, CSIS is an organization worth paying attention to and their postings. It's the Center for Strategic and International Studies, CSIS.org.

Joe McNamara: Yeah, and the only other thing I'd add to that, John, because I completely agree, would be three little numbers and a letter, right? So 314(a) and 314(b). I think that in and of itself is still a well underutilized opportunity between both law enforcement and financial institutions to better prevent and, quite frankly, share data more quickly. To your point, that may lead to more uncovering of additional typologies, or at the very least just unlock some of the behavioral context that is often missing when it comes to looking at the transaction data itself, right?

John Byrne: No, 100 percent agree. Last thing on my end. We'd be remiss, we always try to focus if there's a particular corrupt action that's occurred that the media and others are covering, or if they're not covering it, frankly. The Wall Street Journal and many, many other outlets reported on this Russian oligarch that financed Donald Trump Jr.'s wedding celebrations. Reading from the Wall Street Journal: a Russian businessman with ties to Putin, who in fact received a medal from Putin, financed celebrations in the Bahamas that immediately followed Trump Jr.'s wedding in the summer. The statement confirmed that Umar Kremlev paid for two nights of post-wedding events that took place on secluded Bahamian islands. There are also pictures. ProPublica, I think, was the first outlet to report this. They also posted a picture of the entire wedding party, which includes Kremlev standing in the back. So when there has been some response from folks that say they have no idea who this person is, just take a look at the ProPublica article and the follow-up pictures, which, we've been told, are not AI generated.

Joe McNamara: Nice callback. Very nice callback. All right, John, well, that was pretty much what I had on my list this week. Obviously, lots to cover. For those of you that are our habitual listeners, the last thing I'll talk to you about is just the upcoming webinar this month. So if one Byrne wasn't enough, we've got two. For AML compliance best practices, you and your daughter Rachele, along with our panel, are going to be navigating the evolving global compliance landscape.

John Byrne: Yeah, I think Elliot's doing that one. But Rachele will be part of it, yes.

Joe McNamara: Oh, well. Whoops. Well, then I guess we're only going to get one Byrne after all. So for the one in September, you can catch us live on the 24th at 1 p.m. Eastern. And again, sorry to get your hopes up, folks. It'll be one Byrne, not two.

John Byrne: Believe me, if that's their hopes, we're going to have to have some therapy. But that's okay.

Joe McNamara: All right, John, well, hey, thanks again for letting me sit in. Like I said, I always enjoy doing these with both you and Elliot. Hopefully it's a good change of pace. I hope you guys have a great rest of your week. Stay safe.

John Byrne: Yeah, you too. Bye-bye.