PODCAST
This Week in AML
Southeast Asia’s Criminal Economy, Crypto Crime Risks, and AMLA’s Compliance Wake-Up Call
AML RightSource
:
Jul 24, 2026
This week on This Week in AML, Elliot Berman and Joe McNamara examine a series of reports and regulatory updates highlighting the growing sophistication of global financial crime.
The discussion begins with a new United Nations Office on Drugs and Crime (UNODC) threat assessment that details how Southeast Asia has become a hub for interconnected criminal ecosystems, with organized crime groups increasingly offering “fraud as a service” at enterprise scale. Elliot and Joe explore how criminal organizations are evolving from trafficking goods to operating highly sophisticated criminal services businesses.
They also discuss FATF’s latest targeted update on virtual assets and VASPs, including concerns about stablecoins, regulatory gaps, and ongoing challenges in implementing the Travel Rule across jurisdictions. The conversation highlights how organized crime networks are leveraging crypto assets to move illicit funds globally.
The episode then turns to new guidance from the Wolfsberg Group on managing risks associated with non-bank payment service providers, AMLA’s growing focus on vulnerabilities in the non-financial sector, and ongoing concerns about real estate as a money-laundering vehicle.
Southeast Asia’s Criminal Economy, Crypto Crime Risks, and AMLA’s Compliance Wake-Up Call - Transcript
Elliot Berman: Hi Joe, how are you today?
Joe McNamara: Hey Elliot, I'm doing great. As always, really excited anytime I get a chance to participate in the ongoing This Week in AML series. But how are you doing?
Elliot Berman: I'm good. As our listeners know from last week, John's in transit to Milwaukee — one of his daughters is getting married here on Saturday of this week. And my daughter is getting married this Thursday. So it's all weddings all the time for the TWIA team. But I didn't have any travel, and since it's about fifteen minutes to the venue for my daughter's wedding, you and I are going to do today's episode. So where would you like to start?
Joe McNamara: I thought — we've probably got six or seven pieces here — it might be best to start in Southeast Asia. I'm not sure if you saw, but there was a new United Nations Office on Drugs and Crime report that came out. The full report, in all honesty, is somewhere between 240 and 260 pages, so I wouldn't necessarily recommend it — although some of you may find that to be light reading. I was most drawn to the press release, which essentially outlines how the report reveals the scale of Southeast Asia's ever more interconnected criminal economy. It goes into great depth on all of these different tentacles of the larger money laundering, fraud, and organized crime vehicles — all of which are established and running at more or less an enterprise scale coming out of Southeast Asia. This release specifically came out of Thailand. I was curious about your thoughts on anything you pulled out of the report, or the press release we were reading.
Elliot Berman: Yeah, I did not read the entire report — I'll 'fess up to that — but I did read a fair amount of it. The report's actual title is Interconnected Criminal Ecosystems: Transnational Organized Crime Threat Assessment for Southeast Asia. UNODC did an earlier version of this about six years ago, in April of 2019. As the title tells you, and as you indicated, it focuses on Southeast Asia as a hub for transnational criminal activity that is global. It goes through a variety of types of crime and related infrastructure activity — there's a long list, and I'm not going to read it, but big picture: drugs, technology innovation, gambling on illegal online platforms, trafficking in persons, and many others.
I think the big conclusion is what you mentioned. Six years ago, when they did the report, the focus was still primarily on the sale of goods — illegal goods, illegal drugs, things like that. Now the report concludes, in part, that we've shifted and are primarily seeing services. Many of these transnational criminal organizations are offering fraud as a service. We worry about banking as a service; they're scaling fraud as a service, and, as you said, to enterprise and even industrial levels. They're innovating as fast as those of us on the defense side are — and in many respects we're actually playing catch-up.
So I think it's a worthy skim — certainly the introduction and the high points. There's a lot in there. As John would say, there are things in there that could be spun into good training materials. But as you point out, a 250-ish-page report is not something you're going to hand to each one of your analysts and say, "Okay, here's today's homework." Some synthesis and focus is necessary. But UNODC, like the other major organizations we often talk about — FATF and the Wolfsberg Group, both of which we'll get to later today — puts out high-quality material and deep research. They're valuable tools that all of us in the space should be monitoring on a regular basis.
Joe McNamara: No doubt. And to your point about mentioning FATF, but also staying in the realm of organized crime — I saw this week there was a news report out of AML Intelligence titled Organized Crime Moves Billions Through Crypto; Some Stablecoins Impossible to Seize or Freeze, Per FATF. Not to beat what would essentially be a dead horse here, but the running thread is certainly the focus on organized transnational crime. I think what we're seeing is less of these spontaneous one-offs and more of what I'd consider a pattern. And this pattern points to what we saw in the other report as well — an ongoing transformation of these crime syndicates as they look for more ways to establish, I don't know if I'd call it legitimacy, but certainly more of a structural procedure or infrastructure that lets them carry on their business at a much higher clip than we've seen in probably the past decade.
In terms of the specifics of what FATF warned about, there were a few call-outs, specifically around how they're utilizing cryptocurrencies — in this case, stablecoins — over the past year to move illicit funds around the world. But thoughts on that from your perspective?
Elliot Berman: So we're talking about the seventh targeted update on implementation of the FATF standards on virtual assets and VASPs. By the title, we know this is something FATF has been working on continuously for a while. And you're right — it focuses on the fact that organized crime is taking advantage of the regulatory gaps that allow illicit proceeds to be moved through the crypto industry. Stablecoins are becoming more attractive because other cryptocurrencies and virtual assets have a value-volatility issue, and — by their name — the concept behind stablecoins is that they have a more stable value. So the shift to stablecoins, in part, is taking out currency-volatility risk, which you wouldn't necessarily think of.
They talked about crypto-enabled crime becoming more complex and interconnected just in the last year. They noted that regulators, banks, and crypto companies face — and I'm quoting here — "significant and ongoing challenges" in detecting and stopping dirty money flows from scam compounds. So now we're back to Southeast Asia, and investment fraud networks, which we haven't specifically talked about today but have talked about in other episodes. And significant gaps remain in translating risk assessments into actual steps to reduce crypto crime.
We know from previous conversations that the AML program rule in the US will now specifically require risk assessments, which is a good thing — it's some clarity, and risk assessments, well done, are valuable. But the whole idea of translating your risk assessments into actionable programmatic activity continues to be an ongoing challenge. Not because people don't know it's important, but it's like the drawing of a new airplane with new technology: there's a process between that drawing, turning it into plans, and then actually putting one in the air. That's really what we face — a similar challenge between the risk assessment process and active interdiction and detection.
Joe McNamara: Correct. The word that comes to mind is almost a "lag." That's what we've seen with FATF's efforts — this being the seventh, and I'm certain it will not be the last one they put out on this topic. There are some numbers in this report too that talk about the comparison in terms of legislation implemented specifically around the travel rule. From 2025, about 73% of surveyed jurisdictions — not all global jurisdictions, but at least the ones surveyed — we saw a 10% increase to 83% that have now implemented some form of legislation, especially around the travel rule. So that still leaves the better part of 20% of surveyed jurisdictions, let alone the ones that went unsurveyed, still trying to play catch-up.
So it's something we'll continue to monitor. But moving on — I feel like I'm driving this whole thing. I'd be curious about other things you saw this week.
Elliot Berman: Well, we've talked about FATF. The Wolfsberg Group came out with new guidance on how financial institutions should conduct a thorough assessment of specific non-bank payment service providers — PSPs is the acronym — their activities and flow of funds, so institutions understand the unique risks.
Most folks in the traditional financial services space are familiar with the wire systems and, in the US, the Automated Clearing House system, ACH. There are parallels to that in other countries. But now, with technological innovation, we have a wide variety of non-traditional payment service providers, new rails, and things like that. Understanding how they work and how the funds flow matters, because for many of them the funds ultimately do end up in the traditional system. The Wolfsberg Group provides some strong recommendations, and also talks about ways to make these assessments so you really know who you're dealing with. As John and I have talked about in other episodes, the Wolfsberg Group does a nice job of providing practical insights. You can find the report on their website.
Joe McNamara: Absolutely. I'd say too — while obviously not from Wolfsberg — I saw some similar language out of AMLA this week, specifically around what they've termed the "non-financial sector." In this case, it was specific to blind spots they were uncovering for every country. As the director of AMLA pointed out, and I'll quote: the non-financial sector is really a blind spot for every member state. This was within the prism of looking at how businesses and supervisors outside the financial sector still seem to require more time to adapt to some of the new anti-money laundering rules. That in itself is a challenge, but also a good reminder that regardless of how familiar you are — as a traditional actor like a bank or financial institution, or as something more along the lines of a gatekeeper — the emphasis still remains.
At this point, it's really critical for some of these other, non-financial sectors to begin investing the time and getting smart around the challenges and threats associated, directly or indirectly, with illicit actors trying to circumvent traditional financial compliance regulations within the larger global system.
Elliot Berman: Yes. And both her remarks and an announcement out of FIU Deutschland zeroed in, in part, on the real estate markets — the fact that they have the possibility of being a place to either hide or launder illicit funds. Particularly, the comments from FIU Deutschland were that it's more than just the purchase transaction. There are a lot of people in the chain of real estate transactions, and bad or corrupted things can happen at pretty much any step in the chain. Then, on a going-forward basis, there's servicing activity — loans, and all kinds of service providers to large real estate holding companies. So understanding the full dimensions of real estate activity, both residential and commercial, matters, and those things have become more global, like everything else.
We've talked about real estate here in the US. We've gone back and forth about how it took a long time to get real estate included, and now we're not so sure how we want to include it. This is something other countries have been earlier to the party on, but still not at the level they've reached with other industries. The EU and UK have done more in the real estate space, but still not 100%. And once you get to real estate, you're touching a lot of the gatekeepers — attorneys, accountants, and so on. So, nothing brand new here, other than that people continue to raise the consciousness of the fact that we haven't taken a full-on approach globally. We can feel comfortable, like everything's fine, until you really think about it: what are we doing in these spaces?
Joe McNamara: That's right. And specifically, in the analysis of what FIU Deutschland found, there's a list — I'm not going to read it — of probably nine or ten methods of operation that came up, pattern-wise, in the STRs they were analyzing.
If there was a running theme through all of this, Elliot, this week seems to be a lot of reminders. I'm not sure if you saw, but there was also another article titled KYC Failures Top EU Banks' Money Laundering Weaknesses, AMLA Says. So AMLA's been very busy this week — admittedly, as they should be.
Elliot Berman: Well, they were having meetings in Brussels with members of the European Parliament. When folks like that get together, it's not surprising there are a lot of comments, speeches, presentations, and announcements. And as we've talked about, since the passage of the new regime that created AMLA as an entity, they've got a gigantic list of things to do and a time clock that's ticking.
Joe McNamara: And admittedly, that's a good thing, in my opinion — AMLA should be noisy at this point. The resounding message I got from this, in part to your point, is that I wouldn't consider any of it novel. There's nothing new here so much as it's a good reminder and a reprioritization of things. I'm going to read directly from this excerpt: AMLA specifically called out material weaknesses identified across a broad range of institutions — not just the large or high-risk entities. Those differences, influenced by sectoral and national supervisory approaches, included things like failures in identifying and verifying customers and beneficial owners, inadequate screening of politically exposed persons (PEPs), and insufficient risk profiling leading to the misclassification of high-risk customers.
So again, nothing new, as much as it's a good reminder that things will continue to progress. We're excited to see some of the things AMLA has sunk its teeth into. But ultimately, the burden will still lie with these institutions to figure out better ways not only to service their customers, but to make sure those customers are protected from illicit actors.
Elliot Berman: The good reminder for our listeners in the US is that, even though AMLA is regulating in the EU, most of the things they're talking about are good reminders for anybody running a program. Has it become so routine that we're really not paying attention to it? And while we're automating all kinds of functions where we can, even the automation has to be double-checked every so often. Are we really asking the right questions? If we're using scoring models, are they accurate — does a flag actually go up when it should, saying "higher risk, additional activity required"? So paying attention, at least to the top-level things coming out of AMLA, is good for people around the globe. So much of what we're trying to do, regardless of where you are, is similar enough that when an organization like AMLA raises a flag, it's probably a flag for everyone.
Joe McNamara: I would agree. I'm sure everybody could make an argument for nuance here and there, but I couldn't agree more on the general approach. It's probably good to keep an eye on what your neighbors are doing — you might pick up a couple of things. And if not, it's a really good reminder to continue down the path you're currently on.
Elliot Berman: Right.
Joe McNamara: Okay. I think the only other piece — and this brings us back domestically, at least to where you and I are sitting here in the States — is another good reminder about the emphasis on internal training and making sure your program accounts for things like insider threats. In this case, we saw a former TD Bank employee sentenced after pleading guilty to facilitating a money laundering scheme that moved hundreds of millions of dollars through the bank's accounts. I'm sure you saw this one. There were actually two employees mentioned in the article. The bigger one, related to the insider threat, involved an exchange of value: approximately $11,000 in gift cards as payment, in exchange for moving about $92 million illicitly through the bank.
Any thoughts on that? From my perspective, it's a good battle cry for ensuring your program is up to date on internal training and the policies and processes you put in place — but also for making sure there are enough mechanisms to allow for the safety of things like whistleblowing. As was stated in the prosecutorial piece of this hearing, there were other employees who essentially raised their hands and said, "Hey, there's something funny going on here."
Elliot Berman: Insider threats are, in many respects, the toughest. We do a lot in all of our organizations to harden our systems and procedures against outside threats. We do our best against inside threats too, but inside threats are tougher to manage. This is a great example — it was done using official bank checks to launder the money, apparently by a person who was able to override limitations, or was placed high enough that their authority was sufficient to make these things happen.
We've talked about this many times on our AML Conversations podcasts, with experts, about how to manage and detect internal activity. When I was a practitioner, figuring out how to do internal detection was always something we thought about. It's a complex combination of culture, systems, and training — and you need to be vigilant about it.
Joe McNamara: Absolutely. With that, I think that runs us clear across the horn. I'd say a huge mazel to both you and John — by the time this airs, at least one of you will have a daughter married, and the other will be working on it.
Elliot Berman: Yeah. Well, he has one daughter already married, so —
Joe McNamara: Good cleanup. I'd also say that by the time this airs, we'll have concluded our monthly webinar on AI and financial compliance. I happen to be moderating, so I'm probably a little biased here, but — shameless plug — I'd encourage folks to keep an eye out for when it hits the website, probably next week. And another shameless plug for our August webinar, which is going to cover the risks related to virtual assets. I know you've been working on an impressive panel for that conversation.
Elliot Berman: Yeah, that'll live-stream August 27th at 1:00 PM Eastern. By the time you hear this episode, you should be able to register on our website. And John did a really interesting interview — I think he mentioned last week that he was getting ready to do it — with Tess Davis from the Antiquities Coalition. By the time you hear this, or rather sometime next week, you should be able to hear that conversation, which I strongly recommend. So Joe, thanks for sitting in. It's been great to talk with you, and I'm sure we'll do this again at some point.
Joe McNamara: I look forward to that. I'm glad you left the door open there, Elliot. Always a pleasure, and I look forward to the next time. Until then, we'll see you soon.
Elliot Berman: You be well. And bye-bye to all our listeners.

