Abstract
Targeted financial sanctions regimes and regulations on ‘dirty money’ put banks on the front line in securing financial circulation. This is the context in which banking actors face the challenge of juggling with hundred of sanction, watch and regulatory lists. In light of that list mania for banking policing, list appears to have become the security device of choice in the everyday life of the financial industry across the world. Instead of reducing the complexity of security-finance dynamics to a zero-sum game (securitization of finance vs financialization of security), the article rather aims to question the critical role of lists in the cross-colonization of finance and security. Drawing on empirical research in the United Kingdom and India, the article adopts an ‘analytics of devices’ to think of and analyse banking policing practices through the instrumentation that makes these practices possible and stable over time. It argues that banking appropriation of security lists both (re)configures lists ‘social identity’ and banking actors’ power-relations in the fields of finance and security. Ultimately, the analytical focus on lists appropriation sheds new light on what securing circulation means in finance.
Keywords
Introduction
Screening lists? With our own intelligence systems, at the moment we run 35 pages of names of lists, twelve lists on a page, and that’s just the titles of the lists.
1
The US Office of Foreign Assets Control (OFAC), the European Parliament, the United Nations, the Financial Action Task Force on Money Laundering (FATF), among others, issue lists of thousand of entries (companies, countries, vessels or individuals) for which financial transactions must be blocked. (FircoSoft, 2014a: 1)
With regards to money laundering and terrorist financing regulations, they must implement what is colloquially termed KYC (‘know-your-customer’) programme. KYC includes procedures for customer acceptance, customer identification and on-going monitoring of business relationships, in particular with ‘high-risk customers’ such as individuals falling under the category of ‘politically exposed persons’ (PEPs). 2 There is no official registry of PEPs but commercial companies make and sell ‘PEP lists’ for banks that may consist of over 1.3 million entries in 240 countries and territories. 3 They also supply business services for monitoring over 400 sanction, watch and regulatory lists. 4
In light of that list mania for banking policing, list appears to have become the security device of choice in the everyday life of banking industry across the world. This state of affairs may lead to different, sometimes contradictory assumptions about current connections between fields of finance and security that both ‘share a claim to universal applicability in (all) other social spheres, resulting in various forms of financialization and securitization’ (Boy et al., 2011: 115).
On the one hand, lists proliferation can be interpreted as another kind of securitization of the financial system inasmuch banking activities are rendered and governed as security problems (Amicelle, 2011; Langley, 2013). Financial circulation has become subject to further control and surveillance in the name of national and international security, especially for the protection of states against ‘terrorist networks’. More generally, the global banking and financial crisis has been increasingly phrased as a threat to national security, both in the United States and across the European Union (De Goede, 2010). On the other hand, the emphasis on banking policing can be seen as an expression of the financialization of security with an increasing empowerment of financial actors and influence of financial motives in the daily operations of security (on financialization, see Aitken, 2011; Epstein, 2005; Langley, 2008). Moreover, financial logics pervade the field of security to the extent that the management of sanctions regimes, money laundering and terrorist financing is framed not only in terms of international security but also in terms of financial security. While the notion of financial security is rather broad and polysemic (Boy, 2015), here it primarily relates to ‘financial integrity’ (the ability of the financial system to be protected from criminal misuse, particularly from a reputational point of view) and ‘financial stability’ (‘the ability of the financial system to be protected to resist stress, turmoil and shocks’ (Boy, 2015).
Instead of reducing the complexity of security–finance dynamics to a zero-sum game (securitization of finance versus financialization of security), the article rather aims to question the critical role of lists in the cross-colonization of finance and security. Indeed, the above-mentioned lists are the instrumental condition of possibility of policing at the interface of finance and security. They allow sanctions regimes and regulations on ‘dirty money’ to be made operational on a daily basis. In other words, they constitute the main device to give form and effect to security policies in finance. At the same time, their force of action ultimately depends on ‘appropriation’, i.e. ‘the dynamic process of dialogue and reflection between an object [the lists] and a space of activities [finance in general, banks in particular] producing usages either routinized or innovative’ (Crespin and Lascoumes, 2000: 134). It is how, precisely, this ‘dialogue’ is held that matters. The question is neither do the lists determine end-users’ behaviour nor do end-users instrumentalize the lists. The question is rather what does the relation between lists and lists end-users do to its terms?
Following an ‘analytics of devices’ (Amicelle et al., 2015), the study of policing practices in finance through the appropriation of lists implies to take note of their technical and functional features. In particular, the move to the digital changes the forms and potentialities of lists deployment. Contrary to the old-fashioned appropriation of paper lists, the daily use of digital lists depends on their combination with ‘high-tech’ devices such as list filtering software with a variety of algorithmic fine-tuning. Devices internal characteristics both enable and constrain end-users’ practices who try to domesticate them according to the meanings that they attach to their mission in banking policing.
Drawing on empirical research in the United Kingdom and India, the article argues that appropriation process both (re)configures the ‘social identity’ of the device of choice (lists) and end-users (banking actors)’ power relations. First, the appropriation process creates a dual identity for lists as both compliance and disciplinary devices, which impact power relations between banking actors and state authorities. As compliance devices, lists enable banking actors to protect themselves from their regulators. At the same time, however, as disciplinary devices, lists constrain banking actors to be further accountable vis-à-vis their regulators. Second, the appropriation process creates a dual identity for lists as both exclusionary and inclusionary devices, which impacts banking actors’ business relations. Their ways of operating lists contribute to include or exclude business partners according to a financial logic rather than (inter)national security purposes against crime and terrorism. Ultimately, lists appropriation sheds new light on what securing financial circulation means in practice.
To help understand the cross-colonization of finance and security through lists, we look at two differing (albeit partly overlapping) regulatory contexts in two countries in which the securing of financial circulation takes place: the implementation of targeted financial sanctions in the United Kingdom, especially on terrorism, and the implementation of KYC programmes in India against ‘dirty money’. On the one hand, the UK has been a founding member of the international policing-making body on money laundering and terrorist financing (Financial Action Task Force (FATF)) since 1989. Here, we look at the appropriation of ‘terrorists lists’ through their combination with filtering engines, algorithms and risk management methods. On the other hand, India is one of the newest members of the FATF with a membership in 2010. Here, we look at the appropriation of a variety of lists through their combination with other devices such as biometrics (Jacobsen, 2012) to implement KYC. The article draws on interviews conducted in both countries with providers of business services and compliance officers of UK, Indian and foreign banks, medium and global sized institutions. Local differences – in both narratives and user characteristics – and similarities are unpacked by studying the everyday actions of actors and their ways of operating lists.
Questioning lists as compliance and disciplinary devices
Implementing targeted financial sanctions in the UK
‘The term targeted financial sanctions means both asset freezing and prohibitions to prevent funds or other assets from being made available, directly or indirectly, for the benefit of designated persons and entities’ (FATF, 2013: 3). Since the 1990s, ‘targeted’ rather than ‘comprehensive’ sanctions have been used for a variety of objectives in relation to conflict prevention and resolution, democratization, human rights, non-proliferation, protection of population and so on and so forth. Moreover, the ‘economic weapon’ is part of a long tradition of unilateral and multilateral counter-measures to pressure an open-ended list of ‘pariahs’ (Elliott, 2010).
In keeping with that tradition, the prioritization of counterterrorism has produced, however, a transition from applying asset freezing measures primarily as a political measure against governments or persons linked to them (the original aim of most UN and EU sanctions regimes prior to 9/11) to freezing as a preventive measure, targeting terrorist individuals and groups. (European Council, 2004: 4)
This transition into preventive, or rather pre-emptive rationale has been the subject of in-depth studies that have enriched our understanding of the critical implications of counter-terrorism sanctions regimes (Guild, 2008; Hayes and Sullivan, 2011; Sullivan and De Goede, 2013). The vast majority of studies are focused on the tension between list-making processes and the rights of designated suspects while the daily use of lists for the freezing of funds has not been the subject of much analysis.
In the UK context, the asset freeze obligation for banking actors mostly refers to two supranational ‘terrorist lists’: first, the UN Al-Qaida/Taliban sanctions list pursuant to UNSC resolution 1267 (1999) and its successor resolutions; second, the European Union list pursuant to UNSC resolution 1373 (2001) and its successor resolutions. Both counter-terrorism regimes, like other targeted financial sanctions in the European Union, are managed under the Common Foreign and Security Policy for the EU (CFSP). Since 9/11, the private sector has been really aware that there are financial countermeasures related to CFSP because the fight against terrorism has become the biggest priority. I am not surprised that they began to send us their recommendations and complaints in 2002 and not in 1998, for instance. The CFSP was created in 1994 and the first sanctions were adopted in 1996 but the banks did not react. They reacted in 2002 when the topic became huge and they decided to protect their reputations.
5
Various sanctions lists, such as those dealing with Former Yugoslavia and Slobodan Milosevic or Afghanistan and the Taliban, existed before 11 September 2001. However, the EU and UN decisions adopted after 9/11 have had a stronger impact on banking actors than any other targeted sanctions regime.
Indeed, ‘terrorist lists’ were constantly updated – sometimes on a weekly basis – and extended, resulting in a threshold effect that challenged the previous ‘craft’ use of lists for transactions/accounts monitoring. Furthermore, asset-freezing obligations have been increasingly associated with a fear of non-compliance consequences, including legal, reputational and business damage. As a result, the banks’ initial modus vivendi has been progressively modified through the digitization of official lists. You need to imagine the chaos in relation to the first official lists in the 1990s, especially with the regulations on Yugoslavia. […] At the time, and this not a joke, European regulations were published and printed in Luxembourg. Then, they were sent to us [European banking association] and we forwarded them to our members [national banking federations] who forwarded them to their members [banks]. In short, there was an incredible loss of time and often a loss of information quality because of bad photocopies with incomplete information. […] At the end of 2001 and in the course 2002, banks lobbied to get an downloadable electronic list from European public authorities.
6
The ‘European electronic-consolidated targeted financial sanctions list’ (e-CTFSL) was established in June 2004 to provide a comprehensive, up-to-date and publicly available online database of listed parties. Fully funded by banks under the aegis of the European Commission, this ‘important new tool in the fight against terrorism’ has been promoted as ‘a very good example of an efficient public-private partnership project in the field of security policy’ (European Commission, 2004), although its legal force, as compared to paper lists published in the official journal of the European Union, is still unclear. Nevertheless, banking actors rely on the e-CTFSL and other equivalent consolidated lists on a daily basis, using them through a combination with filtering devices.
Among pioneering companies competing on the global filtering device market, FircoSoft has been regularly ranked as the ‘#1 watch list filtering solution’, with more than 770 customers, including ‘8 of the world’s top 10 financial institutions’ (Fircosoft, 2015). FircoSoft sells ‘a powerful filtering engine [that] determines in milliseconds if the transaction contains names, countries, companies, vessels or banking codes that match the blocked-parties lists selected’ (Fircosoft, 2015). The device aims at filtering banking customers and financial transaction against the selected lists. Once a ‘hit’ is detected, the flagged transaction is reviewed to see if it is a true match with a designated individual or entity. If it is, bank compliance officers are accountable for freezing the assets and reporting the operation to the relevant authorities. Most of filtering devices are ‘list independent’. They can operate with any kind of list at the same time, including all sanctions lists, PEP lists and so on and so forth. ‘For us, lists are files that we import into our small tool, which is the thing that deals with the soup. We put several ingredients in and we obtain the soup, which we filter’. 7 The visualization of lists is systematically recast through the digital lens of high-tech devices.
Although UN-related sanctions are legally designed and justified in the framework of international security, banking incentives for investing in filtering devices to use sanctions lists are primarily addressed in terms of financial security. Regardless any idealist involvement against terrorism, banking actors are rather sensitive to the FATF emphasis on ‘both the potential criminal and civil liabilities for non-compliance, as well as the reputational risks for financial institutions of being seen to be in breach’ (FATF, 2013: 14). FircoSoft representatives define their ‘mission’ along these lines, that is ‘to partner closely with our customers to provide them the greatest regulatory protection, by adapting [their] solutions to keep ahead of new regulations, thereby eliminating the risk of fines and reputational exposure’ (Fircosoft, 2015). UN stated goals for counterterrorism sanctions are systematically translated into compliance risk management to guard reputations by making it possible to show formal evidence of compliance.
To be compliant means satisfying regulators and ‘to satisfy regulators, all hits must be documented’ (Deloitte, 2009: 16). One of the main things also is really to stress the importance of documenting your decisions. If regulators come in to carry out a review and you haven’t got it documented on how you went through the process and how you made a decision, it’s a big problem.
8
In a similar vein, everything must be documented. When regulatory institutions arrive in your bank, you do reasonably well if you can explain what you’ve done. If you are no longer able to know why you’ve done something, this is the end because you cannot justify your acts.
9
The combination of lists with high-tech filtering equipment facilitates this task by helping to systematize documentation on every flagged transaction/client. Filtering devices are valued to the extent that they generate digital traces about all ‘hits’, which are recorded for ex post justification of decisions. In other words, they contribute to produce ‘just in case’ audit trails to make compliance visible, i.e. to make it possible for the regulators ‘to follow internal procedures and to scrutinize the decision-making processes of regulated financial institutions’ (Amicelle, 2011: 173). Thus, the banking appropriation of lists with filtering engines transforms them into compliance devices for procedural self-defence. However, the everyday usage of lists also backfires on their end-users who are both agents and targets of banking policing.
Indeed, banking actors live under the gaze of various state authorities, from financial services supervisors to financial intelligence units. By resulting in more detailed and systematic audit trails, the combination of digital lists with filtering engines fosters the internalization of such a regulatory gaze with disciplinary effects. The most interesting aspect of auditing is ‘the process by which the people concerned prepare for it, internalize it, fear it, and pre-emptively respond to the idea that they might be audited at some future time’ (Power, 2009: 2). Filtering engines are digital lenses to monitor banking customers as much as bankers. The banking appropriation of lists also transforms them into disciplinary devices which reconfigure power relationships between state authorities and banking actors. It formally allows a regulatory surveillance that is ‘permanent in its effects, even if it is discontinuous in its action’ (Foucault, 1975: 201). Paradoxically, the continuous movement of personnel from state authorities to banks compliance units supports rather than undermines the ‘social identity’ of lists as disciplinary devices. Indeed, the wide range of bank compliance officers coming from state agencies is very aware of this aspect. While a detailed description of differences between banks is beyond the scope of this paper, it is worth noting that the impact on financial practices may vary from one institution to the other. A bank is less a monolithic bloc than an internal system of tensions, including between (national and financial) security dynamics and business expectation in for-profit entities. What is an acceptable cost of doing business can also vary depending on the type and the size of banks. Compliance officers’ differing dispositions and organizational positions can alleviate or reinforce the disciplinary power of lists pairing with filtering engines.
In any case, banking actors are both perpetrators and victims of their own interpretation of security policies in finance. Their appropriation of lists and list-related devices enable them to appear compliant while it makes them more accountable and increase their ambivalent involvement in the securing of financial circulation. This pervading logic goes beyond targeted sanctions regimes. It relates to the whole apparatus of banking policing to the extent that filtering engines are only one part of the machinery used to identify, monitor and manage financial flows and banking customers in the UK and India. ‘The requirement to “Know your customer” [KYC] is a huge thing. With regard to our filtering solutions, we sell only one key of the KYC keyboard in the world’. 10
Implementing ‘know your customer’ programmes in India
Internationally, KYC programmes are seen as an essential part of banking policing, both for the FATF and the ‘Basel Committee’, i.e. the main international forum for cooperation on banking supervisory matters. The Basel Committee issued Customer Due Diligence for Banks in 2001, and further reinforced its framework with the General Guide to Account Opening and Customer Identification in 2003, in which KYC programmes were outlined. They provide the framework for account opening, proper identification of clients, ongoing monitoring of accounts identified as posing a financial security risk and risk management (Basel Committee on Banking Supervision, 2004). In recent years, KYC has become particularly important, as the banking sector in India is expanding to include customers from differing economic and social strata. In India, many individuals do not have any form of identification papers, such as birth certificates and many have not been officially ‘identified’ prior to becoming a customer of a bank, meaning that banks are now taking on the function of official registrar of individuals. Consequently, they play a variety of roles from making to using lists both for securing financial circulation and contributing to broader Indian state activities of population government.
KYC programmes are promoted to filter out illicit financial flows, preventing them from entering the system, or, excluding them when they are already part of the system. They are implemented through the combination of devices such as lists to help sustain the systemic fluidity of financial circulation by enabling efficient filtering of ‘good’ and ‘bad’ flows. The Reserve Bank of India (RBI) introduced KYC guidelines in 2002, and in 2004 banks were directed to ensure full compliance by 2005. 11 The guidelines of the RBI emphasize ‘necessary checks before opening a new account so as to ensure that the identity of the customer does not match with any person with known criminal background or with banned entities such as individual terrorists or terrorist organisations, etc.’ (Reserve Bank of India, 2011). At the time an account is opened, banks are obliged to screen the potential client’s name, location and other categories of identification against international terrorist lists. The banks are also expected to categorize the customer according to lists and risk criteria – whether the potential customer can be considered to be low, medium or high risk in terms of money laundering or terrorist financing – and to decide whether the category of the customer suggests that enhanced due diligence procedures are required, such as closer monitoring of accounts. If the customer is put in a category other than low risk such as high-risk individuals listed as ‘politically exposed persons’, the banks are obliged to carry out extensive due diligence checks (Reserve Bank of India, 2011). KYC implies ‘knowing’ the customer as well as having detailed information on his/her behavioural patterns. In India, most new private banks have a centralized Compliance Office where high-risk accounts are closely monitored, supplemented with local monitoring of customer behaviour, which is primarily done by relationship managers (RMs). The localized, branch-level bankers are closer to the customer and play an important role in the overall management of risk as they are mediators between customers and the centralized Compliance Office.
In the last few years, banks have been encouraged by the government and the Unique Identification Authority of India (UIDAI) to include biometric identification practices as part of the KYC process.
12
In 2013 the RBI recognized digital biometric IDs registered under the national biometric UID programme as ‘officially valid documents’ for compliance with Prevention of Money Laundering Rules. Banks were thus advised to obtain the infrastructure necessary to deal with biometric identification in what is called e-KYC. E-KYC is currently used by many Indian banks and is seen as a means to include those who are not using banks into the banking system, as well as ‘plugging leakages’ in subsidy payments (Times of India, 2014). It is expected that incorporating biometric devices in the KYC process will make it possible to record the ‘full audit trail’ of customers, including source of information, digital signatures, reference number, original request generation number, machine ID for device used to generate the request, date and time stamp with full trail of message routing, UIDAI encryption date and time stamp, bank’s decryption date and time stamp, etc. (Reserve Bank of India, 2013: 4)
The biometric device allows for algorithmic processing of individual data to compute whether the biometric sample of the individual customer and that of the list are a match. In other words, whereas the list is definite and actionable, the biometric device that allows for data-matching algorithms works in the background to feed and clean existing lists in terms of information, as well as filter entries to such lists (Johns, 2015: 2).
The inclusion of biometrics in the KYC process changes the conditions of possibility with regards to the lists. The move to digital form of individual records and the biometric identification of clients lead to a layered potential of filtering practices. Moving beyond checking individual clients against external lists, the combined governmental technique of ‘list-plus algorithms’ (ibid: 1) offers the potential for creating a variety of internal lists (risky clients, bad clients, good clients, favourable clients), as well as tracing the complete history and behaviour of clients. Lists appropriation is ultimately altered though the domestication of biometric devices in KYC programmes. This implies both a policing process – which includes various forms of customer monitoring – and a business process that allows the client to utilize services related to financial circulation. Customers categorized as ‘high risk’ are followed on a regular basis, and their accounts and behaviour are closely monitored. 13
From the banker’s perspective, KYC standards have gradually tightened, particularly over the past two to six years: ‘Prior to 2006 the accounts were not very well documented, and we did not have proper KYC practice’.
14
India has joined several international bodies in fighting terrorism through anti-money laundering measures. The terrorist attacks on India’s financial centre, Mumbai, in 2008 led to more severe policies being instituted with regard to banks and the financial sector. Five years back, before the Mumbai attacks, KYC norms were not stringent. In both cases [9/11 and the Mumbai attacks] much money was laundered for terrorist attacks. Earlier it was a one-time exercise but now the Reserve Bank of India on a periodic basis checks if a customer has a clean profile or has done money laundering.
15
As a result, bankers have become stricter about KYC compliance: Black money and illegal money may find its roots and flow into the financial system. All money can fund terrorist activities. This money should not flow into the financial system, that is why KYC is very important … other activities happen as a result of bad KYC, you do not know how money enters the system.
16
Regardless if stringent standards cause financial loss for the bank, bankers remain committed to applying them: If a bank is found guilty of these [fraudulent, money laundering] transactions then the bank risks heavy penalties, bad media coverage, and losing its license to operate. The risks are huge, that is why we are cautious, especially international banks.
17
National security dynamics against terrorism are embedded in banks’ everyday life in terms of financial security, with compliance and reputational risks as the dominant logic of organization, such as in the UK.
In India, the regulatory gaze, the ‘field of visibility’ with regard to KYC processes, is selective, which leads to certain actions being disciplined while others are allowed. According to bankers, private foreign banks are scrutinized more frequently and are penalized to a greater extent. ‘Norms are the same, but the practices are different, banks use different practices. KYC norms are more stringent in foreign banks’. 18 Foreign private banks are therefore more inclined to use a wide range of devices in order to comply with the regulations, whereas national public sector banks perform less stringent KYC procedures and are permitted to apply less restrictive norms. Here, the usage of multiple devices consisting of ‘list-plus-algorithms’ becomes essential for preventing large losses to the bank as a result of lack of compliance.
The threats posed by money laundering are understood to affect not only the state and the financial system as a whole, but also individual bankers and the bank establishment as such. The extensive KYC process undertaken through different devices also produces digital trails that can be scrutinized by auditors, meaning that the activities of both customers and bankers can be monitored. In recent years, the number of external audits of banks has increased, and such audits have been particularly stringent for foreign banks: ‘At external audits they check all parameters of security’. 19 The responsibility for preventing money laundering has increased the possibility that bank management, and the individual banker, will be subject to additional supervision. The audit trail makes it possible to trace whether the banker followed proper KYC procedure: ‘Suppose fraud happens. The person opening the bank account and signing/approving the form will be held responsible’. 20 The awareness that fraudulent accounts or transactions can be traced back to the individual banker who dealt with the customer makes bankers more cautious when dealing with customers in general and increases motivation to apply KYC standards. ‘If there is a single doubt, we have to verify’. 21 The bankers internalize the gaze of the supervising authorities. They then have to justify their own practices and make sure that their everyday performance complies with regulative standards.
Banking actors in the UK and India are on the side of both those who aspire to police finance and those whose conduct is the target of that policing. In both cases, they possess some degree of freedom, as security policies in finance rely on monitored self-discipline rather than radical coercion. They are not formally obliged to buy high-tech devices for using lists to operate targeted financial sanctions and KYC programmes. With the exception of lists, most of security devices are not legally binding in supranational regulations. The security policies in finance act through banks’ interests to financial security and bank compliance officers’ unease in relation to the potential adverse effects of non-compliance. None of the regulations said you had to have automated tools, but in order to have appropriate system of control, especially in the big retail environment, yes, you draw in that line. I’m relying on them [filtering devices], they’re providing regulatory protection to me.
22
It is a fairly non-contentious and accepted part of the literature that the massive investment banking actors have made in high-tech devices has been undertaken at least as much, if not more, to protect themselves from regulators as to protect the states and citizens from criminal and terrorists threats. The articulation of lists of suspicious and/or risky clients with other devices both helps the bankers to comply with regulations and the regulators to make banks more accountable through the disciplinarization of compliance officers. The dual identity of lists as compliance and disciplinary devices is only one part of the appropriation process. The next section explores how the use of a repertoire of devices for security policies in finance extends lists multiple ‘social identity’ as being also devices of exclusion and inclusion.
Questioning lists as exclusionary and inclusionary devices
The management of financial exclusion in the UK
Another constant challenge faced by financial institutions is verifying that a possible match is a true match with the specially designated individual or entity on a sanctions list. FATF should encourage all governmental authorities to provide sufficient resources to help financial institutions resolve questions about whether a subject is truly the entity or individual covered by the sanctions programme, and this should include a reasonable timeframe for resolving uncertainties. (International Banking Federation, 2011: 2)
‘False positives are potential matches to listed persons and entities, either due to the common nature of the name or due to ambiguous identifying data, which on examination prove not to be matches’ (FATF, 2013: 16). The issue of false-positives is a recurrent problematic with ‘terrorist lists’ but it also exists with other sanctions regimes and other lists. For example, do you know how many Charles Taylor we’ve got as customers? Some names come up and up and up, and the only way of doing it is to check every single one to make sure that he is not the Liberian Charles Taylor. It is very time-consuming: it has to be done manually. We also have an issue around recognition of Chinese characters as well with lists.
23
While the principle of filtering transactions and clients against lists is fairly simple, filtering in practice involves complex actions that must be taken in order to avoid untimely decisions. Sorting through even obvious false positives requires time and resources and is not foolproof. In July 2008, a global retail bank twice froze the weekly pay of a UK national of Zimbabwean birth when it was deposited into her local London bank account, because she shared a surname with the sanctioned Zimbabwean President Mugabe. (Deloitte, 2009: 8)
The daily number of alerts – automatically created by filtering devices – is so important for banks that there is usually a significant back-office unit whose function is entirely dedicated to eliminating as many false-positives as possible.
Fluidity and speed of financial circulation is an end in itself for banking actors who must therefore attempt to reduce the large number of false alerts that may slow down systemic ‘traffic flow’ in the financial system. ‘Resolving these questions and conflicts is important to avoid unnecessary disruption of international commerce and to avoid unfairly penalizing innocent parties’ (International Banking Federation, 2011: 2). From the perspective of banks, false-positives appear at least as threatening as listed suspects of terrorists, if not more. In this respect, the binary mode of list, which involves either presence or absence on the list, is adjusted to the contemporary turn to risk-based approach in banking policing. To obtain as few hits as possible, I always say that we begin with an enormous circle and the purpose of the game is not to cut the circle into two separate parts with completely crazy rules. The purpose of the game is to diminish its diameter by listing the risks we take. We take a risk each time that we diminish the diameter of the circle. Is the risk worth it? At least, the risk is controlled with the technological tools. There is may be less risk because it is controlled, because bankers know, because there are possibilities to check things afterwards. So, this is really the purpose of the game, it is really to reduce the circle with a clear view of the risks attached.
24
Like the idea of risk in numerous security studies (Boy, 2015), the risk-based approach ‘sold’ in banking policing appears somewhat misleading to the extent that the quote merely refers to the management of a form of non-probabilistic uncertainty. It needs to be understood in terms of governability rather than probability. ‘By utilizing a combination of artificial intelligence, fuzzy logic, and your choice of 33 algorithms, customers can adapt the behaviour of the filtering engine to match their risk appetite while keeping a very low false positive rate’ (Fircosoft, 2014b: 2). Risk-based schemes are combined with filtering devices to render list using, transactions screening and the issue of false-positives governable.
This quest for governability draws attention to the key role of algorithms in securing financial circulation, but from what? The metaphor of finding the needle in a haystack comes to mind here as current justification of security programmes with mass surveillance capabilities (Aradau, 2015). However, the increasing use of algorithms for big (financial) data filtering is less about finding the needle (targeted money) in a haystack (the financial system) than protecting the haystack from the destabilizing effects of needles detection practices. The risk-based approach is primarily implemented to deal with financial (security) risk rather than (national) security risk. With regard to their business partnership with the corporate bank Mizuho, FircoSoft representatives emphasize that once the [filtering] solutions were implemented, the next step was to work with Compliance and IT to implement rules and exceptions to reduce false positive hits. Approximately 170 exceptions and 60 rules were written by the team. After testing, with the rules in place, the system achieved Mizuho’s hit rate requirement. (2014c)
FircoSoft employees integrate each bank’s special characteristics within algorithmic design to secure financial circulation from false-positives rather than designated terrorist suspects. The promise of algorithms has less to do with unveiling terrorist money than avoiding any systemic slowdown of financial flows because of counter-terrorism measures. The means and goals of ‘terrorist lists’ usage are constantly redefined by banking actors to secure financial circulation from international security policies rather than international security ‘threats’.
Furthermore, the banking appropriation of lists often reflect a radical diversion of devices, that is ‘a form of appropriation or reinterpretation that may be regarded as resistance, generally on the part of agents involved in implementation, who grasp [the device] to master it for their own purposes’ (Le Bourhis and Lascoumes, 2014: 507). Beyond compliance, banking ways of operating lists and list-related devices are informed by broader purposes of business relationships management, unconnected with any terrorism issue.
For instance, the bankruptcy of Lehman Brothers was already known or at least anticipated in September 2008 when the German bank KfW sent (and lost) 300 million euros to the New Yorker investment bank (Kulish, 2008). While KfW was mocked for this multi-million dollar mistake, a wide range of global banks based in London were in almost the same situation. Their compliance officers therefore mobilized their repertoire of security devices to avoid similar errors and a loss of profit in connection with Lehman Brothers and other failed banks. They listed Lehman Brothers so that filtering practices would automatically stop any financial flows to the US bank. I mean, with the credit crunch and the Island banks issue, there are screening systems in banks which were used for sanctions and that were suddenly used to make sure that you protect your investors’ interests. Money wasn’t sent to banks which weren’t sanctioned but where we knew that if we sent anything the customer would have lost money, so the industry has started to use those [filtering] systems for other purposes … Other banks were in trouble. Lots of banks dealt with Island Banks and Lehman and the only defence was to try to stop the money going out, so people put those bank names on their filter systems and blocked the money.
25
From the perspective of national security, the aim of securing financial circulation was linked to formal requirements of banking policing for separating ‘good’ flows from ‘bad’ ones depending on official lists. The diversion process of security devices does not eliminate this sorting aspect. Instead, it rather broadens the definition of bad flows to cover and filter other categories than parties under official sanctions. We look for basically both the sanctioned ones and the names from let’s say the ‘bad boys’ lists, but again ‘bad boys’ lists are typically unique to organizations. They may be based on sharing names with other banks but typically we have our list, X has their list, Y has their list, and we don’t share.
26
Banks both make and use lists of natural and legal persons with whom they do not want to have business relationships for a variety of reasons (commercial, reputational, and so on). The merger of digitized lists with filtering devices is thus used to identify and exclude both designated suspects and unwanted clients in general. 27 Numerous compliance officers also add bank employees to lists to filter and monitor their business relationships and operations in order to prevent internal fraud. Here is a striking example of the performativity of lists to (re)configure a variety of business power relationships and (re)draw lines of exclusion. While the stated purpose of list-related devices is to comply with requirements of financial sanctions against specific ‘bad boys’, targeted possibilities are interpreted in a broader sense as a way of keeping the financial system clean from ‘bad’ clients, ‘bad’ partners and ‘bad’ employees. As exclusionary devices, digital lists and filtering lenses are adapted to each bank’s interests in order to implement, to varying degrees, Stanley Cohen’s definition of exclusion: ‘to create purified domains inhabited by just the right groups’ (1985: 234).
The management of financial inclusion in India
In India, the implementation of KYC programmes through lists appropriation also leads to the attempt to isolate clients categorized as suspicious or ‘bad’, as well as to a differential treatment of high-risk customers and the multiplication of formal and informal lists locally for business purposes. Indeed, KYC programmes are primarily directed to guiding bankers about what to consider when evaluating customers and considering their status against international sanctions and commercial lists, yet also extend to the bankers’ relationships with customers to the extent that banks form their own lists of preferable customers. It is expected that bankers will regulate customers, but also that they will, in their own everyday behaviour, follow certain regulations in their relationships with customers and relevant authorities. In the case of KYC processes through lists and list-related devices, a practice of ‘panoptic sorting’ (Gandy, 1993) is prevalent. Here, clients are sorted according to ‘categorical seduction’ (Lyon, 2007: 185), whereby those clients who are seen as highly profitable receive ‘first-class’ service and a closer follow-up by RMs, while low-risk clients are subject to more lenient KYC procedures.
As part of a banking environment that is undergoing a period of rapid transformation, Indian banks are adopting a consumer-oriented approach (Verma and Chaudhuri, 2008). KYC implementation makes it possible to filter customers into different categories, and lists as well as profiling devices can then be used to further differentiate clients. KYC programmes are making it possible to both include more customers in the banking system and to differentiate these customers into a broader range of categories. At the same time, the notion of ‘inclusion’ is becoming central to international anti-money laundering strategies. Including a large number of people into the formalized circulation of monetary flows is seen as a way to improve monitoring of international flows. This furthermore implies a more comprehensive sorting of ‘good’ and ‘bad’ flows through the extension of the number of persons on the one hand in the list of accepted customers of banks, and on the other categorized as risky in terms of money laundering or terrorist financing. Indeed, the FATF has launched several strategies for financial inclusion in order to bring the ‘bottom of the pyramid’ into the banking system. This interest in financial inclusion is officially framed in terms of financial security to the extent that it is driven by the FATF ‘objective of protecting the integrity of the global financial system, covering the largest range of transactions that pose money laundering and terrorist financing risk in the jurisdictions that have committed to the FATF Standards’ (FATF, 2011: 8). In this context, KYC programmes are used to sort new customers into categories according to risk criteria, in relation to both security and financial risk.
The drive towards financial inclusion has led to an increasingly wide adaptation of no-frills, low-risk accounts that require minimal KYC procedures. To make it possible to include the poorer sections of society, the procedures required to ‘know’ the customer are minimalized. Clients at the margin of the financial pyramid are being seduced into the system through various strategies, but it is expected that a large percentage of the newly ‘included’ will be classified as both low-risk and low-net-worth clients, and thus will not require follow up involving intensive monitoring of their accounts. The articulation between the list, and the background device of algorithmic calculation and filtering, thus form the basis for a complex sorting and profiling of clients according to risk criteria, which furthermore should make it possible to enlarge the range of population included in the formal banking system. Such machinery of inclusion is further enabled by the national biometric Unique Identification Number (UID) scheme, which is increasingly accepted as a valid KYC identifier for people lacking other forms of identification (Rathod et al., 2012).
The implementation of KYC programmes in India leads to the filtering and banning of clients considered to be either suspicious or not profitable for the bank, as well as to a sorting of lucrative and low-risk clients. If, over a long period of time, a customer does not comply with the requirements of the bank, such as keeping a certain minimum amount in their account, they are further designated as non-lucrative clients: ‘If customers are not profitable for the bank we filter them out’. 28 Risk assessments with the application of KYC processes also make it possible to single out potential high-value customers and provide them with preferential treatment. Such customers are seen not only as favourable but also as profitable: ‘Say a one crore customer, he is more profitable’. 29 Larger, international banks in particular therefore assign RMs to these customers. ‘Relationship Managers are given to the ones who have big money … out of a hundred customers, forty are good customers. The Relationship Manager will take care of them’. 30
Because of their assets, listed high-risk customers such as PEPs also tend to be the most lucrative customers of the bank. Thus, the need for special follow-up is two-fold: both to monitor flows for suspicious transactions and to care for and seduce the customer inventoried as desirable. This process therefore relates to both international sanctions lists (banning customer transactions) and internal lists of profitable customers (encouraging transactions). Both the beliefs and the everyday practices of bankers reflect the idea that a personalized relationship between the banker and the client is important not only for compliance with KYC requirements but also for the growth and profit of the bank. In the case of a suspicious transaction, the branch-level RM will contact the customer and is ultimately the mediator between a centralized Compliance Office and the customer. ‘As a responsible banker you have to watch; the software cannot do everything. It is more important to be alert, to do resident verification, to get original documents, and to know the customer well’.
31
Despite increasing pressure to adapt various high-tech devices and to rely on a computerized risk-based approach, Indian banks continue to value more informal meetings between RMs and high net-worth clients. This again leaves room for interpretation in the ways of appropriating securing devices for KYC processes. This implies on the one hand differential interpretation of international regulations regarding KYC depending on the client, as well as the creation of internal – and at times non-digitized – lists that bankers use in their everyday interaction with clients. Globally, there is a tremendous amount of competition for high-net-worth clients; these clients are treated deferentially, and it is easy to understand why a relationship manager may have a desire to make the relationship as comfortable as possible for the client - in the process perhaps suspending or not implementing the various anti-money laundering procedures. (Ruce, 2011: 551)
Conclusion
The appropriation process of any policy device contributes to destabilize its ‘social identity’ that is initially shaped by policy-makers (Crespin and Lascoumes, 2000). While the ‘List’ is primarily presented as the security device of choice in finance against crime and terrorism, it acquires multiple, simultaneous identities in the course of its banking appropriation with a reinterpretation of goals (from a compliance and disciplinary device to an inclusionary and exclusionary device). The emphasis on end-users shows the dynamic nature of devices ‘social identity’ depending on contexts, actors and purposes (Crespin and Lascoumes, 2000). At the same time, the process of ‘dialogue’ and reflection between a device and a specific space of activities also impacts this social space and its actors, beginning with the end-users’ practices and power relationships. Approaching security dynamics in finance through lists appropriation sheds new light on the twin and overlapping processes of securitization of finance and financialization of security.
On the one hand, the list mania in banking policing both makes the presence and management of terrorist and criminal issues material and operational in the field of finance. It thus entails ‘a kind of securitization of finance in which financial practices of all sorts have become subject to the surveillance and pressures associated with anti-terrorism [and anti-money laundering] techniques’ (Aitken, 2011: 126). Banking policing is to be seen as a two-way process in which the embedded constraints and enablements of lists and list-related devices contribute to police banking actors as much as banking customers. The security policies in finance put the former in the ambivalent situation of being both agents and targets of banking policing. The move to the digital and the combination of lists with high-tech devices both enable banking actors to show compliance while constraining them to be more accountable. From this perspective, the everyday appropriation of lists relays the calling up of responsible and disciplined financial actors in the name of international security with questionable effects.
On the other hand, banks appear to be ‘instrumental organizations’ in the context of policing to the extent that they are guided by objectives (counterterrorism and anti-money laundering) and means (lists and list-related devices) that are defined outside of them. As a consequence, there is a permanent attempt to redefine and make sense of external objectives and means in order to bring them into line with internal, professional interests. Both goals and devices of security are largely financialized, that is ‘made governable in terms of the logic and practices associated with the financial world’ (Aitken, 2011: 127). While various devices are adopted and combined to comply with banking policing requirements, they are also reappropriated in the mundane organization of business relationships according to a logic of financial profit. This financialization of security shifts the focus from the detection of pre-designated ‘bad boys’ to the internal inventory and management of good and bad business partners, with exclusionary and inclusionary effects in the financial system.
Ultimately, how does this cross-colonization of finance and security through lists frame the ways of securing financial circulation? As rightly noted by Nina Boy, ‘both of these developments – the securitisation of finance and the financialisation of security – can be seen as expressions of the demands posed by the central liberal problematic of securing circulation’ (2015: 8). However, both of these developments increasingly lead to diverging interpretation of what ‘securing financial circulation’ means. The implementation of counterterrorism asset-freezing mechanisms is a striking example of such a divergence of views. From the perspective of national security, securing financial circulation primarily means blocking the assets of targeted persons to protect the state and its citizens. From the perspective of financial security, securing financial circulation primarily means ensuring systemic ‘traffic flow’ of money to protect the financial system and its institutions. In practice, both perspectives aim at securing financial circulation but not necessarily from the same ‘threat’. While terrorism is identified as the main threat in the first perspective, counterterrorism is seen as threatening as terrorism, if not more, in the second perspective (i.e. with the issue of false-positives). In sum, the permanent tensions and adjustments between the fields of finance and security are crystallized around the appropriation of one particular security device, the ‘List’.
Footnotes
Acknowledgements
We wish to thank the anonymous reviewers and the guest editors for helpful comments on this article.
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: This article is related to the ‘DIGICOM: Communicating Risk in the Digital Age’ project supported by the Research Council of Norway.
