Chapter 6 · Other Financial Crimes

8 of 50 exam questions (~16%) · bribery + corruption · fraud · sanctions · tax evasion · market abuse · cybercrime
← Back to quiz
Why this chapter matters. 8 of 50 exam questions (~16%). Everything that isn't ML or TF. Trap zones: UKBA has NO facilitation-payment exception; FCPA has a narrow one (but modern enforcement discourages use), UKBA s.7 corporate offence — "adequate procedures" defence (6 principles), US OFAC reach = US person / USD / US-origin goods / US infrastructure, UK OFSI moved to STRICT LIABILITY June 2022, tax EVASION (criminal) vs AVOIDANCE (legal) vs PLANNING (fine) — CCO under CFA 2017 covers facilitation of evasion, MAR insider info test: precise · non-public · price-sensitive, off-channel comms (WhatsApp) enforcement wave — $2bn+ in fines since 2022.

6.1 Bribery + corruption — UKBA, FCPA, adequate procedures

UK Bribery Act 2010 — the four offences syllabus 1.1

SectionOffence
s.1Offering / promising / giving a bribe (active)
s.2Requesting / agreeing / accepting a bribe (passive)
s.6Bribery of foreign public officials
s.7Corporate offence — failure of commercial organisation to prevent bribery

Max individual sentence: 10 years imprisonment + unlimited fine. Corporate: unlimited fine + reputational damage + potential public-contract exclusion.

UKBA s.7 — the corporate "failure to prevent" offence syllabus 1.2

The most significant innovation of the UKBA: strict-liability corporate offence where an associated person (employee, agent, subsidiary) bribes to secure business for the firm.

Only defence: "adequate procedures" to prevent bribery — see §1.3.

Extraterritorial reach: applies to any organisation that carries on business (or part of business) in the UK, regardless of where the bribery took place.

Adequate procedures — the six principles syllabus 1.3

Ministry of Justice guidance on the s.7 defence sets out six principles:

  1. Proportionate procedures — risk-based, proportionate to size + risk
  2. Top-level commitment — board + senior management visibly committed
  3. Risk assessment — periodic, documented
  4. Due diligence — on associated persons (third parties, agents)
  5. Communication + training
  6. Monitoring + review

These principles are also the template for the s.7 defence pattern replicated in the CFA 2017 tax CCO and the ECCT 2023 failure-to-prevent-fraud offence.

US Foreign Corrupt Practices Act (FCPA) 1977 syllabus 1.4

Two prongs:

  1. Anti-bribery — prohibits offering / paying anything of value to foreign officials to obtain / retain business
  2. Accounting — books + records + internal controls requirements (applies to SEC issuers)

Enforced by: DOJ (criminal) + SEC (civil, for issuers). Extraterritorial reach: US persons + US issuers + foreign persons acting within US territory. Recent enforcement often via Deferred Prosecution Agreements (DPAs).

UKBA vs FCPA — key differences syllabus 1.5

AspectUKBAFCPA
CoveragePublic + private sectorForeign public officials only
Facilitation paymentsNOT permittedNarrow exception (limited to small routine payments)
Corporate strict-liabilitys.7 offencePiercing corporate veil case-by-case
"Adequate procedures" defenceYesCompliance programme = mitigation, not defence
Extraterritorial reachAny UK-nexus businessUS persons + US-issuer accounting
Trap: UKBA has NO facilitation-payment exception. FCPA has one (narrow, and modern enforcement discourages use). Global firms typically apply UKBA-level standards (no facilitation payments anywhere).

Gifts + hospitality controls syllabus 1.6

Modest gifts + hospitality aren't automatically bribery — but firms need controls to distinguish. Typical policy features:

  • Value threshold (e.g. ≤£100 per gift / occasion) below which pre-approval not required
  • Pre-approval required above threshold
  • Absolute prohibition on gifts/hospitality to/from public officials during decision-critical periods (tender, licensing, regulatory review)
  • Register of gifts + hospitality received / given
  • Enhanced controls for higher-risk relationships (foreign officials, key clients)

6.2 Fraud — categories, APP scams, ECCT

Fraud — the categories syllabus 2.1

UK Fraud Act 2006 — three principal offences (s.1):

  1. Fraud by false representation (s.2)
  2. Fraud by failing to disclose information (s.3)
  3. Fraud by abuse of position (s.4)

Common typologies:

  • Payment fraud (card fraud, cheque fraud)
  • Investment fraud (Ponzi, boiler room)
  • Identity fraud
  • Insurance fraud
  • Mortgage fraud
  • Business email compromise (BEC) — see §6.6
  • Internal fraud (see §6.2 below)

APP scams — the UK response syllabus 2.2

Authorised Push Payment (APP) scams — customer is deceived into authorising a payment to a fraudster (impersonating bank, police, HMRC, contractor, romantic interest).

Scale: UK Finance reported £485m stolen via APP scams in 2022, £460m in 2023 — persistent large-scale problem.

Regulatory response — PSR mandatory reimbursement effective October 2024:

  • Payment firms (both sending + receiving) must reimburse victims (subject to caps + limited defences)
  • Reimbursement cap: £415k per claim (raised from initial £85k proposal)
  • Consumer standard of caution defence (limited)

UK ECCT 2023 — failure-to-prevent-fraud syllabus 2.3

Economic Crime and Corporate Transparency Act 2023 introduces a new corporate offence: failure to prevent fraud committed by employees / agents for the organisation's benefit. In force Sept 2025.

Scope: large organisations only — meets 2 of 3 tests:

  • >250 employees
  • >£36m turnover
  • >£18m total assets

Defence: "reasonable procedures" (identical pattern to UKBA s.7 + CFA 2017 CCO). See [[Ch 7]] for the full ECCT summary.

Internal fraud — rogue traders syllabus 2.4

Historic mega-losses from internal fraud (rogue traders):

  • Barings Bank — Nick Leeson · $1.4bn · 1995 (bank collapse)
  • Société Générale — Jérôme Kerviel · €4.9bn · 2008
  • UBS — Kweku Adoboli · $2.3bn · 2011
  • JPMorgan London Whale — Bruno Iksil · $6bn · 2012

Common root causes: inadequate segregation of duties, weak trade-cancellation controls, management pressure for returns, ignored risk alerts, back-office short-cuts.

6.3 Sanctions — OFAC, OFSI, screening

Sanctions violation — key risk exposure syllabus 3.1

Sanctions breaches typically produce the largest enforcement fines in financial crime:

  • BNP Paribas — $8.9bn · 2014 (Sudan, Cuba, Iran)
  • HSBC — $1.9bn · 2012 (Mexico + Iran/Sudan)
  • Commerzbank — $1.5bn · 2015
  • Standard Chartered — multiple settlements ~$1.7bn
  • Binance — $4.3bn · 2023 (Iran, Cuba, Syria, DPRK)

US OFAC extraterritorial reach syllabus 3.2

OFAC sanctions apply to any transaction touching:

  1. A US person (citizen, resident, US entity)
  2. The US dollar (cleared through US correspondent banks)
  3. US-origin goods or technology
  4. US financial infrastructure

This is why global banks obsess about US sanctions — a wire cleared in USD pulls US jurisdiction even where neither party is US-connected. BNP Paribas' $8.9bn 2014 fine had no US party in the transactions themselves.

UK OFSI — strict liability from June 2022 syllabus 3.3

The Office of Financial Sanctions Implementation (OFSI) moved to strict-liability civil enforcement in June 2022 — under the Economic Crime (Transparency and Enforcement) Act 2022.

Impact: no need for OFSI to prove that the firm knew or had reasonable cause to know it was breaching sanctions. Mere factual breach can trigger a monetary penalty.

Raised enforcement risk substantially — post-Russia, firms need robust screening + governance around sanctions decisions.

Trap: candidates often assume UK sanctions enforcement requires intent / knowledge. Not since June 2022 — strict liability applies civil-side. Criminal offences still require mens rea, but civil monetary penalties don't.

Sanctions evasion typologies syllabus 3.4

Post-Russia (Feb 2022) has taught the industry the modern evasion playbook:

  • Third-country routing — via Turkey, UAE, Kazakhstan, Kyrgyzstan (import re-export)
  • Shell company networks — layers of front companies
  • Ship-to-ship transfers + flag hopping — for oil, coal
  • Alternative payment mechanisms — crypto, gold, informal value transfer
  • Deceptive shipping practices — disabled AIS, false certificates of origin
  • Family + close-associate proxies — designated person's relatives

Sanctions screening — the list universe syllabus 3.5

Firms must screen against multiple lists:

  • UN — Consolidated List (binding globally)
  • OFAC SDN — Specially Designated Nationals (US)
  • OFSI Consolidated List — UK
  • EU Consolidated Sanctions List
  • Country-specific autonomous lists (Australia DFAT, Canada, Japan, Switzerland)
  • Adverse-media + PEP data (industry vendors: World-Check, Dow Jones, LexisNexis, ComplyAdvantage)

Screening must be at onboarding, at each list update, and typically real-time on transactions.

6.4 Tax evasion — vs avoidance, CCO, CRS

Evasion vs avoidance vs planning syllabus 4.1

ConceptLegal statusExample
Tax evasionCriminal offenceUndeclared cash income · false expense claims · offshore hidden accounts
Tax avoidanceLegal but often disapprovedAggressive schemes to reduce tax within letter of law
Tax planningLegal + acceptedISAs, pensions, allowances, legitimate structures

The line between avoidance and evasion has narrowed — modern anti-avoidance rules (GAAR in UK, DAC-6 in EU) target aggressive schemes even where technically legal.

UK CFA 2017 — CCO tax offence syllabus 4.2

Criminal Finances Act 2017 introduced the Corporate Criminal Offence (CCO): failure of a corporate to prevent facilitation of tax evasion by an associated person.

Two CCOs:

  1. Failure to prevent facilitation of UK tax evasion
  2. Failure to prevent facilitation of foreign tax evasion (subject to dual criminality)

Defence: "reasonable prevention procedures" (same six-principles pattern as UKBA s.7 + ECCT).

Practical: covers any employee or agent who facilitates a customer's evasion — banks, accountants, lawyers, tax advisers all in scope.

CRS — automatic tax information exchange syllabus 4.3

Common Reporting Standard (CRS) — OECD 2014 framework for automatic exchange of financial account information between tax authorities. Signed by 110+ jurisdictions.

Financial institutions report:

  • Account holder name + tax residency (self-certified)
  • Account balance + income (dividends, interest, sale proceeds)
  • To the local tax authority, which shares with the tax authorities of the holder's residency

Key point: US does NOT participate in CRS — the US uses FATCA (bilateral treaties + 30% withholding tax on non-compliant FFIs).

Trap: FATCA and CRS overlap but are different. FATCA = US-specific, withholding-tax teeth. CRS = OECD, multilateral, no withholding. US does not participate in CRS.

6.5 Market abuse — MAR, insider dealing

Market Abuse Regulation (MAR) syllabus 5.1

EU / UK Market Abuse Regulation (MAR) covers three main behaviours:

  1. Insider dealing — trading on inside info
  2. Unlawful disclosure — leaking inside info
  3. Market manipulation — false signals, price manipulation, benchmark manipulation

Enforced in UK by FCA (civil) + prosecuted for criminal cases via CJA 1993 s.52 + FSMA. Max criminal sentence 7 years.

Insider information — the 3-part test syllabus 5.2

Information is "inside" if it is:

  1. Precise — specific enough to allow conclusions about price impact
  2. Non-public — not generally available
  3. Price-sensitive — likely to have significant effect on price if made public

All three must be met. Rumour + gut feel isn't inside info; a specific unannounced acquisition is.

Off-channel communications enforcement syllabus 5.3

Since 2022, US regulators (SEC + CFTC) have levied over $2bn in fines on firms for failing to preserve WhatsApp / text / personal-device business communications. Notable settlements:

  • JPM 2021 — $200m (early landmark case)
  • 10+ major banks · Sept 2022 — $1.8bn combined
  • Additional waves 2023-24 — spread to buy-side firms

Root cause: MAR + record-keeping rules require preservation of business communications. Employees using personal devices bypassed firm surveillance + record-keeping. UK FCA parallel enforcement expected.

6.6 Cybercrime + cyber-enabled fraud

Modern cybercrime typologies syllabus 6.1

  • Business Email Compromise (BEC) — impersonation of executive/vendor to redirect wire transfers
  • Ransomware — encryption + extortion; typical demands in crypto
  • Account takeover — credentials stolen via phishing / infostealer malware
  • Deepfake / synthetic media fraud — voice/video impersonation of executives
  • SIM-swap fraud — bypass SMS 2FA
  • Supply-chain attacks — MOVEit, SolarWinds (2020) — enterprise-scale

Ransomware — the sanctions overlay syllabus 6.2

Complexity: many ransomware groups (LockBit, Conti, BlackCat) are US-designated OR linked to sanctioned jurisdictions (Russia, DPRK). Paying ransom can be a sanctions violation.

OFAC 2020 Advisory: paying ransom to a designated person may violate sanctions even where paid via intermediary — mitigating factor if firm engaged law enforcement, but no safe harbour.

6.7 Ch 6 cheat sheet

All the numbers + names

ItemAnswer
UKBA offences4 · s.1 · s.2 · s.6 · s.7
UKBA s.7 defenceAdequate procedures (6 MoJ principles)
UKBA max sentence10 years imprisonment · unlimited fine
UKBA facilitation paymentsNOT permitted
FCPA prongsAnti-bribery + accounting (books/records)
FCPA facilitation exceptionNarrow · discouraged
FCPA enforcersDOJ (criminal) + SEC (civil, issuers)
Fraud Act 2006False rep · fail to disclose · abuse of position
APP reimbursementPSR mandatory · Oct 2024 · £415k cap
ECCT failure to prevent fraudIn force Sept 2025 · large orgs
Rogue trader lossesBarings · SocGen · UBS · JPM Whale
OFAC reachUS person / USD / US goods / US infrastructure
UK OFSI strict liabilityJune 2022
Sanctions listsUN · OFAC SDN · OFSI · EU · country-specific
CFA 2017 CCOFailure to prevent facilitation of tax evasion
CFA 2017 defenceReasonable prevention procedures
CRSOECD · 110+ jurisdictions · automatic tax info
FATCAUS · bilateral · 30% withholding
US in CRS?NO — US uses FATCA
MAR behavioursInsider dealing · unlawful disclosure · market manipulation
Inside info testPrecise · non-public · price-sensitive
UK insider dealing (CJA 1993)Max 7 years
Off-channel comms fines$2bn+ since 2022 (SEC/CFTC)
BECBusiness Email Compromise (impersonation fraud)
Ransomware sanctionsPaying designated group = sanctions risk (OFAC 2020 Advisory)
Next: Ch 7 — Recent Developments. Or jump to the cram sheet.