[#]: http://www.justice.gov/opa/documents/hsbc/dpa-attachment-a.p...
[#]: http://www.justice.gov/opa/documents/hsbc/dpa-attachment-a.p...
I can't see that anywhere in the link.
"HSBC Bank USA knowingly set the thresholds in CAMP so that wire transfers by customers located in countries categorized as standard or medium risk, including foreign financial institutions with correspondent accounts, would not be subject to automated monitoring unless the customers were otherwise classified as high risk."
The document outlines a pattern of decisions by high level HSBC executives -- ranging from individual transgressions such as simply falsifying or sanitizing otherwise illegal transactions, to more long-term choices, such as ignoring basically everyone else in the industry as you mentioned earlier, and systematically under-resourcing compliance departments -- that led the bank to appear to comply with AML laws and regulations when in reality it was flagrantly violating them.
In fact, it is a crime to fail maintain an effective AML program if you are a bank, and HSBC does not dispute that they committed this crime.
From the document, page 3:
7. The Department alleges, and HSBC Bank USA admits, that HSBC Bank USA’s conduct, as described herein, violated the BSA. Specifically, HSBC Bank USA violated Title 31, United States Code, Section 5318(h)(1), which makes it a crime to willfully fail to establish and maintain an effective AML program, and Title 31, United States Code, Section 5318(i)(1), which makes it a crime to willfully fail to establish due diligence for foreign correspondent accounts.
The problem with AML laws is that they are so vague, it's impossible to ever really be sure you're in compliance. They turn banks into a privatised police force. How much effort should they make? Governments won't tell. They just say "be sensible about it". Banks hate this, as would you in their position, they want clarity about what to do, but governments don't want to give them a list of boxes to tick because they feel it'd be too slow and inflexible to keep up with criminals.
See the problem? Banks invest VAST sums in AML compliance. They develop automated software to spot suspicious transactions, they have massive internal compliance departments, they ID verify all their customers. It's a huge, huge drain (which is passed on to all of us, of course). But how much is enough? As far as the Justice Department is concerned, there can never be enough. Whilst criminals exist, it must mean failures of compliance by banks.
14. HSBC Bank USA maintained correspondent accounts for a number of foreign financial institutions, including HSBC Group Affiliates, within its Payments and Cash Management (“PCM”) business. HSBC Bank USA was required under the BSA to conduct due diligence on all foreign financial institutions with correspondent accounts, including HSBC Group Affiliates.
15. Despite this requirement, from at least 2006 to 2010, HSBC Bank USA did not conduct due diligence on HSBC Group Affiliates for which it maintained correspondent accounts, including HSBC Mexico. The decision not to conduct due diligence was guided by a formal policy memorialized in HSBC Bank USA’s AML Procedures Manuals.
...
17. From 2006 to 2009, HSBC Bank USA knowingly set the thresholds in CAMP so that wire transfers by customers located in countries categorized as standard or medium risk, including foreign financial institutions with correspondent accounts, would not be subject to automated monitoring unless the customers were otherwise classified as high risk. During this period, HSBC Bank USA processed over 100 million wire transfers totaling over $300 trillion. Over two-thirds of these transactions involved customers in standard or medium risk countries. Therefore, in this four-year period alone, over $200 trillion in wire transfers were not reviewed in CAMP.
18. Between 2000 and 2009, HSBC Bank USA, and its executives and officers, were aware of numerous publicly available and industry-wide advisories about the money laundering risks inherent to Mexican financial institutions. These included:
a. The U.S. State Department’s designation of Mexico as a “jurisdiction of primary concern” for money laundering as early as March 2000;
b. The U.S. State Department’s International Narcotics Control Strategy Reports from as early as 2002 stating with regard to Mexico that “the illicit drug trade continues to be the principal source of funds laundered through the Mexican financial system. . . . The smuggling of bulk shipments of U.S. currency into Mexico and the movement of the cash back into the United States via couriers, armored vehicles, and wire transfers, remain favored methods for laundering drug proceeds. Mexico’s financial institutions are vulnerable to currency transactions involving international narcotics- trafficking proceeds that include significant amounts of U.S. currency or currency derived from illegal drug sales in the United States. . . . According to U.S. law enforcement officials, Mexico remains one of the most challenging money laundering jurisdictions for the United States.”;
c. The April 2006 Financial Crimes Enforcement Network Advisory concerning bulk cash being smuggled into Mexico and deposited with Mexican financial institutions (discussed in paragraph 22 below);
d. The federal money laundering investigations that became public in 2007-08, involving Casa de Cambio Puebla, a Mexican-based money services business that had accounts at HSBC Mexico, and Sigue, a U.S.-based money services business, that had accounts at HSBC Mexico; and
e. The federal money laundering investigation into Wachovia for its failure to monitor wire transactions originating from the correspondent accounts of certain Mexican money services businesses, known as casas de cambio (“CDCs”), which became public in April 2008.
All of these advisories or events were known to numerous HSBC Bank USA AML officers and business executives at or near the time they occurred.
19. Despite this evidence of the serious money laundering risks associated with doing business in Mexico, from at least 2006 to 2009, HSBC Bank USA rated Mexico as standard risk, its lowest AML risk category. As a result, wire transfers originating from Mexico, including transactions from HSBC Mexico, were generally not reviewed in the CAMP system. From 2006 until May 2009, when HSBC Bank USA raised Mexico’s risk rating to high, over 316,000 transactions worth over $670 billion from HSBC Mexico alone were excluded from monitoring in the CAMP system.
> 17. From 2006 to 2009, HSBC Bank USA knowingly set the thresholds in CAMP so that wire transfers by customers located in countries categorized as standard or medium risk, including foreign financial institutions with correspondent accounts, would not be subject to automated monitoring unless the customers were otherwise classified as high risk.
> 18. Between 2000 and 2009, HSBC Bank USA, and its executives and officers, were aware of numerous publicly available and industry-wide advisories about the money laundering risks inherent to Mexican financial institutions. These included:
> 19. Despite this evidence of the serious money laundering risks associated with doing business in Mexico, from at least 2006 to 2009, HSBC Bank USA rated Mexico as standard risk, its lowest AML risk category.
In other words, HSBC executives ignored industry guidance of the money laundering risks in Mexican institutions, and continued to rate the country as "standard risk", a rating which did not require monitoring in the CAMP system. They knowingly set the thresholds based on that rating, and they knew about the industry guidance, but the government has absolutely zero evidence that they set the rating with intent to facilitate money laundering.
From point 16, CAMP is the "Customer Account Monitoring Program" automated system which monitors wire transfers.
-> Therefore, HSBC Bank USA knowingly took "active steps to disable specific automated countermeasure."
Point 19 "Despite this evidence of the serious money laundering risks associated with doing business in Mexico, from at least 2006 to 2009, HSBC Bank USA rated Mexico as standard risk, its lowest AML risk category. As a result, wire transfers originating from Mexico, including transactions from HSBC Mexico, were generally not reviewed in the CAMP system." (Point 18 establishes that "Between 2000 and 2009, HSBC Bank USA, and its executives and officers, were aware of numerous publicly available and industry-wide advisories about the money laundering risks inherent to Mexican financial institutions")
-> Therefore, HSBC willfully disabled specific automated countermeasures.
=> Combine these two "therefore"s, and you'll see that milkshakes's statement is confirmed.
Or look at points 64-66, which establishes that HSBC Bank plc bypassed the automated system which detects funds transfers involving a Sanctioned Entity. They would put a "cautionary note in their SWIFT payment messages" the the messages would "[fall] into what HSBC Europe termed a “repair queue” where HSBC Europe employees manually removed all references to the Sanctioned Entities." HSB know about this since 2000, and their compliance group spoke up about it in 2003.
=> So there were at least two automated systems where "specific automated countermeasures" were "knowingly and willfully" bypassed.
These weren't all that hard to find - I looked for the word "automated".
What the USG is saying here is they think HSBC should have been treating internal HSBC-to-HSBC transfers as high risk and reviewing them all. But this doesn't make much sense for a single company. The lack of it certainly cannot be equated to a deliberate "disabling" of controls.
With respect to the repair queue, this is due to America's insane approach to sanctions - a transfer from country A to country B where there are no sanctions on B in A, that happens to get routed via a US bank, would have sanctions applied, despite that no laws were being violated by either party to the transaction. In order to work around this brain damage EU banks routinely edited ("repaired") wire transfers to avoid hitting the Great Firewall of America, safe in the knowledge that they were not violating any sanctions laws where they lived.
Later, the US decided that jurisdiction was such a bothersome concept they decided that anyone who made a transfer to Iran, anywhere, regardless of local laws at the time, was guilty of money laundering. See also: Standard Charter.
I don't think people here seem to realise the general backstory here. The US Government lies all the time. They routinely get innocent people to plead guilty without any kind of trial by threatening them with absurdly over-harsh penalties. The HSBC case is a classic example of this dynamic in action.
That is, that HSBC agrees that the information provided by the State Department, the April 2006 Financial Crimes Enforcement Network (“FinCEN”) Advisory, the money laundering lawsuits involving two of their customers, etc. from #18, and that this is "evidence of the serious money laundering risks associated with doing business in Mexico, in #19.
You cannot go from "well defined" to "entirely subjective". There are points in between, and to argue otherwise is bad style.
"this doesn't make much sense for a single company" - technically these are different companies, though some are wholly owned by others. That aside, some internal HSBC-to-HSBC transfers were illegal: "From at least 2000 through 2006, HSBC Group knowingly and willfully engaged in conduct and practices outside the United States that caused HSBC Bank USA and other financial institutions located in the United States to process payments in violation of U.S. sanctions."
Now, you're absolutely right that this is an "insane approach to sanctions." (We've switched from Mexico to the Middle East, btw, but that doesn't make a difference.) But you've just argued that communications with HSBC Mexico to HSBC Bank USA were a "single company", so it's a bit disingenuous to say that HSBC Europe is not part of the same company.
There's a nasty problem with jurisdiction, yes, but there are legal ways to resolve it. For one, stop doing business with US banks. But few want to do that, and the SWIFT network (and Snowden's disclosure of documents of how the US is systematically undermining the SWIFT-agreement) make it a gnarly process to completely disentangle from the US.
What you said is different. You wrote "EU banks routinely edited ("repaired") wire transfers to avoid hitting the Great Firewall of America, safe in the knowledge that they were not violating any sanctions laws where they lived." But point #67 says that "HSBC Group Affiliates intentionally hid the practice of amending payments involving Sanctioned Entities from HSBC Bank USA. As a result, during the relevant time period, HSBC Bank USA and other financial institutions in the United States processed hundreds of millions of dollars in transactions involving Sanctioned Entities in violation of U.S. sanctions."
You are right - they didn't break the law where they lived. But according to the statement of facts, you are also wrong - they sent transfers through the "Great Firewall of America", and caused HSBC Bank USA to break US law by not being able to provide the required compliance.
Regarding Standard Chartered, the London-based bank sent the funds through its New York unit, which is how both US and New York laws applied. It's not the case that the US was suing a foreign bank with no US ties.
"The US Government lies all the time. ... They routinely get innocent people to plead guilty without any kind of trial by threatening them with absurdly over-harsh penalties"
While the first is certainly true (see previous, with the US undermining the SWIFT agreement), that doesn't mean it's true all the time, or appropriate for this case. Again, technically this is a statement of facts agreed upon by both sides, and not one-sided accusations from the government.
Which leads to the second half of what I quoted from you. The US could be threatening to shut down HSBC Bank USA should they not comply, and this is the best HSBC could do under the circumstances. The reason I disagree with you here is that HSBC has plenty of legal, political, and economical resources to defend themselves against flagrantly false accusations.
Standard Chartered, for example, doesn't say that they were innocent. Their defense is that there were only $14 million which did not comply with the U-turn regulations. (This was an initial number. The final judgment after investigation was $133 million.). They paid a $674 million fine, which is about 5x of the $133 in prohibited transactions or 10x of the original $14m. BTW, the original USG claim was that "as much as $250 billion" was laundered.
In other words, no, this doesn't seem like a "classic example of this dynamic in action." The classic examples are for people with no resources, poor legal defense, and a judge that doesn't care. Not HSBC where a fine of $1.9 billion represents 5 weeks of profit.