21 Analytics’ Post

View organization page for 21 Analytics, graphic

3,166 followers

#1 Operational Risk for EU Banks? Cyber & Data Security ⚠️ Why should compliance teams at VASPs care?    📋The EBA recently published the spring edition of its risk assessment report (RAR), noting that European banks face their biggest operational risks in cyber and data security. ❗ Cyber-attacks, including successful ones, are on the rise.  Over half of EU-assessed banks stated they had 𝗯𝗲𝗲𝗻 𝘃𝗶𝗰𝘁𝗶𝗺𝘀 𝗼𝗳 𝗮𝘁 𝗹𝗲𝗮𝘀𝘁 𝗼𝗻𝗲 𝗰𝘆𝗯𝗲𝗿-𝗮𝘁𝘁𝗮𝗰𝗸 in the second half of 2023! 🏦 EU banks are not alone — 𝗩𝗔𝗦𝗣𝘀 𝗮𝗿𝗲 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗹𝗲 𝘁𝗼 𝘁𝗵𝗲 𝘀𝗮𝗺𝗲 𝗿𝗶𝘀𝗸𝘀 and may use these insights to inform their priorities and IT choices. 📋 Enhancing cyber and data security will be mandatory under the Digital Operational Resilience Act (DORA) starting in 2025. Still, it is clear that the risks to the entity and its customers are real and relevant right now. 🔗 𝗧𝗵𝗲 𝘀𝘁𝗮𝗸𝗲𝘀 𝗮𝗿𝗲 𝗲𝘃𝗲𝗻 𝗵𝗶𝗴𝗵𝗲𝗿 𝗳𝗼𝗿 𝗩𝗔𝗦𝗣𝘀, 𝗲𝘀𝗽𝗲𝗰𝗶𝗮𝗹𝗹𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗰𝗼𝗻𝘁𝗲𝘅𝘁 𝗼𝗳 𝘁𝗵𝗲 𝗧𝗿𝗮𝘃𝗲𝗹 𝗥𝘂𝗹𝗲, since the sensitive data collected and exchanged can uncover a greater amount of financial detail than the VASP holds due to the visibility of a person's activities on the blockchain. 🔐 Hence, keeping bank-grade 𝗰𝘆𝗯𝗲𝗿 𝗮𝗻𝗱 𝗱𝗮𝘁𝗮 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗹𝗲𝘃𝗲𝗹𝘀 𝘀𝗵𝗼𝘂𝗹𝗱 𝗻𝗼𝘁 𝗯𝗲 𝗮𝗻 𝗮𝗳𝘁𝗲𝗿𝘁𝗵𝗼𝘂𝗴𝗵𝘁 for any process that touches sensitive data, which is the case of Travel Rule compliance. 👁️🗨️ This is best achieved by keeping PII within the financial entity, as adding a third-party provider impacts transparency on how this sensitive data is handled, stored and deleted. 🔹 Finally, risks related to customers’ transactions received from or sent to jurisdictions subject to international sanctions remain the most relevant financial crime risks for banks. The Travel Rule aims to solve this exact need for VASPs. 🔹 Although most firms focus on the collection of data from their customers and rely on VASP networks for vetting counterparties, the key for compliance teams 𝘁𝗼 𝗺𝗶𝘁𝗶𝗴𝗮𝘁𝗲 𝗳𝗶𝗻𝗮𝗻𝗰𝗶𝗮𝗹 𝗰𝗿𝗶𝗺𝗲 𝗿𝗶𝘀𝗸𝘀 𝗶𝘀 𝗸𝗻𝗼𝘄𝗶𝗻𝗴 𝘆𝗼𝘂𝗿 𝗰𝗼𝘂𝗻𝘁𝗲𝗿𝗽𝗮𝗿𝘁𝗶𝗲𝘀 through proper due diligence. Ensuring transactions only occur with vetted and trusted firms. 🔹 Banks, mining companies, and VASPs who take data protection seriously opt for an on-premises Travel Rule solution, like 𝟮𝟭 𝗧𝗿𝗮𝘃𝗲𝗹 𝗥𝘂𝗹𝗲. ✅ Choosing an on-premises solution allows you:  - to decide when data is physically deleted and data protection obligations are fulfilled;  - be independent and not rely on the provider's availability and uptime to complete transactions; - prevent additional risks and points of failure. 💡 If you are concerned about the data risks Travel Rule compliance adds to your operations, talk to us and learn why we differ from the alternatives.

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics