Revolut's lost USD20 million shows up a flaw in the "global" approach to money laundering.

Revolut has made no statement about this story. So what we have is gleaned from a single report in the Financial Times which has been widely re-written by many media outlets. This article isn't about the loss per se. It's about a much bigger problem revealed by the limited facts that can be relied upon reveal.
Shock - fintechs have business bank accounts. Those accounts are subject to monitoring for e.g. money laundering and terrorist financing purposes.
Fintechs are required to monitor their transactions for the same purposes.
But, these systems are defined and controlled by the regulators in each country. Therefore, companies are guided towards systems to meet and comply with the requirements of domestic regulators where they operate.
Also, there is increasing pressure from regulators to, and in some jurisdictions plans to legislate for, banks (in particular) to monitor accounts for fraud on customers. Most jurisdictions require banks, in particular, to report to regulators instances of fraud where the bank is the victim. But, again, these systems are local, not global.
So how come no one noticed that Revolut was the victim of a USD20 million fraud? The simple answer is that no one was looking for a fraud of the type that was used.
The fraud, to simplify it, arose because of what Revolut call "a flaw" but the rest of us would call a mistake in their payment systems. Where credit card transactions were declined, Revolut issued a refund into the cardholder's Revolut account which would then be drained.
The refunds were made from Revolut's own funds. This, when one thinks about it, is how it should be.
Revolut's own media section carries only good news and makes no mention of this fraud and all facts currently "known" arise from a re-write, in many media outlets, of a story in the Financial Times which says it comes from multiple anonymous sources. So let's not trouble ourselves too deeply with the most of the facts.
The one that interests us is this: none of the fraudulent transactions were picked up by transaction monitoring.
Revolut found out about the problem when one of its banks told them that an account was overdrawn by USD20 million, ish.
By that time, news of the opportunity had circulated outside the company and criminals (it's said organised crime but that term may be used loosely) found that if they made credit card purchases for large amounts that would be declined, Revolut would credit accounts with funds that could be, in FinTech language, "cashed out."
Suspicious transaction reporting, internationally, within all financial services businesses, is notoriously poor - and often for good reason: jurisdictions don't like the pooling of information across borders, even within the same group of companies. And so the data to help Revolut identify the mis-match was probably not available in one place, providing an overview of all sides of the transactions. If the data isn't there, no amount of human or electronic surveillance or audit will identify relevant transactions.
No amount of domestic regulation or compliance can prevent this kind of problem unless international groups can and do have full, unrestricted, access to all KYC, risk and transactional data.


