Reputational Risk Archives - Thomson Reuters Institute https://blogs.thomsonreuters.com/en-us/topic/reputational-risk/ Thomson Reuters Institute is a blog from 抖阴成年, the intelligence, technology and human expertise you need to find trusted answers. Fri, 17 Jul 2026 15:14:18 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.6 Lessons learned from the ACAMS/抖阴成年 Human Trafficking Initiative at the World Cup /en-us/posts/human-rights-crimes/acams-thomson-reuters-human-trafficking-initiative-world-cup/ Fri, 17 Jul 2026 14:21:10 +0000 https://blogs.thomsonreuters.com/en-us/?p=71757 Key insights:
      • Collaboration is the strongest enabler of detection 鈥 Financial institutions are most effective at identifying human trafficking when they work closely with NGOs, law enforcement, and regulators, combining financial intelligence with victim-centered and investigative insights.

      • Data, technology, and AI can uncover trafficking networks 鈥 By analyzing financial transactions alongside open-source intelligence, social media activity, public records, and specialized datasets, organizations can identify patterns, relationships, and high-risk accounts more efficiently.

      • Financial institutions have a critical role in disrupting trafficking 鈥 Because human trafficking depends on moving and laundering illicit profits, banks and other financial institutions can help stop it by detecting suspicious activity, filing targeted reports, and supporting law enforcement investigations.


Human trafficking is not only one of the most devastating financial crimes but also one of the most complex as it cuts across fraud, money laundering, and organized crime, with some crime rings use their existing drug trafficking networks for human trafficking-related crimes.

Financial institutions are in a unique position to help battle this scourge as they can see the financial flows generated from human trafficking and sexual exploitation. Without the ability to launder the proceeds, human trafficking as a crime would lose some of its appeal.

To understand this better, a multi-city initiative around the FIFA World Cup, co-led by 抖阴成年 and , brought in leaders from financial institutions, law enforcement, non-governmental organizations (NGOs), regulators, and corporate risk departments to address human trafficking from a financial crime perspective.

Indeed, as research shows, forced labor in the private economy generates as much as $236 billion in , according to the International Labour Organization. If financial institutions can identify the proceeds of traffickers and their patterns, however, they can close suspected accounts, file prioritized suspicious activity reports, and notify law enforcement to help put a quicker end to this terrible problem.

The use of data and technology

Unfortunately, financial institutions often lack the context and the data points to act with certainty. These data points often include the names of victims, their behaviors, and their relationships with traffickers and can provide important clues about the origins and methods of human trafficking, including locations and transportation patterns. NGOs can help in this area; and such NGOs as the and already are providing critical, victim-centered insight.

In addition, NGOs often build datasets and proprietary content on their own to uncover trafficking. , for example, maintains a large, proprietary dataset that鈥檚 built from network metadata and behavioral signals collected from publicly accessible online environments. This data is then analyzed into real鈥憈ime intelligence, such as risk scores and activity patterns, which helps law enforcement identify and prioritize suspected child exploitation offenders.


Traffickers use social media platforms, online ads, and messaging apps to recruit victims and to advertise illicit services, often leave a digital footprint that can be analyzed, which enables law enforcement and analysts to identify victims, map relationships between illicit actors, detect recruitment patterns, identify locations, and uncover entire trafficking networks.


Other relevant information sources include the Illicit Massage Business (IMB) database from 抖阴成年 Special Services, which includes business accounts, the location, and the owner of every massage parlor in the US, in which trafficking victims are forced to operate.

Because traffickers use social media platforms, online ads, and messaging apps to recruit victims and to advertise illicit services, they often leave a digital footprint that can be analyzed. This enables law enforcement and analysts to identify victims, map relationships between illicit actors, detect recruitment patterns, identify locations, and uncover entire trafficking networks. This information can then be enhanced by combining it with public records and data from the open web, deep web, and dark web.

Learning the lessons of collaboration

As we at the ACAMS鈥摱兑醭赡 Human Trafficking Initiative looked back at the lessons learned and reviewed best practices, we can see that any success in identifying illicit trafficking accounts is based on three factors: i) close cooperation with law enforcement and NGOs; ii) specialized investigative resources with human trafficking backgrounds; and iii) the use of data and open-source intelligence, either standalone or integrated into monitoring workflows.

Financial institutions understand their role and the need to obtain specialized data and expertise; and leveraging these capabilities typically results in the termination or de-risking of suspicious accounts.

Because collaboration with law enforcement is not consistent across financial institutions, particularly in the US, this means that overall, there鈥檚 a very uneven focus on human trafficking detection and prevention, depending on the availability of resources and the level of collaboration.

The role of regulators, like the U.S. Treasury Department鈥檚 , is crucial because these entities can leverage AI to act even more rapidly and connect information quicker, which can help disrupt human trafficking more effectively. Investigators are instructed to make a specific selection, field 38(h), when filing a report and include a specific reference to human trafficking. This will allow FinCEN to analyze and identify patterns, trends, and trafficking networks by linking these reports together.

In that context financial institutions have another reason to embrace AI within their customer data. By analyzing transactions and other patterns of risk using all available data sources and building agentic capabilities and workflows within their own customer data, financial institutions will be able to better identify high-risk accounts without carrying out labor-intensive investigations.

While this event series focused on the 2026 World Cup, human trafficking existed long before the tournament and will not stop once it concludes. However, if NGOs, authorities, and financial institutions can significantly improve their ability to detect and disrupt it, that would represent a major step forward.


You can find out more about how law enforcement and others are disrupting human trafficking networks here

]]>
Why Section 301 tariffs won’t go away so fast /en-us/posts/international-trade-and-supply-chain/section-301-tariffs/ Wed, 08 Jul 2026 14:01:09 +0000 https://blogs.thomsonreuters.com/en-us/?p=71651

Key insights:

      • Sect. 301 and IEEPA tariffs operate on fundamentally different legal foundations 鈥 The IEEPA tariffs flow from an executive emergency declaration that can be unwound overnight, while Sect. 301 findings are built on a formal evidentiary record that can survive numerous administrations.

      • Those manufacturers that diversified away from China now face compounded exposure 鈥 The countries to which many manufactured moved their trade operations 鈥 including Vietnam, India, Bangladesh, and Malaysia 鈥 are now named in the recent Sect. 301 action.

      • Managing this complexity without purpose-built tools is no longer realistic 鈥 The need for access to quality vendor data, tariff classifications, country-of-origin mapping, and duty layering requires systems that can be updated continuously, not spreadsheets that are reviewed quarterly.


Since early 2025, manufacturers have lived in a tariff environment defined by volatility that鈥檚 been dictated seemingly at the whim of the United States. Rates announced one week were paused the next, country-specific deals emerged from diplomatic calls, and 90-day exemptions became the operating rhythm. For supply chain teams, the rational response was to treat every new tariff as provisional 鈥 something to monitor, not necessarily something to plan around.

That logic does not apply to the of the U.S. Trade Representative (USTR), under听Section 301 of the Trade Act of 1974听that a list of 60 economies 鈥 comprising the largest US trading partners 鈥 had failed to enforce a ban on goods produced with forced labor听are therefore were听restrictive to US trade.

To understand why, it actually requires and how it compares to the International Emergency Economic Powers Act (IEEPA), which the Trump Administration had used as its authority behind the 2025 reciprocal tariffs until that was disallowed .

Unlike the IEEPA, Sect. 301 is not an executive power that turns on or off depending on when a national emergency is declared. Rather, it is a statutory framework that requires the USTR to conduct a formal investigation, gather evidence, hold public hearings, and build a record before making an actionability determination. In the June 2 action alone, the USTR received testimony from nearly 60 witnesses and almost 500 public comments before issuing its findings.

That record matters, because it is what makes tariffs issued in response to Sect. 301 findings structurally resistant to reversal. Unwinding them requires either a new formal determination, a negotiated bilateral resolution in which the trading partner actually changes its practices, or Congressional action. A new administration cannot simply issue a presidential order lifting them because the legal bar is categorically higher.

And this distinction is no longer theoretical. After the Supreme Court ruled his tariffs invalid, President Trump immediately pivoting to Section 122 of the Trade Act of 1974, which permits a temporary global surcharge of up to 15% for no more than 150 days. That took effect February 24, and is set to expire July 24, unless extended by Congress. Tariffs imposed because of the June 2 Sect. 301 findings were never exposed to the same legal vulnerability and is now the administration’s primary vehicle for building durable tariff authority.

There is also a political dimension that compounds the durability. The June 2 findings are grounded specifically the failure of the named economies to prohibit the importation of goods made with forced labor. That framing carries broad bipartisan support in Washington, and neither party is positioned to argue against forced labor prohibitions, which means the political incentive to reverse these tariffs is far weaker than it was for the IEEPA-based tariffs.

The compounded exposure problem

For manufacturers that spent 2024 and 2025 diversifying their supply chains away from the tariff-heavy China, the June 2 findings create a specific and uncomfortable problem. The most common destinations for that diversification 鈥 Vietnam, Bangladesh, India, Malaysia, Thailand, and Indonesia 鈥 are all named in USTR’s recent action. Proposed additional duties of 10% to 12.5% would layer on top of existing duties and any Sect. 122 tariffs still in place during the transition period.

In other words, the move that looked like risk mitigation then may now carry its own tariff exposure now 鈥 and unlike the situation in 2025, there is no obvious alternative jurisdiction.

That means vendor management systems that integrate tariff data in real time 鈥 pulling current duty rates by code, flagging country-of-origin changes, modeling landed cost across multiple sourcing scenarios 鈥 are no longer a competitive advantage. Now they are a baseline operational requirement. The same applies to supplier compliance documentation. As forced labor attestations become relevant to exclusion eligibility under Sect. 301, having those records organized, current, and accessible is not an audit-readiness question, rather, it鈥檚 a cost-of-goods question.

Then, the practical challenge for manufacturers becomes an operational one, not just a strategic one. Tracking tariff exposure across dozens of suppliers, multiple countries of origin, layered duty structures, and evolving classification rules is not a task that can be easily scaled with traditional tools. For example, in the 24 hours following the Supreme Court鈥檚 tariff ruling, the US terminated one tariff regime, enacted a replacement under a different statute, and announced the launch of multiple new Sect. 301 investigations. A manufacturer鈥檚 spreadsheet that鈥檚 updated monthly cannot keep pace with a regulatory environment moving at that speed.

The durable lesson

The IEEPA tariff experience trained supply chain teams to stay nimble 鈥 and then demonstrated exactly how fragile executive-action tariffs can be when the Supreme Court invalidated them. That instinct toward flexibility still has value, of course; however, the Sect. 301 framework requires a parallel capability that requires manufacturers to recognize when a tariff is structural, model its long-term cost impact, and adapt sourcing and vendor strategies accordingly.

These new Sect. 301-based tariffs are not a negotiating position waiting to be resolved. They are a legal determination, built on a formal record, grounded in a cause 鈥 the elimination of forced labor from global supply chains 鈥 that has strong consensus across the political spectrum.

Those manufacturers that plan around them as permanent while investing in the tools to manage that complexity in real time will be better positioned than those waiting for the next exemption announcement.


You can find out more about how tariffs continue to impact global trade here

]]>
Red cards and red flags: What AML professionals need to know during the World Cup鈥檚 final weeks /en-us/posts/corporates/world-cup-aml-professionals/ Thu, 02 Jul 2026 13:50:09 +0000 https://blogs.thomsonreuters.com/en-us/?p=71636

Key insights:

      • Financial institutions on the frontlines of trafficking prevention 鈥 As the 2026 World Cup continues, it puts financial institutions on the frontlines of detection and prevention of human trafficking, whether they are in a host city or not.

      • US government has offered guidance 鈥 FinCEN’s updated Section 314(b) guidance, issued June 12, gives institutions explicit authority to share fraud and trafficking-related information with each other, and strongly encourages them to do so.

      • Cross-sector collaboration is essential 鈥 Organizations like The Knoble are building the cross-sector collaboration infrastructure that makes that kind of information sharing operational, not just theoretical.


The 2026 FIFA World Cup is, by every measure, the largest sporting event ever staged on North American soil, drawing 3.6 million spectators through its early weeks and generating billions of dollars in economic activity 鈥 that level of transaction volume that would strain any risk & compliance team on its best day.

The World Cup and its millions of international visitors also are creating the very conditions that human traffickers are always eager to exploit.

It is a pattern that researchers, law enforcement, and financial crime professionals have documented around major global events for years. And it is precisely why, as the World Cup enters its most dramatic final weeks, compliance teams at financial institutions of every size are treating this moment as the operational inflection point it is.

The World Cup as a financial ecosystem

Most people associate the World Cup with soccer and international competition; yet for compliance professionals, it also represents a full financial ecosystem of its own that they have to navigate.

Julie Conroy, a leader at , a nonprofit founded in 2019 to bring together financial services and law enforcement to combat human trafficking, financial scams, elder financial exploitation, and child sexual exploitation, is direct about threat compliance teams face. “All of these big, massive global events bring together lots of people,鈥 Conroy says. 鈥淎nd that makes it very easy for the criminals鈥 to hide their human trafficking.”

Of course, the financial footprint of that activity runs through the banking system, through peer-to-peer transfers, prepaid card activity, late-night ATM withdrawals, unusual hotel charges, or vague payment memos reading “services” or “personal care.” None of these transactions are inherently suspicious in isolation; yet together, as a pattern layered across time and accounts, they can signal exploitation in real time.

FinCEN’s recent guidance changed the calculus

On June 12, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued clarifying how financial institutions can share information with one another about suspected fraud, money laundering, and other financial crimes under Section 314(b) of the USA PATRIOT Act.


The World Cup and its millions of international visitors also are creating the very conditions that human traffickers are always eager to exploit.


The guidance is both a clarification and a signal. It explicitly confirms that institutions may share information about suspected trafficking-related activity with any other financial institution eligible to participate in the 314(b) program. It broadens the categories of shareable information to include video surveillance footage, cyber-related data such as IP addresses, and behavioral fraud indicators such as newly added payees followed by large transfers, multiple accounts with similar identifying information, and login activity from geographically distant locations.

framed the urgency plainly: “Financial institutions are often the first to see suspicious activity in real time. They need the tools to act quickly and share information that can help stop fraud before it spreads.”

For human trafficking detection specifically, this matters because no single institution sees a complete trafficking network. One bank might observe the late-night ATM pattern, another might flag the prepaid card activity, and a third might notice the unusual payroll behavior of a temporary staffing company supplying event workers. Individually, those fragments are insufficient; however, when shared, they become actionable intelligence.

“Now we can share data among ourselves for fraud prevention purposes 鈥 which is amazing,鈥 Conroy notes.

The collaboration infrastructure already exists

The regulatory green light from FinCEN is necessary but not sufficient on its own. Effective information-sharing requires relationships, operational frameworks, and trust that take time to build. That is the gap The Knoble was created to close.

The organization has spent six years building the bridges between financial institutions and law enforcement that make inter-agency collaboration real rather than aspirational. That work is harder than it sounds due to personnel changes and departments that operate in silos. The Knoble’s member network is designed to outlast those structural challenges by creating a durable community of practice around financial crime detection.

“The amazing thing that The Knoble has been able to do is bring together banks and law enforcement, build those bridges between the two of them, and give a guide to banks about what are the red flags,” Conroy explains.

, which was developed in anticipation of the tournament, reinforces what FinCEN’s guidance also makes clear: Trafficking rarely presents itself through a single dramatic transaction. Investigators need to identify clusters of behavior across time, look at shared devices and phone numbers, and track rapid movement of funds across accounts. The behavioral anomaly, not the individual transaction, is the signal.


Every suspicious activity report filed, every bit of information shared, and every frontline employee who escalates an unusual interaction contributes to an intelligence picture that law enforcement can act on immediately, while victims are still at risk.


However, perhaps the most consequential misconception in AML and fraud around the World Cup right now is that human trafficking is a host-city problem.

Trafficking networks are geographically distributed by design. Victims may be recruited in one state, transported to and exploited in a host city, and their proceeds moved through financial institutions located elsewhere. That means that a regional bank in Kansas City or a credit union in a midsize market with no World Cup connection can still observe funnel account activity, unusual prepaid card funding, or suspicious peer-to-peer transfers tied to a network operating hundreds of miles away.

Training is not optional

FinCEN’s guidance also makes clear that transaction monitoring systems cannot address trafficking issues alone 鈥 a financial institution鈥檚 frontline staff matter.

Tellers, branch employees, and customer service representatives are often in a position to observe indicators that never appear in an alert queue. A customer who appears fearful, cannot speak freely, or gives answers that seem scripted. These behavioral signals and more require trained human observation.

That鈥檚 why these frontline professionals are so important. Every suspicious activity report filed, every bit of information shared, and every frontline employee who escalates an unusual interaction contributes to an intelligence picture that law enforcement can act on immediately, while victims are still at risk. This is critical, because human trafficking is happening in real time, and the transactions that compliance teams are observing are occurring while the exploitation is ongoing.

Conroy frames The Knoble’s mission in exactly these terms. The organization exists to take financial professionals who are already passionate about stopping human trafficking and other crimes and mobilize them within their day-to-day work.

Now, as the World Cup enters its final weeks, the question now is whether compliance teams will continue to treat this moment as an operational priority by using the collaboration tools and the regulatory guidance at their disposal to make a crucial difference in the lives of trafficking victims.


For more on this, tune into the Thomson Reuters Institute鈥檚 recent 鈥淐larity鈥 podcast

]]>
De-banking in the US: Why objectivity and process are non-negotiable /en-us/posts/corporates/de-banking-financial-institutions/ Mon, 29 Jun 2026 14:04:02 +0000 https://blogs.thomsonreuters.com/en-us/?p=71585

Key insights:

      • De-banking reasons have to be articulated and verifiable 鈥 De-banking that鈥檚 driven by category avoidance rather than individual risk assessment, exposes institutions to legal, regulatory, and reputational harm and pushes legitimate customers out of the regulated financial system.

      • A screening flag is not a conclusion 鈥 Proper investigation must follow any identified red flag before any de-banking decision is made.

      • Political considerations have no place in de-banking decisions 鈥 The only defensible standard is documented, individualized risk analysis that would be applied consistently not matter the customer.


De-banking 鈥 or the involuntary removal of a customer from financial services 鈥 has moved from a compliance back-office concern to a front-page issue. Members of Congress have called for hearings.; advocacy groups representing small businesses, cryptocurrency firms, firearms dealers, and faith-based organizations have filed complaints; and financial institutions, often caught between genuine compliance obligations and growing pressure to justify their de-banking decisions, are operating in an environment with significant legal and reputational exposure on both sides.

Banks have the legal right to exit customer relationships, of course; however, what is in dispute is whether the decisions driving those exits are defensible. Are they grounded in documented, individualized risk analysis? Or are they being shaped by broad category avoidance, reputational anxiety, or political considerations that have no formal basis in law?

Getting this wrong is not a minor procedural failure; rather, it鈥檚 a legal exposure, a regulatory liability, and, increasingly, a legislative headache.

Objectivity requires removing politics from the process

The de-banking debate did not emerge recently. During , the U.S. Department of Justice (DOJ) initiative began in 2013, the government applied pressure on banks to exit relationships with industries it found undesirable, including payday lenders and firearms dealers, without formal legal prohibition.

The episode revealed a structural vulnerability: Financial institutions are susceptible to removing customers not because individual accounts present documented risk, but because external pressure, political or otherwise, has labeled entire categories of customers inconvenient. (The DOJ ultimately acknowledged the program was in August 2017.)


Banks have the legal right to exit customer relationships, of course; however, what is in dispute is whether the decisions driving those exits are defensible.


Yet, that pattern has persisted in subtler forms. Today, cannabis businesses operating legally under state law, money services businesses, crypto exchanges, and organizations associated with politically sensitive causes routinely report being dropped from banking relationships with little explanation and no apparent individualized analysis. The common thread is not confirmed financial crime, rather it鈥檚 membership in a certain category of enterprises.

In , President Trump issued an Executive Order titled “Guaranteeing Fair Banking for All Americans,” directly addressing this pattern and directing federal banking regulators to remove “reputation risk” and other subjective criteria from supervisory guidance and examination materials.

This is precisely where objectivity becomes a legal and operational imperative, not just a principle. A risk-based de-banking or off-boarding process must apply the same documented criteria to every customer, regardless of industry association, political affiliation, or public profile. When an institution debanks one customer for activity it tolerates in another, the inconsistency itself becomes the liability. have long reinforced that risk-based compliance means evaluating customers on their own merits, and that blanket policies applied to industries rather than individuals do not satisfy that standard.

Screening raises questions, and investigation answers them

One of the most consequential errors that financial institutions make is treating a screening alert as a final determination rather than a starting point. Know your customer frameworks, customer due diligence requirements, governmental watchlists, adverse media flags, and transaction monitoring alerts are tools for identifying accounts that warrant closer review. By themselves, they are not grounds for termination.

The gap between a flag and a confirmed risk finding is where decisions 鈥 both defensible and indefensible 鈥 are actually made. An adverse media hit on a business owner may reflect a decade-old civil dispute that has no bearing on current account activity. A transaction pattern that triggers a monitoring alert may have a straightforward, documented business explanation. Enhanced due diligence exists precisely because some customers require deeper analysis before a meaningful risk determination can be made.


A risk-based de-banking or off-boarding process must apply the same documented criteria to every customer, regardless of industry association, political affiliation, or public profile.


A sound investigation process includes several elements that are often absent in practice, such as documented escalation paths from front-line staff to BSA officer to legal review; a genuine opportunity for the customer to respond to concerns before a decision is finalized; findings recorded in writing with sufficient specificity to withstand external scrutiny; and a proportionality review requiring the institution to evaluate whether risk mitigation short of termination is viable before defaulting to de-banking.

The stakes extend well beyond any single customer relationship

Financial institutions often treat de-banking as a discrete internal risk decision; however, the aggregate effect of category-based de-banking carries systemic consequences that regulators and legislators are increasingly unwilling to overlook.

When categories of legitimate customers cannot access banking services, the burden falls hardest on those with the fewest alternatives. Equally important, pushing customers out of the regulated financial system does not eliminate risk; instead, it relocates it to less transparent channels in which illicit activity is harder to detect and report.

Three states 鈥 Florida, Tennessee, and Idaho 鈥 have already enacted fair access laws requiring that financial institutions make services available based on objective risk criteria. And more than a dozen additional states have proposed . At the federal level, the would require larger banks to provide services based on quantified, documented risk standards.

Practical steps for financial institutions

Institutions need to build defensible, consistently applied processes as the foundation for any de-banking decision. There are several steps they can take, including:

      • Audit current de-banking criteria for political and categorical language 鈥 Review existing off-boarding policies for any language that excludes industries or customer types based on perceived political sensitivity or reputational association rather than documented risk.
      • Establish a neutrality standard in all de-banking decisions 鈥 Require that every de-banking decision be traceable solely to facts in the customer file. External pressure, government signals, and industry headlines should play no role in the determination.
      • Separate screening from decision-making 鈥 Build a formal investigation step between any monitoring alert or red flag and a de-banking decision. Document what was reviewed, who reviewed it, and what the findings support.
      • Create a customer response mechanism 鈥 Where legally permissible, provide customers with an opportunity to respond to concerns before a final decision is made. Record whether and how that response was considered.
      • Establish a proportionality review 鈥 Before exiting a relationship, require a written determination that any other risk mitigation, including enhanced monitoring, transaction limits, or additional documentation requirements, was evaluated and found insufficient. Document everything.

As regulatory scrutiny around de-banking decisions intensifies, financial institutions can no longer treat it as a routine internal decision. The path forward demands consistent, well-documented, and objectively applied processes that stand up to legal, regulatory, and public scrutiny. Institutions that embed neutrality, transparency, and proportionality into their decision-making will not only reduce risk but also will strengthen trust in the financial system as a whole.


You can find more about the challenges facing financial institutions here

]]>
Modern slavery: Government funding for enforcement is key to prevention /en-us/posts/human-rights-crimes/modern-slavery-prevention/ Mon, 15 Jun 2026 17:00:39 +0000 https://blogs.thomsonreuters.com/en-us/?p=71262

Key highlights:

      • Plans without funding are political theater, not strategyAcross the G20 and beyond, governments spend about $1 per vulnerable person per year, making the most comprehensive national action plans functionally undeliverable.

      • Corporate forced labor is a crime with no perpetratorsDespite an estimated tens of millions of victims in global supply chains, there has been only one forced labor investigation ever brought against a Fortune 500 company, exposing a near-total absence of criminal accountability in non-financial industries.

      • Real-time data accountability can work on a shoestring budgets 鈥 Uganda’s TipMap platform, built on a budget of just hundreds of thousands of dollars with NGO and US government support, demonstrates that transparent, publicly accessible prosecution tracking is achievable even for low-income countries 鈥 yet most wealthy nations have yet to replicate this model.


Every year, governments around the world publish sweeping national action plans to combat modern slavery, covering everything from vulnerable children, forced labor, and gender-based violence to prosecution targets and victim support. These action plans are, in many cases, genuinely comprehensive documents, and also in many cases, they are almost entirely unfunded.

That is the central finding of the (MSPI), a new tool developed by Duncan Jepson, Director of Strategy and Operations at . After decades working across supply chains, corporate law, and financial crime compliance in Asia, Jepson grew frustrated with a sector that was generating more conferences and consultants than criminal prosecutions. The MSPI takes a step back from that ground-level work and asks how governments are investing in this problem at a scale that matches their stated ambitions.

The answer, unsurprisingly, is that there is a big gap between plans and funding the execution of those plans. Across the G20 plus additional countries, total government spending on modern slavery prevention amounts to roughly $1.6 billion annually, Jepson notes. When measured against the estimated population of up to 2 billion people living in conditions of poverty and precarity that make them vulnerable to exploitation, the 鈥渋nvestment鈥 by governments works out to approximately $1 per person per year.

Grand plans & empty coffers

The MSPI evaluates governments across four dimensions, which include the context of exploitation within their borders, the comprehensiveness of their national action plan, the funding allocated to that plan, and the measurable outcomes produced. The gap between the second and third dimensions is the point at which the analysis reveals the most confounding gap.

Most national action plans, Jepson notes, look remarkably similar regardless of whether they come from wealthy nations or some of the poorest countries in the world. They include all the right elements; however, the problem is that the ambition of the plan rarely maps onto available resources. “If you see a similar kind of plan in a country which is not providing anywhere near the same investment, maybe only providing $10 million to $20 million,” then they’re clearly not going to be able to build the kind of institutional mechanisms and have them operational to achieve their stated ends, Jepson explains.


When measured against the estimated population of up to 2 billion people living in conditions of poverty, the 鈥渋nvestment鈥 by governments works out to approximately $1 per person per year.


This gap is partly a result of how these plans get written. Policy teams include every desirable outcome, every population group, and every intervention type because comprehensiveness signals seriousness. The result is what Jepson describes as a political product rather than a strategic one because it is detached from realities of resource constraints.

The three Ps framework 鈥 set out in the , which organizes anti-trafficking efforts around prevention, protection, and prosecution 鈥 has drifted from being a planning tool into being a target in itself. Governments check the boxes, publish the plan, and treat that as a win. The actual investment required to deliver outcomes becomes secondary.

Many perpetrators face no accountability

Perhaps the most sobering element of Jepson’s analysis concerns corporate accountability which, outside of healthcare and financial services, is extremely limited for criminal matters such as forced labor. Modern slavery in global supply chains, particularly forced labor in agriculture, manufacturing, fishing, and extractive industries, generates enormous profits. Prosecutions against the corporations involved are nearly nonexistent.

The , which Jepson brought to the U.S. Department of Homeland Security鈥檚 investigations unit a few years ago, remains a rare landmark. When he received a World Customs Organization award for the work, the citation described it as recognition for “the first investigation into a Fortune 500 company.鈥 Indeed, the fact that there is only one successful investigation in the entire history of Fortune 500 enforcement on forced labor is stunning in itself.

The structural reason for this, Jepson argues, is that non-financial industries operate without a criminal legal framework wrapped around their regulatory obligations. Banks are required to identify suspicious transactions, file reports, and de-risk clients connected to illicit activity, all under threat of serious legal regulatory consequence.


Modern slavery in global supply chains, particularly forced labor in agriculture, manufacturing, fishing, and extractive industries, generates enormous profits, while prosecutions against the corporations involved are nearly nonexistent.


Manufacturers, food producers, and commodity traders face no equivalent pressure. Their obligations tend to be framed in the language of sustainability and ethical sourcing, which are voluntary, subjective, and entirely company controlled.

When violations are discovered, the response is typically managed internally through grievance mechanisms, remediation programs, and consultant-led audits. Workers rarely have access to independent legal recourse and access to justice.

What good funding and enforcement should look like

Jepson is careful to point out that meaningful progress exists, even on limited budgets. , developed with support from the Human Trafficking Institute and US funding, provides a real-time, publicly accessible database of trafficking prosecutions and arrests. For a country investing only hundreds of thousands of dollars in this space, the platform demonstrates how transparency and institutional accountability can be achieved without enormous resources.

Italy and Germany both earn recognition for aligning their plans with their investment levels and for building on contextual knowledge. Yet neither country has solved corporate supply chain accountability, even though both demonstrate that coherent strategy tied to realistic resourcing produces better outcomes than aspirational planning without funding.

The US import ban mechanism, developed through U.S. Customs and Border Protection, remains the most significant enforcement tool in the world, although it鈥檚 still largely unique to one country.

The case for realistic investment

What Jepson would like to see instead is relatively straightforward. Governments need to develop a deeper, intentional recognition that their current spending levels are insufficient, he says, adding that investment in prevention also makes economic sense.

Every dollar not spent stopping exploitation upstream generates far greater costs in law enforcement response, victim and social services, and lost economic productivity downstream. Clearly, $1 per vulnerable person per year will not build the necessary infrastructure to protect anyone.


You can find out more about the challenges in combatting force labor in supply chains here

]]>
10 years after the Panama Papers: Beneficial ownership is still unfinished business /en-us/posts/government/panama-papers-beneficial-ownership/ Fri, 12 Jun 2026 14:08:38 +0000 https://blogs.thomsonreuters.com/en-us/?p=71320

Key insights:

      • The Panama Papers transformed beneficial ownership 鈥 The release of the Papers in 2016 changed the idea of beneficial ownership from a technical compliance footnote into a global policy imperative, and the pressure has not let up.

      • Regulatory responses have been significant but uneven 鈥 The EU has pushed forward aggressively, while US reforms under the Corporate Transparency Act have been substantially narrowed.

      • For compliance professionals, the enduring lesson is not about any single regulation 鈥 Rather, compliance professionals should have one goal: Maintaining the discipline of asking who, ultimately, is behind the transaction.


When 11.5 million documents from Mossack Fonseca were published on April 3, 2016, compliance teams across financial institutions around the world faced unprecedented pressure from senior leadership to prove they actually knew the true identities of their clients’ beneficial owners. A decade later, establishing that ultimate ownership remains both the most important and the most difficult task in anti-money laundering compliance.

A watershed moment, but not a starting point

It would be a mistake to credit the Panama Papers with inventing beneficial ownership as a compliance concern. The Financial Action Task Force (FATF), an intergovernmental organization created to promote anti-money laundering (AML) activities, had long emphasized the risks of anonymous shell companies. The United Kingdom was already developing its Persons with Significant Control register; and the United States鈥 Treasury Department鈥檚 Financial Crimes Enforcement Network (FinCEN) had a draft of customer due diligence guidance in circulation before a single Mossack Fonseca document was made public.

Yet, what the leak of the Panama Papers did was something more powerful than create law 鈥 it created political will.

The leak showed, with granular specificity, how shell companies, nominee directors, layered trusts, and intermediary accounts could be stacked together to place meaningful distance between regulators and the individuals who actually control the assets. These were not fringe techniques; rather, they were routine services offered at scale to clients in more than 200 jurisdictions. The “gatekeeper problem” 鈥 the tendency of lawyers, accountants, and formation agents to introduce clients without responsibility for verifying who those clients ultimately were 鈥 was no longer theoretical. It was documented, widespread, and systemic.

What the decade of response produced

The regulatory response to the Panama Papers was substantial, even if ultimately uneven in execution.

In the US, FinCEN’s 2016 CDD Final Rule standardized what many institutions were doing selectively: requiring identification and verification of beneficial owners of legal-entity customers using a 25% ownership threshold and a control prong. For the first time, this was an enforceable expectation across covered financial institutions 鈥 not a best practice, but a mandate.


The regulatory response to the Panama Papers was substantial, even if ultimately uneven in execution.


Globally, the momentum was stronger. The European Union moved through successive Anti-Money Laundering Directives, expanding registration requirements and tightening obligations for designated non-financial businesses and professions. Ultimately, the EU established the Anti-Money Laundering Authority (AMLA) in its 2024 package to deliver cross-border supervisory consistency. And the FATF’s revised Recommendation 24 in 2022 raised the bar further, shifting the mission from collecting beneficial ownership data to ensuring it is accurate, current, and verifiable, with timely access for competent authorities. Having a register is not the same as having reliable information, and regulators have spent a decade making that distinction explicit.

The 2020 FinCEN Files added a further dimension. Where the Panama leak exposed the formation agents who were enabling shell company abuse, the FinCEN Files implicated the banks themselves, showing that suspicious activity reports (SARs) were being filed on transactions that institutions continued to process. Together, these successive leaks sustained the political will that the Panama Papers first generated.

The data is only as good as what’s behind it

The Panama Papers exposed that beneficial ownership frameworks could be gamed in ways that left regulators technically satisfied but substantively blind. Nominee arrangements created paper trails that went nowhere, and outdated register entries gave the appearance of compliance while concealing real control.

The lesson that proved most durable is that transparency requires verification, accessibility, and enforcement working together. A register without verification is a filing cabinet, verified data without accessible reporting channels is compliance theater, and accessible data without enforcement consequences for misrepresentation is an honor system.

For compliance professionals today, this translates into a concrete operational expectation. Enhanced scrutiny for complex legal entity customers is not optional. Nominee arrangements, offshore links, unexplained control structures, and identifying a politically exposed person (PEP) are not risk factors to note and move past. They are the scenarios that point to where the framework is most likely to fail, and examiners know it.

Where the picture gets complicated

Today, further progress is real, but uneven. In the US, the Corporate Transparency Act of 2021 was the most ambitious attempt to extend beneficial ownership reporting to companies themselves, not just the financial institutions serving them.

Under FinCEN’s March 2025 interim final rule, that ambition has been significantly narrowed: US-formed entities and US persons are now exempt, with reporting obligations falling primarily on certain foreign entities registered to do business domestically. That outcome followed a prolonged and contentious legal battle, involving multiple conflicting injunctions, a Supreme Court intervention, and sustained pushback from small business and industry groups, which ultimately made a political resolution rather than a judicial one the path of least resistance for the U.S. Treasury Department.


听The core problem shone by the Panama Papers leak in 2016 remains unresolved. A decade of regulatory response has only narrowed it.


Real estate reporting faces its own legal turbulence, with the Residential Real Estate Rule vacated and on appeal; and investment adviser AML coverage has been pushed to 2028, a delay driven in part by industry objections and competing agency priorities. These are not minor footnotes; rather, they are meaningful gaps in a system that was supposed to be closing.

Enforcement outcomes globally have been equally inconsistent. Panama’s own courts in a major Panama Papers-related trial in 2024. And Germany charged , the firm’s co-founder, in 2026. Jurisdiction still matters enormously, which is precisely what offshore structures were designed to exploit.

The durable lesson

Of course, none of this means the decade of reform was without consequence. It simply means the work is not done.

The Panama Papers’ most important legacy is not any specific regulation; rather it鈥檚 a permanently elevated expectation around knowing your customer, not just by name, but by ultimate beneficial owner, control structure, the credibility of information on file, and the ongoing monitoring that keeps that picture current. The most effective AML programs treat beneficial ownership as a living element of the customer relationship, not a checkbox at onboarding.

Still, the core problem shone by the Panama Papers leak in 2016 remains unresolved. A decade of regulatory response has only narrowed it and made it significantly harder to exploit, but as compliance professionals know better than most, the absence of a finding is not the same as the absence of risk.


You can find out more about the challenges of fraud identification and prevention here

]]>
Beyond prevention: The convergence of detection, investigation & organizational strategy /en-us/posts/corporates/beyond-prevention-fraud-investigation/ Mon, 08 Jun 2026 12:21:22 +0000 https://blogs.thomsonreuters.com/en-us/?p=71242

Key insights:

      • Fraud management works best as a connected workflow 鈥斕鼳ligning corporate fraud, AML, compliance, and investigation teams can strengthen visibility and response.

      • Monitoring must move beyond on-boarding听鈥 Existing customers require ongoing risk-based review, smart alerts, and transaction monitoring that can identify potentially suspicious behavior without overwhelming teams.

      • AI can accelerate investigations, but humans remain essential鈥 AI-driven automation helps process data and prioritize alerts; however, skilled analysts are still needed to provide context, judgment, and industry expertise.


Fraud prevention represents only the first step in comprehensive fraud management. Organizations must develop robust detection and investigation capabilities to identify fraudulent activity and respond effectively.

Indeed, the most successful organizations think about fraud management in a systematic way, says Andrew Pellington, a senior director in Risk & Fraud solutions at 抖阴成年. 鈥淭he most successful organizations think about fraud management in more of a workflow phase that moves systematically from initial prevention through ongoing detection and into detailed investigation,鈥 explains Pellington.

Phases of organizational structures

Understanding how these phases interconnect and then building the proper organizational structures to properly execute them can help corporate risk, fraud & compliance teams create the foundation for effective fraud protection. These phases include:

1. Build organizational alignment across fraud and compliance functions

One of the most significant structural shifts in fraud management is the convergence of corporate fraud and anti-money laundering (AML) departments. Historically siloed, these functions are increasingly merging because fraud and money laundering are deeply intertwined. Fraudsters commit fraud, obtain illicit proceeds, and then need to launder those funds 鈥 effectively, two sides of the same coin, Pellington notes.

That means, financial and non-financial institutions can benefit from unified teams sharing data, processes, and expertise; and this convergence extends beyond AML and fraud to prevention, detection, and investigation phases. Organizations can gain competitive advantage when these functions share integrated toolsets, consolidated data sources, and cross-departmental communication. Before sharing knowledge across institutions, however, organizations must first establish robust information sharing across their own departments.

2. Establish monitoring systems for existing customers and accounts

As your organization moves through the fraud management workflow, the focus shifts from high-volume account opening activities to continuous monitoring of existing customers and account holders. This phase requires different tools, processes, and resources than does prevention.

Monitoring 鈥 both proactively and reactively 鈥 allows organizations to identify suspicious patterns and behaviors, then sophisticated systems must track transactions across time, identify deviations from normal behavior, and flag accounts for review.

Proactively, organizations should segment customers by risk level and establish review cycles: monthly for high-risk customers, semi-annual for medium-risk, and annual for lower-risk accounts. Reactively, they should deploy adverse media and sanctions alerts against public records, coupled with transaction monitoring models that specifically identify potential money laundering or structuring patterns.

“As you move through the monitoring, now you’re looking at your existing customers and account holders, and then you get alerts thereafter,鈥 Pellington explains.

3. Implement alert systems and prepare for regulatory scrutiny

While effective monitoring generates alerts that bridge passive systems and active investigation teams, these alerts need to be calibrated to identify genuine fraud risks without overwhelming investigators with false positives. This requires regular tuning and coordination between technology and investigation teams.

Organizations should adopt scenario planning and war games to test their processes by simulating potential fraud cases, regulatory inquiries, and adverse media incidents. Fraud incidents are a matter of when, not if, Pellington says, and those organizations that proactively test their response processes 鈥 rather than waiting for actual events 鈥 will maintain regulatory confidence and demonstrate institutional readiness.

4. Leverage AI while maintaining human expertise in investigations

While AI-driven automation of some work processes is a big advantage, deeper dive investigations require specialized expertise that cannot be fully automated. This is where generative AI (GenAI) and agentic AI can create significant opportunities. Agentic AI can prescreen alerts and determine which warrant investigation; and GenAI can rapidly produce enhanced due diligence reports by pulling together transaction histories, communications, vendor relationships, and public records.

Automating this work frees specialized fraud analysts to focus on what humans do best 鈥 applying industry knowledge and making judgment calls. Indeed, investigation is equal parts art and science, Pellington explains, adding that AI excels at the science 鈥 processing data at scale, and humans excel at the art 鈥 understanding context, industry fraud typologies, and customer relationships.

5. Transform data into knowledge and wisdom

The final critical gap Pellington identifies is the journey from information to knowledge to wisdom. Organizations possess unprecedented volumes of data, yet many drown in it without extracting actionable intelligence.

More data doesn’t guarantee better decisions; and organizations must elevate information to knowledge, understanding what their peers are doing, what best practices exist, and which approaches work best for the organization. Wisdom then comes from sharing across institutions, learning from industry experts, and avoiding mistakes others have experienced. This requires deliberate peer learning and thought leadership engagement.

Preparing for the future of fraud

Fraud risks are evolving fast, and those organizations best positioned to keep up will be the ones that keep their teams connected, sharpen their investigative tools, and pair AI with human judgment to act faster and stay more resilient while proactively transforming data into actionable wisdom.

By implementing these five phases of fraud protection, organizations can improve their detection and investigation capabilities and create comprehensive fraud protection that evolves with emerging threats.


You can find out more about ways to

]]>
Breaking down silos to counter multi-vector AI-enabled fraud risks /en-us/posts/corporates/breaking-down-silos-fraud-risks/ Thu, 04 Jun 2026 14:34:02 +0000 https://blogs.thomsonreuters.com/en-us/?p=71180

Key insights:

      • AI is supercharging old fraud schemes听鈥 By making synthetic identities, deepfake scams, and customer fraud faster, more credible, and harder to detect, AI is amplifying fraud and crime.

      • The real vulnerability may be internal silos听鈥 Institutions need to be on the lookout, because what looks like a credit loss, an HR issue, or a payment request may actually be part of a wider multi-vector AI-enabled attack.

      • Institutions already have the tools to respond听鈥 Through KYC and internal and behavioral data, financial institutions have the ability to respond to fraud threats 鈥 but only if teams connect and act together.


Fraud and crime existed long before AI, of course, but today鈥檚 technology delivers an acceleration in speed, scale, and success rate for fraudsters, resulting in billions of dollars in losses for victims. AI-enabled frauds on financial institutions by 2027 in the United States alone, and of detected fraud attempts on financial institutions use AI 鈥 and of these, 29% are successful.

To respond effectively to these threats, institutions need to implement a unified response that brings together departments that may not traditionally be partners. This cross-functional coordination should include not only the institution鈥檚 fraud and financial crime risk teams but also its credit risk, cybersecurity, and human resources functions.

And this response is critical, because today, financial institutions are being targeted by multiple types of AI-enabled attacks, including tactics such as:

      • use of synthetic identities to circumvent know your customer/customer due diligence (KYC/CDD) controls and perpetrate fraud or launder money;
      • use of deepfake identities to gain employment, particularly by North Korean IT workers;
      • AI-enhanced 鈥淐EO frauds鈥 to deceive staff into taking unauthorized actions; and
      • Bank customers may be targeted by fraud too, presenting further risk to financial institutions.

Let鈥檚 look at these threat vectors individually:

Vector 1: Synthetic identities and KYC/CDD

Synthetic identities can be entirely fabricated or may use combinations of real and fabricated personal information to create a new identity. For example, a fraudster may construct a synthetic identity using a Social Security number exposed during a data breach combined with an AI-generated passport.

This threat is real and happening now: identifies that criminals have already used AI to successfully open accounts using falsified documents, photographs, and videos. And according to , synthetic identities were used to open as many as 3% of US bank accounts, representing millions of identities. Not surprisingly, these illicit accounts are used to commit fraud and launder the proceeds of money laundering.

Vector 2: North Korean IT workers

North Korean individuals have successfully gained employment as remote IT workers at American companies, often passing themselves off as US nationals using AI-generated face-swapping technology combined with proxy computers and false identity documents. North Korean IT workers are almost $800 million annually for the regime.

Institutions deceived into employing these workers are not only against North Korea, but they are also exposing commercially sensitive data and systems to an adversary state, increasing the possibility of theft, cyber-attacks, and extortion.

Vector 3: CEO Fraud

A 鈥淐EO fraud鈥 is a cybercrime in which an attacker impersonates an executive to deceive an employee into taking actions such as sending unauthorized wire transfers or disclosing sensitive information. AI accelerates these frauds by making them more personalized and credible.

In one of the more well-known examples, in an AI-enhanced CEO fraud in 2024 after the fraudster impersonated Arup Engineering鈥檚 CFO and requested a staff member to make several financial transfers. The criminals added credibility to the fraud by using a in which the target recognized many of their colleagues 鈥 unfortunately, all of them were deepfakes.

Vector 4: Frauds targeting customers

Where customers are targets, AI provides the scale, speed, and personalization to allow illicit actors to deliver individualized fraud. For example, whereas romance scams previously used repetitive scripts and re-used the same images of the romantic 鈥減artner,鈥 fraudsters can now use AI-generated messages, images, or videos, continuously adapting the execution of the scam to the target鈥檚 responses and behaviors.

Creating a cross-functional and unified response

The examples above demonstrate the diverse and highly sophisticated uses of AI by illicit actors, both adversary states and criminal networks. Detecting and responding to these illicit activities requires joint action between teams that may not traditionally work closely together.

For example, if an account holder fails to repay a loan, the credit team may consider it to be a default by a legitimate customer and write it off as a credit loss. However, if the account was opened using a synthetic identity, investigation may reveal other accounts that share similar customer data points or transactional patterns. This could reveal a network of accounts that are perpetrating a fraud or money-laundering scheme. To detect and respond effectively, joint action is needed between KYC/CDD on-boarding teams, financial crime investigators, and fraud and credit risk professionals.

Alternatively, for HR teams to effectively identify use of face-swapping videos during a hiring process, knowledge from the organization鈥檚 cybersecurity team, especially of deepfake indicators, would be valuable. If a North Korea IT worker is hired and only later identified, cybersecurity and sanctions teams must be involved in the response to mitigate data, network, and compliance exposures.


Detecting and responding to all illicit activities requires joint action between teams that may not traditionally work closely together.


Finally, all staff may be targeted by deepfake fraud, but those in senior positions or departments with financial authority are the most vulnerable. This means it is essential for institutions to deliver employee training using real-life case studies, 鈥渘ear misses,鈥 and scenarios drawn from across the institution and industry. This type of training will increase vigilance and minimize the likelihood of a successful attack.

For customers, financial institutions are well-positioned to identify indicators of fraud due to their extensive datasets of KYC/CDD records, transactional, and behavioral information. Institutions should enhance their customer relationships (as well as meet applicable regulatory requirements) by taking proactive measures to inform and protect their customers.

While AI has accelerated fraud and crime, financial institutions also hold valuable and relevant assets: the knowledge distributed across their cybersecurity, HR, credit risk, financial crime compliance, fraud, and KYC/CDD teams. By connecting these teams together, even in contexts in which these departments have not traditionally been partners, institutions will be well-positioned to protect both themselves and their customers from illicit actors鈥 sophisticated AI-enabled threats.


You can learn more about the fraud-fighting challenges faced by financial institutions and other organizations here

]]>
The human cost of the AI governance gap: What the data tells us /en-us/posts/human-rights-crimes/ai-governance-gap-human-cost/ Mon, 01 Jun 2026 16:58:18 +0000 https://blogs.thomsonreuters.com/en-us/?p=71110

Key highlights:

      • AI governance is hard to prove in practice 鈥 While our research shows that 44% of companies publish an AI strategy, 76% of those same companies show no evidence of having policies to evaluate the quality of data used to train AI systems.

      • Workers are being left under-prepared and under-protected 鈥 Only 14% of companies have policies to mitigate the negative impacts of AI on workers, and only 31% offer any reskilling or training programs around adapting to an AI-integrated workplace.

      • Human rights and ethics appear an afterthought in AI governance 鈥 Almost three-quarters (72%) of companies conduct no AI impact assessments, and less than 1 in 10 companies conduct ethical or human rights assessments.


There is a widening chasm at the heart of corporate AI governance, according to a new report, , published by the 抖阴成年 Foundation and the United Nations Educational, Scientific and Cultural Organization (UNESCO).

The Foundation鈥檚 analyzed publicly available information from nearly 3,000 companies across 11 industry sectors, creating the most comprehensive picture yet of how organizations are managing AI.

Beneath the surface of corporate AI governance mechanisms, divergence between the speed of AI adoption and meaningful human oversight is growing. The report’s findings make clear that this is no longer a gap that organizations can afford to ignore, especially when backlash against is growing and are solidifying among consumers in the United States.

Data highlights the illusion of AI governance

Businesses of different sizes and across multiple sectors are adopting AI technology at a rapid pace. When governance exists only in the wording of a strategy or company vision, however, the people most affected by AI systems 鈥 workers, consumers, and communities 鈥 are left vulnerable. According to the report:

      • 44% of companies publicly communicate having an AI strategy. However, a gap in AI governance is evident as more than three-quarters of those companies (76%) do not seem to have policies to evaluate the quality of data used to train AI systems.
      • 40% of companies report board- or committee-level oversight of AI. At the same time, strategic signals do not necessarily indicate operational capacity or day-to-day governance. In fact, less than one-third of all sampled companies claim to have an additional team or resource dedicated to AI governance. Moreover, limited information is publicly disclosed on the teams, processes, and accountability mechanisms that translate intent into action.

Workers are being left behind

Research by the International Monetary Fund finds almost , highlighting the acute nature of concerns about job displacement and declining opportunities for some groups. Without sufficient oversight, AI can threaten workers’ rights, amplify bias, and increase surveillance and work intensity, which can enable inhumane decision-making at scale.

The TR Foundation/UNESCO report notes that many companies are adopting AI without the safeguards needed to support workers and help them to adapt to the changes this technology brings. Less than one-third of companies were shown to offer training and reskilling programs for employees who may be adapting to an AI-integrated workplace. Even within the 31% of organizations in which these training programs exist, there is a vast variation in the scope and depth of the training offered.

In fact, many company training programs are not enterprise-wide or structured. Instead, they are ad-hoc or limited to leadership roles. This lack of investment in talent risks undermining the significant investment that companies are making in AI.


Despite growing pressure from regulators, policymakers and social justice campaigners, the ethical impact of AI appears poorly governed, with companies sharing limited information publicly.


The picture on worker protections is equally concerning. Only 14% of companies have public policies in place to mitigate the negative impacts of AI systems on workers, the report shows. This means the majority of companies either have no policies in place or do not publicly communicate them.

What is more troubling is that when workers experience harm, there is almost nowhere for them to turn. Only 2% of companies indicated they had a complaints mechanism 鈥 a critical early warning system for potential concerns. The findings suggest many organizations lack a mechanism for AI-related internal complaints beyond the broad generic complaint channel, and this is compounded by low awareness of the areas in which AI systems may infringe employees’ rights and protections.

Ethics and human dignity as an afterthought

Despite growing pressure from regulators, policymakers and social justice campaigners, the ethical impact of AI appears poorly governed, with companies sharing limited information publicly.

Human rights and ethical use of AI are treated as secondary considerations to compliance, according to our research. The majority of companies (72%) do not conduct any impact assessment with regard to AI. Only 7% publicly communicate conducting a fundamental or human rights impact assessment, and just 5% report conducting an ethical impact assessment.

Among those companies conducting some form of impact assessment, the focus skews sharply toward compliance rather than people. The most prevalent assessments are privacy or compliance-focused, with 18% of those companies that conduct some form of impact assessment reporting that they conducted a data protection impact assessment, and 14% reporting they conducted a privacy impact assessment.

How to center people in AI governance

Closing this governance gap is essential for companies in order to adopt AI responsibly and avoid costly legal, ethical operational, talent-related risks.

To support companies in navigating this challenge, offers a free survey to help companies map the areas in which AI is used across products, operations and services, and then benchmark those against peers their sector.

The report also contains case studies from companies that voluntarily shared their responsible practices with us. For example, German software company SAP intentionally designs and deploys its internal AI systems with a human-in-the-loop in which AI automates repetitive tasks and supports decision-making while final judgment and complex problem-solving remain firmly in the hands of employees.


As AI becomes part of core business infrastructure, companies must move beyond statements of intent and toward measurable AI governance.


In another example, BASF, a German chemical conglomerate, has jointly agreed with its workers’ councils on a general reskilling program that covers technical, hard, and soft skills. Finally, Canadian telecom company TELUS’ Indigenous Advisory Council provides guidance on AI ethics issues that directly affect indigenous communities.

Next steps for companies

The TR Foundation/UNESCO report highlights the most impactful concrete commitments that companies can take now to future proof against AI-related risk, including:

      • investing in structured, enterprise-wide worker-reskilling programs that measure outcomes, not just participation;
      • establishing enforceable human rights impact assessments as a standard part of AI deployment, not as an optional addition; and
      • creating accessible, AI-specific internal grievance mechanisms so that workers and users have a genuine pathway to raise concerns and seek remedy.

As AI becomes part of core business infrastructure, companies must move beyond statements of intent and toward measurable AI governance. While this data demonstrates clear governance gaps, it also presents an opportunity for companies to take the lead on implementing responsible AI that operates openly in the public interest.


You can learn more about

]]>
Beyond detection: 5 pillars of proactive corporate fraud prevention /en-us/posts/corporates/5-pillars-corporate-fraud-prevention/ Mon, 01 Jun 2026 12:55:10 +0000 https://blogs.thomsonreuters.com/en-us/?p=71085

Key insights:

      • Define your risk appetite 鈥 A clearly defined fraud risk appetite aligns prevention efforts with strategic objectives and ensures accountability by establishing acceptable levels of fraud risk across the organization.

      • Create a fraud-specialized team 鈥 Dedicated ownership of the vendors that supply fraud solutions by a fraud-specialized team 鈥 rather than by the procurement function 鈥 is critical to maximizing technology performance and adapting to emerging threats.

      • Establish a specialized prevention division 鈥 The rise of sophisticated scams demands the creation of a separate, specialized prevention division to avoid overburdening core fraud teams and ensure targeted, effective responses.


Corporate fraud represents one of the most significant risks facing organizations today. Yet many companies lack the structured governance and technology infrastructure needed to combat fraud effectively.

The solution requires that comprehensive fraud prevention frameworks be built on clear governance, proper technology deployment, and data-driven insights, according to Aaron Frye, Founder & CEO of Lucid Point Consulting. Organizations that implement these five pillars create resilient fraud prevention functions capable of identifying and preventing fraud before it impacts results. These five pillars include:

1. Develop a fraud risk appetite

Effective fraud prevention begins with a well-defined fraud risk appetite that tells the right story to the right stakeholders. Your framework must communicate to your board, executive leadership, and operational teams the level of fraud losses your organization should tolerate, and in which areas you should prioritize fraud prevention investments.

The fraud risk appetite framework must address several key considerations; for example, it should define the level of fraud risk that aligns with the organization’s growth objectives, identify the areas of greatest vulnerability, and evaluate which investments will yield the strongest return. Equally important is the ongoing monitoring and communication of progress through regular reporting on fraud risk metrics, vendor assessments, and investigation outcomes. These actions demonstrate to stakeholders that fraud prevention remains an active priority for the organization and ensures that fraud risk continues to inform organizational decision-making.

2. Establish clear ownership of risk-solution vendors

Many organizations invest significantly in fraud detection tools only to see disappointing returns. The problem often lies not in the tools themselves, but in unclear ownership and accountability for their performance.


Organizations that implement these five pillars create resilient fraud prevention functions capable of identifying and preventing fraud before it impacts results.


If your organization lacks a designated person or team within your fraud strategy function whose job it is to ensure the risk-solution tools you鈥檙e getting from vendors are the best for your enterprise, you likely aren’t getting the most out of your vendors. This dedicated fraud service ownership role must act as your internal champion, evaluating vendor performance, staying current with product enhancements, and ensuring integration with other fraud prevention initiatives.

Critically, procurement, sourcing, and vendor management functions should never own this role. These teams, by the nature of their titles and responsibilities, don’t prioritize fraud. They lack the specialized knowledge required to assess whether your fraud detection technology is performing optimally or adapting to emerging threat landscapes. Without dedicated fraud expertise overseeing your technological investments, advanced tools sit underutilized and critical fraud signals go undetected.

3. Develop a fraud governance function

Every organization should have a dedicated fraud risk governance team within its fraud risk management organization. This governance function serves as your second line of defense, working proactively to reduce operational chaos within your fraud strategy, operations, and investigation groups.

If a non-fraud governance function owns fraud governance, you are guaranteed not to be getting the best form of governance. Fraud is a specialized discipline requiring dedicated expertise and focus; and your governance team must develop policies, establish standards, monitor control effectiveness, and ensure consistent application of fraud prevention practices across the enterprise.

4. Document existing risks and resource gaps

One of the most important responsibilities of your fraud governance function is identifying and documenting the areas related to fraud risk that your current fraud risk teams don’t have time to review. Due to capacity constraints, it is impossible for many fraud risk teams to cover all open gaps. Your organization must understand those open gaps and not be ashamed to address them.

Create an action plan that documents open risk and self-identified issues that your current team cannot adequately address. This transparency demonstrates clear-eyed realism about your organization鈥檚 limitations and creates the business case for requesting additional resources or engaging external consultants to help close these risk gaps.

5. Address the growing scam-prevention challenge

needs its own prevention strategy division within your fraud risk function. Compromised business email, investment scams, and vendor fraud schemes represent an entirely new category of fraud risk that demands specialized attention.


Every organization should have a dedicated fraud risk governance team that serves as its second line of defense, working proactively to reduce operational chaos within corporate strategy, operations, and investigation groups.


There has never been a full manageable grip on fraud prior to the spike in scams. Therefore, you cannot expect your existing fraud risk teams to tackle a new wave of scams as a priority as well as to manage traditional fraud prevention responsibilities. Your core fraud function manages internal control systems, transaction monitoring, and investigation protocols. Adding comprehensive scam prevention to this workload without dedicated resources guarantees that identifying and preventing scams will receive insufficient attention.

Establish a dedicated scam-prevention division focused specifically on emerging scam threats, employee education, scam-specific prevention technology, and response protocols. This specialized approach ensures sophisticated scam schemes receive the expertise and resources necessary while your core fraud function continues addressing traditional fraud prevention requirements.

Going forward into the fight against fraud

In an era of escalating fraud threats, reactive detection is no longer sufficient. Organizations must adopt a proactive stance grounded in strong governance, clear accountability, and strategic resource allocation.

By defining a fraud risk appetite, assigning ownership of fraud prevention tools, strengthening governance, documenting unaddressed risks, and establishing a dedicated scam prevention function, companies can build resilient, forward-looking fraud prevention frameworks. These five pillars enable organizations to anticipate threats, allocate resources effectively, and protect both financial performance and reputational integrity.

Today, the path to fraud resilience begins not with technology alone, but with deliberate, enterprise-wide commitment to proactive risk management.


You can find out more about ways to

]]>