By PAUL O’DONOGHUE, Senior Correspondent
IN February 2000, Khalid al-Mihdhar walked into Bank of America to open an account using his real name and identity.
He deposited $9,900, and left with a Visa card. The bank had no reason to suspect that just a year and a half later, their customer would play a key role in the deadliest terror attack in modern history.
The same was true for many of those involved in the atrocity – the terrorists often used their real names and passports to open bank accounts.
Financing the attack cost a surprisingly small amount of money – only about $500,000.
The perpetrators used the money for relatively mundane expenses, such as food, travel and accommodation costs. $10 here, $20 there.
It flowed through major US banks, with al-Qaeda conspirators sending wire transfers of between $5,000 to $70,000 to the hijackers.
These terrorists followed up on these deposits with many small ATM or credit card withdrawals – again via accounts which were often in the their own names. The plotters also physically imported cash, used traveler’s checks and accessed overseas accounts in Saudi Arabia and the UAE (United Arab Emirates).
The 9/11 Commission later described these all of these methods “essentially invisible amid the billions of dollars flowing around the world every day”.
This begs an obvious question – how could the financing for such a major terror plot so easily go unnoticed?
Pre-9/11 anti-financial crime focus
The simple answer is that, at the time, the financial system simply wasn’t designed to recognise these transactions as suspicious.
The world of AML and counter-terrorist financing has changed dramatically over the past 25 years. At the time, the system focused much more on drug trafficking proceeds, with no intenton of disrupting more ‘routine’ transactions.
And this is perhaps the main lesson which lenders can take from the terrible tragedy – that terrorism financing often looks completely ordinary.
This is a point which the 9/11 Commission’s report drove home repeatedly. It states that no financial institution ever filed a suspicious activity report (SAR) in connection with the 9/11 hijackers.
It also makes this extraordinary statement: “Even with the benefit of hindsight, none of them should have.”
Why? Because the way the terrorists used their accounts was almost exactly the same as millions of other bank customers. They bought food, paid for car insurance, and so on.
In retrospect, one might argue that the thousands they spent on flight training could have been viewed as concerning. But that is only due to what we know now.
At the time, “no one monitoring their transactions alone would have had any basis for concern”, the Commission concluded.
While this was true at the time, have things changed since 9/11? That is – is the financial system now more likely to detect these terror plots before they happen?
9/11 financing and subsequent changes
In many ways, yes.
For example, banks now have much more sophisticated customer identification processes. And they are much better at identifying potentially suspicious sources of funds.
They also now have ongoing transaction monitoring, which companies use to focus on identifying patterns rather than isolated payments. If there are changes in transaction sizes, or what customers are spending their money on, banks are much more likely to flag them.
Many other measures have come in over the last 25 years.
These include tighter wire-transfer controls, so banks know more about who is sending money and where it is going. And better information sharing, so lenders can potentially connect information about individual customers between each other.
These are all steps in the right direction, which have given banks more information, and more tools to identify potentially suspicious activity.
This means that modern monitoring is much better equipped to flag potentially risky activity, or matches known terrorist-financing typologies.
But the central challenge still remains for banks. Terror transactions still often appear to be normal day-to-day spending.
Lessons
A major takeaway for banks which emerged from 9/11 was not “look for bigger red flags”. It is that the absence of something obviously suspicious doesn’t necessarily ensure that a customer is clean.
Simple rules are not enough. For example, US banks have been required for years to report all cash transactions above $10,000. This was already in place before 9/11, but did nothing to detect the smaller wire transfers and ATM withdrawals the hijackers utilised.
But more context and better intelligence can help banks identify this ‘mundane’ activity which can be part of a bigger terror plot.
The US government has specifically pointed to examples where financial institutions joining the dots helped scupper potential terror attacks, such as a suspected plot involving trans-Atlantic commercial airliners.
It is the key lesson for banks in the post 9/11 era. Terror activity will rarely be obvious – but lenders now have much better tools to identify it.










