CyberWiseCon Europe 2025

Stefano Tempesta: ML for Anti-Money Laundering

46:00 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

This talk focuses on the application of machine learning in anti-money laundering (AML) processes. The speaker, Stefan Tempesta, discusses the challenges that traditional rule-based AML systems face, such as high rates of false positives and the increasing speed and volume of financial transactions. He explains how machine learning can enhance AML efforts by utilizing anomaly detection techniques to identify suspicious activities more accurately and efficiently. Additionally, he covers the importance of data privacy, especially when aggregating data across different institutions, and introduces concepts like confidential computing to ensure secure data usage. The session highlights the potential for AI and machine learning to transform how financial institutions detect and prevent money laundering, emphasizing a more dynamic approach that combines both internal and external data sources.

Full transcript

[Music] yeah hi hi hi guys this is the first session and I'm want to re I want to introduce because by yourself I'm Lucas from zpro and making the backup solution and want to introduce of course the our main speaker Stefan tempesta director of engineering lecture and co-author at Atlas and Stefan is a a web architect working at the Crossroad of uh web 20 and 30 to

make the internet and more accessible meaningful and inclusive space as he said Stan is the ambassador of the AI and blockchain technology for good purposes and former advisor of Department of Industry Australia on the national blockchain road map he is also a technology advisor in carbon asset solution for climate action and Sensibility Network mission to slow carbon deite emission and remove access atmospheric CO2 by using regulative

agricultur techniques and Technologies this is really this is really hard something to understand but I think the sto will show you and uh uh explain a little about the machine learning for anti-money laundering today and uh uh about the ex um X effective Solutions can help Financial Service flight go Global crime if I miss something Stefan could you could you tell more about well that was an

impressive introduction Lucas thanks so much and welcome everybody um yes so I've been uh in the technology space for a long time um currently based in Australia and my core field are in the application of AI technology and and blockchain technology for good good purposes and these good purposes have different flavors I look after technology for environmental impact carbon credits as Lucas mentioned in the introduction and

also aspect that are more connected to financial transactions which is today's session today's session is about AML anti- money laundry basically making sure that money Financial transactions I use for the best purpose I have a few slides to go through a presentation to introduce a few topics and then I will show you how to build um sort of a simple payment anomaly detection system in machine learning

a few concept though H to get started um I'm first of all I want to position not the impact of of um the the the market the industry for um AML and time money laundry in the industry is a financial impact that has a big big numbers dollar numbers attached to it which are in the billions of dollars and when I say this that has been calculated

that over10 billion doar fines has been raised to organization that do not comply with proper regulation for AML and time money laundry and also there is has been 1% of a crime in across the world is connected to laundering money so basically to smuggle money in across countries across borders that is significant is very impactful and has the impact on many many people's lives but before we

go uh we carry on with the solution let me ask you something what is money laundry why is called laundry has anything to do with washing machines well the story actually goes back at the beginning of the last century in um the early 1900s Al Capone you probably have heard this name in some Hollywood movies Associated to some Italian mafia in the US now so alapon was

covering his illegal business by hiding the money that he will get that he will earn from this illegal business inside a l r that he bought all H the the the place where he operated so by hiding money in uh in this way you will basically uh manage to transfer money H from one place to another one with without being detected now eventually Al Capone was captured

and was charged with tax evasion in 22 Federal uh States and he was sentenced to $50,000 of De time so it's a huge amount of money in nowadays currency and 11 years of imprisonment imprisonment so at the end the crime doesn't pay but it made the history because uh now we talk about money laundry with Association to what alapon started over 100 years ago now we have

a we have historically no banks financial institutions been historically working with some traditional realle base systems this realle BAS system basically an analyze a number of rules and detect whether a transaction and the individual doing the transaction is uh in the risk section or not so basically is a sort of if then else no if you want to relate this to a programming language if this transaction

falls into this category raise the risk if it doesn't fall lower the risk and so on now obviously there is a big um Evolution since the first AML system were created dozens and dozens of years ago which data has become more volumetric so a a lot of more data in that to analyze and at the same time uh the the speed of transaction the volume of transaction

has changed a lot this has created a problem with the traditional rule based system they are too slow they can't keep up with evolving regulation with different strategies and with all this big big data with this complex scenario we need something that is more automatic and can process data escales and you already get idea this is AI technology this is machine learning now now very quickly again

traditional AML systems are based on fixed rules they raise some alerts based on these rules and most of the times even 95% of these alerts are false positive a transaction seems suspicious but it's not how many times it happened to you that your credit card has been declined because you have done a payment for the first time in a new country because you are traveling and then

you get stopped and then sometimes you require a multiactor authentication you require not to receive an SMS or a code by email while you are overseas you're not connected to the internet you're not roaming so you can't uh receive the code you can't unblock the transaction it happens all the time so this rule base systems are really struggling with keeping up with the evolution with the speed

of trans actions that happens today is very sequential approach we have a lot of data all the transactions we organize in different rules no this rule engine and then it comes out yes suspicious no suspicious yes suspicious not suspicious often and I'm not kidding here there is a manual analysis of the suspicious transaction they get list and then analyze by a team of people that go transaction

by transaction and decide whether is uh acceptable or not and this is why sometimes um it takes a little bit of time for your credit card payment to be processed or sometimes the bank even call you how many times did it happen to you they call you and say it could be an automatic system but they still call you and they say we notice on this account

is that you say yes after the beep right it at least it happens to me all the time now let's go more specific into AML because the use cases that I mentioned they're more related to payment right which is connected to AML and time money laundry but it's just part of it AML is bigger than that ml is really about also identifying victims for for example of

you human uh crimes as in um trafficking of O of people because obviously the consequences of money laundry is uh also in the space no of um human trafficking which is a a big big problem uh not very very much in the in the media not very much many people talk about it so it obviously create a bit of a um interest in in the space because

not only there is technology that can help as we're going to see in a moment but there there is a humanitarian impact goes beyond the the financial transaction and what I mean with this is there is a I took a screenshot here from an application that um no I work in the past where we have a classifi identified a potential victim of a human trafficking case gender

female age range between 20 and 30 unemployed being with a bank between one to five years a lot of EMT electronic money transfers over 100,000 uh dollars in a year receiving a lot of small transaction for multiple remitters so from from um from different payments sounds a little bit bizarre right so why this person is receiving such a small amount 20 to 80 from over 200 people

in a month uh what kind know of services is is is she in this case is fale selling once even received a large amount over $900 from one male customer uh and again there is something suspicious in here and this was triage escalated with the police now you can understand that this where I'm I'm going to with this situation and it also happen in different cities 33

different cities five provinces a lot of Transportation with like uber and so on so there is something dodging going on there and I'm not going into defining it you probably got the idea already but certainly something that was identified and had to be escalated to uh to to stop this human trafficking now that's the story behind it but let's capture all the data point here gender age

occupation number of transactions size the transaction number of parties involved in the transaction geography of the transactions all of these are data point see this is how anti- money laundering works works on identifying all these different data points and analyzing them there are two types of of anti money laundries and they're not one or the other one they cannot both work together level one is identification of

all the activities everything that I just said all these data points they are analyzed and they are checked against this rule engine um if anybody's wondering I'm absolutely happy to share these slides after the session so just reach out and I will uh definitely share this and any additional material if you're interested obviously to deepen your knowledge on AML and the impact that AML has on human

trafficking and and the the payment processing now there is a second level of AML which is is called a indirect identification the direct identification is let me check for all these data points we know the data points I just go for it and check if the conditions meet or not real engine the indirect identification is on a volume of transaction frequency category of transaction where I don't

know what to search for yet is basically a machine Learning System that is looking for the principal components in data and identify these components without knowing up front what these components are if the real engine works on the principle that data is known up front all the transaction against all these categories the level two AML so the indirect identification works with unsupervised machine learning algorithm an unsupervised

machine learning algorithm is an algorithm that doesn't know the quality of data that is getting data has not been label yet and it will search for the components that that qualify that data it's a process called PCA principal component analysis that is meant to analyze data and that is unsupervised that is unqualified from the very beginning okay now you're getting the idea the idea is we need

the machine learning we need the AI ER technology to keep up with this big volume of data especially when we don't know what kind of data we're going to get what if we are missing something in all the transaction that we have analyzed but those uh those missing missing points are actually critical to understand whether a transaction is positive or negative so we need to look into

the next generation of AML system which are based on knowing your customer no kyc process that it is not just in isolation like a silo where we put the the customer into sort of a box and we classify it's been screen it's been scrutinized and then before you get out of the box or say that you've been labeled as high risk then it's going to be really

hard it's like a credit score that is attached to your identity and it goes both way because you may not have a a negative uh credit score but still perform dodgy transaction and never get detected so we need something that has the capacity to adapt to be more Dynamic to process massim volume of data and also to be looking for patterns of this data that we don't

know yet looking into something that we don't know yet if is called anomaly detection basically identify anomalies something that looks different but we don't know just yet what it is and we have to find out so let's get there and then we jump into the system and I'll show you how to build an anomal detection system in um the the opportunity here is to consolidate all the

different data points that we have identified profile of the client the kyc all the financial transactions all your bank account all your emails anything all the different data points and manage them in a way that can be process by Machine learning speed and it sounds exciting it is H there is a challenge though all the financial institution managed all this data centrally all these big data that

are used to train the model are managed by the bank by the financial institution and they're a little bit proprietary they don't want to share with anybody else well on one side it's understandable right so they don't want to share anything that has confidential information with any other institution and as a customer I also don't want my bank to share my data with another bank right so

we all want that but at the same time you know how machine Learning Works the more the data the more accurate is the result because uh models can be trained on a larger volume of data set and obviously the accuracy can be the Precision uh can be increased so basically we need something like integrating all these different internal systems also with additional external sources that can come

from third parties from government from other Banks and entities uh organizations that can increase the diversity of the data points that we need for analysis now obviously this is a challenge now this is a little bit of the pipeline all the different transactional data uh data aggregate across different dimension given as in as a feed to the machine algorithm and then produce the the recommendation uh I'll

come back into this uh later when we show U the process in in the machine Learning Studio environment now all of this will produce very long H meth a model evidence framework and again I'm going to share this slide so uh with don't have the time to go in details of all these uh properties but or features but what a meth is a model evidence framework categorization

of all these data sources H better let me rephrase is the outcome the output of the uh categorization of all the different data sources we we have all the data coming from different sources internal and external to the financial institution and they are aggregated transformed in a way to to produce different features looking for tax evasion looking for inconsistency of activities excess of expenses unusual fund transfer

association with um um uh um with organizations or entities that have been identified as a fraudulent in the past lack of transparency you know like sometimes there is a transaction that is not clear where it's going and what is the purpose of it so there are a lot of these features every every features in the big picture of AML has a different weight no so the contribution

is different so the value is different and there are a lot of other points this is just one little extract of a very very long spreadsheet that we have in the system um the the the purpose at the end is to Define these typologies from all the different data sources that we need in AML this process is called feature engineering which basically means that we collect all

this data and we are transforming all these data to ID in these risk typologies the features that we are uh creating we are we are engineering now let me come back to the problem that I mentioned before the problem that I mentioned before is that all these data sources they're not just internal if they were internal then Happy Days everything is quite confidential inside the bank but

to be able to understand the for example Geographic trffic risk so how a person that operate on a larg geography can can be identified as a Smuggler we can't rely on a local bank the local bank will never be able to scale to different geography and the same for the other typologies or risk identified so we need dis agregation this agregation is a processed H with a

technique in in machine learning called um decision tree a decision tree is basically creating a tree structure where each data point is compared against some threshold values and the process will go H property by property or feature by feature H you know until all the different data points are analyzed now the this process obviously inevitably span across the different data sources because it's going to count for

not transaction with unknown address in the last 30 days um foreign personal investment country where the transaction has been executed number of people know known and unknown involved in the transaction volume of transaction so this decision tree is basically creating a direction into these uh into all these data points until arrive to the last Leaf of the tree which defines your level or risk this uh this

is a common technique use in machine learning for analyzing data uh going step by step but again the problem here is that these data points can come from different sources probably here the the color coding is is not clear but um the the gray the light gray are internal sources the dark gray should have Pi a better color anyway are external sources so in this way there

is a mix of internal and external sources and mixing different data sources creates always a problem of H data privacy and U data leakage if put in the wrong hands so we need to move into an aspect of confidentiality which is actually called confidential AML confidential antimony laundry which basically leverage trusted execution environment for allowing multiple financial institution multiple Banks to share confidential in a confidential way

or dat dat sources the the machine learning algorithm runs inside this trusted execution environment which is agreed between all the different banks data is encrypted and the Machine learning algorithm is able to process these encrypted data without any transformation and without disclosing this data to the other Banks so the original data set remains in the hands of each Bank an encrypted copy of it is shared with

the other institut and obviously the algorithm will benefit from this larger volume this technology is called confidential Computing and is an addition to the traditional encryption technique that we already know we know how to protect data at rest when it's store in a database for example we know how to protect data when it's transfer uh to over the wire or over the Internet https for example this

technology is the new way of encrypting data when it is in memory in use because in that moment the data is accessible is visible and basically works by reserving a space of memory in uh the virtual machine in the container where it is running so that data and also the algorith of the machine learning uh uh app the the the code itself runs in complete isolation this

isolation is done by the CPU so is Hardware encryption the the hardware the CPU creates a protected enclaves where the code and data runs and the operating system cannot access the hypervisor cannot access so this create a this prevent access even by the cloud hosting provider so if you run this in AWS in Azure in the Google Cloud wherever you run it h no one at Amazon

at Microsoft at Google can access your coded data because they are protected inside a hardware secure enclaves now H this was just an extension to my conversation let's go back to machine learning and the anary detection so this is where it gets important it gets important because now we know that we can aggregate different dat sources from different sources we can data set from different sources we

can confidentially process to analyze to engineer all the different features and we can now um build the machine learning algorithm so I'm going to show you this here H you can see yes you can uh I'm running a machine Learning Studio there there is a classic and a modern version I'm still on the classic one I haven't moved to the uh modern side but I will I

promise I will for now is okay to work on the classic version um here we can create what are called experiment an experiment in machine learning terminology is an algorithm that start with data and produce an output which is a score okay so I have created here and now I'm going to look into my second screen here so uh here we go uh payment anomaly detection and

is predictive version okay so let's start with the the the regular experiment this regular experiment is built by defining a flow of action we started with a payment data which I'm going to show you in a moment obviously is a a sample data I simplify this data I extracted from a larger data set I have removed a lot of confidential data yes there are some names of

people that have been made up so everything here is meant to be um used for the purpose of this demonstration in the real world you will have thousand and thousand and thousand even millions of rows and hundreds of different columns again here I have simplified and I'm picking only the time stamp the name of the person the description of where the transaction was done they bought some

something on Amazon the country and the amount they spend okay obviously there can be a lot of other features in there a lot of other columns and uh if you look into for example identifying no a client and comparing with the amount they spent then we can see this nice diagram here which is a multibox plot which basically is telling me that for each client know Jo

Brian Mike Jill they spent from a minimum to a maximum but the majority of the transaction is in this box here in the case of John between just a little bit less than 80 euros and a little bit more than 160 EUR and the average is the line in between 120 Mike instead is in between uh 80 and 100 so let's say is about 90 and 220

with an average of 150 okay so in this way we start identifying how people are spending their money now after this we're going to go into the training you know the process of machine learning right so you you load the data set you split the data between uh a portion of data that you Ed for training and another one that is used for testing and the algorithm

so this is split data does exactly this split the original data set in a number of rows that are used for the training so then the algorithm can be trained against that data and the other one the other lines the other rows are used for the actual testing of the of the train model so for training we are using an anomaly detection this is what we are

doing right so we want to identify anomalies in payment pass patterns of these people here and we use a one class support Vector now I'm not a data scientist as I'm an engineer I build this stuff H but I don't write the the machine learning algorithm to create this one class support Vector machine but basically is a technique for machine um anomaly detection there are a different

other techniques that can be used in this case the one class basically is a similar concept to the decision three that we have seen in the previous slide where the there is a classification of data whether is or one type of the other one in this case whether is a risk or not now it goes all the way until the scoring and the scoring at the end

we can also display score data set identifies a score probability and the is a number obviously that identifies the likelihood that uh record is in the of in the detected range or outside the detected range and therefore an anomaly how do we do this now the good things about this machine Learning Studio is that you can just set up a web service basically after you write all

your algorithm click the button and publish as a web service completely hosted in the cloud you don't have to provision any virtual machine you don't have to provision any containers and no no web server there is no coding there is no no no JS there is no python I mean if you want to you can add some python modules or even R which is not the programming

languages of data scientists but you don't have to there are many machine learning algorithm ready to use for clustering regression and and so on so on so on maybe this can be a topic for another session another time now stay in in this here we going to go into the experiment that has been published as a web service I open my web service and this web service

can be accessed in any programming language that can do an HTTP request right so if you can see now here it's going to open the the the post URL with the authentication barer that you have to put inside and the request which is a Json payload where you pass these parameters and the response which is another Json uh file that contain means the score probability now instead

of looking into this Json file we can even test it directly here so we can test directly how algorithm performs on the spot so we can say today is 21st yes 21st of May 2024 our client Mike Randall has spent on Amazon in Ireland uh 100 okay so we can test the response and based on the train model we get this score probability which is very low

but is an indication of the distance of this transaction from the center uh from the anomaly range okay obviously higher number it means that the probability is higher so if I increase the transaction and go to 1,000 and not much happens for for this guy let's change country let's put him in Australia and yes so there is a change of of value here so obviously changing conditions

uh create different ways of testing data that at the end will produce these figures that was in the in the picture before if I manag to get back with my mouse I can show that again this one here so all the transaction are within a range of typical activities those that are outside because the number is of the score probability is different from the average then they

are possible fraud now obviously this is one type of anomal detection purely for payment as we understood there are many many money Laing solution so an AML solution is a collection of several algorithm each of them is processed each of them raise a alert and each of them is analyzed for the producing the final result and I would say is just last slide say after implementing this

AI power AML uh system we measure an increase in uh the overall performance of the system well this is what we expected right so a reduction of 85% of false positive alerts and an increase of over 200% of money laundry activities so thank you very much for your attention we have a few minutes for some Q&A I know there is a lot of information here the idea

is certainly to not trigger your interest and obviously if you want to know more about it feel free to reach out anytime Lucas how about you yeah thank you thank you for for presentation really good but maybe I want to have only ask you about something because I'm always thinking about the security and and trying to find way if those data those uh uh uh those system

are separate if the clients want because you you you tell that you learn the system for private data or global data right and some clients want to have only private I think you may have the private uh uh things right that that's correct yes so to make an AML work it's best you need to have a combination of private and so internal and external data sources and

you need to protect these data sources by preventing sharing I describe one technique which is a called uh confidential Computing there are a few other ones that are used uh most organization simply encrypt data with asymmetric encryption which is a good way of doing the only challenge is that uh then you need to protect your keys as so if your keys are compromised then obviously your encryption

is compromised as well with confidential Computing said encryption is at Hardware level so is the encryption key is in the CPU the only way to compromise uh trusted execution environment is to compromise the hardware all right thank you thank you now we're waiting maybe a few seconds for another questions if you have some place place us on the chat and I will show the uh all all

those questions on the screen guys uh and maybe uh before we we uh we decide to finish I I want to ask you uh uh how long it Stakes the uh learning process yeah good question um it is typically hours uh it depends obviously on the volume of of data and the number of data points that are analyzed and the volume of transactions uh this algorithm take

hours and hours to complete the training and I I believe uh when we ran it for the first time it took like 12 hours or something H but then the the beauty of it is that you don't need to do a full training all the time you do an incremental retraining with a new transaction that come and the ret trining still take time though because every day

there are transactions right so it's not something that changes once in a while like every week or every month every day you have new transaction so every day there is a retraining process in place so this why it's also important to set up your Cloud infrastructure properly the infrastructure for training and retraining has to be quite robust possibly even using gpus that are know more powerful for

this numeric calculation and instead the infrastructure for the scoring so which is the prediction based on the train model can be a bit more a bit lighter because you don't need a lot of computing power for the scoring mechanism a cool that's cool so yeah consider AML also from a microservice perspective we have that was my next question that's right the other oneing absolutely yeah yeah because

the clients if they if the clients want to send the new data then they always open it for right over the some API or okay is yes yeah well question I think yeah I think we we may close close to finish and if you don't uh don't have any U any ideas want to me to say more because the time is is almost finishing got 1 minute

minutes if anybody wants to want to um ask about something three two one no one okay that's right yes glad to be here enjoy the the conference this is a great event it's my second time uh and um yeah look forward one day to meet everybody in person have a good day yeah bye everybody thank you very much bye-bye thanks for