Digital Financial Crime Demands Smarter, Data-driven Compliance - Labuan FSA
By Jailani Hasan
LABUAN, Aug 4 (Bernama) -- Financial institutions must adopt more intelligent, data-driven and risk-based compliance systems as financial crimes become increasingly digital, interconnected and difficult to trace.
Labuan Financial Services Authority (Labuan FSA) deputy director-general Syahrul Imran Mahadzir noted that developments involving digital assets, tokenisation, stablecoins, artificial intelligence-enabled financial services and automated electronic know-your-customer processes have become part of mainstream financial risk considerations. “Financial crime has also gone digital. It is faster, more networked, more sophisticated and does not respect borders,” he said in his opening remarks at the Second Labuan International Compliance Conference 2026 (LICC 2026) here today.
Syahrul said proceeds from fraud, cybercrime, illegal online gaming and investment scams could eventually enter the formal financial system through legitimate-looking business dealings. The issue facing regulators and the financial industry was not a choice between innovation and regulation, but the need to pursue innovation responsibly, he added.
New technologies and innovative business models should be allowed to grow, but must be supported by safeguards capable of preserving confidence, credibility and the integrity of the financial system, he advised. “Technology can generate alerts, dashboards can show trends and artificial intelligence can detect patterns, but sound judgement remains essential. The most important question in compliance is still a human one: Does this make sense?” he said, adding that global compliance standards were increasingly shifting from paperwork to demonstrable outcomes.
Although policies, customer files and compliance checklists remain important, regulators also expected financial institutions to prove that risks were properly understood, controls were functioning and warning signs were acted upon promptly. “A well-completed file is important, but a well-understood customer is far more valuable,” he added.
He observed that compliance officers were no longer merely interpreters of regulatory requirements, but also served as risk translators, control advisers and guardians of organisational trust.
Syahrul highlighted that the 2025 Financial Action Task Force Mutual Evaluation report recognised Malaysia’s strengthened defences against illicit finance, with 24 recommendations rated “compliant” and 16 rated “largely compliant”. However, he noted that fraud and investment scams, cross-border criminal activities and the misuse of corporate structures remain key elements of the country’s evolving risk profile.
The expansion of virtual assets, including stablecoins and unhosted wallets, could also create additional channels for money laundering and terrorism financing through peer-to-peer transfers, cross-chain transactions and virtual asset networks.
Syahrul said an FATF targeted report noted that stable-coins had exceeded US$300 billion in market capitalisation by mid-2025, while illicit activities increasingly involved virtual assets. The United Nations Office on Drugs and Crime estimated that industrial-scale scam centres generated just under US$40 billion in annual profits, with proceeds laundered through cryptocurrencies, underground banking networks and global financial channels.
Global financial institution penalties during the first half of 2025, meanwhile, totalled about US$1.23 billion, representing a 417 per cent increase from the previous year, with digital asset firms receiving greater regulatory attention, according to Syahrul. Against this background, he outlined four priorities for financial institutions.
He said institutions must understand their customers rather than merely maintain customer records, particularly in relation to cross-border activities, complex ownership structures, sources of funds and digital asset exposure. They must also strengthen intelligence-led transaction monitoring, sanctions screening and escalation procedures to identify unusual activities more efficiently.
He said compliance controls should be proportionate to each Labuan institution’s business model, customer base and risk profile, particularly as many institutions were branches or subsidiaries of international financial groups. “At the same time, compliance should not operate in isolation or unnecessarily constrain legitimate business. It must strike the right balance, robust enough to uphold accountability and regulatory confidence while supporting responsible business growth,” he added.
-- BERNAMA