Artigo
12/06/2023
Atualizado em 10/04/2026

Open Compliance, are you ready for it? Can Anti-Fraud teams help you out? ENGLISH AND PORTUGUESE

O compartilhamento regulado de indícios de fraude pode aproximar compliance, controles internos e antifraude na defesa contínua do sistema financeiro.

Resumo

Imagem de capa do artigo

Open Compliance, are you ready for it? Can Anti-Fraud teams help you out?

What comes first? Is it the crime or its classification in the norm? Such questioning is something that increasingly generates speed with the innovations that criminals make in different spheres and environments, and without a doubt the virtual environment, especially financial institutions, must be aware of the generating fact of an illicit act.

Customer behavior, the way they register and update their data are factors that require close attention in areas of investigation and fraud. Identify and verify (ID&V) must be a joint action with registration and due diligence areas with technological support that somehow supports decisions to block a suspected crime or the continuity of a monitored relationship. This equation makes the investment in the defense of customers, the financial institution and the financial system itself continuous and without rest, with teams and systems operating 24 hours a day, seven days a week.

Despite advances in data protection laws, initiated with the GPDR in Europe and adapted in several countries, including Brazil, with the LGPD, the central bank of Brazil (BACEN) recently published joint resolution number 6, which provides the requirements for sharing data and information on evidence of fraud between financial institutions that are authorized to operate by BACEN.

This norm strengthens what is already demonstrated the need for the development of protection, providing security and privacy of information to be shared between institutions, either by the customer's consent to register their data via contract at the beginning of the banking relationship and consequently having a registration system evidence of crimes accessed by other banks, with reports to be created by an auditing company with this expertise.

Additionally, internally, there is a need for the internal controls team to act, ensuring the effectiveness of compliance with the rules by carrying out their usual activities.

This evolution, summarized in the BACEN rule, may, from a financial system defense point of view, be the embryo of "Open Compliance", there is already "Open Finance" in which data from healthy customers, through their authorizations, are shared for It is better to offer products and needs to those seeking financial solutions, whether on your cell phone or your home banking screen, there will always be such an option.

But, isn't it time for bank compliance areas to go hand in hand? Not only in committees of various regulators, but in everyday life, creating “red flags” about some type of monitoring, being it KYC, AML or even better communications about atypicalities? Defending that the “lines of defense”, especially compliance and internal controls have this interaction approved by the regulator will generate more speed and more assertive risk classifications, especially when we go to the risk-based approach, which, basically, each one, each institution, performs the way it fits, where a client can be high risk in one business and low in another, this equation does not fit and must be aligned with the reality of the security of the national financial system. Who wins? Everyone, be it society, the banks, the regulator, generating more and more innovative ideas to protect the business.

Link to the norm:

https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20Conjunta&numero=6

Open Compliance, você está pronto para isso? As equipes antifraude podem ajudá-lo?

O que vem primeiro? O crime ou a tipificação dele na norma? Tal questionamento é algo que cada vez gera mais velocidade com as inovações que criminosos fazem em diferentes esferas e ambientes, e sem dúvidas o ambiente virtual, especialmente de instituições financeiras deve estar atento ao fato gerador de um ato ilícito.

O comportamento do cliente, a forma de cadastro e de atualizações de seus dados são fatores que necessitam de muita atenção por áreas de investigação e fraudes. Identificar e verificar ou seja (ID&V) devem ser uma ação conjunta com áreas de cadastro e due diligence com suporte tecnológico que de alguma forma dê suporte às decisões de bloquear uma suspeita de crime ou da continuidade de um relacionamento monitorado. Tal equação faz com que o investimento na defesa dos clientes, da instituição financeira e do próprio sistema financeiro seja contínuo e sem descansos, com equipes e sistemas atuando 24 horas por dia e sete dias por semana.

Apesar dos avanços de leis de proteção de dados, iniciados com a GPDR na Europa e adaptados em diversos países, inclusive no Brasil, com a LGPD, o banco central do Brasil (BACEN) publicou recentemente a resolução conjunta número 6, que dispõe sobre os requisitos para compartilhamento de dados e informações sobre indícios de fraude entre instituições financeiras que são autorizadas a funcionar pelo BACEN.

Tal norma fortalece a necessidade já demonstrada de haver o desenvolvimento de proteção, dando segurança e privacidade de informações a serem compartilhadas entre as instituições, sejam pelo consentimento do cliente para registrar seus dados via contrato ao início do relacionamento bancário e consequentemente haver um sistema de registro de indícios de crimes com acesso pelos demais bancos, com relatórios a serem criados por empresa de auditoria com esta expertise.

Adicionalmente, no âmbito interno, há a necessidade de atuação da equipe de controles internos, assegurando a efetividade do cumprimento das normas realizando suas atividades costumeiras.

Esta evolução, resumida da norma do BACEN, pode, num ponto de vista de defesa do sistema financeiro, ser o embrião do “Open Compliance”, já há o “Open Finance” em que dados de clientes saudáveis, mediante suas autorizações são compartilhados para melhor oferecer produtos e necessidades aos que buscam soluções financeiras, seja na tela de seu celular ou do seu home banking, sempre haverá tal opção.

Mas, será que não está na hora de áreas de compliance dos bancos andarem de mãos dadas? Não somente em comissões de reguladores diversos, mas no dia a dia, criar “alertas vermelhos” sobre algum tipo de monitoramento, seja este de KYC, de PLD e até mesmo de melhores comunicações sobre atipicidades? Defender que as linhas “de defesa”, especialmente compliance e controles internos tenham esta interação homologada pelo regulador gerará mais velocidade e classificações de risco mais assertivas, especialmente quando tocamos na abordagem baseada em risco, que, basicamente, cada um, cada instituição, realizada do jeito que lhe cabe, onde, um cliente pode ser alto risco em um negócio e baixo no outro, esta equação não bate e deve ser alinhada com a realidade da segurança do sistema financeiro nacional. Quem ganha com isso? Todos, seja a sociedade, os bancos, o regulador, gerando cada vez mais ideias inovadoras para proteção do negócio.

Link para a norma:

https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20Conjunta&numero=6

What comes first? Is it the crime or its classification in the norm? Such questioning is something that increasingly generates speed with the innovations that criminals make in different spheres and environments, and without a doubt the virtual environment, especially financial institutions, must be aware of the generating fact of an illicit act.

Customer behavior, the way they register and update their data are factors that require close attention in areas of investigation and fraud. Identify and verify (ID&V) must be a joint action with registration and due diligence areas with technological support that somehow supports decisions to block a suspected crime or the continuity of a monitored relationship. This equation makes the investment in the defense of customers, the financial institution and the financial system itself continuous and without rest, with teams and systems operating 24 hours a day, seven days a week.

Despite advances in data protection laws, initiated with the GPDR in Europe and adapted in several countries, including Brazil, with the LGPD, the central bank of Brazil (BACEN) recently published joint resolution number 6, which provides the requirements for sharing data and information on evidence of fraud between financial institutions that are authorized to operate by BACEN.

This norm strengthens what is already demonstrated the need for the development of protection, providing security and privacy of information to be shared between institutions, either by the customer's consent to register their data via contract at the beginning of the banking relationship and consequently having a registration system evidence of crimes accessed by other banks, with reports to be created by an auditing company with this expertise.

Additionally, internally, there is a need for the internal controls team to act, ensuring the effectiveness of compliance with the rules by carrying out their usual activities.

This evolution, summarized in the BACEN rule, may, from a financial system defense point of view, be the embryo of "Open Compliance", there is already "Open Finance" in which data from healthy customers, through their authorizations, are shared for It is better to offer products and needs to those seeking financial solutions, whether on your cell phone or your home banking screen, there will always be such an option.

But, isn't it time for bank compliance areas to go hand in hand? Not only in committees of various regulators, but in everyday life, creating “red flags” about some type of monitoring, being it KYC, AML or even better communications about atypicalities? Defending that the “lines of defense”, especially compliance and internal controls have this interaction approved by the regulator will generate more speed and more assertive risk classifications, especially when we go to the risk-based approach, which, basically, each one, each institution, performs the way it fits, where a client can be high risk in one business and low in another, this equation does not fit and must be aligned with the reality of the security of the national financial system. Who wins? Everyone, be it society, the banks, the regulator, generating more and more innovative ideas to protect the business.

Link to the norm:

https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20Conjunta&numero=6

Material consultado via Okai.
As opiniões dos autores convidados da nossa comunidade são independentes e não necessariamente representam a opinião da Okai.
Atualizado

Não há sinal de desatualização relevante neste conteúdo.

Perguntas e respostas

Quais cuidados o compartilhamento exige?
Segurança, privacidade, base adequada, consentimento quando aplicável, registros, auditoria e controles internos efetivos.
O que seria Open Compliance?
Uma cooperação estruturada entre instituições e funções de controle para compartilhar indícios e fortalecer prevenção e monitoramento.
Qual benefício se espera para o sistema financeiro?
Alertas mais rápidos, classificações mais consistentes e maior capacidade de impedir fraudes e atividades atípicas.
Como equipes antifraude podem contribuir?
Integrando sinais comportamentais, cadastro, verificação, investigação e tecnologia às decisões de risco e continuidade do cliente.

Conteúdo gerado com apoio de IA. Não substitui análise profissional.

Autor

AP

Alison Dorigão Palermo

Diretor de Compliance | AML | KYC | Fintech | Apostas & Crypto | +18 anos em Risco Reg., ESG e GRC | Ex-Nuvei | Consultor | Professor | Autor | Palestrante | Top Voice em Compliance