ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Insider risk: Learning and combatting misconceptions

October 3, 2025
Reading Time: 2 mins read
Insider risk: Learning and combatting misconceptions

Although banks have invested in systems designed to detect and prevent threats emanating from external illicit activities, insider threats often are underestimated.

Insider threats — from negligent behavior to malicious intent — demand a coordinated response to detection, escalation and mitigation, according to experts. A session at the upcoming ABA Financial Crimes Enforcement Conference will explore how financial institutions are integrating anti-money laundering, fraud, cyber, and conduct risk insights to detect behavioral red flags, manage insider risk and foster a culture of compliance.

According to Matthew S. Haslinger, EVP and chief BSA/AML and sanctions compliance officer for M&T Bank and session panelist, insider risk has evolved from negligent or rogue employees to complex, organized collusion, and remote work has expanded the threat.

“Larger banks tend to have more robust insider threat programs, but smaller banks can be more agile,” Haslinger said. “Midsize institutions often struggle with resource constraints. That said, the risk is present across all sizes [of institutions], but impact and detection capabilities vary. Smaller banks may face higher risk due to limited monitoring tools. Overall, this is a risk that all banks need to be thinking about and addressing through a risk-based approach.”

Haslinger said one of the biggest misconceptions among banks is that insider risk only involves intentional misconduct — like employees stealing money, selling customer data, or colluding with criminals.

“In reality, insider threat is often just as much about negligence or human error as it is about malicious actors,” he said. “For example, employees mishandling sensitive data, failing to follow AML procedures or clicking on phishing links can create the same level of regulatory, reputational and financial exposure as deliberate misconduct.

Another popular misconception is that insider threats are rare or limited to a few bad actors.

“In truth, every employee, contractor or third-party partner has the potential to become an insider threat under the right circumstances — whether through financial stress, coercion, lack of training or even burnout,” he explained.

Banks should be engaged in proactive detection and cross-departmental collaboration, Haslinger said, and it’s something they often aren’t doing or don’t realize they should.

“Banks often silo human resources, security, compliance and IT monitoring,” he explained. “Few have a centralized insider threat program that integrates behavioral red flags, access logs, policy violations and financial stress indicators. Many banks focus on fraud or data theft, but they don’t connect insider risk to failures in suspicious activity reporting, know-your-customer remediation, or sanctions screening. Recent enforcement actions are a reminder that insiders can directly undermine AML programs.”

Haslinger said banks need to understand that risk is a people problem and not just a technical one.

It’s a financial crimes compliance risk that Bank Secrecy Act and fraud officers need to work together to address.” He said. “Prevention requires culture, training and visibility. Don’t wait for a breach — proactive detection and continuous education are key.”

Editor’s note: Haslinger recently co-authored an in-depth article on bank insider risk for the ABA Banking Journal.

Tags: Bank Secrecy ActEmployeesFraudRisk management
ShareTweetPin

Author

Christopher Delporte

Christopher Delporte

Christopher Delporte is a senior editor for the ABA Banking Journal and vice president of editorial strategy for member communications at the American Bankers Association.

Related Posts

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN updates guidance for financial institutions on sharing information about fraud

Compliance and Risk
June 12, 2026

FinCEN issued an updated fact sheet to clarify how financial institutions can share information with each other about suspected fraud under the provisions of the USA PATRIOT Act.

Reports explore information exposure, costs of data breaches

Report: Software vulnerabilities become top vector for data breaches

Compliance and Risk
June 12, 2026

Exploitation of software vulnerabilities has become the most common initial access vector for data breaches, according to the most recent Data Breach Investigations Report by Verizon.

CFPB, DOJ warn against using immigration status to determine creditworthiness

Podcast: Understanding bank regulators’ guidance on illegal immigration

ABA Banking Journal Podcast
June 11, 2026

On the ABA Banking Journal Podcast, ABA's Heather Trew breaks down recent news about the president's executive order on illegal immigration and the financial system and the FinCEN advisory on red flags associated with the employment of illegal...

OCC to merge community bank, large bank supervision departments

OCC publishes draft reporting forms for stablecoin issuers

Compliance and Risk
June 11, 2026

The OCC has released for public review draft forms that will be used to collect information from payment stablecoin issuers under its jurisdiction.

With AI threats, CISA offers agencies guidelines for patching software vulnerabilities

With AI threats, CISA offers agencies guidelines for patching software vulnerabilities

Compliance and Risk
June 11, 2026

CISA released a new framework for federal civilian agencies in determining how quickly to patch software vulnerabilities, noting that artificial intelligence is “vastly increasing” the pace at which such vulnerabilities are discovered.

CFPB claims ‘complex’ pricing drives up cost of financial products

Trump nominates Johnson to lead CFPB

Compliance and Risk
June 10, 2026

President Trump nominated bank executive Brian Johnson to lead the CFPB, which has been without a full-time leader since the firing of Rohit Chopra last year.

NEWSBYTES

FinCEN updates guidance for financial institutions on sharing information about fraud

June 12, 2026

Report: Software vulnerabilities become top vector for data breaches

June 12, 2026

ABA DataBank: A tale of two cabins

June 12, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Understanding bank regulators’ guidance on illegal immigration

June 11, 2026

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.