IN THE HIGH COURT OF NEW ZEALAND AUCKLAND REGISTRY
I TE KŌTI MATUA O AOTEAROA TĀMAKI MAKAURAU ROHE
CIV 2024-404-314
[2024] NZHC 2781
UNDER The Anti-Money Laundering and Countering Financing of Terrorism Act 2009 BETWEEN
THE DEPARTMENT OF INTERNAL AFFAIRS
Plaintiff
AND
SKYCITY CASINO MANAGEMENT LIMITED
Defendant
Hearing: 5 September 2024 Appearances:
S McMullan for the plaintiff
B A Keown and A M Boberg for the defendant
Judgment:
26 September 2024
JUDGMENT OF CAMPBELL J
This judgment was delivered by me on 26 September 2024 at 12.30 pm pursuant to Rule 11.5 of the High Court Rules
Registrar/Deputy Registrar
THE DEPARTMENT OF INTERNAL AFFAIRS v SKYCITY CASINO MANAGEMENT LTD [2024] NZHC
2781 [26 September 2024]
Introduction
[1] SkyCity Casino Management Ltd (SkyCity) operates casinos in New Zealand. Since 2013, SkyCity has been subject to obligations under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (the Act). The Department of Internal Affairs (the Department) is the supervisor responsible for monitoring and enforcing SkyCity’s compliance with the Act.
[2] The Department commenced this civil proceeding against SkyCity on 16 February 2024, alleging breaches of the Act and seeking pecuniary penalties. SkyCity constructively engaged with the Department to resolve the matter. On 21 May 2024, the parties reached a settlement in which SkyCity admitted to five breaches of the Act during the period from 16 February 2018 to 22 March 2023 (the relevant period).
[3] As part of the settlement, the parties agreed to jointly approach the Court to seek the imposition of a pecuniary penalty at an agreed level. The parties agree that SkyCity should be ordered to pay a penalty of $4.16 million in respect of SkyCity’s admitted breaches of the Act. The parties also acknowledge that the amount of any penalty is a matter for the Court to determine.
[4] The Court’s role in such circumstances is not to embark on its own enquiry of what would be an appropriate penalty but to consider whether the proposed penalty is within the proper range. I am satisfied, for the reasons that follow, that it is within range.
SkyCity’s business
[5] SkyCity is a wholly-owned subsidiary of SkyCity Entertainment Group Ltd (SkyCity Group), which is the largest tourism, leisure and entertainment company in New Zealand. SkyCity operates three casinos in New Zealand. Other SkyCity Group companies hold, or held, licences to operate casinos in Australia.
[6] Between the financial years ending 30 June 2018 and 30 June 2023, SkyCity Group’s gaming-related revenues, a significant proportion of which was derived from SkyCity’s business, totalled between $430 million and $763 million per year.
[7] SkyCity caters to various sectors of the gaming market. During the relevant period, it operated an international business programme which catered for high-net- worth international customers. Between the financial years ending 30 June 2018 and
30 June 2020, SkyCity Group’s gaming-related revenue associated with its international business programme alone (including at its Australian casinos) totalled between $76 million and $139 million per year. This accounted for between 10 and 15 per cent of SkyCity Group’s overall business.
[8] Between 16 February 2018 and April 2021, as part of its international business programme, SkyCity: conducted transactions involving other casinos outside New Zealand at the request of, or in relation to, international customers; used accounts with banks outside New Zealand to make or receive payments; received or made payments through money remitters on behalf of international customers; and received cash payments from, or on behalf of, international customers. Also, until April 2021 SkyCity’s international business programme included the use of group commission programmes, commonly referred to as junkets. Many of these services were assessed by SkyCity as having an inherently high risk of money laundering and financing of terrorism (ML/FT).
SkyCity’s obligations under the Act
[9] SkyCity, as the holder of a casino operator’s licence, is a “reporting entity’ under the Act. As a reporting entity, SkyCity has a number of anti-money laundering and countering the financing of terrorism (AML/CFT) obligations under the Act. I now outline the obligations that are relevant to this proceeding.
Undertake and review an ML/FT risk assessment, and establish, implement and maintain an ML/FT compliance programme
[10] By s 58(1) of the Act, SkyCity is obliged to undertake an assessment of the risk of ML/FT that it may reasonably expect to face in the course of its business (ML/FT risk assessment). In assessing that risk, SkyCity must have regard to the matters set out in s 58(2). These include matters such as the size and complexity of its business, the products and services it offers, and the types of customers it deals with.
[11] By s 56, SkyCity is obliged to establish, implement, and maintain a compliance programme that includes internal procedures, policies, and controls to detect ML/FT and manage and mitigate the risk of ML/FT (AML/CFT compliance programme). The AML/CFT compliance programme must be in writing and be based on the ML/FT risk assessment. It must include adequate and effective procedures, policies and controls for the matters set out in s 57(1). Relevantly, these include complying with customer due diligence requirements (including account monitoring), reporting suspicious activities and prescribed transactions, and setting out what SkyCity needs to do, or continue to do, to manage and mitigate the risk of ML/FT.
[12] This Court has rightly said that a risk assessment and compliance programme are “foundational aspects of the Act”1 and that the requirements of these documents are “intended to ensure that reporting entities can fulfil their [customer due diligence] and reporting obligations”.2
Conducting account monitoring
[13] By s 31, SkyCity is obliged to monitor its customers’ accounts. This includes ensuring that the information its customers provided initially continues to match their activities and transaction behaviour, having regard to the level of risk posed by each customer, and ensuring it has systems in place to identify transactions, or patterns of transactions, that raise a suspicion of ML/FT. To discharge this obligation, SkyCity must regularly review its customers’ account activity and transaction behaviour, as well as the information its customers provided at the start of their business relationship with SkyCity.
Conducting customer due diligence
By s 14, SkyCity is required to conduct customer due diligence if it establishes a business relationship with a new customer, or if a customer seeks to conduct an “occasional transaction” through SkyCity. The records obtained from customer due diligence allow supervisors (such as the Department) to perform their functions under the Act. Customer due diligence is therefore central to the Act.
1 Department of Internal Affairs v OTT Trading Group Ltd [2020] NZHC 1663 at [6].
2 Reserve Bank of New Zealand v TSB Bank Ltd [2021] NZHC 2241, [2021] NZCCLR 27 at [5].
The level of due diligence required depends on the ML/FT risk presented by the individual customer or transaction. At a minimum, SkyCity is obliged to conduct “standard” due diligence. Under ss 15–17, this requires SkyCity to obtain verified information relating to each customer’s identity, the nature and purpose of the proposed business relationship, and sufficient information to determine whether the customer should be subject to “enhanced” customer due diligence.
Enhanced customer due diligence requires SkyCity to obtain additional information, including verified information relating to the source of the customer’s funds or wealth: ss 23 and 24. Under s 22, the circumstances in which enhanced due diligence is required include where a customer seeks to conduct a transaction which is complex or unusually large or is a part of an unusual pattern of transactions that have no apparent economic or lawful purpose, or when SkyCity considers that the level of risk involved with a customer is such that enhanced due diligence should be conducted. Under s 22A, it is also required whenever a suspicious activity report must be filed in respect of an existing customer.
Terminating existing business relationships
If SkyCity is unable to conduct due diligence on a customer, s 37 provides that SkyCity must not establish a business relationship with the customer and must terminate any existing business relationship with the customer. This prohibition underpins the customer due diligence regime.
SkyCity’s admitted breaches of the Act: its “civil liability acts”
Breaches of the Act’s AML/CFT obligations are, under s 78 of the Act, termed “civil liability acts”. SkyCity admitted to five civil liability acts during the relevant period. These are that it failed:
(a)to undertake and review an ML/FT risk assessment that complied with the Act;
(b)to establish, implement and maintain an AML/CFT compliance programme;
(c)to conduct adequate account monitoring;
(d)to conduct enhanced customer due diligence; and
(e)to terminate existing business relationships when required.
I provide more detail on the manner in which SkyCity breached the Act later in this judgment, when considering the appropriate pecuniary penalty for each civil liability act.
Pecuniary penalties for civil liability acts
[14] Under s 79 of the Act, there are several possible responses to civil liability acts, ranging in seriousness from the Department issuing a formal warning to the court ordering a pecuniary penalty. The parties agree that a pecuniary penalty is the appropriate response to SkyCity’s civil liability acts.
Approach to determining pecuniary penalties
[15]Section 90(4) of the Act provides:
90 Pecuniary penalties for civil liability act
…
(4)In determining an appropriate pecuniary penalty, the court must have regard to all relevant matters, including—
(a)the nature and extent of the civil liability act; and
(b)the likelihood, nature, and extent of any damage to the integrity or reputation of New Zealand’s financial system because of the civil liability act; and
(c)the circumstances in which the civil liability act occurred; and
(d)whether the person has previously been found by the court in proceedings under this Act to have engaged in any similar conduct.
[16] The approach to determining the amount of a pecuniary penalty is now well- established.3 There is a four-step approach:
(a)Starting point: assess the seriousness of the civil liability act to select a starting point based on the seriousness of the non-compliance and the aggravating and mitigating factors relating to it.
(b)Aggravating and mitigating factors specific to the reporting entity: consider aggravating and mitigating factors of the reporting entity, to determine whether these warrant the imposition of a higher or lower penalty.
(c)Admissions and cooperation: make deductions from the starting point to reflect any admission of liability or cooperation with the authorities.
(d)Totality: undertake a totality assessment to ensure there is no overlap between the penalties imposed for difference types of non-compliance, and consider whether the total penalty imposed fairly and adequately reflects the overall extent of non-compliance.
[17] In Financial Markets Authority v ANZ Bank Limited, Muir J reviewed pecuniary penalty decisions under the Act and summarised the penalties that had been imposed as follows:4
(a)between 50 and 70 per cent of the available maximum for conduct involving:
(i) “serious, systemic deficiencies in complying with a multiplicity of obligations under the Act” in circumstances showing a disregard of the Act’s requirements.5
(ii)long-term noncompliance with the Act, despite prior oversight and warnings from the Department of Internal Affairs and despite
3 Department of Internal Affairs v Ping An Finance (Group) New Zealand Co Ltd [2017] NZHC 2363, [2018] 2 NZLR 552 at [88]. This has been applied in several cases, including Department of Internal Affairs v OTT Trading Group Ltd [2020] NZHC 1663 at [51] and Financial Markets Authority v Tiger Brokers (NZ) Ltd [2023] NZHC 1625 at [32].
4 Financial Markets Authority v ANZ Bank New Zealand [2021] NZHC 399, (2021) 16 TCLR 28 at [80].
5 Ping An, above n 3, at [6].
the company having had ample evidence that the transactions’ processed [sic] were suspicious.6
(iii)“brazen” contraventions of the enhanced due diligence requirements occurring across a significant volume of transactions.7
(b)between 25 and 33 per cent of the available maximum for conduct involving significant contraventions, but in circumstances which suggested that a defendant had made at least some attempt to comply with their obligations;8 and
(c)between 6 and 11 per cent of the available maximum for conduct involving inadvertent breaches by a company which was unaware that it was substantially noncompliant.9
[18] In Financial Markets Authority v Tiger Brokers (NZ) Ltd, Gault J said that Muir J’s summary was “a helpful cross-check in relation to totality”.10 I agree.
Maximum penalties
[19] Section 90 sets maximum penalties for four of the civil liability acts committed by SkyCity. For failing to conduct customer due diligence and for failing to establish, implement, or maintain an AML/CFT compliance programme the maximum penalty is
$2 million. For failing to terminate a business relationship and for failing to adequately monitor accounts and transactions the maximum penalty is $1 million.
[20] Section 90 does not set a maximum penalty for the other civil liability act committed by SkyCity (failing to undertake and review an ML/FT risk assessment). This appears to have been a drafting oversight. A series of cases have taken the view that a maximum penalty of $2 million should nonetheless be adopted, as this civil liability act has much in common with the civil liability acts for which a maximum penalty of $2 million has been specified.11 I agree with that approach.
[21] Accordingly, the total maximum penalty available against SkyCity for the five civil liability acts is $8 million.
6 Department of Internal Affairs v Jin Yuan Finance Ltd [2019] NZHC 2510 at [40]–[45].
7 OTT Trading, above n 3, at [70], [105] and [108].
8 At [73].
9 Department of Internal Affairs v Qian Duoduo Ltd [2018] NZHC 1887 at [148].
10 Tiger, above n 3, at [34].
11 Ping An, above n 3, at [82]–[85], and Qian Duoduo, above n 9, at [23].
Court’s role where penalties are agreed
[22] The Court’s role, where a penalty has been agreed between the parties, is not to embark on its own enquiry of what would be an appropriate figure but to consider whether the proposed penalty is within the proper range.12 To be within the proper range, the Court must be satisfied that the proposed penalty satisfies the objectives of the Act and reflects the particular circumstances of the case.13
[23] The Court adopts this role because there is a significant public benefit when reporting entities acknowledge wrongdoing, thereby avoiding time-consuming and costly investigation and litigation. The Court should play its part in promoting such resolutions by accepting a proposed penalty if it is within the proper range.14
Is the proposed penalty within the proper range?
In determining whether the proposed penalty of $4.16 million is within the proper range, I start by describing the way in which SkyCity’s compliance with the Act was monitored from 2014 to 2023. I do so because this is relevant background to an assessment of the seriousness of each of the civil liability acts admitted by SkyCity. I then follow the four-step approach to determine the proper range of penalties, by:
(a)assessing the starting points for the five civil liability acts;
(b)considering the aggravating and mitigating factors specific to SkyCity;
(c)making deductions for SkyCity’s admissions and cooperation; and
(d)undertaking a totality assessment.
Background: monitoring SkyCity’s compliance with the Act
[24] The Department’s supervisory role includes assessing the overall inherent ML/FT risk for the casino sector. This was considered high from April 2014 to
12 Financial Markets Authority v Cigna Life Insurance New Zealand Ltd [2022] NZHC 3610 at [47].
13 Financial Markets Authority v ANZ Bank New Zealand [2021] NZHC 399, (2021) 16 TCLR 28 at [32].
14 Tiger, above n 3, at [36].
September 2018, and medium-high from September 2018. SkyCity was aware of these assessments.
[25] The Department has powers to conduct desk-based reviews of SkyCity’s ML/FT risk assessment and AML/CFT compliance programme, and to conduct on-site inspections of its casino premises, in order to monitor SkyCity’s compliance with the Act. Such reviews and inspections were undertaken in 2014 and annually between 2018 and 2023.
[26] In 2014, the Department carried out a desk-based review of SkyCity’s ML/FT risk assessment and AML/CFT compliance programme and undertook an on-site inspection of SkyCity’s AML/CFT policies and processes at three of its New Zealand casinos. These concluded there was an overall high level of compliance in relation to SkyCity’s systems and processes, but identified several concerns with SkyCity’s compliance with the Act. SkyCity engaged with the Department in late 2014 and early 2015 regarding areas for improvement.
[27] In December 2018, the Department completed another desk-based review of SkyCity’s compliance with its obligations under the Act. This concluded that SkyCity’s written risk assessment and AML/CFT compliance programme largely met the Act’s requirements. The review also made two recommendations to SkyCity.
[28] In April and May 2019, the Department carried out an on-site inspection. The Department concluded that SkyCity had met most of its AML/CFT obligations in relation to the policies, procedures and controls that the Department had assessed. However, the Department also identified a number of issues, including in respect of SkyCity’s ML/FT risk assessment and its obligations to conduct enhanced due diligence and monitor accounts. SkyCity acknowledged the findings and said it would address some of the Department’s concerns.
[29] The Department undertook a limited desk-based review in December 2020. This focussed on SkyCity’s compliance with the Act in relation to transactions involving three international customers who were the subject of a Police investigation.
That review stated that SkyCity had failed to meet its enhanced customer due diligence obligations in relation to two of the three customers.
[30] The Department conducted an on-site inspection in March 2021. That inspection concluded that SkyCity had largely remediated the findings from the 2019 on-site inspection but identified several further concerns. The concerns related predominantly to SkyCity’s account monitoring practices and systems.
[31] In addition to the Department’s oversight, SkyCity engaged Ernst and Young (EY) to independently audit its ML/FT risk assessment and AML/CFT compliance programme. EY completed two independent reports in 2019 and 2021. These found that SkyCity had a detailed ML/FT risk assessment and AML/CFT compliance programme that were aligned with the requirements of the Act. The reports also made several findings and observations about SkyCity’s suspicious activity and transaction reporting, account monitoring, enhanced due diligence and risk assessment.
[32] SkyCity amended its ML/FT risk assessment and AML/CFT compliance programme periodically, including in response to issues identified by the Department or EY. SkyCity was aware it did not have an ML/FT risk assessment and AML/CFT compliance programme which complied in all respects with the Act until 31 July 2021, by which time matters of which SkyCity was aware were fully remediated.
[33] The Department undertook another on-site inspection in September 2022. The Department then issued notices requiring that certain records and information be provided. On 23 August 2023, the Department commenced a review of SkyCity’s compliance with its obligations under the Act for the period 1 January 2018 to 22 March 2023. As a result of the review, the Department identified varying degrees of non-compliance in four specific areas:
(a)Transactions involving other casinos.
(b)SkyCity’s use of foreign holding accounts.
(c)Transactions involving money remitters.
(d)The receipt of cash payments into casino deposit accounts, including by third parties.
[34]Following that review, the Department commenced this proceeding.
Starting point for failing to undertake and review an ML/FT risk assessment
SkyCity’s breach
[35] SkyCity knew that it functioned in a fairly high ML/FT risk environment. In particular, SkyCity knew that the Department assessed the overall inherent ML/FT risks for casinos as high from April 2014 to September 2018 and as medium-high from September 2018. In relation to its international business, SkyCity knew that the Department assessed junkets as posing high ML/FT risk factors.
[36] Despite its awareness of these risks, from 16 February 2018 SkyCity’s ML/FT risk assessment did not have regard, or adequate regard, to several risks relevant to its gaming services for international customers. These were:
(a)Prior to March 2019, the risks associated with engaging in transactions with other casinos within the SkyCity Group.
(b)Prior to September 2020, the inherent risks associated with different customer types or with a customer’s country of origin.
(c)Prior to July 2021, the risks associated with dealings with casinos outside SkyCity Group, transactions made through foreign holding accounts, and third-party transactions involving money remitters.
SkyCity was aware of some of these deficiencies from its interactions with the Department during reviews and on-site inspections. SkyCity periodically updated its ML/FT risk assessment in response. By July 2021, SkyCity had fully remediated all matters of which it had been made aware, either by updating its risk assessment or ceasing the relevant high-risk conduct.
The deficiencies in SkyCity’s ML/FT risk assessment resulted in or contributed to a number of significant consequences. Contrary to s 58(1) of the Act, SkyCity’s risk assessment did not adequately reflect all of the ML/FT risks that it may reasonably have expected to face in the course of its business, particularly in relation to its international business. As a result, SkyCity’s AML/CFT compliance programme did not provide fully for these risks. This meant SkyCity did not have adequate procedures, policies, and controls in place to detect money laundering and the financing of terrorism, or to manage and mitigate the risk of money laundering and financing of terrorism. This also reduced SkyCity’s ability to identify and respond to ML/FT risks as they arose. For example, enhanced customer due diligence was not conducted on customers in all circumstances where it should have been.
Is the proposed starting point within the proper range?
[37] In respect of this breach, the parties propose a starting point of $1.5 million. This is 75 per cent of the adopted maximum penalty of $2 million.
[38] The parties referred me to several pecuniary penalty cases. I accept the submission of Ms Boberg, counsel for SkyCity, that most of the cases are of limited assistance. That is because many of the cases involve complete failures to have in place an ML/FT risk assessment or AML/CFT compliance programme, to conduct due diligence or to monitor accounts. Others involve reporting entities that have ignored formal warnings from their supervisors or shown disregard for the Act’s requirements.
[39] An exception is TSB,15 in which TSB had for about a year failed to conduct an ML/FT risk assessment in respect of its realty operations, instead relying on the risk assessment for its banking operations. The breach was not identified for seven months, after which TSB took steps to remediate it. The parties proposed a starting point of
$1.25 million. Mallon J said:
[93] I consider the proposed starting point to be at the top of the available range if not a little outside that range. This was not a wholesale failure by TSB to comply with its obligations under the Act in relation to its realty operations. It was a specific failure, albeit of a key component of the Act’s
15 TSB, above n 2.
requirements. It was unintentional in that TSB intended to comply with its obligations and was discussing a wider review that would encompass this work. The breach related to a seven-month period rather than extending over several years and it occurred at the start of the regime as it applied to realty businesses. It is also relevant that the realty business was a relatively small part of TSB’s overall operations.
[40] In one respect SkyCity’s breach is less serious than TSB’s: SkyCity always had an ML/FT risk assessment in place, whereas TSB had none for seven months for its realty operations. Nonetheless, I consider other factors make SkyCity’s breach significantly more serious than TSB’s. First, SkyCity’s breach spanned a longer period of time (nearly three and a half years) than TSB’s. Secondly, SkyCity’s breach covered more aspects of its business, including those relating to a number of high-risk areas of its operations. Thirdly, SkyCity’s turnover is considerably greater than TSB’s, which means its risk assessment breach had a wider exposure than TSB’s. Fourthly, SkyCity was put on notice by the Department about some of the deficiencies in its risk assessment.
[41] Taking those matters into account, I consider SkyCity’s breach to be very serious. The proposed starting point of $1.5 million is within range, albeit near the top of the range.
Starting point for failing to establish, implement and maintain an AML/CFT compliance programme
SkyCity’s breach
[42] SkyCity always had an AML/CFT compliance programme. It was based on its ML/FT risk assessment. The programme ran to hundreds of pages and was in sections, each dealing with a different obligation or set of obligations under the Act.
[43] However, SkyCity’s compliance programme was deficient in a number of respects from 16 February 2018 until July 2021. The compliance programme lacked adequate written procedures, policies, and controls relating to transactions involving other casinos, the use of foreign holding accounts, and transactions involving money remitters. The programme included enhanced customer due diligence practices that were contrary to the Act. The programme lacked transaction value thresholds which identified when enhanced customer due diligence should be conducted.
[44] These deficiencies meant SkyCity did not identify all customers in respect of whom enhanced customer due diligence should have been conducted or conduct enhanced customer due diligence when it should have. SkyCity customers engaged in just over $1.065 billion in transactions that were not subject to enhanced customer due diligence when they should have been.
[45] SkyCity’s compliance programme was also deficient in relation to account monitoring. SkyCity used an account monitoring system called “Jade”, which automatically monitored account activity and identified transactions that triggered a set of rules. On 18 January 2022, SkyCity undertook a bulk closure of historic alerts that had been generated by Jade rules that were no longer deemed effective and were generating excessive false positives. The bulk closure meant that activities that may have been suspicious, and triggered an obligation to report a suspicious activity, may not have been identified and a suspicious activity report may not have been made. It also meant that enhanced customer due diligence may not have been conducted on customers in all circumstances where it should have been.
SkyCity’s compliance programme also provided for manual account monitoring. The programme was deficient in this area, as SkyCity did not make such reports in all circumstances in which these were flagged as being required.
As a consequence of the deficiencies in SkyCity’s account monitoring, SkyCity failed to make, within the timeframes under the Act, at least 704 prescribed transaction reports and 15 suspicious activity reports.
During the course of its reviews and inspections, the Department told SkyCity of these deficiencies in its compliance programme. SkyCity did not fully remediate them until 31 July 2021.
Is the proposed starting point within the proper range?
[46] For this breach, the parties propose a starting point of $1.5 million. This is, again, 75 per cent of the maximum penalty of $2 million.
[47] The parties both say that TSB provides the closest analogy. I agree. In TSB, a starting point penalty of $1.25 million was imposed for each of two separate breaches by TSB in relation to its AML/CFT compliance programme. First, over a period of six years TSB’s programme did not contain adequate and effective documented assurance measures (as required by s 57(1)(l) of the Act). Secondly, TSB failed to review and maintain its programme: a 2017 audit identified two areas of non- compliance, and by the time of the next audit in 2019 those issues remained unaddressed.
[48] For the first breach, Mallon J considered that the main culpability factors were the length of time over which the failure occurred and the size and status of TSB as a registered bank. Factors that reduced the seriousness of the breach were that it was not a case of TSB failing to implement any AML/CFT programme, it was not a deliberate failure, and some steps were taken to implement assurance measures. Mallon J considered the proposed starting point of $1.25 million within range, although towards high side of the range.16
[49] Mallon J considered the second breach to be a little more serious than the first. The non-compliance was over a shorter period but related to issues that had been brought to TSB’s attention. TSB had then failed to follow through on action plans, system-generated alerts and internal review dates. This indicated systemic failures.
Her Honour considered the proposed starting point as not outside range.17
[50] SkyCity’s breach spans a much shorter period than TSB’s. But SkyCity’s breach is both more extensive and more serious than TSB’s. SkyCity’s breach affected SkyCity’s practices in relation to key obligations under the Act: customer due diligence and account monitoring. While SkyCity’s breach was not deliberate, it had very serious consequences. A significant number of transactions were not adequately monitored, reported or escalated when they should have been. Transactions that should have been the subject of prescribed transaction reports or suspicious activity reports were not identified or reported within the prescribed timeframes. SkyCity failed to identify and conduct enhanced customer due diligence in all instances where
16 At [42]–[43].
17 At [77].
it should have done. All this meant that SkyCity’s customers engaged in $1.065 billion in transactions that were not subject to adequate AML/CFT controls. Many of these transactions presented a high ML/FT risk.
[51] Further, SkyCity’s breach occurred despite being put on notice by the Department that its programme was deficient in some respects. Although SkyCity eventually remediated these deficiencies, it did not do so immediately.
[52] Overall, I consider SkyCity’s breach is of such magnitude and gravity that it warrants a serious penalty. The proposed penalty of $1.5 million is at the bottom of what I consider to be the available range.
Starting point for failing to conduct adequate account monitoring
SkyCity’s breach
[53] SkyCity had automated and manual account monitoring controls in place, including the Jade system. It nonetheless failed to undertake adequate account monitoring, for several reasons. First, the Jade system identified individual transactions but was unable to adequately identify patterns of transactions over time. This meant additional manual account monitoring was required – but SkyCity did not have sufficient resources in its AML/CFT team to do this. Secondly, certain transactions that should have been reviewed were not (either because of the bulk closure of Jade alerts or because an observation report was not conducted). Thirdly, SkyCity’s account monitoring did not have regard to the level of risk involved with, or the customer due diligence performed on, each customer.
[54] These account monitoring failures had extensive consequences. SkyCity failed to undertake adequate account monitoring of 18 customers that the Department sampled in its review. As a result, SkyCity was unable to identify all transactions engaged in by those customers that should have been the subject of observation reports, prescribed transaction reports or suspicious activity reports. SkyCity agrees that this was representative of the way in which it undertook account monitoring across its business during the relevant period.
Is the proposed starting point within the proper range?
[55] For this breach, the parties propose a starting point of $750,000. Once again, this is 75 per cent of the maximum penalty of $1 million.
[56] Mr McMullan, for the Department, referred me to four cases that have decided pecuniary penalties for inadequate account monitoring. In Ping An, a starting point of $500,000 was adopted for Ping An’s failure to adequately review the account activity, transaction behaviour or customer information of 122 customers.18 In Qian Duoduo, around 1,327 transactions totalling $136 million were not subjected to adequate scrutiny via account monitoring. Powell J adopted a starting point of $100,000.19 In OTT Trading, Lang J considered a starting point of $250,000 on the basis that although OTT’s systems were inadequate, it had at least adopted the practice of reviewing the transactions regularly.20 In Jin Yuan, at times the compliance programme did not address account monitoring at all. A starting point of $500,000 was adopted.21
[57] Those cases are so different from the present that they are of limited assistance. I agree with Ms Boberg that in those cases the conduct tended to be more serious but the consequences much more limited. I prefer to focus on what I regard to be the relevant aggravating and mitigating factors of SkyCity’s breach.
[58] The mitigating factors are that SkyCity’s breach was not deliberate and SkyCity did engage in both automated and manual account monitoring. This is not a case of deliberate breaches or a complete failure to monitor.
[59] That said, SkyCity knew that its account monitoring had limitations. It admitted to EY that alerts generated by the Jade system that did not relate to prescribed transaction reports were not being used to monitor transactions. This resulted in the bulk closure of Jade alerts without review of those alerts. Further, SkyCity devoted inadequate resources to account monitoring. Despite the volume and
18 Ping An, above n 3, at [118].
19 Qian Duoduo, above n 9, at [145].
20 OTT Trading, above n 3, at [73].
21 Jin Yuan, above n 4, at [40].
size of the transactions, SkyCity’s AML/CFT team had only three people until around September 2021, and grew to a maximum of six during the relevant period. Also, SkyCity failed to implement all of EY’s 2019 recommendations on account monitoring before the 2021 audit.
[60] SkyCity’s inadequate account monitoring continued over a five-year period. It is not known how many customers and transactions were inadequately monitored, but given the size of SkyCity’s business this would have been significant. This means the magnitude of SkyCity’s breach is much greater than in the four cases to which I was referred.
[61] This collection of aggravating factors well outweighs the mitigating factors that I identified. I consider the proposed starting point of $750,000 to be in the middle of the available range.
Starting point for failing to conduct enhanced customer due diligence
SkyCity’s breach
[62] SkyCity failed to conduct enhanced customer due diligence, when required, on 18 of the Department’s sampled customers and 98 of 116 further customers in respect of whom SkyCity submitted suspicious activity reports. In relation to these customers, SkyCity failed to obtain and adequately verify further information when their transactional activity, or the making of a suspicious activity report, triggered a requirement under the Act to conduct enhanced customer due diligence.
[63] There were several instances where SkyCity’s failures to conduct enhanced customer due diligence when required were particularly serious. In respect of six customers, SkyCity submitted multiple suspicious activity reports after it was required to conduct enhanced customer due diligence. Seven of the Department’s 18 sampled customers were junket operators and therefore posed an inherently high risk of ML/FT. Several of the customers engaged in significant transactions after the requirement to conduct enhanced customer due diligence had been triggered.
[64]In the relevant period, SkyCity engaged in transactions totalling just over
$1.065 billion with the Department’s sampled customers after the date on which SkyCity was required, but failed, to conduct enhanced customer due diligence.
[65] The Department warned SkyCity in 2014, 2019 and 2020 that some of its enhanced customer due diligence practices did not satisfy its obligations under the Act. Despite this, SkyCity’s failures were not fully remediated until October 2020.
Is the proposed starting point within the proper range?
[66] For this breach, the parties propose a starting point of $1.6 million. This is 80 per cent of the maximum penalty of $2 million.
[67] The parties agree that this breach constitutes a separate civil liability act, distinct from the due diligence deficiencies in its compliance programme, for which a separate penalty can be imposed.
[68] A starting point of $1.3 million was adopted in Ping An. There, Ping An did not conduct adequate customer due diligence for at least 362 of its customers and it was inferred that Ping An had engaged in over 1,588 transactions, involving a total of $105.4 million. Toogood J said:22
Assessed against a benchmark of a maximum penalty of $2 million, I consider that a pecuniary penalty of at least $1.3 million (65 per cent) is necessary to mark the extent of the breach of a fundamentally important AML/CFT requirement and act as a deterrent. That may be conservative, given the systemic nature of the failure to comply and the number of individual breaches. I am satisfied that it leaves sufficient headroom to accommodate even more serious cases.
In Jin Yuan, the breach involved a failure to conduct compliant customer due diligence in relation to 55,097 transactions totalling $278.5 million. Woolford J adopted a starting point of $1.3 million for this breach.23 Similarly, in OTT Trading, where the entity failed to conduct enhanced customer due diligence for a significant volume of
22 Ping An, above n 3, at [113].
23 Jin Yuan, above n 4, at [40].
transactions, totalling at least $196 million, the same starting point of $1.3 million was adopted.24
Those cases involved more deliberate and therefore, in one sense, more serious conduct than SkyCity’s. In OTT Trading, for example, Lang J said that OTT Trading had shown a complete disregard towards its customer due diligence obligations.25 Here, by contrast, it is not that SkyCity failed altogether to conduct enhanced customer due diligence, but rather that its practices were non-compliant.
Nonetheless, the duration, scale and consequences of SkyCity’s non-compliance are such that a starting point higher than that adopted in those other cases is appropriate. SkyCity’s failings occurred over a five-year period. The failings occurred notwithstanding warnings from the Department. While fewer customers were affected than in some of the other cases, a much higher volume of transaction activity was implicated.
In these circumstances, I consider the proposed starting point of $1.6 million is within range, albeit at the top of the range.
Starting point for failing to terminate existing business relationships when required
SkyCity’s breach
[69] Section 37 of the Act requires a reporting entity to terminate its business relationship with a customer in respect of whom it is unable to conduct customer due diligence. SkyCity’s failure to conduct enhanced customer due diligence on the 116 customers who are subject to the fourth civil liability act meant that SkyCity was required to terminate its business relationships with those customers. SkyCity failed to do so.
24 OTT Trading, above n 3, at [73].
25 At [66].
[70] The Department had warned SkyCity after the 2019 on-site inspection and after the 2020 review that it had failed to terminate its business relationships with customers when required by s 37.
Is the proposed starting point within the proper range?
[71] For this breach, the parties propose a starting point of $200,000. This is 20 per cent of the maximum penalty of $1 million.
[72] The parties agree that SkyCity’s failure to terminate existing business relationships and the failure to conduct customer due diligence arise, in part, from the same conduct. Thus, care needs to be taken to avoid double counting. Under s 74(2) of the Act, a person may not be required to pay more than one civil penalty in respect of the same or substantially the same conduct.
[73] However, whether the one-penalty rule is engaged will depend on the particular facts. I agree with the parties that in this case, although the two breaches arise in part from the same conduct, the conduct is not the same or substantially the same. The present breach arises from the failure to conduct customer due diligence, but the breach itself lies in the failure to terminate. In similar cases, the courts have imposed penalties for both the failure to conduct customer due diligence and the failure to terminate, but have adjusted the starting point for the latter breach to recognise that there is some overlap between them.26
[74] In Financial Markets Authority v CLSA Premium New Zealand Ltd, CLSA’s failure to terminate business relationships meant that further substantial transactions were undertaken on at least two occasions, some of which were suspicious.27 CLSA had also breached its customer due diligence obligations. Edwards J adopted a starting point of $50,000, reduced from the $150,000 that would have been appropriate had the failure to terminate breach been considered on a standalone basis.28
26 Financial Markets Authority v CLSA Premium New Zealand Ltd [2021] NZHC 2325; and Tiger, above n 2.
27 CLSA, above n 26, at [59].
28 At [60].
[75] In Financial Markets Authority v Tiger Brokers (NZ) Ltd, Tiger’s failure to terminate business relationships had allowed ten significant transactions to take place, all of which were suspicious. Gault J adopted a starting point of $100,000, scaled back from the $300,000 that would have been appropriate had there been a standalone breach.29
[76] SkyCity’s failure to terminate existing business relationships when required is more serious than the failures in CLSA and Tiger. It enabled over $1.065 billion to be transacted through SkyCity. This included 757 large cash transactions and 52 transactions that were suspicious. These figures far exceed any of the pecuniary penalty cases determined under the Act to date.
[77] Were this breach to be considered on a standalone basis, a starting point in the range of $550,000 to $700,000 would be warranted. Given the starting point of
$1.6 million that I have accepted for the customer due diligence breach, I consider the proposed starting point of $200,000 is in range.
Aggravating and mitigating factors specific to SkyCity
The total of the starting points that I have adopted is $5.55 million.
[78]The parties agree there are no aggravating factors specific to SkyCity.
[79] SkyCity has no record of non-compliance. It says this is a mitigating factor. Ms Boberg pointed to s 90(4)(d) of the Act, which provides that in determining an appropriate penalty, a court must have regard to all relevant matters, including “whether the person has previously been found by the court in proceedings under this Act to have engaged in any similar conduct”. By contrast, Mr McMullan submitted that the courts have held that no weight should be ascribed to previous non-compliance where the breaches before the court span a long period.30
29 Tiger, above n 3, at [48].
30 Mr McMullan relied on Ping An, above n 3, at [119]; Qian Duoduo, above n 9, at [142]-[143];
OTT Trading, above n 3, at [87]; and Tiger, above n 3, at [62].
[80] I accept Mr McMullan’s submission. SkyCity’s breaches were over such a long period that its previous record of non-compliance is a neutral factor.
[81] SkyCity’s breaches are historic. It has remediated the shortcomings that led to its previous non-compliance with the Act. SkyCity does not claim this as a mitigating factor. It accepts that its remedial steps were required of it in any event under the Act. SkyCity was right to accept that position. It is consistent with previous decisions that have declined to reduce civil pecuniary penalties for remedial steps.31
Deductions for SkyCity’s admissions and cooperation
SkyCity is entitled to a deduction from the overall starting point of $5.55 million for its admissions of liability and cooperation.
SkyCity constructively engaged with the Department. It complied with the Department’s five notices requesting information in 2023. Once the Department issued this proceeding, SkyCity sought to resolve the Department’s claims at a very early stage. This cooperation led to the parties agreeing the factual basis for the breaches three months after the Department commenced the proceeding.
The parties agree that SkyCity’s admissions and cooperation warrant a deduction of 25 per cent from the starting point. I agree. A deduction recognises the savings in time and expense from avoiding a disputed hearing. There is a significant public interest in encouraging admissions and cooperation in proceedings such as these. As to the amount of the deduction, 25 per cent has been allowed in other cases where there has been agreement on both the facts and penalty.32
Applying that deduction leads to a penalty of $4.16 million.
Totality
[82] The parties agree that no further reduction in penalty is needed for totality. I agree with that approach. The combined starting point already accounts for the
31 Qian Duoduo, above n 9, at [162]; CLSA, above n 26, at [90]; and Tiger, above n 3, at [64].
32 TSB, above n 15; and Tiger, above n 3.
(limited) overlap in SkyCity’s breaches and ensures there is no double counting. A penalty of $4.16 million properly reflects the overall extent of SkyCity’s non- compliance and allows for SkyCity’s admissions and cooperation. It will deter others from non-compliance and encourage admissions and cooperation in appropriate cases.
Costs
The issue of costs has been resolved between the parties, so no order is needed.
Result
I enter judgment for the Department on the five causes of action pleaded in its amended statement of claim.
I order SkyCity to pay a pecuniary penalty to the Crown of $4.16 million.
Campbell J
- AGLC
- Department of Internal Affairs v Skycity Casino Management Limited [2024] NZHC 2781
- Case
- [2024] NZHC 2781
- Decision Date
CaseChat Overview and Summary
The court outlined the breaches: SkyCity failed to properly undertake and review its money laundering and financing of terrorism (ML/FT) risk assessment, establish and maintain an ML/FT compliance programme, conduct adequate account monitoring, perform enhanced customer due diligence, and terminate existing business relationships as required. These failures led to significant consequences, including inadequate monitoring and reporting of suspicious transactions. The court applied a four-step approach to determine the appropriate penalty: assessing the seriousness of the breaches, considering aggravating and mitigating factors, making deductions for admissions and cooperation, and ensuring the total penalty reflected the overall non-compliance.
After evaluating the breaches and comparing them to previous cases, the court found that the proposed penalty of $4.16 million was within the proper range. It considered the long duration and significant impact of the breaches, as well as SkyCity’s cooperation and admissions. The court concluded that the penalty would deter future non-compliance and encourage similar cooperation in resolving disputes. The court entered judgment in favor of the Department, ordering SkyCity to pay the agreed penalty of $4.16 million.
Orders
Orders of the court
Full text does not contain this section.
Background
Background to the litigation
Full text does not contain this section.
Evidence
Evidence Before The Court
Full text does not contain this section.
Decision
Reasons for decision
Full text does not contain this section.
Ratio Decidendi
Legal Principle Established
Full text does not contain this section.