Back to Bizweek
SEARCH AND PRESS ENTER
Latest News

Legacy systems are leaving the door open to financial crime

Andy Jarvis, Co-Founder and Chief Digital Officer of Elevated eXperience

Andy Jarvis, Co-Founder and Chief Digital Officer of Elevated eXperience

Mauritius has the connectivity, talent and digital ecosystem to strengthen its defence against financial crime. But according to Andy Jarvis, the country’s financial-services sector must stop layering new technology onto outdated infrastructure. His warning is stark: fragmented systems, spreadsheets and paper-based processes create gaps that criminals can exploit, while AI can make those weaknesses even more dangerous. “AI does not automatically fix bad systems. It can simply make bad processes faster,” says Andy Jarvis. Speaking at the 8th Financial Crime Conference at Hilton Resort & Spa on September 2 and 3, he urged the country’s financial-services sector to accelerate its digital transformation, eliminate paper-based processes and develop a new technology infrastructure rather than continually extending legacy systems.

You argue that broken and disconnected systems are a gift to financial criminals. How exactly do criminals exploit those gaps? 

It is a mixture of things. I work with institutions, enterprises and corporates of varying sizes, from small to large. One of the fundamental problems is that technology grows over time. You start with a system, then you build and build and build. You might begin with a trust and company service provider system or a banking platform such as T24, and then layer more technology on top.

What happens is that, over time, staff come and go. People are not necessarily trained properly; they are often trained by the person who is leaving. So, you have complexity and gaps in education. And therefore, you have gaps in the process. That is where criminals come in and exploit those gaps.

The other thing that happens is that the world’s most loved system is Excel. If people want to work with data, they export it to Excel. Every system in the world seems to have an “export to Excel” button.

The minute you dump information into Excel, it is not encrypted, it is not audited, it is not backed up, and the IT department often does not know anything about it. That is where crime happens because the data is essentially open to interpretation.

Are financial institutions investing heavily in new technology while still operating with fundamentally fragmented systems? 

Yes indeed. I think one of the biggest things to answer that question is that no one ever turns anything off. 

There is a lack of investment in consolidating what you have today and making the best of what you already have. Instead, there is a real willingness to invest in the next best thing because competitors are doing it or customers are asking for the latest innovation.

Are we implementing a chatbot on our website? Are we implementing AI in our systems? In fact, crime can happen silently in our organisations. Sometimes it happens from within; sometimes externally. And the channels are everywhere. 

Currently, the cost of simply maintaining compliance in our organisations is around USD 206 million a year globally, and that is before any financial crime happens. That is just trying to keep the back door shut and it is still wide open. It is effectively a tax: a subscription that none of us signed up for, a bit like Spotify. 

Where is the greatest vulnerability today? Outdated technology, poor data sharing, human error, or organisations working in silos? 

Probably, well, all of the above. But the biggest vulnerability is human error. That does not mean people go to work intending to make mistakes. The problem is that the processes have become increasingly complicated, with numerous workarounds, manual interventions and spreadsheets embedded in organisations.  

Take, for example, the Barings Bank incident where the bank lost more than USD 800 million. Essentially, a securities trader was managing investments through a spreadsheet and made a simple copy and paste error. A calculation that was supposed to average figures ended up summing them instead. 

The consequences were enormous!

Mistakes happen every day. But when those mistakes occur within complex financial systems, the value and impact of a seemingly small human error can be massive.

Can you give us an example of how a seemingly minor disconnect between two systems can create an opportunity for financial crime? 

I think one of the biggest ones, again, is within the compliance function itself – anti-money laundering and KYC. The majority of the organisations that I work with run those functions on spreadsheets.

So, the disconnect between systems is fundamentally that the work is not being done in a system; it ends up in a system after the compliance work has been done. 

So, you are extracting things from a system to run a set of processes on spreadsheets, or on paper, or you are emailing files backwards and forwards. And the intersection for a criminal has nothing to do with the systems.

The systems are controlled, but you are working outside them. And that is where the gap is. Unbelievable.

We are still making the same mistakes we were making 20 years ago!

Financial institutions collect an enormous amount of KYC and transaction data. Is the real problem now, not the lack of data, but the inability to connect and interpret it effectively? 

Exactly. KYC data is often captured outside core systems, so the ability to genuinely verify it is limited.

Firms are now implementing KYC and KYB platforms that can do things such as automated passport scanning. But they are still open to human interpretation.

But they are still open to human interpretation. And equally, you have insider attacks. People can override controls quite easily. Everything is still subject to fraud. We hear cases every day about fraudulent copies of passports circulating and people being hacked all the time.

It is not a bomb-proof science. My concern is that you then put AI on top of that and take away some of the human intervention or intelligence needed to interpret something through multiple checkpoints.

AI is essentially giving you an answer, and that answer is not always correct. You could therefore end up taking on a business or transacting business that you do not necessarily want to be doing.

As criminals increasingly use AI and automation, are banks and compliance teams technologically equipped to keep pace? 

No. I mean, I could leave it at that. Take a very good example. A lot of banks are now implementing WhatsApp as a customer communication channel. At the same time, criminals are literally building farms that use WhatsApp to harvest credentials and then hack accounts.

The South African government, as a really good example, is using WhatsApp as a primary communication channel now. And it has been proven that this is a weak backdoor. WhatsApp Business is, yes, perhaps encrypted, but it is not a secure channel because it does not have the verification mechanisms required. 

All you are essentially verifying is: does my client have this phone number? Yes. But that is not an unhackable route.

Could AI actually create another layer of risk if institutions integrate it into already fragmented or poorly designed systems? 

Absolutely. 

Within an organisation, the technology stack is generally looked after by the IT team. They manage the banking platform and the core systems. But they are often unaware of the spreadsheets, the data sitting in SharePoint and all the other places where information actually resides. The real working processes are largely understood by the staff, not the IT teams.

Then the IT teams implement AI for employees to use, without necessarily knowing how that AI is actually being used. So, AI is going to accelerate it.

On an unstructured dataset, AI will essentially give you the same answer — if not worse — in a faster time, with better grammar, wearing a nicer suit. It is essentially accelerating the car crash.

If you do not get rid of the legacy and the complexity, the car will eventually crash. You put AI on top of that and you simply speed it up.

How do institutions modernise legacy systems without creating new vulnerabilities during the transition? 

When we work with an organisation, the primary thing we focus on is making sure that, at board level and within the leadership and management teams, everyone has one vision, one set of values and one mission.

Organisations today often do not. At best, you have three different directions.

You have the technology function, which has its own strategy, vision, mission and budget. Then you have the people function, which is focused on employees and protecting the organisation. And then you have the client-facing teams — sales and marketing — dealing with customers and operating according to another strategy.

They utilise IT, but those three groups do not necessarily talk to each other. We bring them together and make sure they are aligned. They need the same mission, the same roadmap and the same transformation plan.

You cannot stop vulnerabilities from creeping in. What you can do is agree on getting to a better future, establish the timeline and create a roadmap.

We give teams a 30, 60 and 90-day plan to resolve immediate issues.

But my advice is simple: turn off as much of the old stuff as you can, as fast as possible.

Mauritius is an international financial centre connecting Africa, Asia, and Europe. Does that interconnectedness make system integration and real-time information sharing even more important? 

Absolutely. A really good example is where I come from. In Jersey, we worked for years to build connectivity. I worked in telecoms for quite a long time, including on the world’s first fully fibre network.

Mauritius is now in a really strong position from a connectivity perspective. Despite reliability issues around power and infrastructure, you are one-gigabit connected. And the interconnections between Mauritius, India and Asia are extremely powerful. I think it is still early days, but you are in a very strong position as an island nation. You are self-governed, you have a well-educated population and a strong expatriate population. You are consuming global knowledge. Your ability to connect not only to India and Africa, but globally, puts you in a strong position to close the door on financial crime.

Mauritius has already demonstrated that it can respond quickly when it decides to act. The country was placed on the FATF Grey List and subsequently, 18 months later, removed after addressing the identified deficiencies.

That is a very good example of the government saying: “We have these issues; we are going to close every single one of them.”

If institutions follow the same approach, the world will be a much better place.

So, if you were advising the Mauritian financial services sector, what is the one technological or organisational weakness that you would address first? 

I think, the number one, after looking at the landscape here, is: “Get off paper”. 

There are still a lot of paper processes here. There is still significant reliance on people physically coming into an office with documents. Given the way the world is moving, particularly with AI and the acceleration of financial institutions globally, there is a real danger of being left behind because other international financial centres will move faster.

And where you have paper, you have opportunities for crime. Where you have digital systems, you lessen those opportunities. As an island nation, Mauritius can also be quite nimble in implementing technology.

You have a good digital ecosystem and a strong digital sector. We have been talking to people in South Africa who have literally moved to Mauritius because of the investments being made in digital technology. Take that and utilise it faster. But again, turn the old stuff off as quickly as possible.

I was speaking to someone from a large banking institution and he asked me what I would do. I said: “Build the new house. Operate like a startup.”

What do you actually want to do? Forget the history. Forget the legacy. Your existing clients may be perfectly happy with the systems they have been using for 20 years. But that is not the point. The question is: what do you want to do as an organisation, and how do you avoid being left behind by the startups coming after you?

Big institutions can fail very quickly. Look at Blockbuster. It went bankrupt because it did not see streaming coming. It thought it would never take off. If an institution believes it cannot build a new infrastructure and gradually move its clients into it, it is wrong. It will ultimately fail.

So, the imperative  is – and I will reiterate this strongly – to invest in getting off your legacy. 

What do conferences like the 8th Financial Crime Conference, held at Hilton Mauritius Resort & Spa on 02 and 03 September 2026, contribute? 

I think it’s the can-do attitude. So, for the suppliers like us, it is about bringing global knowledge to a local table. The way my business operates, I am a keynote speaker first. Then we run masterclasses and work with leadership teams, empowering them with tools, techniques and know-how. But we also work with local partners.

We are a small operation, but we have partners all over the world. Coming to Mauritius is therefore about building that network and developing strong partnerships. We can leave knowing that the local market is in good hands because people have learned something and are using frameworks that are accredited by us and proven to work.

For attendees, I think it is about getting out of your day job for a couple of days and having the opportunity to think clearly about what you are actually doing. How many times in an organisation are you sitting there pushing buttons and filling things in without really knowing why?

You are taught to fill in the form and tick the box. Then, when something happens whether it is a disaster, an anomaly or a criminal event, it can be difficult to spot because you do not understand the mechanics behind it.

The best drivers in the world are often very good mechanics because they understand how the car works. You can get into a car and drive it fast, but only up to a point. That is why Lewis Hamilton has won seven world championships. He can talk to the team and say, “I need that front wing,” because he understands exactly what changing it will do.

 There are not many people in organisations with that level of know-how.

So, I would strongly encourage people to learn, learn, learn and question everything. That is how you help your organisation truly thrive.

Skip to content