2026-07-14
Added
The amendments replace the term 'management institution' with 'management' and clarify that the definition of sanctions risk includes the impact of violating applicable sanctions regimes. Institutions must implement group-level policies, maintain IT systems for sanctions screening, and assess risks related to outsourcing. Credit institutions and licensed payment institutions must update their sanctions risk assessments at least annually, while other entities must do so every three years. Senior management is responsible for the internal control system and must notify the central bank of the appointed sanctions risk manager within 30 days.
FCMC published 1 document in the last 30 days — get each new one by email the day it lands.
Amendments to Latvijas Banka Regulation No. 277 "On the Establishment and Control Requirements for the Internal Control System for Sanctions Risk Management" /No. 422/
Issued in accordance with Article 13, Part 4, Point 3 of the International and National Sanctions Law of the Republic of Latvia
Make the following amendments to Latvijas Banka Regulation No. 277 "On the Establishment and Control Requirements for the Internal Control System for Sanctions Risk Management" (Latvijas Vēstnesis, 2024, No. 62) dated March 25, 2024:
Replace the words "management institution" (in the appropriate case) with the word "management" (in the appropriate case) throughout the text of the regulation.
Supplement point 2 with the words "including the impact that a violation of a sanctions regime binding on the institution may have."
Supplement point 3 with the second sentence in the following wording:
"An institution that is part of a group implements group-level policies and procedures in sanctions risk management."
"6.3.1. the procedure by which the institution ensures the search of clients, their beneficial owners, authorized persons, participants, and client transactions in sanctions lists, as well as the procedure by which the compliance of these persons and transactions with sanctions requirements is assessed if a match is identified. The institution is obliged to prove that the solutions it has chosen for searching clients, their beneficial owners, authorized persons, participants, and client transactions in sanctions lists ensure effective sanctions risk management;"
Strike out the words "avoidance of sanctions or attempt to evade sanctions or" in sub-point 6.4.
Express sub-point 6.11 in the following wording:
"6.11. information technology support suitable for sanctions risk assessment for sanctions risk management, including providing for the functional requirements of the information technology support and a procedure for regular assessment of effectiveness and testing;"
Strike out sub-point 6.12.
Replace the words "avoidance or avoidance" in sub-point 6.13 with the words "violation or violation."
Supplement the regulation with sub-point 6.14 in the following wording:
"6.14. the procedure for assessing and managing risks associated with the use of outsourcing."
"7. The institution regularly updates the sanctions risk assessment, but not less than once every three years, in accordance with the sanctions risk inherent in its activities. A credit institution, licensed payment institution, licensed electronic money institution, investment broker company, or crypto-asset service provider reviews and updates the sanctions risk assessment not less than once every 12 months."
Strike out point 9.
Strike out the words "to the State Security Service and for the avoidance of sanctions or attempt to evade sanctions" in point 11.
Express point 12 in the following wording:
"12. The senior management of the institution is responsible for the establishment and effective operation of the internal control system for sanctions risk management, including providing appropriate resources and ensuring that the internal control system for sanctions risk management is functionally independent from the main activities (business functions) of the institution. The senior management of the institution provides the employee responsible for sanctions risk management with appropriate powers and access to the information necessary for the performance of their official duties. The institution notifies Latvijas Banka in writing within 30 days after appointing the employee responsible for sanctions risk management or replacing this employee with another, indicating in the notification the first name, last name, personal code, position, date of appointment to the position, email address, and phone number of the employee responsible for sanctions risk management."
"14.1. If the institution has submitted information to Latvijas Banka regarding the appointment of the employee responsible for sanctions risk management in a volume smaller than that specified in the third sentence of point 12 of these regulations, compliance with the requirements specified in the third sentence of point 12 of these regulations shall be ensured by September 1, 2026."
Deputy President of Latvijas Banka M. Kālis
Act Details
Name: Amendments to Latvijas Banka Regulation No. 277 "On the Establishment and Control Requirements for the Internal Control System for Sanctions Risk Management" ...
Status:
In force
In force
Issuer: Latvijas Banka
Type: Regulation
Number: 422 Adopted: 13.07.2026. Enters into force: 15.07.2026. Published: Latvijas Vēstnesis, 132, 14.07.2026.
OP number:
2026/132.5
Related Documents
Amended
Issued in accordance with
Abstract
369690
87
0
With my notes
With larger font
Print legal act
X
Draugiem.lv
"Everyone has the right to know their rights."
Article 90 of the Constitution of the Republic of Latvia
© Official Publisher "Latvijas Vēstnesis"
Read the rest free
Source: Financial and Capital Market Commission Latvia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from FCMC
FCMC published 1 document in the last 30 days. We email you each new one the day it's published.