2023-09-10

Added · Updated

AML/CFT Council Instructions on Due Diligence Rules No. 1 of 2023 for Financial Institutions and Specified Non-Financial Businesses and Professions

The Anti-Money Laundering and Counter-Terrorist Financing Council's Instructions No. 1 of 2023 establish due diligence rules for financial institutions and specified non-financial businesses and professions in Iraq. The document mandates customer identification and verification procedures for natural persons, legal entities, and legal arrangements, including specific requirements for beneficial ownership determination with a 20% ownership threshold for control. It prohibits dealing with anonymous, fictitious, or shell bank accounts and requires ongoing monitoring of business relationships and transactions, particularly for high-risk clients and occasional transactions exceeding specified limits.

Iraqi Securities Commission logo

Iraq

Iraqi Securities Commission

Click to view thumbnail

Anti-Money Laundering and Counter-Terrorist Financing Council, Based on the provisions of Articles (10 and 56) of Law No. (39) of 2015 concerning the combating of money laundering and terrorist financing, And based on the powers delegated to us, And in pursuit of the public interest,

We have issued the following instructions:

No. (1) of 2023 Instructions on Due Diligence Rules For Financial Institutions and Specified Non-Financial Businesses and Professions towards Clients

Article (2) - The following terms are intended for the purposes of these instructions as indicated:

The Regulated Entity: A financial institution and any of the specified non-financial businesses and professions.

The Supervisory Authority: The competent authority for licensing or authorizing financial institutions and specified non-financial businesses and professions, or supervising them and ensuring their compliance with the requirements necessitated by the combating of money laundering and terrorist financing, including the Ministry of Trade, the Ministry of Industry, the Central Bank of Iraq, the Securities Commission, the Insurance Directorate, and any other authority whose jurisdiction is designated as a supervisory authority by a decision of the Council of Ministers based on the Council's proposal and published in the Official Gazette.

Legal Arrangements: The relationship arising under a contract between two or more parties that does not result in the creation of a legal entity, such as trusts and other similar arrangements.

Direct Trust: Legal relationships arising between living persons or upon death, established clearly by the settlor, usually in the form of a document, such as a direct trust deed, whereby funds are placed under the control of the trustee for the benefit of one or more beneficiaries or for a specific purpose, and such funds constitute independent assets and are not part of the trustee's property. The right to the trust assets is held in the name of the trustee or in the name of another person on their behalf, and they possess the authority to manage, use, and dispose of the assets in accordance with the terms of the trust, its duties, and legal powers. This trust differs from trusts arising through the execution of the law and not from the settlor's intention or clear decision to create a trust or similar legal arrangements such as trusts by court rulings.

The Settlor or Trust Creator: The natural or legal person who transfers ownership of their assets to trustees via a trust deed or direct arrangement.

Page 1 | 24

The Trustee: The natural or legal person who receives and holds assets separately from their own owned assets, and is responsible for managing those assets for the benefit of the beneficiary. They are the legal owner of these assets, but cannot benefit from them for their own benefit, taking into account the possibility that the trustee may be a professional, such as a lawyer or a credit company, if paid to act as a trustee in the context of the business they conduct, or a non-professional, such as a person acting without compensation on behalf of their family.

Trust Beneficiary: The person or persons, whether natural or legal persons or legal arrangements, who are entitled to benefit from any trust arrangement as specified in the trust deed.

Client: Any person who conducts or initiates any of the following activities with one of the financial institutions or specified non-financial businesses and professions (arranging, opening, or executing a transaction or business relationship or account for them) and (participating in signing a transaction, business relationship, or account) and (assigning or transferring an account or rights or obligations under a transaction) and (acting to conduct a transaction or control a business relationship or account).

Occasional Client: The client who does not have a business relationship with them with the expectation of continuation.

Business Relationship: The relationship arising between the financial institution or specified non-financial businesses and professions and their client, which relates to the activities and services provided to them as long as the concerned institution intends for the relationship to extend for a period of time.

Financial Group: Any group consisting of a parent company or its subsidiaries or any person exercising control over its branches and subsidiaries.

Correspondent Banking Relationships: Banking services provided by the correspondent bank to another responding bank, including cash management services, multi-currency accounts generating leads, telegraphic or electronic money transfers, check settlement, and correspondent payment accounts, and foreign exchange services.

Beneficial Owner: The natural person who owns or exercises ultimate direct or indirect control over the client or the natural person on whose behalf the transaction is conducted, as well as the person who exercises actual control on behalf of a concerned person or legal arrangement.

Correspondent Payment Accounts: Correspondent accounts used directly by third parties to conduct business on their behalf.

Shell Bank: A bank registered or licensed in a country or region without having a physical presence there, and not part of a financial group subject to effective banking regulation and supervision. Physical presence is meant to mean a real office and actual management of the bank, not merely the presence of an agent, lawyer, or low-level employees.

High-Risk Senior Position Holder: The natural person who represents any of the categories stipulated in Article (25) of these instructions.

Telegraphic Transfer: Any transaction conducted on behalf of the transfer initiator through a regulated entity via electronic means with the aim of making an available amount of funds available to a beneficiary person at a regulated beneficiary entity, regardless of whether the transfer initiator and the beneficiary are the same person.

Transfer Initiator: The account holder who permits the telegraphic transfer from this account, or in the absence of an account, the natural or legal person who issues instructions to the regulated entity issuing the transfer to execute the telegraphic transfer.

Aggregated Transfer File: A transfer consisting of a number of individual telegraphic transfers sent to the same regulated entities, but may or may not be ultimately directed to different persons.

Money or Value Transfer: A financial service involving the acceptance of cash, checks, or other monetary instruments or reserve values and paying an equivalent amount in cash or in any other form to a beneficiary via connection, message, transfer, or through a clearing network to which this service specializing in money or value transfer ends. Financial operations conducted by such services may include one or more intermediaries and payment to a third party at the end. It may also include any new payment methods. These systems often have halls in certain geographical areas, hence the description with different terms, such as Hawala and Hundi and Fei-chen.

Secondly – The definitions stipulated in Law No. (39) of (2015) concerning the combating of money laundering and terrorist financing apply wherever they appear in these instructions.

Article (2) - Scope of Application

The provisions of these instructions apply to all Regulated Entities, which consist of the financial institutions and specified non-financial businesses and professions stipulated in items (eighth and ninth) in Article (1) of the Law, taking into account the statement issued by the Chairman of the Council regarding the limits of cash transactions participated in by jewelers and precious metal or gemstone traders. The provisions of these instructions also apply to any person acting as a trustee for a trust or performing a similar act on behalf of a legal arrangement as part of the specified non-financial businesses and professions according to the provisions of Article 1 (Paragraph d/4 of Item ninth) of the Law.

Chapter Two: Due Diligence Measures

Article 3 - Prohibition of Dealing

The Regulated Entity is prohibited from:

  1. Opening or maintaining numbered accounts or any anonymous or fictitious or sham names accounts or business relationships.

  2. Dealing with persons of unknown identity or persons carrying fictitious or sham names.

  3. Dealing with shell banks.

  4. Dealing with any natural or legal person who takes as a profession providing any of the activities, services, or operations designated for Regulated Entities or virtual asset service providers according to legislation, without a license or registration, whether for the benefit of their clients or on their behalf. This excludes preliminary dealing with financial institutions or specified non-financial businesses and professions or virtual asset service providers under establishment, subject to the prevailing legislation in the country.

Article 4 - Timing of Due Diligence Measures

The Regulated Entity must take the due diligence measures stipulated in this chapter in the following cases:

  1. Before and during the opening of an account or establishment of a business relationship with the client.

  2. Any occasional transaction reaching or exceeding the amount determined by the Chairman of the Council by a statement issued for this purpose and published in the Official Gazette, whether conducted as a single transaction or multiple transactions that appear to be connected to each other.

  3. Conducting occasional transactions in the form of local or external telegraphic or electronic transfers, regardless of their value.

  4. Doubt regarding the correctness, accuracy, or sufficiency of data related to client identification obtained previously.

  5. Suspicion of money laundering or terrorist financing, regardless of any exemptions or specific limits mentioned in the Law or any other systems, instructions, statements, or legislation.

Article 5 - Customer Identification and Verification Procedures

The Regulated Entity must identify and verify the identity of clients, whether permanent or occasional, local or foreign, by obtaining the following information and documents:

A. If the client is a natural person:

(1) The client's full name, nationality, date and place of birth, permanent addresses, ID card number or passport number for the foreign person, place and date of issue, mother's name, marital status, wife's name, and keeping a copy of the personal ID card (or passport for the foreign client).

(2) The client's economic activity, nature and address of their work, sources of income, job title, employer's name or employing entity, monthly income value, and obtaining a copy of the document proving that activity according to the risk level.

(3) Actual residence address or current residence.

(4) Client contact information, including mobile and landline phone numbers, address (if available), and email.

(5) Any other information and documents the financial institution deems necessary to obtain to identify the client.

B. If the client is a legal person or legal arrangement:

(1) The client's name, legal form, articles of association, registered office address or headquarters address, registration date and number, place and date of issuance of establishment proof documents, types of documents regulating the work of the legal person or legal arrangement, obtaining registration documents of the legal person, articles of association or statutes, and internal regulations, type of activity and capital, the contract or deed governing the management of funds regarding legal arrangements, waqf assets and trust assets, place of residence of the mutawalli (trustee) of the waqf, as well as place of dismissal of the trust trustee, and any assets held or managed regarding any mutawallis or trustees with whom a business relationship is established or an occasional transaction is conducted on their behalf, and any other information the institution deems necessary to obtain.

(2) Information on the natural persons authorized to sign on behalf of the client, as required for a natural person according to paragraph (a/1) of this Article, and names of those holding senior management positions.

(3) Obtaining the necessary information regarding the nature of the client's work, ownership structure, and control, and determining whether the ownership or control structure is complex or multi-layered.

  1. The Regulated Entity must understand the purpose and nature of the business relationship and collect information about it as appropriate.

  2. The Regulated Entity must verify the information obtained under the provisions of this Article by reviewing the original documents and documents proving the correctness and accuracy of the information and matching them with it, and ensuring they are valid, updated, and free from any signs of forgery or tampering, and using reliable and independent sources, including contacting the official authorities issuing or responsible for those documents and records, and taking any other actions according to the risk level, such as contacting the client or investigating them or conducting a field visit to their headquarters.

  3. The Regulated Entity must keep a copy of all documents and records obtained under this Article, and it must indicate that it is an exact copy.

C. If the client is from associations and non-profit organizations:

(1) Identifying the association or organization, its official name, legal form, headquarters address, type of activity, date of establishment, organizational structure, minutes of the election of management or appointment decision, names of those authorized to deal with the account, phone numbers, purpose of dealing, and any other information the institution deems necessary to obtain.

(2) Verifying the existence of the association or organization and its legal status through the establishment certificate from the competent authority and the internal regulations of the association or organization.

(3) Providing a letter specifying the bank where the account is opened, signed by the competent authority.

(4) Obtaining documents indicating the existence of authorization from the association or organization for natural persons authorized to deal with the account, and identifying the identity of the authorized person to deal according to the customer identification procedures stipulated in these instructions.

(5) Obtaining identity information of donors and beneficiaries of deposited and withdrawn funds.

D. Verifying the existence of the concerned person with respect to government (state) circles through the legal instrument by which it was established and the approval of the highest person legally authorized to open the account, and a document authorizing the person authorized to sign on the account and the limits of their powers, signed by the highest person legally authorized.

E. Different types of joint-stock companies are exempted from requesting data related to owners and ownership shares, and it is sufficient to request data related to the names of shareholders whose share exceeds (10%) ten percent of the company's capital.

Article 6 - Acting on Behalf of the Client

  1. The Regulated Entity must take the following actions when dealing with any person claiming to act on behalf of the client:

A. Verify that this person is actually (legally) authorized to act on behalf of the client, i.e., through an official power of attorney granting the agent the authority to deal with the principal's account, and verify by reviewing the original documents and official documents proving their right to this act, and ensure they are valid, updated, and free from any signs of forgery or tampering, and obtain a copy signed to indicate it is an exact copy, or by using independent and reliable sources, including contacting the official authorities issuing those documents and records when necessary.

B. Apply the identification and verification procedures for natural persons referred to in Article (5) of these instructions to the person acting on behalf of the client.

  1. The provisions of paragraph (1) of this Article apply to all forms of acting on behalf of the client, including in the case that the client is the person authorized as an agent for the client, or the legal representative of a minor or incapacitated person, or authorized to sign on behalf of the legal person or legal arrangement, or trustee of a direct trust or the equivalent position in similar legal arrangements, or agent for the founders (in case the legal person or legal arrangement is under establishment), or representative of the client in any other capacity.

Article 7 - Determination of Beneficial Owner

Firstly - The Regulated Entity must take reasonable measures according to the money laundering and terrorist financing risks arising from the client and the business relationship, to identify the beneficial owners and verify their identities based on information documented in official documents, to the extent that the institution is convinced of its knowledge of the beneficial owner's identity, through the following information:

A. If the client is a natural person: It must be determined whether the client is acting on their own behalf. If so, their signature must be obtained on a declaration stating that they are the beneficial owner of the business relationship. If not, or in case of doubts about the validity of the client's declaration, the natural person or persons who are actually and ultimately beneficiaries or responsible for the business relationship, or on whose behalf the dealing is conducted, or who ultimately and effectively control the client's accounts or business relationship, must be identified, and the capacity in which the client acts on behalf of the beneficial owner must be determined.

B. If the client is a legal person: Determine the beneficial owner according to the following sequential approach:

(1) Control through ownership: Identify the identity of the natural person or persons (if any) who have a controlling actual ownership share in the legal person, whether directly or indirectly, by considering anyone owning (20%) or more of the legal person's shares as a beneficial owner, whether that ownership is direct or indirect, as well as identifying the shareholder who exercises actual control over the legal person regardless of their share percentage, whether alone or with other shareholders indirectly.

(2) Control by other means: When no natural person exercises control over the legal person through controlling ownership shares, such that ownership shares may be very diverse, or in case of any doubts about identifying the beneficial owner after applying the provisions of item (b/1) of the first paragraph of this Article, the identity of the natural person or persons (if any) who exercise actual control over the legal person through other means such as those resulting from personal links with persons allowing ownership, or with persons in the positions mentioned in item (b) of the first paragraph of this Article, or control without ownership through participation in financing the concerned person or close or intimate family relationships, or historical or contractual links, or those that appear if the concerned person fails to make some payments, can be assumed even if not actually exercised, for example, when using assets owned by the concerned person or enjoying or benefiting from them.

(3) Control through management: If no natural person is identified under the application of the provisions of items (1, 2 b) of the first paragraph of this Article, the identity of the natural person holding a senior management position must be determined, such as that who assumes responsibility for strategic decisions that fundamentally affect the commercial practices or general production of the concerned person or who exercises executive control over the daily or ordinary affairs of the concerned person through a senior management position, such as chairman or chief executive officer, or financial director, or administrative director, or who exercises fundamental authority over the financial relations of the concerned person, including financial relations with financial institutions holding accounts in the name of the concerned person, and the ongoing financial affairs of the concerned person.

C. If the client is a legal arrangement: The Regulated Entity must:

(1) Identify the identity of the settlor or trust creator, the identity of the trustee or guardian or protector, if present, and the identity of the trust beneficiaries. In the absence of current specified beneficiaries, such as when beneficiaries are specified by characteristics or categories, sufficient information regarding the beneficiary must be obtained to convince the Regulated Entity that it will be able to identify the beneficiary's identity upon payment or when the beneficial owner intends to exercise their legally acquired rights. In the event that any of those parties is a legal person, the beneficial owner of the concerned person is determined.

(2) The identity of any other natural person exercising effective and actual control over the trust, whether through a chain of control or ownership or through any other means.

(3) Regarding waqf and other types of legal arrangements, information must be obtained regarding the identity of persons holding positions equivalent or similar to those mentioned in item (c/1) of the first paragraph of this Article.

Secondly - The Regulated Entity must apply the identification and verification procedures for natural persons stipulated in Article (5) of these instructions to the beneficial owner or beneficial owners identified under the provisions of this Article, to the extent that convinces the Regulated Entity that it has identified the beneficial owner.

Article 8 - Exemptions from Determining Beneficial Owner

  1. The Regulated Entity may refrain from taking the measures stipulated in Article (7) of these instructions to identify and verify the beneficial owner's identity of the legal person if the client or controlling shareholder is a company listed on the Iraq Stock Exchange or a subsidiary majority-owned by the listed company, provided that disclosure requirements are met, whether through stock market rules, the exchange, the law, or any other binding means, which impose conditions to ensure sufficient transparency for the beneficial owner.

  2. It is required to apply the provisions of paragraph (1) of this Article by obtaining relevant beneficial owner data from official records or from the client or from other reliable sources.

Article 9 - Ongoing Due Diligence

The Regulated Entity must take ongoing due diligence measures regarding business relationships, including the following:

  1. Studying the transactions executed throughout the duration of the business relationship and presenting them in detail, to ensure they are consistent with the information in its possession regarding its clients, their commercial activity patterns, and their risk profile, and if necessary, the source of funds.

  2. Ensuring that the documents, records, data, or information obtained under the due diligence measures referred to in Article (5) of these instructions are continuously updated and appropriate, by reviewing existing records and monitoring them, particularly high-risk customer categories.

Article 10 - Timing of Verification

  1. The Regulated Entity must take verification actions for the client's and beneficial owner's identity according to the provisions of the Law and these instructions, before or during the business relationship or executing transactions for occasional clients. The Regulated Entity may complete verification procedures after establishing the business relationship, provided that:

A. It happens as soon as practically possible.

B. It is necessary to avoid interrupting normal business flow.

C. Effectively managing money laundering and terrorist financing risks.

  1. The Regulated Entity must adopt appropriate procedures to manage risks regarding circumstances where the client may benefit from the business relationship before the verification process, which must include a set of measures, including determining limits or caps or imposing controls on the number, type, and/or quantity of transactions or operations that can be conducted, and monitoring large or complex transactions exceeding the agreed limits for this type of relationship.

  2. The Regulated Entity is prohibited from delaying the completion of the verification process when there are indicators of high risk or when there is suspicion of money laundering or terrorist financing.

Article 11 - Special Provisions for Insurance

The Regulated Entity providing insurance services and products is required to take the following actions, in addition to the due diligence measures required for clients and beneficial owners according to the provisions of this chapter:

  1. Take the following due diligence measures on beneficiaries of life insurance policies and other investment insurance products, once these beneficiaries are identified or named:

(1) Obtaining the name of the person for beneficiaries who are natural persons, legal persons, or legal arrangements specifically named.

(b) Obtaining sufficient information about beneficiaries named by characteristics or categories (such as spouse or children at the time of the insured event) or through other means such as a will, to the extent that the Regulated Entity is convinced it will be able to identify the beneficiary's identity at the time of paying the claim.

(c) Verifying the identity of beneficiaries stipulated in paragraph (1) of this Article at the time of paying the claim.

  1. Consider the beneficiary of a life insurance policy as a risk factor when determining the applicability of enhanced due diligence measures. When the Regulated Entity determines that the insurance beneficiary is a legal person or legal arrangement, for example, as a high risk, it must apply enhanced due diligence measures according to the provisions of Article (26) of these instructions, including taking reasonable measures to identify and verify the beneficial owner of the insurance policy beneficiary at the time of paying the claim according to the provisions of Article (7) of these instructions.

  2. Regarding life insurance policies, the Regulated Entity is obligated to determine whether the beneficiary or beneficial owner is a politically exposed person representing risk, no later than the time of paying insurance benefits. When determining higher risks, it must do the following:

A. Notify senior management before paying insurance policy benefits.

B. Conduct a detailed and enhanced review of the entire business relationship of the policyholder.

C. Consider filing a suspicious transaction report to the office according to the provisions of the Law.

Article 12 - Reliance on Previous Procedures

The Regulated Entity may rely on identification and verification procedures previously taken according to the provisions of Article (5) of these instructions when executing or preparing financial transactions, without needing to repeat those procedures every time those transactions are executed or prepared, except in the following cases:

  1. Doubts regarding the validity of that information.

  2. Suspicion of money laundering, terrorist financing, or any predicate crime.

  3. A fundamental change in the ownership structure and nature of the business relationship and the client's financial transactions that do not align with the client's activity.

Article 13 - Reliance on Third Parties

  1. The Regulated Entity relying on the third party bears the ultimate responsibility for due diligence measures towards clients if the supervisory authority permits reliance on third parties from financial institutions or specified non-financial businesses and professions, whether from within the country or outside it, to carry out the due diligence measures stipulated in Articles (5, 6, 7, 8) of these instructions or to conduct business. In this case, it must do the following:

A. Identify the third party and obtain the supervisory authority's approval to rely on it.

B. Immediately obtain from the third party the necessary information related to the due diligence measures in these instructions.

Page 9 | 24

C. Take sufficient and appropriate steps, including making necessary arrangements with third parties, to ensure and reach self-satisfaction that the third party will, without delay and upon request by the Regulated Entity, provide copies of all documents, records, and data related to client and beneficial owner identification and other documents related to due diligence requirements according to the provisions of the Law and these instructions.

D. Ensure and reach self-satisfaction that the third party is subject to regulation and supervision or oversight, and that it has implemented procedures to comply with due diligence requirements towards clients and keep records in accordance with the provisions of the Law and these instructions.

E. In the event that the third party meeting the conditions specified in paragraph (1) of this Article is in another country, the Regulated Entity must take into account the available information regarding the risk level related to those countries.

  1. When the Regulated Entity relies on a third party that is part of the same financial group or professional group, the competent authorities in the home country and host country may consider that the requirements stipulated in the provisions of paragraph (1) of this Article are met in the following cases:

A. The financial group or professional group applies due diligence requirements towards clients, including enhanced due diligence, and keeps records and anti-money laundering and counter-terrorist financing programs in accordance with the provisions of the Law and these instructions.

b. Supervision by a competent authority over the implementation by the financial or professional group of customer due diligence requirements, record-keeping, and anti-money laundering and counter-terrorist financing programs.

c. The financial or professional group taking necessary measures to adequately mitigate any risks associated with countries through its adopted anti-money laundering and counter-terrorist financing policies.

Article 14 - Inability to Comply with Due Diligence Measures

In the event of an inability to comply with the customer due diligence measures stipulated in this Chapter, the regulated entity must do the following:

  1. Not open an account or commence business relationships or execute transactions.

  2. Terminate the business relationship with existing customers.

  3. Submit a suspicious transaction report to the Office regarding the customer's suspicious transactions or activities.

Article 15 - Exemption from Continuing Due Diligence

The regulated entity may, based on reasonable grounds, cease applying due diligence measures in cases where there are indicators of suspicion of money laundering or terrorist financing, if continuing due diligence would tip off such suspicion, provided that a report on the suspicious transaction or activity is submitted to the Office immediately, along with the reasonable and justified reasons for not taking due diligence measures.

Chapter Three Risk-Based Approach

Article 16 - Self-Assessment of Risks

a. The regulated entity is committed to conducting a self-assessment of money laundering, terrorist financing, and proliferation financing risks by identifying, assessing, and understanding those risks, commensurate with the nature and size of its business. This self-assessment must include incorporating or including information or results of any risk assessment conducted by the State, particularly information related to high risks.

b. Identifying, assessing, and understanding customer, country, or geographic area, product and service, process, and delivery or service provision channel risks.

c. Considering all risk factors in accordance with the provisions of Articles (18) and (19) of these Instructions, before determining the overall risk level and before determining the appropriate level and type of risk mitigation measures to be applied.

d. Considering risk variables in accordance with the provisions of Paragraph (c) of Article (21) of these Instructions.

  1. The regulated entity must apply the provisions of Paragraph (1) of this Article by doing the following:

a. Updating assessment processes periodically and as needed; documenting, updating, and retaining the risk assessments it conducts.

b. Making its risk assessment reports available periodically to competent regulatory authorities upon completion or upon request by these authorities.

c. According to the deadlines and mechanisms determined by it, either during on-site inspections or to the Supervision Department through persons entrusted with delivering reports in a sealed (confidential) envelope via the institution's private mail.

Disseminating and informing the results of the self-risk assessment to all employees.

Article 17 - Exceptions to Assessment Documentation

The regulated entity may refrain from conducting documented self-assessments in accordance with the provisions of Article (16) of these Instructions if the following conditions are met collectively:

  1. Money laundering and terrorist financing risks in the sector are clearly defined and understood.

  2. The regulated entity has a clear understanding of the money laundering and terrorist financing risks it faces.

  3. This exemption is based on prior approval from the regulatory authority.

Article 18 - High-Risk Factors

The regulated entity, when assessing money laundering and terrorist financing risks in accordance with Article (16) of these Instructions, must consider all high-risk factors related to customers, countries or geographic areas, products and services, processes, and delivery or service provision channels, including the following:

  1. High-risk factors related to customers: a. High-risk senior officials. b. Non-resident customers. c. Politically exposed persons or legal arrangements whose purpose is holding personal assets. d. The customer is a legal entity with nominee shareholders (nominee or proxy shareholders), such that the issuance of these shares allows one person to act on behalf of another. e. The customer is a legal entity that can issue bearer shares, such that ownership in the legal entity is granted to the person holding the bearer share certificate. f. Activities requiring intensive use of cash. g. The business relationship is conducted under unusual circumstances, for example, an unjustified large geographical distance between the customer's address and the regulated entity's address. h. The company's ownership structure appears unusually or excessively complex compared to the nature of the company's business. i. Any high-risk factors according to risk assessments conducted by the State, or trend or pattern reports issued by the Office, or based on what is issued by the Council or the regulatory authority, and any other potential high-risk factors related to customers.

  2. High-risk factors related to countries or geographic areas: a. Countries or geographic areas identified by the Council as high-risk countries. b. Countries or geographic areas identified by reliable sources as: (1) Lacking a suitable anti-money laundering or counter-terrorist financing system, or having strategic deficiencies in that system, according to joint assessment reports published by the Financial Action Task Force, or other detailed assessment reports issued by international bodies. (2) Characterized by high levels of corruption or other criminal activities. (3) Providing safe tax havens. (4) Providing funding or support for terrorist activities or operating with designated terrorist organizations. (5) Subject to regular sanctions, embargoes, or similar measures by the United Nations. c. Any high-risk factors according to risk assessments conducted by the State, or trend or pattern reports issued by the Office, or based on what is issued by the Council or the regulatory authority, and any other potential high-risk factors related to countries or geographic areas.

  3. High-risk factors related to products and services, processes, and delivery or service provision channels: a. Private banking services. b. Anonymous transactions (especially cash transactions). c. Business relationships or transactions not conducted face-to-face. d. Incoming payments from unrelated or unaffiliated third parties. e. New products, technologies, or professional practices, if assessed by the State, competent authority, or the regulated entity itself as high risk. f. Correspondent payment accounts. g. Products that allow large volumes of transactions to be executed in a short time. h. Travel networks. i. Single-premium insurance policies if the premium is large. j. Any high-risk factors according to risk assessments conducted by the State, or trend or pattern reports issued by the Office, or based on what is issued by the Council or the regulatory authority, and any other potential high-risk factors related to products and services, processes, and delivery or service provision channels.

Article 19 - Low-Risk Factors

The regulated entity, when assessing money laundering and terrorist financing risks in accordance with Article (16) of these Instructions, must consider all low-risk factors related to customers, countries or geographic areas, products and services, processes, and delivery or service provision channels, including the following:

  1. Low-risk factors related to customers:

a. Specified financial institutions, businesses, and non-financial professions, when subject to anti-money laundering and counter-terrorist financing obligations consistent with Financial Action Task Force recommendations, effectively applying these obligations, and subject to effective supervision or oversight in accordance with recommendations to ensure compliance with requirements.

b. Public companies listed on the financial market or stock exchange and subject to disclosure requirements (either through financial market rules, law, or any mandatory means), which impose requirements to ensure sufficient transparency of the beneficial owner.

c. Public institutions or bodies.

d. Individuals with limited fixed income whose income sources are specific, clear, and reliable, with no indicators of high risk around them.

e. Any low-risk factors according to risk assessments conducted by the State, or based on what is issued by the Council or the regulatory authority, and any other potential low-risk factors related to customers.

  1. Low-risk factors related to countries or geographic areas:

a. Countries or geographic areas identified by reliable sources, such as joint assessment reports published by the Financial Action Task Force or detailed assessment reports issued by international bodies, as having effective anti-money laundering and counter-terrorist financing systems.

b. Countries or geographic areas identified by reliable sources as characterized by low levels of corruption or other criminal activities.

c. Any low-risk factors according to risk assessments conducted by the State, or based on what is issued by the Council or the regulatory authority, and any other potential low-risk factors related to products and services, processes, and delivery or service provision channels.

Page 13 | 24

a. Life insurance documents where premiums are low, such as an annual premium less than (100) US dollars or its equivalent in legally circulating currencies, or a single premium less than (2500) US dollars or its equivalent in legally circulating currencies.

b. Retirement insurance documents if they do not include an early surrender option, and when the insurance document cannot be used as collateral.

c. Pension systems, or similar systems that provide retirement benefits to employees, when contributions are made via payroll deduction, and when the system rules do not allow the assignment of beneficiary rights under the system.

d. Financial products or services that appropriately provide limited services to specific types of customers for the purpose of enhancing financial inclusion.

e. Products or services, processes, or delivery or service provision channels associated with small non-cash financial amounts, with no indicators of high risk.

f. Any low-risk factors according to risk assessments conducted by the State, or based on what is issued by the Council or the regulatory authority, and any other potential low-risk factors related to products and services, processes, and delivery or service provision channels.

Article 20 - Risks of Modern Technologies

The regulated entity is committed to the following:

  1. Identifying and assessing money laundering and terrorist financing risks that may arise in relation to the development of new services, products, and professional practices, including new means of service delivery, and those arising from the use of new or developing technologies regarding both new and existing products.

  2. Conducting a risk assessment before launching, practicing, or using products, practices, or technologies.

  3. Taking appropriate measures to manage and mitigate those risks.

Article 21 - Application of the Risk-Based Approach

  1. The regulated entity is required to apply the risk-based approach based on its risk assessment in accordance with the provisions of Article (16) of these Instructions, or any risk assessment conducted by the State, as follows:

a. Establishing policies, controls, and procedures approved by senior management, enabling it to manage and mitigate identified risks, and supervising and enhancing them if necessary.

Page 14 | 24

b. Taking enhanced risk management and mitigation measures when high risks are identified, including taking enhanced due diligence measures in accordance with the provisions of Articles (23, 24, 25) of these Instructions.

c. Taking simplified risk management and mitigation measures only when low risks are identified, consisting of taking simplified due diligence measures in accordance with the provisions of Article (26) of these Instructions.

  1. The regulated entity, when applying the risk-based approach, must consider the following:

a. That the risk-based approach measures are consistent with the law, these Instructions, and guidelines issued by the regulatory authority or the Council.

b. The risk-based approach does not apply in cases where customer due diligence measures are required; rather, it is applied to determine the scope of these measures.

c. Changes in risks related to customers, countries or geographic areas, products and services, processes, and delivery or service provision channels can increase or decrease potential risks. Risk variables include, for example:

(1) The purpose of establishing the business relationship.

(2) The volume of transactions related to the customer's activities.

(3) The regularity of the business relationship or the duration of the business relationship.

d. Determining low money laundering or terrorist financing risk at the identification and verification stage does not automatically mean that the customer itself poses low risk for all types of due diligence measures, especially since the risk level may change when applying ongoing due diligence measures for financial transactions in accordance with the provisions of Article (9) of these Instructions, and based on risk variables in accordance with the provisions of Paragraph (2/c) of this Article.

Article 27 - Enhanced Due Diligence Measures

In addition to the due diligence measures specified in the law and these Instructions, the regulated entity is committed to the following:

  1. Examining the background and purpose of all unusual, large, or complex financial transactions and all unusual financial transaction activities that lack a clear economic or legal purpose, to the greatest extent possible and reasonably.

  2. Applying enhanced due diligence measures when money laundering or terrorist financing risks are high and in accordance with the nature of those risks, by increasing the degree and nature of monitoring the business relationship, to determine if those transactions or activities appear unusual or suspicious. This includes applying a set of enhanced due diligence measures to high-risk business relationships, including the following:

a. Obtaining additional information about the customer, such as additional information about profession and economic activities, other income sources, volume of funds or assets, and information resulting from public databases, the internet, etc.

b. Updating customer and beneficial owner identification data periodically, or repeating updates more frequently according to the risk level.

c. Obtaining additional information about the nature of the expected or existing business relationship.

d. Obtaining information to identify the source of funds or the customer's wealth, and verifying it.

e. Obtaining additional information to identify the purposes and reasons for expected or executed transactions.

f. Obtaining senior management approval to initiate or continue a business relationship.

g. Applying enhanced monitoring of the business relationship by increasing the frequency and timing of controls on that relationship, and identifying transaction patterns that require more scrutiny and review.

h. In the event that the customer has an account at a bank subject to due diligence standards, it may be required that the initial payment be made through an account in the customer's name at that bank.

Article 23 - Enhanced Due Diligence Measures for Correspondent Relationships

  1. The correspondent financial institution, regarding correspondent banking relationships conducted across borders, must take the following measures regarding respondent institutions:

a. Collecting sufficient information about the institution to fully understand the nature of its business, and using published information to identify the institution's reputation and the level of supervision it is subject to, and verifying whether it has undergone investigations regarding money laundering or terrorist financing or regulatory audits.

b. Evaluating the controls used by the institution to combat money laundering and terrorist financing.

c. Obtaining senior management approval before establishing new correspondent relationships.

d. Clarifying the responsibilities of both the correspondent and respondent institutions in combating money laundering and terrorist financing.

  1. The provisions of Paragraph (1) of this Article apply to other relationships similar to correspondent banking relationships, such as similar relationships arising for securities transactions or money transfers, whether for a cross-border financial institution in its principal capacity or for its customers.

  2. The financial institution allowing the use of correspondent payment accounts must ensure that the respondent bank has fulfilled its due diligence obligations towards customers who have direct access to the correspondent bank's accounts, along with ensuring its ability to provide customer due diligence information upon request by the correspondent bank.

  3. The financial institution is prohibited from entering into or continuing a correspondent banking relationship with shell banks, and must ensure that the respondent financial institution does not allow its accounts to be used by shell banks.

Article 24 - Enhanced Due Diligence Measures for High-Risk Countries

  1. In addition to the due diligence measures stipulated in the law and these Instructions, the regulated entity is committed to applying the following enhanced due diligence measures to business relationships and financial transactions conducted with natural and legal persons, including financial institutions, from countries identified by the Council or those authorized by the Council to do so according to its competence, whether based on what is determined by the Financial Action Task Force or based on what the Council deems appropriate independently:

a. Enhanced due diligence measures stipulated in Article (23) of these Instructions.

b. Any additional enhanced measures or procedures disseminated by the Council or those authorized by the Council to do so.

c. Any other enhanced measures having a similar effect in mitigating risks.

  1. The regulated entity is committed to applying measures disseminated by the Council or those authorized by it regarding countermeasures or measures related to high-risk countries.

Article 25 - High-Risk Senior Officials

  1. High-risk senior officials refers to any natural person representing any of the following categories:

a. Foreign high-risk person, which is a natural person who holds or has held a prominent public office in foreign countries, including heads of state or government, senior politicians, senior government, judicial, or military officials, senior officials of state-owned companies, senior officials of political parties, and other persons identified by the Council.

b. Local high-risk person, which is a natural person who holds or has held a prominent public office in the State, including the positions mentioned in item (a) of this paragraph.

c. International organization official, which is a natural person who holds or has held a prominent position in an international organization, including senior management members (directors and their deputies), board members, and equivalent positions.

  1. In addition to the due diligence measures required in accordance with this Chapter, the regulated entity is committed to taking the following measures towards foreign high-risk senior officials:

a. Establishing suitable risk management systems to determine if the customer or beneficial owner is a high-risk senior official, and complying with what is issued by the Council and regulatory authorities in this regard.

b. Obtaining senior management approval before initiating a business relationship with the customer or continuing it for existing customers.

c. Taking reasonable measures to identify the source of wealth and source of funds for the customer and beneficial owner identified as politically exposed high-risk persons.

d. Conducting enhanced ongoing monitoring of the business relationship.

  1. The regulated entity is committed to taking appropriate and sufficient measures to determine if the customer or beneficial owner is a local high-risk senior official or an international organization official. In addition to applying the due diligence measures stipulated in this Chapter, it must apply items (b, c, d) of Paragraph (2) of this Article when there is a high-risk business relationship with these persons.

  2. The measures required under the provisions of Paragraphs (2, 3) of this Article apply to family members of high-risk senior officials of all types or persons closely associated with them.

Article 26 - Simplified Due Diligence Measures

  1. The regulated entity may take simplified due diligence measures as part of simplified measures, provided that the following conditions are met collectively:

a. Sufficient risk mitigation by the State, and the regulated entities fulfilling all their risk-related obligations stipulated in Chapter Three of these Instructions.

b. Applying the provisions of the risk-based approach in accordance with the provisions of Article (21) of these Instructions.

c. When money laundering or terrorist financing risks are low, taking into account the nature of these risks and their consistency with the low-risk factors stipulated in Article (19) of these Instructions.

d. Applying simplified due diligence measures in accordance with Instructions and/or guidelines issued by the regulatory authority or the Council in this regard.

  1. The regulated entity is prohibited from applying simplified due diligence measures in the following cases:

a. Suspicion of money laundering or terrorist financing.

b. Occurrence of specific high-risk situations.

c. Absence of any of the conditions referred to in Paragraph (1) of this Article.

Article 27 - Existing Customers

The regulated entity is committed to the following:

  1. Applying due diligence measures to existing customers based on materiality and risk, from the date of entry into force of the provisions of these Instructions.

  2. Taking due diligence measures towards existing business relationships at appropriate times, taking into account whether they were previously taken and when, and the adequacy of the data obtained.

Chapter Four

Special Rules for Licensed Financial Institutions Providing Telegraphic Transfer and Money or Value Transfer Services

Article 28 - Procedures of the Remitting Financial Institution

In addition to the due diligence measures required in accordance with Chapter Two of these Instructions, the remitting financial institution, on behalf of the originator of the transfer, whether the transfer is local or international and regardless of the transfer value, is committed to obtaining the following information and retaining it in accordance with Article (32), and ensuring that this information accompanies the transfer process:

Page 18 | 24

In addition to the due diligence measures required in accordance with Chapter Two of these Instructions, the beneficiary financial institution, whether receiving the transfer directly from the remitting financial institution or indirectly through an intermediary financial institution, is committed to the following:

  1. Taking reasonable measures to identify international telegraphic transfers lacking the required information about the originator or beneficiary of the transfer, including follow-up procedures for execution, or follow-up procedures that result in the execution, rejection, or suspension of telegraphic transfers lacking the required information.

  2. Establishing risk-based policies and procedures to determine when to execute, reject, or suspend telegraphic transfers lacking the required information about the originator or beneficiary, and to determine appropriate follow-up measures based on risk.

  3. Verifying the identity of the transfer beneficiary, if not previously verified, and retaining it in accordance with Article (32) of these Instructions.

Article 31 - Money or Value Transfer Service Providers

  1. The provisions of Articles (28 to 30) of Chapter Four of these Instructions apply to all money or value transfer service providers regardless of the country in which they conduct their business, whether directly or through their agents. If the money or value transfer service provider controls both the remitter side and the beneficiary side of the transfer, it must:

(a) Take into account all information issued by the remitter side and the beneficiary side to determine the necessity of submitting a report on the suspicious transaction or not.

(b) Submit a report on the suspicious transaction in any of the countries concerned with the suspicious telegraphic transfers, and provide all relevant information regarding the transaction to the Office or the Financial Intelligence Unit.

  1. Money or value transfer service providers using agents are committed to the following:

(a) Maintaining an updated list of their agents that is easily accessible by competent authorities in the countries where the money or value transfer service providers and their agents operate.

(b) Including agents in anti-money laundering and counter-terrorist financing programs and monitoring their compliance with these programs.

Chapter Five Record Keeping and Internal Procedural Measures

Article 32 - Record Keeping

The regulated entity is committed to retaining the following:

  1. All records, documents, and papers related to local or international transactions or operations, for a period of no less than (5) years from the date of completion of the transaction or operation.

More like this from ISC

ISC published 13 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share