2018-06-26

Added · Updated

Anti-Money Laundering and Counter-Terrorist Financing Instructions for Licensed Banks No. (14/2018)

The Central Bank of Jordan mandates licensed banks to implement a risk-based approach for managing money laundering and terrorist financing risks, including annual risk assessments and customer classification. Banks are required to perform enhanced due diligence, verify beneficial owners, and monitor transactions, with specific thresholds for occasional customers and wire transfers. The instructions define key terms, establish reporting obligations to the central bank, and outline procedures for handling high-risk clients and shell entities.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

In the name of Allah, the Most Gracious, the Most Merciful

Central Bank of Jordan

Number: 8554/4/10 Date: 15/10/1439 AH Corresponding to: 26/6/2018 AD

Anti-Money Laundering and Counter-Terrorist Financing Instructions for Licensed Banks No. (14/2018)

Issued in reliance on the provisions of paragraph (b) of Article (99) of the Banking Law No. (28) of 2000 and its amendments, and on the provisions of Article (14/a) and Article (18/b) of the Anti-Money Laundering and Counter-Terrorist Financing Law No. (46) of 2007 in force.

Article (1): Definitions: First: The words and phrases contained in these Instructions shall have the meanings assigned to them in the Anti-Money Laundering and Counter-Terrorist Financing Laws in force wherever mentioned in these Instructions, unless the context indicates otherwise. Second: The following words and phrases shall have the meanings assigned to them below wherever they appear in these Instructions, unless the context indicates otherwise:-

The LawThe Anti-Money Laundering and Counter-Terrorist Financing Law in force.
Banking RelationshipThe relationship arising between the Bank and the Client concerning the activities, products, and services provided by the Bank to its clients.
Occasional CustomerA customer who does not have a bank account with the Bank and is not bound to the Bank by a banking relationship.
Beneficiary of the TransferThe natural or legal person or legal arrangement designated by the originator of the transfer as the recipient of the requested financial transfer.
Non-Profit OrganizationAny legal person, legal arrangement, or institution established in accordance with relevant laws to collect or spend funds for charitable, religious, cultural, educational, social, or other similar purposes, without its activity targeting the generation of profit, sharing of profits, or achieving personal benefit, including foreign branches and international non-profit organizations.
ControlThe direct or indirect ability to exercise effective influence over the business and decisions of another person.
Beneficial OwnerThe natural person with the real interest, for whose benefit or on whose behalf the business relationship is conducted, or who has full or effective control over a legal person or legal arrangement, or the right to carry out legal transactions on behalf of either.
Foreign Politically Exposed PersonsPersons who hold or have held a senior public office in a foreign country, such as: head of state or government, judicial or military officials, or a high-level government position, or were a prominent politician or prominent figure in a political party or senior executives in companies owned by a foreign country, and includes relatives of these persons to the first degree at a minimum or their partners in work or partners who have power of attorney issued by them.
Local Politically Exposed PersonsPersons who hold or have held a senior public office in the Kingdom, such as: head of government or minister, judicial or military officials, or a high-level government position, or were a prominent politician or prominent figure in a political party or senior executives in state-owned companies, and includes relatives of these persons to the first degree at a minimum or their partners in work or partners who have power of attorney issued by them.
Persons (foreign or local) who held a prominent position in an international organizationThey are senior management members, i.e., Directors, Deputy Directors, Board members, or positions equivalent to them in an international organization, and includes relatives of these persons to the first degree at a minimum or their partners in work or any persons acting on their behalf or who have power of attorney issued by them.

This definition does not apply to individuals holding middle or lower positions in the categories mentioned above.

Shell BankA Bank that has any of the following characteristics: 1. It has no physical presence in the country where it was established and licensed, meaning physical presence implies actual head office and management within a country, whereas mere presence of a local agent or low-level employees does not constitute physical presence. 2. It does not keep records of its transactions. 3. It is not subject to supervision by a competent regulatory authority, whether in the country where it was established or in any other country. The definition of Shell Bank does not apply to a Bank without a fixed headquarters if it is a branch of a licensed Bank with physical presence and subject to effective supervision.
Shell CompanyA Company used as a vehicle to pass transactions through without holding any assets or conducting operations specific to its activity, even if registered.
Non-residentA natural or legal person who usually resides or has their headquarters outside the Kingdom, or who has not completed a period of one year of residence within the Kingdom, regardless of the nationality of this person, except for families and individuals who have an economic status or interest and have a permanent economic activity and permanent residence within the Kingdom, even if they reside there intermittently.
The UnitThe Anti-Money Laundering and Counter-Terrorist Financing Unit formed in accordance with the provisions of the Law.
Money Laundering Reporting Officer (MLRO)A senior management official in the Bank (who may be the Compliance Manager) appointed for the purpose of reporting transactions suspected of being related to money laundering or terrorist financing.
Senior Executive ManagementIncludes the Bank's General Manager or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant Regional Director, Chief Financial Officer, Operations Manager, Risk Management Director, Internal Audit Director, Treasury (Investment) Director, Compliance Manager, and any Bank employee with executive authority parallel to any of the aforementioned and functionally reporting directly to the General Manager.
Wire TransferAny transfer process carried out by a Bank using electronic money transfer means on behalf of the originator, whereby funds are sent to another Bank or any other financial company where the beneficiary can receive them, regardless of whether the originator is the same person as the beneficiary.
Batch TransferA transfer consisting of a number of individual financial transfers sent to the same financial institution, but which may or may not ultimately be directed to different persons.
Financial GroupA group consisting of a parent company or any other legal person who holds controlling shares and coordinates functions with other group members to apply or implement group-wide supervision under the Basel Committee on Banking Supervision's Principles for Effective Banking Supervision, along with branches and/or subsidiaries subject to Anti-Money Laundering and Counter-Terrorist Financing policies and procedures at the group level.
Financial InstitutionA legal person that exercises one or more financial activities stipulated in the Banking Law under its establishment, including insurance companies, for the purposes of these Instructions.
Subsidiary CompanyA Company in which a person or group of persons united by a common interest owns not less than (50%) of its capital, or in which this person or these persons have an influential interest allowing control over its management or general policy.
Straight Through ProcessingPayment operations carried out electronically without the need for manual intervention.
Legal ArrangementsThe relationship arising under a contract between two or more parties that does not result in the creation of a legal person, such as direct trusts or similar legal arrangements.
Express TrustsLegal relationships arising - inter vivos or upon death - by a person or trustee, where assets have been placed under the control of the person or trustee for the benefit of a beneficiary or for a specific purpose, such that the assets are independent funds and not part of the trustee's property, and the right to the trustee's assets remains in the name of the settlor or in the name of another person on behalf of the settlor.

Article (2): Scope of Application: The provisions of these Instructions shall apply to each of the following: First: Banks operating in the Kingdom. Second: Branches of Jordanian Banks operating and their subsidiaries operating abroad to the extent permitted by the laws and regulations in force in the countries where they operate, while applying the strictest standards possible in case of differences in Anti-Money Laundering and Counter-Terrorist Financing requirements in the host country compared to the home country. The Bank must notify the Central Bank of any obstacles or restrictions that may limit or prevent the application of the provisions of these Instructions. Third: Subsidiaries of Jordanian Banks operating in the Kingdom, unless these companies are subject to the supervision of another regulatory authority in the Kingdom, and that authority has issued specific instructions for combating money laundering and terrorist financing.

Article (3): Risk-Based Approach: First: Risk Management: 1- Within the framework of the Risk-Based Approach, the scope and intensity of the risk management function must be commensurate with the nature, size, and complexity of the Bank's operations and its level of money laundering and terrorist financing risks. 2- The function of managing money laundering and terrorist financing risks in the Bank must be aligned and integrated with the overall risk management framework within the Bank.

Second: Risk Assessment: 1- The Bank must conduct a comprehensive assessment of money laundering and terrorist financing risks at least annually, or whenever a need arises due to a fundamental change in the nature of risks faced by the Bank. This assessment aims to identify, evaluate, and understand money laundering and terrorist financing risks regarding customers, countries, geographic areas, products, services, operations, and service delivery channels, according to a methodology approved by its Board of Directors or the Regional Management of the foreign Bank. The assessment must include the Bank's branches and subsidiaries abroad, and the assessment processes must be documented. 2- The assessment must include at least the following: 1,2 Results of monitoring activities conducted by the Bank, such as the Bank's exposure level to money laundering and terrorist financing risks, risk details by main activities and customer categories, trends in suspicious transaction reports and cash transaction reports, and trends in requests received by the Bank from law enforcement agencies. 2,2 Details of significant risk events that occurred internally or externally and their impact on the Bank. 3,2 Any recent changes in instructions or circulars regulating the combating of money laundering and terrorist financing and their impact on the Bank. 3- The Bank must provide the Central Bank before the end of April of each year with the following: 1,3 The approved assessment methodology and any amendments introduced to it. 2,3 The assessment results submitted to Senior Management and the Board of Directors. 3,3 A report from the Bank's Internal Auditor or the specialized committee emanating from its Board of Directors, clarifying recommendations and measures intended to be taken to mitigate high risks identified as a result of the assessment.

Third: Risk Control and Mitigations: The Bank must have the following: 1- Policies, controls, and procedures for managing and reducing identified money laundering and terrorist financing risks, approved by Senior Management in the Bank according to their respective jurisdictions. 2- Monitoring the application of these policies, controls, and procedures and enhancing them if necessary. 3- Taking enhanced due diligence measures to manage and reduce risks identified as "high risk." 4- Verification of the application of these policies, controls, and procedures on the ground by Internal Audit as an independent body.

Fourth: Customers Classification: 1- The Bank must classify its customers according to the nature of their money laundering and terrorist financing risks, updating this classification periodically in accordance with the nature and level of such risks for each customer, taking into account the following factors:

  • Resident or non-resident.
  • Customer type (natural or legal person, non-profit organization, etc.).
  • Occasional customer.
  • Ownership structure of the legal person.
  • Types of politically exposed persons.
  • Types of professions.
  • Geographic location.
  • Customer's country of origin.
  • Products, services, operations, or service delivery channels (e.g., cash operations, direct or indirect dealing, cross-border transactions).
  • Any other information indicating the customer's risk level. 2- The risk mitigation measures applied by the Bank must be commensurate with the nature of the customer's risk.

Fifth: Higher risk: Situations where the Bank's assessment of money laundering/terrorist financing risk is high, taking into account the following factors (as a minimum): 1- Factors related to customer risks:

  • Conducting business under unusual circumstances (e.g., unjustified large geographical distance between the Bank and the customer).
  • Non-resident customers.
  • Cases where the legal person or legal arrangements are a special purpose entity.
  • Businesses relying heavily on cash.
  • Unjustified complexity in ownership structure compared to the nature of the company's business.
  • Private banking customers (High Net Worth Customers).
  • Customers belonging to areas known for high crime rates (e.g., countries known for drug production, transport, or smuggling).
  • Customers belonging to or present in countries that do not apply Financial Action Task Force (FATF) recommendations or do not apply them sufficiently.
  • Businesses classified by the Financial Action Task Force (FATF) as "high risk" in money laundering and terrorist financing.
  • Customers meeting risk indicators specified by the Bank. 2- Factors related to country and geographic area risks:
  • Countries lacking sufficient systems for combating money laundering and terrorist financing or not applying FATF recommendations sufficiently.
  • Countries subject to sanctions, embargoes, or other measures issued by the United Nations.
  • Countries suffering from high levels of corruption or other criminal activities.
  • Geographic areas considered to be terrorist financing or supporting terrorist activities.
  • Countries where terrorist organizations are present.
  • Countries suffering from political or security conditions that hinder compliance with FATF recommendations. When determining factors related to risks for countries and geographic areas, the Bank may refer to credible sources such as mutual evaluation reports, follow-up reports, and any other relevant reports published by international organizations such as: the United Nations and the Financial Action Task Force (FATF). 3- Factors related to product, service, or distribution channel risks:
  • Operations conducted by anonymous persons (which may involve cash).
  • Business relationships or operations not conducted face-to-face.
  • Amounts received by the customer from multiple persons or from countries disproportionate to the nature of their business and risks.
  • Amounts received by the customer from unknown sources or from a third party with no clear relationship to the customer. High-Risk Countries: Represent countries listed by the Financial Action Task Force (FATF) as high-risk countries regarding money laundering and terrorist financing, or those with deficiencies in anti-money laundering and counter-terrorist financing procedures posing a risk to the global financial system, or for which the Kingdom has information indicating they are high-risk countries in money laundering and terrorist financing.

Sixth: The Bank must identify and assess money laundering and terrorist financing risks that may arise regarding the development of products within new lines of business, including new means of service delivery, and those that may arise from the use of new technologies within new or developing lines of business regarding both new and existing products, and take appropriate measures to manage and reduce those risks, and notify the Central Bank of the results. Seventh: Take into account all relevant risk factors before determining the overall risk level and the appropriate level of risk mitigation measures to be applied. Eighth: Provide appropriate mechanisms to supply identified risks to competent authorities upon request.

Article (4): Due Diligence Requirements: First: General Rules: 1- The due diligence concerning customers to be taken by the Bank refers to the following: 1,1 Obtaining information about the identity of customers (permanent or occasional, whether natural or legal persons or legal arrangements) and their legal status, and verifying it using original documents, data, or information from a reliable and independent source. 2,1 Comparing the customer's name with names of persons and entities listed on sanctions lists issued by United Nations Security Council resolutions. 3,1 Ascertaining the customer's activity and understanding the purpose and nature of the business relationship with the Bank and obtaining information related to that. 4,1 In case a person acts on behalf of the customer, verification must be made that they are authorized to do so, identifying and verifying their identity. 5,1 Identifying the beneficial owner and taking reasonable measures to verify their identity using an identification document issued by a government authority, such that the Bank is convinced it is aware of the beneficial owner's identity. 6,1 Verifying the sources of funds and supporting documents for transactions conducted within the banking relationship. 7,1 Exercising ongoing due diligence regarding business relationships and scrutinizing transactions carried out throughout the duration of the relationship to ensure consistency of these transactions with what the Bank knows about its customer, their activity pattern, and risk nature, including the source of funds when necessary, and comparing them with peers in the same activity or those within the same risk degree, and recording and retaining all related data in accordance with the provisions of these Instructions. 8,1 Ensuring that documents, data, or information obtained under due diligence procedures are continuously updated and appropriate by reviewing existing records, especially for high-risk customer categories. 9,1 Obtaining any other information related to customer risk assessment indicators. 2- The Bank must apply all due diligence measures regarding customers stipulated in paragraph (1) of item (First) above in this Article, defining the scope of those measures using the Risk-Based Approach referred to in Article (3) of these Instructions. 3- The Bank must take due diligence measures regarding customers in the following cases: 1,3 Before or during the banking relationship. 2,3 When there is doubt about the accuracy or sufficiency of data and information previously obtained regarding customer identification. 3,3 When conducting transactions for occasional customers where the value of a single transaction or multiple seemingly linked transactions exceeds (10,000) Jordanian Dinars or its equivalent in foreign currencies. 4,3 If the Bank suspects that the transaction is suspected of being related to money laundering or terrorist financing, regardless of its value or the applicability of simplified due diligence procedures. 5,3 Any wire transfers conducted by an occasional customer, regardless of their value. 4- In case the Bank is unable to fulfill due diligence procedures regarding customers, it must not open an account or enter into any banking relationship with the customer or execute any transaction on their behalf, and must immediately notify the Unit in case of suspicion of connection to money laundering or terrorist financing according to the form or means approved by the Unit for this purpose. 5- Timing of verifying customer and beneficial owner identity: 1,5 The Bank must verify the identity of the customer and beneficial owner before or during the banking relationship or execution of transactions from reliable and neutral sources. 2,5 The Bank may defer some customer and beneficial owner identity verification procedures until after establishing a continuous business relationship, provided they are completed within a period not exceeding (10) working days from the date of relationship creation; otherwise, the relationship must be terminated, and the Unit must be immediately notified in case of suspicion of connection to money laundering or terrorist financing according to the form or means approved by the Unit for this purpose, without allowing the customer to withdraw cash upon termination, but using other means that enable tracking (Audit trail), and the deferral must be according to the following: 1,2,5 That deferring verification is necessary to maintain the completion of ordinary business, without resulting in money laundering or terrorist financing risks. 2,2,5 That the Bank has taken necessary measures to effectively control money laundering or terrorist financing risks regarding the case where deferral was applied, including setting limits on the type and amounts of transactions that can be executed before completing verification procedures, and including that in the Bank's approved work procedures.

6- In case the Bank enters into a banking relationship with the customer and indicators appear of a transaction suspected of being related to money laundering or terrorist financing, the Bank must do the following: 1,6 Complete/re-fulfill due diligence procedures regarding suspicious transactions. 2,6 In case the Bank does not reach conviction of the sufficiency of due diligence procedures, and that continuing to demand the customer to complete due diligence procedures may alert the customer (Tipping off), then in such cases, the Bank must not continue completing those procedures and must immediately notify the Unit according to the form or means approved by the Unit for this purpose, without allowing the customer to withdraw cash, and using other payment means regarding account tracking (Audit trail).

7- The Bank must exercise due diligence towards existing customers based on relative importance and risk, and take necessary due diligence measures towards its current relationships with them in the cases stated below, and the Bank must be aware of whether due diligence procedures were taken previously, when they were taken, and the sufficiency of the data obtained: 1,7 When executing transactions in large amounts or using banking instruments in an unusual manner. 2,7 When a fundamental change occurs in the mechanism of documenting customer information. 3,7 When a noticeable change occurs in the method of account management. 4,7 When the Bank realizes it does not have sufficient information about one of these customers.

8- Updating Data: The Bank must take due diligence measures on a continuous basis regarding business relationships, including: 1,8 Scrutinizing transactions carried out throughout the duration of the relationship to ensure consistency of executed transactions with what the Bank knows about customers, their activity pattern, and the risks they represent, including the source of funds if necessary. 2,8 Ensuring that documents, data, or information obtained under due diligence procedures are continuously updated and appropriate by reviewing existing records, especially for high-risk customer categories. 3,8 The Bank may rely on identification and verification procedures previously conducted, unless it has doubts about the validity of that information or in case of suspicion of money laundering or terrorist financing or a fundamental change in the way the customer's account is operated that does not align with the customer's activity. 4,8 In case the customer does not cooperate with the Bank's request to update their data as the Bank deems appropriate, the Bank may gradually suspend some financial operations and services provided to the non-cooperative customer, until the customer updates their data properly, provided that awareness tools and campaigns are activated for customers regarding the consequences of non-compliance with updating their data and urging them to update whenever necessary.

  1. The following shall be observed in the identification procedures for non-profit entities:

1.5 Identification data shall include: the name of the non-profit entity, legal form, national ID of the entity (if available), headquarters address, nature of activity, date of establishment, names of authorized account handlers and their nationalities, phone numbers, purpose of the transaction, sources of income or funding, names of persons holding senior management positions in the non-profit entity, and any other information the Bank deems necessary to obtain.

2.5 Obtain documents evidencing authorization from the non-profit entity for the natural persons authorized to handle the account, in addition to the necessity of identifying the authorized account handler in accordance with the customer identification procedures stipulated in Item (1.3) of this Article.

Attached is a model representing the minimum identification data for customers that must be fulfilled.

Thirdly: Procedures for verifying customer identification data: The Bank shall take the necessary measures to verify the accuracy of the data and information obtained from the customer through neutral and reliable sources, including communication with competent authorities for official documents confirming this data, as follows:

  1. Verification of the identity of a natural person: This is done by referring to the Civil Status, Passports, and Residence Department website for Jordanians, and obtaining a certified copy of a valid passport and any of the identity proof documents mentioned in Item Second, Paragraph (1.3) of this Article for non-Jordanians, signed by the competent official certifying it as a true copy, with the customer signing an acknowledgment to provide the Bank with a copy of the passport upon renewal for non-Jordanians, and that the Bank has the right to gradually suspend some financial transactions and services provided to the customer if this is not provided, in addition to obtaining proof of the customer's place of work and income sources (such as obtaining an original copy of contracts or a salary certificate).

  2. Verification of the identity of a legal person or legal arrangement: This is done by verifying the items mentioned in Article (4, Second/4) through the necessary documents and the information they contain, and referring to the websites of the Companies Control Department and the Ministry of Industry, Trade, and Supply, such as: the establishment contract and the articles of association of the legal person and certificates issued by the Ministry of Industry, Trade, and Supply and by Chambers of Commerce and Industry, and that they are recent, in addition to obtaining an official certificate issued by the competent authorities, authenticated according to the rules, in case the legal person or legal arrangement is registered abroad, and any other information the Bank deems necessary.

  3. In the case where the legal person is a foreign company not registered and not licensed to operate within the Kingdom: It must be ensured that the establishment of such companies opening accounts or conducting any operations in the Kingdom complies with the prevailing laws and legislations, taking into account the nature of the operations conducted through these accounts.

  4. Verification of the identity of the non-profit entity and its legal entity status: This is done through official documents and the information they contain, such as certificates issued by the Ministry of Social Development or any other competent authority, and whether it is authorized to operate in the Kingdom and/or accept donations and grants from local or foreign sources, and referring to the website of the Societies Register.

  5. Verification of the addresses of the natural person, legal person, legal arrangement, and non-profit entity: This is done by obtaining copies of the lease contract, utility bills, visiting the customer's headquarters, and trade licenses.

  6. In the case of opening accounts by correspondence: The required information and documents shall be obtained in accordance with the customer identification requirements stipulated in Article (4) of these Instructions, authenticated according to the rules either through a financial institution belonging to the same group or authenticated by official authorities such as (Jordanian and foreign embassies and consulates) or obtaining a recommendation or official signature certification from well-known banks or financial institutions.

Fourthly: Beneficial Owner:

  1. The Bank shall request every customer to provide a written declaration identifying the beneficial owner of the transaction to be executed (in cases requiring this), such that the declaration includes at least the customer identification information.

  2. The Bank shall identify the beneficial owner and take reasonable measures to verify this identity according to the customer's risk profile, relying on data or information obtained from official documents and data, such that the Bank is convinced that it is aware of the beneficial owner's identity.

  3. The following shall be observed in identifying the beneficial owner in the case of a legal person:

1.3 Identify the identity of the natural person(s) (if any) who has actual controlling ownership in the customer within the legal person.

2.3 In case of doubt about identifying the natural person or inability to identify them in accordance with Item (1.3) above, the Bank shall identify the identity of the natural person who has control within the legal person through other means.

3.3 In case no natural person is identified under the application of Items (1.3) and (2.3) above, the Bank shall determine and take reasonable measures to verify the identity of the relevant natural person holding a senior administrative position within the legal person.

  1. The following shall be observed in identifying the beneficial owner if the customer is a legal arrangement:

1.4 Trusts: Identify the identity of the settlor, trustee, or protector (as appropriate) and the beneficiaries or class of beneficiaries for each other natural person exercising effective and actual control over the trust.

2.4 Other types of legal arrangements: Identify the identity of persons holding positions equivalent to those mentioned above or similar.

Article (5): The Bank is prohibited from keeping or dealing with anonymous accounts or fictitious name accounts, including digital ones, as well as dealing or entering into banking relationships with persons of unknown identity or fictitious names, or with fictitious companies or banks.

Article (6): Simplified Due Diligence Procedures:

Firstly: The Central Bank shall, by orders issued, determine the cases or operations requiring simplified due diligence measures when identifying the customer and beneficial owner, and verifying them, which determine examples of low-risk customers or operations and any international controls or local requirements in this regard.

Secondly: Simplified due diligence measures shall not be taken in case of suspicion of money laundering or terrorist financing or in case of circumstances involving high risks.

Article (7): Due Diligence Procedures within the Financial Group or a Third Party Outside the Financial Group:

Firstly: The Bank may rely on financial institutions that are members of the financial group to which it belongs or a third party outside the financial group, in accordance with the provisions of these Instructions, in applying enhanced due diligence procedures towards politically exposed persons (PEPs) representing risks, and the third party must be subject to regulation and supervision by competent authorities and have procedures to comply with due diligence requirements towards customers and maintain records and anti-money laundering and terrorist financing programs stipulated in these Instructions.

Secondly: The Bank must take into account the risk assessment level of the country where the member financial institution or the third party outside the financial group is located, such that enhanced due diligence measures are taken if the country is high-risk, and any country-specific high risks are sufficiently mitigated by the financial group's policies related to anti-money laundering and terrorist financing.

Thirdly: The ultimate responsibility for applying due diligence procedures towards customers remains with the Bank, which must comply with the following:

  1. Obtain immediately the necessary information related to the following:

1.1 Establishing business relationships.

2.1 When conducting transactions for occasional customers where the value of a single transaction or several seemingly related transactions exceeds (10,000) Jordanian Dinars or its equivalent in foreign currencies.

3.1 Conducting occasional transactions in the form of electronic transfers.

  1. Take the necessary measures so that the Bank is convinced that copies of customer identification data and documents and other documents related to customer due diligence requirements will be provided by the member financial institution or the third party outside the financial group upon request without delay.

Article (8): Cases Requiring Enhanced Due Diligence [i.e., carrying out additional due diligence procedures and obtaining additional and more detailed information about these customers] in addition to the due diligence requirements mentioned in Article (4) of these Instructions:

Firstly: The Bank shall take enhanced due diligence measures when the customer's risk classification in money laundering and terrorist financing is "high," as follows:

  1. Obtain the approval of the Bank's General Manager / Regional Manager or those authorized by senior executive management before establishing or continuing the relationship with these customers, and this approval must also be obtained when it is discovered that the risk of one of the customers or beneficial owners has become within this category.

  2. Take sufficient measures to ensure the sources of wealth of customers and beneficial owners classified within this risk category.

  3. Monitor the transactions of these customers with the Bank carefully and continuously, and exercise enhanced due diligence for business relationships and transactions conducted with any of them, while continuing to take enhanced due diligence measures and monitoring for these relationships.

  4. Take the necessary measures to ascertain the background of the circumstances surrounding any of the business relationships and transactions conducted with any of the customers classified within this category and their purposes, if the Bank determines that any of them is not based on clear economic justifications, and make a decision regarding them while retaining the results in its records.

Secondly: Dealing with Foreign Banks:

  1. The Bank shall apply the due diligence requirements regarding customers stipulated in Article (4) above when establishing a banking relationship with a foreign bank.

  2. The Bank shall ascertain the nature of the foreign bank's activity, its reputation in the field of anti-money laundering and terrorist financing through information available to the public, and whether it has undergone investigation regarding money laundering or terrorist financing or regulatory action by regulatory authorities.

  3. Approval from the Bank's General Manager / Regional Manager must be obtained before establishing a dealing relationship with the foreign bank.

  4. The Bank must ensure that the foreign bank is subject to effective supervisory oversight by the regulatory authority in the home country and/or the country where it is located.

  5. The Bank must verify the availability of sufficient anti-money laundering and terrorist financing programs at the foreign bank.

  6. The Bank shall evaluate the policies, procedures, and controls related to anti-money laundering and terrorist financing at the foreign bank, such that it is convinced that the foreign bank does not allow its accounts to be used by fictitious banks or in executing transactions related to money laundering or terrorist financing, and that the relationship with the foreign bank is based on each bank's clear understanding of its responsibilities in the field of anti-money laundering and terrorist financing.

  7. The Bank shall not enter into or continue the banking relationship if it is found that the foreign bank has dealings with fictitious banks.

  8. The Bank must ensure that the foreign bank has implemented due diligence procedures regarding its customers who have the right to use payment intermediary accounts which are used directly by third parties to conduct their business, such as (Payable-Through Accounts) / (Nested Account / Upstream Clearing), and that the foreign bank has the ability to provide information related to due diligence for these customers and transactions executed on these accounts when necessary.

Thirdly: Indirect Dealing with Customers: The Bank must put in place the necessary policies and procedures to mitigate the risks related to the misuse of indirect dealing with customers which is not face-to-face and apply them effectively, especially those conducted using modern technological techniques such as ATM services, telephone banking, internet network, electronic point of sale, and prepaid or reloadable cards, taking into account the prevailing instructions issued by the Central Bank of Jordan regarding this matter.

Fourthly: Foreign Politically Exposed Persons (PEPs):

  1. The Bank must put in place a management system to identify which of its customers or beneficial owners fall into this category.

  2. If any of the Bank's customers or beneficial owners are identified within this category, the Bank must take enhanced due diligence measures as outlined in Item (Firstly) of this Article.

Fifthly: Local Politically Exposed Persons (PEPs):

  1. The Bank must take reasonable measures to determine whether the customer or beneficial owner falls into this category.

  2. If any of the Bank's customers or beneficial owners are identified within this category, the Bank must evaluate the level of money laundering and terrorist financing risks involved in the business relationship with this customer.

  3. If the Bank evaluates the customer's risk as high-risk, the Bank must take enhanced due diligence measures as outlined in Item (Firstly) of this Article, and the Bank may suffice with due diligence measures if the customer's risk is evaluated otherwise.

Sixthly: Unusual Transactions:

  1. The following are considered unusual transactions:

1.1 Large or complex transactions to an unusual degree compared to the customer's transactions and account activity or several related transactions that constitute a single transaction in total.

2.1 Any other transaction with an unusual pattern that does not appear to have a clear economic justification or does not match the nature of the customer's work and activity.

  1. The Bank must exercise enhanced due diligence regarding unusual transactions, as well as when there is doubt about the accuracy or correctness of customer identification data after establishing the banking relationship, by conducting the necessary analysis and studies and any other necessary measures to verify the source of funds and the nature of the transaction, with the necessity of keeping special records regarding them regardless of the decision taken regarding them, and including examples of the decision taken regarding them in the Bank's compliance policy and/or implementation procedures, and including enhanced due diligence regarding such transactions.

Seventhly: Other Cases: The Bank must also exercise enhanced due diligence in the following cases in proportion to the level of risk:

  1. When opening a correspondence account.

  2. When requesting facilities against deposits.

  3. When renting safe deposit boxes.

  4. When depositing cash amounts or checks into an existing account by a person(s) who do not represent the account holder by a judicial power of attorney or authorization approved by the Bank.

Article (9): Financial Group and Foreign Branches:

  1. If the Bank is part of a financial group, the group should be required to apply anti-money laundering and terrorist financing programs at the group level, which should apply, as appropriate, to all branches and subsidiaries in which the group holds a majority, and take into account money laundering and terrorist financing risks and the volume of business. These programs should include the following measures:

Firstly: Preparing policies, procedures, internal controls, and appropriate arrangements regarding the following:

  1. Compliance management (including appointing a compliance officer at the management level).

  2. Appropriate screening procedures to ensure high efficiency standards when appointing employees.

Secondly: Establishing a continuous employee training program.

Thirdly: Creating an independent audit unit to test the system.

Fourthly: Establishing policies for exchanging required information for customer due diligence and managing money laundering and terrorist financing risks.

Fifthly: Providing information related to customers, accounts, and transactions from branches and subsidiaries to compliance, audit, and/or anti-money laundering and terrorist financing functions at the group level, which may include analysis of unusual transactions and may also include that a notice was sent to the unit regarding the transaction, when necessary for anti-money laundering and terrorist financing purposes in line with risk management.

Sixthly: Providing sufficient guarantees regarding confidentiality and the use of exchanged information, including guarantees of non-alerting.

  1. If the host country does not allow the appropriate implementation of measures specific to anti-money laundering and terrorist financing that are consistent with the Kingdom's procedures, the financial group should apply additional appropriate measures to manage money laundering and terrorist financing risks and inform the Central Bank of Jordan of this.

Article (10): Transfers:

Firstly: Scope of Application:

  1. The provisions of this Article apply to incoming and outgoing transfers, including electronic transfers exceeding seven hundred Jordanian Dinars or its equivalent in foreign currencies, taking into account the obligations imposed by United Nations Security Council resolutions regarding the prohibition of dealing with listed individuals and entities and freezing any funds belonging to them in accordance with the provisions of the instructions issued in this regard.

  2. Despite what was stated in Paragraph (1) of this Item, the Bank is committed to ensuring that all transfers less than seven hundred Dinars or its equivalent in foreign currencies contain all the information of the electronic transfer issuer and the electronic transfer beneficiary stipulated in this Article, with the understanding that it is not necessary to verify the accuracy of this information unless there is suspicion of money laundering or terrorist financing.

Secondly: Obligations of the Remitting Bank:

  1. The Bank must obtain complete information about the transfer issuer and the beneficiary, as follows:

1.1 If the issuer is a customer with a banking relationship with the Bank, the following information for the transfer must be taken from the banking system (automatic link) and within locked, non-editable fields (LOCKED):

1.1.1 Full name of the transfer issuer.

2.1.1 International Bank Account Number (IBAN).

3.1.1 Address of the transfer issuer or a statement from the customer that their address in the Bank's records has not changed.

In addition to the following data:

4.1.1 Purpose and objective of the transfer.

5.1.1 Relationship between the transfer issuer and the transfer beneficiary.

6.1.1 Declaration from the transfer issuer regarding the beneficial owner of the transfer, according to available information.

2.1 If the transfer beneficiary is a customer with a banking relationship with the Bank:

1.2.1 Full name of the transfer beneficiary.

2.2.1 International Bank Account Number (IBAN).

3.2.1 Address of the beneficiary.

4.2.1 Purpose and objective of the transfer.

5.2.1 Relationship between the issuer and the transfer beneficiary.

6.2.1 Declaration from the transfer beneficiary that they are the beneficial owner of the transfer.

  1. In the case where the transfer issuer does not have an account with the Bank (occasional customer):

1.2 The Bank shall create a system that provides a unique reference number for the transaction, allowing it to be tracked.

2.2 Take due diligence measures regarding customers stipulated in Article (4) of these Instructions.

  1. Take verification measures for all information according to the standards and procedures stipulated in Article (4) of these Instructions before sending the transfer.

  2. The Bank must attach all the data stipulated in Paragraphs (1) and (2) of this Item to the transfer, as follows:

1.4 It must be able to provide the receiving Bank or competent official authorities with the required information completely within three working days from the date of receiving the request for it.

2.4 The Bank must be able to respond immediately to any order issued by competent official authorities requiring it to disclose this information.

  1. For a bundled transfer, the remitting Bank attaches the transfer issuer's account number or the unique reference number in case of no account, subject to the following:

1.5 The Bank must retain the complete information about the transfer issuer and beneficiary stipulated in Paragraphs (1) and (2) of this Item.

2.5 The Bank must be able to provide the receiving Bank or competent official authorities with the required information completely within three working days from the date of receiving the request for it.

3.5 The Bank must be able to respond immediately to any order issued by competent official authorities requiring it to disclose this information.

  1. The Bank must ensure that non-routine transfers are not sent within bundled transfers in cases that would increase money laundering and terrorist financing risks.

  2. In case the Bank is unable to fulfill the requirements stipulated in Item (Secondly) of this Article, the Bank must not execute/issue the transfer.

Thirdly: Obligations of the Receiving Bank:

  1. The Bank must put in place effective systems to detect any deficiency in the information related to the transfer issuer or beneficiary stipulated in Paragraphs (1) and (2) of Item (Secondly) above.

  2. The Bank must rely on a risk-based methodology in verifying information related to transfers received into its customers' accounts, as well as when there is suspicion that the executed transfer is related to money laundering or terrorist financing.

  3. The Bank must adopt effective measures relying on risk assessment in dealing with transfers where information about the transfer issuer or beneficiary is not completed, and these measures include requesting the missing information from the remitting Bank, and in case of not obtaining it, the Bank must take measures based on risk assessment, including executing the transfer, suspending it, or rejecting it, which shall be an indicator relied upon in the Bank's assessment of the suspicion of money laundering or terrorist financing in that transaction.

  4. Regarding cross-border electronic transfers equivalent to (700) Dinars or more, the receiving Bank must verify the identity of the beneficiary, if not verified previously, and retain data and records as stipulated in Article (10) of these Instructions.

  5. In case of receiving a bundled transfer, the receiving Bank must obtain all the information and requirements referred to in Article (10/Secondly/5) above, and in case of inability to fulfill this data within three working days, the receiving Bank must reject the execution of the transfer.

  6. The Bank must verify the identity of the beneficiary and retain this information for a period of not less than five years.

Fourthly: Obligations of the Intermediary Bank:

  1. If the Bank participates in executing the transfer without being the issuer or receiver, it must ensure that all information attached and stipulated in Item (Secondly) of this Article remains with the transfer during the transfer and take reasonable measures consistent with direct bank transfer by the customer, to identify transfers missing information about the transfer issuer or beneficiary.

  2. If the Bank is unable to keep the information attached to the transfer for technical reasons, it must retain all attached information as received for a period of not less than five years, regardless of the completeness or deficiency of this information, enabling it to provide the available information to the receiving Bank within three days from the date of request.

  3. If the Bank decides to execute the transfer according to its internal policies and procedures, it must notify the receiving Bank of the incomplete information when performing the transfer, and retain all attached information as received for a period of not less than five years, regardless of the completeness or deficiency of this information.

Fifthly: The following are exempt from the attachment provisions stipulated in Paragraph (4) of Item (Secondly) and Item (Fourthly) of this Article:

  1. Electronic transfers arising from transactions conducted using payment or credit cards, provided that the transfer is accompanied by the card number.

  2. Electronic transfers where both the issuer and the receiver are banks acting on their own account.

Sixthly: General Provisions Regarding Transfers: The Bank must put in place effective policies and work procedures relying on risk assessment in dealing with transfers, determining when the transfer is executed, rejected, or additional data is requested regarding it, for transfers that have not fulfilled complete information about the transfer issuer or beneficiary according to appropriate cases, including notifying the Unit immediately.

Article (11): Retention of Records and Documents:

Firstly: The Bank must retain records and documents for the financial local and international transactions it conducts, such that these records include data related to due diligence and enhanced due diligence stipulated in these Instructions, including risk assessment procedures, for a period of at least five years from the date of transaction completion or relationship termination, as appropriate.

Secondly: The Bank must retain records and documents supporting banking relationships and transactions, commercial correspondence, and the results of any analysis conducted in accordance with the obligations stipulated in these Instructions, such that they include original documents or copies thereof acceptable to courts according to the legislations in force in the Kingdom, for a period of at least five years from the date of transaction completion or relationship termination according to the actual situation, including the date of termination of the occasional transaction.

Thirdly: The Bank must develop an integrated information system for retaining the records, documents, and information referred to in Items (Firstly) and (Secondly) of this Article, enabling it to respond to requests from the Unit and competent official authorities for any data or information in an integrated and rapid manner within the specified period, and that transaction records are sufficient to allow for the reconstruction of individual transactions.

Article (12): Notification of Transactions Suspected to be Related to Money Laundering or Terrorist Financing:

Firstly: If there is suspicion among any Bank employee that the transaction to be executed is a transaction suspected to be related to money laundering or terrorist financing, they must immediately inform the Reporting Officer.

Secondly: Duties of the Reporting Officer:

  1. The Reporting Officer must immediately inform the Unit about all transactions suspected (or for which there are reasonable grounds for suspicion) of being related to money laundering or terrorist financing, whether these transactions were executed or not, and regardless of the value of this transaction, using the means or form approved by the Unit.

  2. In case the suspected customer requests closing their account(s), do not allow the customer to withdraw amounts in cash, but use one of the other payment methods that allows tracking the movements "Audit Trail" and inform the Unit of this immediately.

  3. The Reporting Officer is responsible for providing the Unit and competent authorities with data related to transactions suspected to be related to money laundering or terrorist financing and any other information or data requested from them according to the means approved by these authorities, and facilitating their access to records and information related to carrying out their duties.

  4. No employee is permitted to disclose, directly or indirectly, or by any means whatsoever, the notification to the Unit or any of the notification procedures taken regarding transactions suspected to be related to money laundering or terrorist financing or any of the information related to them.

  5. No one who becomes aware or learns, directly or indirectly, or by virtue of their position or work, is permitted to disclose any information provided or exchanged in accordance with the provisions of the Law and regulations and instructions issued pursuant thereto, including these Instructions.

  6. The Bank must prepare special files for transactions suspected to be related to money laundering or terrorist financing, in which copies of notifications about these transactions and the data and documents related to them are kept, and these files must be retained for a period of not less than five years from the date of notification or until a final judicial ruling is issued regarding these transactions, whichever is longer.

Article (13): Internal Regulations: The Bank must establish a suitable internal system comprising internal policies, controls, and sufficient and effective procedures based on the Bank's understanding of money laundering and terrorist financing risks. This system must include the following:

First: A clear policy for combating money laundering and terrorist financing, approved by the Board of Directors or the Regional Manager of branches of foreign banks, and continuously updated, such that this policy includes as a minimum the requirements set forth in these instructions.

Second: Detailed written procedures for combating money laundering and terrorist financing, taking into account the precise identification of duties and responsibilities in accordance with the approved policy and instructions issued by the Central Bank on this matter.

Third: The allocation of an independent and qualified staff within the Internal Audit Department, equipped with sufficient resources to test compliance with policies, internal controls, and procedures for combating money laundering and terrorist financing.

Fourth: A suitable mechanism to verify compliance with the instructions, policies, and procedures established for combating money laundering and terrorist financing by both the audit staff mentioned in Item (Third) of this Article and the Compliance Officer, taking into account coordination in the field of determining authorities and responsibilities between them.

Fifth: Establishing systems and procedures that ensure that internal audit bodies perform their role of examining internal control systems to ensure their effectiveness in combating money laundering and terrorist financing, with the necessity of reviewing them periodically to complete any deficiencies, update them, and develop them to increase their efficiency and effectiveness.

Sixth: Determining the name of the Reporting Manager and the name of his deputy, and notifying the Unit and the Central Bank in the event of a change in either of them, provided that each of them possesses appropriate qualifications and obtains the Central Bank's non-objection to their appointment or termination of services.

Seventh: Determining the authorities of the Reporting Manager, which must include at least the following:

  1. Receiving information and reports on unusual operations or those suspected of being related to money laundering or terrorist financing, examining them, and making the appropriate decision regarding immediate notification to the Unit or archiving them, provided that the decision to archive is justified, and that the necessary documents regarding archived reports are kept for a period of not less than five years.
  2. Preparing periodic statistical reports presented to the Board of Directors regarding operations suspected of being related to money laundering or terrorist financing.

Eighth: Determining the authorities of the Reporting Manager, which must include at least what enables him to exercise his authorities independently and in a manner that ensures the confidentiality of the information received by him and the procedures he undertakes, and for this purpose, he must have access to the records and data necessary for the performance of his duties.

Ninth: Training and Qualification:

  1. The Bank must establish continuous training plans and programs in the field of combating money laundering and terrorist financing for Bank employees, such that these programs include methods of money laundering and terrorist financing, how to detect them and report them, and how to

More like this from CBJ

We email you every new CBJ publication the day it's published.

Topics
Share