2018-07-05
Added · Updated
The Central Bank of Jordan issues Instructions No. (2018/70) and their amendments, which establish comprehensive anti-money laundering and counter-terrorist financing obligations for licensed money exchange companies operating in Jordan. The document mandates rigorous risk assessment methodologies, enhanced due diligence for high-risk clients including Politically Exposed Persons, and strict customer identification and verification procedures. It also regulates the reliance on third parties for due diligence and requires annual reporting of risk assessments to the regulator.
In the name of Allah, the Most Gracious, the Most Merciful
[Central Bank of Jordan Logo]
Reference No.: 17/3/9/8974 Date: 21/10/1439 AH Corresponding to: 5/7/2018 AD
Circular to Licensed Money Exchange Companies
Subject: Anti-Money Laundering and Counter-Terrorist Financing Instructions for Money Exchange Companies
Greetings,
With reference to the Anti-Money Laundering and Counter-Terrorist Financing Instructions for Money Exchange Companies No. (2018/70) communicated to you via our Circular No. (17/3/9/932) dated 17/1/2018, we hereby attach the Anti-Money Laundering and Counter-Terrorist Financing Instructions for Money Exchange Companies No. (2018/70) and their amendments, which replace the aforementioned instructions. We emphasize the necessity to comply with them and take the necessary measures to implement their provisions in due course.
Please accept our highest regards,
[Signature] Dr. Ziad Frieh
P.O. Box 37, Amman 11118 - Jordan Tel: 4630301/9 * Fax: 4638889, 4639730 Website: www.cbj.gov.jo Email: info@cbj.gov.jo
[Central Bank of Jordan Logo]
Reference No.: 17/3/9/8974 Date: 21/10/1439 AH Corresponding to: 05/07/2018 AD
Anti-Money Laundering and Counter-Terrorist Financing Instructions for Money Exchange Companies No. (2018/70) and Amendments Issued pursuant to the provisions of Articles (4/A/1) and (18/B) of the Anti-Money Laundering and Counter-Terrorist Financing Law No. (46) of 2007, as amended, and Article (17/A) of the Money Exchange Business Law No. (44) of 2015
Article (1): Definitions: A- The definitions contained in the Anti-Money Laundering and Counter-Terrorist Financing Law and the Money Exchange Business Law, in force, shall apply wherever mentioned in these Instructions, unless the context indicates otherwise. B- The following words and expressions shall have the meanings assigned to them below wherever they appear in these Instructions, unless the context indicates otherwise:
The Law: The Anti-Money Laundering and Counter-Terrorist Financing Law in force. Banking Relationship: The relationship arising between the Company and the Client concerning the financial transactions and services executed by the Company for its clients. Ongoing Relationship: A banking relationship that is expected to extend for an indefinite period upon its establishment and to include multiple transactions. Beneficial Owner: The natural person who is the true beneficiary, for whose benefit or on whose behalf the business relationship is conducted, or who exercises full or effective control over a legal person or legal arrangement, or has the right to carry out legal transactions on behalf of either. Beneficiary: The natural or legal person or legal arrangement designated by the remitter as the recipient of the required financial transfer.
Client: Any natural or legal person or legal arrangement that receives or deals in any of the banking services with the Company. Any person who has started to receive or deal in any of those services is also considered a client. Remittance: Any financial transfer process carried out by the Company using any means to any other party, regardless of whether the remitter is the same person as the payee. Electronic Remittance: Any transfer process carried out by the Company using electronic money transfer means on behalf of the remitter, whereby the funds are sent to another company or bank so that the payee can receive them, regardless of whether the remitter is the same person as the payee. Consolidated Transfer: A transfer consisting of a number of individual financial transfers sent to the same financial institutions, but which may or may not be ultimately directed to different persons. Control: The direct or indirect ability to exercise effective influence on the actions and decisions of another person. Foreign Politically Exposed Persons (PEPs): Persons who hold or have held prominent public functions in a foreign country, such as Head of State, Head of Government, judge, military officer, or high-ranking government official, or prominent politician in a political party, or executive in state-owned companies. This includes their family members up to the first degree as a minimum, or persons close to them, or any persons acting on their behalf or holding authorization issued by them. Domestic Politically Exposed Persons (PEPs): Persons who hold or have held prominent public functions in the Kingdom, such as Heads of Government, high-ranking government officials, prominent politicians, judges, military officers, or prominent figures in a political party, or executives in state-owned companies. This includes their family members up to the first degree as a minimum, or persons close to them, or any persons acting on their behalf or holding authorization issued by them.
Persons entrusted with prominent functions by an international organization: They are senior management members, i.e., Directors, Deputy Directors, Board members, or positions equivalent to them in an international organization. Trusts: Legal relationships arising - inter vivos or upon death - by a person or trustee, where assets have been placed under the control of the person or trustee for the benefit of a beneficiary or for a specific purpose, such that the assets are independent and not part of the trustee's estate, and the right to the trustee's assets remains in the name of the settlor or in the name of another person on behalf of the settlor. Legal Arrangement: Direct trusts or similar legal arrangements. Non-Profit Entity: Any legal person or legal arrangement established in accordance with relevant laws, primarily engaged in collecting or spending funds for charitable, religious, cultural, educational, social, fraternal, or other "good works" purposes, without its activity targeting profit generation, distribution, or personal benefit, including foreign branches of international non-profit organizations and entities. Shell Bank: A bank that meets the following criteria:
Non-Resident: A natural or legal person who usually resides or has their headquarters outside the Kingdom, or who has not completed one year of residence within the Kingdom, regardless of this person's nationality, except for individuals who have permanent economic activity or permanent residence within the Kingdom, even if they reside there intermittently. Financial Group: A group consisting of a parent company or any other type of natural or legal persons who hold controlling shares and coordinate functions with the rest of the group to apply or implement supervision over the group in accordance with the fundamental principles, along with branches and/or subsidiaries subject to anti-money laundering and counter-terrorist financing policies and procedures at the group level. Third Party: Financial institutions and non-financial businesses and professions subject to supervision or regulation and governed by the Anti-Money Laundering and Counter-Terrorist Financing Law. Unique Reference Number: Refers to a combination of letters, numbers, and symbols, determined by the Company for each transfer according to the transfer system used, allowing for tracking. Unit: The Anti-Money Laundering and Counter-Terrorist Financing Unit formed in accordance with the provisions of the Anti-Money Laundering and Counter-Terrorist Financing Law in force. Subsidiary Company: A company in which a person or a group of persons united by a common interest owns no less than (50%) of its capital, or in which this person or these persons hold an influential interest allowing control over its management or general policy.
Article (2): The provisions of these Instructions shall apply to: First: Companies and their branches operating within the Kingdom licensed by the Central Bank of Jordan. Second: Branches of companies operating abroad and subsidiary companies to the extent permitted by the laws and regulations in force in the countries where they operate, while observing the application of the strictest standards possible in case of differences between anti-money laundering and counter-terrorist financing requirements in the host country and the home country. The Company must apply appropriate additional procedures to manage money laundering and terrorist financing risks and notify the Central Bank of Jordan of any obstacles or restrictions that may limit or prevent the application of the provisions of these Instructions.
Article (3): First: The Company must take appropriate steps to identify, assess, and understand its money laundering and terrorist financing risks, including customer risks, geographic risks (countries or regions), products, services, operations, and service delivery channels, and take all measures that reduce those risks and monitor and control them effectively. This requires the following: A- Establishing policies, controls, and procedures and adopting the necessary bases for identifying, assessing, monitoring, and verifying the level of money laundering and terrorist financing risks, approved by senior management/authorized signatories of the Company, enabling them to manage identified risks, supervise the application of these controls, and enhance them. B- Providing internal control and monitoring systems capable of managing risks. C- Examining the effectiveness of the internal control and monitoring systems established to manage identified risks.
Second: Documenting risk assessment processes.
Third: Taking into account all relevant risk factors before determining the overall risk level and the appropriate level of risk mitigation procedures to be applied. The classification of those risks must be reviewed and updated at least every two years or in case of changes necessitating it, and the last update must be documented.
Fourth: Providing appropriate mechanisms to supply identified risks to competent authorities upon request.
Fifth: The Company must conduct a comprehensive assessment of money laundering and terrorist financing risks at least annually, or whenever a need arises to conduct this assessment due to a fundamental change in the nature of risks faced by the Company, according to a methodology approved by the Company's management. Assessment processes must be documented, and the assessment must include at least the following:
Sixth: The Company must update and assess money laundering and terrorist financing risks that may arise regarding products within new business lines, including new service delivery means, and those arising from the use of new technologies within new or developing business lines regarding both new and existing products, and take appropriate measures to manage and mitigate those risks, and inform the Central Bank of the results.
Article (4): Due Diligence Requirements: First: The Company is prohibited from dealing with anonymous accounts, fictitious name accounts, or digital accounts, including dealing or entering into banking relationships with persons of unknown identity, fictitious or pseudonymous names, or with Shell Companies or Shell Banks.
Second: Customer due diligence procedures to be adopted by the Company include the following: A. Identifying the Client's identity, legal status, and activities, and verifying them through original documents, data, or information from reliable and independent sources. B. Verifying whether any person claiming to act on behalf of the Client is actually authorized to do so, identifying their identity, and verifying it. C. Identifying the Beneficial Owner's identity and taking reasonable measures to verify this identity, including relying on data or information obtained from official documents and data, such that the Company is convinced it is aware of the Beneficial Owner's identity. D. Understanding the purpose and nature of the business relationship and obtaining information regarding this, as appropriate. E. Exercising ongoing due diligence regarding business relationships, scrutinizing transactions carried out during the duration of this relationship, to ensure that transactions carried out are consistent with what the Company knows about its Client, their activity, and risk profile, and comparing them with peers in the same activity or those falling within the same risk degree, and recording and retaining all data related thereto in accordance with the provisions of these Instructions, including knowing the source of funds as appropriate.
F. Ensuring that documents, data, or information obtained under due diligence procedures are up-to-date and appropriate, particularly for high-risk customer categories.
Third: Cases requiring due diligence: A. The Company must exercise due diligence regarding Customers, especially in the following circumstances:
B. The Company must apply all due diligence measures regarding Customers stipulated in Clause (Second) above of this Article, defining the scope of those measures using the risk-based approach referred to in Article (3) of these Instructions.
Fourth: The Company must exercise due diligence regarding existing Customers based on relative importance and risk, and take necessary due diligence measures regarding its current relationships with them in the cases stated below, and the Company must be aware of whether due diligence measures were previously taken, when they were taken, and the sufficiency of the data obtained: A. When executing transactions in large amounts or in an unusual manner. B. When a fundamental change occurs in the mechanism of documenting information about the Client. C. When the Company realizes it does not have sufficient information about one of these Clients.
Fifth: The Company must verify the identity of the Client and the Beneficial Owner before or during the establishment of an ongoing business relationship or executing transactions for occasional Clients from reliable and neutral sources, taking into account the following: A. Verification procedures for the Client's and Beneficial Owner's identity may be postponed until after the establishment of the ongoing business relationship as follows:
Sixth: In case the Company is unable to complete due diligence procedures regarding Customers, and is unable to obtain the necessary information, it must not enter into any banking relationship with the Client or execute any transactions on their behalf, and notify the Unit in case of a transaction suspected to be related to money laundering or terrorist financing according to the approved form or means for this purpose.
Seventh: In case the Company suspects money laundering or terrorist financing and reasonably believes that completing due diligence will alert the Client, the Company is allowed not to complete this process, provided it notifies the Unit immediately of the transaction suspected to be related to money laundering or terrorist financing according to the approved form or means for this purpose.
Eighth: Reliance on Third Parties: A. The Company may rely on third parties to implement the elements contained in Clause (Second) above of this Article, provided the criteria listed below are met, with the ultimate responsibility for customer due diligence measures remaining with the Company relying on the third party:
B. The Company may also rely on third parties that are part of the same Financial Group to implement the elements contained in Clause (Second) above of this Article, provided the criteria in paragraphs (1) to (4) of Clause (Eighth/A) of this Article are met, in addition to the following criteria, with the ultimate responsibility for customer due diligence measures remaining with the Company relying on the third party:
Article (5): Customer Identification and Verification Procedures: First: The Company must establish systems to identify the Client's identity and verify it in accordance with the requirements imposed on it in Article (4) above. Second: The Company must review original official documents to identify the Client's identity or certified copies thereof, and verify them, obtaining a copy of these documents signed by the relevant employee indicating that it is a true copy. Third: The following shall be considered in the identification procedures for natural persons: A. Identification data for the Client must include their full name, date and place of birth, nationality, nature of work, permanent residence address, phone numbers, purpose and nature of the business relationship, national ID number, and all information related to the identity document for Jordanians, personal number for foreigners, passport number for non-Jordanians, and the annual residence permit issued by the Ministry of Interior or a valid work permit issued by the competent authority in case the Client is foreign labor, and any other information the Company deems necessary to complete the Client identification process.
B. For persons with partial or no legal capacity, such as minors, documents related to them and their legal representatives in the banking relationship must be obtained in accordance with the provisions of Clause (A) of Clause (Third) of this Article. C. In case a person deals with the Company as an agent for the Client, it must be ensured that a valid judicial power of attorney exists, with the power of attorney or a certified copy retained, in addition to identifying the agent's identity according to the customer identification procedures stipulated in Clause (Second) of this Article.
Fourth: The following shall be considered in the identification procedures for legal persons or legal arrangements: A. Identification data must include the name of the legal person or legal arrangement, legal form, names and addresses of owners, ownership shares, authorized signatories, headquarters address, nature of work and type of activity practiced, amount of capital, registration date and number, tax number, national establishment number, names of authorized signatories and their nationalities, their phone numbers, purpose and nature of the business relationship, and names of persons holding senior management positions in the legal person or legal arrangement, and any other information the Company deems necessary to obtain for completing identification and keeping it up-to-date. B. It is necessary to obtain official documents or certified copies thereof proving the establishment and registration of the legal person or legal arrangement with competent authorities, such as the memorandum of association, articles of association, certificates issued by the Ministry of Industry, Trade and Supply, Ministry of Social Development, Companies Control Department, and certificates issued by Chambers of Commerce and Industry, and they must be recent. In addition, it is necessary to obtain an official certificate issued by competent authorities in case the legal person or legal arrangement is registered abroad. C. Obtaining documents indicating authorization from the legal person or legal arrangement for the natural persons representing them, the purpose and nature of the business relationship, identifying the identity of the authorized natural person and the Beneficial Owner, if any, according to customer identification procedures stipulated in these Instructions, verifying the absence of legal obstacles preventing dealing with them, and obtaining samples of their signatures. D. Obtaining information about the provisions regulating the work of the legal person or legal arrangement, including the structure and controlling management, and provisions regulating the authority to make binding decisions for the legal person. Public joint stock companies are exempt from requesting data related to owner names and ownership shares less than (10%) of the company's capital.
E. In case dealing with Non-Profit Entities, whether registered inside or outside the Kingdom, a letter from the relevant competent authorities in the Kingdom must be obtained indicating the registration of those entities.
Fifth: The Company must take necessary measures to verify the accuracy of data and information obtained from Clients through reliable and independent sources, such as contacting the competent authorities issuing official documents for this data, referring to the Companies Control Department website, Ministry of Industry and Supply websites, and electronic websites of document and certificate issuing authorities.
Sixth: Verifying whether the person is acting as an agent for a Client or Beneficial Owner and taking reasonable steps to obtain sufficient data to verify that person's identity, such that the Company is convinced it is aware of the Client's or Beneficial Owner's identity.
Seventh: The Company must obtain a written declaration from the Client identifying the Beneficial Owner of the transaction to be executed, such that the Beneficial Owner's identification information includes at least the following: A. If the Client is a legal person:
B. If the Client is a legal arrangement:
Article (6): The Company must exercise enhanced due diligence commensurate with the risk level in identifying the Client and their activity, by conducting necessary analysis and studies to verify the sources of funds and wealth for Clients and Beneficial Owners, and taking necessary measures to ascertain the background circumstances surrounding any business relationships and transactions contrary to their purposes, and any other necessary measures to verify the nature of the transaction, in addition to the due diligence requirements mentioned in Article (4) of these Instructions, in the following cases:
First: Banking transactions carried out with persons belonging to or present in countries that do not have appropriate systems for combating money laundering and terrorist financing, or with legal persons belonging to or present in high-risk countries that the Financial Action Task Force (FATF) concerned with setting anti-money laundering and counter-terrorist financing standards calls for taking action against.
Second: Banking transactions carried out with Foreign Politically Exposed Persons, and enhanced due diligence must include the following: A. Establishing appropriate risk management systems to determine whether the Client or Beneficial Owner is a Politically Exposed Person. B. Obtaining approval from the Company's senior management before establishing any business relationship with these persons or continuing it for existing Clients. C. Taking reasonable measures to know the source of wealth or funds for Clients and Beneficial Owners identified as Politically Exposed Persons. D. Conducting enhanced follow-up of the business relationship.
Third: Banking transactions conducted with politically exposed persons, local risk representatives, or persons entrusted with or having entrusted prominent functions by an international organization, and that must include the following enhanced due diligence:
A. Taking adequate measures to determine whether the customer or the beneficial owner is one of these persons.
B. In the event of a high-risk business relationship with these persons, the company must apply the following procedures:
Fourth: Unusually large or complex transactions, or any transaction that the company, in its discretion, considers to pose a high risk for money laundering and terrorist financing. Unusual transactions are considered to include the following:
A. Cash transactions exceeding a value of (20,000) Jordanian Dinars or their equivalent in foreign currencies. Cash transactions below this threshold that evidence indicates are interrelated are considered as a single cash transaction.
B. Any other transaction with an unusual pattern that has no clear economic or legal justification or does not match the customer's profile.
Fifth: Banking transactions conducted with non-resident customers.
Sixth: Banking transactions that are not conducted face-to-face, particularly dealings using modern technological technologies such as the internet or using electronic payment means. In these cases, the company must put in place the necessary policies and procedures, conduct a risk assessment before practicing or using them, and take appropriate measures to manage and mitigate those risks.
Article (7): Financial Group and Foreign Branches:
If the company is part of a financial group, the group should be required to apply anti-money laundering and counter-terrorist financing programs at the group level, which should apply, as appropriate, to all branches and subsidiaries in which the group holds a majority stake. These programs should include the following measures:
First: Preparing appropriate policies, procedures, internal controls, and arrangements regarding the following: A. Compliance management (including appointing a compliance officer at the management level). B. Appropriate vetting procedures to ensure high standards are maintained when appointing employees.
Second: Establishing a continuous employee training program.
Third: Creating an independent audit unit to test the system.
Fourth: Establishing policies and procedures for exchanging required information for customer due diligence and managing money laundering and terrorist financing risks.
Fifth: Providing information related to customers and transactions from branches and subsidiaries to compliance, audit, and/or anti-money laundering and counter-terrorist financing functions at the group level, when necessary for anti-money laundering and counter-terrorist financing purposes.
Sixth: Providing sufficient guarantees regarding confidentiality and the use of exchanged information.
Article (8): First: The Central Bank of Jordan may decide, by orders issued for this purpose, the cases in which the company may follow simplified due diligence procedures because they pose low risks regarding money laundering and terrorist financing.
Second: In all cases, simplified due diligence procedures must not be followed for transfers carried out by non-electronic means, or in the event of suspicion of money laundering or terrorist financing, or in the presence of circumstances involving high risks.
Article (9): Remittances:
First: The provisions of this article apply to all incoming and outgoing remittances, including electronic remittances, regardless of their value, which the company subject to these instructions sends or receives.
Second: The company must appoint employees responsible for implementing and following up on remittances, who possess a high degree of competence, professionalism, and sufficient experience in this field, while ensuring they have completed specialized courses and training programs on topics related to combating money laundering and terrorist financing.
Third: Obligations of the Remittance Issuing Company:
A. The company must, upon issuing a remittance, obtain complete information from the remittance requester, including: the full name of the remittance requester, nationality, purpose of the transfer, full name of the beneficiary, the relationship between the remittance requester and the beneficiary, the address of each, and a declaration from the remittance requester that they are the true originator. It must also include the national ID number and personal ID document number for Jordanians, the personal number for foreigners, and the passport number for non-Jordanians, or the number of any document approved by the competent authorities for this purpose. The company must verify the accuracy of this information and take the due diligence measures stipulated in Article (4) of these instructions.
B. Providing and using a system by which remittances are numbered with a unique reference number to facilitate reference to and tracking of the remittance when needed.
C. Providing the receiving entity and competent official authorities with complete information about issued or received remittances within a maximum of three working days from the date of receiving the request for such information.
D. Responding immediately to any order issued by competent official authorities requiring the company to provide them with this information.
E. If the company sends remittances on behalf of its customers through a licensed bank, it must provide the bank with the information and documents related to the due diligence procedures for the remittance requester.
F. If the company is unable to meet the requirements stipulated in Item (Third) of this article, the company must not execute/issue the remittance.
Fourth: Obligations of the Intermediary Company:
If the company participates as an intermediary in executing the remittance without being the issuer or recipient, it must do the following:
A. Ensure that all information attached to the remittance regarding the source of the remittance and the beneficiary remains with it during the transfer.
B. If the company, as an intermediary, is unable to keep the information attached to the remittance for technical reasons, it must retain all information attached as it received it from the remittance-sending company or another company for five years, regardless of the completeness or incompleteness of this information, enabling it to provide the available information to the licensed bank or the receiving company within a maximum of three working days from the date of the request.
C. Taking reasonable measures, consistent with the automated processing of transfers, to identify international remittances that lack the required information about the requester or the beneficiary.
D. Adopting effective policies and procedures regarding incoming remittances where information about the remittance requester is incomplete, as referred to in paragraph (A) of Item (Third) of this article, based on risk assessment in dealing with such remittances. This includes requesting the missing information from the licensed bank or the remittance-sending company, suspending the remittance, or rejecting it, in addition to putting in place appropriate follow-up procedures.
E. If receiving incomplete information about the remittance requester, the company must notify the receiving entity of the remittance before executing the transfer.
Fifth: Obligations of the Remittance Receiving Company:
A. If the company receives remittances, it must do the following:
B. The company must, upon delivering the remittance, obtain information about the remittance beneficiary, including: the full name of the remittance beneficiary, nationality, permanent place of residence, the relationship between the remittance requester and the beneficiary, a declaration from the remittance beneficiary regarding the true beneficiary, in addition to taking the due diligence measures stipulated in Article (4) of these instructions.
C. If the company receives remittances on behalf of its customers through a licensed bank, it must provide the bank with the information and documents related to the due diligence procedures for the remittance beneficiary.
D. Regarding non-profit entities, ensuring they have obtained the necessary approvals for the receipt of funds in accordance with the prevailing laws in the Kingdom regulating financial transactions for these entities.
Sixth: The company must observe the following when dealing with electronic remittances:
A. Not executing electronic remittances where the name of the requester or the beneficiary is incomplete, abbreviated, or does not match identity proof documents.
B. Comparing the names and fields contained within electronic remittance messages, whether transmitted through any messaging system, with the sanctions lists referred to in Article (15) of these instructions or any other sanctions lists issued by special instructions from the Central Bank of Jordan.
C. Not modifying, canceling, or changing any information in electronic remittance issuance requests or in the messages of these remittances, or using any type or form of remittance for the purpose of evading or avoiding identifying any information that would cause the receiving company or the intermediary company to reject, hold, or report the remittance as a suspicious financial transaction.
Seventh: Regarding Consolidated Remittances:
A. The company issuing these remittances must attach the unique reference number of the remittance requester in a manner that allows for full tracking in the beneficiary country, subject to the following:
B. For remittances received as consolidated remittances, the receiving company must adopt a unique reference number for the remittance beneficiary in a manner that allows for full tracking, subject to the following:
Article (10): The company must do the following:
First: Providing a suitable internal control and monitoring system based on risk and volume of work, which includes the following:
A. A clear policy for combating money laundering and terrorist financing, continuously updated, including detailed work procedures for controlling and preventing transactions suspected of being related to money laundering or terrorist financing and reporting them. This policy must carefully define duties and responsibilities in accordance with the provisions of prevailing legislation, and must include measures to prevent the exploitation of modern technology for money laundering and terrorist financing.
B. Arrangements taken by senior management to ensure compliance with prevailing laws and legislation.
C. The company must adopt policies, procedures, and controls to ensure the highest standards when appointing employees, to verify the suitability of senior management, reporting officers, and other employees involved in combating money laundering and terrorist financing. It must be ensured that those appointed have not previously been convicted of any crime involving moral turpitude or public trust, or sentenced for money laundering or terrorist financing.
D. Developing continuous training plans and programs for employees in the field of combating money laundering and terrorist financing, including the following matters, while keeping records of all training programs conducted for a period of no less than five years, including the names and qualifications of trainees and the entity that conducted the training, whether within or outside the Kingdom:
Second: Providing written procedures for due diligence and enhanced due diligence regarding customers as stipulated in the law and Articles (4, 5, 6) of these instructions.
Third: Providing an automated system within the company that allows for monitoring financial transactions, tracking them, and issuing warning reports to be studied and analyzed by compliance specialists, while ensuring the efficiency of the system by an independent entity.
Fourth: Providing written procedures to meet the requirements of retaining records and documents related to customer due diligence and supporting evidence for local or international financial transactions.
Fifth: Allocating an independent and qualified cadre within the internal audit department and equipped with sufficient resources to test compliance with policies, internal controls, and procedures to combat money laundering and terrorist financing.
Sixth: Establishing policies that ensure the internal audit department independently evaluates internal control systems to ensure their effectiveness in combating money laundering and terrorist financing, and recommending to senior management/authorized signatories to sign whenever necessary to review them to complete any deficiencies, update them, and develop them to increase their efficiency and effectiveness.
Seventh: Auditing and examining complex transactions and transactions that have no clear economic or legal purpose, documenting the results reached in writing, and retaining them for at least five years, making them available to the Unit and competent authorities upon request.
Eighth: Continuous auditing of transactions conducted throughout the duration of the relationship to ensure consistency of transactions performed with what the company knows about customers, their activity patterns, and the risks they represent.
Ninth: The company, when dealing with foreign financial institutions, must do the following:
A. Obtaining approval from senior management/authorized signatories when establishing a relationship with these institutions.
B. Verifying the existence of sufficient instructions and controls issued by regulatory authorities regarding combating money laundering and terrorist financing governing the work of the foreign financial institutions intended to be dealt with, their reputation in combating money laundering and terrorist financing through publicly available information, and whether they have been subject to investigation regarding money laundering or terrorist financing or regulatory action by regulatory authorities.
C. Verifying the existence of policies, systems, procedures, and controls related to combating money laundering and terrorist financing within the foreign financial institution intended to be dealt with, and evaluating them, so that the company is convinced that the foreign institution does not allow its accounts to be used by shell banks, and that the relationship with the foreign financial institution is built on each party's clear understanding of its responsibilities in combating money laundering and terrorist financing.
D. The company must not enter into or continue a banking relationship if it is found that the foreign financial institution has dealings with shell banks.
Article (11): Retention of Records and Documents:
The company must do the following:
First: Retaining records and documents for any local or external financial transactions it conducts, including sufficient data to identify these transactions, and retaining these records and documents, including the results of any analysis conducted and records related to customer due diligence stipulated in Articles (4, 5) of these instructions, for a period of five years from the date of completing the transaction or terminating the banking relationship, as appropriate.
Second: Retaining records and supporting evidence for banking relationships, account files, and commercial correspondence stipulated in Articles (4, 5, 6, 9) of these instructions, in accordance with the laws governing this field, including original documents or copies acceptable in courts according to prevailing legislation in the Kingdom and instructions issued by the Unit for this purpose, for a period of at least five years from the date of completing the transaction or terminating the banking relationship, as appropriate.
Third: Developing an integrated system for preserving the records and documents referred to in Items (First and Second) above, enabling it to refer to any reports and/or documents upon request, to facilitate responding to requests from the Unit and competent official authorities for any data or information, and facilitating their access in an integrated and rapid manner within the specified period. Transaction records must be sufficient to allow reconstructing individual transactions as evidence for prosecution against criminal activity.
Fourth: Taking necessary measures to ensure the readiness of the system referred to in Item (Third) above to meet requirements related to providing any data or statistical information that could measure money laundering and terrorist financing risks according to models approved by the Central Bank of Jordan for this purpose.
Article (12): Reporting on Transactions Suspected of Being Related to Money Laundering or Terrorist Financing:
First: The company must do the following:
A. Appointing a compliance officer with appropriate academic qualifications, practical experience, and specialized training courses, and obtaining approval from the Central Bank of Jordan for his appointment.
B. Determining the name of the person who will replace the compliance officer in his absence, notifying the Unit and the Central Bank in case of any change, and ensuring that the replacement possesses the same conditions and qualifications as the compliance officer.
C. Establishing a suitable mechanism to verify compliance with the instructions, policies, and procedures established for combating money laundering and terrorist financing by the compliance officer referred to above, while coordinating in the field of determining authorities and responsibilities in combating money laundering and terrorist financing.
D. Preparing special files for transactions suspected of being related to money laundering and terrorist financing, in which copies of reports on these transactions and the data and documents related to them are kept. These files must be retained for a period of no less than five years from the date of reporting or until a final judicial ruling is issued regarding these transactions, whichever is longer.
E. Not affecting the independence of the compliance officer in any way during the execution of his duties.
F. If any employee of the company suspects that any banking transaction is related to money laundering or terrorist financing, they must report it to the compliance officer.
Second: The compliance officer must study the reports received and any suspicious cases that become apparent to him during the performance of his duties, and immediately report to the Unit any transactions suspected of being related to money laundering or terrorist financing, whether these transactions were executed or not, and regardless of the transaction amount, according to the method and form approved by the Unit for this purpose. He must cooperate with the Unit and provide it with data and facilitate its access to records and information for the purpose of performing its duties within the period specified by it.
Article (13): A. It is prohibited to disclose, directly or indirectly, or by any means whatsoever, the reporting to the Unit or any of the reporting procedures taken regarding transactions suspected of being related to money laundering or terrorist financing, or any of the information related to them.
B. It is prohibited for anyone who becomes aware or learns, directly or indirectly, or by virtue of their position or work, to disclose any information provided or exchanged in accordance with the provisions of the Law and the systems and instructions issued pursuant to it, including these instructions.
Article (14): The company must include in the contract concluded with the external auditor a clause stating his commitment to ensure that the company applies the provisions of the Law, the prevailing Exchange Business Law, these instructions, and the decisions issued pursuant to them, and to evaluate the adequacy of the company's policies and procedures related to combating money laundering and terrorist financing, and include this in his report. It is also necessary to notify the Central Bank immediately upon discovering any violation of these instructions.
Article (15): Without prejudice to the provisions of instructions issued based on the provisions of the Law, the company must implement the obligations contained in relevant international decisions that are enforceable, including all decisions issued under Chapter VII of the UN Charter, which are notified to it by the Central Bank or the competent authorities for this purpose.
Article (16): Without prejudice to any heavier penalty stipulated elsewhere, the company violating the provisions of these instructions shall be punished with the penalties stipulated in the Law and the prevailing Exchange Business Law.
Article (17): Final Provisions:
A. The instructions for combating money laundering and terrorist financing for exchange companies No. (2010/2) dated 2010/12/30 are repealed.
B. These instructions shall come into effect from their date.
[Signature] Dr. Ziad Freis