2025-04-04
Added · Updated
Circular No. 129 mandates financial institutions in Haiti to implement preventive programs against money laundering, terrorism financing, and proliferation financing. It requires the establishment of internal controls, risk assessments, compliance officers, and continuous training. Institutions must apply enhanced due diligence for transactions exceeding 1,320,000 HTG or involving electronic transfers, and must identify clients and beneficial owners for transactions of 132,000 HTG or more. Suspicious transactions must be reported to the Financial Intelligence Unit (UCREF).
Bank of the Republic of Haiti CIRCULAR No. 129
TO FINANCIAL INSTITUTIONS
This circular establishes the preventive measures that financial institutions must take to combat money laundering, terrorism financing, and the financing of the proliferation of weapons of mass destruction, hereinafter referred to as "proliferation". It applies to:
a) banks; b) development finance companies; c) leasing companies; d) credit card companies; e) savings and credit cooperatives; f) microfinance institutions; g) investment promotion companies; h) money transfer houses; i) exchange bureaus; j) electronic payment service providers; and k) any other entity designated by the Bank of the Republic of Haiti (BRH).
Financial institutions must put in place a prevention program against money laundering, terrorism financing, and proliferation, in accordance with Article 31 of the Decree of April 30, 2023 sanctioning money laundering, terrorism financing, and the financing of the proliferation of weapons of mass destruction.
The said program must reflect the nature, scope, and complexity of the financial institution's activities and include the following elements:
1
The prevention program must be approved by the board of directors of the financial institution or by the foreign correspondent if the financial institution is an agent representing fund transfer activities.
Financial institutions are required to develop a prevention program comprising written policies, procedures, and methods that allow for the identification of risk factors and the assessment of money laundering, terrorism financing, or proliferation risks presented by their activities.
Policies, procedures, and methods must be approved by the board of directors and kept up to date. They must be clearly communicated to all executives called upon to deal with clients.
Policies and procedures must cover all reporting, document retention, document conservation, client identification, control, assessment, and risk mitigation obligations applicable to the financial institution. They must be integrated into the institution's overall risk management strategy and include appropriate steps to prevent, detect, assess, monitor, manage, and continuously mitigate money laundering and/or terrorism financing risks related to clients, countries or geographic areas, or products, services, new technologies, operations, and distribution channels.
Policies and procedures must also cover the handling of international sanctions (United Nations list or others), the modalities for freezing assets in the context of combating terrorism financing and proliferation.
Policies, procedures, and methods must apply to all branches, agencies, service points, and subsidiaries, if it is a group as defined in Article 13 of the Law of May 14, 2012 on banks and other financial institutions. In this case, financial institutions must adopt policies and procedures for information sharing within the group for the purpose of customer due diligence and money laundering, terrorism financing, and proliferation risk management. Adequate guarantees regarding confidentiality and the use of exchanged information must be put in place. They must ensure the availability of information related to clients, accounts, and
2
operations from their branches and subsidiaries to compliance, audit, and/or money laundering and terrorism fighting functions at the group level. Furthermore, financial institutions must ensure that their foreign subsidiaries, where applicable, and which carry out the same activities as themselves, implement the group's prevention program including group information sharing policies and procedures. If the host country of the subsidiary does not allow the appropriate implementation of money laundering and terrorism fighting measures consistent with national measures, the group must apply additional appropriate measures to manage money laundering and terrorism financing risks and inform the BRH.
Furthermore, money transfer houses acting as agents must ensure that their sub-agents implement their prevention program. The same applies to exchange bureaus regarding any network constituted by exchange sub-agents, where applicable.
Policies and procedures must take into account relationships with correspondent banks and cover issues related to the collection of information on said correspondent banks (nature of their activities, their clientele, control exercised by competent authorities, etc.) as well as the suspension and non-establishment of correspondent relationships with:
a) foreign banks that do not have sufficient control procedures regarding criminal activities, or b) foreign banks that are not subject to effective supervision by competent authorities, or c) shell banks.
Financial institutions are also required to develop appropriate selection procedures ensuring the recruitment of employees according to strict criteria.
Financial institutions must have an IT system allowing the centralization of data on the identity of clients, principals, beneficial owners, agents, proxy holders, and on suspicious transactions.
Any financial institution must proceed with the appointment of a compliance officer. This officer must be a senior executive of the institution, selected based on competence, experience, integrity, and professional ethics. He must know the functions and structure of the institution, and be aware of the risks and vulnerabilities related to money laundering and terrorism financing in his sector of activity as well as the trends and typologies that characterize these threats. He must report directly to the board of directors for all matters related to combating money laundering, terrorism financing, and proliferation.
3
The compliance officer has among his duties: a) to ensure the application of legislation and regulation; b) to enforce internal procedures and methods for combating money laundering, terrorism financing, and proliferation; c) to identify deficiencies and make necessary recommendations; d) to propose training programs on a periodic basis; e) to ensure liaison with sub-agents (money transfer houses or exchange bureaus); f) to ensure liaison with the Central Financial Intelligence Unit (UCREF); g) to prepare and forward suspicious transaction reports to the UCREF; h) to ensure that transaction reports are completed and forwarded to the UCREF within the required deadlines; i) to receive and follow up on information requests from the UCREF and any other authority acting in the context of combating money laundering, terrorism financing, and proliferation.
Financial institutions must designate, in each branch, agency, or service point, an executive responsible for enforcing anti-money laundering laws and regulations and ensuring coordination with the compliance officer. To ensure the application of the prevention program, the compliance officer may delegate certain functions to other employees. In no case does the designation of these executives relieve the compliance officer of his responsibilities under the law.
The prevention and compliance program must include a component related to the assessment of money laundering and terrorism financing risks.
Risk assessment is an analysis of threats and weaknesses in money laundering and terrorism financing presented by the financial institution's activities. This assessment varies notably according to the size of the financial institution, its geographic location, and the activities carried out. A risk classification must be performed based on services offered, conditions of proposed transactions, distribution channels used, client characteristics, country or territory of origin or destination of funds, and geographic regions of activity.
Risk assessment implies that employees are well versed in the institution's activities and exercise judgment to assess risks. This assessment must not be static and must be modified at least every twelve (12) months.
The prevention program must include a training component. All employees who are in contact with clients, who are aware of operations carried out by clients, or who handle cash or funds in any way, or who are responsible for the implementation or monitoring of the compliance regime must understand, among other things, reporting obligations, client identification, and document retention.
4
All sub-agents belonging to a network of a money transfer house or bank must also understand reporting obligations, client identification, and document retention.
The training program must be documented in writing and kept up to date. The modalities regarding the frequency and method of training must be established. It must indicate, among other things, the categories of participants, the subjects to be covered, and the frequency of training sessions. Each new employee or new sub-agent must be trained before starting to work with clients.
Updates to the program must take place periodically to keep all interested parties informed of legislative and regulatory changes.
The program and continuous training plan must be adapted to the size, structure of the institution, the complexity of its activities, and its level of exposure to money laundering and terrorism financing risks.
Financial institutions must exercise constant vigilance and have an organization and internal procedures designed to ensure compliance with provisions provided by law and allowing operations managers to prevent and identify any attempt at money laundering or terrorism financing. One of the roles of this control is to avoid the use of the financial system for money laundering, terrorism financing, or proliferation financing and to minimize the risks faced by institutions.
This internal control system must contain, among other things: a) a control mechanism for internal policies, procedures, and methods for combating money laundering, terrorism financing, and proliferation; b) a structure guaranteeing the confidentiality of information processing; c) measures to identify elements at risk related to money laundering, terrorism financing, and proliferation, and systems for assessing these risks; d) a surveillance system that can guarantee control of risks related to money laundering, terrorism financing, and proliferation; e) a centralized documentation and information system; f) an information system on initiatives taken in terms of compliance, deficiencies in this area, and corrective measures taken.
The control system in place must extend to all components of the institution. Financial institutions are therefore required to take necessary measures to guarantee the strict application of existing policies, procedures, and methods, especially those related to money laundering, terrorism financing, and proliferation.
5
During periodic independent tests regarding compliance with internal procedures, or good risk monitoring, a specific check on the money laundering, terrorism financing, and proliferation component must be performed by the institution's internal audit.
Checks can notably apply to the following points: a) the assessment of the quality of risk management and control for all operations and in all branches, agencies, and/or service points; b) interviews with employees in charge of operations and their supervisors to assess their level of knowledge and respect for the money laundering, terrorism financing, and proliferation fighting procedures adopted by the institution; c) compliance with account opening and closing procedures; d) the examination of a sample of client profiles, sanction screening, document archiving forms, and forms for reporting suspicious financial transactions; e) a verification of the document retention system; f) the existence of supporting documents attached or referenced to accounting records; g) the knowledge of the clientele by branches and operations managers, taking into account the following elements: professional activity, account functioning, financial situation, and accounting and financial documentation consistent with credits granted and volumes of business processed. Particular attention must be paid to the economic justification of operations and their adequacy with the known situation of the clientele; h) periodic reviews of all correspondent banking relationships established with foreign banks to detect high-risk partners; i) the knowledge by collaborators of internal anti-money laundering rules.
The results of any verification must be submitted to the board of directors. Depending on the institution's hierarchical structure, questions related to measures taken or to be taken and deadlines provided for this purpose must be known and disclosed to executing personnel.
Financial institutions must develop and implement policies regarding the identification and follow-up of unusual or suspicious transactions. These policies must define what is considered suspicious or unusual, and provide examples in this regard.
The identification of unusual or suspicious transactions can be done by monitoring transactions, contacts with the client (meetings, visits, discussions, etc.), information from third parties (newspapers, internet, etc.), the knowledge the financial institution has of the client's environment.
6
For any transaction that appears complex, unusual, unjustified, or without economic justification or lawful object, even when the amount involved does not reach the established threshold, all relevant information regarding the origin of funds, the object of the operation, and the identity of the persons involved in the transaction must be collected and a report must be established by the financial institution. The confidential written report must contain all useful and legally required information regarding the modalities of the operation as well as the identity of the principal, and where applicable, the economic actors involved.
Transaction reports and suspicious transaction reports must be transmitted to the UCREF by electronic communication, or failing that by any written means, in accordance with deadlines established by regulation.
Financial institutions must pay particular attention to customer knowledge standards to preserve their reputation and the integrity of the financial system. To avoid exposure to reputational risk, operational risk, and legal risk, financial institutions must have appropriate policies, methods, and procedures taking into account, among other things, the following elements:
a) clear conditions for accepting new clients; b) precise rules on the identification of permanent or occasional clients and their agents, beneficial owners, principals, and beneficiaries; c) rules regarding occasional high-amount operations; d) constant monitoring of high-risk accounts; e) appropriate procedures and means for risk management and constant monitoring of the clientele; f) clear conditions for abandoning a relationship with a client, if necessary; g) vigilance measures for the clientele.
Financial institutions must have risk management procedures regarding the conditions under which a client can benefit from the business relationship before the verification of their identification (operations not involving the physical presence of the client).
Before establishing a business relationship with a client, the financial institution is required, based on its client acceptance policy, to examine the reputational risks associated with the client's profile and the nature of the business relationship.
Financial institutions must exercise constant vigilance throughout the duration of the business relationship and carefully examine operations carried out by the clientele to ensure they are consistent with what they know about their clients, their business activities, their risk profile, and where applicable, the source of their funds.
Financial institutions must adopt and apply customer due diligence measures during:
7
In compliance with the provisions of the Decree of April 30, 2023 sanctioning money laundering, terrorism financing, and the financing of the proliferation of weapons of mass destruction, financial institutions are required to identify their permanent or occasional clients, the agents of their clients, proxy holders, and beneficial owners. Money transfer houses must also ensure that their sub-agents implement similar preventive measures.
Before entering into a business relationship with a client, whether a natural person, legal entity, or legal construction, financial institutions must collect and analyze the necessary information elements for client knowledge as well as the intended object and nature of the business relationship. For legal entities or legal constructions, financial institutions must understand their ownership and control structure.
When clients do not act for their own account, financial institutions are required to inquire by any means about the identity of the true principal. After verification, if doubt persists regarding the identity of the true principal, the operation must be terminated, without prejudice to the obligation to file a suspicious transaction report. Furthermore, a lawyer, notary, accountant, or securities broker acting as a financial intermediary cannot invoke professional secrecy to avoid disclosing the identity of the true principal, in accordance with Article 43 of the Decree of April 30, 2023.
During client identification, a copy of all documents must be made, classified, and centralized by the financial institution. Formal controls must be performed regarding the signature, any anomalies on the photograph, and the physical appearance of the potential client.
The documents and information used for client identification must be requested during fund remittances and transfers for a globally equal or greater sum than one hundred thirty-two thousand gourdes (132,000.00 HTG) or the equivalent in foreign currency, for an occasional high-amount operation, for any transaction carried out under conditions of unusual complexity or unjustified.
Money transfer houses must ensure that transfers contain all required information on the principal and the beneficiary 8
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 56,126-character original (43% of the document). The remainder was not translated. The complete original-language text is stored with this document.]