2025-07-15
Added · Updated
Resolution SSF No. 2025-336 amends the Norms Compilation to introduce differential treatment for local and foreign Politically Exposed Persons (PEPs), requiring enhanced due diligence for foreign PEPs and high-risk local PEPs, while mandating senior management approval and intensified monitoring for non-high-risk local PEPs. The resolution authorizes the outsourcing of account and transaction monitoring subject to express authorization by the Superintendency of Financial Services and permits investment advisors to outsource client due diligence. It also establishes specific documentation requirements and a USD 120,000 annual transaction threshold for certain foreign PEPs, while updating the regulatory framework for third-party service outsourcing.
1 Montevideo, July 15, 2025 Ref: ALL MARKETS - Regulatory modifications regarding PEP clients and outsourcing
The market is informed that the Superintendency of Financial Services adopted Resolution SSF No. 2025-336 on July 7, 2025.
JUAN PEDRO CANTERA Superintendent of Financial Services
2025-50-1-00914 Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy CIRCULAR No. 2483
SUPERINTENDENCY OF FINANCIAL SERVICES – RESOLUTION SUPERINTENDENCY OF FINANCIAL SERVICES
VIEWING: The regulations regarding clients who are politically exposed persons (PEPs) and the outsourcing of account and transaction monitoring established within the framework of customer due diligence procedures that institutions must implement as part of the system to prevent being used for money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction (AML/CFT/CPF), contained in Book III of the various Norms Compilations.
RESULTING: I) As a result of the analysis of proposals received from the industry, a project was developed comprising modifications to the topics referred to in the VIEWING section. II) For the development of the proposal, reports prepared by members of the Financial Supervision Intendancy were used, and in the case of monitoring outsourcing, by the Financial Information and Analysis Unit. III) Regarding the regulations applicable to PEP clients, the proposal establishes differential treatment for local and foreign PEPs, in line with the approach the FATF Recommendations give to this type of client. IV) In the proposal, foreign PEPs maintain the current treatment, whereas for local PEPs, a distinction is made between those in which the institution has identified a higher-risk commercial relationship (which will be subject to the same procedures as foreign PEPs) and the remaining PEP clients. V) For local PEPs that are not higher-risk, the following additional procedures are established: obtaining approval from the main hierarchical levels of the institution when establishing or continuing a relationship with them, and performing more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. VI) Regarding the monitoring of accounts and transactions for the purpose of detecting unusual or suspicious patterns in client behavior, the proposal enables their outsourcing subject to express authorization by the Superintendency of Financial Services. VII) The regulatory proposal containing the modifications to the Norms Compilations was put out for consultation with supervised institutions and the general public on March 17 of the current year. VIII) Comments were received from the State Insurance Bank, Mortgage Bank of Uruguay, Association of Private Banks of Uruguay (ABPU), Uruguayan Association of Insurance Companies (AUDEA), Uruguayan Chamber of Information Technologies (CUTI), Uruguayan Compliance Association, Insigneo, AFAP ITÁÚ S.A., OCA S.A., Pronto (Kedal S.A. and Bautzen S.A.), and Paigo.
CONSIDERING: I) It is understood to be appropriate to adjust the due diligence requirements applicable to PEP clients according to a risk-based approach and to enable the use of third-party services for the performance of account and transaction monitoring for the purpose of detecting unusual or suspicious patterns in client behavior. II) The comments mentioned in Resulting VIII) provided elements that allowed improving the original proposal, corroborating the value that the consultation process has for the regulator, motivating the following modifications:
ATTENTIVE: To what is provided in letter A) of article 38 of Law No. 16.696 of March 30, 1995, as amended by article 2 of Law No. 20.345 of September 19, 2024, and to the reports issued by this Superintendency of Financial Services.
RESOLVES:
ARTICLE 35.1.1 (AUTHORIZATION OF OUTSOURCING). The authorization referred to in article 35.1 may be granted expressly or tacitly according to the following provisions:
When it concerns services provided by third parties located outside the country, express authorization from the Superintendency of Financial Services must be requested. Express authorization must also be requested when the third parties are located in the country but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the evaluation of risks associated with the outsourcing, including the assessment of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in numeral 1) of art. 35.1.2. Once the authorization is granted, the aforementioned report must be kept in the institution's offices at the disposal of the Superintendency of Financial Services and updated periodically based on the result of the risk evaluation performed regarding the outsourcing. The authorization refers only to the specific service object of the request and is made without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be subject to a new request. The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendency of Financial Services. The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution. The Superintendency of Financial Services may provide that certain services will not require express authorization for their hiring, establishing the conditions for such hiring to be considered authorized. Additionally, if deemed necessary, the Superintendency of Financial Services may request additional information to that indicated previously.
When it concerns services provided in the country by third parties located therein, their hiring will be considered authorized provided that the requirements referred to in article 35.1.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is provided in numeral 1) letter e) of the aforementioned article to be considered authorized. For the purposes of outsourcings that imply data processing, the provisions of articles 35.2 and 35.3 will also apply. With respect to the hiring of correspondent services, the provisions of articles 35.6 to 35.17 will also apply. Outsourcings that imply direct contact with clients for securities intermediation services, portfolio management, or investment advice will be considered authorized when they comply with what is provided in article 67.1.3 of the Norms Compilation of the Securities Market, even in the case of third parties located abroad. The authorization for the use of third-party services to perform due diligence procedures will be governed by what is provided in article 304. The Superintendency of Financial Services may establish that certain services will not require authorization for their hiring.
SUBSTITUTE in Chapter II – Due diligence policies and procedures regarding clients, of Title I - Prevention of the use of financial intermediation institutions, exchange houses, financial services companies, and funds transfer companies for money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction, of Book III – Protection of the Financial System against illicit activities of the Norms Compilation of Regulation and Control of the Financial System, articles 299, 301, and 304 with the following:
ARTICLE 299 (ENHANCED DUE DILIGENCE PROCEDURES). Institutions must apply enhanced due diligence procedures for categories of clients, commercial relationships, or operations considered higher risk, according to what arises from the risk assessment performed by the institution. However, the following will be considered higher risk: a) commercial relationships and operations with non-resident clients coming from countries that do not comply with international standards in matters of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction. b) transactions of those persons who link with the entity through operations in which personal contact is not usual, as in the case of clients who carry out operations through operational modalities that, using new or developing technologies, may favor client anonymity. c) politically exposed persons from abroad, as well as their family members and close associates. d) all those operations that are carried out under unusual circumstances according to the uses and customs of the respective activity.
In application of enhanced due diligence procedures, institutions must: i. obtain approval from the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client. ii. prepare a detailed report in which all elements considered to elaborate their activity profile will be explicit. The report must be adequately backed by documentation that allows establishing the financial, economic, and financial situation or justifying the origin of the funds handled by the client. For these purposes, accounting statements with a Public Accountant's report, tax returns, responsibility statements, minutes of profit distribution, sales contracts, or other documentation that allows complying with the aforementioned must be available. Nevertheless, in all cases, copies of sworn declarations or equivalent documentation presented to the corresponding tax administration must be available. This requirement is exempted when it concerns reference, advice, and portfolio management services provided to non-resident clients of other financial institutions abroad that are subject to regulation and supervision, provided that:
In the case of persons included in letter c) whose annual transactions, according to their activity profile, reach amounts less than USD 120,000 (one hundred twenty thousand United States dollars) or its equivalent in other currencies, or carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the financial, economic, and financial situation or justifying the origin of the funds handled by the client will be required. To determine said threshold, the total amount to be deposited or deposited into the account will be considered, and in the case of transactions not associated with an account, their accumulated volume excluding those related to another operation, such as a currency purchase-sale followed by a transfer.
iii. increase the frequency of updating client information, according to what is provided in article 297.1. iv. perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. For those clients who operate with significant amounts, the provisions of numerals ii. and iii. must also be met. The threshold to determine those clients who operate with significant amounts will be defined by each institution considering elements such as: i. the maintenance of passive balances or funds under management superior to a determined amount; ii. habitual client who deposits extraordinary funds into their bank account or processes transactions for amounts superior to a minimum value established for a determined period, regardless of the activity profile that had been assigned to them; iii. occasional client who proposes to carry out a transaction that exceeds an established amount.
ARTICLE 301 (POLITICALLY EXPOSED PERSONS). “Politically exposed persons” are understood to be persons who perform or have performed in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, high-ranking government, judicial, or military officials, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and high executives of state companies and other public entities. Politically exposed persons are also understood to be those persons who perform or have performed in the last 5 (five) years a high-ranking function in an international organization, such as: members of senior management, directors, deputy directors, board members, or equivalent functions. Institutions must have procedures that allow them to determine when a client or final beneficiary is a politically exposed person, a family member, or a close associate of a politically exposed person. In the case of having clients who are local politically exposed persons of lower and medium risk, in addition to executing the due diligence procedures provided in article 293, institutions must perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. The enhanced due diligence procedures provided in numerals i. to iv. of article 299 will apply to foreign politically exposed persons. Likewise, said procedures must be applied to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 304 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES). The use of third-party services to perform due diligence procedures will require the authorization of the Superintendency of Financial Services, which may be granted expressly or tacitly. In particular, the hiring of third parties for the performance of account and transaction monitoring with the aim of detecting unusual or suspicious patterns in client behavior will require express authorization in all cases. Companies that provide outsourced services will be subject, regarding those activities, to the same norms that govern when they are fulfilled by the controlled entities, with the exception of those of a sanctioning character, and will be obliged to apply the client due diligence procedures established by the institution. The institution will maintain at all times the final responsibility for the adequate identification, knowledge, and monitoring of them, must verify the adequate application of its procedures to the clients whose due diligence is performed by a third party. It must obtain and conserve the information and documentation relative to the identification and knowledge of the client in all cases, as if the due diligence procedures had been completed directly by it. Likewise, the institution must conserve the alerts generated by account and transaction monitoring systems, as well as the analysis thereof. Those outsourcings of due diligence procedures with clients that comply with the aforementioned provisions and the requirements detailed below are considered authorized: a. The third party providing the service must be registered with the control body of its country to perform financial activities, and be regulated and supervised or monitored by it, especially regarding compliance with client due diligence requirements and record maintenance, in accordance with international standards in the matter. b. The third party providing the service must be located in a country that is not subject to special measures by the Financial Action Task Force (FATF) and that is not included in the list of countries that do not comply with transparency and cooperation criteria in fiscal matters issued by the Organization for Economic Co-operation and Development (OECD). c. The services to be outsourced must be detailed in a contract between the parties which must contain, at minimum, the following clauses: c.1. the obligation of the contracted third party to maintain personal contact with the potential client or, failing that, to establish that personal contact will be carried out by the institution itself. c.2. the necessary documentation to verify the client's identity. c.3. the financial information and documentation that the third party must collect to obtain adequate knowledge of the economic activity developed by the potential client, and the manner in which it will be verified. c.4. the documentation that the client must complete and sign depending on the service to be provided by the institution once accepted (account opening contracts, client knowledge forms for new links or information updates, etc.). c.5. the obligation of the contracted third party to inform the potential client that no commercial link will be initiated until the entity formally accepts it. c.6. commitments of confidentiality and personal data protection. c.7. prohibition of subcontracting. The information and documentation mentioned in letters c.2 to c.4 must be consistent with those required by the institution for the rest of its clients, according to their profile. d. The institution must: d.1. keep in its offices the contracts celebrated with the company in which the services were outsourced, as well as sufficient and updated information that accredits the suitability and background of the contracted third party, as well as a declaration from the same regarding the personnel who will perform the due diligence, accrediting that they know the current regulation in matters of prevention of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction applicable to the contracting institution and the due diligence procedures to be applied. The information and documentation mentioned must be updated at least every 2 (two) years. d.2. have a list of clients whose due diligence was performed by a third party. The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution. In the case of financial intermediation institutions, the aforementioned provisions must be complied with even when the client due diligence services have been provided to the institution by its headquarters or its branches abroad.
ARTICLE 316.9 (ENHANCED DUE DILIGENCE PROCEDURES). Large credit administrator companies must apply enhanced due diligence procedures for categories of customers, commercial relationships or operations considered higher risk, according to what arises from the risk assessment carried out by the institution. However, the following shall be considered higher risk: a) Commercial relationships and operations with non-resident customers, especially those coming from countries that do not comply with international standards regarding money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction. b) Transactions by persons who link with the entity through operations where personal contact (physical presence) is not usual, such as in the case of non-resident customers, in internet operations or through any other operational modality that, using new or developing technologies, could favor the anonymity of customers. c) Foreign politically exposed persons, as well as their family members and close associates. d) All those operations that are carried out under unusual circumstances according to the uses and customs of the respective activity. In application of enhanced due diligence procedures, institutions must: i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of customer. ii. prepare a detailed report in which the assigned activity profile will be included to adequately monitor the customer's transactions and all elements that have been considered to determine said profile will be specified. The report must be adequately backed up by documentation that allows establishing the patrimonial, economic and financial situation or justifying the origin of the funds handled by the customer. For these purposes, accounting statements with Public Accountant report, tax returns, liability statements, profit distribution minutes, sales contracts or other documentation that allows complying with the above must be available. RR-SSF-2025-336 Date: 07/07/2025 14:29:03 CIRCULAR N°2483
Notwithstanding this, in all cases copies of sworn declarations or equivalent documentation presented before the corresponding tax administration must be available. In the case of persons included in letter c) whose annual transactions according to their activity profile reach amounts less than USD 120,000 (one hundred twenty thousand United States dollars) or its equivalent in other currencies, or carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the patrimonial, economic and financial situation or justifying the origin of the funds handled by the customer will be required. To determine said threshold, the accumulated volume of transactions will be considered. iii. increase the frequency of updating customer information. iv. perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. For those customers who operate with significant amounts, compliance with items ii. and iii. must also be met.
ARTICLE 316.11 (POLITICALLY EXPOSED PERSONS). "Politically exposed persons" means persons who hold or have held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, government, judicial or military officials of high rank, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and top executives of state-owned companies and other public entities. Politically exposed persons also includes those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: senior management members, directors, deputy directors, board members or equivalent functions. Large credit administrator companies must have procedures that allow them to determine when a customer or ultimate beneficiary is a politically exposed person, a family member or close associate of a politically exposed person. In the case of having customers who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures established in article 316.4, institutions must perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. The enhanced due diligence procedures established in items i. to iv. of article 316.9 shall apply to foreign politically exposed persons. Likewise, said procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 316.12 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES). The use of third-party services to carry out required due diligence procedures requires authorization from the Superintendency of Financial Services, which may be granted expressly or tacitly. In particular, contracting third parties for the monitoring of accounts and transactions in order to detect unusual or suspicious patterns in customer behavior requires express authorization in all cases. Companies providing outsourced services are subject, with respect to those activities, to the same norms that govern when they are fulfilled by the controlled entities, except for those of a sanctioning nature, and are obliged to apply the customer due diligence procedures established by the institution. Large credit administrator companies will maintain at all times the final responsibility for the adequate identification, knowledge and monitoring thereof, verifying the adequate application of their procedures to customers whose due diligence is carried out by a third party. They must obtain and conserve the information and documentation relative to the identification and knowledge of the customer in all cases, as if the due diligence procedures had been completed directly by them. Likewise, the institution must conserve the alerts generated by account and transaction monitoring systems, as well as the analysis thereof. Outsourcing of due diligence procedures with customers that comply with the aforementioned provisions and the requirements detailed below are considered authorized: a. The third party providing the service must be registered with the control body of its country to carry out financial activities, and be regulated, supervised or monitored by it, especially regarding compliance with customer due diligence requirements and record keeping, according to international standards in the matter. b. The third party providing the service must be located in a country that is not subject to special measures by the Financial Action Task Force (FATF) and is not included in the list of countries that do not meet transparency and cooperation criteria in fiscal matters issued by the Organisation for Economic Co-operation and Development (OECD). c. The services to be outsourced must be detailed in a contract between the parties which must contain, at minimum, the following clauses: c.1. the obligation of the contracted third party to maintain personal contact with the potential customer or, failing that, to establish that personal contact will be carried out by the institution itself. c.2. the necessary documentation to verify the identity of the customer. c.3. the financial information and documentation that the third party must collect to obtain adequate knowledge of the economic activity developed by the potential customer, and how it will be verified. c.4. the documentation that the customer must complete and sign depending on the service to be provided by the institution once accepted (customer knowledge forms for new links or information updates, etc.). c.5. the obligation of the contracted third party to inform the potential customer that no commercial link will be initiated until the entity formally accepts it. c.6. commitments of confidentiality and protection of personal data. c.7. prohibition of subcontracting. The information and documentation mentioned in letters c.2 to c.4 must be consistent with that required by the large credit administrator company for its other customers, according to their profile. d. Large credit administrator companies must: d.1. keep in their offices the contracts celebrated with the company in which services were outsourced, as well as sufficient and updated information accrediting the suitability and background of the contracted third party, as well as a declaration from the latter regarding the personnel who will carry out the due diligence, accrediting that they know the current regulation regarding prevention of money laundering, terrorist financing and financing of the proliferation of weapons of mass destruction applicable to the contracting institution and the due diligence procedures to be applied. The information and documentation mentioned must be updated at least every 2 (two) years. d.2. have a list of customers whose due diligence was carried out by a third party. The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution.
ARTICLE 316.31 (ENHANCED DUE DILIGENCE PROCEDURES). Representations must apply enhanced due diligence procedures for categories of customers, commercial relationships or operations considered higher risk, according to what arises from the risk assessment carried out by the institution. However, the following shall be considered higher risk: a) Commercial relationships and operations with non-resident customers, especially those coming from countries that do not comply with international standards regarding money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction. b) Foreign politically exposed persons, as well as their family members and close associates. c) All those operations that are carried out under unusual circumstances according to the uses and customs of the respective activity. In application of enhanced due diligence procedures, representations must: i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of customer. ii. prepare a detailed report in which the assigned activity profile will be included to adequately monitor the customer's transactions and all elements that have been considered to determine said profile will be specified. The report must be adequately backed up by documentation that allows establishing the patrimonial, economic and financial situation or justifying the origin of the funds handled by the customer. For these purposes, accounting statements with Public Accountant report, tax returns, liability statements, profit distribution minutes, sales contracts or other documentation that allows complying with the above must be available. Notwithstanding this, in all cases copies of sworn declarations or equivalent documentation presented before the corresponding tax administration must be available. This requirement is exempted when dealing with non-resident customers provided that:
To determine said threshold, the accumulated volume of transactions will be considered. iii. increase the frequency of updating customer information. iv. perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
ARTICLE 316.33 (POLITICALLY EXPOSED PERSONS). "Politically exposed persons" means persons who hold or have held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, government, judicial or military officials of high rank, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and top executives of state-owned companies and other public entities. Politically exposed persons also includes those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: senior management members, directors, deputy directors, board members or equivalent functions. Representations must have procedures that allow them to determine when a customer or ultimate beneficiary is a politically exposed person, a family member or close associate of a politically exposed person. In the case of having customers who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures established in article 316.27, institutions must perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. The enhanced due diligence procedures established in items i. to iv. of article 316.31 shall apply to foreign politically exposed persons. Likewise, said procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 316.44 (ENHANCED DUE DILIGENCE PROCEDURES). Cash-in-transit companies must apply enhanced due diligence procedures to: a) Commercial relationships and operations with non-resident customers, especially those coming from countries that do not comply with international standards regarding money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction. b) Foreign politically exposed persons, as well as their family members and close associates. c) All those operations that are carried out under unusual circumstances according to the uses and customs of the respective activity. In application of enhanced due diligence procedures, cash-in-transit companies must: i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of customer. ii. prepare a report stating the origin of the funds or values to be transported, which must be adequately backed up by documentation that allows justifying their origin. In the case of persons included in letter b) whose annual transactions reach amounts less than USD 120,000 (one hundred twenty thousand United States dollars) or its equivalent in other currencies, only the documentation that allows justifying the origin of the funds or values to be transported will be required. To determine said threshold, the accumulated volume of transactions will be considered. iii. increase the frequency of updating customer information. iv. perform more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
ARTICLE 316.46 (POLITICALLY EXPOSED PERSONS). "Politically exposed persons" means persons who hold or have held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, government, judicial or military officials of high rank, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and top executives of state-owned companies and other public entities. Politically exposed persons also includes those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: senior management members, directors, deputy directors, board members or equivalent functions. Cash-in-transit companies must have procedures that allow them to determine when a customer or ultimate beneficiary is a politically exposed person, a family member or close associate of a politically exposed person.
In the case of having clients who are local politically exposed persons of lower and medium risk, in addition to executing the due diligence procedures set forth in Article 316.39, institutions must perform more intensive monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. To foreign politically exposed persons, the enhanced due diligence procedures set forth in items i. to iv. of Article 316.44 shall apply. Likewise, such procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 316.56 (ENHANCED DUE DILIGENCE PROCEDURES). Companies providing security deposit box rental and custody services shall apply enhanced due diligence procedures for commercial relationships considered higher risk, according to what arises from the risk assessment carried out by the institution. However, the following shall be considered higher risk: a) commercial relationships with non-resident clients, especially those from countries that do not comply with international standards in matters of money laundering, terrorism financing, and financing of proliferation of weapons of mass destruction. b) foreign politically exposed persons, as well as their family members and close associates. c) all those operations carried out under unusual circumstances according to the usages and customs of the respective activity. In application of enhanced due diligence procedures, institutions must: i. obtain approval from the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client. ii. increase the frequency of updating client information. iii. perform more intensive monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
ARTICLE 316.57 (POLITICALLY EXPOSED PERSONS). “Politically exposed persons” are understood to be persons who hold or have held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, government, judicial or military officials of high rank, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and senior executives of state-owned companies and other public entities. Politically exposed persons are also understood to be those persons who hold or have held in the last 5 (five) years a hierarchical function in an international organization, such as: members of senior management, directors, deputy directors, board members or equivalent functions. Institutions must have procedures that allow them to determine when a client or beneficial owner is a politically exposed person, a family member or close associate of a politically exposed person. In the case of having clients who are local politically exposed persons of lower and medium risk, in addition to executing the due diligence procedures set forth in Article 316.51, institutions must perform more intensive monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. To foreign politically exposed persons, the enhanced due diligence procedures set forth in items i. to iii. of Article 316.56 shall apply. Likewise, such procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 316.72 (ENHANCED DUE DILIGENCE PROCEDURES). Companies administering platforms for peer-to-peer lending shall apply enhanced due diligence procedures for categories of clients, commercial relationships or operations considered higher risk, according to what arises from the risk assessment carried out by the institution. However, the following shall be considered higher risk: a) foreign politically exposed persons, as well as their family members and close associates. b) all those operations carried out under unusual circumstances according to the usages and customs of the respective activity. c) clients who, during a calendar year, grant loans for an accumulated amount exceeding 1,700,000 indexed units (one million seven hundred thousand indexed units). d) non-resident clients from countries that do not comply with international standards in matters of money laundering, terrorism financing, and financing of proliferation of weapons of mass destruction. In application of enhanced due diligence procedures, institutions must: i. obtain approval from the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client. ii. prepare a detailed report in which the activity profile assigned to adequately monitor the client's transactions will be included, and all elements considered to determine said profile will be specified. The report must be adequately backed by documentation that allows establishing the patrimonial, economic and financial situation or justifying the origin of the funds handled by the client. For these purposes, accounting statements with a Public Accountant's report, tax returns, responsibility statements, minutes of profit distribution, sales contracts or other documentation that allows complying with the aforementioned must be available. However, in all cases, copies of sworn declarations or equivalent documentation submitted to the corresponding tax administration must be available. In the case of persons included in item a) whose annual transactions, according to their activity profile, reach amounts less than USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the patrimonial, economic and financial situation or justifying the origin of the funds handled by the client will be required. To determine said threshold, the accumulated volume of transactions will be considered. iii. increase the frequency of updating client information. iv. perform more intensive monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. For those clients who operate with significant amounts, compliance with items ii. and iii. shall also be required. The threshold to determine those clients who operate with significant amounts shall be defined by each institution considering elements such as:
ARTICLE 316.74 (POLITICALLY EXPOSED PERSONS). “Politically exposed persons” are understood to be persons who hold or have held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, government, judicial or military officials of high rank, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and senior executives of state-owned companies and other public entities. Politically exposed persons are also understood to be those persons who hold or have held in the last 5 (five) years a hierarchical function in an international organization, such as: members of senior management, directors, deputy directors, board members or equivalent functions. Companies administering platforms for peer-to-peer lending must have procedures that allow them to determine when a client or beneficial owner is a politically exposed person, a family member or close associate of a politically exposed person. In the case of having clients who are local politically exposed persons of lower and medium risk, in addition to executing the due diligence procedures set forth in Article 316.66, institutions must perform more intensive monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. To foreign politically exposed persons, the enhanced due diligence procedures set forth in items i. to iv. of Article 316.72 shall apply. Likewise, such procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 316.76 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES). The use of third-party services to carry out the required due diligence procedures will require the authorization of the Superintendence of Financial Services, which may be granted expressly or tacitly. In particular, the contracting of third parties for the monitoring of accounts and transactions in order to detect unusual or suspicious patterns in client behavior will require, in all cases, explicit authorization. Companies providing outsourced services will be subject, with respect to those activities, to the same rules that govern when they are complied with by the controlled entities, with the exception of those of a sanctioning nature, and will be obliged to apply the client due diligence procedures established by the institution. Companies administering platforms for peer-to-peer lending will maintain at all times the final responsibility for the adequate identification, knowledge and monitoring of said clients, verifying the adequate application of their procedures to clients whose due diligence is carried out by a third party. They must obtain and conserve the information and documentation relating to the identification and knowledge of the client in all cases, as if the due diligence procedures had been completed directly by them. Likewise, the institution must conserve the alerts generated by account and transaction monitoring systems, as well as the analysis thereof. Outsourcing of due diligence procedures with clients that comply with the aforementioned provisions and the requirements detailed below are considered authorized: a. The third party providing the service is the local financial entity contracted to channel the fund movement associated with the granted loans. b. The services to be outsourced must be detailed in a contract between the parties which must contain, at minimum, the following clauses:
ARTICLE 58.1.1 (AUTHORIZATION OF OUTSOURCING). The authorization referred to in Article 58.1 may be granted expressly or tacitly according to the following provisions: When it concerns services provided by third parties located outside the country, the explicit authorization of the Superintendence of Financial Services must be requested. Likewise, explicit authorization must be requested when the third parties are located in the country but the services are provided totally or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the evaluation of risks associated with outsourcing, including the valuation of the patrimonial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, according to Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 58.1.2. Once the authorization is granted, the aforementioned report must be kept in the offices of the stock exchange available to the Superintendence of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization refers only to the specific service object of the request and is made without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted, must be subject to a new request. The granted authorization may be revoked in case of observing deviations from what is indicated, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services. The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution. The Superintendence of Financial Services may provide that certain services will not require explicit authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated above. When it concerns services provided in the country by third parties located therein, their contracting will be considered authorized provided that the requirements referred to in Article 58.1.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity, will only need to comply with what is set forth in item 1) item e) of said article to be considered authorized. For the purposes of outsourcings that imply data processing, the provisions of Articles 58.2 and 58.3 shall also apply. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 59.19 (AUTHORIZATION OF OUTSOURCING). The authorization referred to in Article 59.18 may be granted expressly or tacitly according to the following provisions: When it concerns services provided by third parties located outside the country, the explicit authorization of the Superintendence of Financial Services must be requested. Likewise, explicit authorization must be requested when the third parties are located in the country, but the services are provided totally or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the evaluation of risks associated with outsourcing, including the valuation of the patrimonial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, according to Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of Article 59.20. Once the authorization is granted, the aforementioned report must be kept in the offices of the company available to the Superintendence of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization refers only to the specific service object of the request and is made without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted, must be subject to a new request. The granted authorization may be revoked in case of observing deviations from what is indicated, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services. The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution. The Superintendence of Financial Services may provide that certain services will not require explicit authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated above. When it concerns services provided in the country by third parties located therein, their contracting will be considered authorized provided that the requirements referred to in Article 59.20 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity, will only need to comply with what is set forth in item 1) item e) of said article to be considered authorized. For the purposes of outsourcings that imply data processing, the provisions of Articles 58.2 and 58.3 shall also apply. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
provided for in item 1) letter e) of the aforementioned article to be considered authorized. For the purposes of outsourcing involving data processing, the provisions of articles 59.21 and 59.22 shall also apply. The authorization for the use of third-party services to carry out due diligence procedures shall be governed by the provisions of article 206.15. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 67.1.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 67.1 may be granted expressly or tacitly according to the following provisions: When services are provided by third parties located outside the country, the express authorization of the Superintendence of Financial Services must be requested. The same applies when the third parties are located in the country but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with the outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to the legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 67.1.2. Once the authorization is granted, the aforementioned report must be kept in the offices of the securities intermediary at the disposal of the Superintendence of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization refers only to the specific service that is the subject of the request and is made without prejudice to the registration of databases and authorizations for the international transfer of personal data that may correspond before the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services. The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services shall be charged to the supervised institution. The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated previously. When services are provided in the country by third parties located therein, their contracting shall be considered authorized provided that the requirements referred to in article 67.1.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity shall only comply with what is provided for in item 1) letter e) of the aforementioned article to be considered authorized. For the purposes of outsourcing involving data processing, the provisions of articles 67.2 and 67.3 shall also apply. Outsourcings that imply direct treatment with clients for securities intermediation services, portfolio management, or investment advice shall be considered authorized when they comply with what is provided in article 67.1.3, even in the case of third parties located abroad. The authorization for the use of third-party services to carry out due diligence procedures shall be governed by the provisions of article 198. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 76.2.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 76.2 may be granted expressly or tacitly according to the following provisions: When services are provided by third parties located outside the country, the express authorization of the Superintendence of Financial Services must be requested. The same applies when the third parties are located in the country, but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with the outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to the legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 76.2.2. Once the authorization is granted, the aforementioned report must be kept in the offices of the institution at the disposal of the Superintendence of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization refers only to the specific service that is the subject of the request and is made without prejudice to the registration of databases and authorizations for the international transfer of personal data that may correspond before the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. In no case shall authorization be requested in case of modifications or readjustments of the price or consideration. The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services. The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services shall be charged to the supervised institution. The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated previously. When services are provided in the country by third parties located therein, their contracting shall be considered authorized provided that the requirements referred to in article 76.2.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity shall only comply with what is provided for in item 1) letter e) of the aforementioned article to be considered authorized. The provision of these services by such institutions shall be considered own activities or related to their business. For the purposes of outsourcing involving data processing, the provisions of articles 76.3 and 76.4 shall also apply. The authorization for the contracting of third parties for the management of the Investment Fund assets shall be governed by the provisions of article 76.6. The authorization for the use of third-party services to carry out due diligence procedures shall be governed by the provisions of article 198. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 106.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 106 may be granted expressly or tacitly according to the following provisions: When services are provided by third parties located outside the country, the express authorization of the Superintendence of Financial Services must be requested. The same applies when the third parties are located in the country but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with the outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to the legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 106.1.1. Once the authorization is granted, the aforementioned report must be kept in the offices of the trustee at the disposal of the Superintendence of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization refers only to the specific service that is the subject of the request and is made without prejudice to the registration of databases and authorizations for the international transfer of personal data that may correspond before the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services. The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services shall be charged to the supervised institution. The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated previously. When services are provided in the country by third parties located therein, their contracting shall be considered authorized provided that the requirements referred to in article 106.1.1 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity shall only comply with what is provided for in item 1) letter e) of the aforementioned article to be considered authorized. For the purposes of outsourcing involving data processing, the provisions of articles 106.2 and 106.3 shall also apply. The authorization for the use of third-party services to carry out due diligence procedures shall be governed by the provisions of article 198. When it comes to outsourcing linked to private offer financial trusts, trustees shall only obtain the certificate referred to in article 108 and subsequently seek the acceptance of the beneficiaries. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 127.1 (OUTSOURCING OF SERVICES). Investment advisors must request authorization from the Superintendence of Financial Services for the contracting of third parties for the provision on their behalf of those services so inherent to their business that, when carried out by their own departments, are subject to the regulatory and control powers of the aforementioned Superintendence. The companies providing the outsourced services shall be subject, with respect to those activities, to the same rules that govern when they are carried out by the controlled entities, with the exception of those of a sanctioning nature. Outsourcing does not in any case exempt or limit the responsibility that the law or regulations impose on the investment advisor for non-compliance with its obligations. Activities described in letters a) and b) of article 124.1 nor client acceptance may not be outsourced. Investment advisors must have written policies and procedures established that allow ensuring effective identification, measurement, control, and monitoring of risks -both present and future- associated with outsourcing agreements made. In particular, they must evaluate the emerging risks from the outsourcing of multiple activities to the same provider.
ARTICLE 127.1.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 127.1 may be granted expressly or tacitly according to the following provisions: When services are provided by third parties located outside the country, the express authorization of the Superintendence of Financial Services must be requested. The same applies when the third parties are located in the country but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with the outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to the legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 127.1.2. Once the authorization is granted, the aforementioned report must be kept in the offices of the investment advisor at the disposal of the Superintendence of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization refers only to the specific service that is the subject of the request and is made without prejudice to the registration of databases and authorizations for the international transfer of personal data that may correspond before the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services. The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services shall be charged to the supervised institution. The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated previously. When services are provided in the country by third parties located therein, their contracting shall be considered authorized provided that the requirements referred to in article 127.1.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity shall only comply with what is provided for in item 1) letter e) of the aforementioned article to be considered authorized. For the purposes of outsourcing involving data processing, the provisions of articles 127.2 and 127.3 shall also apply. The authorization for the use of third-party services to carry out due diligence procedures shall be governed by the provisions of article 207.9.1. The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 127.17.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 127.17 may be granted expressly or tacitly according to the following provisions: When services are provided by third parties located outside the country, the express authorization of the Superintendence of Financial Services must be requested.
Superintendency of Financial Services. Likewise, express authorization must be requested when third parties are located in the country but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 127.17.2. Once the authorization is granted, the aforementioned report must be kept in the portfolio manager's offices at the disposal of the Superintendency of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization will refer only to the specific service object of the request and will be carried out without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendency of Financial Services. The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution. The Superintendency of Financial Services may provide that certain services will not require express authorization for their hiring, establishing the conditions for such hiring to be considered authorized. Additionally, if deemed necessary, the Superintendency of Financial Services may request additional information to that indicated previously. When it comes to services provided in the country by third parties located in it, their hiring will be considered authorized as long as the requirements referred to in article 127.17.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is established in item 1) letter e) of said article to be considered authorized. For the purposes of outsourcings that imply data processing, what is established in articles 127.18 and 127.19 will also apply. Outsourcings that imply direct treatment with clients for investment advisory services will be considered authorized when they comply with what is established in article 127.17.3, even in the case of third parties located abroad. The authorization for the use of third-party services to carry out due diligence procedures will be governed by what is established in article 207.9.1. The Superintendency of Financial Services may establish that certain services will not require authorization for their hiring.
ARTICLE 135.1.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 135.1 may be granted expressly or tacitly according to what is established below: When it comes to services provided by third parties located outside the country, express authorization from the Superintendency of Financial Services must be requested. Likewise, express authorization must be requested when third parties are located in the country but the services are provided wholly or partially in or from abroad. The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 135.1.2. Once the authorization is granted, the aforementioned report must be kept in the institution's offices at the disposal of the Superintendency of Financial Services and updated periodically based on the result of the risk assessment carried out regarding the outsourcing. The authorization will refer only to the specific service object of the request and will be carried out without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society. Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated are observed without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendency of Financial Services. The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution. The Superintendency of Financial Services may provide that certain services will not require express authorization for their hiring, establishing the conditions for such hiring to be considered authorized. Additionally, if deemed necessary, the Superintendency of Financial Services may request additional information to that indicated previously. When it comes to services provided in the country by third parties located in it, their hiring will be considered authorized as long as the requirements referred to in article 135.1.2 are met. Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is established in item 1) letter e) of said article to be considered authorized. For the purposes of outsourcings that imply data processing, what is established in articles 135.2 and 135.3 will also apply. The Superintendency of Financial Services may establish that certain services will not require authorization for their hiring.
ARTICLE 194 (ENHANCED DUE DILIGENCE PROCEDURES). Securities intermediaries and investment fund administrators must apply enhanced due diligence procedures for categories of clients, commercial relationships or operations considered of higher risk, according to what arises from the risk assessment carried out by the institution. However, the following will be considered of higher risk: commercial relationships and operations with non-resident clients coming from countries that do not comply with international standards in matters of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction. transactions of those persons who link with the entity through operations in which personal contact is not usual, as in the case of clients who carry out operations through operational modalities that, using new or developing technologies, could favor the anonymity of clients. foreign politically exposed persons, as well as their family members and close associates. all those operations that are carried out in unusual circumstances according to the usages and customs of the respective activity. In application of the enhanced due diligence procedures, institutions must: i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client. ii. elaborate a detailed report in which all elements that have been considered to elaborate their activity profile will be explicit. The report must be adequately backed by documentation that allows establishing the financial, economic and financial situation or justify the origin of the funds handled by the client. For these purposes, accounting statements with Public Accountant report, tax returns, responsibility statements, minutes of profit distribution, sales contracts or other documentation that allows complying with what indicated previously must be available. However, in all cases, copies of sworn declarations or equivalent documentation presented before the corresponding tax administration must be available. This requirement is exempted when it comes to referencing, advisory and portfolio management services provided to non-resident clients of foreign financial institutions that are subject to regulation and supervision as long as: they do not receive from said clients - under any title - sums of money, securities or precious metals, the institutions ensure that the presentation of said documentation is not a requirement established by the financial regulator of the foreign financial institution in its anti-money laundering, terrorist financing and financing of the proliferation of weapons of mass destruction prevention norms, and a certificate issued by the corresponding Tax Administration or a letter issued by a professional or by the client's representatives indicating that they are up to date with their tax obligations is obtained. In the case of persons included in letter c) whose annual transactions, according to their activity profile, reach amounts less than USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the financial, economic and financial situation or justify the origin of the funds handled by the client will be required. For the purposes of determining said threshold, the total amount to be deposited or deposited into the account will be considered. iii. increase the frequency of updating client information, according to what is established in article 191.1. iv. carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. For those clients who operate by significant amounts, what is established in items ii. and iii. must also be complied with. The threshold to determine those clients who operate by significant amounts will be defined by each institution considering elements such as: i. the maintenance of funds under management superior to a determined amount; ii. wholesale client who enters extraordinary funds into their account or processes transactions by amounts superior to a minimum value established for a determined period, regardless of the activity profile that had been assigned to them; iii. retail client who proposes to carry out a transaction that exceeds an established amount.
ARTICLE 196 (POLITICALLY EXPOSED PERSONS). "Politically exposed persons" are understood to be persons who perform or have performed in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, high-ranking governmental, judicial or military officials, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and high executives of state companies and other public entities. Politically exposed persons are also understood to be those persons who perform or have performed in the last 5 (five) years a function of hierarchy in an international organization, such as: members of senior management, directors, deputy directors, members of the board or equivalent functions. Securities intermediaries and investment fund administrators must have procedures that allow them to determine when a client or final beneficiary is a politically exposed person, a family member or close associate of a politically exposed person. In the case of having clients who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures established in article 189, institutions must carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. To foreign politically exposed persons, the enhanced due diligence procedures established in items i. to iv. of article 194 will apply. Likewise, said procedures must be applied to local politically exposed persons in which the institution has identified a higher risk commercial relationship.
ARTICLE 198 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES). The use of third-party services to carry out due diligence procedures will require the authorization of the Superintendency of Financial Services, which may be granted expressly or tacitly. In particular, the hiring of third parties for the monitoring of accounts and transactions in order to detect unusual or suspicious patterns in client behavior will require express authorization in all cases. The companies that provide the outsourced services will be subject, regarding those activities, to the same norms that govern when they are fulfilled by the controlled entities, with the exception of those of a sanctioning character, and will be obliged to apply the client due diligence procedures established by the institution. The institution will maintain at all times the final responsibility for the adequate identification, knowledge and monitoring of them, having to verify the adequate application of its procedures to the clients whose due diligence is carried out by a third party. It must obtain and conserve the information and documentation relative to the identification and knowledge of the client in all cases, as if the due diligence procedures had been completed directly by it. Likewise, the institution must conserve the alerts generated by the account and transaction monitoring systems, as well as the analysis of them. Those outsourcings of due diligence procedures with clients that comply with what established previously and the requirements detailed below are considered authorized: The third party providing the service must be registered before the control body of its country to carry out financial activities, and be regulated and supervised or monitored by it, especially regarding the application of client due diligence procedures and maintenance of records, according to international standards in the matter. The third party providing the service must be located in a country that is not subject to special measures by the Financial Action Task Force (FATF) and that is not included in the list of countries that do not comply with transparency and cooperation criteria in fiscal matters issued by the Organization for Economic Co-operation and Development (OECD). The services to be outsourced must be detailed in a contract between the parties which must contain, at minimum, the following clauses: the obligation of the contracted third party to maintain personal contact with the potential client or, in its defect, establish that the personal contact will be carried out by the institution itself. the necessary documentation to verify the identity of the client. the financial information and documentation that the third party must collect to obtain adequate knowledge of the economic activity developed by the potential client, and the way in which it will be verified. the documentation that the client must complete and sign depending on the service to be provided by the institution once accepted (account opening contracts, client knowledge forms for new links or information update, etc). the obligation of the contracted third party to inform the potential client that no commercial link will be initiated until the entity formally accepts it. commitments of confidentiality and protection of personal data. prohibition of subcontracting. The information and documentation mentioned in letters c.2 to c.4 must be consistent with those required by the institution for the rest of its clients, according to their profile. Securities intermediaries and investment fund administrators must: keep in their offices the contracts celebrated with the company in which the services were outsourced as well as sufficient and updated information that accredits the suitability and background of the contracted third party, as well as a declaration by the same regarding the personnel that will carry out the due diligence, accrediting that they know the current regulation in matters of prevention of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction applicable to the contracting institution and the due diligence procedures to apply. The information and documentation mentioned must be updated at least every 2 (two) years have a list of clients whose due diligence was carried out by a third party. The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution.
ARTICLE 206.11 (ENHANCED DUE DILIGENCE PROCEDURES). Crowdfunding platform administrator companies must apply enhanced due diligence procedures for categories of clients, commercial relationships or operations considered of higher risk, according to what arises from the risk assessment carried out by the institution. However, the following will be considered of higher risk: a) foreign politically exposed persons, as well as their family members and close associates. b) all those operations that are carried out in unusual circumstances according to the usages and customs of the respective activity. c) non-resident clients coming from countries that do not comply with international standards in matters of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction. In application of the enhanced due diligence procedures, institutions must: i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client. ii. elaborate a detailed report in which the activity profile assigned to adequately monitor the client's transactions will be included and all elements that have been considered will be explicit.
considered to determine said profile. The report must be adequately supported by documentation that allows establishing the patrimonial, economic, and financial situation or justifying the origin of the funds managed by the client. To this end, there must be accounting statements with a Public Accountant's report, tax returns, responsibility statements, minutes of profit distribution, sales contracts, or other documentation that allows compliance with the aforementioned provisions.
Notwithstanding the foregoing, in all cases, copies of sworn declarations or equivalent documentation submitted to the corresponding tax authority must be available.
In the case of persons included in item a) whose annual transactions, according to their activity profile, reach amounts less than USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or who carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the patrimonial, economic, and financial situation or justifying the origin of the funds managed by the client will be required.
To determine said threshold, the accumulated volume of transactions will be considered.
iii. increase the frequency of updating client information.
iv. carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
ARTICLE 206.13 (POLITICALLY EXPOSED PERSONS).
A "politically exposed person" is understood to be a person who holds or has held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, high-ranking government, judicial, or military officials, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and senior executives of state-owned companies and other public entities.
Politically exposed persons are also understood to be those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: members of senior management, directors, deputy directors, board members, or equivalent functions.
Crowdfunding platform administrator companies must have procedures that allow them to determine when a client or beneficial owner is a politically exposed person, a family member, or a close associate of a politically exposed person.
In the case of having clients who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures established in Article 206.5, institutions must carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
The enhanced due diligence procedures established in items i. to iv. of Article 206.11 shall apply to foreign politically exposed persons. Likewise, said procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 206.15 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES).
The use of third-party services to carry out the required due diligence procedures will require authorization from the Superintendency of Financial Services, which may be granted expressly or tacitly.
In particular, the hiring of third parties to carry out the monitoring of accounts and transactions in order to detect unusual or suspicious patterns in client behavior will require express authorization in all cases.
Companies providing outsourced services will be subject, regarding those activities, to the same rules that govern when they are fulfilled by the controlled entities, with the exception of those of a sanctioning nature, and will be obliged to apply the client due diligence procedures established by the institution.
Crowdfunding platform administrator companies will maintain at all times the final responsibility for the adequate identification, knowledge, and monitoring of the same, verifying the adequate application of their procedures to clients whose due diligence is carried out by a third party. They must obtain and conserve the information and documentation related to the identification and knowledge of the client in all cases, as if the due diligence procedures had been completed directly by them. Likewise, the institution must conserve the alerts generated by the account and transaction monitoring systems, as well as the analysis thereof.
Outsourcing of due diligence procedures with clients that comply with the aforementioned provisions and the requirements detailed below are considered authorized:
a. The third party providing the service must be registered with the supervisory body of its country to carry out financial activities, and be regulated and supervised or monitored by it, especially regarding the application of client due diligence procedures and record keeping, in accordance with international standards in the matter.
b. The third party providing the service must be located in a country that is not subject to special measures by the Financial Action Task Force (FATF) and is not included in the list of countries failing to meet transparency and cooperation criteria in fiscal matters issued by the Organization for Economic Co-operation and Development (OECD).
c. The services to be outsourced must be detailed in a contract between the parties, which must contain, at a minimum, the following clauses:
The information and documentation mentioned in items b.2 to b.4 must be consistent with those required by the crowdfunding platform administrator company for the rest of its clients, according to their profile.
d. Crowdfunding platform administrator companies must:
The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution.
ARTICLE 207.7 (ENHANCED DUE DILIGENCE PROCEDURES).
Investment advisors and portfolio managers must apply enhanced due diligence procedures for categories of clients, commercial relationships, or operations considered of higher risk, according to what arises from the risk assessment carried out by the institution.
Notwithstanding, the following will be considered of higher risk:
In application of the enhanced due diligence procedures, investment advisors and portfolio managers must:
i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client.
ii. elaborate a detailed report in which the activity profile assigned to adequately monitor the client's transactions will be included, and all elements that have been considered to determine said profile will be explicit. The report must be adequately supported by documentation that allows establishing the patrimonial, economic, and financial situation or justifying the origin of the funds managed by the client. To this end, there must be accounting statements with a Public Accountant's report, tax returns, responsibility statements, minutes of profit distribution, sales contracts, or other documentation that allows compliance with the aforementioned provisions.
Notwithstanding the foregoing, in all cases, copies of sworn declarations or equivalent documentation submitted to the corresponding tax authority must be available.
This requirement is exempted when it concerns referencing, advisory, and portfolio management services provided to non-resident clients of foreign financial institutions that are subject to regulation and supervision, provided that:
In the case of persons included in item b) whose annual transactions, according to their activity profile, reach amounts less than USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or who carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the patrimonial, economic, and financial situation or justifying the origin of the funds managed by the client will be required.
To determine said threshold, the accumulated volume of transactions will be considered.
iii. increase the frequency of updating client information.
iv. carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
ARTICLE 207.9 (POLITICALLY EXPOSED PERSONS).
A "politically exposed person" is understood to be a person who holds or has held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, high-ranking government, judicial, or military officials, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and senior executives of state-owned companies and other public entities.
Politically exposed persons are also understood to be those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: members of senior management, directors, deputy directors, board members, or equivalent functions.
Investment advisors and portfolio managers must have procedures that allow them to determine when a client or beneficial owner is a politically exposed person, a family member, or a close associate of a politically exposed person.
In the case of having clients who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures established in Article 207.3, institutions must carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
The enhanced due diligence procedures established in items i. to iv. of Article 207.7 shall apply to foreign politically exposed persons. Likewise, said procedures shall apply to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 207.9.1 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES).
The use of third-party services to carry out the required due diligence procedures will require authorization from the Superintendency of Financial Services, which may be granted expressly or tacitly.
In particular, the hiring of third parties to carry out the monitoring of accounts and transactions in order to detect unusual or suspicious patterns in client behavior will require express authorization in all cases.
Companies providing outsourced services will be subject, regarding those activities, to the same rules that govern when they are fulfilled by the controlled entities, with the exception of those of a sanctioning nature, and will be obliged to apply the client due diligence procedures established by the institution.
Investment advisors and portfolio managers will maintain at all times the final responsibility for the adequate identification, knowledge, and monitoring of the same, verifying the adequate application of their procedures to clients whose due diligence is carried out by a third party. They must obtain and conserve the information and documentation related to the identification and knowledge of the client in all cases, as if the due diligence procedures had been completed directly by them. Likewise, the institution must conserve the alerts generated by the account and transaction monitoring systems, as well as the analysis thereof.
Outsourcing of due diligence procedures with clients that comply with the aforementioned provisions and the requirements detailed below are considered authorized:
The third party providing the service must be registered with the supervisory body of its country to carry out financial activities, and be regulated and supervised or monitored by it, especially regarding the application of client due diligence procedures and record keeping, in accordance with international standards in the matter.
The third party providing the service must be located in a country that is not subject to special measures by the Financial Action Task Force (FATF) and is not included in the list of countries failing to meet transparency and cooperation criteria in fiscal matters issued by the Organization for Economic Co-operation and Development (OECD).
The services to be outsourced must be detailed in a contract between the parties, which must contain, at a minimum, the following clauses:
The information and documentation mentioned in items c.2 to c.4 must be consistent with those required by the investment advisor and portfolio manager for the rest of their clients, according to their profile.
d. Investment advisors and portfolio managers must:
The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution.
ARTICLE 16.1.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 16.1 may be granted expressly or tacitly according to the following provisions:
The authorization request must be accompanied by the text of the service contract to be signed and a report stating the evaluation of risks associated with the outsourcing, including the assessment of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 16.1.2. Once the authorization is granted, the aforementioned report must be kept in the institution's offices at the disposal of the Superintendence of Financial Services and updated periodically based on the results of the risk assessment carried out regarding the outsourcing.
The authorization will refer only to the specific service that is the subject of the request and will be granted without prejudice to the registration of databases and authorizations for the international transfer of personal data that may correspond before the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Information and Knowledge Society.
Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated requirements are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with instructions issued by the Superintendence of Financial Services.
The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services will be borne by the supervised institution.
The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated above.
Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is provided in item 1) letter e) of the aforementioned article to be considered authorized.
For the purposes of outsourcings that imply data processing, the provisions of articles 16.2 and 16.3 will also apply.
The authorization for the use of third-party services to carry out due diligence procedures will be governed by the provisions of article 79.
The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 77 (ENHANCED DUE DILIGENCE PROCEDURES). Companies must apply enhanced due diligence procedures for categories of clients, commercial relationships, or operations considered to be of higher risk, according to what arises from the risk assessment carried out by the institution.
However, the following will be considered to be of higher risk:
transactions by persons who link with the entity through operations where personal contact is not usual, such as clients who carry out operations through operational modalities that, using new or developing technologies, may favor client anonymity.
commercial relationships and operations with non-resident clients coming from countries that do not comply with international standards in matters of money laundering, terrorist financing, and financing of the proliferation of weapons of mass destruction.
foreign politically exposed persons, as well as their family members and close associates.
all operations carried out under unusual circumstances according to the customs and practices of the respective activity.
clients who have contracted life insurance with an annual premium greater than USD 10,000 (ten thousand US dollars) or its equivalent in other currencies and those with a single premium greater than USD 200,000 (two hundred thousand US dollars) or its equivalent in other currencies.
surety bonds that present unusual complexity in their structuring or when any of the parties is a non-resident person.
In application of enhanced due diligence procedures, companies must:
obtain approval from the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client.
craft a detailed report in which the activity profile assigned to adequately monitor the client's transactions will be included, and all elements considered to determine said profile will be explicitly stated. The report must be adequately backed by documentation that allows establishing the financial, economic, and patrimonial situation or justifying the origin of the funds managed by the client. For these purposes, accounting statements with a Public Accountant's report, tax returns, liability statements, minutes of profit distribution, sales contracts, or other documentation that allows complying with the aforementioned must be available.
However, in all cases, copies of sworn declarations or equivalent documentation presented to the corresponding tax administration must be available, in the case of clients who have contracted life insurance under the terms of letter e).
In the case of persons included in letter c) whose annual transactions, according to their activity profile, reach amounts less than USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the financial, economic, and patrimonial situation or justifying the origin of the funds managed by the client will be required.
To determine said threshold, the accumulated volume of transactions will be considered.
increase the frequency of updating client information.
carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
ARTICLE 78.1 (POLITICALLY EXPOSED PERSONS). "Politically exposed persons" are understood to be persons who hold or have held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, high-ranking government, judicial, or military officials, representatives and senators of the Legislative Power, prominent leaders of political parties, directors and high executives of state-owned companies and other public institutions.
Politically exposed persons are also understood to be those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: senior management members, directors, deputy directors, board members, or equivalent functions.
Companies must have procedures that allow them to determine when a client or beneficial owner is a politically exposed person, a family member, or a close associate of a politically exposed person.
In the case of having clients who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures established in article 72, institutions must carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied.
Enhanced due diligence procedures established in items i. to iv. of article 77 will apply to foreign politically exposed persons. Likewise, said procedures must be applied to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.
ARTICLE 79 (SERVICES PROVIDED BY THIRD PARTIES FOR DUE DILIGENCE PROCEDURES). The use of third-party services to carry out due diligence procedures will require authorization from the Superintendence of Financial Services, which may be granted expressly or tacitly.
In particular, the contracting of third parties for the monitoring of accounts and transactions to detect unusual or suspicious patterns in client behavior will require express authorization in all cases.
Companies providing outsourced services will be subject, regarding these activities, to the same rules that govern when they are fulfilled by the controlled entities, with the exception of those of a sanctioning nature.
The institution will maintain at all times the final responsibility for the adequate identification, knowledge, and monitoring of the same, and must verify the adequate application of its procedures to clients whose due diligence is carried out by a third party.
Third parties will be obliged to apply the client due diligence procedures established by the institution.
The institution must obtain and conserve the information and documentation regarding the identification and knowledge of the client in all cases, as if the due diligence procedures had been completed directly by it. Likewise, the institution must conserve the alerts generated by the account and transaction monitoring systems, as well as the analysis thereof.
The following outsourcings of due diligence procedures with clients who comply with the aforementioned provisions and the requirements detailed below are considered authorized:
a. The third party providing the service may be an insurance intermediary in the country with which the insurance or reinsurance company maintains links, or a third party that must be registered with the control body of its country to carry out financial activities, and be regulated and supervised or monitored by it, especially regarding compliance with client due diligence requirements and record maintenance, in accordance with international standards in the matter.
b. The third party providing the service must be located in a country that is not subject to special measures by the Financial Action Task Force (FATF) and is not included in the list of countries that do not meet transparency and cooperation criteria in fiscal matters issued by the Organisation for Economic Co-operation and Development (OECD).
c. The services to be outsourced must be detailed in a contract between the parties, which must contain, at a minimum, the following clauses:
c.1. the obligation of the contracted third party to verify the identity of the potential client or, failing that, to establish that such verification will be carried out by the institution itself.
c.2. the necessary documentation to verify the client's identity.
c.3. the financial information and documentation that the third party must collect to obtain adequate knowledge of the economic activity developed by the potential client, and the manner in which it will be verified.
c.4. the documentation that the client must complete and sign once accepted (contracts, client knowledge forms for new links or information updates, etc.).
c.5. the obligation of the contracted third party to inform the potential client that no commercial link will be initiated until the entity formally accepts it.
c.6. commitments of confidentiality and personal data protection.
c.7. prohibition of subcontracting.
The information and documentation mentioned in letters c.2 to c.4 must be consistent with those required by the institution for the rest of its clients, according to their profile.
d. The institution must:
keep in its offices the contracts celebrated with the company in which the services were outsourced, as well as sufficient and updated information that accredits the suitability and background of the contracted third party, as well as a declaration by the latter regarding the personnel who will carry out the due diligence, accrediting that they know the current regulation in matters of prevention of money laundering, terrorist financing, and financing of the proliferation of weapons of mass destruction applicable to the contracting institution and the due diligence procedures to be applied.
The aforementioned information and documentation must be updated at least every 2 (two) years.
have a list of clients whose due diligence was carried out by a third party.
The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services will be borne by the supervised institution.
ARTICLE 30.1.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in article 30.1 may be granted expressly or tacitly according to the following provisions:
The authorization request must be accompanied by the text of the service contract to be signed and a report stating the evaluation of risks associated with the outsourcing, including the assessment of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of art. 30.1.2. Once the authorization is granted, the aforementioned report must be kept in the institution's offices at the disposal of the Superintendence of Financial Services and updated periodically based on the results of the risk assessment carried out regarding the outsourcing.
The authorization will refer only to the specific service that is the subject of the request and will be granted without prejudice to the registration of databases and authorizations for the international transfer of personal data that may correspond before the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Information and Knowledge Society.
Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request. The granted authorization may be revoked if deviations from the indicated requirements are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with instructions issued by the Superintendence of Financial Services.
The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services will be borne by the supervised institution.
The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized. Additionally, if deemed necessary, the Superintendence of Financial Services may request additional information to that indicated above.
Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is provided in item 1) letter e) of the aforementioned article to be considered authorized.
For the purposes of outsourcings that imply data processing, the provisions of articles 30.1.3 and 30.1.4 will also apply.
The contracting of promoters will be governed by the provisions of article 11.
The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.
JUAN PEDRO CANTERA Superintendent of Financial Services
More like this from BCU
We email you every new BCU publication the day it's published.