2020-04-28

Added · Updated

Circular on Due Diligence Procedures for Prepaid Card Service Customers (March 2020)

The document establishes mandatory due diligence procedures for banks and payment service providers regarding prepaid card customers, requiring identity verification through official documents such as national ID cards or passports. It mandates the identification of beneficial owners for corporate clients and small enterprises, specifying thresholds for verifying ownership structures and managing risks associated with politically exposed persons. The circular also outlines policies for customer acceptance, risk-based monitoring, and the use of third-party service providers for identity checks.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

1 Due diligence procedures for prepaid card service customers Issued March 2020 Table of Contents

Introduction
3 :-1 Terminology
4-2 Scope of
Application
These procedures
5-3 Use of
Service
Providers for
Identification
and Verification
of Customer
Identity
6-4 Customer
Acceptance
Policy
8-5 Identification
and
Verification of
Customer
Identity
9.1.5 General
Provisions
9 :.2.5
Identification
and
Verification
Procedures for
Natural Person
Customers
11.3.5
Identification
and
Verification
Procedures for
Corporate and
Micro Enterprise
Customers
12-6 Data
Retention
14-7 Supervision
of Operations
15-8 Internal
Control
Mechanisms for
Money
Laundering and
Terrorist
Financing
15.1.8 Risk
Assessment
15.2.8 Limitations
on
Risks
16-9 Monitoring
of
Transactions
16.1.9
Suspicious
Transaction
Reporting
16.2.9 Automatic
Transaction
Monitoring
Systems
17.3.9
Cases where
Banks and
Payment
Service
Providers are
Exempted from
Transaction
Monitoring
18Annex: Internal
Control
Mechanisms for
Money
Laundering and
Terrorist
Financing in
Payment
Services via
Prepaid Cards
16

Introduction:

The Central Bank of Tunisia has issued this circular to update the regulatory framework governing prepaid card services, aiming to align with international standards set by the Financial Action Task Force (FATF) and local legislation, including Law No. 2015-27 on combating money laundering and terrorist financing. This document updates previous guidelines issued in 2011 to reflect changes in technology and risk profiles.

These procedures apply to all banks and payment service providers offering prepaid card services. They mandate strict due diligence measures, including customer identification, verification, and ongoing monitoring, to prevent the misuse of prepaid cards for illicit activities.

The circular emphasizes the importance of risk-based approaches, requiring institutions to assess and mitigate risks associated with different types of customers and transactions. It also outlines specific requirements for identifying beneficial owners and handling politically exposed persons.

Furthermore, the document addresses the use of third-party service providers for customer identification and verification, ensuring that such arrangements do not compromise compliance obligations. It reinforces the responsibility of banks and payment service providers to maintain robust internal controls and reporting mechanisms.

This circular is effective immediately and supersedes any conflicting provisions in previous regulations. Institutions are required to implement these measures promptly and report any non-compliance issues to the Central Bank.

-1 Terminology

For the purposes of these procedures, the following terms shall have the meanings assigned to them below wherever they appear:

Service: The provision of prepaid card services by banks and payment service providers.

Beneficial Owner: The natural person(s) who ultimately owns or controls the customer and/or on whose behalf a transaction is being conducted. It also includes the natural person(s) exercising ultimate effective control over a legal person or arrangement.

Unit: The bank or payment service provider subject to these procedures.

Service Provider: An entity authorized to provide prepaid card services under the supervision of the Central Bank of Tunisia.

Due Diligence Procedures for Banking Customers: Refers to the procedures outlined in Circular No. 2011-01 and its subsequent amendments.

Micro Enterprises and Small Businesses: Entities defined as micro-enterprises or small businesses according to Tunisian law.

Negative Lists: Lists of individuals and entities identified by the United Nations Security Council Resolutions 1267 (1999), 1373 (2001), and others related to terrorism and proliferation, which must be screened against.

Freezing of Assets: The prohibition of making funds or economic resources available, directly or indirectly, to or for the benefit of designated persons or entities.

Specialized Employee: The employee designated within the unit to ensure compliance with anti-money laundering and counter-terrorist financing regulations and to liaise with relevant authorities.

-2 Scope of Application

2.1. These procedures apply to all banks and payment service providers authorized to offer prepaid card services in Tunisia. They cover the issuance, management, and operation of prepaid cards.

2.2. These procedures also apply to foreign branches and subsidiaries of banks operating in Tunisia, particularly those engaged in cross-border transactions. However, local laws may impose additional requirements.

2.3. For individual customers using prepaid cards for personal use, simplified due diligence measures may apply, provided the transaction limits and usage patterns do not pose significant risks. However, enhanced due diligence is required if suspicious activity is detected.

2.4. These procedures do not exempt banks or payment service providers from their general obligations under anti-money laundering and counter-terrorist financing laws. Institutions must still conduct risk assessments and implement appropriate controls.

2.5. These procedures apply to all employees of banks and payment service providers involved in the issuance and management of prepaid cards.

-3 Use of Service Providers for Identification and Verification of Customer Identity

3.1. If a bank or payment service provider uses a third-party service provider for customer identification and verification, it remains fully responsible for compliance with these procedures. The third party must meet the following criteria:

3.1.1. Must be licensed and regulated under applicable laws, such as Law No. 2015-27 on combating money laundering and terrorist financing.

3.1.2. Must have adequate systems and controls in place to ensure accurate identification and verification.

3.1.3. Must comply with data protection and privacy laws.

3.1.4. In the case of corporate customers or entities, the third party must verify the legal status and ownership structure.

3.1.5. The bank or payment service provider must have a written agreement with the third party outlining responsibilities and liabilities.

3.1.6. The third party must be able to provide immediate access to customer identification data upon request by the bank or payment service provider.

3.1.7. The bank or payment service provider must conduct regular audits of the third party's compliance with these procedures.

3.2. If a bank or payment service provider uses a third-party service provider, it must ensure that:

3.2.1. The third party complies with all relevant anti-money laundering and counter-terrorist financing regulations.

3.2.2. The bank or payment service provider can obtain customer identification data immediately when needed.

3.2.3. The third party maintains records of customer identification and verification for at least five years.

3.2.4. The bank or payment service provider retains ultimate responsibility for compliance.

3.2.5. The bank or payment service provider conducts periodic reviews of the third party's performance and compliance.

3.2.6. The bank or payment service provider has mechanisms to address any failures or breaches by the third party.

3.2.7. The bank or payment service provider ensures that the third party does not subcontract its duties without prior approval.

3.2.8. The bank or payment service provider verifies that the third party has adequate training and resources.

3.2.9. The bank or payment service provider monitors the third party's adherence to risk management practices.

3.2.10. The bank or payment service provider reports any issues with the third party to the relevant authorities.

3.2.11. The bank or payment service provider ensures that the third party cooperates with investigations and requests from authorities.

3.2.12. The bank or payment service provider maintains a record of all agreements and communications with the third party.

3.2.13. The bank or payment service provider conducts annual reviews of the third party's compliance status.

3.2.14. The bank or payment service provider ensures that the third party implements necessary updates to regulations.

3.2.15. The bank or payment service provider ensures that the third party provides timely notifications of any changes in customer information.

-4 Customer Acceptance Policy

4.1. Banks and payment service providers must establish and implement a customer acceptance policy that defines the types of customers they are willing to serve. This policy should consider the risk profile of the customer and the nature of the prepaid card services offered.

4.2. The policy must include criteria for rejecting customers who pose a high risk of money laundering or terrorist financing. This includes customers listed on negative lists or those associated with sanctioned countries.

4.3. Banks and payment service providers must regularly review and update their customer acceptance policies to reflect changes in risk assessments and regulatory requirements.

4.4. The policy must be approved by the board of directors or senior management and communicated to all relevant staff.

4.5. Banks and payment service providers must maintain records of all customer acceptance decisions and the rationale behind them.

-5 Identification and Verification of Customer Identity

5.1 General Provisions:

5.1.1. Banks and payment service providers must implement a risk-based approach to customer identification and verification, taking into account the type of customer, the nature of the prepaid card services, and the potential risks involved.

5.1.2. Banks and payment service providers must identify and verify the identity of their customers before issuing prepaid cards or conducting transactions.

5.1.3. Identification and verification must be based on reliable, independent source documents, data, or information.

5.1.4. If there is doubt about the reliability of the identification documents, banks and payment service providers must take additional steps to verify the customer's identity, such as requesting supplementary documents or conducting face-to-face meetings.

5.1.5. Banks and payment service providers must identify the beneficial owner of the customer and take reasonable measures to verify their identity.

5.1.6. For corporate customers, banks and payment service providers must identify and verify the identity of the legal representatives and authorized signatories.

5.1.7. For corporate customers, banks and payment service providers must identify and verify the identity of the beneficial owners, including natural persons who own or control more than 25% of the shares or voting rights.

5.1.8. For corporate customers, banks and payment service providers must identify and verify the identity of the beneficial owners, including natural persons who exercise ultimate control over the entity.

5.1.9. For corporate customers, banks and payment service providers must identify and verify the identity of the beneficial owners, including natural persons who are members of the senior management.

5.1.10. Banks and payment service providers must keep records of all identification and verification activities for at least five years after the business relationship ends.

5.1.11. Banks and payment service providers must ensure that all staff involved in customer identification and verification are trained and competent.

5.1.12. Banks and payment service providers must have procedures in place to handle cases where customer identification or verification cannot be completed.

5.1.13. Banks and payment service providers must report any suspicious activities related to customer identification or verification to the relevant authorities.

5.1.14. Banks and payment service providers must ensure that customer identification and verification processes are secure and protected against unauthorized access.

5.1.15. Identification and Verification Procedures for Natural Person Customers

5.2.1 Obtaining Necessary Information for Identification

Banks and payment service providers must collect the following information from natural person customers:

  • Full name.
  • Date of birth.
  • Nationality.
  • Gender.
  • Residential address.
  • Postal address (if different).
  • Phone number.
  • Email address.
  • Occupation.
  • Purpose of the account.
  • Source of funds.
  • Expected transaction volume.
  • Name of the person authorizing the account opening (if applicable).
  • Name of the person authorized to make transactions (if applicable).
  • Any other information deemed necessary by the bank or payment service provider.

5.2.2 Verification Procedures

5.2.2.1. Banks and payment service providers must verify the identity of natural person customers using reliable, independent source documents, data, or information. This includes checking the authenticity of identification documents such as national ID cards, passports, or driver's licenses.

5.2.2.2. If the identification documents are not available or cannot be verified, banks and payment service providers must use alternative methods, such as video conferencing or in-person verification, to confirm the customer's identity.

5.3 Identification and Verification Procedures for Corporate and Micro Enterprise Customers

5.3.1 Obtaining Necessary Information for Identification

Banks and payment service providers must collect the following information from corporate and micro enterprise customers:

  • Legal name of the entity.
  • Registration number.
  • Legal form.
  • Registered address.
  • Principal place of business.
  • Nature of business.
  • Names and details of directors and shareholders.
  • Names and details of beneficial owners.
  • Authorized signatories.
  • Purpose of the account.
  • Source of funds.
  • Expected transaction volume.
  • Any other information deemed necessary by the bank or payment service provider.

[RegAlert note: the English text above is a translation of the first 24,000 characters of a 42,468-character original (57% of the document). The remainder was not translated. The complete original-language text is stored with this document.]