2020-04-28
Added · Updated
The document establishes mandatory due diligence procedures for banks and payment service providers regarding prepaid card customers, requiring identity verification through official documents such as national ID cards or passports. It mandates the identification of beneficial owners for corporate clients and small enterprises, specifying thresholds for verifying ownership structures and managing risks associated with politically exposed persons. The circular also outlines policies for customer acceptance, risk-based monitoring, and the use of third-party service providers for identity checks.
1 Due diligence procedures for prepaid card service customers Issued March 2020 Table of Contents
| Introduction | ||
|---|---|---|
| 3 : | -1 Terminology | |
| 4 | -2 Scope of | |
| Application | ||
| These procedures | ||
| 5 | -3 Use of | |
| Service | ||
| Providers for | ||
| Identification | ||
| and Verification | ||
| of Customer | ||
| Identity | ||
| 6 | -4 Customer | |
| Acceptance | ||
| Policy | ||
| 8 | -5 Identification | |
| and | ||
| Verification of | ||
| Customer | ||
| Identity | ||
| 9 | .1.5 General | |
| Provisions | ||
| 9 : | .2.5 | |
| Identification | ||
| and | ||
| Verification | ||
| Procedures for | ||
| Natural Person | ||
| Customers | ||
| 11 | .3.5 | |
| Identification | ||
| and | ||
| Verification | ||
| Procedures for | ||
| Corporate and | ||
| Micro Enterprise | ||
| Customers | ||
| 12 | -6 Data | |
| Retention | ||
| 14 | -7 Supervision | |
| of Operations | ||
| 15 | -8 Internal | |
| Control | ||
| Mechanisms for | ||
| Money | ||
| Laundering and | ||
| Terrorist | ||
| Financing | ||
| 15 | .1.8 Risk | |
| Assessment | ||
| 15 | .2.8 Limitations | |
| on | ||
| Risks | ||
| 16 | -9 Monitoring | |
| of | ||
| Transactions | ||
| 16 | .1.9 | |
| Suspicious | ||
| Transaction | ||
| Reporting | ||
| 16 | .2.9 Automatic | |
| Transaction | ||
| Monitoring | ||
| Systems | ||
| 17 | .3.9 | |
| Cases where | ||
| Banks and | ||
| Payment | ||
| Service | ||
| Providers are | ||
| Exempted from | ||
| Transaction | ||
| Monitoring | ||
| 18 | Annex: Internal | |
| Control | ||
| Mechanisms for | ||
| Money | ||
| Laundering and | ||
| Terrorist | ||
| Financing in | ||
| Payment | ||
| Services via | ||
| Prepaid Cards | ||
| 16 |
The Central Bank of Tunisia has issued this circular to update the regulatory framework governing prepaid card services, aiming to align with international standards set by the Financial Action Task Force (FATF) and local legislation, including Law No. 2015-27 on combating money laundering and terrorist financing. This document updates previous guidelines issued in 2011 to reflect changes in technology and risk profiles.
These procedures apply to all banks and payment service providers offering prepaid card services. They mandate strict due diligence measures, including customer identification, verification, and ongoing monitoring, to prevent the misuse of prepaid cards for illicit activities.
The circular emphasizes the importance of risk-based approaches, requiring institutions to assess and mitigate risks associated with different types of customers and transactions. It also outlines specific requirements for identifying beneficial owners and handling politically exposed persons.
Furthermore, the document addresses the use of third-party service providers for customer identification and verification, ensuring that such arrangements do not compromise compliance obligations. It reinforces the responsibility of banks and payment service providers to maintain robust internal controls and reporting mechanisms.
This circular is effective immediately and supersedes any conflicting provisions in previous regulations. Institutions are required to implement these measures promptly and report any non-compliance issues to the Central Bank.
For the purposes of these procedures, the following terms shall have the meanings assigned to them below wherever they appear:
Service: The provision of prepaid card services by banks and payment service providers.
Beneficial Owner: The natural person(s) who ultimately owns or controls the customer and/or on whose behalf a transaction is being conducted. It also includes the natural person(s) exercising ultimate effective control over a legal person or arrangement.
Unit: The bank or payment service provider subject to these procedures.
Service Provider: An entity authorized to provide prepaid card services under the supervision of the Central Bank of Tunisia.
Due Diligence Procedures for Banking Customers: Refers to the procedures outlined in Circular No. 2011-01 and its subsequent amendments.
Micro Enterprises and Small Businesses: Entities defined as micro-enterprises or small businesses according to Tunisian law.
Negative Lists: Lists of individuals and entities identified by the United Nations Security Council Resolutions 1267 (1999), 1373 (2001), and others related to terrorism and proliferation, which must be screened against.
Freezing of Assets: The prohibition of making funds or economic resources available, directly or indirectly, to or for the benefit of designated persons or entities.
Specialized Employee: The employee designated within the unit to ensure compliance with anti-money laundering and counter-terrorist financing regulations and to liaise with relevant authorities.
2.1. These procedures apply to all banks and payment service providers authorized to offer prepaid card services in Tunisia. They cover the issuance, management, and operation of prepaid cards.
2.2. These procedures also apply to foreign branches and subsidiaries of banks operating in Tunisia, particularly those engaged in cross-border transactions. However, local laws may impose additional requirements.
2.3. For individual customers using prepaid cards for personal use, simplified due diligence measures may apply, provided the transaction limits and usage patterns do not pose significant risks. However, enhanced due diligence is required if suspicious activity is detected.
2.4. These procedures do not exempt banks or payment service providers from their general obligations under anti-money laundering and counter-terrorist financing laws. Institutions must still conduct risk assessments and implement appropriate controls.
2.5. These procedures apply to all employees of banks and payment service providers involved in the issuance and management of prepaid cards.
3.1. If a bank or payment service provider uses a third-party service provider for customer identification and verification, it remains fully responsible for compliance with these procedures. The third party must meet the following criteria:
3.1.1. Must be licensed and regulated under applicable laws, such as Law No. 2015-27 on combating money laundering and terrorist financing.
3.1.2. Must have adequate systems and controls in place to ensure accurate identification and verification.
3.1.3. Must comply with data protection and privacy laws.
3.1.4. In the case of corporate customers or entities, the third party must verify the legal status and ownership structure.
3.1.5. The bank or payment service provider must have a written agreement with the third party outlining responsibilities and liabilities.
3.1.6. The third party must be able to provide immediate access to customer identification data upon request by the bank or payment service provider.
3.1.7. The bank or payment service provider must conduct regular audits of the third party's compliance with these procedures.
3.2. If a bank or payment service provider uses a third-party service provider, it must ensure that:
3.2.1. The third party complies with all relevant anti-money laundering and counter-terrorist financing regulations.
3.2.2. The bank or payment service provider can obtain customer identification data immediately when needed.
3.2.3. The third party maintains records of customer identification and verification for at least five years.
3.2.4. The bank or payment service provider retains ultimate responsibility for compliance.
3.2.5. The bank or payment service provider conducts periodic reviews of the third party's performance and compliance.
3.2.6. The bank or payment service provider has mechanisms to address any failures or breaches by the third party.
3.2.7. The bank or payment service provider ensures that the third party does not subcontract its duties without prior approval.
3.2.8. The bank or payment service provider verifies that the third party has adequate training and resources.
3.2.9. The bank or payment service provider monitors the third party's adherence to risk management practices.
3.2.10. The bank or payment service provider reports any issues with the third party to the relevant authorities.
3.2.11. The bank or payment service provider ensures that the third party cooperates with investigations and requests from authorities.
3.2.12. The bank or payment service provider maintains a record of all agreements and communications with the third party.
3.2.13. The bank or payment service provider conducts annual reviews of the third party's compliance status.
3.2.14. The bank or payment service provider ensures that the third party implements necessary updates to regulations.
3.2.15. The bank or payment service provider ensures that the third party provides timely notifications of any changes in customer information.
4.1. Banks and payment service providers must establish and implement a customer acceptance policy that defines the types of customers they are willing to serve. This policy should consider the risk profile of the customer and the nature of the prepaid card services offered.
4.2. The policy must include criteria for rejecting customers who pose a high risk of money laundering or terrorist financing. This includes customers listed on negative lists or those associated with sanctioned countries.
4.3. Banks and payment service providers must regularly review and update their customer acceptance policies to reflect changes in risk assessments and regulatory requirements.
4.4. The policy must be approved by the board of directors or senior management and communicated to all relevant staff.
4.5. Banks and payment service providers must maintain records of all customer acceptance decisions and the rationale behind them.
5.1.1. Banks and payment service providers must implement a risk-based approach to customer identification and verification, taking into account the type of customer, the nature of the prepaid card services, and the potential risks involved.
5.1.2. Banks and payment service providers must identify and verify the identity of their customers before issuing prepaid cards or conducting transactions.
5.1.3. Identification and verification must be based on reliable, independent source documents, data, or information.
5.1.4. If there is doubt about the reliability of the identification documents, banks and payment service providers must take additional steps to verify the customer's identity, such as requesting supplementary documents or conducting face-to-face meetings.
5.1.5. Banks and payment service providers must identify the beneficial owner of the customer and take reasonable measures to verify their identity.
5.1.6. For corporate customers, banks and payment service providers must identify and verify the identity of the legal representatives and authorized signatories.
5.1.7. For corporate customers, banks and payment service providers must identify and verify the identity of the beneficial owners, including natural persons who own or control more than 25% of the shares or voting rights.
5.1.8. For corporate customers, banks and payment service providers must identify and verify the identity of the beneficial owners, including natural persons who exercise ultimate control over the entity.
5.1.9. For corporate customers, banks and payment service providers must identify and verify the identity of the beneficial owners, including natural persons who are members of the senior management.
5.1.10. Banks and payment service providers must keep records of all identification and verification activities for at least five years after the business relationship ends.
5.1.11. Banks and payment service providers must ensure that all staff involved in customer identification and verification are trained and competent.
5.1.12. Banks and payment service providers must have procedures in place to handle cases where customer identification or verification cannot be completed.
5.1.13. Banks and payment service providers must report any suspicious activities related to customer identification or verification to the relevant authorities.
5.1.14. Banks and payment service providers must ensure that customer identification and verification processes are secure and protected against unauthorized access.
5.1.15. Identification and Verification Procedures for Natural Person Customers
Banks and payment service providers must collect the following information from natural person customers:
5.2.2.1. Banks and payment service providers must verify the identity of natural person customers using reliable, independent source documents, data, or information. This includes checking the authenticity of identification documents such as national ID cards, passports, or driver's licenses.
5.2.2.2. If the identification documents are not available or cannot be verified, banks and payment service providers must use alternative methods, such as video conferencing or in-person verification, to confirm the customer's identity.
Banks and payment service providers must collect the following information from corporate and micro enterprise customers:
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 42,468-character original (57% of the document). The remainder was not translated. The complete original-language text is stored with this document.]