2019-12-05
Added · Updated
CVM Resolution 50 establishes the regulatory framework for the prevention of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction (PLD/FTP) within the Brazilian securities market, revoking Instruction CVM No. 617/2019. It mandates that covered entities—including securities distributors, market administrators, and independent auditors—implement a risk-based PLD/FTP policy, conduct internal risk assessments, and maintain robust internal controls, client identification, and monitoring procedures. The resolution requires the appointment of a compliance director to submit an annual risk assessment report to the CVM by the last business day of April and defines specific obligations for identifying beneficial owners and reporting suspicious transactions to the Financial Activities Control Council (COAF).
SECURITIES AND EXCHANGES COMMISSION OF BRAZIL (CVM) Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – ZIP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – ZIP: 01333-010 – Brazil - Tel.: (11) 2146-2000 SCN Q.02 – Bl. A – Ed. Corporate Financial Center, S.404/4th Floor, Brasília/DF – ZIP: 70712-900 – Brazil - Tel.: (61) 3327-2030/2031 www.cvm.gov.br
CVM RESOLUTION NO. 50, OF AUGUST 31, 2021, WITH AMENDMENTS INTRODUCED BY CVM RESOLUTIONS NO. 179/23 AND 245/26.
Provides for the prevention of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction – PLD/FTP within the securities market and revokes CVM Instruction No. 617, of December 5, 2019, and the Explanatory Note to CVM Instruction No. 617, of December 5, 2019.
THE PRESIDENT OF THE SECURITIES AND EXCHANGES COMMISSION OF BRAZIL – CVM makes public that the Board, in a meeting held on August 25, 2021, in view of Laws No. 6,385, of December 7, 1976, 9,613, of March 3, 1998, 13,260, of March 16, 2016, and 13,810, of March 8, 2019, as well as Decree No. 5,640, of December 26, 2005, APPROVED the following Resolution:
CHAPTER I – SCOPE, DEFINITIONS AND PURPOSE
Art. 1. The following are regulated by this Resolution: I – the establishment of the policy for the prevention of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction – PLD/FTP, the internal risk assessment, and rules, procedures, and internal controls; II – the identification and registration of clients, as well as continuous due diligence aimed at collecting supplementary information and, in particular, identifying their respective beneficial owners; III – the monitoring, analysis, and communication of the operations and situations mentioned in this Resolution; IV – the recording of operations and maintenance of files; and V – the implementation, within the securities market: a) measures aimed at the unavailability of assets, rights, and values resulting from resolutions of the United Nations Security Council – UNSC; and b) demands for international judicial cooperation arising from other jurisdictions in accordance with current national legislation and other legal provisions.
Art. 2. For the purposes of this Resolution, the following are considered:
I – senior management: the highest decision-making body or individuals comprising the administration, responsible for conducting its strategic affairs as provided in the PLD/FTP policy; II – foreign central authority: a body, entity, or public agent of a foreign jurisdiction responsible, according to its own legislation or international agreements, for centralizing the interlocution with other jurisdictions regarding the adoption of cooperation measures in matters of prevention and combat against terrorism, terrorist financing, and the financing of the proliferation of weapons of mass destruction; III – beneficial owner: natural person or natural persons who, together, own, control, or significantly influence, directly or indirectly, a client on whose behalf a transaction is being conducted or from which it benefits; IV – registration: the record, in physical or electronic media, of the information and identification documents of clients with whom the institution maintains a direct relationship due to the provision of services in the securities market; V – client: investor who maintains a direct commercial relationship with the persons mentioned in Art. 3 of this Resolution; VI – active client: the client who in the last 12 (twelve) months has: a) made movements in their checking account or in their custody position; b) carried out an operation in the securities market; or c) presented a balance in their custody position; VII – self-regulatory entity: entity responsible for the self-regulation of the organized markets referred to in the regulation that disciplines the regulated securities markets; VIII – financial market infrastructure operating entity: entity that performs, cumulatively or individually, the processing and settlement of operations, the registration, and the centralized deposit of securities; IX – significant influence: a situation in which a natural person, whether the controller or not, exercises de facto influence on decisions or is the holder of more than 25% (twenty-five percent) of the share capital of legal entities or of the equity of investment funds and other entities referred to in items II to V of Art. 1 of Annex B, without prejudice to the use of the simplified registration referred to in Annex C; X – investor: natural or legal person, fund, or collective investment vehicle or the non-resident investor on whose behalf operations with securities are carried out; XI – participant: legal person, fund, or investment vehicle to which an organized market administrator has granted authorization to act in the trading or registration environments or systems of the markets administered by it; and XII – trust or similar vehicle: any impersonal entity constituted by assets held under fiduciary title and gathered in a segregated estate, segregated from the general estate of the holder.
Sole Paragraph. For the purposes of this norm, the proxies, attorneys, or legal representatives of the beneficial owner are equivalent to the beneficial owner.
Art. 3. The following are subject to the obligations provided for in this Resolution, within the limits of their attributes: I – natural or legal persons who provide, in the securities market, on a permanent or occasional basis, services related to distribution, custody, intermediation, or portfolio administration; II – entities administering organized markets and financial market infrastructure operating entities; III – other persons referred to in specific regulation who provide services in the securities market, including: a) registrars; b) securities consultants; c) credit rating agencies; d) representatives of non-resident investors; and e) securitization companies; and IV – independent auditors within the securities market.
§ 1. This Resolution does not apply to securities analysts and public companies, unless they perform other activities covered by items I to IV of the caput.
§ 2. Institutions integrated into the securities distribution system must subject autonomous investment agents and other proxies linked to them to their respective PLD/FTP policy, as well as to the rules, procedures, and internal controls established in accordance with this Resolution.
§ 2. Institutions integrated into the securities distribution system must subject investment advisors and other proxies linked to them to their respective PLD/FTP policy, as well as to the rules, procedures, and internal controls established in accordance with this Resolution.
• § 2 with wording given by CVM Resolution No. 179, of February 14, 2023.
§ 3. The provisions of § 2 do not exempt the institutions integrated into the securities distribution system from responsibility for complying with the commands provided for in this Resolution.
CHAPTER II – PLD/FTP POLICY, INTERNAL RISK ASSESSMENT, AND RULES, PROCEDURES, AND INTERNAL CONTROLS
Section I – Policy for the Prevention of Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons of Mass Destruction
Art. 4. The legal persons mentioned in items I to III of Art. 3 of this Resolution must elaborate and implement a PLD/FTP policy containing, at a minimum: I – governance related to compliance with the obligations of this Resolution, including a detailed description of how the senior management bodies are structured, when applicable, as well as the definition of roles and assignment of responsibilities of members of each hierarchical level of the institution regarding the elaboration and implementation of the risk-based approach process, with special emphasis on the routines provided for in Arts. 17, 18, 20, 21, 22, and 23 of this Resolution; II – the description of the methodology for treating and mitigating identified risks, which must support the parameters established in the internal risk assessment, including the detailing of the guidelines: a) that underpinned the adopted risk-based approach; b) to continuously know:
§ 1. The policy referred to in the caput must be: I – documented; II – approved by senior management; and III – kept updated.
§ 2. The persons mentioned in items I and III of Art. 3 who belong to the same financial conglomerate must establish in the PLD/FTP policy mechanisms for information exchange between their internal control areas to ensure compliance with their obligations provided for in this article, considering the relevance of the risk identified in each case, in their internal risk assessment.
§ 3. The information exchange referred to in § 2 may include, whenever applicable and necessary, information about the client profile held by companies subject to specific regulation that provides for the duty of verifying the adequacy of products, services, and operations to the client profile.
§ 4. The PLD/FTP policy elaborated and implemented by independent auditors must cover, at a minimum, the content defined in specific regulation issued by the Federal Council of Accounting – CFC.
Section II – Internal Risk Assessment
Art. 5. The persons mentioned in items I to III of Art. 3 of this Resolution must, within the limits of their attributes, identify, analyze, understand, and mitigate the risks of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction – PLD/FTP, inherent to their activities performed in the securities market, adopting a risk-based approach to ensure that prevention and mitigation measures are proportional to the identified risks and to ensure compliance with this Resolution, and must: I – list all products offered, services provided, respective distribution channels, and trading and registration environments in which they operate, segmenting them minimally into low, medium, and high PLD/FTP risk; and II – classify their respective clients by degree of PLD/FTP risk, segmenting them minimally into low, medium, and high risk.
§ 1. For the purposes of the provision in the caput of this article, the following factors must be taken into account, among others: I – the type of client and its legal nature, its activity, its geographical location, the products, services, operations, and distribution channels used by it, as well as other risk parameters adopted in the relationship with its clients; II – the relationship with other persons provided for in Art. 3, considering, inclusive, the PLD/FTP policies of such persons; and III – the counterparty of operations carried out in the name of its client, in the case of operations carried out in registration environments.
§ 2. The PLD/FTP risks inherent to the following categories of clients must consider their respective peculiarities and characteristics, as well as be subject to specific treatment within the PLD/FTP policy and the periodic process of internal risk assessment: I – politically exposed persons, as well as their family members, close collaborators, and legal entities in which they participate, in accordance with Annex A; and II – non-profit organizations, in accordance with specific legislation.
§ 3. The persons mentioned in items I to III of Art. 3 of this Resolution who do not have a direct relationship with the investor must identify, analyze, understand, and mitigate the PLD/FTP risks inherent to their activities performed, considering the parameters established in §§ 1 and 2 of Art. 17.
Art. 6. The director referred to in the caput of Art. 8 must prepare a report regarding the internal PLD/FTP risk assessment, to be sent to the senior management bodies specified in the PLD/FTP policy, by the last business day of April, containing, in addition to the information required in items I and II of Art. 5, the following: I – identification and analysis of PLD/FTP risk situations, considering the respective threats, vulnerabilities, and consequences; II – if applicable, analysis of the performance of proxies, autonomous investment agents, or relevant service providers hired, as well as the description of the governance and duties associated with the maintenance of simplified registration, in accordance with Annex C; II – if applicable, analysis of the performance of proxies, investment advisors, or relevant service providers hired, as well as the description of the governance and duties associated with the maintenance of simplified registration, in accordance with Annex C; • Item II with wording given by CVM Resolution No. 179, of February 14, 2023. III – table relating to the previous year, containing: a) the consolidated number of atypical operations and situations detected, segregated by each hypothesis, in accordance with Art. 20; b) the number of analyses carried out, as provided in Art. 21; c) the number of reports of suspicious operations reported to the Financial Activities Control Council – COAF, as provided in Art. 22; and d) the date of the negative declaration report, if applicable, as provided in Art. 23; IV – the measures adopted to comply with the provisions of items “b” and “c” of item II of Art. 4; V – the presentation of effectiveness indicators as defined in the PLD/FTP policy, including the timeliness regarding the activities of detection, analysis, and communication of atypical operations or situations; and VI – the presentation, if applicable, of recommendations aimed at mitigating the risks identified in the previous exercise that have not yet been properly treated, containing: a) possible changes in the guidelines provided in the PLD/FTP policy referred to in Art. 4; b) improvement of the rules, procedures, and internal controls referred to in Art. 7, with the establishment of remediation schedules; VII – the indication of the effectiveness of the recommendations adopted referred to in item VI in relation to the respective previous report, according to the methodology referred to in item II of Art. 4, recording the results individually.
§ 1. The report referred to in the caput must: I – be prepared annually by the last business day of April and its content must refer to the year prior to the delivery date; II – be available to the CVM and, if applicable, to the self-regulatory entity, at the institution's headquarters.
§ 2. The report referred to in the caput may be unique or compose a comprehensive supervision report of rules, procedures, and internal controls for implementation and compliance with policies required by CVM regulation, observing the compatibility of delivery deadlines, as applicable.
Section III – Rules, Procedures, and Internal Controls
Art. 7. The legal persons mentioned in items I to III of Art. 3 of this Resolution must: I – adopt and implement rules, procedures, and internal controls consistent with their size, as well as with the volume, complexity, and type of activities they perform in the securities market, in order to enable faithful observance of the provisions of this Resolution, including: a) prior analysis for the purposes of mitigating PLD/FTP risks of new technologies, services, and products; and b) the selection and monitoring of administrators, employees, autonomous investment agents, and relevant service providers hired, with the aim of guaranteeing high standards of their staff; and b) the selection and monitoring of administrators, employees, investment advisors, and relevant service providers hired, with the aim of guaranteeing high standards of their staff; and • Item b with wording given by CVM Resolution No. 179, of February 14, 2023. c) the manner in which the responsible director referred to in Art. 8 will access the necessary information for the proper management of PLD/FTP risks; and II – maintain a continuous training program for administrators, employees, autonomous investment agents, and relevant service providers hired, aimed at disseminating their PLD/FTP policy, as well as the respective rules, procedures, and internal controls. II – maintain a continuous training program for administrators, employees, investment advisors, and relevant service providers hired, aimed at disseminating their PLD/FTP policy, as well as the respective rules, procedures, and internal controls. • Item II with wording given by CVM Resolution No. 179, of February 14, 2023.
§ 1. The rules, procedures, and internal controls referred to in this article must: I – be written; II – be verifiable; and III – be available for consultation by the CVM, the administrators of the organized markets, and the market infrastructure operating entities in which the obligated person acts as a participant, and by the self-regulatory entity, if applicable.
§ 2. The rules, procedures, and internal controls referred to in this article must provide that the administrators, employees, autonomous investment agents, and relevant service providers hired, if applicable, of the legal persons mentioned in items I to III of Art. 3 must report, within the limits of their attributes, to their internal control area the proposals or occurrences of the operations or situations provided for in Art. 20.
§ 2. The rules, procedures, and internal controls referred to in this article must provide that the administrators, employees, investment advisors, and relevant service providers hired, if applicable, of the legal persons mentioned in items I to III of Art. 3 must report, within the limits of their attributes, to their internal control area the proposals or occurrences of the operations or situations provided for in Art. 20.
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 96,777-character original (25% of the document). The remainder was not translated. The complete original-language text is stored with this document.]