Description of AML/CTF program: Risk Mitigants
Rating: Scale of 1 (strong), 2 (satisfactory) and 3 (weak). When assigning a rating, the Supervisor must take into account the balance between policy and procedures and their implementation. Assessment of implementation will however be largely conducted during onsite inspections.
Risk Mitigants (risk management, controls, compliance, etc.)
Yes/No | FI’s Description/Comments | MANDATORY Citation: Law, Regulation, etc. | For CBJ Use Only: Inspector’s Preliminary Evaluation of Responses and Rating
A. Corporate Governance and Role of the Board
General Policy
- Has the Board of Directors formally established an AML/CTF policy and compliance program? Describe its main features and consistency with the AML/CTF legislation?
- Has the Board of Directors approved written AML/CTF policies and procedures? If so when established and last updated.
- How often are the policies and procedures reviewed and updated? Is there a policy on this?
- How does the FI communicate, and ensures, that the AML/CTF program is effectively implemented by all relevant offices or units?
- How does the Board supervise implementation of the AML/CTF program, including risk management, and STR and CTR reporting requirements?
- Has the Board designated any of its members responsible for AML/CTF issues or created an AML/CTF Committee? If so when was the director or committee designated/ established?
- What types of reports do the Board and top management receive on implementation of the AML/CTF program? From whom and how often are such reports received?
- What types of arrangements are in place for the Board to provide feedback/decisions to management on reports it receives?
- Describe the reporting and communication arrangements with respect to AML/CTF between the Board and the Internal Audit and Compliance functions.
- Describe the main features of the AML/CTF policy with respect to ML/TF risks and applicable policies and procedures?
- Has the Board formulated and communicated a code of conduct/ethics for directors, management and staff? Does it include AML/CTF issues?
i. Management Information Systems (MIS)
- Does the MIS generate reports on ML/TF risks and trends of risk?
- Does the FI have an information system capable of generating reports on transactions and account activities for purposes of detecting, analyzing reporting unusual and suspicious transactions?
- Does the FI maintain a customer database that can be used to ascertain the risk profile of customers? Are there specific customer reports that are generated e.g. on PEPs and other high risk customers? If so, is the database integrated into MIS?
- Do the management and the Board receive AML/CTF reports generated by the system or summaries thereof?
Rating:
A. Corporate Governance and Role of the Board
Supervisors’ Comments Supporting Rating:
B. Risk Management
- Is there a formal risk management policy? Does it include ML and TF risks?
- Is there a specialized Risk Management group or unit within the FI? If so, does its functions include ML/TF risks?
- Is there a policy and procedures for conducting periodic ML/TF risk assessments? If so what is the scope and frequency and scope of such assessments?
- Does your institution have a ML/TF risk classification system in effect? If so, please describe.
- Has the FI classified any customers, business activities and processes as high risk? If so, state the underlying justification for such classification?
- Are there customers that are prohibited from doing business with the FI based on risk of ML/TF? If so, which ones?
- Does the FI have a screening mechanism for PEPs, UN sanctioned persons/entities list, other official lists, internally generated lists of high-risk customers? What system and procedures are used for such classification and screening?
- Are there any specific risk controls to prevent the FI from being used for purposes of Proliferation Finance?
- Are there any policies and procedures that take into account ML/TF risks in approving expansion of product and business lines including new branches subsidiaries in domestically an in other countries? Has the FI identified/classified high-risk locations where it conducts business?
- What role if any do risk management staff, internal auditors and compliance function play in development of new product, business lines and geographic markets?
Rating:
B. Risk Management
Supervisors’ Comments Supporting Rating:
C. AML/CTF Policies and Procedures
Customer Due Diligence (CDD/KYC)
- Does the FI have written and Board approved policies and procedures for CDD/KYC principles?
- Have the policies and procedures been disseminated to management and relevant employees? How is dissemination conducted?
- How often are the CDD policies and procedures reviewed? Updated?
- Are there specific CDD policies and procedures for high and low risk customers? Is it correlated with the risk management policies? How?
- Are there specific CDD measures for certain customer categories. E.g. Non-residents, Legal entities and arrangements, PEPs (domestic and foreign), Societies/Non-profit organizations, Money changes and remitters, Other categories of e.g. high risk clients or business sectors.
- Are the same AML/CTF policies and procedures implemented across all branches and subsidiaries, domestic and foreign? If not, why?
- Do the CDD policies and procedures provide for: Customer Acceptance/Rejection, Closure business relationships, Risk-based CDD, Customer, and transaction monitoring.
- Are there specific CDD policies and procedures for: Identifying and verifying beneficiaries/ultimate beneficiaries of clients? Recording information on the purpose and intended nature of the business relationship/transaction. Where applicable obtaining information on the source of funds and wealth. Updating customer records including risk profile.
- Does the FI´s CDD policy include checking of clients against high-risk customers in official country lists or lists issued by international organizations e.g. UN terrorism lists.
- Describe the FI CDD procedures when customer business is conducted through or with the participation of: Third party intermediaries (e.g. lawyers and other professionals), Others non-face-to-face business.
- Are any CDD procedures outsourced? Does the FI depend on CDD conducted by other parties, e.g. banks and related entities?
Monitoring and Suspicious Activity Reporting
- Does the FI have an internal system for detecting and reporting unusual and suspicious activities? Is it manual or automated? Describe.
- Are there specific monitoring systems for terrorism and proliferation finance? If so describe in detail.
- Does the FI have a system for monitoring and reporting unusual and suspicious activity on a group-wide basis from branches and subsidiaries? What are the procedures with respect to foreign branches and affiliates reporting to head office?
- Describe the role of compliance (officer) in STR reporting.
- Describe, if any, the security measures applied to prevent information about unusual and suspicious activities from being to unauthorized parties internally and outside of the FI.
- Are monitoring mechanisms risk-based?
- Are there specific monitoring mechanisms for? PEPs, High risk foreign clients and cross-border transactions? Societies/NPOs, Other client, or transaction categories.
- What is the procedure applied once an, transaction or activity is identified as unusual or suspicious? Are these procedures documented? How are these communicated to staff?
- Describe the analytical process that is undertaken to analyze unusual and suspicious activities.
- Describe the decision making process for determining whether or not to send a STR to the AMLU.
- Who has the final decision on whether to send a STR to the AMLU?
- How many STRs have been sent to the AMLU in the past 1-3 years, per year and year to date?
- Is there a policy to protect the employees, if they report suspicious transactions in good faith? E.g. from administrative, and legal liability and of their identity including within the FI.
- Are there administrative sanctions for employees that do not adhere to the monitoring and reporting policies and procedures? Have any been applied in the last 3 years?
Record keeping
- Is there a records retention policy? If so describe.
- How long are customer identification and CDD, transactions, suspicious activity reports, etc. maintained?
- How are records maintained? Paper, electronically, onsite, offsite storage?
- How do records allow for tracing transactions and provide a clear audit trail? Has this system been tested? If so when and by whom?
- What are the security measures for recordkeeping?
- Describe the procedures for accessing and retrieving AML/CTF related data. How long would it take to retrieve the information for a particular customer going back 5 years if requested by the supervisor and other competent authorities? Has this been tested? If so when was it last done?
- Have there been requests from the authorities (e.g. AMLU) for customer data? What were the results with respect to ease of access by the authorities?
- Are there any secrecy, contractual, legal or fiduciary restrictions on the provision of information to competent authorities?
- Can the FI obtain records relating to clients of foreign branches and subsidiaries? Can such information include STR related information? Describe in detail.
Know Your Employee
- Does the FI have an internal human resources policy and procedures that include measures to ensure the integrity of officers/employees?
- Does the FI screen prospective employees, (e.g. criminal records, work experience, etc.)? If yes, what other checks and examinations does your company conduct?
- Describe the institution’s employee vacation policy. Is this policy applied for AML/CFT controls? If so explain why and how it is applied.
Rating:
C. Policies and Procedures
Supervisors’ Comments Supporting Rating:
D. Internal Controls (System-Wide)
Internal Audit
- Does the FI have an Internal Audit Department/function? If so to whom does the internal audit report?
- Does the internal audit review and test the AML/CTF program, CDD/KYC policies and procedures? Is there a specific AML/CTF audit plan?
- If 2 above is yes, how frequent is the review conducted? When was the last time internal audit review AML/CTF? Describe the scope of the last review and its findings.
- Has the Board...