2019-12-05
Added
CVM Instruction 617 modernizes the Brazilian securities market regulation regarding money laundering and terrorist financing prevention by establishing a Risk-Based Approach as the primary governance tool. Regulated entities must implement a PLDFT Policy, conduct periodic internal risk assessments, and reformulate internal rules, procedures, and controls. The instruction mandates specific duties for the responsible director and senior management, defines the Know Your Customer policy steps including beneficial owner identification with a 25% reference threshold, and sets requirements for internal data exchange within financial conglomerates and alternative registration systems.
CVM published 2 documents in the last 30 days — get each new one by email the day it lands.
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 Ref: CVM Instruction No. 617, of December 5, 2019, which provides for the prevention of money laundering and terrorist financing – AML/CFT within the securities market.
INTRODUCTION
The main purpose of CVM Instruction No. 617, of 2019, is to modernize the regulation of the Brazilian securities market regarding the prevention of money laundering and terrorist financing, doing so in full alignment with the guidelines of the main international bodies dealing with this theme, especially the Financial Action Task Force - FATF.
This Explanatory Note aims to provide more detailed clarifications regarding some of the main innovations of CVM Instruction No. 617, of 2019, among which stand out:
a) the insertion of the Risk-Based Approach as the main governance tool for the prevention of money laundering and terrorist financing (AML/CFT), which results in the need, by regulated agents: (i) to structure an AML/CFT Policy; (ii) to periodically prepare an internal risk assessment; and (iii) to reformulate their internal rules, procedures, and controls; b) the improvement of the functions of the director responsible for the rule, as well as the presentation of duties linked to senior management; c) the definition of the steps linked to the conduct of the “Know Your Customer” Policy, including the detailing of routines related to the full knowledge of the beneficial owner; and d) the greater detailing of the alert signals to be monitored and the points that must integrate the analysis of the atypical operation or situation that was detected, as well as the presentation of the minimum elements that must integrate a report to the Financial Intelligence Unit.
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 It should be noted that the content of this Explanatory Note is aligned with Circular Letters already published by the technical areas of the CVM, as well as with publications from FATF and the Basel Committee. Furthermore, it is worth warning that the issuance of this Explanatory Note does not restrict or replace the future disclosure of Circular Letters that may be pertinent. In addition to this brief introduction, the document contains three chapters, namely:
(I) Considerations on the Role of the Responsible Director and Senior Management; (II) Internal Rules, Procedures, and Controls; and (III) “Know Your Customer” Policy.
I – Considerations on the Role of the Responsible Director and Senior Management
Section 2 of Article 4 of the new instruction establishes that the legal entities mentioned in items I and III of Article 3 that belong to the same financial conglomerate must establish in their AML/CFT policies mechanisms for information exchange between their internal control areas. It is worth highlighting that it is possible to adopt a single policy for the entire conglomerate; in this case, it is important to detail the institutions covered and the respective peculiarities of each of them.
The purpose of the regulation is to address the risk that failures in communication between internal control units prevent compliance with the obligations provided for in the provision, regardless of the adoption or not of a single policy for the conglomerate. Naturally, the exchange of information must consider the relevance of the risk identified in each case, always in alignment with the respective internal risk assessment, as per Section II of Chapter II of the Instruction. Note that such a provision does not conflict with Sections 4 and 5 of Article 8, especially when it is clear that maintaining a single, or more directors, to perform the duties described in the Instruction will be a choice of the institutions that make up the financial conglomerate. In any case, it must be emphasized that the director responsible for the Instruction must have broad, unrestricted, and timely access to any information related to the regulated entity's performance in the capital market, thereby enabling the data necessary for the exercise of their duties and those of their employees, especially regarding the effective management of money laundering and terrorist financing (ML/TF) risks, to be used effectively and timely. Those responsible for ML/TF risk management and internal audit activities, when applicable, must base their analyses on all information they deem relevant, including, when appropriate, restricted or even confidential information obtained through internal mechanisms, which enable such access, as well as information from hotline channels. Thus, in no situation can the legal entities listed in items I to III of Article 3 claim any type of access restriction to any corporate data by said director, such as – for example – issues derived from an eventual confidentiality regime (legal, commercial, among others), or other legal restrictions, such as events within the scope of the General Data Protection Law or resulting from regulations that govern the existence of activity segregation (Chinese wall) between some areas of said institution. The manner in which such data will be made available to the director responsible for the Instruction and their employees should be an integral part of the institution's rules, procedures, and internal controls. Furthermore, the systems responsible for the institution's internal data flow must be guided to avoid the possibility that the routines inherent to ML/TF risk management may be prejudiced by eventual information asymmetry, by the untimely receipt of data, or even by the non-receipt of some information. That is, it is fundamental the implementation of adequate internal communication processes, thus enabling the responsible director and their employees to access any sensitive information related to the theme of ML/TF risk management without delay. Be alerted that senior management must not only be aware of its duties set out in Section II of Chapter III of the Instruction, but also must ensure that:
a) it is timely aware of compliance risks related to AML/CFT;
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 b) the responsible director has independence, autonomy, and sufficient technical knowledge for the full fulfillment of their duties, as well as has full access to all information they deem necessary for the respective ML/TF risk governance to be carried out; c) the systems responsible for collecting, updating, and storing information related to the “Know Your Customer” Policy described in Chapter IV of the Instruction are adequate for the purpose they are intended for; d) the monitoring systems for operations and atypical situations are aligned with the institution's “risk appetite”, as well as can be promptly customized in the event of any change in the respective ML/TF risk matrix; and e) sufficient human and financial resources have been effectively allocated to fulfill the previously described points.
II – Internal Rules, Procedures, and Controls
The nature and extent of AML/CFT internal rules, procedures, and controls will depend on a series of factors, including the scope, scale, and complexity of the regulated entity's performance in the securities market.
This includes, but is not limited to, the following:
a) the diversity of its operations; b) the geographic location; c) the client base; d) the profile of the products and activities offered; and
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 e) the degree of risk associated with the peculiarities inherent to all business lines (for example, to what extent there is, or is not, direct relationship with the investor, or commercial relationship with other persons who are part of items I to III of Article 3 of the Instruction). In this way, ML/TF risk management must necessarily:
a) prioritize the monitoring of the institution's products and services that are most vulnerable to ML/TF risks, customizing, whenever necessary, internal rules, procedures, and controls for the specific treatment of an event with a higher probability of damage; b) ensure the existence of a regular process for reviewing all routines for assessing and managing these risks, taking into account the environment in which the institution operates; c) verify, before offering new products or services, or even the use of new technologies, the existence of prior assessments and the respective proposal of adequate controls for ML/TF risks; d) monitor the professional performance of its employees, taking into account the relevance of their duties for the execution of AML/CFT; and e) provide initial and refresher training appropriate for all persons provided for in item II of Article 7 of the Instruction.
III – “Know Your Customer” Policy
The “Know Your Customer” Policy is one of the main pillars of AML/CFT and must be understood as the adoption of a minimum of 4 (four) distinct steps, namely:
a) the identification of the client; b) registration; c) the conduct of due diligence; and
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 d) the process of identifying the beneficial owner.
Client identification comprises the implementation of adequate procedures for the purpose of ensuring their real identity, given that it is the preliminary moment to the start of the investor's relationship with the institution. There is, at minimum, the need to certify that they indeed possess an identity document number or respective CNPJ registration. In the case of non-resident investors, regardless of the use of simplified registration, this information must also include the “CVM code” number. It is worth emphasizing that this first contact will not necessarily be carried out in person, at the institution's premises. Often this moment will be marked by the use of various technologies, so the routines related to this stage must observe, for the purposes of future risk classification, that the continuation of the relationship with this client may, in fact, be conducted in non-face-to-face environments. Parallel to this, this is also the moment when qualification procedures must allow a first approach in the preliminary collection and validation of some relevant information from this investor, which will likely be necessary for the adequate future monitoring of their transactions. Thus, in accordance with Section 2 of Article 5 of the Instruction, it must be possible to evidence the attempt to, for example, verify if the natural person client is a politically exposed person (PEP). In the event that the investor is a legal entity, identify if it is controlled by a PEP, or, alternatively, if it can be classified as a non-profit organization, in accordance with current legislation. Such information, by itself, does not have any restrictive character nor is it sufficient to conclude the respective risk classification of this client. Subsequently, the process of collecting all registration information begins, in accordance with Annex 11-A of the Instruction. At the institution's discretion, this process may be carried out through alternative registration systems, including electronically, provided that the adopted solutions satisfy the objectives of current regulations and the procedures are verifiable.
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 For this purpose, institutions that opt for the alternative registration system must necessarily:
a) fulfill the essential functions of the client registration process, with evidence that the following were guaranteed:
(i) client protection, through the provision of preliminary and basic information that mitigates their information asymmetry regarding contract conditions and offered services (disclosure); (ii) compliance with legal and regulatory norms, especially those related to AML/CFT, product suitability processes, and the combat against the use of insider information (insider trading); and (iii) the management of other risks inherent to the institution's performance in the securities market; b) increase the security and reliability of registration data through consultations to official sources for validating information; c) ensure that all changes and updates within the registration are traceable and auditable; d) mitigate the risk of false or inaccurate information in the registration process; and e) implement a permanent process for collecting and updating client registration data, and that allows timely access to such information. Note that, in any case, the information will be declared by the client themselves, and must then undergo a validation process by the institution, through public or private databases of recognized reliability, and such consultation can be carried out in both environments.
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 Thus, discrepancies eventually pointed out during the analysis and validation process of the registration data provided must be resolved with the clients and treated by the respective areas and hierarchical instances responsible for approving and maintaining the relationship with clients. Note that, regardless of the existence or not of discrepancies in the registration bases, the institution must always be proactive and base such routines on the terms of items II and III of Article 4, of Sections 1 and 3 of Article 11, and of item I of Article 17. To achieve the previously emphasized principles, institutions that opt for the alternative registration system must observe:
a) the maintenance of the content, date, time, origin, and identification of the person responsible for providing and updating all registration information carried out for a period of, at minimum, 5 (five) years; b) the system's ability to retroact to a previous date, for a minimum period of 5 (five) years, in order to show the data present in the active registration on that date; c) security controls and procedures that allow blocking access to registration data by unauthorized persons, as well as the identification of users who had access or made changes to registration data for a period of, at minimum, five years; d) expiration and blocking alert mechanisms for carrying out new operations by clients with outdated registrations, except in the cases of requests for account closure or alienation or redemption of assets, always in observance of the terms of Section 3 of Article 11, as well as Articles 16 to 18 of the Instruction; and e) description of analytical procedures and approval processes that evidence the additional due diligence appropriate for: (i) confirming the registration information of their clients, keeping it updated, and monitoring the operations carried out by them, in order to avoid the use of the account by third parties and identify the beneficial owners of the operations; (ii) identifying politically exposed persons, as well as non-profit organizations; and (iii) attempting, within the limits of the institution's duties, to identify
COMMISSION OF SECURITIES AND EXCHANGE COMMISSION Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 the origin of the resources involved in the transactions of clients and beneficiaries identified as politically exposed persons. It is worth reiterating here that the signature of the client or their proxy in the registration can be made digitally, which links the digital certificate to the electronic document being signed, in this case the registration form, or, in the case of electronic systems, by which the registration is carried out with the typing of registration data directly by the investor, future client, supplemented by other mechanisms, provided that the adopted procedures allow confirming the client's identification with precision. Once the phase of collecting registration information is concluded, the continuous conduct of due diligence begins, which will last throughout the entire commercial relationship with the client, aiming to: (i) reinforce the verification of the truthfulness of the collected information, (ii) collect supplementary information, when necessary, as well as (iii) keep them updated, in the event of detection of a new fact that justifies the anticipation of the period established by the institution for registration updates. In the conduct of these continuous due diligences, efforts must be made and evidenced in the search for supplementary information for the proper classification and management of ML/TF risks for this client. The search for additional data must initially comprise all areas of the institution, as well as other information eventually available in other entities that may be part of the same financial conglomerate, in accordance with Section 2 of Article 4 of the Instruction. Notwithstanding, the institution must, within the scope of its risk-based approach methodology, permanently evaluate how supplementary information will be obtained from third parties outside the financial conglomerate, if applicable, observing eventual confidentiality or access restriction regimes provided for in legislation. It is worth clarifying that, as already defined in the Instruction, a beneficial owner is considered a natural person or natural persons who, individually or jointly, possess, control, or significantly influence, directly or indirectly, a client on whose behalf a transaction is being conducted or from which they benefit. Thus, when the process of identifying the beneficial owner is applicable, the minimum reference value must be noted, which was defined at 25% (twenty-five percent) of the share capital of legal entities or of the net equity of investment funds and other entities in the cases covered by items II to V of Article 1 of Annex 11-A, without prejudice to the eventual use of simplified registration
provided for in Annex 11-B. This parameter must be aligned with the results of the internal risk assessment and may be lower than this percentage in situations of higher risk. Furthermore, it must be observed that the process of identifying one or more beneficial owners goes beyond the parameters defined in the concepts of control or ownership. Sometimes the causal link of this identification should focus on the act or effect of significant influence, regarding which there may be one or more persons who actually participate in the strategic decision-making of that investor, and who do not necessarily go, for example, to compose the corporate structure of a company, nor will they appear as its administrators or even employees. Another point to be verified is that in many situations in legal entities, or even in legal arrangements of non-resident investors, the beneficial owner will be solely the one who ultimately benefits directly or indirectly from the assets owned by that client, without necessarily having any formal registration that they are part of the shareholders' board, or even the board of administrators or employees. All the above reinforces the need for the permanent conduct of due diligence aiming at the full knowledge of the client, including the understanding of its legal nature and its decision-making process, in a risk-based approach, and within the limits of the institution's duties. As for the specifically simplified registration of the non-resident investor, provided for in Annex 11-B of CVM Instruction 617, it will initially be up to the legal entities mentioned in items I to III of Article 3 of the norm to identify in which item of Section 1, of Article 1, of Annex 1, of CVM Instruction 560/2015, the referred foreign client is classified. Sequentially, the due diligence must guide the situations in which it is possible to individualize a natural person or natural persons as beneficial owners of these investors, and the best efforts must be evidenced to identify them. The adoption of simplified registration for non-resident investors allows the Brazilian institution to hold a reduced amount of registration information, however, it does not exempt it from conducting the routines provided for in the investor knowledge process that have already been mentioned in this Note.
COMMISSION OF SECURITIES AND EXCHANGE COMMISSIONS Sete de Setembro Street, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Cincinato Braga Street, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 Explanatory. Such routines must be conducted on a permanent basis during the commercial relationship between the Brazilian institution and the non-resident investor, and do not require prior demand from the CVM or the self-regulatory entity to be implemented.
Even if the foreign institution can be considered the main source of the information to be collected, if the data required by CVM regulations is truly not made available by the foreign institution holding the non-resident client's information to the Brazilian institution, there is no restriction on obtaining supplementary inputs from third parties.
Therefore, other information may eventually be collected from independent sources, as well as be effectively used, provided they prove useful and reliable as substitutes or good references for the "Know Your Customer" process.
In this context, if the necessary information is not provided by the foreign institution, or even cannot be obtained from reliable third parties, and such a gap prevents full knowledge of the client classified as a non-resident investor, the Brazilian institution must adopt the necessary measures to, considering all hypotheses provided for in the items of Article 20 of the Instruction, after analyzing the situation in concreto according to Article 21, evaluate the relevance and timeliness of communicating the facts to the Financial Intelligence Unit.
Furthermore, other measures must also be adopted, such as the evaluation by the respective senior management regarding the maintenance of the commercial relationship with that non-resident investor.
It is worth emphasizing that the lack of knowledge of the beneficial owner, in situations where it is applicable, of any Brazilian or foreign client, resident or non-resident, regardless of the use of simplified registration, must always be based on evidence that the due diligence was conducted for this purpose, within the limits of the institution's responsibilities.
The institution must observe that the lack of knowledge of the beneficial owner is not, by itself, a sufficient element for sending a communication to the Financial Intelligence Unit. Consequently, this fact must provide more rigorous continuous monitoring, aiming to detect other atypical operations or situations, in accordance with Article 20 of the Instruction, regardless of the risk classification of this investor.
COMMISSION OF SECURITIES AND EXCHANGE COMMISSIONS Sete de Setembro Street, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – CEP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Cincinato Braga Street, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/SP – CEP: 01333-010 – Brazil - Tel.: (11) 2146-2000 Finally, in the event that additional atypicalities are detected, the institution must conduct a deeper analysis, with a view to verifying the need for the communications referred to in Articles 22 and 27, always paying attention to the minimum parameters that must integrate a report to the Financial Intelligence Unit, as provided for in § 1 of Article 22.
Original signed by
MARCELO BARBOSA
President
Read the rest free
Source: Comissão de Valores Mobiliários — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CVM
CVM published 2 documents in the last 30 days. We email you each new one the day it's published.