2023-08-08 | POJK 15 Tahun 2023Added
Financial Services Authority Regulation Number 15 of 2023 establishes a centralized administrative service for storing customer identification data and documents to support Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) in the capital market. It designates the Financial Services Authority to appoint administrators and mandates specific financial institutions, including securities companies, investment managers, and custodian banks, to utilize this service. The regulation defines the operational standards, data protection obligations, and reporting requirements for both administrators and users, while imposing administrative sanctions for non-compliance.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
COPY
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 15 OF 2023
CONCERNING
THE ADMINISTRATION OF CUSTOMER DUE DILIGENCE PRINCIPLES BY THE GRACE OF GOD THE ALMIGHTY, THE COMMISSIONERS COUNCIL OF THE FINANCIAL SERVICES AUTHORITY, Considering:
a. that for the efficiency of implementing customer due diligence and/or enhanced due diligence and supporting supervisory activities in the capital market, it is necessary to centralize the administration of data and documents of prospective customers and/or customers; b. that for the effective use of the customer due diligence principles administration infrastructure, regulations are needed to govern the use of this infrastructure by financial service institutions;
c. that based on the considerations referred to in letters a and b, it is necessary to establish a Financial Services Authority Regulation concerning the Administration of Customer Due Diligence Principles;
Recalling:
Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2023 Number 4, Supplement to the State Gazette of the Republic of Indonesia Number 6845); DECIDING:
To establish:
FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE ADMINISTRATION OF CUSTOMER DUE DILIGENCE PRINCIPLES.
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation, the following terms are defined as:
Article 2
LAPMN is administered to centralize the administration of data and documents of Prospective Customers and/or Customers in the implementation of CDD and/or EDD so that:
a. it supports supervisory activities in the capital market; and b. it simplifies the process of opening Customer accounts and updating Customer data across multiple LAPMN Users.
CHAPTER II
LAPMN PROVIDERS
Article 3
(1) LAPMN Providers are appointed by the Financial Services Authority.
(2) LAPMN Providers as referred to in paragraph (1) are Depository and Clearing Institutions and/or other Parties.
(3) Regulations concerning other Parties as referred to in paragraph (2) are established by the Financial Services Authority.
Article 4
The activities of LAPMN Providers include:
a. receiving initial static data of Prospective Customers and/or Customers, receiving updates to Customer data, centralizing data, and CDD and/or EDD documents submitted electronically by LAPMN Users; b. distributing CDD and/or EDD data and documents to LAPMN Users; and
c. notifying information regarding data updates and CDD and/or EDD documents to LAPMN Users where the Customer is registered.
Article 5
The administration of LAPMN is conducted with the following provisions:
a. the administration of LAPMN is not a CDD and/or EDD activity; b. the administration of LAPMN is conducted on static data for the identification of LAPMN Users' Prospective Customers, excluding risk profile assessment data;
c. LAPMN Providers are not Parties responsible for the CDD and/or EDD processes conducted by LAPMN Users; and
d. the administration of LAPMN is conducted with the consent of Prospective Customers and/or Customers of LAPMN Users for their data and CDD and/or EDD documents to be used by LAPMN Providers according to their functions and duties.
CHAPTER III
AUTHORITY OF THE FINANCIAL SERVICES AUTHORITY
Article 6
The Financial Services Authority has the authority to access data and documents administered by LAPMN Providers for supervisory purposes.
CHAPTER IV
LAPMN USERS
Article 7
(1) LAPMN Users are Parties that conduct CDD and/or EDD activities.
(2) Parties as referred to in paragraph (1) include Parties that, based on written agreements, act as agents or third parties to assist LAPMN Users in conducting CDD and/or EDD activities. (3) LAPMN Users conducting CDD and/or EDD activities as referred to in paragraph (1) include:
a. Securities Companies conducting business as PPEs; b. Investment Managers;
c. Custodian Banks;
d. Mutual Fund Sales Agents; e. Institutional PPE Marketing Partners; f. Bank RDNs; g. Crowdfunding Service Providers; and h. Other Parties designated by the Financial Services Authority as LAPMN Users.
Article 8
Securities Companies conducting business as PPEs, Investment Managers, Custodian Banks, Mutual Fund Sales Agents, and Crowdfunding Service Providers that conduct CDD and/or EDD activities in the capital market sector as referred to in Article 7 paragraph (3) letters a, b, c, d, and g are required to become LAPMN Users.
Article 9
(1) LAPMN Users that are Securities Companies conducting business as PPEs are required to:
a. open sub-accounts for Securities; b. open fund accounts at banks in the name of Customers; and
c. create a single investor identification number for Customers who do not yet have a single investor identification number.
(2) Sub-accounts for Securities as referred to in paragraph (1) letter a can serve as a substitute for:
a. the obligation to open Customer fund accounts at banks as referred to in paragraph (1) letter b, including storing Customer funds and conducting fund transfers for Customer Securities transaction settlements through Customer fund accounts; b. the requirement for investors to have Customer fund accounts at banks when expressing interest in Securities offered and/or placing orders for Securities offered through electronic public offering systems.
Article 10
In using LAPMN, LAPMN Users as referred to in Article 7 paragraph (3) are required to:
a. ensure that data and/or completeness of documents of Prospective Customers and/or Customers comply with the format and data standards established by the LAPMN Provider; b. confirm with Prospective Customers and/or Customers regarding data and/or completeness of documents obtained from the LAPMN Provider to ensure that the data and/or documents are current and valid;
c. submit data and/or completeness of documents of Prospective Customers and/or Customers electronically to the LAPMN Provider;
d. submit data and/or completeness of Customer documents that have been updated electronically to the LAPMN Provider; e. document data and/or completeness of CDD and/or EDD documents; f. comply with regulations and procedures established by the LAPMN Provider; g. sign a LAPMN usage agreement with the LAPMN Provider; h. ensure the security and reliability of systems connected to the LAPMN Provider's system;
i. protect and ensure the security of data and/or completeness of documents of Prospective Customers and/or Customers of LAPMN Users in accordance with statutory regulations concerning personal data protection;
j. maintain the confidentiality and security of LAPMN User access limits in the LAPMN system; and k. be responsible for losses caused by errors or negligence of LAPMN Users in the use of LAPMN.
Article 11
LAPMN Users are prohibited from disclosing data of Prospective Customers and/or Customers obtained through LAPMN Providers to other Parties unless prior written consent has been obtained from the Prospective Customers and/or Customers of LAPMN Users or it is required by statutory regulations.
CHAPTER V
OPERATIONAL AND INTERNAL CONTROL OF LAPMN PROVIDERS
Article 12
In administering LAPMN, LAPMN Providers are required to:
a. provide a continuous LAPMN system; b. have and establish standard operating procedures for the administration of LAPMN;
c. be responsible for the operation and management of the LAPMN system according to their authority;
d. have a business continuity plan related to the administration of LAPMN; e. have and locate data center facilities related to the administration of LAPMN within the territory of Indonesia in a safe place; f. have and locate replacement data center and disaster recovery facilities related to the administration of LAPMN within the territory of Indonesia in a safe place separate from the main data center; g. notify LAPMN Users in the event of system changes or development, including the addition of system services and features that require adjustments to LAPMN Users' systems; h. protect and ensure the security of data and documents of LAPMN Users' Customers administered in accordance with statutory regulations concerning personal data protection;
i. supervise every official and/or employee of the LAPMN Provider involved in the processing of LAPMN Users' Customer data;
j. prevent unauthorized access to LAPMN Users' Customer data; k. document all activities related to the processing of data and documents of Prospective Customers and/or Customers of LAPMN Users;
l. process data and documents of Prospective Customers and/or Customers of LAPMN Users in LAPMN in accordance with the purpose of administering LAPMN as referred to in Article 2 and the scope of administering LAPMN as referred to in Article 5;
m. be responsible for losses caused by errors or negligence of LAPMN Providers in the provision and management of LAPMN; and n. provide access and support to the Financial Services Authority for supervisory purposes.
Article 13
(1) Data and documents administered by LAPMN Providers are data and documents owned by LAPMN Users' Customers.
(2) LAPMN Providers are prohibited from disclosing data of Prospective Customers and/or Customers of LAPMN Users outside the implementation of LAPMN administration activities unless prior written consent has been obtained from the Prospective Customers and/or Customers of LAPMN Users or it is required by statutory regulations.
Article 14
(1) LAPMN Providers are required to establish regulations concerning the administration of LAPMN.
(2) Regulations concerning the administration of LAPMN as referred to in paragraph (1) and their amendments must obtain approval from the Financial Services Authority. (3) Regulations concerning the administration of LAPMN as referred to in paragraph (1) must cover at least:
a. requirements and procedures for the registration of LAPMN Users, including the cancellation of LAPMN User registration; b. procedures for the use of LAPMN;
c. format and data standards related to static data and completeness of documents of Customers and/or Prospective Customers used by LAPMN Users in the CDD and/or EDD process of Prospective Customers and/or Customers, through LAPMN at the time of opening Customer accounts, while complying with Financial Services Authority regulations regarding the implementation of anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs in the financial services sector;
d. rights and obligations of LAPMN Users; e. LAPMN costs; f. access limits for the use of LAPMN; g. mechanisms for the submission and retrieval of data and/or documents on LAPMN electronically; h. mechanisms for submitting updated data;
i. mechanisms to ensure business continuity related to the administration of LAPMN;
j. temporary suspension of services to LAPMN Users; k. the obligation of LAPMN Users to have and document consent from Prospective Customers and/or Customers that CDD and/or EDD data can be used by LAPMN Providers according to their functions and duties; and
l. the obligation of LAPMN Users to maintain the confidentiality, integrity, availability, and protection of CDD and/or EDD data information in accordance with statutory regulations concerning personal data protection.
Article 15
(1) In administering LAPMN, LAPMN Providers are required to have a written agreement concerning the use of LAPMN.
(2) The written agreement as referred to in paragraph (1) must cover at least:
a. the scope of activities; b. the rights and obligations of LAPMN Providers and LAPMN Users;
c. statements and guarantees of the truthfulness and currency of data and information of Prospective Customers and/or Customers submitted by LAPMN Users into the LAPMN system; and
d. dispute resolution.
CHAPTER VI
REPORTING AND NOTIFICATION BY LAPMN PROVIDERS
Article 16
LAPMN Providers are required to report to the Financial Services Authority regarding:
a. plans for system changes or development, including the addition of system services and features that require adjustments to LAPMN Users' systems, at least 3 (three) months before the implementation of system changes or development is carried out; b. disruptions that cause the LAPMN system to be unusable and the follow-up actions being and/or already taken, which can be submitted electronically at the latest on the next working day since the LAPMN system disruption occurred; and
c. temporary suspension of services to LAPMN Users, at the latest 2 (two) working days since the temporary suspension of services to LAPMN Users.
Article 17
LAPMN Providers are required to provide information to LAPMN Users, which can be done electronically, regarding:
a. plans for system changes or development, including the addition of system services and features that require adjustments to LAPMN Users' systems, at least 6 (six) months before the implementation of system changes or development is carried out; and b. disruptions that cause the LAPMN system to be unusable as referred to in Article 16 letter b, as soon as possible after the LAPMN system disruption occurs.
CHAPTER VII
SANCTION PROVISIONS
Article 18
(1) Any Party that violates the provisions as referred to in Article 8, Article 9 paragraph (1), Article 10, Article 11, Article 12, Article 13 paragraph (2), Article 14 paragraph (1) and (2), Article 15 paragraph (1), Article 16, and Article 17 shall be subject to administrative sanctions. (2) Sanctions as referred to in paragraph (1) shall also be imposed on Parties that cause the violations as referred to in paragraph (1). (3) Sanctions as referred to in paragraph (1) and paragraph (2) shall be imposed by the Financial Services Authority. (4) Administrative sanctions as referred to in paragraph (1) consist of:
a. written warnings; b. fines, namely the obligation to pay a certain amount of money;
c. restrictions on business activities;
d. suspension of business activities; e. revocation of business licenses; f. revocation of approvals; and/or g. cancellation of registration.
(5) Administrative sanctions as referred to in paragraph (4) letters b, c, d, e, f, or g may be imposed with or without prior imposition of administrative sanctions in the form of written warnings as referred to in paragraph (4) letter a. (6) Administrative sanctions in the form of fines as referred to in paragraph (4) letter b may be imposed separately or together with the imposition of administrative sanctions as referred to in paragraph (4) letters c, d, e, f, or g. (7) The procedures for imposing sanctions as referred to in paragraph (3) shall be implemented in accordance with statutory regulations.
Article 19
In addition to administrative sanctions as referred to in Article 18 paragraph (4), the Financial Services Authority may take specific actions against any Party that violates the provisions of this Financial Services Authority Regulation.
Article 20
The Financial Services Authority may announce:
a. the imposition of administrative sanctions as referred to in Article 18 paragraph (4); and b. specific actions as referred to in Article 19, to the public.
CHAPTER VII
CLOSING PROVISIONS
Article 21
This Financial Services Authority Regulation shall come into force after 6 (six) months from the date of its promulgation.
This copy is in accordance with the original
Director of Law 1
Legal Department signed
Mufli Asmawidjaja
In order that everyone may know it, it is ordered to promulgate this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Determined in Jakarta on August 4, 2023
CHAIRMAN OF THE COMMISSIONERS COUNCIL
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
MAHENDRA SIREGAR
Promulgated in Jakarta on August 8, 2023
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2023 NUMBER 26/OJK
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
OF THE REPUBLIC OF INDONESIA
NUMBER 15 OF 2023
CONCERNING
THE ADMINISTRATION OF CUSTOMER DUE DILIGENCE PRINCIPLES
I. GENERAL
Customers in the Indonesian Capital Market can open Securities or investment accounts at several financial service institutions, where each financial service institution is required to conduct a CDD process, including identification of each Customer. Consequently, Customers will undergo repeated CDD processes corresponding to the number of financial service institutions visited to open Securities or investment accounts. The repetition of the identification process as part of CDD is considered inefficient from both the Customer's and the financial service institution's perspectives, as it requires more time and incurs higher costs because data, information, and supporting documents for CDD for the same Customer must be stored at all financial service institutions where the Customer opens Securities or investment accounts.
In order to facilitate financial service institutions in conducting CDD and updating Customer data, as well as to accelerate the time for Prospective Customers in opening accounts at several financial service institutions, it is necessary to have the administration of CDD data storage services by LAPMN Providers. In this regard, it is necessary to have regulations governing the administration of LAPMN activities so that they can be utilized effectively.
II. ARTICLE BY ARTICLE
Article 1
Clearly sufficient.
Article 2
Clearly sufficient.
Article 3
Clearly sufficient.
Article 4
Letter a
The term "static data" refers to detailed data belonging to Prospective Customers and/or Customers for the purpose of CDD and/or EDD identification by LAPMN Users, and does not include risk profile assessment data for Prospective Customers and/or Customers as referred to in Financial Services Authority Regulations regarding the implementation of anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs in the financial services sector.
Letter b
Clearly sufficient.
Letter c
Clearly sufficient.
Article 5
Clearly sufficient.
Article 6
Clearly sufficient.
Article 7
Paragraph (1)
Clearly sufficient.
Paragraph (2)
Parties that, based on written agreements, act as agents or third parties to assist LAPMN Users include, for example, Mutual Fund Sales Agents as agents of Investment Managers, and Institutional PPE Marketing Partners as agents of Securities Companies conducting business as PPEs.
Paragraph (3)
Letter a
Clearly sufficient.
Letter b
Clearly sufficient.
Letter c
Clearly sufficient.
Letter d
Clearly sufficient.
Letter e
Clearly sufficient.
Letter f
Clearly stated.
Letter g
Clearly stated.
Letter h
The term “Other Parties” refers to parties using the LAPMN for the purposes of anti-money laundering, counter-terrorist financing, and counter-proliferation financing of weapons of mass destruction in the financial services sector.
Article 8
Clearly stated.
Article 9
Paragraph (1)
The term “sub-account of Securities” refers to the securities account of each Customer recorded in the securities account of a participant at the Securities Depository and Clearing Institution.
Paragraph (2)
Letter a
The term “obligation to open a customer fund account at a bank, including storing customer funds and performing fund transfers for the settlement of the Customer’s securities transactions through the customer fund account” refers to the obligation as stipulated in the regulations of the Financial Services Authority regarding internal control of Securities Companies conducting business as a Securities Provider (PPE) and its implementing provisions.
Letter b
The term “requirement for investors to have a customer fund account at a bank” refers to the requirement as stipulated in the regulations of the Financial Services Authority regarding the implementation of public offerings of equity securities, debt securities, and/or sukuk electronically.
Article 10
Clearly stated.
Article 11
The term “Other Parties” refers to parties other than LAPMN Users who have obtained Candidate Customer and/or Customer data from the LAPMN Provider.
Article 12
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
Clearly stated.
Letter f
Clearly stated.
Letter g
Clearly stated.
Letter h
Clearly stated.
Letter i
Clearly stated.
Letter j
Clearly stated.
Letter k
The term “processing” includes, among other things, the receipt of initial data and updated Customer data, the utilization of Customer data shared with LAPMN Users in the context of conducting CDD and/or EDD, and the notification of updated CDD and/or EDD data and documents to other LAPMN Users with whom the Customer is registered.
Letter l
Clearly stated.
Letter m
Clearly stated.
Letter n
Clearly stated.
Article 13
Clearly stated.
Article 14
Paragraph (1)
Clearly stated.
Paragraph (2)
Clearly stated.
Paragraph (3)
Letter a
Clearly stated.
Letter b
Clearly stated.
Letter c
Clearly stated.
Letter d
Clearly stated.
Letter e
Clearly stated.
Letter f
Clearly stated.
Letter g
Clearly stated.
Letter h
Clearly stated.
Letter i
Clearly stated.
Letter j
The temporary suspension of services to LAPMN Users may be caused by violations committed by the LAPMN User in violation of these Financial Services Authority regulations or regulations established by the LAPMN Provider.
Letter k
Clearly stated.
Letter l
Clearly stated.
Article 15
Clearly stated.
Article 16
Letter a
Clearly stated.
Letter b
The term “disruptions causing the LAPMN system to be unusable” includes:
Letter c
Clearly stated.
Article 17
Clearly stated.
Article 18
Clearly stated.
Article 19
The term “certain actions” refers to actions by the Financial Services Authority ordering the LAPMN Provider to temporarily suspend services to LAPMN Users due to sanctions imposed by the Financial Services Authority.
Article 20
Clearly stated.
Article 21
Clearly stated.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 50/OJK ---
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.