2020-03-22
Added · Updated
The Attorney General of Fiji issued the Financial Transactions Reporting Regulations 2007 to implement the Financial Transactions Reporting Act 2004 and combat money laundering and terrorist financing. The regulations mandate financial institutions to conduct customer due diligence, maintain risk-based internal controls, and report suspicious or large cash transactions to the Fiji Islands Revenue and Customs Authority. These requirements establish specific thresholds for reporting, detailed identification procedures for various customer types, and compliance standards for supervisory authorities and the Financial Intelligence Unit.
No. 22 MONDAY 30th APRIL 2007
[LEGAL NOTICE NO. 53]
(Act No. 22 of 2004)
IN exercise of the powers conferred upon me by section 1 of the Financial Transaction Reporting Act 2004, I appoint 1 January 2008 as the date on which Section 13 and Part 5 of the Act come into force.
Dated this 30th day of April 2007.
A. S. KHAIYUM
Attorney-General, Minister for Justice, Electoral Reform & Anti-Corruption
First Schedule — Reporting forms
Second Schedule — Other forms
(Act No. 22 of 2004)
IN EXERCISE of the powers conferred upon him by section 42 of the Financial Transactions Reporting Act 2004, the Attorney General and the Minister of Justice, has made the following Regulations:
(2) A financial institution must achieve full compliance with the requirements of these Regulations before 31st December 2007.
(2) For the purpose of section 13(1) and (2) of the Act, the threshold for reporting financial transactions is prescribed as: (a) transaction of an amount in cash of $10,000 and above or its equivalent in foreign currency; (b) the sending out of the Fiji Islands, at the request of a customer any electronic fund transfer; (c) the receipt from outside the Fiji Islands of any electronic funds transfer, sent at the request of a customer.
(3) Pursuant to paragraph (c) of the definition of “terrorist group” in section 2 of the Act, “terrorist group”, for the purpose of these Regulations, includes the individuals and entities set out in — (a) the current consolidated list of individuals and entities issued by the bodies established pursuant to the United Nations Security Council Resolution 1267 and 1373; or (b) any other recognised list of terrorist groups that include individuals and entities listed in the consolidated list in sub regulation 4(a).
(2) When a financial institution has identified the customer, the financial institution must then verify the identity of the customer using reliable, independently sourced and valid documents, data, or information which must include one or more of the following — (a) bank statement or account statement issued by another financial institution if the person previously transacted with a bank or financial institution and that bank or financial institution had confirmed the person’s identity; (b) tax identification number and acknowledgement from Fiji Islands Revenue and Customs Authority; (c) notice of taxation assessment by the Fiji Islands Revenue and Customs Authority; (d) utility bill for electricity, water, telephone or other similar services issued by the authority responsible for the supply of such services; (e) municipal business licence certificate or municipal rates statement or invoice; (f) mortgage statement from another financial institution; (g) cellular phone account statement; (h) television account statement; (i) long-term or short-term insurance policy document issued by an insurance company;
(2) In this regulation — “legal person” means bodies corporate, foundations, partnerships or associations, or any similar bodies that can establish a permanent customer relationship with a financial institution or otherwise own property; “legal arrangement” refers to express trusts or other similar legal arrangements.
(3) A financial institution must take reasonable measures to understand and document the ownership and control structure of the legal person or arrangement including the name and permanent residential address of the natural person(s) who ultimately owns or controls the legal person or arrangement.
(4) For a customer that is a company, limited partnership, or similar form of arrangement, a financial institution must identify and verify the identity of the principal owner of the company, limited partnership or similar form of arrangement and must at a minimum identify — (a) each natural person who owns directly or indirectly 30 percent or more of the vote or value of an equity interest in the company, limited partnership, or similar arrangement; and (b) any person exercising effective control of the company, limited partnership or similar arrangement; and (c) each natural person who exercises a signing authority on behalf of the company, limited partnership, or similar arrangement.
(5) For the purpose of sub regulation (4), the financial institution may not undertake identification and verification of the principal owners if the customer is — (a) a public company quoted on the South Pacific Stock Exchange or other exchanges supervised by the Capital Markets Development Authority; or (b) a non-resident public company subject to adequate regulatory disclosure and is quoted on a stock exchange and is in a jurisdiction that is implementing effectively the Financial Action Task Force (FATF) 40 + 9 Recommendations. (FATF was formed in 1989 by G7 countries as an inter-governmental body whose objective is to develop and promote policies to combat money laundering and terrorist financing. The 40 recommendations were initially issued in 1990 and revised in 2003. The 8 recommendations were initially issued in 2001 and 1 additional recommendation was issued in 2004. The International Monetary Fund and the World Bank have adopted the FATF 40 + 9 Recommendations in 2004 in the revised methodology for assessment of anti-money laundering and combating the financing of terrorism systems.)
(6) For a customer that is a trust or other similar arrangement, the financial institutions must identify and verify the identity of the settlor and trustee, and any beneficiary whose interest is 30 percent or more of the value of trust or arrangement.
(7) In determining indirect ownership of equity interests — (a) an equity interest held by a company, limited partnership, trust or other similar arrangement, must be considered as being owned proportionately by its shareholders, partners, or vested beneficiaries; and (b) an equity interest held by a family member must be considered as also being owned, in its entirety by each family member (family members include brothers and sisters, whether by the whole or half blood, spouse, ancestors, and lineal descendants).
(2) A financial institution may undertake the identification and verification of a beneficiary before the time of payout or the time the beneficiary intends to exercise the right under the policy.
(2) If a financial institution determines that the customer is acting on behalf of any other person, the financial institution must identify and verify the identity of the person on whose behalf the customer is acting using reliable, independently sourced documents as provided in regulation 9.
(2) A financial institution may rely on another financial institution to perform customer identification requirements.
(3) A financial institution may rely on a non-financial institution to perform customer identification requirements if the financial institution is satisfied that the third party intermediary is adequately regulated and supervised and such intermediary has measures in place to comply with the customer identification requirements of the Act and these Regulations.
(4) When relying on a third party or intermediary as set out in sub regulations (1), (2) and (3), the financial institution must — (a) be satisfied that the customer due diligence procedures of the intermediary are as rigorous as those which the financial institution would have conducted itself for the customer; (b) enter into a written agreement with the third party or intermediary that it will verify promptly the due diligence undertaken by the third party or intermediary at any stage; (c) be satisfied that the third party or intermediary is subject to customer identification and verification requirements comparable with the Act and these Regulations; (d) be satisfied that the third party or intermediary is subject to supervision to enforce the customer identification and verification requirements; (e) not be subject to any action that calls into question its execution of those policies, and is located in a jurisdiction that is implementing effectively the FATF 40 + 9 Recommendations.
(5) If a financial institution relies on a third party or intermediary, the financial institution must immediately obtain from the third party or the intermediary the customer identification information required in this Act or these Regulations.
(6) A financial institution must take adequate steps to satisfy itself that any copy of identification data and other relevant documentation relating to the information will be made available without delay.
(7) A financial institution must not rely upon — (a) a third party or intermediary identified by the relevant supervisory authority or the Unit as not complying with customer identification and verification requirements comparable with the Act or these Regulations; or (b) a third party or intermediary which the financial institution has reason to believe is not complying with such requirements.
(8) A financial institution must not rely upon any third party or intermediary specified in writing by the Unit.
(9) Despite the provisions of this regulation, a financial institution is still ultimately responsible for the implementation of the customer identification and verification requirements under the Act and these Regulations.
(2) The monitoring system must, taking into account the size and nature of business of a financial institution, be capable of identifying any transaction that is — (a) from any source or to any recipient, identified as being of questionable legitimacy; (b) unusual in terms of — (i) the amount, such as by reference to predetermined limits for the customer in question or to comparative figures for similar customers; (ii) the type, such as international wire transfers for the customer in question; (iii) the number, such as high account activity in relation to the size of the balance of the customer in question; and (iv) any other risk factor identified by the financial institution. (c) identified in writing by the Unit, as being a transaction that the financial institution must monitor.
(2) A customer profile must include — (a) relevant information as to the normal and reasonable activity for particular types of customer taking into account the nature of the customer’s business; (b) a comprehensive picture of the customer’s transactions; (c) where necessary, the source and legitimacy of the funds; (d) the overall relationship with the financial institution.
(2) An internal control and procedure referred to in subregulation (1) may include the following — (a) any measure required under Part 2; (b) any other additional measure to ensure that the required information is obtained when a transaction is conducted by the customer;
(3) A financial institution — (a) must not proceed with the attempted transaction if it had failed to ascertain the required information; (b) must report such transaction to the Unit as a suspicious transaction under section 14 of the Act; and (c) must not proceed with such transaction unless directed to do so by the Unit.
(2) Any enhanced customer due diligence must include enhanced — (a) scrutiny of customer’s identity (including of the beneficial owner and controller); (b) scrutiny of the source and legitimacy of funds; (c) transaction monitoring; and (d) customer profiling.
(4) Any enhanced customer due diligence must be applied to any higher risk customer, business relationship or transaction, as appropriate at each stage of the customer identification and verification process.
(5) In addition to measures required in sub regulation (4), a financial institution must have policies and procedures in place and must ensure an effective implementation of these measures to address any specific risk associated with non-face-to-face business relationship or transaction.
(6) Pursuant to sections 4(3) and 4(4)(c) of the Act, a financial institution must undertake enhanced customer due diligence in relation to a politically exposed person, as a category of high risk customer.
(7) A financial institution must put in place appropriate risk management systems to determine whether a customer, a potential customer or the beneficial owner is a politically exposed person.
(8) A relevant supervisory authority or the Unit may issue guidelines specifying the factors a financial institution must take into account when determining whether a customer is of a higher risk.
(9) A financial institution must not enter into a business relationship with a higher risk customer unless a senior member of the financial institution’s management has given approval in writing.
(2) For the purposes of sub regulation (1), customers which may be subject to simplified due diligence procedures include — (a) licensed and regulated financial institutions; (b) locally incorporated public companies that are subject to regulatory and disclosure requirements; (c) Fiji Government administrations or enterprises; (d) local governments and municipal councils;
(3) Simplified customer due diligence may include a lower level of — (a) scrutiny for customer identification; (b) scrutiny of the source and legitimacy of funds; (c) scrutiny of the legitimacy of the recipient of funds; (d) transaction monitoring; and (e) customer profiling.
(4) A financial institution, as a minimum requirement, must obtain information about the name and address of the customer, occupation and the legal form and nature of business and activity conducted by the customer.
(5) A financial institution must terminate simplified customer due diligence procedures when there is suspicion of money laundering or terrorist financing or conditions under regulation 21 apply.
(6) The relevant supervisory authority or the Unit may issue guidelines specifying what factors a financial institution must take into account when determining whether customers are of a lower risk.
(2) Full originator information includes — (a) the name of the originator; (b) the originator’s bank and account number, or a unique reference number if there is no account number; (c) the originator’s address; (d) the amount of payment order;
(3) For cross-border electronic funds transfers and any other forms of funds transfers (including transactions using a credit or debit card to effect a funds transfer), the ordering financial institution must include full originator information in the message or payment form accompanying the funds transfer.
(4) For any domestic funds transfer (including a transaction using a credit or debit card, as a payment system to effect a money transfer), the ordering financial institution must include either — (a) full originator information in the message or payment form accompanying the electronic funds transfers and all other forms of funds transfers; or (b) only the originator’s account number or, where no account number exists, a unique identifier, within the message or payment form, providing that full originator information can be made available to the beneficiary financial institution and to the Unit, within 3 business days of receiving a request.
(5) If a cross-border electronic funds transfer and any other forms of transfer is contained within a batch transfer and is sent by a financial institution, the batch transfer may be treated as a domestic electronic funds transfer.
(6) A financial institution must ensure that any non-routine transaction is not batched if this would increase the risk of money laundering or terrorist financing.
(7) An intermediary in the payment chain must maintain all the required originator information with the accompanying funds transfer.
(8) A beneficiary financial institution must identify and scrutinize a funds transfer that are not accompanied by complete originator information and constitute an enhanced risk of money laundering and financing of terrorism.
(9) For the purposes of subregulation (8), a financial institution must have in place procedures to address funds transfers that are not accompanied by complete originator information and as a minimum these procedures must include — (a) the financial institution requesting the missing originator information from the financial institution that sent the funds transfer;
(b) if the missing information is not forthcoming, the requesting financial institution must consider whether, in all the circumstances, the absence of complete originator information creates or contributes to suspicion about the funds transfer or a related transaction; (c) if the funds transfer is deemed to be suspicious, then it must be reported by the requesting financial institution to the Unit under section 14 of this Act and the financial institution may decide not to accept the funds transfer.
(2) A financial institution must report to the Unit — (a) all suspicious funds and transactions, including attempted transactions, and all suspicious information; (b) pursuant to section 7 of the Act, all transactions and attempted transactions for which satisfactory evidence of identity has not been obtained under the Act and this Regulation; or (c) pursuant to section 16 of the Act, information relating to terrorist groups.
(3) A relevant supervisory authority and the Unit may issue guidelines relating to the reports to be made under section 14 of the Act.
(2) Pursuant to section 42(a) of the Act, a financial institution set out in sub regulation (3) need not report the following class of transactions of an amount in cash of $10,000 and above or its equivalent in foreign currency; (a) transactions with established retail customers, as specified in writing by the Unit except transactions involving the selling of vehicles, vessels, farm machinery, aircraft, jewelleries, or other high value commodities; (b) transactions with Fiji government authorities; (c) routine pay-roll transactions; (d) transactions with other class or type of customers, as specified in writing by the Unit.
(3) Sub regulation (2) applies to a financial institution carrying on a business or activity of: (a) banking; (b) an insurer; or (c) foreign exchange.
(4) A financial institution must report transactions under sub regulation (1) in Form 2 as set out in the First Schedule – Cash Transaction Report (CTR).
(2) A financial institution must report transfers under sub regulation (1) in Form 3 as set out in the First Schedule – Electronic Funds Transfer Transaction Report (EFTR).
(2) Notwithstanding sub regulation (1), a financial institution must report to the Unit the reports referred to in regulation 24, 25 or 26 electronically by a secure reporting system established by the Unit, if 250 transactions of each type are reportable in a year.
(3) The report referred to in regulation 24 shall be submitted as soon as practicable after the financial institution forms the suspicion or obtains the information referred to in section 14(1)(b) of the Act but no later than 2 working days after the forming of the suspicion or the receipt of the information.
(4) If practicable, a suspicious transaction report must be filed before a transaction is made.
(5) A report required under regulation 25 or 26 shall be transmitted to the Unit — (a) no later than the end of 5 working days after the day in which the transaction was undertaken; or (b) within such other period as the Unit may specify for any particular class of customers, class of transactions, or class of financial institutions.
(6) The reports may be transmitted by batch, and the Unit and a financial institution must agree as to what constitutes a batch.
(7) A relevant supervisory authority or the Unit, shall issue guidelines in relation to the reporting of transactions referred to in regulation 24, 25 or 26.
(2) The cash transaction report referred to in regulation 25 must contain all relevant information concerning the customer, transaction and financial institution, as set out in Form 2 of Schedule 1.
(3) The electronic funds transfer transaction report referred to in regulation 26 must contain all relevant information concerning the customer, transaction and financial institution as set out in Form 3 of Schedule 1.
(4) The Unit, after consultation with the financial institution, may — (a) waive compliance with certain parts of the reporting forms referred to in regulation 25, 26, 27; and (b) determine the mandatory and optional details to be reported under subregulation (1), (2) or (3).
(2) The programmes referred to in sub regulation (1), regulation 4 and regulation 5 must have regard to the risk of money laundering and financing of terrorism, the size and nature of business, and the types of products and services offered by the financial institution.
(2) In this regulation, “shell bank” shall mean a bank incorporated in a jurisdiction in which it has no physical presence or which is unaffiliated with a regulated financial group.
(2) The compliance officer and other employees designated by such officer must have timely access to customer identification data and other customer due diligence information, transaction records and other relevant information.
(3) Subject to section 21(4) of the Act, a financial institution must provide the Unit with the contact information, and any changes to such information for its compliance officer.
(4) The compliance officer’s contact information must be provided to the Unit in Form 5 set out in Schedule 2 – AML Compliance Officer Contact Information and Notification Form and shall contain such details as set in the form.
(2) A financial institution may provide a copy of the report of the audit function undertaken under sub regulation (1) to the Unit and a supervisory authority.
(3) Notwithstanding sub regulation (2), an auditor of a financial institution must report to the Unit any suspicious information or transaction noted during the audit function.
(2) Any procedure for screening employee must ensure that — (a) employees have the high level of competence necessary for performing their duties; (b) employees have appropriate ability and integrity to conduct its business activities; (c) potential conflicts of interests are taken into account, including the financial background of the employee; (d) proper code of conduct requirements are defined; (e) persons convicted of offences involving fraud, dishonesty or other similar offences are not employed by it.
(3) For the purposes of section 21(1)(b) of the Act, a financial institution must establish ongoing employee training to ensure that employees are kept informed of new developments, including — (a) information on current money laundering and financing of terrorism techniques, methods and trends; (b) aspects of anti-money laundering and combating the financing of terrorism laws and obligations, and in particular; (c) requirements concerning customer due diligence and suspicious and other transaction reporting.
(4) The relevant supervisory authority or the Unit may issue guidelines in relation to the development and implementation of internal procedures, policies, controls and programmes by financial institutions.
(2) The relevant supervisory authority may issue guidelines specifying what factors the financial institution must take into account when determining whether customers are of a higher risk.
(3) The relevant supervisory authority may issue guidelines specifying what factors the financial institution must take into account when determining whether customers are of a lower risk.
(2) The relevant supervisory authority may issue guidelines in relation to the reporting of suspicious transactions referred to in section 14 of the Act.
Made this 30th day of April, 2007
A. S. KHAIYUM
Attorney-General, Minister for Justice, Electoral Reform & Anti-Corruption