COPY
REGULATION OF THE BOARD OF COMMISSIONERS
OF THE FINANCIAL SERVICES AUTHORITY
OF THE REPUBLIC OF INDONESIA
NUMBER 4 OF 2026
CONCERNING
GUIDELINES FOR IMPLEMENTING ANTI-MONEY LAUNDERING,
COUNTER-TERRORISM FINANCING, AND COUNTER-PROLIFERATION
FINANCING PROGRAMS FOR TRUSTEES
BY THE GRACE OF GOD THE ALMIGHTY,
THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that in order to provide guidelines for the implementation of anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs for trustees as mandated by Financial Services Authority Regulation Number 8 of 2023 concerning the Implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs in the Financial Services Sector, it is necessary to regulate further technical guidelines regarding the reporting of the implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing programs for Trustees;
b. that based on the considerations as referred to in letter a, it is necessary to establish a Regulation of the Board of Commissioners concerning Guidelines for Implementing Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs for Trustees;
Recalling:
- Law Number 8 of 1995 concerning the Capital Market (State Gazette of the Republic of Indonesia Year 1995 Number 64, Supplement to the State Gazette of the Republic of Indonesia Number 3608) as amended lastly by Law Number 4 of 2026 concerning Amendments to Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2026 Number 62, Supplement to the State Gazette of the Republic of Indonesia Number 7180);
- Law Number 21 of 2011 concerning the Financial Services Authority (State Gazette of the Republic of Indonesia Year 2011 Number 111, Supplement to the State Gazette of the Republic of Indonesia Number 5253) as amended lastly by Law Number 4 of 2026 concerning Amendments to Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2026 Number 62, Supplement to the State Gazette of the Republic of Indonesia Number 7180);
- Financial Services Authority Regulation Number 8 of 2023 concerning the Implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs in the Financial Services Sector;
DECIDES:
Establishing: A REGULATION OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY CONCERNING GUIDELINES FOR IMPLEMENTING ANTI-MONEY LAUNDERING, COUNTER-TERRORISM FINANCING, AND COUNTER-PROLIFERATION FINANCING PROGRAMS FOR TRUSTEES
Article 1
Provisions regarding guidelines for the implementation of anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs for trustees are contained in the Appendix of this Regulation of the Board of Commissioners of the Financial Services Authority.
Article 2
Provisions regarding guidelines for the implementation of anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs for trustees as contained in:
a. Appendix I which contains Guidelines for Implementing Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs for Trustees; and
b. Appendix II which contains reporting formats, questionnaires for anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs for trustees, and examples of suspicious financial transactions related to anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs for trustees,
which are an integral part of this Regulation of the Board of Commissioners of the Financial Services Authority.
Article 3
(1) Updates to individual risk assessments of money laundering crimes, terrorism financing crimes, and proliferation financing of weapons of mass destruction that have been prepared and submitted to the Financial Services Authority prior to the entry into force of this Regulation are declared still valid.
(2) Updates to the risk assessment documents as referred to in paragraph (1) conducted after the entry into force of this Regulation of the Board of Commissioners of the Financial Services Authority must use the format as regulated in this Regulation of the Board of Commissioners of the Financial Services Authority.
Article 4
Provisions regarding the submission of anti-money laundering, counter-terrorism financing, and counter-proliferation financing questionnaires as regulated in this Regulation of the Board of Commissioners of the Financial Services Authority shall apply for the 2027 reporting period.
Article 5
This Regulation of the Board of Commissioners of the Financial Services Authority shall enter into force on the date of establishment.
Established in Jakarta
on July 7, 2026
EXECUTIVE HEAD OF CAPITAL MARKET, DERIVATIVE FINANCIAL, AND CARBON BOURSE SUPERVISOR,
FINANCIAL SERVICES AUTHORITY
OF THE REPUBLIC OF INDONESIA,
sd.
HASAN FAWZI
APPENDIX I
REGULATION OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY
OF THE REPUBLIC OF INDONESIA
NUMBER 4 OF 2026
CONCERNING
GUIDELINES FOR IMPLEMENTING ANTI-MONEY LAUNDERING, COUNTER-TERRORISM FINANCING, AND COUNTER-PROLIFERATION FINANCING PROGRAMS FOR TRUSTEES
I. GENERAL PROVISIONS
In the Appendix of this Regulation of the Board of Commissioners of the Financial Services Authority, the following terms are meant:
- Trustee is a Party representing the interests of holders of debt securities and/or sukuk.
- Public Offering is the activity of offering securities conducted by the Issuer to sell securities to the public based on procedures regulated in the Law on the Development and Strengthening of the Financial Sector and its implementing regulations.
- Securities are negotiable instruments or investment contracts, whether conventional and digital or other forms according to technological developments, which give rights to their owners to directly or indirectly obtain economic benefits from the issuer or from a specific party based on agreements and any Derivatives over Securities, which can be transferred and/or traded on the Capital Market.
- Trust Agreement is an agreement between the Issuer and the Trustee in the context of issuing debt securities and/or Sukuk.
- Issuer is the party conducting the Public Offering.
- Third Party is a financial institution, provider of goods and/or services, specific professions, and/or other entities that are required to implement the Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing programs in the Financial Services Sector, including having customer due diligence procedures and document management, and subject to regulation, supervision, and monitoring by competent authorities in accordance with legislation.
- Prospective Customer is an Issuer that will use the services of the Trustee based on the Trust Agreement.
- Customer is an Issuer that uses the services of the Trustee based on the Trust Agreement.
- Transaction is the Trust Agreement.
- Financial Transaction is the payment of interest, profit sharing, margin, or remuneration and/or repayment of the principal amount or principal value of debt securities and/or sukuk including penalties (if any) to holders of debt securities and/or sukuk for and on behalf of the Customer, conducted by the Customer directly or through a payment agent, in accordance with provisions in the Trust Agreement.
- Suspicious Financial Transaction is a suspicious financial transaction related to money laundering crimes, terrorism financing crimes, and/or proliferation financing of weapons of mass destruction.
- Board of Directors is the Board of Directors as referred to in the Law concerning limited liability companies.
- Board of Commissioners is the Board of Commissioners as referred to in the Law concerning limited liability companies.
- Money Laundering Crime, hereinafter abbreviated as TPPU, is TPPU as referred to in laws concerning the prevention and eradication of money laundering crimes.
- Terrorism Financing Crime, hereinafter abbreviated as TPPT, is TPPT as referred to in laws concerning the prevention and eradication of terrorism financing crimes.
- Proliferation Financing of Weapons of Mass Destruction, hereinafter abbreviated as PPSPM, is PPSPM as referred to in laws concerning proliferation financing of weapons of mass destruction.
- Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing, hereinafter abbreviated as APU, PPT, and PPPSPM, are efforts to prevent and eradicate TPPU, TPPT, and/or PPSPM.
- List of Suspected Terrorists and Terrorist Organizations, hereinafter abbreviated as DTTOT, is a list of names of suspected terrorists and terrorist organizations as referred to in legislation concerning the prevention and eradication of TPPT.
- List of Proliferation Financing of Weapons of Mass Destruction, hereinafter abbreviated as DPPSPM, is a list of names of suspected perpetrators of PPSPM as referred to in legislation concerning the prevention and eradication of PPSPM.
- Customer Due Diligence, hereinafter abbreviated as CDD, is an activity consisting of identification, verification, and monitoring conducted by the Trustee to ensure transactions align with the profile, characteristics, and/or transaction patterns of Prospective Customers and Customers.
- Politically Exposed Person, hereinafter abbreviated as PEP, is a person given authority to perform important functions (prominent function), not intended for middle or lower levels.
- Enhanced Due Diligence, hereinafter abbreviated as EDD, is more in-depth CDD actions conducted by the Trustee against Prospective Customers or Customers with high risk and/or in high-risk areas.
- High-Risk Customer is a Customer who, based on background, identity, history, and/or the results of risk assessments conducted by the Trustee, has a high risk of engaging in activities related to TPPU, TPPT, and/or PPSPM.
- High-Risk Country is a country or territory that is potentially used as a place for the occurrence of or means for crimes or crimes of origin, TPPU, TPPT, and/or PPSPM.
- Beneficial Owner is an individual who has rights to and/or receives certain benefits related to the Customer, is the actual owner of the Issuer, controls the Customer, grants power of attorney to conduct Transactions, controls corporations or other legal arrangements, and/or is the ultimate controller of the Issuer.
- Financial Action Task Force, hereinafter abbreviated as FATF, is an international body aimed at establishing international standards in the prevention and eradication of TPPU, TPPT, and/or PPSPM and other matters threatening the integrity of the international financial system.
- FATF Recommendations are recommendations issued by FATF and serve as standards for the prevention and eradication of TPPU, TPPT, and/or PPSPM.
- Financial Conglomerate is a financial service institution located within 1 (one) group or cluster due to ownership and/or control linkages.
- Payment Agent is a party that enters into a contract with the Issuer in the form of a notarial deed to execute payments of interest, profit sharing, margin, or remuneration and/or repayment of the principal amount or principal value of debt securities and/or Sukuk including penalties to holders of debt securities and/or Sukuk for and on behalf of the Issuer.
II. OVERVIEW OF TPPU, TPPT, AND PPSPM
- In order to mitigate risks of TPPU, TPPT, and/or PPSPM occurring through the Trustee medium, there is a need to improve the quality of implementing APU, PPT, and PPPSPM programs based on a risk-based approach in accordance with general principles applicable internationally and in line with national risk assessment (NRA) and sectoral risk assessment (SRA).
- Overview of TPPU
a. Fundamentally, the TPPU process can be grouped into 3 (three) stages of activities including:
- placement, which is the effort to place cash derived from criminal acts into the financial system.
- layering, which is the effort to obscure the origin of assets derived from criminal acts (dirty money) involving the Trustee; and/or
- integration, which is the effort to combine or use assets that appear legitimate, either to enjoy directly, invest in various types of financial products/services, or other material forms, used to finance legitimate business activities, or to re-finance criminal activities.
b. Some money laundering modus operandi and typologies related to TPPU in Trustees include:
- utilization of corporations or use of shell companies, where criminal proceeds are channeled into legal corporate entities that are essentially shell companies to facilitate their activities. These shell companies are established solely to conduct fictitious transactions with the aim of obscuring criminal funds;
- misuse of investment funds by Customers that does not align with the purpose of the Public Offering;
- mingling, which is a technique of mixing or combining criminal proceeds with proceeds from legitimate business activities with the aim of obscuring the source of criminal funds;
- use of other people's names (nominees), family members, and/or Third Parties by parties within the Customer's management structure who will represent the Customer in the process of establishing a business relationship with the Trustee, intended to obscure the identities of those committing crimes by using the legitimate identity of other parties;
- use of fake identities by parties within the Customer's management structure who will represent the Customer in the process of establishing a business relationship with the Trustee, intended to obscure the identities of those committing crimes, thereby generating new identities that appear genuine by using the legitimate identity of other parties. The forms of fake identity usage include impersonation identities (imitating identities) and synthetic identities (combining real and fake identities). Impersonation identities are done by stealing another person's identity, while synthetic identities use identity forgery by combining real and fake identities to generate a new identity that appears genuine; and
- use or cooperation with companies in tax haven countries/jurisdictions that have no real business (paper companies), as classified by competent international organizations, including countries/jurisdictions categorized as High-risk and other Monitored Jurisdictions by FATF.
- Overview of TPPT
a. Unlike TPPU, whose purpose is to disguise the origin of assets, the purpose of TPPT is to support terrorist activities, whether with assets derived from criminal acts or from assets obtained legitimately.
b. Fundamentally, the TPPT process can be grouped into 3 (three) stages of activities including:
- fund collection (collecting/raising funds), which is the activity of collecting funds conducted by terrorists, terrorist organizations, and/or other parties providing funds for TPPT, where funds are obtained through legal or illegal means.
- fund transfer (moving/storing/transferring funds), which is the activity of providing, giving, and/or lending funds from the fund owner to terrorists and/or terrorist organizations.
- fund usage (using), which is the activity of using or utilizing funds that have been collected or received by terrorists and/or terrorist organizations for terrorist criminal activities.
c. Some TPPT modus operandi and typologies that may occur through the Trustee medium include:
- misuse of investment funds by Customers that does not align with the purpose of the Public Offering, where investment funds are used to be provided, collected, given, and/or lent to terrorists and/or terrorist organizations, directly or indirectly, with the intent that they be used wholly or partially to commit terrorist crimes; and
- parties within the Customer's management structure who will represent the Customer and/or parties who are Beneficial Owners of the Customer listed in the DTTOT.
- Overview of PPSPM
a. PPSPM is defined as the provision of funds or financial services used, wholly or partially, for the manufacture, acquisition, possession, development, export, shipment, brokering, transport, transfer, stockpiling, or use of nuclear, chemical, or biological weapons, and materials related thereto (such as purchasing goods or wages), in violation of legislation.
b. PPSPM has critical points where the crime is not limited to the process of manufacturing a weapon of mass destruction such as nuclear, but also covers various supporting structures, such as providing raw material logistics, utilizing specific shipping lines to distribute logistics or even other military hardware, up to the formation of front companies to cover transactions used as efforts to support PPSPM.
c. Some PPSPM modus operandi and typologies that may occur through the Trustee medium include:
- misuse of investment funds by Customers that does not align with the purpose of the Public Offering, where investment funds are used to be provided, collected, given, and/or lent to entities, corporations, and/or individuals, directly or indirectly, with the intent that they be used wholly or partially to commit PPSPM; and
- parties within the Customer's management structure who will represent the Customer and/or parties who are Beneficial Owners of the Customer listed in the DPPSPM.
III. IMPLEMENTATION OF APU, PPT, AND PPPSPM PROGRAMS BASED ON RISK (RISK-BASED APPROACH)
- Trustees must implement APU, PPT, and PPPSPM programs effectively according to the needs of the Trustee based on risk assessments of TPPU, TPPT, and/or PPSPM, business model, business activities, business scale, business complexity, business characteristics, and/or significant events or developments in the management and operations of the Trustee, which include:
a. active supervision by the Board of Directors and Board of Commissioners;
b. policies and procedures;
c. internal controls;
d. information management systems; and
e. human resources and training.
- Trustees must identify, assess, and understand TPPU, TPPT, and/or PPSPM risks related to Customers, geographic areas (including countries/jurisdictions), products/services, and/or Transaction methods/distribution channels. Trustees must conduct individual risk assessments (Individual Risk Assessment/IRA) of TPPU, TPPT, and/or PPSPM and implement an effective risk management framework. Trustees can subsequently allocate resources according to the risk profile faced, manage internal controls, internal structures, and implement policies and procedures to prevent and detect TPPU, TPPT, and/or PPSPM.
In implementing a risk-based approach for APU, PPT, and PPPSPM programs, Trustees must pay attention to the IRA prepared, which refers to the NRA and SRA. Since TPPU, TPPT, and/or PPSPM risks can develop and change, Trustees must be responsive and consider these risk changes.
- Risk Concept
a. Definition of Risk
Risk is defined as the possibility of TPPU, TPPT, and/or PPSPM occurring, which can cause damage or losses to the Trustee that may result from a transaction.
b. Risk Management
Risk management is a process widely used to assist in decision-making. In relation to TPPU, TPPT, and/or PPSPM, the process includes understanding TPPU, TPPT, and/or PPSPM risks, assessing these three aspects, and developing methods to manage and mitigate identified risks.
In implementing risk management over TPPU, TPPT, and/or PPSPM risks, Trustees can develop risk management methods according to the needs of the Trustee based on risk assessments of TPPU, TPPT, and/or PPSPM, business model, business activities, business scale, business complexity, business characteristics, and/or significant events or developments in the management and operations of the Trustee, while still referring to legislation regulating the implementation of APU, PPT, and PPPSPM programs.
c. Risk-Based Approach
In the context of TPPU, TPPT, and/or PPSPM, the risk-based approach is a process that includes the following:
- risk assessment covering at least 4 (four) risk factors, namely:
a) Customers;
b) geographic areas (including countries/jurisdictions);
c) products/services; and
d) Transaction methods/distribution channels.
- Trustees must consider all relevant risk factors, including the risk of using information systems.
- Trustees must manage and mitigate TPPU, TPPT, and/or PPSPM risks through the implementation of internal controls and taking mitigation steps appropriate to the identified risks.
- In identifying, assessing, managing, and mitigating TPPU, TPPT, and/or PPSPM risks, Trustees must understand that these activities are not static. Identified risks can change over time in line with...
- 8 -
with the development of products/services/services or new threats that enter the business activities of the Trustee.
- The Trustee must periodically update the assessment of ML, TF, and/or PPF risks according to the needs of the Trustee.
- Risk-Based Approach Cycle
a. In implementing a risk-based approach, the Trustee must carry out 6 (six) stages of activities as follows:
- identifying inherent risks;
- setting risk tolerance;
- implementing a risk-based approach;
- formulating risk mitigation steps;
- evaluating residual risks; and
- reviewing the existing risk-based approach.
b. The cycle of the risk-based approach as stated in the Appendix, which is an integral part of this OJK Commissioner Regulation, is attached.
- Description of Each Stage in the Risk-Based Approach Cycle
a. Stage 1: Identification of Inherent Risk
- In identifying inherent risks, the Trustee must consider the vulnerability of the Trustee to be used as a means of ML, TF, and/or PPF. The initial step in conducting a risk assessment is to understand the Trustee's overall business activities from a broad perspective. This understanding enables the Trustee to consider potential ML, TF, and/or PPF risks, whether they occur on the Client side, geographic area (including countries/jurisdictions), products/services/services, and/or Transaction methods/distribution channels.
- The Trustee must consider elements that trigger risks for the Trustee, from the Client side, geographic area (including countries/jurisdictions), products/services/services, and/or Transaction methods/distribution channels. The Trustee must understand what elements constitute inherent risks and residual risks.
- Client Risk
The Trustee must pay attention to ML, TF, and/or PPF risks related to the profile of Prospective Clients or Clients. The Trustee must categorize clients based on ML, TF, and/or PPF risk levels, referring to the risk classification established by the Trustee.
- Client risks related to the specific business processes of the Trustee increase if:
- 9 -
a) The Client or Beneficial Owner provides very minimal information or information that is suspected to be fictitious;
b) The Client or Beneficial Owner obscures or does not disclose their true identity;
c) The Trustee's Client has a complex ownership structure or makes it difficult to identify who the Beneficial Owner is;
d) The Client is a company whose ownership is held by individuals or corporations located in High-Risk Countries;
e) risk of using Third-Party identities;
f) risk of using fake identities in the form of identity forgery; and/or
g) parties within the Client's management structure who will represent the Client and/or parties who are the Beneficial Owners of the Client are listed in the DTTOT and/or DPPSPM.
- Geographic Area Risk (Including Countries/Jurisdictions)
In conducting risk assessments, the Trustee must identify risks related to geographic area locations (including countries/jurisdictions), both the geographic location of the Trustee and the geographic location of the Client, or the location where the business relationship occurs, and its impact on overall risk.
ML, TF, and/or PPF risks related to geographic areas (including countries/jurisdictions) increase if:
a) The Client has an affiliation relationship with individuals and/or corporations from high-risk geographic areas (including countries/jurisdictions);
b) The Client is located in a high-risk area; and
c) For example, Prospective Client A intends to establish a business relationship with Trustee B, where the Prospective Client has already become a Client of Financial Service Provider C (a third party). Trustee B can use the CDD results conducted by Financial Service Provider C (third party) on Prospective Client A, provided that Trustee B first conducts or has a cooperation agreement with Financial Service Provider C (third party), so that Prospective Client A can be accepted as a Client by Trustee B. Trustee B, as a Trustee using third-party CDD results, remains responsible for those CDD results. If it is later discovered that Prospective Client A committed ML, TF, and/or PPF, then Trustee B is deemed negligent in conducting CDD on Prospective Client A.
d) The Client is or collaborates with companies in tax haven countries/jurisdictions that do not have real business (paper companies), as classified by competent international organizations, including countries/jurisdictions categorized as High-risk and other Monitored Jurisdictions by FATF.
Indicators determining that a country/jurisdiction is high-risk regarding ML, TF, and/or PPF include:
i. Countries/jurisdictions identified by organizations conducting mutual assessments of a country/jurisdiction (such as: Financial Action Task Force on Money Laundering (FATF), Asia Pacific Group on Money Laundering (APG), Caribbean Financial Action Task Force (CFATF), Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the Financing of Terrorism (MONEYVAL), Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), The Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), El Grupo de Accion Financiera de Sudamerica (GAFISUD), Intergovernmental Anti-Money Laundering Group in Africa (GIABA) or Middle East and North Africa Financial Action Task Force (MENAFATF)) as jurisdictions that do not adequately implement FATF Recommendations;
ii. Countries/jurisdictions identified as non-cooperative or Tax Havens by the Organization for Economic Cooperation and Development (OECD);
iii. Countries/jurisdictions with low levels of good governance as determined by the World Bank;
iv. Countries/jurisdictions with high corruption risk levels as identified in the Transparency International Corruption Perception Index;
v. Countries/jurisdictions widely known as places of production and centers of drug trade;
vi. Countries/jurisdictions subject to sanctions, embargoes, or similar measures, including by the United Nations; or
vii. Countries/jurisdictions identified by trusted institutions as funding or supporting terrorist activities, or allowing terrorist organization activities within their country/jurisdiction.
- Product/Service/Service Risk
Risk assessments must also include determining ML, TF, and/or PPF risks that may occur over various products/services/services offered. However, considering that the Trustee only issues 1 (one) type of service, namely trust services, for Clients, the assessment of product/service/service risks must be conducted casuistically or case by case for each Client.
- Risk assessments must also include determining ML, TF, and/or PPF risks on the transaction methods or distribution networks used in Financial Transactions.
Thus, the Trustee must assess the risk level for 2 (two) types of Financial Transactions that can occur based on trust contracts, namely Financial Transactions conducted directly by the Client or Financial Transactions conducted through a payment agent.
- Other Relevant Risks
Other relevant factors that can impact ML, TF, and/or PPF risks include:
a) developments in ML, TF, and/or PPF modus operandi and typologies;
b) business models, business activities, business scale, business complexity, business characteristics, and/or major events or developments in the management and operations of the Trustee; and
c) audit trails, where the Trustee is required to provide audit trails for all its activities within the Trustee's electronic system, at minimum using electronic spreadsheet applications or similar systems. Audit trails are very important as they are used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations.
- The Trustee needs to consider that the risk factors as referred to in items 3) through 8) above may be interrelated between 1 (one) risk factor and other risk factors.
- Indicators that can increase risk are not limited to those referred to in items 3) through 8). Risk-increasing indicators can develop according to the needs of the Trustee based on ML, TF, and/or PPF risk assessments, business models, business activities, business scale, business complexity, business characteristics, and/or major events or developments in the management and operations of the Trustee.
- After identifying and documenting inherent risks, the Trustee needs to assess each risk from Prospective Clients, for example, as low, medium, and high.
- In conducting the identification stage of inherent risks, the Trustee must be able to explain the entire risk identification process conducted by the Trustee and the reasons or considerations behind it.
b. Stage 2: Setting Risk Tolerance
- Risk tolerance is the level and type of risk that can be maximally tolerated or executed and set by the Trustee, where this risk at least covers compliance with regulations regarding the implementation of APU PPT and PPPSPM programs in the financial services sector and its implementing regulations. Risk tolerance is an elaboration of the risk level to be taken (risk appetite). Meanwhile, risk appetite is the risk that the Trustee wishes to take, either in the form of a risk taker or non-risk taker.
- The Trustee must set risk tolerance before considering risk mitigation.
- In setting risk tolerance, the Trustee needs to consider risk categories that can affect the Trustee, including:
a) compliance risk;
b) reputational risk;
c) legal risk;
d) operational risk; and
e) fraud risk.
c. Stage 3: Implementation of Risk-Based Approach
- The Trustee must implement APU, PPT, and PPPSPM programs with a risk-based approach, considering ML, TF, and/or PPF risk assessments as referred to in the IRA, which refer to the NRA and SRA.
- The risk-based approach owned by the Trustee must be documented to demonstrate the Trustee's compliance level. The risk-based approach must be communicated, understood, and adhered to by all employees, especially employees from work units related to Clients, including in the CDD/EDD process and reporting Transactions to relevant authorities.
- The risk-based approach conducted by the Trustee must be able to support the following activities:
a) Client identification based on risk levels;
b) detection of Suspicious Financial Transactions;
c) determination of monitoring intensity adjusted to Client risk levels, including from the aspects of frequency, implementation procedures, and evaluation of monitoring results;
d) special actions for high-risk areas;
e) record-keeping;
f) planning and implementation of updating Client and Beneficial Owner data and information based on risk levels; and
g) reporting related to Suspicious Financial Transactions.
- The Trustee needs to consider that in risk management and risk mitigation, leadership and involvement of senior officials, the Board of Directors, and the Board of Commissioners are required. For example, appointing senior officials responsible for business relationships with Clients and/or Beneficial Owners meeting high-risk criteria, including PEPs for Beneficial Owners. Where such senior officials are authorized to:
a) grant approval or rejection for opening business relationships; and
b) make decisions to continue or terminate business relationships.
d. Stage 4: Risk Mitigation Steps
- Risk mitigation is the application of internal controls to limit identified ML, TF, and/or PPF risks in risk assessments. Risk mitigation helps the Trustee ensure that its business activities remain within the established risk tolerance limits.
- Risk mitigation conducted by the Trustee will vary for each area, depending on the risk level of that area.
- The Trustee must develop mitigation strategies for each risk level, documented in writing. Furthermore, the implementation of these strategies must be documented. The Trustee must be able to explain and provide documented information to the OJK showing that the Trustee has specifically paid attention to and carried out mitigation steps according to the risk level of each area.
- The Trustee must also be able to demonstrate to the OJK that these risk mitigation steps have been implemented effectively, for example, shown through internal audit results or independent audit results.
- With risk mitigation, the Trustee can:
a) set and implement continuous monitoring and updating activities at every risk level for all Clients. For Clients with higher risk levels, the frequency of monitoring and updating is conducted more often compared to Clients with lower risk levels;
b) implement stricter mitigation for high-risk areas, including taking stricter steps in identification, verification, and monitoring in the EDD process for high-risk Clients; and
c) apply internal controls consistently, especially in mitigating risks in high-risk areas.
e. Stage 5: Evaluation of Residual Risk
- Residual risk is the risk remaining after the application of risk mitigation. The Trustee needs to consider that no matter how tight the risk mitigation and risk management are, the Trustee will still have residual risks that must be managed well.
- Residual risk must align with the established risk tolerance. The Trustee must ensure that residual risk is not greater than the established risk tolerance. In cases where residual risk is still greater than risk tolerance, or in cases where mitigation for high-risk areas is inadequate, the Trustee must return to performing risk reduction and mitigation steps, and increase the level or quantity of established risk mitigation steps.
- Characteristics of residual risk are:
a) risk has been tolerated/accepted:
In this risk, the risk remains even though risk mitigation has been conducted according to the Trustee's risk tolerance. Tolerated risks can increase over time. For example, when new ML, TF, and/or PPF threats arise.
b) risk has been mitigated:
In this risk, the risk remains even though it has been mitigated. This risk has been reduced but cannot be eliminated. In practice, established risk mitigation may not be applicable.
- With activities evaluating residual risk, the Trustee can:
a) evaluate the residual risks owned; and
b) adjust the owned risk levels with tolerated/accepted risks.
f. Stage 6: Review of Existing Risk-Based Approach
- The ML, TF, and/or PPF risk assessments owned by the Trustee must be reviewed according to the Trustee's needs based on ML, TF, and/or PPF risk assessments, business models, business activities, business scale, business complexity, business characteristics, and/or major events or developments in the management and operations of the Trustee, which also includes the development of products/services/services and new business practices (including Transaction methods/distribution channels and/or the use of new technologies or technology development for existing products/services/services).
- Reviews of the existing risk-based approach are conducted to test the effectiveness of the implementation of APU, PPT, and PPPSPM programs.
- Reviews of the risk assessment approach can help the Trustee in evaluating improvements to existing policies and procedures or for the formation of new policies and procedures.
- With reviews of the risk-based approach, the Trustee can:
- 15 -
a) conduct reviews according to the Trustee's needs;
b) generate reviews to test the effectiveness of the risk-based approach;
c) record-keep the review process and report to senior officials, the Board of Directors, and/or the Board of Commissioners; and
d) record-keep review results with the establishment of corrective steps to be followed up.
IV. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
- Active Supervision by the Board of Directors
In conducting active supervision, the Board of Directors must at least do the following:
a. propose written policies and procedures regarding the implementation of APU, PPT, and PPPSPM programs to the Board of Commissioners, including ML, TF, and/or PPF risk mitigation, containing at least:
- identification and verification of Prospective Clients or Clients;
- identification and verification of Beneficial Owners;
- continuous management of ML, TF, and/or PPF risks towards Clients, geographic areas (including countries/jurisdictions), products/services/services, and/or Transaction methods/distribution channels;
- maintenance of accurate data related to Transactions, record-keeping of the CDD process, and record-keeping of policies and procedures;
- updating and monitoring;
- reporting to senior officials, the Board of Directors, and the Board of Commissioners regarding the implementation of APU, PPT, and PPPSPM program policies and procedures; and
- reporting to the Center for Reporting and Analysis of Financial Transactions.
b. ensure that the implementation of APU, PPT, and PPPSPM programs is carried out in accordance with established written policies and procedures;
c. form special work units and/or appoint officials responsible for the implementation of APU, PPT, and PPPSPM programs;
d. supervise the compliance of work units/Responsible Officials in implementing APU, PPT, and PPPSPM programs;
e. ensure that written policies and procedures regarding the implementation of APU, PPT, and PPPSPM programs align with changes and developments in products/services/services and technology in the financial services sector as well as with developments in ML, TF, and/or PPF modus operandi and typologies;
f. ensure that employees, especially employees from relevant work units (such as work units directly or indirectly related to Prospective Clients, such as client service officers, officers related to IT management and development, and internal auditors) and new employees, have participated in continuous and periodic training related to the implementation of APU, PPT, and PPPSPM programs at least 1 (one) time in 1 (one) year.
In cases where, based on the Trustee's needs according to ML, TF, and/or PPF risk assessments, business models, business activities, business scale, business complexity, business characteristics, and/or major events or developments in the management and operations of the Trustee, training can be conducted more than 1 (one) time in 1 (one) year; and
g. ensure that discussions regarding the implementation of APU, PPT, and PPPSPM programs take place in Board of Directors meetings.
- Active Supervision by the Board of Commissioners
In conducting active supervision, the Board of Commissioners must at least do the following:
a. ensure that the Trustee has policies and procedures for implementing APU, PPT, and PPPSPM programs;
b. approve the APU, PPT, and PPPSPM program policies and procedures proposed by the Board of Directors;
c. evaluate the APU, PPT, and PPPSPM program policies and procedures;
d. supervise the implementation of the Board of Directors' responsibilities regarding the implementation of APU, PPT, and PPPSPM programs; and
e. ensure that discussions regarding the implementation of APU, PPT, and PPPSPM programs take place in Board of Directors and Board of Commissioners meetings. The discussion meetings of the Board of Directors and Board of Commissioners regarding ML, TF, and/or PPF must consider:
- the frequency of discussions regarding the implementation of APU, PPT, and PPPSPM programs in Board of Directors and Board of Commissioners meetings is conducted according to the needs and risk assessments of each Trustee.
- the discussion materials in Board of Directors and Board of Commissioners meetings can include among others:
a. existing ML, TF, and/or PPF risk mitigation at the Trustee;
b. handling of problems and/or obstacles faced by the Trustee in implementing APU, PPT, and PPPSPM programs;
c. updates of regulations and modus operandi and typologies related to APU, PPT, and PPPSPM;
d. plans and realization of APU, PPT, and PPPSPM training for Trustee employees;
e. internal audit results and follow-up on compliance regarding APU, PPT, and PPPSPM issues; and
f. effectiveness of APU, PPT, and PPPSPM program implementation.
- The results of discussion meetings must be recorded in minutes of meeting signed by the Board of Directors and Board of Commissioners attending the discussion meeting.
- In supporting the effectiveness of the implementation of the AML, CTF, and CPF programs, the Board of Directors and Board of Commissioners must:
a. understand and be responsible for the policies and procedures, implementation and supervision of the implementation of the AML, CTF, and CPF programs, including the management and mitigation of AML, CTF, and/or CPF risks in all Trustee activities.
b. have an understanding related to AML, CTF, and/or CPF risks, as well as inherent risks including Customer risk, geographic areas (including countries/jurisdictions), products/services, and/or Transaction methods/distribution networks (delivery channels), and other relevant risks, that are inherent to the Trustee, so that the Board of Directors and Board of Commissioners are able to manage and mitigate these risks adequately.
c. ensure an adequate organizational structure for the implementation of the AML, CTF, and CPF programs, including ensuring that the AML, CTF, and CPF responsible person is within the organizational structure.
- Responsible Person for the Implementation of the AML, CTF, and CPF Programs
a. The Trustee must have a responsible person for the implementation of the AML, CTF, and CPF programs.
b. The responsible person for the implementation of the AML, CTF, and CPF programs must be within the organizational structure of the Trustee.
c. The appointment of the Responsible Person for the implementation of the AML, CTF, and CPF programs is carried out according to the needs of the Trustee based on the assessment of AML, CTF, and/or CPF risks, business model, business activities, business scale, business complexity, business characteristics, and/or if there are major events or developments in the management and operations of the Trustee, meaning the Trustee can have a special work unit and a responsible official or only have a special work unit or only have a responsible official.
d. Bearing in mind that the Trustee is a business unit of a Commercial Bank, the Responsible Person for the implementation of the AML, CTF, and CPF programs at the Trustee can be held concurrently by the Responsible Person for the implementation of the AML, CTF, and CPF programs at the Commercial Bank.
e. In the event that the responsible person for the implementation of the AML, CTF, and CPF programs is a special work unit, then the following provisions must be met:
- consisting of at least 1 (one) employee acting as the leader and 1 (one) employee acting as the executor;
- the leader and executor in the special work unit do not hold other functions concurrently;
- the leader of the special work unit is determined and appointed by the Board of Directors;
- is under the direct coordination of the Board of Directors in the organizational structure of the Trustee; and
- is independent from other functions.
f. In the event that the responsible person for the implementation of the AML, CTF, and CPF programs is a responsible official, then the responsible official can only hold the compliance and risk management functions concurrently.
- 18 -
g. The responsible person for the implementation of the AML, CTF, and CPF programs reports to and is responsible to the Board of Directors who has the task of supervising the implementation of the AML, CTF, and CPF programs.
h. The responsible person for the implementation of the AML, CTF, and CPF programs at the Trustee has the following duties:
- periodically analyze the assessment of AML, CTF, and/or CPF risks related to Customers, geographic areas (including countries/jurisdictions), products/services, and/or Transaction methods/distribution networks (delivery channels), as many as 1 (one) time in 1 (one) year;
- formulate, update, and propose policies and procedures for the implementation of the AML, CTF, and CPF programs that have been formulated to manage and mitigate risks based on the risk assessment as referred to in item 1), to be considered by the Board of Directors;
- ensure the existence of a system at least using an electronic spreadsheet application or a similar system that can effectively identify, analyze, monitor, and provide reports on Suspicious Financial Transactions in accordance with provisions in the Trust Deed, such as:
a) Transactions that are not in accordance with the trust deed.
b) Based on financial reports, the Customer does not have the financial ability to fulfill obligations to holders of debt securities or sukuk, but it turns out that the Customer can fulfill obligations to holders of debt securities or sukuk;
c) The Customer does not fulfill its obligations to holders of debt securities or sukuk, even though the Customer has good financial ability to settle its obligations;
d) The Board of Directors, Board of Commissioners, shareholders, and/or Beneficial Owners of the Customers are suspected to be involved in predicate crimes, AML, CTF, and/or CPF;
e) Customers are suspected to be involved in AML, CTF, and/or CPF;
f) assets used as the basis for the issuance of sukuk are suspected to be involved in predicate crimes, AML, CTF, and/or CPF; and
g) Customers enter into agreements with material values that require information disclosure with Third Parties originating from High-Risk Countries.
- ensure that the formulated policies and procedures are in accordance with changes and/or developments in products/services, technology, and/or methods and typologies of AML, CTF, and/or CPF in the financial services sector, and/or in accordance with the needs of the Trustee based on the assessment of AML, CTF, and/or CPF risks, business model, business activities, business scale, business complexity, business characteristics,
- 19 -
and/or events or major developments in the management and operations of the Trustee;
- ensure that forms related to Customers have accommodated the data required in the implementation of the AML, CTF, and CPF programs;
- monitor indications of Suspicious Financial Transactions as referred to in item 3);
- conduct evaluations of the results of monitoring and analysis of Customer Transactions to ensure the presence or absence of Suspicious Financial Transactions;
- account for the results of monitoring and evaluation;
- ensure the updating of Customer data and profiles;
- ensure that high-risk business activities against AML, CTF, and/or CPF are identified effectively in accordance with the policies and procedures of the Trustee and provisions as referred to in the Financial Services Authority Regulation regarding the implementation of AML, CTF, and CPF programs in the financial services sector;
- ensure the existence of good communication mechanisms from each relevant work unit to the special work unit or official responsible for the implementation of the AML, CTF, and CPF programs while maintaining information confidentiality and observing anti-tipping-off provisions;
- conduct supervision regarding the implementation of the AML, CTF, and CPF programs by relevant work units, among others supervising whether relevant work units have performed their functions and duties to prepare reports regarding suspected Suspicious Financial Transactions before submitting them to the special work unit or official responsible for the implementation of the AML, CTF, and CPF programs;
- ensure the identification of areas at high risk related to the implementation of the AML, CTF, and CPF programs by referring to legislation and adequate information sources;
- periodically monitor and ensure follow-up on CFT and CPF lists is in accordance with legislation regarding the prevention and eradication of CTF and regulations regarding the prevention and eradication of CPF;
- monitor, analyze, and recommend training needs regarding the implementation of the AML, CTF, and CPF programs for Trustee employees;
- ensure that all activities for the implementation of the AML, CTF, and CPF programs are carried out well; and
- perform other tasks for the implementation of the AML, CTF, and CPF programs.
- follow up on the results of internal audit findings regarding AML, CTF, and CPF.
- formulate plans for and reports on the realization of updating Customer data of the Trustee.
i. The responsible person for the implementation of the AML, CTF, and CPF programs has the following authorities:
- obtain access to the information needed that exists in all organizational units of the Trustee;
- coordinate and monitor the implementation of the AML, CTF, and CPF programs by relevant work units;
- propose employees from relevant work units to assist in the implementation of the AML, CTF, and CPF programs;
- report Suspicious Financial Transactions, including those carried out by the Board of Directors, Board of Commissioners, and/or parties affiliated with the Board of Directors or Board of Commissioners, directly to the Financial Transaction Reports and Analysis Centre; and
- perform other authorities for the implementation of the AML, CTF, and CPF programs.
V. POLICIES AND PROCEDURES
- The Trustee must have policies and procedures to manage and mitigate identified AML, CTF, and/or CPF risks in accordance with the risk assessment documented in writing, and may be accompanied by flowcharts and explanations of each stage of the procedure. The implementation of policies and procedures must be carried out consistently and continuously, and consider information technology factors that have the potential to be abused by perpetrators of AML, CTF, and/or CPF.
- Policies and procedures for the implementation of the AML, CTF, and CPF programs based on a risk-based approach contain at least:
a. identification and verification of Prospective Customers or Customers;
b. CDD by Third Parties, if any;
c. EDD;
d. identification and verification of Beneficial Owners;
e. continuous management of AML, CTF, and/or CPF risks related to Customers, geographic areas (including countries/jurisdictions), products/services, and/or Transaction methods/distribution networks (delivery channels);
f. maintenance of accurate data related to Transactions, accounting of the CDD process, and accounting of policies and procedures;
g. updating and monitoring;
h. reporting to senior officials (officials at the level of division head or section head), Board of Directors, and Board of Commissioners; and
i. reporting to the Financial Transaction Reports and Analysis Centre.
- The Trustee must review policies and procedures as many as 1 (one) time in 1 (one) year.
- In the event that, according to the needs of the Trustee based on the assessment of AML, CTF, and/or CPF risks, business model, business activities, business scale, business complexity, business characteristics, and/or events or major developments in the management and operations of the Trustee, reviews of policies and procedures can be carried out more than 1 (one) time in 1 (one) year.
- If based on the review conducted by the Trustee it is deemed necessary to make changes to the existing policies and procedures, such changes must be formulated at the latest 6 (six) months after the results of the review.
- The Trustee must identify and assess AML, CTF, and/or CPF risks, and take adequate actions to manage and mitigate risks related to the development of products/services and new business practices (including Transaction methods/distribution networks (delivery channels) and/or the use of new technology or development of technology for existing products/services), before they are launched or used.
- Identification and verification of Prospective Customers or Customers (CDD and EDD) is carried out on Prospective Customers when the Prospective Customer establishes a business relationship with the Trustee through a Trust Deed.
- The Trustee must understand the profile, intent, and purpose of the business relationship, and Transactions carried out by Customers and Beneficial Owners through identification and verification.
- Through CDD or EDD, the Trustee can:
a. obtain detailed information regarding Prospective Customers, Customers, Beneficial Owners, and/or Customer Transactions including Suspicious Financial Transactions;
b. protect the reputation and integrity of the Trustee, facilitate compliance with regulations, and protect the Trustee from external threats, namely being used as a means of AML, CTF, and/or CPF; and
c. monitor Suspicious Financial Transactions regarding Customer Transactions that have a business relationship with the Trustee based on the Trust Deed.
- CDD or EDD is carried out by the Trustee at the time:
a. establishing a business relationship with Prospective Customers;
b. there are financial transactions in rupiah and/or foreign currency with a value of at least or equivalent to IDR 100,000,000.00 (one hundred million rupiah), including Transactions carried out in a single transaction or carried out in several transactions that are reasonably suspected to be related;
c. there are indications of Suspicious Financial Transactions related to AML, CTF, and/or CPF. CDD is carried out regardless of any transaction value exceptions or limits; or
d. the Trustee doubts the truthfulness of the information provided by Prospective Customers, Customers, and/or Beneficial Owners.
- Identification and Verification of Prospective Customers
a. In order to establish a business relationship with Prospective Customers, the Trustee must:
- perform identification by requesting data, information, and supporting documents from Prospective Customers to know the profile of the Prospective Customer; and
- perform verification on:
a) the truthfulness and suitability of data, information, and supporting documents provided by the Prospective Customer; and
b) the truthfulness and suitability of the profile of the provider of data, information, and supporting documents with the profile of the Prospective Customer to ensure that the provider of data, information, and documents is the Prospective Customer in question.
b. In establishing a business relationship, the Trustee must perform identification to know the profile of the Prospective Customer by requesting data, information, and supporting documents from the Prospective Customer, including:
- name;
- license number from the competent authority including licenses, if any;
- business field or activities;
- domicile address;
- place and date of establishment;
- legal entity or business form;
- Beneficial Owner identity;
- source of funds;
- intent and purpose of the business relationship or Transaction to be carried out by the Prospective Customer; and
- other data and information, if needed.
c. Bearing in mind that the Prospective Customer of the Trustee is in the form of a corporation, namely a company, then in the identification process it must be supported by company identity documents as follows:
a) power of attorney to the appointed party having the authority to act on behalf of the company in establishing a business relationship with the Trustee stated in the Trust Deed in the form of a notarial deed;
b) specimen signature of the authorized party representing the company in establishing a business relationship with the Trustee. The specimen signature can be replaced with an electronic signature that has met the provisions of legislation regarding electronic signatures;
c) Taxpayer Identification Number (NPWP) card for Customers required to have a Taxpayer Identification Number in accordance with legislation;
d) business place permit or other documents required by the competent authority;
e) deed of establishment/statutes;
f) business license from the competent authority;
g) financial reports or description of company business activities;
h) company management structure;
i) company ownership structure; and
j) identity documents of members of the Board of Directors or holders of power of attorney from members of the Board of Directors authorized to represent the company in establishing a business relationship with the Trustee.
d. The Trustee must verify data, information, and/or supporting documents of Prospective Customers based on documents and/or other information sources that can be trusted and independent, and ensure that the data is current data and based on AML, CTF, and/or CPF risks that have been identified based on the risk assessment conducted by the Trustee.
- 23 -
e. Bearing in mind the business model and business characteristics of the Trustee, the verification stages carried out by the Trustee on Prospective Customers can only be carried out through direct face-to-face meetings, where Trustee employees meet directly/physically with the party representing and acting on behalf of and for the Customer.
f. The Trustee must verify that the party acting on behalf of and for the Prospective Customer has obtained authorization from the Prospective Customer and perform identification and verification of the identity of that party.
g. In the event of doubt, the Trustee must request the Prospective Customer to provide more than 1 (one) identity document issued by the competent authority, and may be accompanied by conducting an interview with the Prospective Customer to ensure the truthfulness of the identity of the Prospective Customer.
h. The process of verifying the identity of Prospective Customers and Beneficial Owners must be completed before opening a business relationship with the Prospective Customer. If the Trustee has applied risk management procedures, the Trustee may establish a business relationship before the verification process is completed. However, the verification process must be completed as soon as possible at the latest 3 (three) working days from the occurrence of the Customer's business relationship with the Trustee, bearing in mind that AML, CTF, and/or CPF risks can be managed effectively and do not disrupt normal business activities.
- Grouping of Risk Levels of Prospective Customers, Customers, and/or Beneficial Owners
a. The Trustee must group Prospective Customers, Customers, and Beneficial Owners based on the level of risk of occurrence of AML, CTF, and/or CPF. Given that Prospective Customers or Customers of the Trustee are corporations in the form of companies, Prospective Customers or Customers are not classified as Prospective Customers or Customers into the low-risk category.
b. Grouping of Prospective Customers based on the level of risk of occurrence of AML, CTF, and/or CPF is carried out based on analysis of:
- identity;
- business location;
- profile;
- business activities;
- ownership structure;
- products/services to be used by the Prospective Customer; and
- other information that can be used to measure the level of risk.
c. Grouping of Customers based on the level of risk of occurrence of AML, CTF, and/or CPF is carried out based on analysis of:
- identity;
- business location;
- profile;
- business activities;
- ownership structure;
- products/services and Transaction methods/distribution networks (delivery channels) used; and
- other information that can be used to measure the level of risk.
d. Grouping of Beneficial Owners based on the level of risk of occurrence of AML, CTF, and/or CPF is carried out based on analysis of:
- identity;
- profile; and
- other information that can be used to measure the level of risk.
- Refusal of Business Relationship and Closure/Termination of Business Relationship
a. The Trustee is prohibited from opening or maintaining a business relationship using a fictitious name, namely a Prospective Customer or Customer using a name that does not match the name stated in the Customer's identity document.
b. The Trustee is prohibited from opening a business relationship with a Prospective Customer or maintaining a business relationship with a Customer, if:
- the Prospective Customer or Customer refuses to comply with regulations related to the implementation of the AML, CTF, and CPF programs; or
- the Trustee doubts the truthfulness of the identity and completeness of documents of the Prospective Customer or Customer.
c. The Trustee must refuse to establish a business relationship with a Prospective Customer with a Customer in the event that conditions meeting the criteria are present:
- unwilling to provide information and/or complete/meet data, information, and/or documents required by the Trustee;
- known and/or reasonably suspected to use fake documents;
- providing information whose truthfulness is doubted;
- having Transaction funds known and/or reasonably suspected to originate from the results of criminal acts; and
- listed on the CFT and/or CPF lists.
d. In the event of refusal of business relationship with a Prospective Customer, the Trustee must still complete the identification and verification process of the identity of the Prospective Customer, Customer, and Beneficial Owner. This must still be done for the purpose of reporting Suspicious Financial Transactions to the Financial Transaction Reports and Analysis Centre.
e. The Trustee must document the refusal of business relationship with the Prospective Customer.
f. The Trustee must report the refusal of business relationship with the Prospective Customer
- Identification and Verification of Beneficial Owners
a. The Trustee must ensure that Prospective Customers or Customers who open a business relationship or conduct Transactions act for themselves or for the benefit of Beneficial Owners.
- 25 -
b. Taking into account the business model and business characteristics of the Trustee, where the Prospective Customer or Customer of the Trustee is a corporation, the Trustee must conduct CDD or EDD against the Beneficial Owner of such Prospective Customer or Customer based on relevant information or data obtained from a trusted source.
What is meant by "trusted source" includes among others:
- Documents, information, and/or data originating from competent ministries/agencies/authorities, for example, family cards issued by ministries/agencies handling population and civil registration, paid databases, Beneficial Owner databases from the ministry handling law and human rights;
- Documents, information, and data in the context of information openness in the capital market and/or public companies, for example, data and information available at the stock exchange related to the information disclosure obligations of issuers and public companies; or
- Documents, information and/or data originating from Third Parties that based on general knowledge possess accurate information and/or data, for example, databases originating from reputable and independent public domains and/or paid Third Party databases.
c. The EDD process is conducted by the Trustee against Beneficial Owners who are at high risk, including those classified as PEPs.
d. In the event of a difference in risk level between the Prospective Customer or Customer and the Beneficial Owner, the Trustee must conduct CDD or EDD based on the higher risk level.
e. Identification and verification of the identity of the Beneficial Owner is conducted against information comprising:
- identity information and documents containing:
a) full name including alias;
b) identity document number;
c) residential address according to the identity document;
d) other residential address, if any;
e) place and date of birth;
f) nationality;
g) occupation;
h) work address and telephone number, if any;
i) gender; and
j) marital status;
- source of funds;
- average annual income and/or net worth value:
- legal relationship between the Prospective Customer or Customer and the Beneficial Owner demonstrated by an appointment letter, agreement letter, power of attorney, or other forms; and
- a statement from the Prospective Customer or Customer regarding the truthfulness of the identity and source of funds of the Beneficial Owner.
f. In the event the Trustee is uncertain regarding who the Beneficial Owner is or there is no individual exercising control through ownership, the Trustee must:
- identify and verify the identity of the individual controlling the corporation through other forms; and/or
- identify and verify the identity of the relevant individual holding a position as a Director or equivalent to that position.
g. In the event the Prospective Customer or Customer is another Domestic Financial Institution acting for and on behalf of the Beneficial Owner, identification and verification of the identity of the Beneficial Owner may be conducted through documents regarding the Beneficial Owner in the form of a written statement from the Prospective Customer or Customer that the identity of the Beneficial Owner has been verified by the Prospective Customer or Customer.
h. In the event the Prospective Customer or Customer is another Foreign Financial Institution that applies an AML, CFT, and CCPF program at least equivalent to the legislation regarding the implementation of AML, CFT, and CCPF programs representing the Beneficial Owner, the Trustee's identification and verification of the identity of the Beneficial Owner may be conducted through documents regarding the Beneficial Owner in the form of a written statement from the Prospective Customer or Customer that the identity of the Beneficial Owner has been verified by the Prospective Customer or Customer.
i. In the event the implementation of AML, CFT, and CCPF programs by Foreign Financial Institutions is not equivalent to the legislation regarding the implementation of AML, CFT, and CCPF programs, the Trustee must conduct identification and verification of the identity of the Beneficial Owner based on relevant information or data obtained from a trusted source.
j. In the event the Trustee doubts or cannot be certain of the identity of the Beneficial Owner of the Prospective Customer, the Trustee must refuse to establish a business relationship with such Prospective Customer.
k. Taking into account the business model and business characteristics of the Trustee, where the Prospective Customer or Customer of the Trustee is an Issuer, in the event that data, documents, and/or identity information of the Beneficial Owner of the Prospective Customer or Customer are available and/or publicly disclosed adequately and reliably, for example, information available and/or disclosed through the IDX website, the Trustee is not required to request data and/or identity information of the Beneficial Owner from the Prospective Customer or Customer. Data, documents, and/or identity
- 27 -
information of the Beneficial Owner that is available and/or publicly disclosed must provide assurance to the Trustee regarding the profile of the Beneficial Owner. In the event the Trustee doubts the data, documents, and/or information of the Prospective Customer or Customer that is available and/or publicly disclosed, the Trustee must request data, documents, and/or identity information of the Beneficial Owner from the Prospective Customer or Customer.
- Identification of High-Risk Prospective Customers or Customers
a. The Trustee must have an adequate risk management system to determine Prospective Customers, Customers, or Beneficial Owners, including high-risk criteria. Subsequently, the Trustee must compile a separate list of Prospective Customers, Customers, or Beneficial Owners that meet the high-risk criteria.
b. In the event the Prospective Customer, Customer, or Beneficial Owner falls under high-risk criteria, the Trustee must conduct EDD.
Several criteria for high-risk Prospective Customers, Customers, or Beneficial Owners must take into account:
- background or profile of the Prospective Customer, Customer, or Beneficial Owner;
- Transactions with parties originating from High-Risk Countries;
- Transactions inconsistent with the profile;
- Beneficial Owner falls into the PEP category. The Trustee must conduct an assessment to determine the Prospective Beneficial Owner as a PEP;
- business field of the Prospective Customer or Customer includes high-risk businesses;
- country/jurisdiction of origin or destination of the Transaction includes High-Risk Countries. Examples of High-Risk Countries include:
a) Countries/jurisdictions identified by organizations conducting mutual assessments of countries/jurisdictions (such as: FATF, Asia Pacific Group on Money Laundering (APG), Caribbean Financial Action Task Force (CFATF), Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the Financing of Terrorism (MONEYVAL), Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), The Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), El Grupo de Accion Financiera de Sudamerica (GAFISUD), Intergovernmental Anti-Money Laundering Group in Africa (GIABA) or Middle East and North Africa Financial Action Task Force (MENAFATF)) as jurisdictions that do not adequately implement FATF Recommendations;
b) Countries/jurisdictions identified as non-cooperative or Tax Havens by the Organization for Economic Cooperation and Development (OECD);
- 28 -
c) Countries/jurisdictions with low levels of good governance as determined by the World Bank;
d) Countries/jurisdictions with high levels of corruption as identified in the Transparency International Corruption Perception Index;
e) Countries/jurisdictions widely known as drug production and trading centers;
f) Countries/jurisdictions subject to sanctions, embargoes, or similar measures, including by the United Nations; or
g) Countries/jurisdictions identified by trusted institutions as funding or supporting terrorist activities, or allowing terrorist organization activities in their country/jurisdiction.
- Transactions conducted by Customers suspected to be related to predicate crimes, Money Laundering, Terrorism Financing, and/or Proliferation Financing.
c. The determination of the risk level of Prospective Customers, Customers, or Beneficial Owners, including high-risk criteria, is based on the risk to be taken and the risk that can be tolerated by the Financial Institution.
d. Regarding Beneficial Owners who are Foreign PEPs, Domestic PEPs, and persons authorized to perform important functions (prominent function) by international organizations (among others International Monetary Fund (IMF), World Bank, United Nations (UN), Organization for Economic Co-operation and Development (OECD), Asian Development Bank (ADB), and Islamic Development Bank (IDB)), in addition to applying the CDD process, the Trustee must meet the following requirements:
- have a risk management system to determine if the Beneficial Owner meets PEP criteria;
- appoint a senior official responsible for the business relationship with Beneficial Owners meeting PEP criteria;
- obtain approval from senior officials to open or continue business relationships, including Transactions, with Beneficial Owners meeting PEP criteria. In addition to providing approval, the senior official has the authority to:
a) refuse to open business relationships with Beneficial Owners classified as high risk (including PEPs); and
b) make decisions to continue or terminate business relationships and/or Transactions with Beneficial Owners falling under high-risk criteria (including PEPs). This applies to Beneficial Owners whose status changes from ordinary Beneficial Owner to PEP, including Beneficial Owners newly identified as PEPs.
- 29 -
e. Regarding Beneficial Owners who are Domestic PEPs or persons authorized to perform important functions (prominent function) in international organizations (among others International Monetary Fund (IMF), World Bank, United Nations (UN), Organization for Economic Co-operation and Development (OECD), Asian Development Bank (ADB), and Islamic Development Bank (IDB)), in addition to applying the CDD process, the Trustee must meet the following requirements:
- have a risk management system to determine if the Beneficial Owner meets PEP criteria;
- in the event there is a higher risk over the business relationship between the Trustee and the Customer or Beneficial Owner, the Trustee must apply the following provisions:
a) appoint a senior official responsible for the business relationship with Beneficial Owners meeting PEP criteria;
b) obtain approval from senior officials to open or continue business relationships with Beneficial Owners meeting PEP criteria. In addition to providing approval, the senior official has the authority to:
i. refuse to open business relationships with Beneficial Owners classified as high risk (including PEPs); and
ii. make decisions to continue or terminate business relationships with Beneficial Owners falling under high-risk criteria (including PEPs). This applies to Beneficial Owners whose status changes from ordinary Beneficial Owner to PEP, including Beneficial Owners newly identified as PEPs.
iii. conduct periodic EDD at least in the form of analysis regarding information on Beneficial Owners, source of funds, and source of wealth; and
c) stricter monitoring of the business relationship demonstrated, among others, through increased number and frequency of supervision and selection of Transaction patterns.
f. The Trustee must apply provisions applicable to Prospective Customers, Customers, or Beneficial Owners falling under high-risk criteria to Beneficial Owners who are family members or close associates of Beneficial Owners who are PEPs. What is meant by "family members of a Beneficial Owner who is a PEP" are family members or related parties of the Beneficial Owner who is a PEP up to the second degree, both horizontally and vertically, namely:
- biological/step/adoptive parents;
- biological/step/adoptive siblings;
- biological/step/adoptive children;
- biological/step/adoptive grandparents;
- biological/step/adoptive grandchildren;
- biological/step/adoptive siblings of parents;
- husband or wife;
- parents-in-law or in-laws;
- husband or wife of biological/step/adoptive children;
- grandparents of husband or wife;
- husband or wife of biological/step/adoptive grandchildren;
- biological/step/adoptive siblings of husband; or
- wife together with husband or her husband from siblings, the concerned party.
What is meant by "close associates of a Beneficial Owner who is a PEP" includes, among others, companies owned or managed by the Beneficial Owner who is a PEP or parties who generally and publicly known to have a close relationship with the Beneficial Owner who is a PEP.
g. The Trustee must conduct EDD and proportional and adequate countermeasures against risks, business relationships, Transactions, Prospective Customers and/or Customers originating from High-Risk Countries published by FATF to be subject to countermeasures.
h. Countermeasures to be conducted by the Trustee must be adjusted to FATF publications and confirmation and clarification must be sought from relevant authorities. In the event FATF publishes a list of High-Risk Countries without accompanying a call for countermeasures, the Trustee must apply countermeasures independently. Examples of countermeasures that the Trustee can choose independently include:
- requiring the Trustee to apply specific aspects in EDD;
- introducing relevant reporting mechanisms or systematic reporting of financial Transactions;
- restricting business relationships or payment obligation Transactions with countries/jurisdictions or persons identified in such countries/jurisdictions;
- prohibiting reliance on Third Parties located in the relevant country/jurisdiction to conduct the CDD process;
- requesting to review and change, or if necessary, terminate correspondent relationships with financial institutions in the relevant country/jurisdiction; and/or
- increasing external audit requirements for Financial Conglomerates, in relation to branches and
- 31 -
subsidiaries of Financial Conglomerates located in the relevant country/jurisdiction.
i. The Trustee may conduct other countermeasures that have a similar effect in mitigating Money Laundering, Terrorism Financing, and/or Proliferation Financing risks.
- Implementation of CDD by Third Parties
a. The Trustee may use identification and verification results already conducted by Third Parties against Prospective Customers who have become Customers of the Third Party.
b. The implementation of using identification and verification results does not apply to outsourcing and/or agency relationships between the Trustee and the aforementioned Third Party. If the Trustee has an outsourcing and/or agency relationship with the Third Party, then the Third Party acts for and on behalf of the Trustee when conducting CDD to Prospective Customers.
c. In the event the Trustee uses identification and verification results, the Trustee must:
- understand the purpose and objective of the business relationship; and
- identify and verify the Customer and Beneficial Owner.
d. In the event the Trustee uses CDD results already conducted by Third Parties, then the Trustee must:
- remain responsible for the CDD results already conducted by Third Parties;
- have cooperation with the Third Party in the form of a written agreement.
In the event the Trustee uses CDD results from a commercial bank where the Trustee is one of the business activities of the commercial bank, then the written agreement may be replaced with internal policies and procedures of the Trustee.
- immediately directly obtain the required information related to information and results of identification and verification;
- take adequate steps to ensure that the Third Party is willing to fulfill information requests (among others information regarding full name as stated on the identity card, address or place and date of birth, identity card number, and nationality of the Prospective Customer) and copies of supporting documents immediately without delay if needed by the Trustee in the implementation of AML, CFT, and CCPF programs;
- ensure that the Third Party is a financial institution, goods and/or service providers, specific professions, and/or other entities that must apply AML, CFT, and CCPF programs, including having CDD procedures and document archiving, and subject to regulation, supervision, and monitoring by competent authorities in accordance with legislation; and
- take into account information related to country/jurisdiction risk where the Third Party originates.
- 32 -
e. In the event the Third Party is located in a High-Risk Country, the Trustee must ensure the Third Party meets the criteria:
- is in the same Financial Conglomerate as the Trustee;
- the Financial Conglomerate has effectively implemented CDD, document archiving, and AML, CFT, and CCPF programs in accordance with FATF Recommendations; and
- the Financial Conglomerate is supervised by competent authorities. What is meant by "Competent Authority" is the authority where the Financial Conglomerate originates, which supervises the implementation of policies and procedures at the Financial Conglomerate level; and
f. In the event the Trustee uses identification and verification results conducted by Third Parties that are the same Financial Conglomerate, the Trustee or the parent company of the Financial Conglomerate must consider requirements with the provisions:
- the Financial Conglomerate applies CDD, document archiving, and AML, CFT, and CCPF programs as regulated in legislation regarding the implementation of AML, CFT, and CCPF programs;
- implementation of CDD, document archiving, and AML, CFT, and CCPF programs is supervised by competent authorities; and
- adequate risk mitigation has been conducted for High-Risk Countries by the AML, CFT, and CCPF unit based on AML, CFT, and CCPF program policies at the Financial Conglomerate level.
- Monitoring and Updating
a. The Trustee must monitor business relationships with Customers by monitoring Customer Transactions related to the realization of the use of funds from the public offering of debt securities and/or Sukuk based on reports on the realization of the use of funds from the public offering of debt securities and/or Sukuk submitted by the Issuer to the OJK and the Trustee in accordance with OJK Regulations regarding Reports on the Realization of the Use of Funds from Public Offerings and Trust Deeds, and not for every Transaction of the Issuer, to ensure that Transactions conducted are in line with the Trustee's understanding of the Customer, business activities, and risk profile of the Customer.
b. The Trustee must analyze all Transactions that are inconsistent with the profile, characteristics, and/or habitual Transaction patterns of the Customer.
c. The Trustee may request information from Customers regarding the background and purpose of Transactions for Transactions inconsistent with the profile, characteristics, and/or habitual Transaction patterns of the Customer, taking into account anti tipping-off in accordance with legislation regarding the prevention and eradication of Money Laundering, Terrorism Financing, and/or Proliferation Financing. What is meant by
- 33 -
"Transactions that do not match the Customer's profile, characteristics, and/or customary transaction patterns"
are Transactions as regulated in legislation concerning the prevention and eradication of Money Laundering (TPPU), legislation concerning the prevention and eradication of Terrorism Financing (TPPT), and/or regulations concerning the prevention and eradication of Proliferation Financing for Weapons of Mass Destruction (PPSPM).
d. In carrying out monitoring, Trustees must have a system using at least an electronic spreadsheet application or a similar system that can:
- identify, analyze, monitor, and provide effective reports regarding the profile, characteristics, and/or customary transaction patterns of Transactions conducted by Customers; and
- trace each Transaction, if necessary, including tracing the Customer's identity, form of Transaction, date of Transaction, amount and denomination of Transaction, and the source of funds used for the Transaction.
e. In the event that information requested by the Trustee from the Customer does not provide a convincing explanation, the Trustee must report to the Financial Transaction Reports and Analysis Centre (PPATK) as a Suspicious Financial Transaction.
f. In the event of changes to Customer data known from the Trustee's monitoring of the Customer or other accountable information, the Trustee must undertake efforts to update data, information, and/or supporting documents for said Customer.
g. Updates to identity documents are conducted, among others, if there are financial Transactions meeting the criteria for Suspicious Financial Transactions as referred to in legislation concerning the prevention and eradication of TPPU, legislation concerning the prevention and eradication of TPPT, and/or regulations concerning the prevention and eradication of PPSPM.
h. In updating data, Trustees pay attention to materiality and risk level, and this is done in a timely manner through review of the Customer's profile and Transactions, considering the timing of previous CDD implementation and the adequacy of data obtained.
i. Trustees must document the data update efforts undertaken.
j. In updating data, Trustees must:
- monitor Customer information and documents;
- prepare a data update plan report, in accordance with the Trustee's assessment of the adequacy of available data and information to update the Customer's risk profile, which aims to monitor said Customer Transactions; and
- prepare a data update realization report, which can serve as a basis for the Trustee to evaluate the Customer's risk level.
- 34 -
k. The data update plan report and data update realization report must receive approval from the Board of Directors.
- Follow-up on DTTOT and/or DPPSPM
a. Trustees must maintain and update the DTTOT and/or DPPSPM provided by the Financial Services Authority (OJK) through the system provided by the Financial Services Authority. This maintenance aims to ensure that Trustees do not establish business relationships with Prospective Customers or conduct Transactions with Customers who have identity and information matching that contained in the DTTOT and DPPSPM.
b. Trustees must identify and ensure the correspondence of identity and other information (including place and date of birth and Customer address) regarding Customers with identity and other information recorded in the DTTOT and/or DPPSPM; and
c. In the event that no correspondence is found between Customer identity and other information and the identity and other information recorded in the DTTOT, the Trustee must create and submit a nil report to the National Police of the Republic of Indonesia with a copy to the Financial Services Authority.
d. In the event that no correspondence is found between Customer identity and other information and the identity and other information recorded in the DPPSPM, the Trustee must create and submit a nil report to the Financial Transaction Reports and Analysis Centre with a copy to the Financial Services Authority.
e. Trustees must identify, assess, understand, and mitigate the risk of sanction evasion regarding DTTOT and/or DPPSPM conducted by Prospective Customers, Customers, and/or Beneficial Owners.
f. Sanction evasion refers to efforts to evade sanctions by parties whose identities are recorded in the DTTOT and/or DPPSPM who conduct business relationships and/or financial Transactions with or on behalf of other parties to avoid the detection of Suspicious Financial Transactions.
As an example, Prospective Customers, Customers, and/or Beneficial Owners conducting business relationships and/or Transactions through the following modus operandi:
- conducted for the benefit of and/or under the direction, directly or indirectly, of parties whose identities are recorded in the DTTOT and/or DPPSPM;
- controlled by parties whose identities are recorded in the DTTOT and/or DPPSPM; and/or
- conducted to assist parties whose identities are recorded in the DTTOT and/or DPPSPM in the context of sanction evasion.
- Document Management
a. Trustees must manage:
- documents related to Prospective Customer and/or Customer data, for a minimum period of 5 (five) years since:
a) the end of the business relationship or Transaction with the Customer; and/or
b) the discovery of Transaction non-compliance with economic purposes and/or business purposes; and
- Customer documents related to financial Transactions for the period as regulated in legislation concerning corporate documents.
b. Documents related to Prospective Customer and/or Customer data include:
- identity of Prospective Customers and/or Customers, including supporting documents;
- Transaction information;
- results of analyses conducted;
- correspondence with Customers; and
- other documents, if required.
c. Trustees must store records and documents regarding the entire process of identifying Suspicious Financial Transactions in accordance with legislation.
d. Trustees provide data, information, and/or documents that are managed, as soon as possible and no later than 3 (three) working days since the Trustee receives a request from the Financial Services Authority and/or other competent authorities.
VI. INTERNAL CONTROL
- The implementation of an effective risk-based AML, CFT, and CPF program must be implemented in internal control and internalized in the Trustee's business processes.
- In internal control, Trustees must pay attention to the following:
a. the scale and complexity of the Trustee;
b. the Trustee's business or operational activities, including geographical aspects (including countries/jurisdictions), Customer profile, products/services, and the Trustee's overall Transaction activities;
c. the Transaction methods/distribution channels used;
d. the volume and intensity of Transactions;
e. the level of risk assessment for each of the Trustee's business activities; and/or
f. the business relationship between the Trustee and Customers, either directly, Third Parties, correspondents, or non-face-to-face communication.
- Trustees must have an effective and independent internal control system to ensure that all functions of implementing the AML, CFT, and CPF programs run in accordance with established policies and procedures. An effective and independent control system can be demonstrated at least by:
a. having adequate policies, procedures, and internal monitoring;
- 35 -
b. having limits on authority and responsibility of relevant work units regarding the implementation of the AML, CFT, and CPF programs; and
c. conducting independent examinations to ensure the effectiveness of the implementation of the AML, CFT, and CPF programs, including compliance testing (including sample testing) of policies and procedures related to the implementation of the AML, CFT, and CPF programs.
- In conducting internal control, Trustees may use regulatory technology such as algorithms, artificial intelligence technology, and/or machine learning.
- In the event that Trustees conduct internal control using regulatory technology as referred to in item 4, Trustees must ensure that the regulatory technology used in the internal control system:
a. is based on the results of risk assessments which include how the Trustee manages and mitigates risks over the information technology used;
b. is guaranteed reliable and has been certified by the ministry responsible for government affairs in the field of communication and informatics; and
c. guarantees data and information security, including the use of security tools such as encryption technology, antivirus usage, and firewalls.
- Effective and independent internal control regarding the implementation of the AML, CFT, and CPF programs must at least include:
a. the existence of a risk-based audit program and procedures;
b. the assessment of the adequacy of processes in place at the Trustee to identify and report Suspicious Financial Transactions, considering anti-tipping off regulations; and
c. improvement recommendations and objective information about inspected activities at all levels of Trustee management, including to the Board of Directors and Board of Commissioners.
- Effective and independent internal control regarding the implementation of the AML, CFT, and CPF programs must:
a. Ensure that the implementation of the AML, CFT, and CPF programs is applied well, correctly, and effectively in accordance with established policies and procedures, and includes the internal control system in item 3;
b. create a risk management and compliance culture at all levels of Trustee management; and
c. ensure that employees comply with established policies and procedures.
VII. MANAGEMENT INFORMATION SYSTEM
- Trustees must have a management information system or mechanism that can identify, analyze, monitor, and provide effective reports regarding Customer characteristics, using parameters adjusted periodically and considering the complexity of business, Transaction volume, and risks held by the Trustee, covering at least:
a. Financial Transactions requested by the Financial Transaction Reports and Analysis Centre to be reported by the Trustee because they involve assets suspected to originate from criminal proceeds;
b. Transactions that do not meet CDD requirements; or
c. Transactions whose information truthfulness is doubted by the Trustee.
- Trustees must have and maintain an integrated Customer profile (single customer identification file).
- Trustees must ensure that the information technology used in the management information system is guaranteed reliable and based on the results of risk assessments which include how the Trustee manages and mitigates risks over the information technology used.
- The information system owned by Trustees is required to consider information technology factors that have the potential to be abused by perpetrators of TPPU, TPPT, and/or PPSPM.
- Trustees must have a management information system that allows tracing of each Transaction and responding fully, quickly, and accurately to information, data, and document requests for internal purposes and/or the Financial Services Authority, as well as in relation to law enforcement efforts and judicial interests.
- Trustees must maintain a database of PEPs, DTTOT, and DPPSPM to identify whether there are Prospective Customers and Customers included in the DTTOT and/or DPPSPM, and whether there are Beneficial Owners included in PEPs, DTTOT, and/or DPPSPM.
- To ensure the management information system continues to run well and effectively, Trustees must mitigate risks, including:
a. To ensure the management information system continues to run well and effectively, Trustees must mitigate risks as regulated in Financial Services Authority regulations concerning the provision of information technology by commercial banks.
b. personal data protection, which can be done by:
- verifying the truthfulness of stored personal data;
- storing personal data in encrypted form; and
- storing personal data in accordance with legislation regulating the retention period of personal data.
If the owner of personal data is no longer a Customer, the Trustee must store such personal data according to the document retention period limit calculated from the date the personal data owner was last a Customer.
c. data centers and disaster recovery centers used by Trustees in conducting Trustee activities.
VIII. HUMAN RESOURCES AND TRAINING
- Human Resources
- 36 -
a. To prevent Trustees from being used as a means of TPPU, TPPT, and/or PPSPM involving internal parties, Trustees must conduct:
- screening procedures to ensure high standards in the acceptance of new employees (pre-employee screening), both permanent and non-permanent employees (employees on probation before becoming permanent, employees in education before becoming permanent, and/or contract employees), including senior officials and experts, from the lowest level up to 1 (one) level below the Board of Directors and Board of Commissioners; and
- introduction and monitoring of employee profiles (know your employee), both permanent and non-permanent employees, including experts, from the lowest level up to the Board of Directors and Board of Commissioners. Introduction and monitoring of employee profiles (know your employee) covers character, behavior, and lifestyle of employees.
b. Screening procedures for the acceptance of new employees (pre-employee screening) are conducted in the form:
- screening methods intended to ensure that the profile of prospective employees has no criminal records, including requiring prospective employees to make a statement letter and/or submit police record certificates;
- verifying identity and education obtained by prospective employees, including through face-to-face or virtual interview processes intended to further ensure the truthfulness of information and data from prospective employees;
- conducting research through media or other information regarding the background of prospective employees, including work history and/or work experience of prospective employees;
- ensuring a good track record of prospective employees, including requesting recommendation letters from previous companies where prospective employees have worked; and
- ensuring that the credit quality of prospective employees is not classified as non-performing loans.
c. Introduction and monitoring of employee profiles, covering employee behavior and lifestyle, include:
- verifying employees who have undergone significant lifestyle changes;
- ensuring that employees understand and comply with the staff code of conduct; and
- evaluating employees responsible for high-risk activities, including those with access to Trustee data and/or those facing Prospective Customers or Customers.
d. Screening procedures (pre-employee screening), introduction, and monitoring of employee profiles are documented in the Trustee's written know your employee policy and procedures, guided by regulations concerning the implementation of anti-fraud strategies.
- Training
a. Trustees must provide continuous and periodic training on the implementation of AML, CFT, and CPF programs and the role and responsibility of employees in preventing and eradicating TPPU, TPPT, and/or PPSPM to employees.
b. Continuous and periodic training regarding the implementation of AML, CFT, and CPF programs must be provided to employees, specifically employees from relevant work units (such as work units directly or indirectly related to Prospective Customers, such as Customer service officers, officers related to IT management and development, and internal auditors) and new employees, at least 1 (one) time in 1 (one) year.
c. In the event that, based on the Trustee's risk assessment of TPPU, TPPT, and/or PPSPM, business model, business activities, business scale, business complexity, business characteristics, and/or major events or developments in Trustee management and operations, training may be conducted more than 1 (one) time in 1 (one) year.
d. In providing continuous and periodic training, Trustees may:
- organize it independently;
- cooperate with other parties such as Trustee associations, the Financial Transaction Reports and Analysis Centre, and/or relevant competent authorities; and/or
- include employees in training organized by Trustee associations, the Financial Transaction Reports and Analysis Centre, the Financial Services Authority, and/or other competent authorities.
e. In determining training participants, Trustees prioritize employees whose daily tasks meet the following criteria:
- conducting supervision of the implementation of AML, CFT, and CPF programs; and/or
- related to the preparation of reports to the Financial Transaction Reports and Analysis Centre and the Financial Services Authority.
f. Other employees besides those referred to in letter e must receive training at least 1 (one) time during their employment, where such training must have been conducted no later than 1 (one) year since the employee first started working as a new employee of the Trustee.
- Training Methods and Materials
a. Training can be conducted virtually or online as well as face-to-face.
b. Virtual or online training as referred to in letter a can use e-learning media provided by competent authorities such as the Financial Transaction Reports and Analysis Centre, the Financial Services Authority, or provided independently by the Trustee.
- 38 -
c. Face-to-face training is conducted using approaches including:
- interactive face-to-face (e.g., workshops) with training topics adjusted to participant needs. This approach is used for priority employees and conducted continuously, e.g., every year; and/or
- one-way face-to-face (e.g., seminars) with training topics being a general overview of the implementation of AML, CFT, and CPF programs. This approach is given to non-priority employees and conducted when there are significant regulatory changes.
- Training Materials and Evaluation
a. Trustees may develop training materials related to the implementation of AML, CFT, and CPF programs according to needs. Some topics that can be training materials include:
- implementation of legislation concerning the implementation of AML, CFT, and CPF programs;
- modus operandi and typologies of TPPU, TPPT, and/or PPSPM;
- policies and procedures for implementing AML, CFT, and CPF programs and the role and responsibility of employees in preventing and eradicating TPPU, TPPT, and/or PPSPM; and
- other training materials, if required.
b. The depth of training materials is adjusted to employee needs and suitability with employee duties and responsibilities.
c. To determine employee understanding levels and training material suitability, Trustees must evaluate each training session provided.
d. Evaluation can be conducted directly, including through interviews, or indirectly through pre-tests and post-tests.
e. Trustees must follow up on training evaluation results through the refinement of training materials and methods.
f. The AML, CFT, and CPF responsible official of the Trustee must report the results of employee AML, CFT, and CPF training to the Board of Directors.
IX. REPORTING
- Reports to the Financial Services Authority include:
a. TPPU, TPPT, and/or PPSPM risk assessment documents that have been prepared individually (Individual Risk Assessment/IRA)
- Updates to TPPU, TPPT, and/or PPSPM risk assessment documents that have been prepared individually (Individual Risk Assessment/IRA) submitted annually no later than the end of June are prepared in the following format:
a) Part I: Introduction, consisting of at least:
i. background; and
ii. objectives.
-
39 -
-
41 -
b) Part II: theoretical foundation, which consists of at least:
i. methodology;
ii. framework; and
iii. scope limitations.
c) Part III: Trustee Profile, containing a description of the Trustee's general overview, both institutionally and operationally.
d) Part IV: Risk Assessment Results, which consists of at least:
i. risk map/ML/TPFU criteria in general, mapped from the perspective of predicate offenses, Corporate Customer business fields, geographic areas (which can be countries as well as provinces and/or cities/regencies in Indonesia), products/services/services, and Transaction methods/distribution networks (delivery channels),
ii. risk map/CTF/TPPT criteria in general, mapped from the perspective of Corporate Customer business fields, geographic areas (which can be countries as well as provinces and/or cities/regencies in Indonesia), products/services/services, and Transaction methods/distribution networks (delivery channels);
iii. risk map/CPF/PPSPM criteria in general, mapped from the perspective of Corporate Customer business fields, geographic areas (which can be countries as well as provinces and/or cities/regencies in Indonesia), products/services/services, and Transaction methods/distribution networks (delivery channels);
iv. risk map of all Customers, i.e., mapping Customers based on their risk level; and
v. the Trustee's aggregate final risk,
e) Part V: Risk Mitigation, which contains at least matters that the Trustee has done in mitigating ML/TPFU, CTF/TPPT, and/or CPF/PPSPM risks; and
f) Part VI: Conclusions and Follow-up, which is a summary of the risk assessment results and risk mitigation to be carried out.
- In the event that the reporting date for the IRA update falls on a holiday, the report submission is carried out on the next working day.
- Submission of the IRA document update is submitted online through an electronic system managed by the Financial Services Authority (OJK). In the event that the electronic system is not yet available or experiences disruption, the submission of the IRA document update is submitted physically or via electronic mail to the Financial Services Authority addressed to the head of the work unit overseeing the development and supervision of Trustees.
- 42 -
b. Customer Data Update Plan Report and Its Changes
- The Customer Data Update Plan Report must receive approval from the Board of Directors.
- The Customer Data Update Plan Report contains quantitative data (statistics on the number of customers) and qualitative data (among other things, obstacles, efforts already made by the Trustee, and progress of such efforts).
- The Customer Data Update Plan Report includes the number of Customers and the ML/TPFU, CTF/TPPT, and/or CPF/PPSPM risk levels of Customers to be updated, information to be updated, update methods or strategies, and the percentage of Customer fulfillment to be updated in a specific period. An example format of the Customer Data Update Plan Report is contained in the Appendix which is an integral part of this Financial Services Authority Board of Commissioners Regulation.
- The Customer Data Update Plan Report must be submitted to the Financial Services Authority every year at the latest by the end of December before the data update period.
- As an example, the Trustee submits the Customer Data Update Plan Report at the latest on December 31, 2026, for the implementation of Customer data updates for the period of January to December 2027.
- Submission of the Customer Data Update Plan Report is submitted online through an electronic system managed by the Financial Services Authority. In the event that the electronic system is not yet available or experiences disruption, the submission of the Customer Data Update Plan Report is submitted physically or via electronic mail to the Financial Services Authority addressed to the head of the supervision work unit.
- In the event that the reporting date for the Customer Data Update Plan Report falls on a holiday, the report submission is carried out on the next working day.
- In the event of changes to the Customer Data Update Plan Report that has been submitted to the Financial Services Authority, the Trustee must submit such changes at the latest 7 (seven) working days since the change was made.
c. Data Update Realization Report
- The Data Update Realization Report must receive approval from the Board of Directors.
- The Customer Update Realization Report to the Financial Services Authority contains the results of Customer updates in the form of the number of target Customers to be updated, the number of Customers successfully updated, the number of Customers not successfully updated reflected in the difference between the target and realization, obstacles faced, and follow-up efforts to be carried out for Customers not successfully updated.
- The Data Update Realization Report must be submitted to the Financial Services Authority every year at the latest by the end of January after the data update period ends.
- As an example, for Customer data updates carried out during the period of January to December 2026, the Trustee submits the Customer Data Update Realization Report at the latest on January 31, 2027.
- Submission of the Data Update Realization Report is submitted online through an electronic system managed by the Financial Services Authority. In the event that the electronic system is not yet available or experiences disruption, the submission of the Customer Data Update Realization Report is submitted physically or via electronic mail to the Financial Services Authority addressed to the head of the supervision work unit.
- In the event that the reporting date for the Data Update Realization Report falls on a holiday, the report submission is carried out on the next working day.
d. Report on Changes to the Implementation Policies and Procedures of the AML, CTF, and CPF Programs
- In the event of changes to policies and procedures that have been submitted to the Financial Services Authority, the Trustee must submit such changes at the latest 7 (seven) working days since the change was made.
- Submission of policies and procedures is submitted online through an electronic system managed by the Financial Services Authority. In the event that the electronic system is not yet available or experiences disruption, the policies and procedures are submitted physically or via electronic mail to the Financial Services Authority addressed to the head of the supervision work unit.
- In the event that the reporting date for policies and procedures falls on a holiday, the submission of policies and procedures is carried out on the next working day.
e. AML/CFT Questionnaire
- Updates to the AML/CFT Questionnaire are submitted every year at the latest by the end of June.
- In the event that the reporting date for the AML/CFT Questionnaire falls on a holiday, the report submission is carried out on the next working day.
- Submission of the AML/CFT Questionnaire is submitted online through an electronic system managed by the Financial Services Authority. In the event that the electronic system is not yet available or experiences disruption, the submission of the AML/CFT Questionnaire is submitted physically or via electronic mail to the Financial Services Authority addressed to the head of the work unit overseeing the development and supervision of Trustees.
f. Copy of Nil Report regarding DTTOT and/or DPPSPM
- In the event that no identity and other information related to Customers or Beneficial Owners (Beneficial Owner) is found to match the identity and other information contained in DTTOT and/or DPPSPM, the Trustee must submit a nil report to the National Police of the Republic of Indonesia (for DTTOT) or to the Center for Reporting and Analysis of Financial Transactions (for DPPSPM) with a copy to the Financial Services Authority at the latest 3 (three) working days since the Trustee received the DTTOT and/or DPPSPM.
- Submission of the copy of the nil report regarding DTTOT and/or DPPSPM is submitted online through an electronic system managed by the Financial Services Authority, namely the AML/CFT Program Information System (SIGAP).
- In the event that the electronic system experiences disruption, the aforementioned nil report is submitted physically through the OJK mailing room or via electronic mail to the Financial Services Authority addressed to the head of the work unit overseeing the development and supervision of Trustees.
- The Trustee must ensure that it is registered as a user (user) of SIGAP by accessing https://sigap.ojk.go.id.
- For Trustees who have never registered on SIGAP, they can choose the Register button to register. In the registration process, information regarding the SIPO (OJK Receipt Information System) account is required, to ensure that only Trustees licensed under the authority of OJK enter the SIGAP system.
- Reports to the Center for Reporting and Analysis of Financial Transactions
Trustees must submit reports to the Center for Reporting and Analysis of Financial Transactions in accordance with the provisions referred to in legislation concerning the prevention and eradication of ML/TPFU, CTF/TPPT, and/or CPF/PPSPM, including its implementing regulations, such as the Regulation of the Head of the Center for Reporting and Analysis of Financial Transactions. Reports that must be submitted to the Center for Reporting and Analysis of Financial Transactions in accordance with the Trustee's business model and business characteristics include, among others:
a. Suspicious Financial Transaction Report
- The Trustee must submit a Suspicious Financial Transaction Report, covering Transactions and/or attempted Transactions suspected to be related to predicate offenses, ML/TPFU, CTF/TPPT, and/or CPF/PPSPM, including in the event that there is a match of identity and other information related to Prospective Customers, Customers, and/or Beneficial Owners (Beneficial Owner) with identity and other information contained in DTTOT and/or DPPSPM, with a copy to the Financial Services Authority.
- The Suspicious Financial Transaction Report also relates to the submission of correction reports for Suspicious Financial Transaction Reports previously submitted.
An example of criteria for Suspicious Financial Transactions is contained in the Appendix which is an integral part of this Financial Services Authority Board of Commissioners Regulation.
b. Nil DPPSPM Report
- 44 -
This copy is in accordance with the original.
Head of Legal Development Directorate
Legal Department
signed.
Aat Windradi
In the event that no identity and other information related to Customers or Beneficial Owners (Beneficial Owner) is found to match the identity and other information contained in DTTOT and/or DPPSPM, the Trustee must submit a nil report to the Center for Reporting and Analysis of Financial Transactions at the latest 3 (three) working days since the Trustee received the DPPSPM, with a copy to the Financial Services Authority.
- Nil DTTOT Report to the National Police of the Republic of Indonesia
a. In the event that no identity and other information related to Customers or Beneficial Owners (Beneficial Owner) is found to match the identity and other information contained in DTTOT, the Trustee must submit a nil report to the National Police of the Republic of Indonesia at the latest 3 (three) working days since the Trustee received the DTTOT, with a copy to the Financial Services Authority.
b. Submission of the Nil DTTOT Report related to DTTOT is submitted physically to the Indonesian National Police at the address Jl. Trunojoyo No.3, RT.2/RW.1, Selong, Kebayoran Baru District, South Jakarta City, Special Capital Region of Jakarta 12110 or via electronic mail dttot.report@gmail.com and dttot.report.2@gmail.com or through other mechanisms regulated by the National Police of the Republic of Indonesia.
X. OTHER PROVISIONS
- Trustees who use and directly appoint supporting professional services that are reporting parties in the AML, CTF, and CPF regimes in Indonesia, must ensure that such supporting professions implement the AML, CTF, and CPF programs and are registered in the AML, CTF, and CPF reporting information system managed by the Center for Reporting and Analysis of Financial Transactions, evidenced by showing:
a. an email confirmation from the Center for Reporting and Analysis of Financial Transactions sent to the supporting profession regarding the acceptance of the registration application; and/or
b. other forms as referred to in legislation concerning the AML, CTF, and CPF reporting information system to the Center for Reporting and Analysis of Financial Transactions.
- Trustees are obliged to provide data, information, and/or documents managed, as soon as possible and at the latest 3 (three) working days since the Trustee receives a request from the Financial Services Authority and/or other competent authorities.
EXECUTIVE HEAD OF CAPITAL MARKET, DERIVATIVE FINANCIAL, AND CARBON BURSA SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA,
signed. HASAN FAWZI
APPENDIX II
REGULATION OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
NUMBER 4 OF 2026
CONCERNING
GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING, COUNTER-TERRORISM FINANCING, AND COUNTER-PROLIFERATION FINANCING PROGRAMS FOR TRUSTEES
- 2 -
A. RISK-BASED APPROACH CYCLE (RISK-BASED APPROACH)
Step 1: IDENTIFY INHERENT RISK
Types of Risks
Customer Risk Country/Area/Geographic/Jurisdiction Risk
Product/Service/Risk
Transaction Method/Distribution Network (Delivery Channels) Risk
Other Relevant Risks
Step 6: REVIEW OF RISK-BASED APPROACH (RISK-BASED APPROACH)
Step 5: RISK-BASED APPROACH
Step 4: EVALUATION OF RESIDUAL RISK
Customers based on risk level considering inherent risk in the Trustee's business activities.
Geographic location, customer geographic location, or location where the business relationship occurs.
Products/services that may be exposed to higher risks related to AML, CTF, and CPF.
Methods used to obtain or offer products/services, i.e., Transactions conducted directly by Customers or through payment agents.
Periodic review of the risk-based approach for the effectiveness of implementing the AML, CTF, and CPF programs.
Implementation of mitigation and control strategies for high-risk areas regarding ML/TPFU, CTF/TPPT, and/or CPF/PPSPM risks.
Step 2: APPLY RISK TOLERANCE
Risks that can be accepted and tolerated by the Trustee.
Step 3: RISK REDUCTION AND CONTROL
Develop and prepare mitigation strategy documents for high-risk areas.
Residual risk is the risk remaining after risk mitigation and control. Residual risk must be compared with the tolerated risk.
- 3 -
B. EXAMPLES OF SUSPICIOUS FINANCIAL TRANSACTIONS RELATED TO ML/TPFU, CTF/TPPT, AND/OR CPF/PPSPM IN TRUSTEES
- utilization of corporations or use of shell companies, where proceeds of crime are channeled into legal corporate entities that are essentially shell companies to facilitate their activities. Such shell companies are established only to conduct fictitious Transactions and aim to obscure the proceeds of crime.
- misuse of investment funds by Customers that does not align with the purpose of the Public Offering.
- mingling, which is a technique of mixing or combining proceeds of crime with proceeds from legitimate business activities to obscure the source of the proceeds of crime.
- use of professional services such as legal consultants, notaries, and accountants including public accountants, with the aim of obscuring the identity of the beneficial owner and the source of the proceeds of crime.
- use of other people's names (nominees), family members, and/or Third Parties by parties within the Customer's management structure who will represent the Customer in the process of establishing a business relationship with the Trustee, intended to obscure the identity of those committing crimes by using the legitimate identity of others.
- use of false identities by parties within the Customer's management structure who will represent the Customer in the process of establishing a business relationship with the Trustee, intended to obscure the identity of those committing crimes, thereby generating a new identity that appears genuine by using the legitimate identity of others. The forms of false identity usage include impersonation identities (mimicking identity) and synthetic identities (combining real and false identities). Impersonation identities are done by stealing another person's identity, while synthetic identities use identity forgery by combining real and false identities to generate a new identity that appears genuine;
- use or cooperation with companies in tax haven countries/jurisdictions that do not have real business (paper companies) as classified by competent international organizations, including countries categorized as High-risk and other Monitored Jurisdictions by the FATF.
- misuse of investment funds by Customers that does not align with the purpose of the Public Offering, where such investment funds are used to provide, collect, give, and/or lend to terrorists and/or terrorist organizations, directly or indirectly, with the intent to be used wholly or partially to commit terrorist crimes.
- parties within the Customer's management structure who will represent the Customer and/or parties who are the Beneficial Owners (Beneficial Owner) of the Customer are listed in the DTTOT.
- misuse of investment funds by Customers that does not align with the purpose of the Public Offering, where such investment funds are used to provide, collect, give, and/or lend to entities, corporations, and/or individuals, directly or indirectly, with the intent to be used wholly or partially to commit CPF/PPSPM.
- parties within the Customer's management structure who will represent the Customer and/or parties who are the Beneficial Owners (Beneficial Owner) of the Customer are listed in the DPPSPM.
- The Trustee is aware that the Customer is a suspected perpetrator of ML/TPFU and/or CTF/TPPT.
- The Trustee finds an inconsistency between the Customer's profile and the value of the Transaction conducted.
- The Trustee suspects involvement between the Customer and parties with affiliation relationships in relation to ML/TPFU, CTF/TPPT, and/or CPF/PPSPM.
- The Trustee receives information from reliable sources (Center for Reporting and Analysis of Financial Transactions, supervisory and regulatory agencies, including the Financial Services Authority, law enforcement agencies, mass media, or other sources) that the Customer is suspected of being involved in illegal activities and/or has a criminal background.
- The Customer changes or cancels the Agreement after the Trustee requests the Customer's identity documents.
- The Customer is suspected of using proceeds of crime.
- The Customer is suspected of committing a crime.
- Financial Transactions requested by the Center for Reporting and Analysis of Financial Transactions due to their connection with other Transactions currently under analysis or examination by the Center for Reporting and Analysis of Financial Transactions.
- Financial Transactions requested by the Center for Reporting and Analysis of Financial Transactions based on investigations or inquiries currently being conducted by law enforcement agencies.
- Financial Transactions requested by the Center for Reporting and Analysis of Financial Transactions because the Customer has been designated as a suspect/defendant in a criminal case.
Example: The Issuer has been designated as a suspect/defendant in the context of corporate crime.
- Prospective Customers or Customers provide incorrect information regarding matters related to identity, income source, or their business.
- Prospective Customers or Customers use identity documents whose authenticity is doubted or suspected to be false, such as different signatures or different photos.
- Prospective Customers or Customers are reluctant or refuse to provide information/documents requested by Trustee officers without clear reason.
- The Customer is unwilling to provide correct information or immediately terminates the business relationship/closes the account when Trustee officers request information regarding the Transaction conducted, including the Customer refusing to provide personal identity documents.
- The Customer is reluctant to provide complete information on the source of funds and the purpose of the Transaction to the Trustee.
- The Customer uses different names (different spellings) from one Transaction to another.
- The Customer attempts to convince Trustee employees not to complete any documentation required to conduct the Transaction.
- Inconsistencies in identification or verification that cannot be explained are found (e.g., differences in previous country/jurisdiction of residence, differences in country/jurisdiction that issued previous passports, differences in countries/jurisdictions visited according to the passport, or differences in documents related to name, address, and date of birth).
- The Customer provides information that is doubted or unclear.
- All presented identities cannot be verified for authenticity due to certain reasons.
- The Customer presents different identity documents each time a Transaction is conducted.
- 5 -
C. FORMAT OF CUSTOMER DATA UPDATE PLAN REPORT
CUSTOMER DATA UPDATE PLAN REPORT
(TRUSTEE NAME)
YEAR …
No. Type of Customer and Risk Level Number of Customers Information to be Updated Method or Strategy Percentage of Target Customer Fulfillment to be Updated in a Specific Period
Customers to be Updated % of Total Number of Customers
(a) (b) (c) (d) (e) (f) (g)
1 High Risk Level Customers
2 Medium Risk Level Customers
3 Low Risk Level Customers
- Column Description:
(a) Filled with the number.
(b) According to the column.
(c) Filled with the planned number of Customers to be updated for the next 1 (one) year.
(d) Filled with the percentage comparison of Customers to be updated with all Customers.
(e) Information can be filled with more than one, such as updating residential address or occupation.
(f) Method or strategy can be filled with more than one, such as correspondence via mail or electronic mail.
-
6 -
-
7 -
(g) Filled with the target fulfillment percentage for updating the single customer identification file within a specific period. The period is determined by adjusting to the capabilities and conditions of each Trustee, for example, quarterly. Example: Quarter I = 30%, Quarter II = 60%, Quarter III = 90%, Quarter IV = 100%
- The number of risk levels can be adjusted according to policies established by the Trustee.
- 8 -
D. FORMAT OF THE CUSTOMER DATA UPDATE REALIZATION REPORT
CUSTOMER DATA UPDATE REALIZATION REPORT
(TRUSTEE NAME)
YEAR …
No. Customer Type and
Risk Level
Development
Obstacles
Measures to Be Taken
Realization Target
Deviation (%)
(a) (b) (c) (d) (e) (f) (g)
1 Customers with
High Risk Level
2 Customers with
Medium Risk Level
3 Customers with
Low Risk Level
- Column descriptions:
(a) Filled with the number.
(b) As per the column.
(c) Filled with the target number of Customers.
(d) Filled with the realized number of Customers updated.
(e) Filled with the percentage difference between the target number of Customers to be updated (c) and (d) the realized number of Customers updated.
(f) Obstacles can be filled with more than one entry.
(g) Filled with measures to overcome obstacles and can be filled with more than one entry.
- The number of risk levels can be adjusted according to policies established by the Trustee.
-
9 -
E. AML-CFT TRUSTEE QUESTIONNAIRE
AML-CFT QUESTIONNAIRE
Trustee Name
:
Date of Filling
:
Person in Charge of Filling
Questionnaire
: Name :
Work Unit
:
Position :
Email Address
:
Notes:
❖ The filling of this questionnaire uses position data as of June 30 of the current year and aggregate data from July 1 of the previous year to June 30 of the current year.
❖ Please fill out this questionnaire as completely and truthfully as possible.
❖ The data input in the AML-CFT Questionnaire constitutes Trustee Customers who are the responsibility of the Trustee and are divided into 2 (two) types, namely Domestic Corporate Customers (Domestic) and Foreign Corporate Customers.
❖ The answers to this questionnaire will be kept confidential.
-
10 -
❖ Furthermore, the Trustee is requested to submit this questionnaire to the Work Unit overseeing the Trustee supervision and guidance function of the Financial Services Authority through the Financial Services Authority mailing room until a reporting system is available.
❖ In case of further questions, please contact via email to dpfp@ojk.go.id and/or other emails informed by the Work Unit overseeing the Trustee supervision and guidance function.
QUESTIONS
- What is the number of customers as of June 30 of the current year based on the following trustee service categories?
No. Service Classification
Number
a. Total All Trustee Customers
*(a=b+c+d)
………
b. Total Trustee Customers for Bond Products
*including customers transacting Bond products through General Bank branches
………
c. Total Trustee Customers for Sukuk Products ………
d. Total Trustee Customers for Other Products (if any), specify:
- .......................................
- .......................................
*including Asset-Backed Securities (ABS), MTN, and Long-Term Debt Securities
that are Trustee Customers, etc.
………
………
- 11 -
Description: In the event that a customer has more than one type of trustee service product, that customer's number is classified into the calculation ONLY under one of the trustee service product types above, with a description of the number of trustee customers who also belong to other trustee service product types and details of those other trustee service products in the description column below.
Example: (total trustee customers for bond products = 50 customers (description = 10 customers from trustee bond customers are also trustee sukuk customers, etc.)).
Description Column
..............................................................................................................................................................
..............................................................................................................................................................
- What is the number of Trustee Customers as of June 30 of the current year based on the following classifications?
No. Customer Classification
Number
a. Total All Trustee Customers
*(a=b)
………
b. Total Corporate Customers
(which are legal entities)
………
- Total Domestic Corporate Customers (Domestic) ………
- Total Foreign Corporate Customers
(The Foreign Corporate referred to is a corporation established and subject to
legislation in another country)
………
- 12 -
Description: The number of customers in item 2 letter a must be equal to the number of customers in item 1 letter a.
- From the total number of corporate customers as per your answer to question number 2 above, how many corporate customers act for and on behalf of/themselves (do not have a Beneficial Owner) and how many corporate customers act for and on behalf of others (have a Beneficial Owner)?
No. Customer Classification
Number
a. Total All Trustee Customers
*(a=b+c)
………
b. Total Domestic Corporate Customers ………
c. Total Foreign Corporate Customers ………
Description: The number of customers in item 3 letter a must be equal to the number of customers in item 1 letter a.
- As per the obligation in Article 20 of POJK 8/2023, what is the number of Trustee Customers as of June 30 of the current year based on the grouping of risk levels for Money Laundering Crimes, Terrorism Financing Crimes, and Proliferation Financing of Weapons of Mass Destruction.
No. Customer Grouping Based on Risk Level of ML/TF/PFM
Number
a. Total All Trustee Customers
*(a=b+c+d)
………
b. High Risk Corporate Customers
*(b=1)+2))
………
- Total High Risk Corporate Customers ………
- 13 -
No. Customer Grouping Based on Risk Level of ML/TF/PFM
Number
a) Total Domestic (Domestic) High Risk Corporate Customers ………
b) Total Foreign High Risk Corporate Customers ………
c. Medium Risk Corporate Customers
*(c=1)+2))
………
- Total Medium Risk Corporate Customers ………
a) Total Domestic (Domestic) Medium Risk Corporate Customers ………
b) Total Foreign Medium Risk Corporate Customers ………
d. Low Risk Corporate Customers
*(d=1)+2))
………
- Total Low Risk Corporate Customers ………
a) Total Domestic (Domestic) Low Risk Corporate Customers ………
b) Total Foreign Low Risk Corporate Customers ………
Description: The number of customers in item 4 letter a must be equal to the number in item 1 letter a.
- What is the number of customers transacting using the methods below during the period from July 1 of the previous year to June 30 of the current year?
- 14 -
No. Transaction Method
Number of Customers
Domestic
Foreign
a. Number of Customers Transacting
*(a=b+c)
……… ………
b. Payments made directly by Customers ……… ………
c. Payments through Payment Agents
d. Customers Not Transacting and Financial Transactions
*(during the data period)
……… ………
Description:
- In the event that a customer has more than one type of transaction method, that customer is ONLY classified into the calculation under one of the most frequently used methods and given a description as in questionnaire question number 1 in the description column below.
Example: (total customers with direct payment by customer transaction method = 50 customers (description = 10 customers with direct payment by customer transaction method are also customers with payment agent transaction method)
- The number of customers in item 5 letter a + item 5 letter d must be equal to the number of customers in item 1 letter a.
- In the event that a company does not pay coupons and is in the process of bankruptcy / PKPU, then 1 (one) data is counted.
- 15 -
Description Column
...................................................................................................................................................................................
...................................................................................................................................................................................
- What is the number of Trustee Customer transactions falling into the Suspicious Financial Transaction (alert) indication during the period from July 1 of the previous year to June 30 of the current year?
No. Transaction Method
Number of Transactions Performed By
Corporate
Domestic
Foreign National
a. Number of Suspicious Financial Transactions ……… ………
Description: The entry column is filled with the frequency of transactions, not the transaction nominal, and is not related to the number of customers, and only relates to transactions conducted at the Trustee.
Example:
If Customer B, who is a customer at the Trustee and a customer at a General Bank, conducts transactions at the General Bank and it is not related to transactions at the Trustee, then it is not included in the criteria of this questionnaire.
Types of Alerts/Indicators Regarding the Above
........................................................................................................................................................................................
........................................................................................................................................................................................
- What is the number of customer transactions reported to PPATK for Suspicious Financial Transactions during the period from July 1 of the previous year to June 30 of the current year?
No. Transaction Method
Number of Transactions Performed By
Corporate
Domestic
Foreign
a. Number of Suspicious Financial Transactions ……… ………
Description: The entry column is filled with the frequency of transactions, not the transaction nominal, and is not related to the number of customers, and only relates to transactions conducted at the Trustee.
Example: If Customer B, who is a customer at the Trustee and a customer at a General Bank, conducts transactions at the General Bank and it is not related to transactions at the Trustee, then it is not included in the criteria of this questionnaire.
- Provide your assessment (self-assessment) of the adequacy of the implementation of the AML, CFT, and CPPFM programs at the Trustee based on 5 (five) aspects in Article 3 of POJK 8/2023 as follows!
A. Aspect of Active Supervision by the Board of Directors and Board of Commissioners
No. Assessment Criteria
Assessment
Give a Checkmark √ on ONE
Choice Most Suitable
With Your Company
1
• The establishment of written policies and procedures by management as well as
organizational policies is very adequate.
• Management supervision implementation is very effective.
-
17 -
2
• The establishment of written policies and procedures by management as well as
organizational policies is adequate.
• Management supervision implementation is effective.
3
• The establishment of written policies and procedures by management as well as
organizational policies is fairly adequate.
• Management supervision implementation is fairly effective.
4
• The establishment of written policies and procedures by management as well as
organizational policies is less adequate.
• Management supervision implementation is less effective.
5
• The establishment of written policies and procedures by management as well as
organizational policies is inadequate.
• Management supervision implementation is ineffective.
Supporting Value Explanation / Evidence of Implementation of the Above Assessment Choice
...
............................................................................................................................................………….........
..................................................................................................................................................................
B. Aspect of Policies and Procedures
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE
Choice Most Suitable
With Your Company
1
• Policies and procedures are very adequate, including handling high
risk customer, high risk business, high risk products /services.
• Implementation of policies and procedures is very consistent and very
effective, including but not limited to:
-
18 -
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE
Choice Most Suitable
With Your Company
➢ Customer Acceptance;
➢ Customer Data Updating;
➢ Transaction Monitoring and Reporting; and
➢ Handling high risk customer, high risk business, high risk
products or services.
2
• Policies and procedures are adequate, including handling high risk
customer, high risk business, high risk products /services.
• Implementation of policies and procedures is consistent and effective, including
but not limited to:
➢ Customer Acceptance;
➢ Customer Data Updating;
➢ Transaction Monitoring and Reporting; and
➢ Handling high risk customer, high risk business, high risk
products or services.
3
• Policies and procedures are fairly adequate, including handling high risk
customer, high risk business, high risk products /services.
• Implementation of policies and procedures is fairly consistent and covers
at least:
➢ Customer Acceptance;
➢ Customer Data Updating;
➢ Transaction Monitoring and Reporting; and
➢ Handling high risk customer, high risk business, high risk
products or services.
-
19 -
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE
Choice Most Suitable
With Your Company
4
• Policies and procedures are less adequate and there are still
weaknesses that must be improved.
• Implementation of policies and procedures is less consistent and less
effective.
5
• Does not have policies and procedures or has policies and
procedures but is very inadequate.
• Implementation of policies and procedures is inadequate.
Supporting Value Explanation / Evidence of Implementation of the Above Assessment Choice
...
.....................................................................................................................................................................
.....................................................................................................................................................................
C. Aspect of Internal Control
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE
Choice Most Suitable
With Your Company
1
• Internal control systems and procedures and internal audit function
are comprehensive.
• Implementation of internal control and internal audit function is very effective.
-
20 -
2
• Internal control systems and procedures and internal audit function
are adequate.
• Implementation of internal control and internal audit function is effective.
3
• Internal control systems and procedures and internal audit function are fairly
adequate.
• Implementation of internal control and internal audit function is fairly effective.
4
• Internal control systems and procedures and internal audit function are less
adequate.
• Implementation of internal control and internal audit function is less effective.
5
• There are no internal control systems and procedures and internal audit
function.
• No internal control and internal audit function is conducted.
Supporting Value Explanation / Evidence of Implementation of the Above Assessment Choice
...
..................................................................................................................................................................
..................................................................................................................................................................
D. Aspect of Management Information System (MIS)
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE Choice
Most Suitable With
Your Company
1
• Has a comprehensive and reliable MIS.
-
21 -
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE Choice
Most Suitable With
Your Company
• MIS is very effective in identifying the occurrence of suspicious
financial transactions.
2
• Has an adequate MIS although there are still weaknesses
that are not significant and do not affect the accuracy
of information.
• MIS is effective in identifying the occurrence of suspicious financial
transactions.
3
• Has a fairly adequate MIS and existing weaknesses are easy
to fix.
• MIS is fairly effective in identifying the occurrence of suspicious financial
transactions.
4
• Has an MIS, but it is less adequate and there are significant
weaknesses.
• MIS is less effective in identifying the occurrence of suspicious financial
transactions.
5
• Does not have an MIS or has an MIS but it is completely
inadequate and cannot identify the occurrence of suspicious
financial transactions.
-
22 -
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE Choice
Most Suitable With
Your Company
Supporting Value Explanation / Evidence of Implementation of the Above Assessment Choice
...
..................................................................................................................................................................
..................................................................................................................................................................
E. Aspect of Human Resources (HR) and Training
Value Assessment Criteria
Assessment
Give a Checkmark √ on ONE Choice Most
Suitable With Your Company
1
• Has very competent and trained HR in
adequate numbers.
• Has a comprehensive and very effective
training program.
2
• Has competent and trained HR in adequate
numbers.
• Has a comprehensive and effective
training program.
3
• Has competent and trained HR but the
number is not large.
• Has a simple but fairly effective
training program.
-
23 -
This copy is consistent with the original
Head of Legal Development Directorate
Legal Department
signed.
Aat Windradi
4
• Has less competent and less trained HR.
• Has a simple and less effective
training program.
5
• Has incompetent and untrained HR.
• Does not have a training program.
Supporting Value Explanation / Evidence of Implementation of the Above Assessment Choice
...
..................................................................................................................................................................
..................................................................................................................................................................
EXECUTIVE HEAD OF SUPERVISOR
OF CAPITAL MARKET, FINANCIAL
DERIVATIVES, AND CARBON EXCHANGE
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA,
sign.
HASAN FAWZI