To:
The Board of Directors of Microfinance Institutions
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 11 /SEOJK.05/2021 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS FOR MICROFINANCE INSTITUTIONS
In accordance with the mandate of Article 68 of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2017 Number 57, Supplement to the State Gazette of the Republic of Indonesia Number 6035) as amended by Financial Services Authority Regulation Number 23/POJK.01/2019 concerning the Amendment to Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2019 Number 178, Supplement to the State Gazette of the Republic of Indonesia Number 6394), it is necessary to further regulate the implementation of anti-money laundering and counter-terrorism financing programs for microfinance institutions in this Circular Letter of the Financial Services Authority as follows:
I. GENERAL PROVISIONS
- In this Circular Letter of the Financial Services Authority, the following terms are defined as:
a. Microfinance Institution, hereinafter abbreviated as MFI, is a financial institution specifically established to provide business development services and community empowerment, either through loans or financing in micro-scale businesses to members and the public, managing deposits, or providing business development consulting services that are not solely profit-seeking. b. Money Laundering is money laundering as referred to in the Law governing the prevention and eradication of Money Laundering criminal offenses.
c. Terrorism Financing is terrorism financing as referred to in the Law governing the prevention and eradication of Terrorism Financing criminal offenses.
d. Proliferation of Weapons of Mass Destruction is the spread of nuclear, biological, and chemical weapons. e. Anti-Money Laundering and Counter-Terrorism Financing, hereinafter abbreviated as APU and PPT, are efforts to prevent and eradicate Money Laundering and Terrorism Financing criminal offenses. f. Prospective Customer is a party that will use the services of the MFI. g. Customer is a party that uses the services of the MFI. h. Deposits are funds entrusted by the public to the MFI in the form of savings and/or fixed deposits based on a fund storage agreement.
i. Customer Due Diligence (CDD) is an activity involving identification, verification, and monitoring conducted by the MFI to ensure transactions align with the profile, characteristics, and/or transaction patterns of Prospective Customers or Customers.
j. Enhanced Due Diligence (EDD) is a more in-depth CDD action conducted by the MFI against Prospective Customers or Customers with high risks, including Politically Exposed Persons (PEP) and/or in high-risk areas. k. High Risk Customers are Customers who, based on their background, identity, and history, are considered to have a high risk of engaging in activities related to Money Laundering and/or Terrorism Financing criminal offenses.
l. Suspicious Financial Transactions are suspicious financial transactions as referred to in the Law governing the prevention and eradication of Money Laundering criminal offenses and the Law governing the prevention and eradication of Terrorism Financing criminal offenses.
m. Center for Report and Analysis of Financial Transactions, hereinafter abbreviated as PPATK, is the PPATK as referred to in the Law governing the prevention and eradication of Money Laundering criminal offenses. n. Board of Directors:
- for MFIs in the form of a limited liability company (perseroan terbatas), is the Board of Directors as referred to in the law governing limited liability companies; and
- for MFIs in the form of a cooperative legal entity, is the management as referred to in the law governing cooperatives.
o. Board of Commissioners:
- for MFIs in the form of a limited liability company (perseroan terbatas), is the Board of Commissioners as referred to in the law governing limited liability companies; and
- for MFIs in the form of a cooperative legal entity, is the supervisors as referred to in the law governing cooperatives.
p. Beneficial Owner is any person who:
- is entitled to and/or receives certain benefits related to the Customer's account;
- is the ultimate owner of the funds and/or securities placed with the MFI (ultimately own account);
- controls Customer transactions;
- grants power of attorney to conduct transactions;
- controls Corporations or other legal arrangements; and/or
- is the ultimate controller of transactions conducted through legal entities or based on agreements.
q. Corporation is a group of people and/or organized groups, whether legal entities or non-legal entities. r. Politically Exposed Person (PEP) includes:
- Foreign PEP is a person given authority to perform important functions (prominent function) by another (foreign) country, such as heads of state or government, senior politicians, senior government officials, military officials or law enforcement officials, senior executives of state-owned companies, important officials in political parties;
- Domestic PEP is a person given authority to perform important functions (prominent function) by the country, such as heads of state or government, senior politicians, senior government officials, military officials or law enforcement officials, senior executives of state-owned companies, important officials in political parties; and
- Persons given authority to perform important functions (prominent function) by international organizations, such as senior managers including but not limited to directors, deputy directors, and board members or equivalent functions.
s. Financial Conglomerate (Financial Group) is a financial service provider within one group or cluster due to ownership and/or control linkages.
-
MFIs have risks of being used as a means for Money Laundering and Terrorism Financing. MFIs may become an entry point for wealth that is the proceeds of Money Laundering crimes or can be used as a source of funding for terrorist activities. For example, for Money Laundering perpetrators who store their illicit wealth in MFIs, this wealth can be withdrawn as seemingly legitimate wealth that can no longer be traced. For Terrorism Financing perpetrators, wealth obtained from MFI loans can be used to fund terrorist activities.
-
The increasing awareness regarding the implementation of APU and PPT programs by mature and large financial services industries causes Money Laundering and Terrorism Financing perpetrators to seek other financial services industries with less strict APU and PPT program implementation to serve as means for Money Laundering and/or Terrorism Financing. This results in increasingly higher risks of MFIs being used as means for Money Laundering and/or Terrorism Financing.
-
In this regard, there is a need to improve the quality of APU and PPT program implementation based on a risk-based approach in accordance with general principles applicable internationally and in line with national risk assessments (NRA) and sectoral risk assessments (SRA). The NRA is an activity to identify and measure APU and PPT risks in Indonesia conducted by the national NRA updating team to know the APU and PPT risk map and formulate strategic steps in preventing and eradicating Money Laundering and Terrorism Financing criminal offenses in Indonesia. The SRA is an activity mapping Money Laundering and Terrorism Financing criminal risks in the financial services sector compiled by the Financial Services Authority based on customer profiles, types of products/services, geographic areas/regions, distribution channels, and modus operandi potentially used by Money Laundering and Terrorism Financing perpetrators.
-
The implementation of a Risk-Based Approach (RBA) for APU and PPT programs must include at least:
a. active supervision by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. internal controls;
d. management information systems; and e. human resources and training.
-
Overview of Money Laundering Criminal Offenses
a. Money Laundering Criminal Offenses (TPPU) are money laundering criminal offenses as referred to in the Law regarding the prevention and eradication of money laundering criminal offenses. b. Several methods, techniques, schemes, instruments, and modus operandi in Money Laundering include:
- Structuring, which is an effort to avoid reporting by breaking down transactions so that the transaction amount becomes smaller but with high frequency;
- Smurfing, which is a method using several accounts under different individual names for the benefit of a specific person;
- Trade-Based Money Laundering and Terrorism Financing, which is a technique involving invoice manipulation and using financial and commodity route channels to avoid legal and financial transparency;
- Mingling, which is a technique using methods to mix or combine criminal proceeds with legitimate business profits to obscure the source of funds;
- Use of professional services, which is a technique using third parties, such as professional services like lawyers, notaries, financial planners, accountants, and public accountants. This is done to obscure the identity of the beneficial owner and the source of criminal proceeds;
- Use of shell companies, which is a technique conducted by formally establishing a company according to applicable legal rules. However, in practice, the company is not used to conduct business activities. Shell companies are established only to conduct fictitious transactions or store the assets of founders or others. Additionally, this technique aims to obscure the identity of those controlling the funds and exploit relatively low reporting requirements;
- New payment technologies, which are techniques using newly emerged payment technologies for Money Laundering and Terrorism Financing, such as mobile-based payment and money transfer systems;
- Use of false identities, which are transactions conducted using false identities to make it difficult to trace the identity and detect the presence of Money Laundering perpetrators. In its development, the trend of using false identities shows a significant increase through various means, including fraud using false identities in the account opening process;
- Use of other people's names (nominees), family members, and third parties, which is a technique commonly used to obscure the identity of those controlling criminal proceeds;
- Purchase of assets or luxury goods (property, vehicles, etc.), which involves investing criminal proceeds into assets/goods with high resale value. This aims to take advantage of reduced reporting requirements to obscure the source of criminal proceeds;
- U-turn, which is an effort to obscure the origin of criminal proceeds by reversing transactions and then returning them to the original account;
- Cuckoo smurfing, which is an effort to obscure the source of funds by sending criminal proceeds through a third party's account waiting for funds from abroad, unaware that the received funds are proceeds of crime; and/or
- Use of third parties, which are transactions conducted using third-party identities to avoid detection of the identity of the actual owner of criminal proceeds.
- Overview of Terrorism Financing Criminal Offenses
a. Terrorism Financing Criminal Offenses (TPPT) are terrorism financing criminal offenses as referred to in the Law regarding the prevention and eradication of terrorism financing criminal offenses. b. Unlike TPPU, which aims to disguise the origin of wealth from criminal proceeds, the purpose of TPPT is to assist terrorist activities. In terrorism criminal offenses, money or funds are intended as a means to carry out terrorist acts and not as a target to be sought, so various methods will be used by perpetrators to obtain funds, either through legal and legitimate activities such as business, obtaining loans through financial services sectors, and/or requesting donations, or through illegal activities such as robbery, fraud, and/or hacking activities. The funds collected from legal and illegal activities will subsequently be used to provide funding for terrorist activities, or other matters related to terrorist acts and/or perpetrators of terrorist acts.
c. Every terrorist act carried out essentially requires support, either direct support for terrorist activities, or indirect support for other matters related to terrorist acts and/or perpetrators of terrorist acts. Direct support for terrorist activities includes, for example, weaponry (firearms, sharp weapons, chemical weapons, biological weapons, radiological weapons, microorganisms, radioactive materials, etc.), explosives, ammunition, war facilities, and so on. Meanwhile, support for other matters related to terrorist acts and/or perpetrators includes, for example, meeting logistical needs, housing, vehicles for mobility, network development costs, training, assistance to terrorist perpetrators' families, and so on.
d. Several methods, techniques, schemes, instruments, and modus operandi in Terrorism Financing include:
- Domestic funding through donations to foundations using cash instruments used for terrorist network management;
- Domestic funding through misuse of foundation funds using cash instruments used for terrorist network management;
- Domestic funding through misuse of foundation funds to open new business activities (goods/services) with proceeds used for terrorist network management;
- Domestic funding through business/trading (goods/services) using cash instruments used for terrorist network management;
- Domestic funding through loan applications; and/or
- Domestic funding through criminal acts using cash instruments used for terrorist network management.
II. IMPLEMENTATION OF RISK-BASED ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS (RISK-BASED APPROACH)
-
Obligations for Implementing Risk-Based Anti-Money Laundering and Counter-Terrorism Financing Programs (Risk-Based Approach).
a. APU and PPT programs are programs that MFIs must implement in conducting business relationships with Customers. These programs are efforts to protect MFIs from being used as means or targets for crimes, whether directly or indirectly by criminals. The Financial Action Task Force (FATF) recommendations emphasize that financial service institutions must identify, assess, and understand Money Laundering and Terrorism Financing risks related to Customers, countries/geographic areas/jurisdictions, products, services, transactions, and/or distribution networks (delivery channels). MFIs conduct their own assessments and implement effective risk management framework processes. MFIs update their assessments and risk management frameworks and remain responsive in adjusting to general principles applicable internationally and risk assessments, both at the national (national risk assessment/NRA) and sectoral (sectoral risk assessment/SRA) levels. b. The implementation of risk-based APU and PPT programs (risk-based approach) supports MFIs in implementing prevention and risk mitigation measures commensurate with the identified Money Laundering and Terrorism Financing risks. MFIs can subsequently allocate their resources according to the risk profiles faced by the MFI, manage internal controls, internal structures, and implement policies and procedures to prevent and detect Money Laundering and Terrorism Financing.
c. In implementing risk-based APU and PPT programs (risk-based approach), MFIs must refer to and consider Money Laundering and Terrorism Financing criminal risks as referred to in the NRA and SRA. Moreover, the risks listed in the NRA and SRA may develop and change; therefore, the APU and PPT programs owned by MFIs must be responsive to such risk changes.
-
Risk Concept
a. Definition of Risk
Risk can be interpreted as the possibility of an event and its consequences. Simply put, risk can be seen as a combination of the likelihood of occurrence and the level of damage or loss that may result from an event. In the context of Money Laundering and Terrorism Financing, risk is defined as:
- at the national level, as a threat and vulnerability caused by Money Laundering and Terrorism Financing that endanger the national financial system as well as national safety and security;
- at the MFI level, as a threat and vulnerability placing the MFI at risk of being used as a means for Money Laundering and Terrorism Financing.
Threats can be individuals or groups of people, objects, or activities with the potential to cause harm. In the context of Money Laundering and Terrorism Financing, threats can include perpetrators of criminal acts, facilitators (parties assisting in the execution of criminal acts), funds of criminals, or even terrorist groups. Vulnerability is an element of business activities that can be exploited by identified threats. In the context of Money Laundering and Terrorism Financing, vulnerability can be interpreted as weak internal controls of the MFI or the offering of high-risk products/services/transactions. Impact refers to the level of serious damage and loss arising if Money Laundering and Terrorism Financing occurs. b. Risk Management Risk management is a process widely used in the public and private sectors to assist in decision-making. In relation to Money Laundering and Terrorism Financing, the process includes understanding Money Laundering and Terrorism Financing risks, assessing these risks, and developing methods to manage and mitigate identified risks. In implementing risk management for Money Laundering and Terrorism Financing risks, MFIs can develop risk management methods according to the characteristics of the MFI while still referring to regulations regarding APU and PPT.
c. Inherent Risk and Residual Risk
In conducting risk assessments, it is important to distinguish between inherent risk and residual risk:
- Inherent risk is the risk attached to an event or condition that exists prior to the implementation of control measures. Inherent risk is risk related to the profiles of Prospective Customers or Customers, products or services, geographic areas, and distribution networks, as well as other relevant risk factors for the MFI. An example of inherent risk related to Customers is depositors included in the PEP category.
- Residual risk is the remaining risk after the implementation of risk mitigation steps and controls. An example of a Customer Depositor included in the PEP category, after mitigation steps such as EDD are taken, but the Customer still has residual risk as a PEP.
d. Risk-Based Approach (RBA)
In the context of Money Laundering and Terrorism Financing, the risk-based approach (risk-based approach) is a process involving the following:
- MFIs must understand the MFI's business activities as a whole with a broad perspective so that the MFI can know the Money Laundering and Terrorism Financing risks that may occur in the MFI;
- Risk assessments covering 4 (four) risk factors, namely:
a) Customers; b) Geographic areas; c) Products/services/transactions; and d) Distribution networks (delivery channels);
- MFIs must conduct customer risk assessments by considering the risk level owned by their customers;
- MFIs must manage and mitigate risks through the implementation of internal controls and steps appropriate to the identified risks, and conduct transaction monitoring and business relationships according to the assessed risk levels; and
- MFIs must periodically update risk assessments according to needs and the MFI's risk assessments, including considering the development of new products, new distributions, and/or threats entering the MFI's business activities.
- Risk-Based Approach (RBA) Cycle
a. In conducting a risk-based approach (risk-based approach), MFIs must perform 6 (six) activity steps as follows:
-
Identify inherent risks;
-
determine risk tolerance;
-
formulate risk reduction and control measures;
-
evaluate residual risk;
-
implement a risk-based approach; and
-
review and evaluate the existing risk-based approach.
b. The cycle flow of the risk-based approach is as set forth in Appendix I, which is an integral part of this Financial Services Authority Circular.
- Steps of the Risk-Based Approach
a. Identification of Inherent Risk
-
In identifying inherent risk, MFIs must consider the vulnerability of the MFI to be used as a vehicle for Money Laundering and Terrorism Financing. The initial step in conducting risk assessment is to understand the MFI's business activities as a whole from a broad perspective. This understanding will enable the MFI to consider where risks occur, whether the risks occur in business activities, Customers, or specific products.
-
The actual amount of risk inventoried by the MFI will vary depending on business activities, as well as the products/services/transactions offered.
-
MFIs must consider elements that trigger the emergence of risk for the MFI from the side of Customers, geographic areas, products/services/transactions, or distribution networks (delivery channels). MFIs understand what elements constitute inherent risk and residual risk.
-
Customer Risk
MFIs must identify their customers to categorize Customers based on the risk level of each Customer. Some indicators of High Risk Customers include:
a) Customers who originate from the identification process results and fall into the PEP category, family members of PEPs, or parties associated (close associates) with PEPs; b) Corporate Customers whose ownership structure is complex and makes it difficult to identify who the Beneficial Owner, ultimate owner, or ultimate controller of the Corporation is; c) charitable organizations or other non-profit organizations that are not regulated and supervised; d) gatekeepers such as accountants, lawyers, or other professions acting on behalf of Customers in relation to accounts/contracts with the MFI and where the MFI relies on the existence of such gatekeepers; e) Customers who conduct transactions that are unnatural and do not match their profile, including: transaction values that do not match their profile, transaction frequency that does not match their usual transaction patterns, and unexplained distances between the transaction location and the Customer's residence/business place; f) Customers whose verification process is non-face to face; g) included in lists of suspected terrorists and terrorist organizations and/or lists of Weapons of Mass Destruction Proliferation Financing; or h) Customers who receive products/services/transactions from the MFI that do not match the Customer's needs or do not provide benefits to the Customer.
-
Geographic Area Risk
MFIs must identify high-risk elements related to geographic locations, both the geographic location of the Customer/business activities. The risk level of a Customer will increase if the Customer originates from an area with high risk. Geographic areas with high risk include districts/cities with high crime rates.
-
Product, Service, and Transaction Risk
MFIs identify the risk level of products, services, or transactions used by Customers. Products with high risk include products that involve significant cash payments.
-
Distribution Network (Delivery Channels) Risk
Distribution networks (delivery channels) are media used to obtain a product/service/transaction or media used to conduct a transaction, including through cashiers/counters, field officers, and others. MFIs must identify the distribution networks used by Customers. Indicators that can cause distribution networks (delivery channels) to be high risk include non-face-to-face transactions. Examples of non-face-to-face transactions include when borrower and/or depositor customers make installment payments without coming directly to the MFI office, but by transferring to an account designated by the MFI.
-
Other Relevant Risks
Other relevant factors that can impact Money Laundering and Terrorism Financing risks include:
a) trends in typologies, methods, techniques, and schemes of Money Laundering and Terrorism Financing; and b) the MFI's business model.
MFIs need to consider the business model, business scale, number of branches, and number of employees as inherent risk factors within the MFI.
-
Determination of Risk Scale
a) After identifying and documenting inherent risk, MFIs need to assign a scale to each risk. b) Risk scales are formulated by considering the characteristics and complexity of business activities. c) MFIs can categorize risks according to the assessment results, divided into 3 (three) categories: low, medium, and high. d) To determine the risk scale for each business activity, MFIs can conduct risk assessment by referring to the example of a risk assessment matrix as set forth in Format A of Appendix II, which is an integral part of this Financial Services Authority Circular.
-
Every identified element that is a high risk must be mitigated and documented. MFIs must be able to explain to the Financial Services Authority the mitigation steps for high-risk elements, for example, steps in policies and procedures or training programs.
-
MFIs must also be able to show the Financial Services Authority that the risk mitigation steps have been implemented effectively, for example, shown through internal audit results or independent audit results.
-
To help MFIs conduct risk assessment evaluation, MFIs can use likelihood and impact matrices as examples. To help MFIs conduct risk assessments for new product development and business practices, MFIs can refer to the example as set forth in Format B of Appendix II, which is an integral part of this Financial Services Authority Circular.
-
In conducting the identification stage of inherent risk, MFIs must be able to explain the entire risk identification process conducted by the MFI and the reasons or considerations.
-
MFIs must provide documented information showing that the MFI has specifically paid attention to high-risk indicators in its risk assessment.
b. Determining Risk Tolerance
- Risk tolerance is the maximum level and type of risk established by the MFI in conducting its business activities according to the risk level to be taken (risk appetite).
- Risk tolerance is an important component of effective risk management.
- Before considering risk mitigation, MFIs must establish risk tolerance.
- When considering threats, the concept of risk tolerance will enable the MFI to determine the level of risk threat that can be tolerated by the MFI.
- In establishing risk tolerance, MFIs need to consider the following risk categories that can affect the MFI, including:
a) regulatory risk; b) reputational risk; c) legal risk; and d) financial risk.
c. Risk Reduction and Control Steps
- Risk mitigation is the application of internal controls to limit identified Money Laundering and Terrorism Financing risks during risk assessment. Risk mitigation will help ensure that the MFI's business activities remain within the established risk tolerance limits. In the event that the risk assessment results show that the MFI has a high risk level, the MFI must develop written risk mitigation strategies (consisting of policies and procedures to mitigate high risks) and apply them to high-risk areas or business relationships as identified.
- Internal controls and risk mitigation in high-risk areas or business relationships are based on risk tolerance and risk acceptance (risk appetite). It is expected that internal controls and risk mitigation will be commensurate with the risks identified by the MFI.
- In all situations, the MFI's business activities must consider internal controls that will influence the mitigation of all identified risks.
- In risk assessment, all identified high-risk areas as part of the risk assessment must be mitigated with internal controls or other steps, and well documented.
- For all Customers and business relationships, MFIs must:
a) monitor all business relationships; and b) document related information and steps taken.
- For high-risk Customers and business relationships, MFIs must:
a) conduct more frequent monitoring of those business relationships; and b) take stricter steps in conducting identification and data updating.
- With the existence of risk mitigation activities, MFIs are expected to:
a) update and maintain Customer and Beneficial Owner information; b) establish and conduct continuous monitoring activities at every level of the MFI's business relationships (for low-risk Customers conducted periodically and for High Risk Customers conducted more frequently); c) implement mitigation for high-risk areas. This risk mitigation strategy must be stated in policies and procedures; and d) consistently apply internal control procedures.
d. Evaluating Residual Risk
- Residual risk is the risk remaining after the application of internal controls and risk mitigation. MFIs need to note that no matter how tight the risk mitigation and risk management are, the MFI will still have residual risk that must be managed well.
- Residual risk must align with the established risk tolerance. MFIs must ensure that residual risk is not greater than the established risk tolerance. In the event that residual risk is still greater than risk tolerance, or in the event that internal controls and mitigation for high-risk areas are inadequate, MFIs are required to repeat the risk reduction and control steps as referred to in letter c and increase the level or quantity of established mitigation steps.
- Characteristics of residual risk are:
a) risk tolerated/accepted:
In this risk, the risk remains beyond the tolerated limit. Acceptance of tolerated risk means that there is no benefit in reducing the risk. However, the tolerated risk can increase over time. For example, when there is a new product or when a new Money Laundering and Terrorism Financing threat occurs; and b) risk mitigated:
In this risk, the risk remains even though it has been mitigated. This risk has been reduced but cannot be eliminated. In practice, established internal controls may not be applicable (for example, monitoring systems or transaction monitoring processes fail, causing some transactions not to be reported).
- With the existence of evaluation activities for residual risk, MFIs are expected to:
a) evaluate the residual risk owned; and b) adjust the risk level owned to the tolerated/accepted risk.
e. Implementation of the Risk-Based Approach
- After the MFI conducts risk assessment, the MFI must implement a risk-based approach in daily business activities/operations. Even with the risk-based approach, existing obligations, such as identification, verification, and monitoring, still need to be done as minimum requirements.
- The risk-based approach owned by the MFI must be documented to demonstrate the MFI's compliance level. Policies and procedures related to the risk-based approach must be communicated, understood, and complied with by all employees, especially employees who conduct identification and maintenance of customer data and information and transaction reporting to relevant authorities. MFIs must provide sufficient information to process and complete transactions, in accordance with the identification and maintenance of customer data and information as required.
- Procedures and policies of the risk-based approach must meet the following minimum requirements:
a) customer identification; b) risk assessment; c) special actions for high-risk areas; d) record keeping; and e) reporting.
- Policies and procedures in the risk-based approach also cover matters related to the detection of suspicious transactions and the determination of monitoring types adjusted to the customer's risk level or business relationship, as well as monitoring aspects from the side of frequency, implementation methods, and evaluation of monitoring results.
- MFIs need to conduct periodic monitoring of all business relationships conducted, and of high-risk business relationships regarding Money Laundering and Terrorism Financing. MFIs apply stricter special steps for high-risk Customers or business relationships.
- MFIs need to note that in risk management and risk mitigation, leadership and involvement of senior officials are required. Senior officials are responsible for decision-making related to policies, procedures, and internal control processes and risk mitigation for Money Laundering and Terrorism Financing in the business activities owned.
- With the risk-based approach, MFIs are expected to:
a) ensure that the risk assessment conducted reflects the risk-based approach process, the frequency of monitoring low-risk and high-risk Customers, and also reflects the internal control steps implemented to reduce identified high risks; b) implement the risk-based approach risk assessment; c) update data and information for Customers and Beneficial Owners; d) monitor all owned business relationships; e) conduct more frequent monitoring of high-risk business relationships; f) take specific steps for High Risk Customers; and/or g) involve senior officials in facing situations or high-risk areas (for example, for PEPs, approval to conduct business relationships is given by senior officials).
f. Review and Evaluation of the Risk-Based Approach:
- The risk assessment owned by the MFI must be reviewed based on the need to test the effectiveness of the implementation of the APU PPT program, which includes:
a) policies and procedures; b) risk assessment related to Money Laundering and Terrorism Financing; and c) human resource training programs (for employees and senior officials).
- In the event of changes in business activity structure and the offering of new products and services, updates to the risk assessment must be conducted for policies and procedures, mitigation steps, and internal controls.
- The review of risk assessment related to Money Laundering and Terrorism Financing must cover all elements including policies and procedures regarding risk assessment, risk mitigation, and more intensive continuous monitoring. Reviews can help MFIs evaluate improvements to existing policies and procedures, or for the formation of new policies and procedures. Identified risks may change or develop along with new product development or the emergence of new threats to business activities. Ultimately, the review procedures will affect the effectiveness of the implementation of the risk-based approach.
- With the review of the risk-based approach, MFIs are expected to:
a) conduct reviews according to the MFI's needs or in the event of changes in business model, new portfolio acquisitions, etc.; b) produce reviews that cover compliance with policies and procedures, risk assessment for Money Laundering and Terrorism Financing, and training programs to test the effectiveness of the risk-based approach; c) maintain records of the review process and report to senior officials; and d) maintain review results along with the establishment of corrective steps to be followed up.
III. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
- Active Supervision by the Board of Directors
Active supervision by the Board of Directors includes at least:
a. ensuring the MFI has policies and procedures for the implementation of the APU PPT program; b. proposing written strategic policies and procedures regarding the implementation of the APU PPT program to the Board of Commissioners, which must contain at least:
- background for the formulation of written policies and procedures;
- structure, duties, authorities, and responsibilities of the working unit or person in charge of implementing the APU PPT program;
- policies and procedures for implementing the APU PPT program;
- supervision over the implementation of the APU PPT program; and
- internal control plan based on supervision results;
c. ensuring the APU PPT program is implemented in accordance with established policies and procedures by agenda-setting the discussion of the APU PPT program implementation in Board of Directors meetings;
d. forming a Special Working Unit (UKK) and/or appointing officials or employees responsible for the implementation of the APU PPT program; e. supervising the compliance of working units in implementing the APU PPT program, including monitoring the implementation of duties of the UKK and/or officials or employees responsible for implementing the APU PPT program; f. ensuring that written policies and procedures regarding the implementation of the APU PPT program align with changes and the development of products, services, and technology in the financial services sector that are appropriate with the development of Money Laundering and/or Terrorism Financing modus operandi, and can be applied in various situations; g. ensuring that all employees, especially employees from relevant working units and new employees, have participated in training related to the implementation of the APU PPT program on a regular basis, including scheduling training; h. being responsible for policies, supervision, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks; and
i. in supporting the effectiveness of the implementation of the APU PPT program, the Board of Directors must:
- have adequate understanding of the Money Laundering and Terrorism Financing risks inherent in all operational activities of the MFI so that the Board of Directors can take necessary actions according to the MFI's risk profile;
- provide clear guidance on policies, supervision, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks; and
- conduct active supervision and risk mitigation, especially customer risk, geographic area risk, product/service/transaction risk, and distribution network (delivery channels) risk.
- Active Supervision by the Board of Commissioners
Active supervision by the Board of Commissioners includes at least:
a. approving the policies and procedures for implementing the APU PPT program proposed by the Board of Directors; b. supervising the implementation of the Board of Directors' responsibilities regarding the implementation of the APU PPT program;
c. ensuring there is discussion related to Money Laundering and/or Terrorism Financing in Board of Directors and Board of Commissioners meetings or General Meeting of Shareholders (GMS)/Annual Members' Meeting (AMM) by agenda-setting the discussion of the APU PPT implementation program in those meetings; and
d. in supporting the effectiveness of the implementation of the APU PPT program, the Board of Commissioners must:
- have understanding related to the risks faced by the MFI, especially customer risk, geographic area risk, product/service/transaction risk, and distribution network (delivery channels) risk; and
- ensure the organizational structure is adequate for the implementation of the APU PPT program.
- Person in Charge of Implementing the APU PPT Program
a. MFIs form a UKK and/or appoint one official or employee as the person in charge of implementing the APU PPT program at the head office and branch offices, while still considering the characteristics, size, and conditions of the MFI. b. In the event that the MFI appoints a person in charge of implementing the APU PPT program at branch offices, the person in charge can be an official or employee from a working unit related to Customers (operations), provided that those operational duties do not affect the independence and professionalism of those employees in carrying out their tasks.
c. The appointment of officials/employees in charge for branch offices can also be held concurrently by the officials/employees in charge at the head office if the MFI has adequate considerations, for example, characteristics, business scale, number of customers, number of employees or HR, and/or the risk level of the relevant MFI branch office.
d. The UKK and/or officials or employees in charge of implementing the APU PPT program report to and are responsible to the Board of Directors. e. So that the tasks of the UKK and/or officials or employees in charge of implementing the APU PPT program can be carried out well, the MFI must have adequate working mechanisms, and be implemented by each relevant working unit while considering regulations regarding anti-tipping off and information confidentiality. The anti-tipping off regulation is a regulation that prohibits the MFI from informing Customers or any other party, directly or indirectly, in any manner, regarding suspicious financial transaction reports that are being drafted or have been submitted to the PPATK. f. The UKK and/or officials or employees in charge of implementing the APU PPT program meet the criteria:
- independent of the activities being monitored;
- able to provide the information needed by the Board of Directors to obtain an overview of the MFI's condition regarding risk management and compliance;
and
3) having appropriate and unrestricted access to customer identification documents, registered accounts, other accounting records, and other related information.
g. The UKK and/or officials or employees responsible for implementing the AML and CFT program at branch offices or offices outside the head office may concurrently serve as the head of the office in implementing the AML and CFT program at offices outside the head office.
IV. POLICIES AND PROCEDURES
-
Microfinance Institutions (LKM) must have policies and procedures to manage and mitigate identified Money Laundering and/or Terrorism Financing risks according to risk assessments.
-
The policies and procedures for implementing the AML and CFT program must include at least:
a. identification and verification of Customers and Prospective Customers; b. identification and verification of Beneficial Owners;
c. termination of business relationships or refusal of transactions;
d. ongoing management of Money Laundering and/or Terrorism Financing risks related to Customers, geographic areas, products/services/transactions, or distribution networks (delivery channels); e. maintenance of accurate data regarding transactions, accounting of the CDD process, and accounting of policies and procedures; f. monitoring and updating; g. reporting to senior officials, the Board of Directors, and the Board of Commissioners regarding the implementation of the AML and CFT program policies and procedures; and h. reporting to PPATK.
-
Identification and verification of Prospective Customers, Customers, and Beneficial Owners consists of:
a. CDD Policy
- LKM must conduct CDD procedures when:
a) establishing a business relationship with a Prospective Customer; b) there are financial transactions with a value of at least or equivalent to Rp100,000,000.00 (one hundred million rupiah); c) there are indications of Suspicious Financial Transactions related to Money Laundering and/or Terrorism Financing; or d) LKM doubts the truthfulness of information provided by Prospective Customers, Customers, authorized representatives, and/or Beneficial Owners.
- LKM must identify and classify Prospective Customers or Customers into groups of natural persons, Corporations, and other legal arrangements.
- LKM must group Prospective Customers and Customers based on the level of risk of Money Laundering and/or Terrorism Financing occurrence based on analysis that includes at least:
a) Customer identity; b) business location for corporate Customers; c) Customer profile; d) transaction frequency; e) Customer's business activities; f) ownership structure for corporate Customers; g) products, services, and distribution networks (delivery channels) used by Customers; and h) other information that can be used to measure the Customer's risk level.
- The risk-based approach CDD mentioned is intended to obtain up-to-date information regarding customer profiles to ensure alignment between customer profiles and transactions conducted. CDD can be conducted on all information or only on partial information.
- In cases where LKM assesses a change in the risk level of a Customer, CDD based on the risk-based approach can be conducted again if:
a) there is a significant increase in transaction value; b) there are significant changes in Customer profiles, including significant or substantial changes in transaction patterns; c) information in the Customer profile is not completed with required documents; and/or d) using anonymous accounts or accounts using fictitious names. b. Prospective Customer Acceptance and Identification Procedures LKM must have policies regarding the acceptance and identification of Prospective Customers that include at least the following:
- requests for information regarding Prospective Customers;
- requests for identity proof and supporting information from Prospective Customers;
- research on the truthfulness of supporting identity documents of Prospective Customers by utilizing comparative data from third parties whose data truthfulness can be accounted for;
- requests for more than one identity card of Prospective Customers issued by competent authorities, if there is doubt about the existing identity card;
- if necessary, interviews with Prospective Customers can be conducted to obtain certainty regarding the truthfulness of information, identity proof, and supporting documents of Prospective Customers;
- prohibition on opening or maintaining anonymous accounts or accounts using fictitious names;
- face-to-face meetings with Prospective Customers at the beginning of establishing business relationships to ensure the truthfulness of Prospective Customer identities; and
- completion of the Prospective Customer identity verification process.
c. Beneficial Owner Identification Procedures
- LKM must understand the profile, purpose, and business relationship, and transactions conducted by Customers and Beneficial Owners through identification and verification.
- LKM must ensure that Prospective Customers or Customers establishing business relationships or conducting transactions act for themselves or for the interests of Beneficial Owners.
- If Prospective Customers represent Beneficial Owners to establish business relationships or conduct transactions, LKM must conduct CDD procedures for Beneficial Owners that are equally strict as CDD procedures for Prospective Customers.
- In cases where Beneficial Owners are classified as PEPs, the procedures applied are EDD procedures.
- In cases where there are differing risk levels between Prospective Customers, or Customers, and Beneficial Owners, CDD application follows the higher risk level.
- In cases where Prospective Customers or Customers are not Beneficial Owners, LKM must identify and verify the identities of Beneficial Owners, including:
a) identity information and documents:
(1) identity containing:
(2) full name including aliases (if any);
(3) identity document number;
(4) residential address according to identity documents and other residential addresses (if any); (5) place and date of birth; (6) nationality; (7) occupation; (8) workplace address and telephone number (if any); (9) gender; (10) marital status; (11) Prospective Customer identity documents and specimen signatures; (12) source of funds; (13) average annual income; and (14) purpose and business relationship or transactions to be conducted by Prospective Customers; b) legal relationships between Prospective Customers or Customers and Beneficial Owners shown by appointment letters, agreements, powers of attorney, or other forms; c) statements from Prospective Customers or Customers regarding the truthfulness of identities and fund sources of Beneficial Owners; and d) statements from Beneficial Owners that they are the actual owners of the funds of Prospective Customers or Customers.
- In cases where LKM doubts or cannot verify the identities of Beneficial Owners, LKM must refuse to establish business relationships or conduct transactions with Prospective Customers or Customers.
- For Prospective Customers or Beneficial Owners whose business relationships or transactions are refused, LKM must obtain at least information on names, identity numbers, addresses, and place and date of birth according to copies of identity documents obtained by LKM for the purpose of reporting Suspicious Financial Transaction Reports (LTKM).
d. Verification of Prospective Customers, Customers, and Beneficial Owners
- LKM must examine the truthfulness of information provided by Prospective Customers by verifying supporting documents based on documents and/or other independent sources and ensuring the currency of such information.
- The information and supporting documents that LKM must request from Prospective Customers who are natural persons include at least:
a) identity containing:
full name including aliases (if any); identity document number; residential address according to identity documents and other residential addresses (if any); place and date of birth; nationality; occupation; workplace address and telephone number (if any); gender; marital status; and Prospective Customer identity documents and specimen signatures. b) Beneficial Owner identities, if any; c) source of funds; d) average annual income; and e) purpose and business relationship or transactions to be conducted by Prospective Customers.
- The information and supporting documents that LKM must request from Corporate Prospective Customers include at least:
a) name; b) license number from competent authorities; c) business field or activities; d) domicile address; e) place and date of establishment; f) legal entity or business form; g) Beneficial Owner identities if Prospective Customers have Beneficial Owners; h) source of funds; and i) purpose and business relationship or transactions to be conducted by Prospective Customers. Meanwhile, information and supporting documents that LKM must request from Prospective Customers who are other legal arrangements include at least:
a) name; b) license number from competent authorities (if any); c) domicile address; d) legal arrangement form; e) Beneficial Owner identities if Prospective Customers have Beneficial Owners; f) source of funds; and g) purpose and business relationship or transactions to be conducted by Prospective Customers.
- To ensure the truthfulness of Prospective Customer identities, verification is conducted by:
a) face-to-face meetings with Prospective Customers at the beginning of establishing business relationships; b) conducting interviews with Prospective Customers if necessary; c) matching the consistency of Prospective Customer profiles with self-portraits contained in identity cards; d) matching the consistency of signatures, thumbprints, or fingerprints with identity documents or other documents containing signatures, thumbprints, or fingerprints. Other documents include Prospective Customer statement letters, family cards, or credit cards; e) requesting Prospective Customers to provide more than one identity document issued by competent authorities if doubts arise regarding existing identity cards; f) accounting for copies of identity cards after matching with original valid documents; g) conducting cross-checks to ensure consistency of various information provided by Prospective Customers. Cross-checks are conducted by, among others:
contacting Prospective Customers via telephone (home or office) or other forms of communication; contacting officials managing human resources at the workplace of Prospective Customers if they are employees of a company or institution; confirming Prospective Customer income by requiring bank statements from banks or other financial service providers; or analyzing geographical information to view forest conditions through remote sensing technology for corporate Prospective Customers operating in the forestry sector; h) ensuring that Prospective Customers have no negative track records by verifying identities using other independent sources, including:
terrorist lists and/or suspected terrorist lists and terrorist organizations issued by the Indonesian National Police; lists of proliferation of weapons of mass destruction financiers; other data owned by LKM, Prospective Customer employer identities, telephone accounts, and electricity accounts; and/or ensuring the possibility of unusual or suspicious matters.
- Verification through face-to-face meetings, as mentioned in number 2 letter a), can be replaced by verification through electronic means, with the following requirements:
a) what you have, namely identity documents owned by Prospective Customers, namely electronic Resident Identity Cards (KTP); and b) what you are, namely biometric data including in the form of Prospective Customer fingerprints.
- The Prospective Customer and Beneficial Owner identity verification process must be completed before establishing business relationships with Prospective Customers.
- In certain conditions, the verification process can be completed later after business relationships have been established.
- The certain conditions mentioned in number 5) are:
a) document completeness cannot be met at the time business relationships are established, for example, because documents are still being processed. Therefore, Prospective Customers can submit documents after establishing business relationships, within the time limit set by LKM; and/or b) if the risk level of individual Prospective Customers is classified as low. e. High-Risk Prospective Customers, Customers, and Beneficial Owners Identification and Verification
- LKM must have adequate risk management systems to determine whether Prospective Customers, Customers, or Beneficial Owners meet high-risk criteria.
- High-risk criteria for Prospective Customers, Customers, or Beneficial Owners based on:
a) backgrounds or profiles of Prospective Customers, Customers, or Beneficial Owners, including High Risk Customers; b) high-risk financial service sector products used as vehicles for Money Laundering and/or Terrorism Financing; c) transactions inconsistent with profiles; d) inclusion in PEP categories; e) business fields of Prospective Customers, Customers, or Beneficial Owners including high-risk businesses (High Risk Business); f) inclusion of Prospective Customers, Customers, or Beneficial Owners in suspected terrorist lists and terrorist organization lists, and/or proliferation of weapons of mass destruction financing lists; or g) transactions conducted by Prospective Customers, Customers, or Beneficial Owners suspected to be related to financial sector criminal offenses, Money Laundering criminal offenses, and/or Terrorism Financing criminal offenses.
- LKM must conduct assessments to determine if Customer Beneficial Owners are PEPs.
- LKM must create separate lists for Prospective Customers, Customers, or Beneficial Owners meeting high-risk criteria.
f. Simplified CDD
- LKM may apply simplified CDD procedures to Prospective Customers or transactions with low risk of Money Laundering and/or Terrorism Financing occurrence meeting the following criteria:
a) Criteria for Prospective Customers or transactions with low Money Laundering and Terrorism Financing risks:
purpose of account opening related to government programs to improve community welfare and/or poverty alleviation, for example, direct cash assistance (BLT) recipients or disabled customers; and/or Prospective Customers classified as low risk based on Money Laundering and/or Terrorism Financing risk assessments and meeting criteria for Prospective Customers with simple profiles and characteristics, including:
(a) low-risk financial service sector products used as vehicles for Money Laundering and/or Terrorism Financing, for example, Student Savings Products; (b) Customers conducting normal transactions consistent with customer profiles, including explainable distances between transaction locations and customer residences/business locations; (c) not being PEPs, PEP family members, close associates of PEPs, or persons authorized to perform important functions (prominent function) in international organizations; (d) not included in suspected terrorist lists and terrorist organization lists, and/or proliferation of weapons of mass destruction financing lists; and/or (e) purpose of account opening for salary payments or receipts. b) Documents required in simplified CDD are:
for Prospective Customers who are natural persons, LKM requests information:
(a) full name including aliases (if any);
(b) identity document number;
(c) residential address according to identity documents and other residential addresses (if any); and (d) place and date of birth, supported by original identity documents such as KTP. for Prospective Customers whose account opening purposes are related to government programs to improve community welfare and/or poverty alleviation, LKM requests information:
(a) full name including aliases (if any);
(b) residential address according to identity documents and other residential addresses (if any); (c) place and date of birth; and (d) occupation, supported by other documents, including:
(a) identification cards issued by the government containing self-portraits, such as participant cards issued by the government; (b) identity documents and reference letters from Customers who know the Prospective Customer's profile; (c) reference letters from villages or village heads where Prospective Customers reside containing self-portraits; or (d) student identification cards for individual Prospective Customers who do not meet requirements to have resident identity cards, accompanied by identity documents and permission letters from parents or other responsible parties for such Prospective Customers.
- LKM may apply separate simplified CDD procedures according to risk assessments for Prospective Customers meeting criteria for Customers with simple profiles and characteristics. In cases where LKM applies separate simplified CDD procedures, LKM must notify OJK, where such notifications include information regarding:
a) Customer identification criteria and low-risk transactions consistent with risk assessments conducted by LKM; b) simplified CDD requirements capable of managing Money Laundering and/or Terrorism Financing threat levels for Prospective Customers and their transactions identified with low risk levels for Money Laundering and/or Terrorism Financing; c) simplified CDD requirements not including Customers classified as high-risk Customers or transactions according to laws and regulations; and d) start time of simplified CDD procedure implementation.
- LKM must implement and be responsible for the execution of separate simplified CDD procedures.
- In implementing simplified CDD, LKM must pay attention to or execute:
a) Simplified CDD procedures as mentioned do not apply if there are suspicions of Money Laundering and/or Terrorism Financing transactions or if risk levels increase. b) LKM must create and store lists of Customers receiving simplified CDD treatment, including information regarding risk determination reasons so they are classified as low risk. c) Customers who have received simplified CDD treatment must be removed from the simplified CDD Customer lists if they meet the following criteria:
indicated to be related to Money Laundering or Terrorism Financing; or inconsistent with initial account opening purposes, including for salary payments or receipts. d) Customers removed from simplified CDD customer lists as mentioned in number 3) must:
undergo CDD or EDD according to current customer risk levels; and/or be reported in Suspicious Financial Transaction Reports (LTKM) if transactions are indicated to be related to Money Laundering or Terrorism Financing. g. Third-Party CDD
- LKM may use CDD results conducted by third parties on Prospective Customers who have become customers of such third parties.
- In cases where LKM uses third-party CDD results as mentioned in paragraph (1), LKM must:
a) understand the purpose and business relationships; and b) identify and verify Customers and Beneficial Owners.
- In cases where LKM uses CDD results conducted by third parties, CDD responsibility remains with such LKM.
- In cases where LKM uses third-party CDD:
a) LKM must obtain necessary information related to CDD procedures as soon as possible; b) LKM must have cooperation with third parties in the form of written agreements; c) LKM must take adequate steps to ensure that third parties are willing to fulfill information requests and copies of supporting documents immediately when needed by LKM in implementing AML and CFT programs; d) LKM must ensure that third parties are financial institutions and providers of goods and/or services and specific professions having CDD procedures and subject to supervision by competent authorities according to laws and regulations; and e) LKM must pay attention to information regarding risk levels of countries where such third parties originate.
- LKM ensures that third parties are in countries compliant with Financial Action Task Force (FATF) standards.
- Third-party CDD does not apply to agency relationships or outsourcing.
h. EDD
- In cases where Prospective Customers, Customers, or Beneficial Owners are classified as high-risk, including PEPs, LKM must conduct EDD.
- LKM must conduct assessments to determine if Prospective Customers, Customers, and Beneficial Owners are PEPs.
- In cases where Prospective Customers, Customers, and Beneficial Owners are classified as high-risk, including PEPs, LKM must conduct EDD.
- Verification and EDD steps include:
seeking additional information regarding the source of funds or customer wealth; seeking additional information about the nature of business relationships; seeking additional information regarding reasons for transactions conducted or intended; requesting approval from senior officials to initiate or continue such business relationships; and/or conducting stricter monitoring of such business relationships, including increasing the number and time of supervisions used, and having transaction patterns requiring further examination.
- LKM accounts for documents related to EDD and updates Customer data periodically or according to LKM needs and complexity.
- In conducting business relationships with Prospective Customers, Customers, or Beneficial Owners, including PEPs, receiving EDD treatment, LKM must appoint senior officials as responsible parties for such business relationships.
- Termination of Business Relationships or Refusal of Transactions
a. LKM conducts refusal of business relationships with Prospective Customers and/or refusal of transactions, transaction cancellations, and/or termination of business relationships with Customers in cases where:
-
Prospective Customers or Customers are unwilling to provide information and/or complete documents required by LKM;
-
Prospective Customers or Customers provide information and/or documents that are inconsistent or reasonably suspected to be fake documents or information whose truthfulness is doubted;
-
transaction fund sources owned by Customers are known and/or reasonably suspected to originate from criminal proceeds;
-
Prospective Customers or Customers are listed in suspected terrorist lists and terrorist organization lists; and/or
-
Prospective Customers or Customers are listed in the database for the Financing of Weapons of Mass Destruction Proliferation.
b. In the event that an MFI suspects financial transactions related to Money Laundering and Terrorism Financing crimes, and the MFI believes that the CDD process would violate anti-tipping-off regulations, the MFI is required to halt the CDD procedure and must report the Suspicious Financial Transaction to PPATK.
c. MFIs are required to document Prospective Customers or Customers for whom business relationships are rejected, transactions are rejected, transactions are cancelled, or business relationships are terminated.
d. MFIs are required to report Prospective Customers or Customers for whom business relationships are rejected, transactions are rejected, transactions are cancelled, or business relationships are terminated in a Suspicious Financial Transaction report if the transaction is suspicious. e. The MFI's obligation to reject, cancel, and/or terminate business relationships with Customers must be included in the account opening agreement and notified to the Customer. f. In the event that an MFI terminates a business relationship, the MFI is required to provide written notice to the Customer regarding the termination of the business relationship. g. Written notice can be done by sending a letter addressed to the Customer according to the address listed in the MFI's database or announced through print media, electronic media, or other media. h. In the event that written notice has been provided and the Customer does not withdraw the remaining funds stored at the MFI, the settlement of the Customer's remaining funds is carried out in accordance with applicable legislation, including by handing over the remaining funds to the Estate Office (Balai Harta Peninggalan).
- Ongoing Management of Money Laundering and/or Terrorism Financing Risk Related to Customers, Geographic Areas, Products/Services/Transactions, or Distribution Channels (Delivery Channels)
a. MFIs apply policies, procedures, and controls to reduce the potential for Money Laundering and Terrorism Financing, particularly related to Customers, geographic areas, products/services/transactions, or distribution channels (delivery channels) that may pose higher risks. b. Controls and mitigation that can be applied include at least:
- developing systems to identify and monitor higher-risk Customer transactions across all MFI business activities;
- upgrading CDD to EDD conducted as the MFI's understanding of the Customer, the source of funds used to purchase products/services/transactions, and the Customer's behavior in purchasing products and services increases;
- escalation or tiered approval for establishing business relationships or transactions through senior official approval;
- increased transaction monitoring (frequency, thresholds, volume, etc.); and
- increasing the frequency of supervision and conducting ongoing reviews of business relationships.
- Maintenance of Accurate Data Related to Transactions, CDD Process Accounting, and Policy and Procedure Accounting
a. MFIs must account for all transaction data or documents obtained through CDD steps. This is an effort to assist authorities in investigating funds indicated to originate from criminal proceeds or to assist in the duties of competent authorities. Thus, the documents owned or stored by the MFI must be sufficient as a tool for reconstructing individual transactions (including the amount, if any) so that they can be used as evidence (if necessary) in prosecuting criminal activities. b. The retention period for documents is as follows:
- documents related to Customer data with a retention period of at least 5 (five) years from:
a) the end of the business relationship with the Customer; and/or b) the discovery of transaction inconsistencies with economic purposes and/or business purposes;
- documents related to Customer financial transactions with a retention period as regulated in laws regarding corporate documents; and
- documents accounted for must at least include:
a) Customer identity at least including copies or recordings of Customer identity documents (examples: ID cards, driver's licenses, passports, or similar documents); b) transaction information including among others the currency amount used, the date of the transaction order, the origin and destination of the transaction, and the account number related to the transaction; c) results of analysis that have been conducted; and d) other supporting documents that need to be accounted for, including account files, results of analysis conducted. Example: analysis conducted to ensure the background and purpose of large transactions.
c. MFIs are required to provide data, information, and/or documents that have been accounted for when requested by the Financial Services Authority (OJK) and/or other competent authorities. Other competent authorities include law enforcement agencies (Police, Attorney General's Office, and KPK) and PPATK.
- Monitoring and Updating
a. MFIs are required to monitor business relationships with Customers by monitoring Customer transactions to ensure that transactions are consistent with the MFI's understanding of the Customer, business activities, and Customer risk profile, including the source of funds, with the following steps.
- MFIs conduct continuous monitoring activities to identify consistency between Customer transactions and Customer profiles and account for such documents, particularly for business relationships or transactions with High Risk Customers.
- Continuous transaction and Customer profile monitoring activities include:
a) ensuring the completeness of Customer information and supporting documents; b) researching and analyzing the consistency of all transactions, including transaction patterns inconsistent with the Customer profile; c) requesting information about the background and purpose of transactions, including transaction patterns inconsistent with the Customer profile, while observing anti-tipping-off regulations, as referred to in the Law governing the prevention and eradication of Money Laundering crimes; and d) researching name similarities or matches with names listed in the terrorist database, suspected terrorist list, terrorist organization list, financing of Weapons of Mass Destruction Proliferation list, names of suspects or defendants published in mass media or by competent authorities.
- Information sources that can be used to monitor MFI Customers designated as suspects or defendants can be obtained from among others:
a) databases issued by competent parties such as PPATK; or b) mass media such as newspapers, magazines, television, and/or the internet.
- Monitoring of transactions and Customer profiles must be conducted periodically using a risk-based approach, for example, for High Risk Customers, monitoring must be stricter.
- One form of monitoring that MFIs must conduct is identifying and checking the consistency of Customer identity with the identity of individuals or Corporations listed in the suspected terrorist and terrorist organization list and the financing of Weapons of Mass Destruction Proliferation list.
- All monitoring activities must be documented systematically and in written form, either through formal documents such as memos, notes, or records or through informal documents such as correspondence via electronic mail.
b. MFIs are required to update data, information, and/or supporting documents in the event of known changes from the MFI's monitoring of Customers or other accountable information, with the following steps:
- MFIs must apply CDD procedures to Customers to update data, considering materiality and risk level. This CDD is conducted by considering the timing of the previous CDD and the adequacy of data obtained.
- MFIs must ensure that documents, data, or information collected in the CDD process are always updated and relevant by re-examining existing data, particularly those related to High Risk Customers.
- Customer data updates are conducted using a risk-based approach that includes updating Customer profiles, including transaction patterns. In the event that the MFI's resources are limited, data update activities are conducted on a priority scale.
- In determining the priority scale for Customer data updates, MFIs may prioritize several criteria among others:
a) Customers with high risk levels; b) transactions with significant amounts and/or deviating from transaction profiles or Customer profiles (red flags); c) account balances with significant value; or d) changes in Customer profiles.
- Data updates are conducted periodically based on Customer or transaction risk levels.
- Implementation of data updates for Customers listed in the data update plan report can be conducted among others at:
a) opening additional accounts; b) extending loan facilities; c) replacing Customer data and identity documents; and/or d) closing accounts.
- Recording updates to the integrated Customer profile data without supporting documents must be approved by the competent MFI official. Example: A Customer fills in the income amount in the account opening form as Rp5,000,000.00 (five million rupiah) per month, but based on obtained information, the income amount is known to be Rp15,000,000.00 (fifteen million rupiah). In this case, the MFI fills in the monthly income amount in the integrated Customer profile data as Rp15,000,000.00 (fifteen million rupiah) accompanied by a note, memo, or record explaining the reason or consideration for filling in that number and the approval of the competent MFI official. Such note, memo, or record documents become an inseparable part of the Customer's account opening agreement.
- All data update activities must be accounted for.
c. MFIs are required to document data update efforts as regulated in the document accounting section.
d. In conducting data updates, MFIs are required to:
- monitor Customer information and documents;
- prepare a data update activity plan report; and
- prepare a data update realization report.
e. The data update activity plan report and data update realization report must receive approval from the Board of Directors.
-
In conducting monitoring, MFIs are required to have a system that can:
a. identify, analyze, monitor, and effectively provide reports on profiles, characteristics, and/or transaction pattern habits conducted by Customers; and b. trace each transaction, if necessary, including tracing Customer identity, transaction type, transaction date, transaction amount and denomination, and the source of funds used for the transaction.
-
MFIs are required to maintain lists of suspected terrorists and terrorist organizations, and the financing of Weapons of Mass Destruction Proliferation list.
-
MFIs are required to identify and periodically ensure that Customer names have similar names and other Customer information match the names and information listed in the suspected terrorist and terrorist organization list, and the financing of Weapons of Mass Destruction Proliferation list.
-
In the event that there is a Customer name similarity with names listed in the suspected terrorist and terrorist organization list, and the financing of Weapons of Mass Destruction Proliferation list, the MFI is required to ensure the consistency of the Customer's identity with other related information. Other information includes among others place and date of birth and Customer address.
-
In the event that there is a Customer name match and other information matches with names listed in the suspected terrorist and terrorist organization list, and the financing of Weapons of Mass Destruction Proliferation list, the MFI is required to immediately conduct immediate blocking.
-
In the event that an MFI has conducted immediate blocking against Customers listed in the suspected terrorist and terrorist organization list and the financing of Weapons of Mass Destruction Proliferation list, the MFI is required to report it as a Suspicious Financial Transaction report.
-
MFIs are prohibited from providing, giving, or lending funds to or for the benefit of persons or Corporations whose identities are listed in the suspected terrorist and terrorist organization list and the financing of Weapons of Mass Destruction Proliferation list.
-
Reporting to senior officials, the Board of Directors, and the Board of Commissioners regarding the implementation of APU and PPT program policies and procedures:
a. In the event that the CDD process shows a Prospective Customer or Customer categorized as high risk, the MFI employee conducting CDD reports to the senior official. The senior official is responsible for the acceptance and/or rejection of business relationships with Prospective Customers or High Risk Customers. b. In the event that the senior official approves a business relationship with a High Risk Customer, the senior official is responsible for monitoring the transactions of High Risk Customers.
c. Senior officials must report to the Board of Directors overseeing the APU and PPT program implementation function regarding the number of Prospective Customers or High Risk Customers, including the number of High Risk Customers that were rejected, accepted, or had their business relationships terminated.
d. The Board of Directors must provide guidance on reports submitted by senior officials and establish risk mitigation steps. e. The Board of Directors reports to the Board of Commissioners regarding the results of monitoring the overall implementation of the APU and PPT program as per the written policies and procedures established by the MFI. f. The Board of Directors may propose updates to policies and procedures in the event of risk developments that need to be mitigated by the MFI, which are not yet listed in the written policies and procedures.
-
Reporting to PPATK
MFIs are required to submit reports to PPATK as regulated in legislation governing the prevention and eradication of TPPU (Money Laundering and Terrorism Financing).
V. INTERNAL CONTROL
- The implementation of a risk-based APU and PPT program must be implemented in internal control and internalized in the MFI's business processes.
- MFIs are required to have an effective internal control system.
- The implementation of an effective internal control system is demonstrated among others by:
a. having adequate policies, procedures, and internal monitoring; b. having limits on authority and responsibility of work units related to the implementation of the APU and PPT program; and
c. conducting independent examinations to ensure the effectiveness of the APU and PPT program implementation.
- In addition to compliance with internal control, the implementation of the APU and PPT program is also influenced by the following factors:
a. the scale and complexity of the MFI; b. the diversity of MFI business or operational activities, including geographic areas, Customers, products/services/transactions, and overall MFI transaction activities;
c. the distribution channels (delivery channels) used;
d. the volume and scale of transactions; e. the level of risk assessment for each MFI business activity; and/or f. the relationship between the MFI and Customers, either directly or through intermediaries, third parties, correspondents, or non-face-to-face communication.
- MFIs must have an internal control framework that includes:
a. an internal audit work unit (SKAI) or designated officials/employees as internal control implementers; b. special monitoring of operational activities that pose high risks, including monitoring of items deemed vulnerable and potentially related to suspicious transactions or requiring special attention based on suggestions and information from regulators or law enforcement;
c. providing regular reviews of risk assessments and process management considering the location where the MFI operates;
d. ensuring adequate controls before offering new products/services/transactions or when modified products/services/transactions are offered that have the potential to increase Money Laundering and Terrorism Financing risks; e. providing fast and accurate information in the event of indications and/or suspicions related to Money Laundering and Terrorism Financing risks, corrective steps taken, results of identifying weaknesses in existing regulations, follow-up plans for improvements, and reports submitted to competent parties; f. focusing on collecting matters related to regulatory requirements, reporting requirements, and recommendations related to compliance with the APU and PPT program implementation and updating changes in regulations; g. applying policies and procedures for CDD control; h. providing adequate controls for high-risk Customers, transactions, and products, such as transaction limits or management approval;
i. providing adequate supervision of MFI employees who complete reports, receive grants, monitor suspicious activities, or are involved in other activities that are part of the APU and PPT program implementation;
j. assessing the level of APU and PPT program implementation compliance according to job descriptions and performance evaluations of all relevant parties within the MFI; k. ensuring the existence of a joint control framework for MFIs that are part of a financial conglomerate; and
l. testing the effectiveness of the APU and PPT program implementation by taking random samples and documenting the tests conducted.
VI. MANAGEMENT INFORMATION SYSTEM
-
The implementation of the APU and PPT program must be supported by a management information system that can identify, analyze, monitor, and effectively provide reports on the characteristics of transactions conducted by Customers using parameters adjusted periodically and considering the complexity of business, transaction volume, and risks owned by the MFI.
-
In the event that the MFI already uses information technology applications, the written policies and procedures owned by the MFI must consider information technology factors that have the potential to be abused by Money Laundering or Terrorism Financing perpetrators, such as account opening via the internet, or fund transfer orders via fax or telephone, and other electronic transactions.
-
The owned information system must allow the MFI to trace each transaction (individual transaction), both for internal and/or Financial Services Authority purposes, and in relation to judicial cases.
-
To facilitate monitoring in the context of analyzing suspicious financial transactions, MFIs are required to have and maintain an integrated Customer profile.
-
Information contained in the integrated Customer profile data includes all products and services used by the Customer at an MFI, namely among others savings, deposits, and loans or financing.
-
For joint accounts, the integrated Customer profile is created for each party owning the joint account. For example, a joint account under the names A and B, the integrated Customer profile created is 2 (two), namely the integrated Customer profile under the names A and B, informing that both A and B have a joint account.
-
For the purpose of maintaining the integrated Customer profile, the MFI must establish a policy that for every addition of accounts and/or services or products by an existing Customer, the MFI must link the additional accounts, services, or products with the integrated Customer profile number of the respective Customer.
VII. HUMAN RESOURCES AND TRAINING
- Human Resources
To prevent the use of MFIs as a medium or goal for Money Laundering and/or Terrorism Financing involving MFI internals, MFIs are required to conduct:
a. screening procedures for new employee recruitment (pre-employee screening) as part of the implementation of know your employee (KYE) with the following regulations:
-
screening methods are adjusted to the needs, MFI business complexity, and MFI risk profile;
-
screening methods must at least ensure that the candidate's profile has no criminal record and no bad credit by requiring the candidate to create a stamped letter of statement covering the following matters:
a) has never been sentenced for committing criminal offenses in the financial services and/or economic sector based on a court decision that has permanent legal force; b) has never been sentenced for committing criminal offenses based on a court decision that has permanent legal force in the last 5 (five) years; and c) is not listed in the bad credit list in the financial services sector;
-
verify the identity and education obtained by the candidate; and
-
conduct research through other information media, among others, print media or electronic media.
b. recognition and monitoring of employee profiles, including employee behavior and lifestyle, among others:
-
conduct research through other information media, among others through print media or electronic media;
-
verify employees who have undergone significant lifestyle changes;
-
monitor employee accounts held at the MFI;
-
ensure that employees understand and comply with the employee code of conduct; and
-
evaluate employees responsible for activities classified as high risk, including those who have access to MFI data, interact with Prospective Customers or Customers, and are involved in the procurement of goods and services.
c. Pre-employee screening procedures, recognition, and monitoring of employee profiles are codified in the human resources policy (Know Your Employee/KYE), which is guided by regulations governing the implementation of anti-fraud strategies.
- Training
a. Training Participants
-
Ensure that employees consistently receive opportunities to enhance their competencies through training related to the implementation of the AML and CTF program.
-
In determining training participants, MFIs prioritize employees who have daily tasks with the following criteria:
a) direct interaction with Customers (front liner); b) supervision of the implementation of the AML and CTF program; and/or c) involvement in the preparation of reports to PPATK and the Financial Services Authority (OJK).
- Employees who supervise the implementation of the AML and CTF program must receive training periodically, while other employees must receive training at least once (1) during their employment period. Employees who have direct interaction with Customers (front liner) must receive training before placement.
b. Training Methods
- Training can be conducted via:
a) electronic (online base)
Electronic training (online base) can utilize electronic learning (e-learning) media.
b) face-to-face
Face-to-face training is conducted, among other forms, through socialization, seminars, or workshops.
- The organization of training can be conducted by, among others, competent authorities (e.g., PPATK or OJK), MFIs or associations, and educational and training institutions.
c. Training Materials and Evaluation
- MFIs may develop training materials related to the implementation of the AML and CTF program according to their needs. Some topics that can serve as training materials include:
a) implementation of statutory regulations related to the implementation of the AML and CTF program; b) techniques, methods, and typologies of Money Laundering and/or Terrorism Financing, including trends and developments in the risk profile of MFI products; and c) policies and procedures for implementing the AML and CTF program, as well as the roles and responsibilities of employees in preventing and combating Money Laundering and/or Terrorism Financing, including consequences if employees engage in tipping-off.
-
The depth of training topics is adjusted to the needs of employees and their alignment with their duties and responsibilities.
-
To determine the level of employee understanding and the appropriateness of training materials, MFIs must evaluate every training session conducted.
-
Evaluation can be conducted directly through interviews or indirectly through tests.
-
MFIs must take follow-up actions based on the results of training evaluations by refining training materials and methods.
VI. REPORTING
- Reports to the Financial Services Authority (OJK)
a. Reports on the Plan for Data Updating Activities and Reports on the Realization of Data Updating Activities
-
Reports on the plan for data updating activities and reports on the realization of data updating activities must be approved and submitted by the Board of Directors overseeing the compliance function or a member of the Board of Directors responsible for the implementation of the AML and CTF program.
-
Reports on the plan for data updating activities, in accordance with the Financial Services Authority Regulation regarding the implementation of the Anti-Money Laundering and Counter-Terrorism Financing program in the financial services sector, must be submitted annually no later than the end of December.
-
Reports on the realization of data updating activities, in accordance with the Financial Services Authority Regulation regarding the implementation of the Anti-Money Laundering and Counter-Terrorism Financing program in the financial services sector, must be conducted no later than 1 (one) month after the reporting period ends.
-
The submission of the data updating plan report as referred to in item 2) for the first time must be submitted no later than the end of December 2021. Meanwhile, the submission of the data updating realization report as referred to in item 3) for the first time must be submitted no later than the end of January 2023.
-
Changes to the data updating plan report can be made as long as changes occur outside the control of the MFI and must be submitted to the Financial Services Authority no later than 7 (seven) working days from when the change is made.
-
The data updating plan report and the data updating realization report can refer to the format as referred to in Format C of Appendix II, which is an integral part of this Financial Services Authority Circular.
b. Report on Changes to Policies and Procedures for Implementing the AML and CTF Program:
-
The report on changes to policies and procedures for implementing the AML and CTF program contains details of changes to the adjustment of policies and procedures for implementing the AML and CTF program that have been previously submitted to the Financial Services Authority.
-
The report on the adjustment of policies and procedures for implementing the AML and CTF program must be approved and submitted by the Board of Directors overseeing the compliance function or a member of the Board of Directors responsible for the implementation of the AML and CTF program.
-
The submission of the report on changes to policies and procedures for implementing the AML and CTF program must be submitted no later than 7 (seven) working days from when the change is made.
For example, if an MFI made changes to the adjustment of policies and procedures for implementing the AML and CTF program on Monday, 14 November 2022, the MFI must submit the report on the adjustment of policies and procedures for implementing the AML and CTF program no later than 22 November 2022.
c. Submission of reports as referred to in letters a and b is subject to the following provisions:
- the cover letter for submission is signed by the Board of Directors and submitted in printed computer output (hardcopy); and
- the content of the AML and CTF program implementation report is submitted in electronic format (softcopy).
d. All reports as referred to in letters a and b are submitted to the Microfinance Directorate or the Regional Office of the Financial Services Authority or the Financial Services Authority Office according to the supervisory area of each MFI.
This copy is consistent with the original
Director of Legal Affairs 1
Legal Department signed
Mufli Asmawidjaja
- Reports to PPATK
MFIs must submit reports to PPATK as regulated in statutory regulations governing the prevention and eradication of Money Laundering and Terrorism Financing, including its implementing regulations.
VII. CLOSING
The provisions in this Financial Services Authority Circular shall take effect on the date of establishment.
Established in Jakarta on 23 March 2021
EXECUTIVE HEAD OF SUPERVISION FOR
INSURANCE, PENSION FUNDS,
LENDING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
RISWINANDI
APPENDIX I
FINANCIAL SERVICES AUTHORITY CIRCULAR
REPUBLIC OF INDONESIA
NUMBER 11 /SEOJK.05/2021
REGARDING
GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS FOR MICROFINANCE INSTITUTIONS
This copy is consistent with the original
Director of Legal Affairs 1
Legal Department signed
Mufli Asmawidjaja
Established in Jakarta on 23 March 2021
EXECUTIVE HEAD OF SUPERVISION FOR
INSURANCE, PENSION FUNDS,
LENDING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
RISWINANDI
APPENDIX II
FINANCIAL SERVICES AUTHORITY CIRCULAR
REPUBLIC OF INDONESIA
NUMBER 11 /SEOJK.05/2021
REGARDING
GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS FOR MICROFINANCE INSTITUTIONS
FORMAT A: EXAMPLE 1 CUSTOMER/PROSPECTIVE CUSTOMER RISK ASSESSMENT MATRIX AGAINST MONEY LAUNDERING AND/OR TERRORISM FINANCING CRIMES
- Customer/Prospective Customer Data and Information
a. Customer/Prospective Customer Data and Information Customer/Prospective Customer ID Name ID Card Number/National ID Number Address Place, Date of Birth Citizenship Occupation Gender Marital Status Source of Funds Average Income per Year Purpose and objective of transaction Beneficial Owner (if any)
b. Beneficial Owner Data and Information (if any) Name ID Card Number/National ID Number Address Place, Date of Birth Citizenship Occupation Gender Marital Status Source of Funds Average Income per Year
- Customer/Prospective Customer Risk Assessment
Customer risk assessment is conducted by assessing the risk of the customer/prospective customer and assessing the risk of the Beneficial Owner (if any).
a. Customer/Prospective Customer Risk Assessment
| Factor | Risk Indicator | Yes | No |
|---|
| Customer/Prospective Customer | PEP | | |
| PEP Family Member | | | |
| --- | --- | | |
| PEP Related Party | | | |
| Unfair Transaction/Not Consistent with Profile | | | |
| Included in Terrorist/D suspected Terrorist List | | | |
| Included in Weapons of Mass Destruction Financing List | | | |
| Income Source from Criminal Acts | | | |
| Product/service received does not match needs or does not provide benefit | | | |
| Products and Services | Deposits Exceed Rp500 Million *) | | |
| Loan Ceiling Exceeds Rp500 Million *) | | | |
| Distribution Network | Using Non-Face-to-Face Transactions without adequate reason ) | | Geographic Area |
Customer/Prospective Customer Risk Level: High/Medium/Low
Notes:
*) The figure setting is only an example
) Adequate reasons include being sick, traveling out of town, performing official duties, etc.
b. Beneficial Owner (if any) Risk Assessment
| Factor | Risk Indicator | Yes | No |
|---|
| Beneficial Owner | PEP | | |
| PEP Family Member | | | |
| --- | --- | | |
| PEP Related Party | | | |
| Unfair Transaction/Not Consistent with Profile | | | |
| Included in Terrorist/D suspected Terrorist List | | | |
| Included in Weapons of Mass Destruction Financing List | | | |
| Income Source from Criminal Acts | | | |
| Product/service received does not match needs or does not provide benefit | | | |
Beneficial Owner Risk Level: High/Medium/Low
- Determination of Customer/Prospective Customer Risk
The determination of the Customer/Prospective Customer risk level follows the higher risk assessment between the Customer/Prospective Customer assessment and the Beneficial Owner (if any) assessment.
Risk Assessment Results:
High: The Customer/Prospective Customer/Beneficial Owner has a checkmark in one or more of the red column items; the Customer/Prospective Customer has high risk.
Medium: The Customer/Prospective Customer/Beneficial Owner does not have a checkmark in the red column, but has a checkmark in one or more of the yellow column items; the Customer/Prospective Customer has medium risk. Low: The Customer/Prospective Customer/Beneficial Owner does not have a checkmark in the red or yellow columns; the Customer/Prospective Customer has low risk.
Additional Information:
PEP Category
| No. | PEP Category | Definition | Example |
|---|
| 1 | Foreign PEP | A person given authority to perform important functions (prominent function) by another (foreign) country | Head of state or government, senior politician, senior government official, military official or law enforcement official, senior executive in state-owned companies, important official in political party 2 |
PEP Family Members include:
| No. | PEP Family Member |
|---|
| 1 | Biological/step/adopted parent |
| 2 | Biological/step/adopted sibling |
| 3 | Biological/step/adopted child |
| 4 | Biological/step/adopted grandparent |
| 5 | Biological/step/adopted grandchild |
| 6 | Husband or wife |
| 7 | In-laws |
PEP Related Parties include:
| No. | PEP Related Party |
|---|
| 1 | Personal Assistant |
| 2 | Personal Secretary |
| 3 | Driver |
Unfair/Not Consistent with Profile Transactions include:
No. | Unfair/Not Consistent with Profile Transaction --- | --- 1 | Unexplainable distance between transaction location and Customer/Prospective Customer's residence/business place 2 | Unexplainable source of funds of Customer/Prospective Customer 3 | Unexplainable use of loan funds 4 | Frequent transactions by the customer in a short period, making it unfair or inconsistent with profile 5 | and others
Note:
The Customer/Prospective Customer Risk Assessment Matrix against Money Laundering and/or Terrorism Financing Crimes above is only an example and is not a standard format. MFIs are given flexibility to create their own Customer/Prospective Customer Risk Assessment Matrix against Money Laundering and/or Terrorism Financing Crimes, while still observing the provisions in this Financial Services Authority Circular.
FORMAT A: EXAMPLE 2 CUSTOMER/PROSPECTIVE CUSTOMER RISK ASSESSMENT MATRIX AGAINST MONEY LAUNDERING AND/OR TERRORISM FINANCING CRIMES
- Customer/Prospective Customer Data and Information
a. Customer/Prospective Customer Data and Information Customer/Prospective Customer ID Name ID Card Number/National ID Number Address Place, Date of Birth Citizenship Occupation Gender Marital Status Source of Funds Average Income per Year Purpose and objective of transaction Beneficial Owner (if any)
b. Beneficial Owner Data and Information (if any) Name ID Card Number/National ID Number Address Place, Date of Birth Citizenship Occupation Gender Marital Status Source of Funds Average Income per Year
- Customer/Prospective Customer Risk Assessment
| Factor | Item | Description | Value |
|---|
| Customer/Prospective Customer | PEP | Yes | 20 |
| No | 0 | |
| --- | --- | --- | |
| PEP Family Member | Yes | 18 | |
| No | 0 | |
| PEP Related Party | Yes | 17 | |
| No | 0 | |
| Unfair Transaction/Not Consistent with Profile | Yes | 16 | |
| No | 0 | |
| Included in Terrorist/D suspected Terrorist List | Yes | 20 | |
| No | 0 | |
| Included in Weapons of Mass Destruction Financing List | Yes | 20 | |
| No | 0 | |
| Income Source from Criminal Acts | Yes | 20 | |
| No | 0 | |
| Product/service received does not match needs or does not provide benefit | Yes | 16 | |
| No | 0 | |
| Products and Services | Deposits Exceed Rp500 Million *) | Yes | 6 |
| No | 0 | |
| --- | --- | --- | |
| Loan Ceiling Exceeds Rp500 Million *) | Yes | 6 | |
| No | 0 | |
| Distribution Network | Using Non-Face-to-Face Transactions without adequate reason ) | Yes | 0 |
| No | 1 | |
| Geographic Area | Originates from a Province with Low Risk and resides in the MFI's business coverage area | Yes | 1 |
| No | 0 | |
| Total Value | Customer/Prospective Customer Risk | | |
Notes:
*) The figure setting is only an example
) Adequate reasons include being sick, traveling out of town, performing official duties, etc.
c. Beneficial Owner (if any) Risk Assessment
| Factor | Item | Description | Value |
|---|
| Beneficial Owner | PEP | Yes | 20 |
| No | 0 | |
| --- | --- | --- | |
| PEP Family Member | Yes | 18 | |
| No | 0 | |
| PEP Related Party | Yes | 17 | |
| No | 0 | |
| Unfair Transaction/Not Consistent with Profile | Yes | 16 | |
| No | 0 | |
| Included in Terrorist/D suspected Terrorist List | Yes | 20 | |
| No | 0 | |
| Included in Weapons of Mass Destruction Financing List | Yes | 20 | |
| No | 0 | |
| Income Source from Criminal Acts | Yes | 20 | |
| No | 0 | |
| Product/service received does not match needs or does not provide benefit | Yes | 16 | |
| No | 0 | |
| Total Value | Beneficial Owner | | |
| Customer/Prospective Customer Risk | | | |
- Determination of Customer/Prospective Customer Risk
The determination of the Customer/Prospective Customer risk level follows the higher risk assessment between the Customer/Prospective Customer assessment and the Beneficial Owner (if any) assessment.
Risk Assessment Results:
| Total Score | Value | Assessment Result |
|---|
| 0 – 5 | Low | |
| 6 – 15 | Medium | |
15 | High |
Additional Information:
PEP Category
| No. | PEP Category | Definition | Example |
|---|
| 1 | Foreign PEP | A person given authority to perform important functions (prominent function) by another (foreign) country | Head of state or government, senior politician, senior government official, military official or law enforcement official, senior executive in state-owned companies, important official in political party 2 |
PEP Family Members include:
| No. | PEP Family Member |
|---|
| 1 | Biological/step/adopted parent |
| 2 | Biological/step/adopted sibling |
| 3 | Biological/step/adopted child |
| 4 | Biological/step/adopted grandparent |
| 5 | Biological/step/adopted grandchild |
| 6 | Husband or wife |
| 7 | In-laws |
PEP Related Parties include:
| No. | PEP Related Party |
|---|
| 1 | Personal Assistant |
| 2 | Personal Secretary |
| 3 | Driver |
Unfair/Not Consistent with Profile Transactions include:
No. | Unfair/Not Consistent with Profile Transaction --- | --- 1 | Unexplainable distance between transaction location and Customer/Prospective Customer's residence/business place 2 | Unexplainable source of funds of Customer/Prospective Customer 3 | Unexplainable use of loan funds 4 | Frequent transactions by the customer in a short period, making it unfair or inconsistent with profile 5 | and others
Note:
The Customer/Prospective Customer Risk Assessment Matrix against Money Laundering and/or Terrorism Financing Crimes above is only an example and is not a standard format. MFIs are given flexibility to create their own Customer/Prospective Customer Risk Assessment Matrix against Money Laundering and/or Terrorism Financing Crimes, while still observing the provisions in this Financial Services Authority Circular.
FORMAT B: EXAMPLE FORMAT FOR PRODUCT DEVELOPMENT AND NEW BUSINESS PRACTICE RISK ASSESSMENT
PRODUCT NAME: Student Savings
-
Risk Assessment Indicators
No. | Risk Assessment Indicator
--- | ---
1 | Product Type: Savings
2 | Maximum Nominal/Transaction: Rp500,000.00
3 | Target Customer: Elementary to High School Students 4 | Product Distribution Network: Face-to-Face
-
Analysis of Likelihood and Impact Matrix
Estimated Likelihood of Product Being Used for Money Laundering and Terrorism Financing | Estimated Impact of Product Being Used as a Medium for Money Laundering and Terrorism Financing --- | --- Low | Almost never or very rarely used | Low | Money Laundering and Terrorism Financing cases related to this product are at most Rp100,000,000.00 Medium | Occasionally used | Medium | Money Laundering and Terrorism Financing cases related to this product are above Rp100,000,000 and less than or equal to Rp500,000,000.00 High | Very frequently used | High | Money Laundering and Terrorism Financing cases related to this product are valued above Rp500,000,000.00
Note:
The risk assessment for product development and new business practices above is only an example and is not a standard format. MFIs are given flexibility to create their own Risk Assessment format for product development and new business practices, considering the potential Money Laundering and Terrorism Financing risks.
-
Explanation:
The student savings product from LKMA Sido Makmur is exclusively for students from Wanajaya Village. Due to its limited nature, restricted to students specifically within Wanajaya Village, and having a daily transaction limit, this product has a very low Money Laundering and Terrorism Financing risk.
-
Mitigation:
LKMA Sido Makmur ensures that student savings customers are indeed students by requesting student ID cards from Customers and setting transaction nominal limits.
FORMAT C: DATA UPDATING ACTIVITY PLAN REPORT
(MFI NAME)
YEAR ….
No. | Customer Risk Level | Quantity | Integrated Customer Profile | Information to be Updated | Method or Strategy | Percentage of Integrated Customer Profile Fulfillment to be Updated | Integrated Customer Profile to be Updated % of Total Integrated Customer Profiles --- | --- | --- | --- | --- | --- | --- | --- (a) | (b) | (c) | (d) | (e) | (f)
- Individual Customers
a. High Risk b. Medium Risk
c. Low Risk
- Corporate Customers
a. High Risk b. Medium Risk
c. Low Risk
- Other Association Customers
a. High Risk b. Medium Risk
c. Low Risk
Column Notes:
(a) As per column
(b) Filled with the planned quantity of integrated customer profiles to be updated for the next 1 (one) year. If there are no integrated customer profiles to be updated, write NIHIL. (c) Filled in percentage (d) Information can be filled with more than one, such as updating residential address or occupation (e) Method or strategy can be filled with more than one, such as correspondence via letter or email. (f) Filled with the target fulfillment percentage of integrated customer profile updates within a specific period. The period is determined by adjusting to each MFI's capacity and conditions, e.g., quarterly. Example: Quarter I = 30%, Quarter II = 60%, Quarter III = 90%, Quarter IV = 100%.
DATA UPDATING REALIZATION REPORT
(MFI NAME)
YEAR ….
No. | Customer Risk Level | Development | Obstacles | Efforts to be Taken | Realization Target | Difference (%) --- | --- | --- | --- | --- | --- | --- (a) | (b) | (c) | (d) | (e) | (f)
- Individual Customers
a. High Risk b. Medium Risk
c. Low Risk
- Corporate Customers
a. High Risk b. Medium Risk
c. Low Risk
- Other Association Customers
a. High Risk b. Medium Risk
c. Low Risk
Column Notes:
(a) As per column
(b) Filled with the target quantity of integrated customer profiles to be updated (c) Filled with the realized quantity of integrated customer profiles to be updated (d) Filled with the percentage difference between the target quantity of integrated customer profiles to be updated (b) and the realized quantity of integrated customer profiles to be updated (c). (e) Obstacles can be filled with more than one.
This copy is consistent with the original
Director of Legal Affairs 1
Legal Department signed
Mufli Asmawidjaja
Established in Jakarta on 23 March 2021
EXECUTIVE HEAD OF SUPERVISION FOR
INSURANCE, PENSION FUNDS,
LENDING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
RISWINANDI