2017-07-17 | 37/SEOJK.05/2017Added · Updated
This circular establishes guidelines for Non-Bank Financial Industry Financial Service Providers (PJK IKNB) to implement a risk-based Anti-Money Laundering and Counter-Terrorism Financing (APU and PPT) program. It mandates that providers identify, assess, and understand risks related to customers, geographies, products, and distribution channels, referencing national and sectoral risk assessments. The document defines key terms, outlines the mechanics of money laundering and terrorism financing, and requires the application of internal controls, management systems, and human resource training to mitigate identified risks.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
at their respective locations.
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 37 /SEOJK.05/2017
CONCERNING
GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE NON-BANK FINANCIAL INDUSTRY SECTOR
In relation to the mandate of Article 68 of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2017 Number 57, Supplement to the State Gazette of the Republic of Indonesia Number 6035), it is necessary to regulate further regarding the guidelines for the implementation of anti-money laundering and counter-terrorism financing programs in the non-bank financial industry sector as follows:
I. GENERAL PROVISIONS
a. Insurance Company is an insurance company as referred to in Law Number 40 of 2014 concerning Insurance. b. Sharia Insurance Company is a Sharia insurance company as referred to in Law Number 40 of 2014 concerning Insurance.
c. Insurance Broker Company is a company that conducts insurance brokerage business as referred to in Law Number 40 of 2014 concerning Insurance.
d. Financial Institution Pension Fund, hereinafter abbreviated as DPLK, is a financial institution pension fund as referred to in Law Number 11 of 1992 concerning Pension Funds. e. Financing Company is a business entity that conducts financing activities for the procurement of goods and/or services, including those that conduct all or part of their business based on Sharia principles. f. Venture Capital Company, hereinafter abbreviated as PMV, is a business entity that conducts venture capital business activities, venture fund management, fee-based service activities, and other activities with the approval of the Financial Services Authority, including those that conduct all or part of their business based on Sharia principles. g. Infrastructure Financing Company is a business entity established specifically to conduct financing in the form of providing funds for infrastructure projects. h. Indonesian Export Financing Institution, hereinafter abbreviated as LPEI, is the Indonesian export financing institution as referred to in Law Number 2 of 2009 concerning the Indonesian Export Financing Institution.
i. Pawnshop Company is a private pawnshop company and a government pawnshop company regulated and supervised by the Financial Services Authority.
j. Non-Bank Financial Industry Financial Service Provider, hereinafter referred to as PJK IKNB, is an Insurance Company, Sharia Insurance Company, Insurance Broker Company, DPLK, Financing Company, PMV, Infrastructure Financing Company, LPEI, and Pawnshop Company. k. Board of Directors:
PJK IKNB is highly vulnerable to the possibility of being used as a medium for Money Laundering and Terrorism Financing. PJK IKNB may become an entry point for assets that are the proceeds of Money Laundering criminal acts or are financing for terrorist activities into the financial system, which can subsequently be utilized for the benefit of criminals. For example, for Money Laundering perpetrators, these assets can be withdrawn again as seemingly legitimate assets that can no longer be traced to their origin. Whereas for Terrorism Financing perpetrators, these assets can be used to finance terrorist activities.
The increasing complexity of financial service products and services, including their marketing (multi-channel marketing), and the increasing use of information technology in the financial services industry, result in a higher risk of PJK IKNB being used as a means for Money Laundering and/or Terrorism Financing.
In this regard, there is a need to improve the quality of the implementation of the APU and PPT program based on a risk-based approach in accordance with general principles applicable internationally and in line with the national risk assessment (NRA) and sectoral risk assessment (SRA).
The implementation of a risk-based APU and PPT program must at least include:
a. active supervision by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. internal controls;
d. information management systems; and e. human resources and training.
Overview of Money Laundering Criminal Acts
a. Money Laundering Criminal Acts (TPPU) are acts of placing, transferring, paying, spending, donating, entrusting, taking abroad, exchanging, or other acts over assets known or reasonably suspected to be the proceeds of criminal acts with the intent to hide or disguise the origin of the assets so that they appear to be legitimate assets. b. Generally, the Money Laundering process can be grouped into 3 (three) stages of activities, including:
a. Every terrorist act carried out in Indonesia essentially requires support, both in the form of armaments (firearms, sharp weapons, and explosives), housing, vehicles for mobilization, war facilities, and provision of needs for members, all of which can be interpreted as financing based on the definition of funds in Law Number 9 of 2013 concerning the Prevention and Eradication of Terrorism Financing Criminal Acts. In terrorist crime acts, money or funds are intended as a means to carry out actions and not as a target to be sought, so various methods will be used by perpetrators to obtain funds, both legitimately such as selling mobile credit, asking for donations, selling computer equipment, selling herbal products, opening internet cafe services, or through criminal acts such as robbery, fraud, up to hacking online investment sites. The collected funds are used to obtain armaments, buy explosives, build networks or recruit members, conduct war training, and mobilize members to or from a place for the implementation of terrorist actions. b. Terrorism Financing Criminal Acts (TPPT) are the direct or indirect use of assets for terrorist activities, terrorist organizations, or terrorists. Terrorism Financing is essentially a type of criminal act different from TPPU, however, both contain similarities in that they use financial services as a means to commit a criminal act.
c. Unlike TPPU, whose purpose is to disguise the origin of assets, the purpose of TPPT is to assist terrorist activities, whether with assets that are the proceeds of a criminal act or with assets obtained legitimately. To prevent PJK IKNB from being used as a means for TPPT, PJK IKNB needs to implement an adequate APU and PPT program.
d. Some Terrorism Financing modus operandi include:
II. IMPLEMENTATION OF RISK-BASED APU AND PPT PROGRAM (RISK-BASED APPROACH)
a. The APU and PPT program is a program that PJK IKNB must implement in conducting business relationships with service users. This program includes matters required in the Financial Action Task Force (FATF) Recommendations as an effort to protect PJK IKNB from being used as a means or target for crime, whether carried out directly or indirectly by criminals. FATF Recommendation 1 affirms that PJK IKNB is obligated to identify, assess, and understand the risks of Money Laundering criminal acts and/or Terrorism Financing criminal acts related to customers, countries/geographic areas/jurisdictions, products, services, transactions, or distribution networks (delivery channels). PJK IKNB conducts its own assessment and implements an effective risk management framework process. PJK IKNB is obligated to update data related to the implementation of the APU and PPT program and be responsive in order to support national risk assessment. b. The implementation of a risk-based APU and PPT program supports PJK IKNB in implementing prevention and risk mitigation measures commensurate with the identified TPPU and TPPT risks. PJK IKNB can subsequently allocate its resources according to the risk profile faced by PJK IKNB, manage internal controls, internal structure, and implement policies and procedures to prevent and detect Money Laundering and Terrorism Financing.
c. In the implementation of a risk-based APU and PPT program, PJK IKNB must refer to and consider risks of national concern listed in the NRA and SRA. The risks listed in the NRA and SRA can develop and change; therefore, the APU and PPT program implemented by PJK IKNB must be responsive to changes in those risks.
a. Definition of Risk
Risk can be defined as the likelihood of an event and its consequences. Simply put, risk can be seen as a combination of the probability of occurrence and the level of damage or loss that may result from an event. In the context of Money Laundering and Terrorism Financing, risk is interpreted as:
a. In conducting a risk-based approach, PJK IKNB must carry out 6 (six) activity steps as follows:
identify inherent risks;
determine risk tolerance;
formulate risk reduction and control measures;
evaluate residual risk;
apply a risk-based approach; and
review and evaluate the existing risk-based approach.
b. The cycle flow of the risk-based approach is as set forth in Appendix I, which forms an integral part of this Financial Services Authority Circular.
policies and procedures, mitigation steps, and internal controls.
Review of risk assessments related to Money Laundering and Terrorism Financing must cover all elements including policies and procedures regarding risk assessment, risk mitigation, and more intensive continuous monitoring. Reviews can help Non-Bank Financial Institutions (PJK IKNB) in evaluating the refinement of existing policies and procedures, or for the formation of new policies and procedures. Identified risks may change or develop alongside the development of new products or the emergence of new threats to business activities. Ultimately, the review procedures mentioned will affect the effectiveness of the implementation of the risk-based approach.
With the review of the risk-based approach, PJK IKNB is expected to:
a) conduct reviews according to the needs of the PJK IKNB or in the event of changes in business models, new portfolio acquisitions, and so on;
b) produce reviews that cover compliance with policies and procedures, risk assessments for Money Laundering and Terrorism Financing, and training programs to test the effectiveness of the risk-based approach;
c) document the review process and report to senior officials; and
d) document the results of the review along with the establishment of corrective measures to be followed up.
III. ACTIVE OVERSIGHT BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
Active oversight by the Board of Directors must at least include:
a. ensuring that the PJK IKNB has policies and procedures for the implementation of the APU and PPT program;
b. proposing written strategic policies and procedures regarding the implementation of the APU and PPT program to the Board of Commissioners, which must at least contain:
background for the formulation of written policies and procedures;
structure, duties, authorities, and responsibilities of the working unit or person in charge of implementing the APU and PPT program;
policies and procedures for the implementation of the APU and PPT program;
oversight of the implementation of the APU and PPT program; and
internal control plan based on oversight results;
c. ensuring that the APU and PPT program is implemented in accordance with the established written policies and procedures;
d. forming a special working unit and/or appointing officials responsible for the implementation of the APU and PPT program;
e. conducting oversight on the compliance of working units in implementing the APU and PPT program, including monitoring the execution of duties by the Special Working Unit (UKK) and/or officials responsible for the implementation of the APU and PPT program;
f. ensuring that written policies and procedures regarding the implementation of the APU and PPT program align with changes and developments in products, services, and technology in the financial services sector and are in accordance with the development of Money Laundering and/or Terrorism Financing modus operandi, and can be applied in various situations;
g. ensuring that all employees, particularly employees from relevant working units and new employees, have participated in periodic training related to the implementation of the APU and PPT program, including scheduling training;
h. being responsible for policies, oversight, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks;
i. providing technical approval for policies, oversight, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks related to the technical execution of the Board of Directors' duties; and
j. in supporting the effectiveness of the implementation of the APU and PPT program, the Board of Directors must:
have adequate understanding of the Money Laundering and Terrorism Financing risks inherent in all operational activities of the PJK IKNB so that the Board of Directors is able to take necessary actions according to the PJK IKNB's risk profile;
provide clear direction on policies, oversight, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks; and
actively conduct oversight and risk mitigation, specifically customer risk, country/geographic area/jurisdiction risk, product/service/transaction risk, and distribution network (delivery channels) risk.
Active oversight by the Board of Commissioners must at least include:
a. providing approval for policies and procedures for the implementation of the APU and PPT program proposed by the Board of Directors;
b. conducting oversight on the Board of Directors' execution of responsibilities regarding the implementation of the APU and PPT program;
c. ensuring that discussions related to Money Laundering and/or Terrorism Financing take place in Board of Directors and Board of Commissioners meetings by agenda-setting the discussion of the APU and PPT implementation program in Board of Commissioners meetings with the Board of Directors;
d. being responsible for policies, oversight, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks;
e. providing strategic approval for policies, oversight, and procedures for the management and mitigation of Money Laundering and Terrorism Financing risks related to policies, oversight, and procedures that are significant and fundamental in the implementation of the APU and PPT program; and
f. in supporting the effectiveness of the implementation of the APU and PPT program, the Board of Commissioners must:
have understanding regarding the risks faced by the PJK IKNB, especially customer risk, country/geographic area/jurisdiction risk, product/service/transaction risk, and distribution network (delivery channels) risk; and
ensure that the organizational structure is adequate for the implementation of the APU and PPT program.
a. Based on considerations of operational workload and business complexity, the PJK IKNB forms a Special Working Unit (UKK) and/or appoints an official responsible for the implementation of the APU and PPT program at the headquarters and at branches or offices outside the headquarters.
b. In carrying out their duties, the UKK and/or the official responsible for the implementation of the APU and PPT program reports to and is responsible to the Board of Directors that oversees the compliance function, risk management function, or one of the Board of Directors members related to the implementation of the APU and PPT program.
c. So that the duties of the UKK and/or the official responsible for the implementation of the APU and PPT program can be carried out well, the PJK IKNB must have adequate working mechanisms, and be carried out by each relevant working unit while paying attention to regulations regarding anti-tipping off and information confidentiality.
d. The UKK and/or the official responsible for the implementation of the APU and PPT program must meet the following criteria:
independent from the activities being monitored;
able to provide information needed by the Board of Directors to obtain a picture of the PJK IKNB's condition regarding risk management and compliance; and
have appropriate and unrestricted access to customer identification documents, registered accounts, other accounting records, and other related information.
e. The UKK must consist of at least 1 (one) person acting as the leader and 1 (one) person acting as the executor.
f. In the event that the PJK IKNB appoints an official responsible for the implementation of the APU and PPT program at the headquarters, the official responsible must be an official or employee at the lowest level below the Board of Directors.
g. In the event that the PJK IKNB appoints an official responsible for the implementation of the APU and PPT program at a branch or office outside the headquarters, the official responsible must be an official or employee at the lowest level equivalent to a supervisor.
h. For branches or offices outside the headquarters, with high business complexity and containing only working units related to customers, the official or employee responsible for the implementation of the APU and PPT program may:
originate from the headquarters or regional office with special duties and responsibilities to oversee the implementation of the APU and PPT program at several specific branches; or
be held concurrently by an employee from a working unit not related to customers (non-operational) at other branches, such as the risk management working unit. Concurrent holding of positions is permitted considering that the working unit implementing the APU and PPT program's policies and procedures is separate from the working unit overseeing its implementation.
i. For branches or offices outside the headquarters, with low business complexity, the official or employee responsible for the implementation of the APU and PPT program may be held concurrently by an employee from a working unit related to customers (operational), provided that such operational duties do not affect the independence and professionalism of the employee in carrying out their duties.
j. The UKK and/or the official responsible for the implementation of the APU and PPT program at branches or offices outside the headquarters for the PJK IKNB is assisted by the head of the office in the implementation of the APU and PPT program at offices outside the headquarters.
IV. POLICIES AND PROCEDURES
PJK IKNB is required to have policies and procedures to manage and mitigate Money Laundering and/or Terrorism Financing risks identified according to risk assessments.
The policies and procedures for the implementation of the APU and PPT program must at least include:
a. customer identification and verification;
b. beneficial owner identification and verification;
c. termination of business relationships or rejection of transactions;
d. continuous management of Money Laundering and/or Terrorism Financing risks related to customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels);
e. maintenance of accurate data related to transactions, documentation of the customer due diligence process, and documentation of policies and procedures;
f. updating and monitoring;
g. reporting to senior officials, the Board of Directors, and the Board of Commissioners regarding the implementation of policies and procedures for the APU and PPT program; and
h. reporting to the Financial Transaction Reports and Analysis Center (PPATK).
a. Customer Due Diligence (CDD) Policy
Customer Due Diligence (CDD) is an activity involving identification, verification, and monitoring conducted by the PJK IKNB to ensure transactions align with the profile, characteristics, and/or transaction patterns of prospective customers or customers.
PJK IKNB is required to conduct CDD procedures at the time:
a) establishing a business relationship with a prospective customer;
b) there is a financial transaction in Rupiah and/or foreign currency with a value of at least or equivalent to Rp100,000,000.00 (one hundred million Rupiah);
c) there are indications of suspicious financial transactions related to Money Laundering and/or Terrorism Financing; or
d) the PJK IKNB doubts the accuracy of information provided by prospective customers, customers, authorized representatives, and/or beneficial owners.
CDD with a risk-based approach is intended to obtain up-to-date information regarding customer profiles to ensure alignment between customer profiles and transactions conducted. CDD can be conducted on all information or only on part of the information.
In the event that the PJK IKNB assesses that there is a change in the customer's risk level, CDD based on the risk-based approach can be conducted again if:
a) there is a significant increase in transaction value;
b) there is a significant change in the customer's profile;
c) information in the available customer identification file (CIF) is not yet supplemented with documents for verification; and/or
d) using anonymous accounts or accounts using fictitious names.
b. Prospective Customer Acceptance and Identification Procedures
PJK IKNB must have policies regarding the acceptance and identification of prospective customers that must at least cover the following:
requests for information regarding prospective customers;
requests for identity proof and supporting information from prospective customers;
investigation into the authenticity of supporting identity documents for prospective customers;
requests for more than one identity card for prospective customers issued by competent authorities, if there is doubt about the existing identity card;
if necessary, interviews with prospective customers may be conducted to obtain assurance regarding the accuracy of information, identity proof, and supporting documents for prospective customers;
prohibition on opening or maintaining anonymous accounts or accounts using fictitious names;
face-to-face meetings with prospective customers at the beginning of establishing a business relationship to assure the authenticity of the prospective customer's identity;
caution regarding transactions or business relationships with prospective customers originating from or related to countries that are not adequate in implementing FATF recommendations; and
the process of verifying the identity of prospective customers must be completed before establishing a business relationship with prospective customers.
c. Beneficial Owner Identification Procedures
If a prospective customer represents a beneficial owner to establish a business relationship or conduct a transaction, the PJK IKNB must conduct CDD procedures on the beneficial owner with the same strictness as CDD procedures for prospective customers.
In the event that the beneficial owner is classified as a Politically Exposed Person (PEP), the procedure applied is stricter CDD procedures or Enhanced Due Diligence (EDD).
In identifying prospective corporate customers, the PJK IKNB must determine the beneficial owner.
For beneficial owners that are state institutions or government agencies, companies with majority state-owned shares, or public companies/issuers, there is no requirement to submit documents and/or identity of the ultimate controller.
Exceptions to the requirement to submit documents and/or identity of the beneficial owner's ultimate controller must be documented.
If the PJK IKNB doubts or cannot verify the identity of the beneficial owner, the PJK IKNB must refuse to establish a business relationship or conduct transactions with the prospective customer.
For prospective customers or beneficial owners whose business relationships or transactions are rejected, the PJK IKNB must obtain at least the name, identity number, address, and place and date of birth according to copies of identity documents obtained by the PJK IKNB for the purpose of reporting Suspicious Financial Transaction Reports (LTKM).
d. Verification of Prospective Customers, Customers, and Beneficial Owners
PJK IKNB must investigate the accuracy of information provided by prospective customers by verifying supporting documents based on documents and/or other independent sources and ensuring the currency of such information.
In order to assure the authenticity of the prospective customer's identity, verification is conducted by:
a) face-to-face meetings with prospective customers at the beginning of establishing a business relationship;
b) conducting interviews with prospective customers if necessary;
c) matching the prospective customer's profile with the self-photo contained in the identity card;
d) matching signatures, thumbprints, or fingerprints with identity documents or other documents containing signatures, thumbprints, or fingerprints. Other documents include, among others, prospective customer declaration letters, family cards, or credit cards;
e) requesting prospective customers to provide more than one identity document issued by competent authorities if there is doubt about the existing identity card;
f) documenting copies of identity cards after matching with original valid documents;
g) conducting cross-checks to ensure consistency of various information provided by prospective customers. Cross-checks are conducted by methods including:
i. contacting prospective customers via telephone (home or office);
ii. contacting human resources officials at the place where the prospective customer works if the prospective customer is an employee of a company or agency;
iii. confirming the prospective customer's income by requiring bank statements from banks or other financial service providers; or
iv. conducting geographic information analysis to view forest conditions through remote sensing technology for prospective corporate customers operating in the forestry sector;
h) ensuring that prospective customers do not have negative records by verifying the identity of prospective customers using other independent sources including:
i. terrorist lists and/or suspected terrorist lists and terrorist organizations issued by the Indonesian National Police;
ii. national blacklists (DHN); or
iii. other data owned by the PJK IKNB, prospective customer employer identities, telephone accounts, and electricity accounts; and/or
i) ensuring the possibility of unusual or suspicious circumstances.
a) what you have, namely identity documents owned by the prospective customer, namely the Electronic Identity Card (KTP);
b) what you are, namely biometric data such as the prospective customer's fingerprints.
The process of verifying the identity of prospective customers and beneficial owners must be completed before establishing a business relationship with prospective customers.
In certain conditions, the verification process can be completed after the business relationship has been established.
a) document completeness cannot be met at the time the business relationship is to be established, for example because documents are still being processed. Therefore, prospective customers may submit documents after establishing a business relationship, within the timeframe established by the PJK IKNB; and/or
b) if the risk level of individual prospective customers is classified as low.
e. Simplified Customer Due Diligence (Simplified CDD)
In the event that the PJK IKNB assesses that the risk of prospective customers or customers is very low or for transactions where the risk of Money Laundering or Terrorism Financing occurrence is low, the PJK IKNB may apply Simplified CDD.
PJK IKNB must document customers receiving Simplified CDD treatment in a list containing information regarding the reasons for risk determination so that they are classified as low risk.
Customers who have received Simplified CDD treatment must be removed from the Simplified CDD customer list if they meet the following criteria:
a) indicated to be related to Money Laundering or Terrorism Financing; or
b) inconsistent with the initial purpose of account opening, such as for payment or salary receipt.
a) undergo CDD or EDD according to the customer's current risk level; and/or
b) be reported in Suspicious Financial Transaction Reports (LTKM) if transactions are indicated to be related to Money Laundering or Terrorism Financing.
f. Third-Party Customer Due Diligence
PJK IKNB may use the results of CDD conducted by third parties on prospective customers who have already become customers of that third party.
In the event that the PJK IKNB uses the results of third-party CDD as referred to in paragraph (1), the PJK IKNB is required to:
a. understand the purpose and intent of the business relationship; and
b. identify and verify customers and beneficial owners.
In the event that the PJK IKNB uses the results of CDD conducted by third parties, the responsibility for CDD remains with the PJK IKNB.
In the event that the PJK IKNB uses third-party CDD:
a. PJK IKNB is required to obtain the necessary information related to CDD procedures as soon as possible;
b. PJK IKNB is required to have cooperation with third parties in the form of written agreements;
c. PJK IKNB is required to take adequate steps to ensure that third parties are willing to fulfill information requests and copies of supporting documents immediately if needed by the PJK IKNB in the implementation of the APU and PPT program;
d. PJK IKNB is required to ensure that the third party is a financial institution and provider of goods and/or services and specific professions that have CDD procedures and are subject to oversight by competent authorities in accordance with applicable laws and regulations; and
e. PJK IKNB is required to pay attention to information regarding the country risk where the third party originates.
PJK IKNB ensures that the third party is in a country that complies with FATF standards; and
Third-party CDD does not apply to agency relationships or outsourcing.
g. Enhanced Due Diligence (EDD)
PJK IKNB is required to conduct assessments to determine if prospective customers, customers, or beneficial owners are PEPs.
In the event that the PJK IKNB assesses that prospective customers, customers, and beneficial owners are high-risk, including PEPs, then the PJK IKNB applies EDD.
EDD as referred to in item 2) is implemented by verifying information on prospective customers, customers, or beneficial owners, including PEPs, based on the accuracy of information, accuracy of information sources, and types of information related.
Verification of information in the implementation of EDD as referred to in item 3) can be conducted by methods including:
a) searching for additional information about the relevant customer and updating customer or beneficial owner identity data;
b) searching for additional information regarding the nature and purpose of the business relationship;
c) searching for additional information regarding the source of funds or customer wealth;
d) searching for additional information regarding the reasons for the intended or conducted transactions;
e) request approval from senior officials to initiate or continue such business relationships; and/or f) conduct increasingly stringent monitoring of such business relationships, namely by increasing the number and duration of supervision used, and having transaction patterns that require further examination.
Non-Bank Financial Institutions (PJK IKNB) must account for documents related to Enhanced Due Diligence (EDD) and periodically update customer data according to the needs and complexity of the PJK IKNB.
In carrying out business relationships with prospective customers, customers, or beneficial owners, including Politically Exposed Persons (PEPs), who receive EDD treatment, PJK IKNB must appoint a senior official as the person responsible for such business relationship.
PJK IKNB shall reject transactions or close business relationships with prospective customers or customers in the event:
a) the prospective customer or customer is unwilling to provide information and/or complete documents required by PJK IKNB; b) the prospective customer or customer provides information and/or documents that are inconsistent or reasonably suspected to be forged documents or information whose truthfulness is doubtful; and/or c) the source of funds for the transaction held by the prospective customer or customer is known and/or reasonably suspected to originate from the proceeds of crime; and/or d) the prospective customer or customer is listed in the terrorist list and/or the list of suspected terrorists and terrorist organizations.
PJK IKNB is required to notify the customer in writing regarding the closure of the business relationship.
Written notification can be done by sending a letter addressed to the customer according to the address recorded in the PJK IKNB database or announced through print media, electronic media, or other media.
In the event that written notification has been carried out and the customer does not withdraw the remaining funds stored at PJK IKNB, then the settlement of the customer's remaining funds is carried out in accordance with applicable legislation, including by handing over the remaining funds to the Estate Administration Office (Balai Harta Peninggalan).
PJK IKNB must document prospective customers or customers subject to transaction rejection or business relationship closure as referred to in item 1) in a separate list.
a. PJK IKNB implements policies, procedures, and controls to reduce the potential for Money Laundering and Terrorism Financing, especially related to customers, countries/geographical areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels) that may pose higher risks.
b. Controls and mitigations that can be applied include at least:
a. PJK IKNB must account for all transaction data or documents obtained through CDD steps conducted both domestically and internationally for at least 5 (five) years. This is an effort to assist authorities in conducting investigations into funds indicated to originate from criminal proceeds or to assist in the execution of duties by competent authorities. Thus, documents owned or stored by PJK IKNB must be sufficient as aids for reconstructing individual transactions (including the amount and type of currency used, if any) so that they can serve as evidence (if necessary) in prosecuting criminal activities.
b. The retention period for documents is as follows:
c. PJK IKNB is required to provide data, information, and/or documents that have been accounted for when requested by the Financial Services Authority (OJK) and/or other competent authorities.
a. Monitoring
The level and nature of monitoring conducted by PJK IKNB will depend on the characteristics of PJK IKNB, business complexity, and the level of Money Laundering and Terrorism Financing risk held by PJK IKNB.
PJK IKNB must conduct monitoring activities at least:
a) conducted continuously to identify the consistency between customer transactions and customer profiles and account for such documents, especially regarding business relationships or transactions with customers and/or PJK IKNB from countries with inadequate AML/CFT programs; b) conducting analysis of all transactions that are inconsistent with customer profiles; and c) if necessary, requesting information about the background and purpose of transactions that are inconsistent with customer profiles, paying attention to anti-tipping off regulations as regulated in laws regarding the prevention and eradication of Money Laundering.
Continuous monitoring of customer profiles and transactions includes activities:
a) ensuring the completeness of customer information and documents; b) examining the consistency between transaction profiles and customer profiles; and c) examining name similarities or matches with names recorded in:
i. terrorist database;
ii. lists of suspected terrorists and terrorist organizations;
iii. names of suspects or defendants published in mass media or by competent authorities; and
iv. national blacklist (DHN).
Information sources that can be used to monitor customers designated as suspects or defendants can be obtained from, among others:
a) databases issued by competent authorities such as the Center for Reporting and Analysis of Financial Transactions (PPATK); or b) mass media, such as newspapers, magazines, television, and the internet.
PJK IKNB must classify transactions and customers requiring special monitoring. Monitoring of customer accounts must be stricter if there are high-risk customers.
All monitoring activities must be well documented in written form through formal documents such as memos, notes, or records, as well as through informal documents such as email correspondence.
b. Data Updating
PJK IKNB must apply CDD procedures to its customers for data updating, to update data materiality and risk. CDD can be conducted by considering the timing of previous CDD implementation and the adequacy of data obtained.
PJK IKNB must update data regarding information and documents as referred to in Financial Services Authority regulations regarding the implementation of AML/CFT programs in the financial services sector and account for them.
PJK IKNB must ensure that documents, data, or information collected in the CDD process are always updated and relevant by re-examining existing data, especially those related to high-risk customers.
PJK IKNB must update customer data so that the identification and monitoring of suspicious financial transactions can run effectively.
Customer data updating is conducted using a risk-based approach. In the event that PJK IKNB's resources are limited, data updating activities are conducted on a priority scale.
Parameters for determining priority scales as referred to in item 5) include, among others:
a) high customer risk level; b) transactions with significant amounts and/or deviating from transaction profiles or customer profiles (red flag); c) significant changes in balance values; and/or d) information in the Customer Identification File (CIF) is not in accordance with Financial Services Authority regulations regarding the implementation of AML/CFT programs in the financial services sector.
Data updating is conducted periodically according to the characteristics and complexity of PJK IKNB's business activities.
Implementation of data updating for customers listed in the data updating plan can be conducted, among others, at:
a) the opening of additional business relationships; b) the extension of the use of PJK IKNB products/services/transactions; c) the replacement of customer data and identity documents; or d) the closure of business relationships.
All data updating activities must be administered.
In the event that a customer to be updated was a customer before the Financial Services Authority regulations regarding the implementation of AML/CFT programs in the financial services sector took effect, PJK IKNB must notify the customer in writing regarding PJK IKNB's obligation to reject transactions and/or close business relationships as stated in Section IV item 4.
a. In the event that the CDD process shows prospective customers or customers categorized as high-risk, PJK IKNB employees conducting CDD must report to Senior Officials. Senior Officials are responsible for the acceptance and/or rejection of business relationships with high-risk prospective customers or customers.
b. In the event that senior officials approve business relationships with high-risk customers, senior officials are responsible for monitoring the transactions of high-risk customers.
c. Senior Officials must report to the Board of Directors overseeing the AML/CFT program implementation regarding the number of high-risk prospective customers or customers, including the number of high-risk customers rejected, accepted, or having their business relationships closed.
d. The Board of Directors must provide guidance on reports submitted by senior officials and establish risk mitigation steps.
e. The Board of Directors reports to the Board of Commissioners regarding the results of monitoring the overall implementation of the AML/CFT program as per the written policies and procedures established by PJK IKNB.
f. The Board of Directors may propose updates to policies and procedures in the event of risk developments that need to be mitigated by PJK IKNB, which are not yet included in the written policies and procedures.
a. PJK IKNB is required to submit Suspicious Financial Transaction Reports (LTKM), Cash Financial Transaction Reports (LTKT), and other reports to the Center for Reporting and Analysis of Financial Transactions (PPATK) as regulated in legislation governing the prevention and eradication of Money Laundering crimes.
b. In the event that PJK IKNB finds indications of cash financial transactions involving the carrying of cash and other payment instruments into or out of the territory of the Republic of Indonesia, including land, waters, and airspace above it, as well as specific zones that are exclusive economic zones and continental shelves where customs laws apply.
c. PJK IKNB must submit other reports regarding the implementation of the AML/CFT program in the event of information requests from the Center for Reporting and Analysis of Financial Transactions (PPATK).
V. INTERNAL CONTROL
Effective risk-based AML/CFT program implementation must be implemented in internal control and internalized into the PJK IKNB culture.
Senior officials are responsible for ensuring that PJK IKNB has an effective internal control structure, including for monitoring and reporting suspicious financial transactions.
Senior officials must create a risk management and compliance culture, ensuring that employees comply with policies and procedures aimed at limiting and controlling risks.
In addition to internal control compliance, the implementation of the AML/CFT program is also influenced by the following factors:
a. the scale and complexity of PJK IKNB; b. the diversity of business or operational activities of PJK IKNB, including the diversity of countries/geographical areas/jurisdictions, customers, products/services/transactions, and PJK IKNB's overall transaction activities;
c. distribution networks (delivery channels) used;
d. transaction volume and scale; e. the level of risk assessment for each business activity of PJK IKNB; and/or f. the relationship between PJK IKNB and customers, either directly or through intermediaries, third parties, correspondents, or non-face-to-face communication.
PJK IKNB must have an internal control framework including:
a. the appointment of a Unit of Compliance (UKK) and/or officials responsible for managing the implementation of the AML/CFT program; b. special monitoring of operational activities with potential high risks, including monitoring of areas deemed vulnerable and potentially related to suspicious transactions or requiring special attention based on suggestions and information from industry associations, regulators, or law enforcement;
c. providing regular reviews of risk assessments and management processes considering the location where PJK IKNB operates;
d. ensuring adequate controls before offering new products/services/transactions or when there are offers of modified products/services/transactions that potentially increase Money Laundering and Terrorism Financing risks; e. the rapid and accurate dissemination of information in the event of indications and/or suspicions related to Money Laundering and Terrorism Financing risks, improvement steps taken, results of identifying weaknesses in existing regulations, action plans for improvement, and reports submitted to competent authorities; f. focusing on the collection of information regarding legal regulations, reporting requirements, and recommendations regarding compliance with the implementation of the AML/CFT program and updating changes in regulations; g. implementing policies, procedures, and controls over Customer Due Diligence (CDD); h. providing adequate controls for high-risk customers, transactions, and products, such as transaction limits or management approval;
i. providing adequate supervision of PJK IKNB employees who complete reports, receive grants, monitor suspicious activities, or are involved in other activities that are part of the AML/CFT program implementation;
j. integrating compliance with the implementation of the AML/CFT program into job descriptions and appropriate performance evaluations; k. providing appropriate and relevant training related to the AML/CFT program for all employees;
l. for business groups, having a joint control framework; and
m. testing the effectiveness of the AML/CFT program implementation by taking random samples and documenting the tests conducted.
VI. MANAGEMENT INFORMATION SYSTEM
The implementation of the AML/CFT program must be supported by a management information system that can effectively identify, analyze, monitor, and provide reports on customer transaction characteristics using parameters adjusted periodically and considering business complexity, transaction volume, and PJK IKNB's risks.
Written policies and procedures owned by PJK IKNB must consider information technology factors that have the potential to be abused by Money Laundering or Terrorism Financing perpetrators, such as account opening via the internet, drafts, or fund transfer orders via fax or telephone, and other electronic transactions.
The owned information system must allow PJK IKNB to trace each individual transaction, both for internal and/or Financial Services Authority purposes, as well as in relation to judicial cases.
To facilitate monitoring for the analysis of suspicious financial transactions, PJK IKNB is required to have and maintain an integrated customer profile (single customer identification file/single CIF).
Information contained in the single CIF covers all products and services used by customers at a PJK IKNB, such as vehicle insurance, life insurance, home ownership insurance, and unit link insurance.
For joint accounts, the CIF is created for each party owning the joint account. For example, a joint account in the names of A and B, the CIF created is 2 (two) CIFs, namely CIFs in the names of A and B, informing that both A and B have a joint account.
For the maintenance of the single CIF, PJK IKNB must establish a policy that for every addition of accounts and/or services or products of PJK IKNB by existing customers, PJK IKNB must link the additional accounts, services, or products to the customer information number of the respective customer.
VII. HUMAN RESOURCES AND TRAINING
Implementation of AML and CTF programs. This approach is provided to employees who do not receive priority and is conducted when there are significant changes in regulations.
c. Training Materials and Evaluation
a) training on the implementation of regulations related to AML and CTF programs; b) trends and developments in the risk profile of financial sector products for training on techniques, methods, and typologies of Money Laundering or Terrorism Financing criminal offenses; and/or c) consequences if employees engage in tipping off, for training on policies and procedures for implementing AML and CTF programs, as well as the role and responsibilities of employees in preventing and eradicating Money Laundering or Terrorism Financing criminal offenses.
The depth of training materials is adjusted to the needs of employees and their suitability with their tasks and responsibilities.
To determine the level of employee understanding and the suitability of training materials, PJK IKNB must conduct an evaluation of each training session held.
Evaluations can be conducted directly through interviews or indirectly through tests.
PJK IKNB must take follow-up actions based on the results of training evaluations through the refinement of training materials and methods.
VIII. REPORTING
a. The action plan report must at least contain steps for the implementation of the AML and CTF program in order to comply with regulations of the Financial Services Authority (OJK) regarding the implementation of AML and CTF programs in the financial services sector, which must be implemented by PJK IKNB according to the time targets set for a specific period as established in the action plan, including among others:
b. The action plan report must be approved and submitted by a Board Member who oversees the compliance function or one of the Board Members responsible for the implementation of the AML and CTF program.
c. In the event of changes to the action plan, policies, and procedures for implementing the AML and CTF program, PJK IKNB is required to submit changes to the data update activity plan previously submitted to the Financial Services Authority no later than 7 (seven) working days from the date the changes were made.
PJK IKNB that already has policies and procedures for implementing AML and CTF programs must submit a report on adjustments to these policies and procedures in accordance with the Financial Services Authority Regulation regarding the implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the financial services sector no later than September 16, 2017.
a. The report on the data update activity plan and the report on data update activity realization must be approved and submitted by the Director overseeing the compliance function or one of the Board Members responsible for the implementation of the AML and CTF program.
b. Submission of the data update plan report in accordance with Financial Services Authority regulations regarding the implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the financial services sector is conducted by the Director overseeing the compliance function or one of the Board Members responsible for the implementation of the AML and CTF program annually no later than the end of December.
c. Submission of the data update realization report in accordance with Financial Services Authority regulations regarding the implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the financial services sector is conducted by the Director overseeing the compliance function or one of the Board Members responsible for the implementation of the AML and CTF program annually no later than the end of December.
d. Submission of the data update plan report as referred to in letter b for the first time must be submitted no later than the end of September 2017. Meanwhile, submission of the data update realization report as referred to in letter c for the first time must be submitted annually no later than the end of December 2017.
e. Changes to the data update activity plan report can be made as long as changes occur outside the control of PJK IKNB and must be submitted to the Financial Services Authority no later than 7 (seven) working days from the date the changes were made.
a. PJK IKNB must submit reports on the implementation of AML and CTF programs signed by the Board, with the following conditions:
b. Submission address for reports to DPLK:
Head of Executive Supervisor for Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions Financial Services Authority attn: Director of Pension Fund Supervision Merdeka Tower Building, 22nd Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
c. Submission address for reports for Financing Companies, PMV, and Infrastructure Financing Companies:
Head of Executive Supervisor for Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions Financial Services Authority attn: Director of Financing Institution Supervision Merdeka Tower Building, 19th Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
and for Financing Companies and PMV that have Sharia business units, submitted to:
Director of Sharia Non-Bank Financial Institutions Merdeka Tower Building, 23rd Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
d. Submission address for reports for Pawnshop Companies and LPEI:
Head of Executive Supervisor for Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions Financial Services Authority attn: Director of Special Financial Service Institution Supervision Merdeka Tower Building, 26th Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
and for Pawnshop Companies that have Sharia business units, submitted to:
Director of Sharia Non-Bank Financial Institutions Merdeka Tower Building, 23rd Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
e. Submission address for reports for Financing Companies, PMV, and Pawnshop Companies that conduct all business activities based on Sharia principles:
Head of Executive Supervisor for Insurance, Pension Funds, Financing Institutions, and Other Financial Service Institutions attn: Director of Sharia Non-Bank Financial Institutions Merdeka Tower Building, 23rd Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
In the event of changes to the address of the Financial Services Authority Office for report submission as referred to in item 4, the Financial Services Authority will convey notification regarding the address change via letter or announcement.
Submission of reports for Insurance Companies, Sharia Insurance Companies, Insurance Brokerage Companies, and Insurance Companies that have Sharia business units is the submission of reports as referred to in the Financial Services Authority regulation regarding periodic reports of insurance companies.
This copy is in accordance with the original
Legal Director 1
Legal Department signed
Yuliana
IX. CLOSING
The provisions in this Circular Letter of the Financial Services Authority shall take effect on the date of determination.
Determined in Jakarta on July 17, 2017
HEAD OF EXECUTIVE SUPERVISOR
FOR INSURANCE, PENSION FUNDS,
FINANCING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY,
signed
FIRDAUS DJAELANI
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.